The video about blind SSRF in Google Cloud for which @david_nechuta got $31k is out!
Watch it to see how it's sometimes possible to exfiltrate data with blind SSRFs. You can also test your own skills with hands-on lab 😎
Enjoy!
https://t.co/glEjgKO4vV
Our team member @0x4148 just published the 2nd part of windows authentication attacks. This part covers Kerberos authentication process and technical analysis of widely used Kerberos attacks.
https://t.co/H00jbjdmAP
Happy reading
We've just published the 1st part of the Windows authentication attacks series.
https://t.co/QF43QTE4Si
The series suppose to cover the NTLM/Kerberos authentication in detail as well as how their attacks work.
Happy reading, and stay tuned for part 2.
This will have huge impact!, another great example on how RCE can be achieved on OWA easily through ViewState deserialization attack. Red Teamers it's your chance now :)
https://t.co/Qu5CW01gkc
"There is no pre-auth RCE in Jenkins since May 2017, but this is the one!"
Relase a more reliable and elegant exploit - "awesome-jenkins-rce-2019" from my #HITB2019AMS talk. Thanks @0ang3el and @webpentest join this party! https://t.co/qQCY2RYDa8
Just released viewgen, a ViewState tool capable of generating both signed and encrypted payloads with leaked validation keys or web.config files. All algorithms supported.
TL;DR: Got a web.config file or LFI on https://t.co/cOwfXlDcKx? Pop a shell!
https://t.co/JAC90xowG7
Kerberoasting revealed.
The 1st part of Microsoft Kerberos implementation attacks series by our team member @Hatemsec .
https://t.co/VibyExol5R
Happy reading.
#PenTest#redteam