Thanks to @cube0x0 works (& the damned RpcBindingSetObject function on Windows🤬), a new #mimikatz 🥝release using MS-PAR protocol instead of MS-RPRN
Now, #printnightmare / CVE-2021-34527 *everywhere*, not only domain controller: servers & workstations
> https://t.co/Wzb5GAfWfd
▶ Microsoft #ADCS - Abusing #PKI in Active Directory environment ◀
I've been bragging about it for months, this is the result of many weeks of work on lesser known compromise paths for #pentest by using enterprise PKI.
Feedback is highly appreciated!
https://t.co/sbqCZhBYiG
CVE-2020-14871 had been exploited and distributed in the wild to numerous groups since at least October 6th 2014. That's 6 years that this vulnerability was available as 0day to multiple non-exclusive parties, VBI leak in HT emails shows it's the same bug. https://t.co/Prh3tm3DHN
Dirty libssh2 PoC for CVE-2020-14871 to core target and pack with your favorite shellcode & return addresses, something for the kidz on lockdown. Happy Hacking. https://t.co/7dqSGjOXqw
Excited to announce my new book series: "The Art Of Mac Malware" https://t.co/jgTOCd34DU 📚
🆓 100% free online
📝 Peer-reviewed & open for comments
When published, proceeds will support our #OBTS conference & charity efforts 😍 #SharingIsCaring
'Removing Kernel Callbacks Using Signed Drivers' - I just released a write-up and tool to blind all EDRs on a system. Many thanks to @matterpreter@gentilkiwi@Jackson_T@SpecterOps@FuzzySec for previous excellent work. Writeup at https://t.co/Sij8hfKLiw
Want to see what EDR sensors see when you practice attacks and develop bypasses, without tipping off defenders?
I'm starting a new series on reversing and evading EDRs, with a paper on how to divert telemetry to private infrastructure. Check it out!
https://t.co/i7zy1xbNPh
I have released my exploit for CVE-2020-3153 - Cisco AnyConnect privilege escalation through path traversal https://t.co/1xSxJUjhuJ
My notes on this vuln: https://t.co/reO88J9Bny
Kudos to @yorickkoster for the advisory & for the -ipc help!
Thank you @maxime_tz for the diagrams!
This was a two coffee read, but packed with great content..such as APC Reserve Objects / Executing code using arbitrary write primitives / Exploitation / Some bad code / Cheating WHQL / TM driver to write your own Rootkit..wouldn't be surprised if other AV vendors do similar.
How to use @TrendMicro's Rootkit Remover to Install a Rootkit, including a fun bonus discovery that @TrendMicro is cheating WHQL certification. cc @msftsecurity https://t.co/c7EEOEnISa
All it takes is a single command to defend & validate:
reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Ports"
See anything odd in there? Delete it. After the patch, this trick will no longer work.
🔥 Awesome BugBounty Writeups 🔥
Created a list of 600+ Bugbounty writeups characterized by Bug type ! Happy Quarantine ! Grab a coffee and give them binge read 🔥
Github : https://t.co/OPTIO90DaD
A novel attack vector allows a hacker to manipulate a #PowerPoint file to download #malware -- simply by hovering over a hypertext link.
https://t.co/pzE9T5H1bc
Just pushed a blog post on a LPE exploit in VMware Fusion that allows an unprivileged user to run commands as root by exploiting a SUID helper binary. It was only partially fixed in the 11.5.2 update; exploit_usb.sh still works on a fully patched system.
https://t.co/CbytT55Q5H