I'm releasing with @decoder_it: Juicy Potato, another Local Privilege Escalation tool from a Windows Service Accounts to SYSTEM by abusing the golden privileges (https://t.co/whGg5G3FBp)
During @offensive_con our @marver presented his research on security aspects of embedded SIM cards.
We are releasing SMShell, an SMS based implant proof of concept for Red Teaming that can evade out of band.
Blogpost: https://t.co/3i4SieWUEm
GitHub: https://t.co/71QbSKwxYZ
This is some spectacular counterintelligence work and exploitation.
Research to discover a vulnerability, and then careful exploitation of that vulnerability so it never gets burned.
Tennis 0day
RemotePotato0 Update:
We can confirm that cross session activation works in the relay scenario too so you can get rid of session 0 limitation! Now the real fun will ensue 😈
cc @decoder_it
When (NTLM) relaying potatoes lead you to domain admin...
A "permanent" 0day Privilege Escalation Vulnerability in Windows RPC Protocol ;-)
cc @splinter_code
Our writeup here:
https://t.co/oIE5MFtpeb
a tenacious kernel panic, happening in macOS network stack when bettercap tries to inject packets in the interface in monitor mode (read only works) ... happening on M1 as well ... can somebody at Apple fix this please? https://t.co/kMtnr69Wo1
Following my "old" blog post https://t.co/hSHriiQhAI , I have published the very quick & dirty "juicy_2" code https://t.co/ycYI1s9eSp , maybe useful when you have impersonation privs on newer versions of Windows 10 & Server 2019 cc @splinter_code@Giutro
MuraenaTeam strikes again.
Together with @Giutro we released the new Muraena and NecroBrowser. Lots of new code+features.
Phishing and post-phishing automation at scale for all your needs. Office365 and GitHub examples added. More coming soon 🎣🪝😎
https://t.co/125mrRrYcy
It has a few more prerequisites, but I finally managed to get a #Zerologon exploit working that doesn't rely on resetting passwords to exploit. Use the printerbug to make DC1 connect to you, then with lots of magic relay that to DC2 directly to DRSUAPI to DCSync 😁