⭕️ Tool designed to dump and parse LSASS using a single file
https://github.com/icyguider/DumpNParse
#lsass #dump
@securation
https://github.com/icyguider/DumpNParse
#lsass #dump
@securation
GitHub
GitHub - icyguider/DumpNParse: A Combination LSASS Dumper and LSASS Parser. All Credit goes to @slyd0g and @cube0x0.
A Combination LSASS Dumper and LSASS Parser. All Credit goes to @slyd0g and @cube0x0. - icyguider/DumpNParse
⭕️ List privileged services that don't come with Windows 10
https://gist.github.com/wdormann/89ed779933fe205fb52ecf3eacf5ff40
#Red_Team #Powershell
@securation
https://gist.github.com/wdormann/89ed779933fe205fb52ecf3eacf5ff40
#Red_Team #Powershell
@securation
Gist
List privileged services that don't come with Windows 10
List privileged services that don't come with Windows 10 - privileged.ps1
⭕️ Reverse engineering and modifying Android apps with JADX & Frida
https://httptoolkit.tech/blog/android-reverse-engineering/
#reverse #re #android #jadx #frida
@securation
https://httptoolkit.tech/blog/android-reverse-engineering/
#reverse #re #android #jadx #frida
@securation
Httptoolkit
Reverse engineering & modifying Android apps with JADX & Frida
I get a lot of emails from users who want to know exactly what their favourite Android app is doing, and want to tweak and change how that works for...
⭕️ UAC Bypass using DLL Injection
https://github.com/shubham0d/UAC-bypass-using-dll-injection
#dll #uac #bypass
@securation
https://github.com/shubham0d/UAC-bypass-using-dll-injection
#dll #uac #bypass
@securation
GitHub
GitHub - shubham0d/UAC-bypass-using-dll-injection: A small project to bypass UAC in windows 10/8/7 using dll injection technique
A small project to bypass UAC in windows 10/8/7 using dll injection technique - shubham0d/UAC-bypass-using-dll-injection
⭕️ Investigates Abusing Windows Server Update Services (WSUS) to Enable NTLM Relaying Attacks
https://www.gosecure.net/blog/2021/11/22/gosecure-investigates-abusing-windows-server-update-services-wsus-to-enable-ntlm-relaying-attacks/
#wsus #windows #relay
@securation
https://www.gosecure.net/blog/2021/11/22/gosecure-investigates-abusing-windows-server-update-services-wsus-to-enable-ntlm-relaying-attacks/
#wsus #windows #relay
@securation
GoSecure
GoSecure Investigates Abusing Windows Server Update Services (WSUS) to Enable NTLM Relaying Attacks
WSUS client automatically authenticates with NTLM as the current user or the machine account, allowing relay for remote code execution or lateral movement.
⭕️ Security Testing and Enumeration of WebSockets
https://github.com/PalindromeLabs/STEWS
#websockets #web
@securation
https://github.com/PalindromeLabs/STEWS
#websockets #web
@securation
GitHub
GitHub - PalindromeLabs/STEWS: A Security Tool for Enumerating WebSockets
A Security Tool for Enumerating WebSockets. Contribute to PalindromeLabs/STEWS development by creating an account on GitHub.
⭕️ Wireless Penetration Testing Articles
https://github.com/Ignitetechnologies/Wireless-Penetration-Testing
#Wireless
@securation
https://github.com/Ignitetechnologies/Wireless-Penetration-Testing
#Wireless
@securation
⭕️ IDApython Scripts for Analyzing Golang Binaries
https://github.com/SentineLabs/AlphaGolang
#reverse #binaries #python #Go
@securation
https://github.com/SentineLabs/AlphaGolang
#reverse #binaries #python #Go
@securation
⭕️ A Glossary of Blind SSRF Chains
https://blog.assetnote.io/2021/01/13/blind-ssrf-chains/
#ssrf #blindssrf #tools #articles
@securation
https://blog.assetnote.io/2021/01/13/blind-ssrf-chains/
#ssrf #blindssrf #tools #articles
@securation
⭕️ هکرهای کره شمالی که قبلا توی شبکه های اجتماعی محققین امنیت سایبری رو مورد هدف قرار داده بودند و توسط گوگل شناسایی شدند , این دفعه به عنوان استخدام کننده ی سامسونگ ظاهر شدن و فایل PDF مخرب رو فرستادن واسه شرکت های امنیتی کره جنوبی و گفتن این فایل شرح وظایف شماست توی سامسونگ:))
⭕️ جالب تر اینه که دریافت کنندگان وقتی شکایت میکردن که چرا فایل pdf باز نمیشه ایمیل میزدن و هکرها درجواب توصیه میکردند به لینکی که Secure PDF Reader هست و میگفتن با این نرم افزار باز میشه.
آخر سر هم گوگل گفته این نرم افزار نسخه modified شده PDFTRON هست و بکدور داشته.
خلاصه که تکنیک های جالب مهندسی اجتماعی اینطوری جواب میده :)
https://therecord.media/north-korean-hackers-posed-as-samsung-recruiters-to-target-security-researchers/
#مهندسی_اجتماعی #فیشینگ #بدافزار
@securation
⭕️ جالب تر اینه که دریافت کنندگان وقتی شکایت میکردن که چرا فایل pdf باز نمیشه ایمیل میزدن و هکرها درجواب توصیه میکردند به لینکی که Secure PDF Reader هست و میگفتن با این نرم افزار باز میشه.
آخر سر هم گوگل گفته این نرم افزار نسخه modified شده PDFTRON هست و بکدور داشته.
خلاصه که تکنیک های جالب مهندسی اجتماعی اینطوری جواب میده :)
https://therecord.media/north-korean-hackers-posed-as-samsung-recruiters-to-target-security-researchers/
#مهندسی_اجتماعی #فیشینگ #بدافزار
@securation
Google
New campaign targeting security researchers
Details on an ongoing campaign, which we attribute to a government-backed entity based in North Korea, targeting security researchers working on vulnerability research and development.
⭕️ Hunting for buggy authentication/authorization services on github
https://xvnpw.github.io/posts/hunting_for_buggy_authentication_authorization_services_on_github/
#bugbounty
@securation
https://xvnpw.github.io/posts/hunting_for_buggy_authentication_authorization_services_on_github/
#bugbounty
@securation
This media is not supported in your browser
VIEW IN TELEGRAM
⭕️ Exploiting CVE-2021-43267
heap overflow vulnerability in the TIPC subsystem of the Linux kernel
https://haxx.in/posts/pwning-tipc/
#heap #kernel #linkux #binexp
@securation
heap overflow vulnerability in the TIPC subsystem of the Linux kernel
https://haxx.in/posts/pwning-tipc/
#heap #kernel #linkux #binexp
@securation
بچه هایی که توی باگ بانتی کار میکنید یاهو یه CTF برگزار کرده :)
https://www.yahooinc.com/paranoids/cyber-security-awareness-month-extravaganza-bug-bounty-ctf-public-009/
@securation
https://www.yahooinc.com/paranoids/cyber-security-awareness-month-extravaganza-bug-bounty-ctf-public-009/
@securation
Yahooinc
Cyber Security Awareness Month Extravaganza! Bug Bounty CTF (Public-009) | Paranoids | Yahoo Inc.
In an effort to celebrate National Cybersecurity Awareness Month, the Paranoids are launching a capture the flag-style bug bounty promotion aimed at offensively testing a number of specified Yahoo accounts.
Smishing Android Botnets Going Viral in Iran
https://research.checkpoint.com/2021/smishing-botnets-going-viral-in-iran/
https://research.checkpoint.com/2021/smishing-botnets-going-viral-in-iran/
Check Point Research
Smishing Botnets Going Viral in Iran - Check Point Research
Research by: Shmuel Cohen Introduction In the last few months, multiple Iranian media and social networks have published warnings about ongoing SMS phishing campaigns impersonating Iranian government services. The story is as old as time: victims click on…
Fuzzing Microsoft's RDP Client using Virtual Channels: Overview & Methodology
https://thalium.github.io/blog/posts/fuzzing-microsoft-rdp-client-using-virtual-channels/
https://thalium.github.io/blog/posts/fuzzing-microsoft-rdp-client-using-virtual-channels/
⭕️ هشدار استفاده از KMSpico برای فعال سازی ویندوز.
روشی که برای این مورد بکار برده شده باید برای فعالسازی آنتی ویروس را غیرفعال کنید تا نرم افزار کرک فعال شود، اما به محض غیرفعال سازی آنتی ویروس، نرم افزار شروع به سرقت ولت رمزارز و کارت های اعتباری و پسورد و مواردی که در سیستم ذخیره شدند میکنه.
https://thehackernews.com/2021/12/malicious-kmspico-windows-activator.html
#windozd #kms #activation
@securation
روشی که برای این مورد بکار برده شده باید برای فعالسازی آنتی ویروس را غیرفعال کنید تا نرم افزار کرک فعال شود، اما به محض غیرفعال سازی آنتی ویروس، نرم افزار شروع به سرقت ولت رمزارز و کارت های اعتباری و پسورد و مواردی که در سیستم ذخیره شدند میکنه.
https://thehackernews.com/2021/12/malicious-kmspico-windows-activator.html
#windozd #kms #activation
@securation