😈 [ n00py1, n00py ]
Web vulns you should look for on an internal pentest: XXE.
We often think of XXE as a way to read local files, but you can also use it to coerce auth. HTTP NTLM does not request signing so you can easily relay it to LDAP. Web service accounts are often over permissioned.
🐥 [ tweet ]
Web vulns you should look for on an internal pentest: XXE.
We often think of XXE as a way to read local files, but you can also use it to coerce auth. HTTP NTLM does not request signing so you can easily relay it to LDAP. Web service accounts are often over permissioned.
🐥 [ tweet ]
😈 [ HackerGautam, Frooti ]
Not only crawling but you can do Subdomain Enumeration using Wayback.
⬇️
curl --insecure --silent "http://web.archive.org/cdx/search/cdx" | sed -e 's_https*://__' -e "s/\/.*//" -e 's/:.*//' -e 's/^www\.//' | sed "/@/d" | sed -e 's/\.$//' | sort -u
#bugbounty #hacking #infosec
🐥 [ tweet ]
Not only crawling but you can do Subdomain Enumeration using Wayback.
⬇️
curl --insecure --silent "http://web.archive.org/cdx/search/cdx" | sed -e 's_https*://__' -e "s/\/.*//" -e 's/:.*//' -e 's/^www\.//' | sed "/@/d" | sed -e 's/\.$//' | sort -u
#bugbounty #hacking #infosec
🐥 [ tweet ]
😈 [ ORCx41, ORCA ]
decided to release this, a highly capable pe packer, with a lot of nice features
https://t.co/iedhKbTlzm
🔗 https://github.com/ORCx41/AtomPePacker
🐥 [ tweet ]
decided to release this, a highly capable pe packer, with a lot of nice features
https://t.co/iedhKbTlzm
🔗 https://github.com/ORCx41/AtomPePacker
🐥 [ tweet ]
😈 [ g0h4n_0, g0h4n ]
Today I share with you #RustHound🦀. A new AD collector written in #Rust for #BloodHound!
It is cross-platform, cross-compiled and generates all json files needed.
Other modules will be available as under development!🔥
Hope you will enjoy it!
https://t.co/bxjCVyocfv https://t.co/8jEcSuEdEj
🔗 https://github.com/OPENCYBER-FR/RustHound
🐥 [ tweet ][ quote ]
Today I share with you #RustHound🦀. A new AD collector written in #Rust for #BloodHound!
It is cross-platform, cross-compiled and generates all json files needed.
Other modules will be available as under development!🔥
Hope you will enjoy it!
https://t.co/bxjCVyocfv https://t.co/8jEcSuEdEj
🔗 https://github.com/OPENCYBER-FR/RustHound
🐥 [ tweet ][ quote ]
😈 [ pdiscoveryio, ProjectDiscovery.io ]
The Ultimate Guide to Finding Bugs With Nuclei by @v3natoris
https://t.co/2GY3QZlTft
#hackwithautomation #cybersecurity #infosec #bugbounty
🔗 https://blog.projectdiscovery.io/ultimate-nuclei-guide/
🐥 [ tweet ]
The Ultimate Guide to Finding Bugs With Nuclei by @v3natoris
https://t.co/2GY3QZlTft
#hackwithautomation #cybersecurity #infosec #bugbounty
🔗 https://blog.projectdiscovery.io/ultimate-nuclei-guide/
🐥 [ tweet ]
😈 [ FortaliceLLC, Fortalice Solutions ]
NTLM Relaying to SCCM for the win 👀👀👀 Fortalice's @Tw1sm just added SCCM support to NtlmRelayX. Check out the PR at: https://t.co/hWfNeiuqxp
🔗 https://github.com/SecureAuthCorp/impacket/pull/1425
🐥 [ tweet ]
NTLM Relaying to SCCM for the win 👀👀👀 Fortalice's @Tw1sm just added SCCM support to NtlmRelayX. Check out the PR at: https://t.co/hWfNeiuqxp
🔗 https://github.com/SecureAuthCorp/impacket/pull/1425
🐥 [ tweet ]
👹 [ snovvcrash, sn🥶vvcr💥sh ]
Based on @dec0ne’s work on ShadowSpray I’ve pushed a small update to #pywhisker of @_nwodtuhs and @podalirius_ implementing the ‘spray’ action. Now you can pass a list of users and try to add the same Shadow Credentials for each of them with pywhisker from Linux 👌🏻
🐥 [ tweet ]
Based on @dec0ne’s work on ShadowSpray I’ve pushed a small update to #pywhisker of @_nwodtuhs and @podalirius_ implementing the ‘spray’ action. Now you can pass a list of users and try to add the same Shadow Credentials for each of them with pywhisker from Linux 👌🏻
🐥 [ tweet ]
🔥1
This media is not supported in your browser
VIEW IN TELEGRAM
😈 [ zux0x3a, Lawrence 勞倫斯 ]
Ported the pascal version to C#, and becomes even better while smuggling the payload using Created Service DisplayName
https://t.co/EhR9yNybF2
what's new? => https://t.co/t7Tkv2AW4O
🔗 https://github.com/0xsp-SRD/0xsp.com/tree/main/chopper
🔗 https://ired.dev/discussion/13/chopper-payload-smuggling/p1?new=1
🐥 [ tweet ]
Ported the pascal version to C#, and becomes even better while smuggling the payload using Created Service DisplayName
https://t.co/EhR9yNybF2
what's new? => https://t.co/t7Tkv2AW4O
🔗 https://github.com/0xsp-SRD/0xsp.com/tree/main/chopper
🔗 https://ired.dev/discussion/13/chopper-payload-smuggling/p1?new=1
🐥 [ tweet ]
😈 [ 0xdf_, 0xdf ]
Perspective from @hackthebox_eu is all about exploitation of a ASP.NET application. There's file read, ssrf, cookie signing, crypto, deserialization, and much more. Beyond Root has JuicyPotatoNG that's almost blocked but not.
🔗 https://0xdf.gitlab.io/2022/10/15/htb-perspective.html
🐥 [ tweet ]
Perspective from @hackthebox_eu is all about exploitation of a ASP.NET application. There's file read, ssrf, cookie signing, crypto, deserialization, and much more. Beyond Root has JuicyPotatoNG that's almost blocked but not.
🔗 https://0xdf.gitlab.io/2022/10/15/htb-perspective.html
🐥 [ tweet ]
😈 [ dr4k0nia, dr4k0nia ]
Time for another blog post :) This time Im writing about building my own string encryption obfuscator in C#. Featuring a simple XOR based cipher and unique per string encryption keys. Works from .NET Framework 4.6+ up to latest .NET
https://t.co/htjR6XdS1Q
🔗 https://dr4k0nia.github.io/dotnet/coding/2022/10/15/Encrypting-Strings-In-NET.html
🐥 [ tweet ]
Time for another blog post :) This time Im writing about building my own string encryption obfuscator in C#. Featuring a simple XOR based cipher and unique per string encryption keys. Works from .NET Framework 4.6+ up to latest .NET
https://t.co/htjR6XdS1Q
🔗 https://dr4k0nia.github.io/dotnet/coding/2022/10/15/Encrypting-Strings-In-NET.html
🐥 [ tweet ]
😈 [ zux0x3a, Lawrence 勞倫斯 | لورانس ]
https://t.co/QOrhGwKctm
CredUI shellcoder runner shared !
🔗 https://ired.dev/discussion/comment/4/#Comment_4
🐥 [ tweet ]
https://t.co/QOrhGwKctm
CredUI shellcoder runner shared !
🔗 https://ired.dev/discussion/comment/4/#Comment_4
🐥 [ tweet ]
😈 [ dr4k0nia, dr4k0nia ]
Alongside my latest blog post about string encryption in .NET Im also releasing the source code of my string encryption obfuscator. https://t.co/eQVP1ZVAjt
🔗 https://github.com/dr4k0nia/XorStringsNET
🐥 [ tweet ]
Alongside my latest blog post about string encryption in .NET Im also releasing the source code of my string encryption obfuscator. https://t.co/eQVP1ZVAjt
🔗 https://github.com/dr4k0nia/XorStringsNET
🐥 [ tweet ]
😈 [ 424f424f, rvrsh3ll ]
Minor update to my BOF_Collection to make compiling a bit easier. https://t.co/SP7Bp4QTxg
🔗 https://github.com/rvrsh3ll/BOF_Collection
🐥 [ tweet ]
Minor update to my BOF_Collection to make compiling a bit easier. https://t.co/SP7Bp4QTxg
🔗 https://github.com/rvrsh3ll/BOF_Collection
🐥 [ tweet ]
😈 [ ORCx41, ORCA ]
Ever wanted to run your payload without being boring ? here you go ...
https://t.co/FmMEwiGWKV
🔗 https://github.com/ORCx41/NoRunPI
🐥 [ tweet ]
Ever wanted to run your payload without being boring ? here you go ...
https://t.co/FmMEwiGWKV
🔗 https://github.com/ORCx41/NoRunPI
🐥 [ tweet ]