@michkostrzynski U nas w kraju jest tylko jedna religia i jak im się nie podoba to mogą wrócić do siebie. Jakos w krajach muzułmańskich my Polacy musimy przestrzegać ich zasad ale oni u nas już nie? Koniec z budowaniem meczetów i zbiórkami lub sponsoring muzułmanów w Polsce.
☀️ We're expecting some hot weather today! 😎
Please carry a bottle of water with you during the warm weather.
If you feel unwell, stay on the platform where colleagues can help you more easily.
Chinese LLMs can hack better than state-sponsored hackers with properly evolved harness -
Kimi K2.5 managed to find and exploit 6 vulnerabilities in browsers: a single page view or an extension install by victims equal full system hijack.
Check https://t.co/d0SZSf1KqF
Another COM object for RedSun can be used to execute commands through arbitrary file write.
Most COM objects that have executables as servers run as the interactive user.
This means that if another COM object is used in RedSun, the shell you get will run as the low-privilege user who starts the exploit.
The Storage Tiers Management Engine COM server is used in RedSun. As far as I found, it is the only COM object that runs as SYSTEM. Using it is very clever, but I think most SOCs already use it as IOC.
However, I found another COM object that can be used with RedSun. It does not give SYSTEM, but it gives LOCAL SERVICE. From there, you can move to SYSTEM by abusing SeImpersonatePrivilege.
The COM CLSID is: d54378cd-91d8-4e10-a00b-819f9a9efcb1, and the executable name is printfilterpipelinesvc.exe.
But it needs some tricks to make it work.
I will try to write a blog post soon when I will be free with all the details. For now, just keep this in mind.