I spent some time exploring browser cache smuggling, where visiting a webpage can lead to malware delivery.
Surprisingly, it is possible to execute Chrome’s original cache file without renaming it, while also achieving persistence.
More details below:
https://t.co/rFrcKyuh31
There’s nothing like sitting down, opening your laptop, ready to get work done. You put on your headphones, turn them up loud, hit play on Spotify and Dinosaur Stomp starts blaring at you 😑 clearly this is my life now
@EricaZelic@merill@dnsinit@maester365 While you could get some of the results there, I am trying to ensure the project maps to CIS explicitly. IE the checks are performed in the exact intention they are described, even if there is a “better” way. This is important imo to ensure continuity when reviewing against CIS
@EricaZelic The short version is because I started them and haven’t finished yet. The unfinished ones are under way, I aim to have the remaining ones done by mid Jan
🛑 5 Common Windows Settings That Leave Your Organisation Vulnerable 🛑
Apart from ADCS HTTP Enrollment, they are all default settings. That’s probably why we keep seeing similar setup 😬
@murmanz@janbakker_ Imo you are starting to over complicate it, and deviating from Microsoft’s recommendations. The new recommendation is to MFA all B/G accounts. Tailoring them to a user sounds fancy, but in an emergency all of that is going to slow you down.
It was a wild ride but my DEF CON 32 adventure is over 😭 Spent an amazing few days at Cloud Village learning new tools, tricks and seeing what others have been researching. Thank you to the speakers and Cloud Village for organising such an amazing set of talks for #defcon32
Chinese Backdoor Alert! Security enhancements on Mifare Classic cards used in hotels/business contain a supply chain backdoor making reading & exploitation trivial. Great paper by Philippe Teuwen Quarkslab https://t.co/lTVOVoULFF Watch your Chinese supply chains carefully folks!
It’s been a busy week but we made it. After a hop skip and a jump I’ll be at DEF CON 32! Look forward to seeing old hacker friends, and meeting some new ones #DEFCON#defcon32