This media is not supported in your browser
VIEW IN TELEGRAM
MyBB 1.8.29 - Remote Code Execution (RCE) (Authenticated)
https://github.com/Altelus1/CVE-2022-24734
#MyBB #RCE #Auth_R
@securation
https://github.com/Altelus1/CVE-2022-24734
#MyBB #RCE #Auth_R
@securation
👍3👎3
⭕️Passive/Active Information Gathering: Subdomain Enumeration
https://medium.com/@fath3ad.22/passive-active-information-gathering-subdomain-enumeration-e5538c3d3ecc
#Web #bugbounty
@securation
https://medium.com/@fath3ad.22/passive-active-information-gathering-subdomain-enumeration-e5538c3d3ecc
#Web #bugbounty
@securation
Medium
Passive/Active Information Gathering: Subdomain Enumeration
This post is design to share some of the information I’ve learned while working through the Information Gathering- Web Edition module in…
⭕️ SysWhispers Shellcode Loader
- Compiles raw shellcode and compile a C++ stub
that has been integrated with SysWhispers in order to bypass AV/EDR.
The included python builder will work on any Linux system that has Mingw-w64 installed.
- 5 different ways to execute your shellcode
https://github.com/icyguider/Shhhloader
#loader #bypass #av #edr #windows #shellcode
@securation
- Compiles raw shellcode and compile a C++ stub
that has been integrated with SysWhispers in order to bypass AV/EDR.
The included python builder will work on any Linux system that has Mingw-w64 installed.
- 5 different ways to execute your shellcode
https://github.com/icyguider/Shhhloader
#loader #bypass #av #edr #windows #shellcode
@securation
GitHub
GitHub - icyguider/Shhhloader: Syscall Shellcode Loader (Work in Progress)
Syscall Shellcode Loader (Work in Progress). Contribute to icyguider/Shhhloader development by creating an account on GitHub.
👍3
Security Analysis | Code Audit |Quiz 1.png
365 KB
کارکرد کد بالا چیه
آسیب پذیر هست یا نه
اگر هست اسم آسیب پذیری چیه و اکسپلویتش چجوریه؟
کامنت کنید.
آسیب پذیر هست یا نه
اگر هست اسم آسیب پذیری چیه و اکسپلویتش چجوریه؟
کامنت کنید.
👍4🔥1
⭕️Securing AWS Lambda function URLs
Learn about the security risks of misconfigured Lambda function URLs and how to properly secure them.
https://www.wiz.io/blog/securing-aws-lambda-function-urls
#aws #cloud #security
@securation
Learn about the security risks of misconfigured Lambda function URLs and how to properly secure them.
https://www.wiz.io/blog/securing-aws-lambda-function-urls
#aws #cloud #security
@securation
wiz.io
Securing AWS Lambda function URLs | Wiz Blog
Learn about the security risks of misconfigured Lambda function URLs and how to properly secure them.
⭕️Combination of 2 PoCs for bypassing Credential Guard with in-memory invocation
PoC 1 (patch wdigest.dll):
https://gist.github.com/N4kedTurtle/8238f64d18932c7184faa2d0af2f1240
PoC 2 (find variable offsets in runtime):
https://github.com/itm4n/Pentest-Windows/blob/main/CredGuardBypassOffsets/poc.cpp
Merged:
https://gist.github.com/snovvcrash/43e976779efdd20df1596c6492198c99
#lsass #wdigest #credguard
@securation
PoC 1 (patch wdigest.dll):
https://gist.github.com/N4kedTurtle/8238f64d18932c7184faa2d0af2f1240
PoC 2 (find variable offsets in runtime):
https://github.com/itm4n/Pentest-Windows/blob/main/CredGuardBypassOffsets/poc.cpp
Merged:
https://gist.github.com/snovvcrash/43e976779efdd20df1596c6492198c99
#lsass #wdigest #credguard
@securation
👍2👎2
⭕️ Debugging and Reversing ALPC
https://csandker.io/2022/05/29/Debugging-And-Reversing-ALPC.html
#windows #internals
@securation
https://csandker.io/2022/05/29/Debugging-And-Reversing-ALPC.html
#windows #internals
@securation
👍1👎1
CVE-2022-22954-main.zip
3.5 KB
⭕️VMware Workspace ONE Access and Identity Manager RCE via SSTI.
exploit+payload+shodan
#vmware #cve
@securation
CVE-2022-22954 - PoC SSTI
*exploit+payload+shodan
#vmware #cve
@securation
⭕️
#shellcode #bypass #edr #av
@securation
New technique for shellcode injection to evade AVs and EDRs
https://github.com/Idov31/FunctionStomping#shellcode #bypass #edr #av
@securation
GitHub
GitHub - Idov31/FunctionStomping: Shellcode injection technique. Given as C++ header, standalone Rust program or library.
Shellcode injection technique. Given as C++ header, standalone Rust program or library. - Idov31/FunctionStomping