Sys-Admin Up – Telegram
Sys-Admin Up
1.06K subscribers
132 photos
4 videos
127 files
2.23K links
InfoSec, Hacks, Perks, Tools, IT/IS Courses, CVE… Contains part of the news that was not included in the Sys-Admin & InfoSec Channel (@sysadm_in_channel)
Download Telegram
Concealed code execution: Techniques and detection

The techniques for concealing code execution became the favorite tool in Advanced Persistent Threat actor's arsenal because of the remarkable stealth benefits they can provide against conventional security mechanisms. Understanding how these techniques operate under the hood and having access to open-source proof-of-concept implementations that reproduce the corresponding behavior greatly helps with detection engineering and aids in incident response investigations

https://www.huntandhackett.com/blog/concealed-code-execution-techniques-and-detection
how SSO works
Windows Secret Extraction Summary

As such, the following type of secrets can be retrieved:
— Secrets in LSASS process.
— Secrets in registry such as LSA secrets.
— DPAPI secrets.

This article will describe each of them..:
https://www.synacktiv.com/publications/windows-secrets-extraction-a-summary
PhoneSploit Pro

PhoneSploit with Metasploit Integration

https://github.com/AzeemIdrisi/PhoneSploit-Pro
Forwarded from Sys-Admin InfoSec
Как растет и кто помогает расти OpenBLD.net (Q2 2023)
 
В экосистеме OpenBLD произошел эволюционный всплеск, теперь это:
— Anycast/GeoDNS, DNSSEC, DNS-over-HTTPS, DNS-over-TLS, DNS

Благодаря этому появились два новых сервиса - Adaptive (ADA), Strict (RIC) которые заменят A-BLD, BLD (в чем отличие)

Настало время тестирования, я тестирую уже более двух недель и это пушка, кто использует OpenBLD пробуй заменить:

🔸 DoH: https://a-bld.sys-adm.in/dns-query на https://ada.openbld.net/dns-query
🔸 DoT: a-bld.sys-adm.in на ada.openbld.net

🔹 DoH: https://bld.sys-adm.in/dns-query на https://ric.openbld.net/dns-query
🔹 DoT: bld.sys-adm.in на ric.openbld.net

В течении недели, мб двух A-BLD будет полностью смерджен с ADA и перестанет существовать как таковой. Один сервер (109.234.39.72) будет заменен другим (46.151.29.15) более шустрым. Начинай тестирование уже сейчас.

Этого не было бы без поддержки. В этом году OpenBLD проект поддержали:
— Сервисно: ClouDNS, Gcore, JetBrains, UptimeRobot
— Информационо: AST Cyber Lab, Core24/7, qCloudy
— Отдельное спасибо Казахстанским хостерам: Unihost.kz, GOhost.kz 🤜️️️️️️🤛️️️️️️

Ты тоже можешь сделать свой вклад в открытый сервис по фильтрации вредоносного контента, пиши @sysadminkz

Всем Peace ✌️
Sys-Admin Up pinned «Как растет и кто помогает расти OpenBLD.net (Q2 2023)   В экосистеме OpenBLD произошел эволюционный всплеск, теперь это: — Anycast/GeoDNS, DNSSEC, DNS-over-HTTPS, DNS-over-TLS, DNS Благодаря этому появились два новых сервиса - Adaptive (ADA), Strict (RIC)…»
This media is not supported in your browser
VIEW IN TELEGRAM
What is ARP Spoofing

ARP spoofing is a type of attack in which a malicious actor sends falsified ARP (Address Resolution Protocol) messages over a local area network. This results in the linking of an attacker’s MAC address with the IP address of a legitimate computer or server on the network.
Forwarded from Sys-Admin InfoSec
OpenBLD DNS prevented new malicious campaign that spreads through of Google Ads
 
Today I discovered a new malicious company that spreads through of Google Ads side...

In short - "Sponsored" link redirects to malicious site, and boom 💥 I felt "OpenBLD" effect!

OpenBLD.net DNS blocked for me browser-hijacking app which was distributing with Google Ads... Wow 💣, very unexpected and nice as I usually try to be more careful when surfing the internet.

Be safe with free and OpenBLD.net DNS 🤜🤛️️️️️️

• Look about of free and OpenBLD DNS service on project site - lab.sys-adm.in
• Страница проекта на русском - https://lab.sys-adm.in/ru

P.S. What is xg4ken and how to removal
Sys-Admin Up pinned «OpenBLD DNS prevented new malicious campaign that spreads through of Google Ads   Today I discovered a new malicious company that spreads through of Google Ads side... In short - "Sponsored" link redirects to malicious site, and boom 💥 I felt "OpenBLD" effect!…»
Fingerprint-Authentication-Brute-force_Attack.pdf
3.4 MB
Expose Smartphone Fingerprint Authentication to Brute-force Attack