🚀 Session Switcher for @Burp_Suite makes manual auth testing faster - easily save & swap cookies/headers
Quickly test IDORs & authZ issues, plus session auto-update rules that track live browser sessions
From #Doyensec's @lokiuox 👇
https://t.co/1dTfHkAHh8
#security#appsec
🚨 Details on a serious #vulnerability from our @MaitaiThe's research. An information disclosure in error messages allows a remote attacker to identify security tokens/credentials when #squid is used. Perfect for SSRF!🚨
#doyensec#appsec#security
https://t.co/Bm0JTqv9rS
In our final ksmbd research post, @73696e65 provides a detailed walkthrough for exploiting a local privilege escalation vulnerability. If you're interested in learning more about exploitation on modern systems - check it out!
https://t.co/RPMvj0grOS
#doyensec#appsec#security
📢 Upset about losing CVE data? Our @MaitaiThe & @lokiuox dropped new 🔥 critical #ComfyUI vulnerabilities, including this RCE, to cheer you up 😉. These are published as part of our coordinated disclosure process.
https://t.co/veILS82IZR
#doyensec#appsec#security
Ahoy! 🦜 Our first "!exploitable" post provides a technical dive 🤿 into the sea 🌊 of IoT exploitation. Read it today to learn how our team 🏴☠️ developed an exploit while floating in the Mediterranean!
https://t.co/NUKP8e9j1C
#doyensec#appsec#security#iot#exploits
🎉Announcing the latest research from our intern @maikypedia! In it, you'll learn all about Decompression Attacks, get to practice in custom-built labs and get some free @semgrep rules for detecting flaws. Check it out today!
https://t.co/we46rcyptw
#appsec#doyensec#semgrep
@21lettere@Pinperepette@signorina37H Io lo uso per un utilizzo "casalingo" e mi ci trovo bene, la cosa migliore imho è la facilità con cui installi, aggiungi nodi e gestisci tutto dal pannello web. Poi lo uso praticamente solo per SSH e SMB quindi non mi preoccupo che il mio traffico venga sniffato
@21lettere@Pinperepette@signorina37H Teoricamente la chiave privata dovrebbe essere generata localmente e rimanere lì, mentre la chiave pubblica viene distribuita agli altri nodi, quindi Tailscale (inteso come azienda) non ha modo di decriptare il traffico. Il client dovrebbe essere anche open source (cont.)
Thrilled to release my latest research on Apache HTTP Server, revealing several architectural issues! https://t.co/7ygwWXY0pd
Highlights include:
⚡ Escaping from DocumentRoot to System Root
⚡ Bypassing built-in ACL/Auth with just a '?'
⚡ Turning XSS into RCE with legacy code from 1996
Just posted! Check out our @viktorot's presentation on DB race conditions from @owasp's Global AppSec. Our latest post gives all the details, slides and a playground to test your skills at finding these issues!
https://t.co/DaZLAoFqfK
#doyensec#appsec#owasp#security
CSRF in modern web apps? It's still possible! Our latest research by @maxenceschmitt dives into using Client-Side Path Traversal to perform CSRF. Check out our latest blogpost and brand new #Burp extension for finding bugs.
#doyensec#appsec#CSPT2CSRF
https://t.co/9XUicACBRI
Has reliance on SSO left orgs with a single point of exploitation? Our latest research by @lacerenza_fra explores various IdP compromise scenarios as well as how to harden and detect attacks in @goteleport installations.
#doyensec#teleport#security
https://t.co/e7KmVUDIIN
@EricaZelic@jeffmcjunkin@garrfoster@Evil_Mog Indeed, this wasn't directly an answer to your question, I just wanted to share this method as an alternative to cracking NTLMv1 as I found it wasn't very well documented in ntlmrelayx the last time I needed it. Sorry for the confusion!
@jeffmcjunkin@EricaZelic@garrfoster@Evil_Mog You have to use --remove-mic with ntlmrelayx. The help text says that it's for exploiting a CVE, but in reality it also works when NTLMv1 is allowed.
@jeffmcjunkin@EricaZelic@garrfoster@Evil_Mog Since https://t.co/ICodqIgxy8 is offline now, a better way (if you don't have a lot of GPUs) would be to use ntlmrelayx and relay auth to LDAP to set RBCD or shadowcreds on the DC. Then request a ticket to use with secretsdump/psexec
PoIEx, a new #Doyensec tool, identifies "Points of Intersection" where code & IaC definitions meet. Visualize & explore IaC, plus create & share real-time notes w/ teammates in VS Code. Try it out today‼️
https://t.co/Z0ekdlATFQ
https://t.co/rBqOlBUEjU
#CloudSecurity#appsec