The chopper webshell must still be the
#OST with the best return of investment ever. Likely the next one will be getting API access to a serverless environment, which enables you to steal everything toolless.
-
-
-
I'd definitely agree its power, success, and reach is comprehensive, and the webshell itself is minimal. It still requires a way to be placed on a system which then needs to become publicly accessible though. So I would still say Metasploit or Mimikatz is the OST with best ROI
Kraj razgovora
Novi razgovor -
-
-
It blows me away that it's 2020 and pass the NTML-hash is still a thing.
-
Yeah, I guess it's challenging when it's part of how the underlying OS works on a domain (in amongst millions of lines of code I'm assuming). At least there's some mitigations with Token Filtering Policies/UAC, segregation, disabling network auth for local accounts etc
Kraj razgovora
Novi razgovor -
-
-
What is the meaning in "Relay ((Net-)NTLM)" ?
-
Either NTLM hashes being dumped and "Passed", or Net-NTLM hashes being obtained through LLMNR/NBT-NS Poisoning and relayed to a remote host.
Kraj razgovora
Novi razgovor -
-
-
Hey, nice list. Just a small addition. If stars are aligned properly (restricted admin enabled) you can also use PtH for RDP.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.