WinFlesher — Automated attack surface assessment framework for Active Directory and local infrastructures, correlating vulnerabilities with attack... https://t.co/IggtorspOK
Like PingCastle went out for drinks with Bloodhound, and they actually decided to get some work done. 🍷
WinFlesher 2.0 automates vulnerability discovery and critical path correlation within Active Directory and local infrastructures.
https://t.co/Iqh6npUwLz
Invoke-WinFlesher is a post exploitation framework for windows, written in powershell.
It was created by adapting the exploitation techniques to MITRE and it was meant to be modular.
https://t.co/Iqh6npCVmZ
I just disclosed two insecure folder permissions vulnerabilities on two open source software applications:
https://t.co/DxaySoLnYc
https://t.co/ShLgH9EnOv
CVE-2021-37363
CVE-2021-37364
I also published two proofs of concepts which you can find on exploit-db.
CVE-2021-37364 : OpenClinic GA 5.194.18 is affected by Insecure Permissions. By default the Authenticated Users group has the modify permission to openclinic folders/files. A low privilege account is able to rename mysqld.exe or tomcat8.... https://t.co/ndBsXfUBdM
Mindsflee had this to share about his VM, Synapse: "Enumeration definition is the act or process of making or stating a list of things one after another. Don't underestimate the basics."
Submit your VM, and get compensated if it meets our criteria: https://t.co/0z1c2HBOvy
La live della settimana scorsa è saltata causa problemi tecnici, ma da questa settimana riprenderemo con una intervista molto interessante @mindsflee
STAY TUNED
#pentestingmadesimple