COM is old but gold—for attackers! 🚨 In our latest blog, Sylvain Heiniger (@sploutchy) exposes a privilege escalation vulnerability in the Google Chrome updater. Want to know how cross-session EoP still happens today? Check it out! #COM
https://t.co/zu6vphlXG0
There we go!
Was a fun challenge :) @offsectraining
thx again everyone for keeping my imposter syndrome under control.
Especially @Pzz02@xct_de@k0zmer and the entire @vulnlab_eu community. I’d be dogshit without you guys! <3
WoWMIPS - A MIPS R4000 emulator which allows legacy Windows NT MIPS binaries to run on modern x86/64 Windows.
A short series of articles describes the development of this emulator:
https://t.co/D4gd0wks5t
My latest blog post diving into the world of Windows AD Cert Publishers group is out 🌐✨ Insights with a little bit of silver++ juice :-) https://t.co/JTGPAr3osc
A new Red Team Lab, Shiva, is coming to Vulnlab next week! This time you get to test a hardened Hybrid-AD environment that involves:
- Hybrid-AD with 10+ machines & active users
- Cloud exploitation
- SIEM, EDR on Clients & Servers
- Common enterprise software
- No CVEs
📢 Just published a detailed writeup on a fascinating "Smart-Bank" CTF challenge! 🏦💻 Dived deep into vulnerabilities from Nginx misconfigurations to NestJS oversights. A real treasure for PTs and CTF enthusiasts! 🚀 🔗 https://t.co/GPRTCwUmrf
@pwnx_official@nohatcon
Perfect DLL Hijacking: It's now possible with the latest in security research. Building on previous insights from @NetSPI, we reverse engineer the Windows library loader to disable the infamous Loader Lock and achieve ShellExecute straight from DllMain. 🔍 Link in bio 🔗
We just released Reflective Call Stack Detections and Evasions! This was co-authored by our @XForce Red intern Dylan Tran @d_tranman! Dylan is wicked smart and it was fun working with him! Check it out!🥷
https://t.co/0XxHZ1snlw
New blog post is up which looks at an unpatched vulnerability in macOS which allows us to hijack entitlements from signed binaries.. aka.. DirtyNIB. https://t.co/B3M6kyssKa
For those of you who are finding #SharePoint Pre-Auth #RCE ( #CVE-2023-29357 + CVE-2023–24955 ) too technical to understand, here's a simplified version.
🧵(0/n)
Push is a chain playable @vulnlab_eu made by myself and @xct_de, which focuses on initial access & exploiting common enterprise software.
Walkthrough available here:
https://t.co/ajxur5g0tc