He creado la comunidad "Яeverse ESP"
Si te mola la seguridad a bajo nivel, el reversing, el exploiting o simplemente tienes curiosidad por saber cómo funcionan las cosas desde cero, ¡únete!
[https://t.co/MHDPDuSNjB] [https://t.co/8KpAgxFqBa]
NetExec has a new Module: Timeroast🔥
In AD environments, the DC hashes NTP responses with the computer account NT hash. That means that you can request and brute force all computer accounts in a domain from an UNAUTHENTICATED perspective!
Implemented by @Disgame_
1/3🧵
Esta es la parte 2 y final de la solucion del ejercicio PARE DE SUFRIR https://t.co/uEHmDJGtJU password a https://t.co/T1tHWwZsuO en un rato estara en HD
@_Kudaes_, operador del Red Team de @BlackArrowSec, ha iniciado su panel sobre call stack spoofing en @NavajaNegra_AB y va mostrar cómo los desarrolladores de malware evitan que un EDR detecte la ejecución de implantes desde memoria.
@CyberSecMonth, #CyberSecMonth
¿Cansado/a de usar Word para los informes?
Tranquilo/a, en este vídeo te enseño a instalar SYSREPTOR, un potente editor de reportes/informes para ciberseguridad, pentesting y otras ramas.
#infosec#Ciberseguridad
https://t.co/y000IGRHcp
September giveaway! I am giving away 1 seat each for @AlteredSecurity on-demand CRTP and AD CS courses. Please Reply, Repost and Like this post to participate.
I will announce 1 random winner for each on 30th September.
https://t.co/LP2i5SMg0v
Make sure to reply with which one would you like to win.
#RedTeam #Pentesting #Giveaway
(1) Decided to release the source code for my LLVM-based static binary analysis framework (https://t.co/xEgouoAkWS). It implements, among other things, an iterative control flow graph reconstruction algorithm heavily inspired by SATURN, using Remill and Souper.
With all the linux RCE drama, it's a good time to bring up a neat scoring system that you (may) not have heard of.
EPSS is the cool younger brother of CVSS.
Patching just 3.5% of all known vulnerabilities covers 67.8% of what is exploited in the wild.
Assuming you don't have infinite resources, it theoretically lets you focus on the CVEs that are more actionable.
¡𝐑𝐞𝐯𝐞𝐫𝐬𝐢𝐧𝐠 𝐚 𝐮𝐧𝐚 𝐟𝐮𝐧𝐜𝐢𝐨́𝐧 𝐞𝐧 𝐞𝐧𝐬𝐚𝐦𝐛𝐥𝐚𝐝𝐨𝐫!
Nuevo artículo en Deep Hacking, en este caso @b1n4ri0 nos enseña un ejemplo de ingeniería inversa a una función en ensamblador x86. Los temas tratados son los siguientes:
- Enunciado del ejercicio
- Método de trabajo
- Comprensión del entorno
- Ejemplo de traducción
- Análisis Estático
- SCAS/SCASB
- REPNE
- Segunda parte de la función
- STOS/STOSB
- REP
- Resumen de la teoría
- Pseudocódigo en C
- Análisis Dinámico
- Debugging con GDB
- Resumen del depurado
- Solución
𝐄𝐧𝐣𝐨𝐲 𝐢𝐭 && 𝐇𝐚𝐩𝐩𝐲 𝐇𝐚𝐜𝐤𝐢𝐧𝐠!
https://t.co/ehEfAt2wWs
𝐀𝐭𝐚𝐪𝐮𝐞𝐬 𝐚 𝐑𝐞𝐝𝐞𝐬 𝐖𝐏𝐀 𝐄𝐧𝐭𝐞𝐫𝐩𝐫𝐢𝐬𝐞 – 𝐅𝐚𝐤𝐞/𝐑𝐨𝐠𝐮𝐞 𝐀𝐏 𝐮𝐬𝐚𝐧𝐝𝐨 𝐡𝐨𝐬𝐭𝐚𝐩𝐝-𝐰𝐩𝐞
En este artículo, exploramos cómo se puede vulnerar una red WPA-Enterprise mediante el uso de un punto de acceso falso (Fake AP/Rogue AP). Con herramientas como hostapd-wpe, es posible capturar las credenciales de los usuarios conectados a la red, mostrándote el proceso detallado paso a paso.
https://t.co/Ef6EymBRzX
Tip: Utiliza certificados en lugar de contraseñas para mayor seguridad en redes WPA-Enterprise
Hyperthreading is Dead.
Major CPU manufacturers (including Intel) are getting ready to abandon SMT hyperthreading completely.
It's not as crazy as you think. In fact, Apple, Qualcomm, and Samsung have *never* used Hyperthreading.
But why?
🧵
¡𝐈𝐧𝐭𝐫𝐨𝐝𝐮𝐜𝐜𝐢𝐨́𝐧 𝐚 𝐥𝐚 𝐭𝐞𝐜𝐧𝐨𝐥𝐨𝐠𝐢́𝐚 𝐑𝐅𝐈𝐃!
Nuevo artículo en Deep Hacking, hoy vamos a ver una introducción a la tecnología RFID de la mano de @T0N1sm
Vamos a ver los distintos tipos de frecuencia, ejemplos, como identificarlas, que factores pueden afectar al alcance...
Además, veremos como detectar el tipo de frecuencia en un enfoque de caja negra.
https://t.co/pglhiDfzaS
𝐄𝐧𝐣𝐨𝐲 𝐢𝐭 && 𝐇𝐚𝐩𝐩𝐲 𝐇𝐚𝐜𝐤𝐢𝐧𝐠!
¡𝐃𝐞𝐞𝐩 𝐇𝐚𝐜𝐤𝐢𝐧𝐠 𝐡𝐚 𝐜𝐨𝐧𝐬𝐞𝐠𝐮𝐢𝐝𝐨 𝐮𝐧𝐚 𝐜𝐨𝐥𝐚𝐛𝐨𝐫𝐚𝐜𝐢𝐨́𝐧 𝐬𝐮́𝐩𝐞𝐫 𝐞𝐬𝐩𝐞𝐜𝐢𝐚𝐥! 🔥
Aunque lo revelaremos en el blog en unas semanas, los suscriptores de nuestra newsletter tendrán acceso exclusivo a un 10% de descuento este mismo viernes.
📩 Suscríbete gratis y no te pierdas esta oportunidad 👇
👉 https://t.co/gjW7APgQEP