New web interface for pypykatz: parse LSASS or registry creds fully offline in your browser - no uploads. Built on top of the excellent work by skelsec and the pypykatz_wasm project.
Try it out: https://t.co/7d7u59qro3
CVE-2021-37794: After investigating FileBrowser, the Checkmarx Security Research Team found a stored Cross-Site Scripting #vulnerability. This vuln allows an attacker to achieve #RCE on the running FileBrowser instance.
Details 👉 https://t.co/ndepwz3bBM
#OpenSource
CVE-2021-37794: After investigating FileBrowser, the Checkmarx Security Research Team found a stored Cross-Site Scripting #vulnerability. This vuln allows an attacker to achieve #RCE on the running FileBrowser instance.
Details 👉 https://t.co/ndepwz3bBM
#OpenSource
https://t.co/PuXg7W1dJU
Check out my our new blog about some vulnerabilities that we found in RaspAP (CVE-2021-33356, CVE-2021-33357, and CVE-2021-33358) including Remote Code Execution and Privilege Escalation!
I just released gowitness 2.3.6 which contains a security & hardening fix. @OmriInbar reported that the report and screenshot servers would let you read files on the host filesystem via screenshots. Thanks!
Check the release notes for more info: https://t.co/2tnlTBPf87
CVE-2021-31800 Multiple path traversal vulnerabilities exist in https://t.co/pQgp4wwSfP in Impacket through 0.9.22. An attacker that connects to a running smbserver instance can list and write to arbitrary files via ../ directory traversal. This could p... https://t.co/az5aQykqal
Exploiting CVE 2019-1388 without hhupd.exe :)
(create cert and exe on the attacker machine, move exe to victim and commence shenanigans)
@Shachar_Korot
@gentilkiwi It's funny to see the CVE being referred to as the "hhupd.exe Exploit". If you don't care about your exe being signed then you can create your own exe that will work perfectly. you just need the added step of installing the certificate at the Trusted Root store:
@Shachar_korot
@gentilkiwi It's funny to see the CVE being referred to as the "hhupd.exe Exploit". If you don't care about your exe being signed then you can create your own exe that will work perfectly. you just need the added step of installing the certificate at the Trusted Root store:
@Shachar_korot
@MrUn1k0d3r Love it!!!
because VSS service is move common than XblAuthManager, I found that it works on more operating systems:
SCShell.exe target VSS "C:\windows\system32\cmd.exe /c echo wabalabadubdub > C:\a.txt" user domain password
tested on Windows XP, 2003, 7, 2008, 2012 and 10 :)