@Decode141 and I will be sharing ideas for engaging in cyber deception in Active Directory at BlackHat USA next Thursday between 11:25 and 12:35 PST in the Business Hall - Arsenal Station 5.
If you are around, please visit us in-person or virtually using a free on-demand business pass.
For more information, please visit https://t.co/WwyU2wDR9W
1) We are finally propagating MotW to Virtual Disk containers! For example, when you download and mount an ISO from the Internet, applications that query the zone of files inside of that ISO will receive the zone of the ISO itself. 3/7
Microsoft fixed my Kerberos PAC verification bypass issue this month in HTTP.sys which me and Nick presented at Blackhat. Sadly no more details for 30 days, but it might be easy to work out how to do it :) https://t.co/GkFHGW0hOw
Google completed its acquisition of Mandiant today. We’re excited to get started on our shared mission to create a comprehensive and best-in-class cyber security solution for customers and partners. Read more here: https://t.co/JpkOHify14
44CON 2022 Talk announce : @sadreck "Codecepticon – Building an obfuscator to bypass Modern EDR and AV" here's a hint "no, this one isn’t a python script that runs “replace” a bunch of times." https://t.co/QMb3CbEwnQ #44CON
Excited to announce that I will be leading an on-demand session at #BlackhatUSA that’ll cover core #GraphQL concepts and how to exploit the most common #security issues. Join the session virtually from Aug 10. https://t.co/KDw6qGGLRQ #BHUSA
Starting our list of Saturday AM workshops, we have @Decode141 and @am0nsec teaching "Windows Defence Evasion and Fortification Primitives"
DC Forum link: https://t.co/VbEcSJRRG3
EventBrite link: https://t.co/FlbSfDISal
Excited to announce "Browser-Powered Desync Attacks: A New Frontier in HTTP Request Smuggling" is coming to @defcon! Can't wait to share it! Check out the abstract here #DEFCON30 https://t.co/x00uIhCVMw
@SteveSyfuhs@tiraniddo Any thoughts on if TGSs will be non-exportable in the future? Atm, the limit is at TGTs, but privileged attackers that steal an access token or use code injection into a victim user process can request arbitrary TGSs and export them?
@djcater@ajxchapman The contract should define IP ownership associated with vulnerabilities, their confidentiality and any credit for vendor products. In case of bug bounties, clients that enforce this may suffer from unreported vulnerabilities entirely if the crowdsourced reward is more.
@tiraniddo Nice one. For pen testers, Kekeo exported “service/target.FQDN” TGSs can be reliable used for lateral movement. CIFS particularly has worked for me with even native sc.