On a recent assessment I found a Pentaho webapp using default creds, which sent me down a rabbit hole.
I return with a tool decrypt 'Encrypted' passwords from .KTR files and a method to recover non-default encryption keys.
https://t.co/zoYRx1c2aX
hashcat v7.0.0 released!
After nearly 3 years of development and over 900,000 lines of code changed, this is easily the largest release we have ever had.
Detailed writeup is available here: https://t.co/fxAIXNXsEr
Had some fun with PDQ deploy/inventory credential decryption and wrote about it here: https://t.co/jwwU7Ykzb5 thanks to @_dru1d for write a BOF out of the POC
tl;dr get admin on PDQ box, decrypt privileged creds
https://t.co/QA4hdKCNhn
It might be a bit rocky for the next couple days as I work out a couple issues with magnet links and the self-hosted tracker but its up and working
On a recent assessment I found a Pentaho webapp using default creds, which sent me down a rabbit hole.
I return with a tool decrypt 'Encrypted' passwords from .KTR files and a method to recover non-default encryption keys.
https://t.co/zoYRx1c2aX
@ZineaLLC This was a fun bit of research and it got me a few privileged database user creds, which led to code exec.
Thx to haicen for pointing out the XOR key recovery process.
https://t.co/0al7nWXoCg
Have fun and good luck!