We are thrilled to announce that NetSPI and @synack have entered into a definitive agreement to merge & form the industry’s leading offensive cybersecurity platform.
Full announcement: https://t.co/O9Uy9csFQI
#NetSPI#Synack#OffensiveSecurity#ContinuousTesting
@techspence PowerHuntShares can help with this too. Not as lightweight or targeted as your own script of course, but it has some nice features built in
https://t.co/1kLqRrWMfB
Microsoft Defender for Identity vulnerability (CVE-2025-26685) allows unauthenticated attackers to capture Net-NTLM hashes and potentially gain AD access. Security tools can become attack vectors - understanding this risk is crucial: https://t.co/mQGrn7tDNo
hakip2host takes a IP addresses via stdin, then does a series of checks to return associated domain names 🚀
👀 DNS PTR lookups
👀 Subject Alternative Names (SANs) on SSL certificates
👀 Common Names (CNs) on SSL certificates
Install hakip2host 👉 https://t.co/YeWSF2cs3n
Been seeing this @SANSInstitute poster floating around lately. I’d like to think that all jobs in InfoSec are cool, but the coolest job is the one YOU are most passionate about. Find the InfoSec niche that makes you happy, keeps you engaged, and pays your bills, and you win.
All the details for CVE-2020-17049 are now available! The overview contains a summary of the vulnerability and its exploit, including links to 2 deep dive posts which cover much more. https://t.co/kVtdVKPfHq
I'm excited to share that CVE-2020-17049 has been issued for a vulnerability that I found. There are more details to come, but I'll be holding off publishing for now while the patchwork is still ongoing. https://t.co/f3xfDL8dzk
Another XSS tip that just got me stored XSS: commonly filtered characters like <> have homoglyphs that are the same to Javascript and the DOM but not caught by blacklists. I use this site to convert my payloads https://t.co/0o86l6Gtuw
Red Tip #425: CVE-2020-16938 allows privileged file read by EVERYBODY according to @jonasLyk You can PoC using 7zip and navigating to the device path \\.\PhysicalDevice0\Basic data partition.img\Windows\System32\Config\ #redteam#cyber
CVE-2020-16938 - aka bits please!
So...recent update changed the permissions on partitions and volume device objects, granting everybody read access.
This means that by opening the device directly you can read the raw data without any privs.
7zip parses NTFS so super for POC
Burp Suite Pro/Community 2020.9.2 released, with support for recorded login sequences in Burp Scanner and various bug/security fixes.
https://t.co/GvEA0tAh0e
On today’s episode of weird windows shit, apparently if you rename a .exe to a .pif windows will still execute it just fine. On top of that, the file icon and type in explorer changes to “Shortcut to MS-DOS program”. Looks a lot less evil.
New blog: A different way of abusing Zerologon. No more password reset needed: using the printer bug with Zerologon to relay to DRSUAPI and DCSync directly with ntlmrelayx: https://t.co/5ixAuW8QHX
Code: https://t.co/nDLcN7LRmh
For the record, Burp Suite does not send details of your vulnerabilities anywhere. But do read this thread if you’re in need of a chuckle.
(In other news, the earth is round and Covid is not a hoax.)