Upgopher finally has a proper home.
One binary. Your files. Any browser.
Share files, folders, text and screenshots between devices, without a database, external runtime or config file.
Website and docs are now live:
https://t.co/usVO8CJxr9
🐚 wp2shell RCE now needs no cracking. thanks @rez0__ for the nudge.
forge a fake WP_Post (route confusion) → it runs a customize_changeset as an existing admin → POST /wp/v2/users makes a new admin → log in → shell.
I know I haven't been very active lately, but I bring you something worth checking out. 👀
The new version of upgopher is out. It is a simple Go file-sharing server, and now it supports uploading entire folders and much better directory navigation.
👇
#go#webserver#upgopher
Upgopher ha sido añadido oficialmente al repositorio de Proxmox VE Helper-Scripts.
Ahora podéis desplegar este servidor de archivos en #Go como un contenedor LXC de forma totalmente automatizada. Lo encontraréis en la categoría Files & Downloads
https://t.co/SSg33vPxTJ
#proxmox
🚆⚽ La lucha antipiratería de LaLiga se cobra una víctima inesperada: la app Transporta’m, usada por +50.000 usuarios para seguir incidencias de Rodalies, queda bloqueada cada fin de semana.
Neutralidad de la red en jaque, con impacto directo en servicios públicos.
🔗 https://t.co/BVbQTEZPgi
#RootedCON #laligagate
Windows 10 offline admin creation? 😈
Why not?!
Everything happens through built-in offlinelsa and offlinesam DLLs. Official, but not very documented.
Enjoy the source code and the compiled exe, as usual: https://t.co/BNp9kaLnkr
NetExec v1.4.0 has been released! 🎉
There is a HUGE number of new features and improvements, including:
- backup_operator: Automatic priv esc for backup operators
- Certificate authentication
- NFS escape to root file system
And much more!
Full rundown:
https://t.co/yjaG8rgzSZ
In the last weeks I had some more time for research as usual. Multiple novel Lateral Movement techniques with PoC's, one alternative for credential theft and now a novel AMSI bypass 😂 What the heck. Some good material for future talks 😎
BleSpammer. Así hemos bautizado la nueva PoC que permite saturar las pantallas de móviles, tablets u ordenadores generando infinidad de popups como los que aparecen cuando quieres emparejar unos cascos inalámbricos.
Tenéis toda la info en GitHub 👇
https://t.co/VQGAQUHD4N
You can relay a user to LDAP that has GenericWrite on a valuable object but you can't use ShadowCredentials? Fear no more! You can now use "gain_fullcontrol"in ntlmrelayx ldapshell to give your account control over that object.
Happy New Year! Wishing everyone a 2025 filled with (ethically reported) vulnerabilities! 🎉
We’re moving HackTricks and HackTricks Cloud to a new domain (https://t.co/895SVs1XEh and https://t.co/qw0KPfRhSy) where we can fully manage SEO.
#hacktricks#hacking
🚀 WiFiChallenge Lab v2.1 is here!
🔥 What's New?
- ARM Support: Docker compatibility for ARM platforms.
- Major Docker Enhancements & Bug Fixes.
- Airgeddon Integrated: Full dependencies included.
- Upgraded hostapd-wpe, Aircrack-ng, hcxtools, and more!
https://t.co/k2CYVSVx2f