@truffzor@pwn_ai I could see this being an RCE in scenarios where the IM output is served by a PHP server, but they didn't show which is disappointing. If they had not just copied the output of their AI and framed it as an RCE in IM it could have been nice (e.g. focus on file-confusions in IM).
SafeBreach Labs discovered a critical RCE vulnerability in the MS-EVEN RPC protocol that allowed low-privileged domain users to write arbitrary files and run code on remote Windows 11 and Windows Server 2025 computers in the domain.
Get the full breakdown: https://t.co/sHklNRXq55
🚀Our tool keycred for KeyCredentialLinks and Shadow Credential attacks now works with updated domain controllers again!
It turns out, Microsoft violated their own specs.
Try it out: https://t.co/OtBYIGVxGn
@buck_steffen@Defte_ The writing of keycredentials on self is handled by a validated write, which is still there (even visible in your picture): https://t.co/ibstlG2Y3e
@Defte_@MGrafnetter From what I looked at yesterday there just weren’t any checks before, except if it parsed at all. I attached the new function and an analysis of it with pyghidra-mcp and Claude haiku at the end of the gist: https://t.co/kWXPR01PrF
@Defte_@MGrafnetter Note that most administrator groups (at a glance at least Key Admins, Enterprise Key Admins and Administrators) have WRITE_PROP privileges on that attribute, so in that case there is no validation.
@Defte_ Here is a Diff for the working and non working version, it seems like they added a new function for checking if a keycredential is valid: https://t.co/IK0R8383pE
@Defte_ I just installed a clean version of Server 2022 (20348.169), setup it up as a DC, and tried to create a keycredential. That worked. Than I installed the latest cumulative update (KB5073457) and now it does not work anymore. So it seems to be a recent change.
We just released my writeup for my first CTF challenge I ever created, "Ghostbusters" for Haix-La-Chapelle 2025 CTF.
it involves some cool techniques for exploiting Ghostscript and PDF/PostScript file type confusion.
https://t.co/N1sCnjnA3C
🔥Only 10 days left until the Haix-la-Chapelle 2025 CTF is starting on November 29!
We're sponsoring the prize money for the best writeups and are excited to see your creative solutions.
https://t.co/m1IXybaV2A
One of our pentesters recently got a new D-Link DAP-X1860 repeater, which they couldn't setup.
This was caused by a neighbor's Wi-Fi containing a single tick in their Wi-Fi name ("Olaf's WiFi"), resulting in the following error while scanning for access points:
@nmatt0 I messed with that last month too, I got into the Android Browser through a link in Mini Metro. However the Android Settings were locked down, so accessing the local network was all I could achieve (no internet), and it was right at the end of the flight 😅