@thsottiaux tl;dr version:
- set up CLIProxyAPI with Claude and Codex auth
- Connect to Claude Code
- Make "claudex" alias that sets some env vars
Took like 2 prompts (I already had the proxy set up tbf)
It looks like the <selectedcontent> vector can solve this impossible lab listed in https://t.co/PVFdF7de0W:
"innerHTML assignment where you can't use ="
PoC:
https://t.co/ILP19EPZI7
Offensive PowerShell for Red Teamer with Defense Evasion Techniques
TLDR; Blog covers fileless malware, social engineering initial access, Active Directory post exploit, credential dumping, log evasion, and basic defense evasion.
Blog:- https://t.co/Q0Acw3lgrf
A blog by: @screetsec
GPOHound v1.1.0 is out! 🎉
This release adds the "sysvol", "ldap", and "parse" modules, along with several bug fixes and improvements.
For more details: https://t.co/BbLSzdinWG
Rumour mill going crazy on this new mistral model
- Napoleon class model with >10T params
- smokes Mythos on VoltaireBench
- for safety reasons only outputs French language code
Hackers can abuse PAM to log SSH credentials in plaintext by modifying authentication modules. Helpful for lateral movement. There are many ways of doing it, but it often comes down to changes in /etc/pam.d/ and /lib/security/
It's a good idea to monitor unauthorized changes in these directories
https://t.co/g6C7mjnR5W
@three_cube@_aircorridor
#dfir #pentesting
If you want to age your sys admins 30 years overnight, remember that Active Directory is fully unicode compatible, so you can rename your laptop with emojis it its hostname, and it will reflect like that in AD
ping desktop-🤷♂️👍👌.mycompany.local
Legba is now officially packaged and part of Kali Linux rolling! To celebrate, I'm releasing 1.3.0, with super fast SMB shares enumeration, a bunch of fixes, and a dedicated website for the documentation! 🎉