Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @DigitalResidue
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @DigitalResidue
-
With their preferred webshells, the actors moved laterally to other systems on the network by dumping credentials with a variant of the notorious Mimikatz tool and using Impacket’s atexec tool to use dumped credentials to run commands on other systems.https://unit42.paloaltonetworks.com/actors-still-exploiting-sharepoint-vulnerability/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Aaron D proslijedio/la je Tweet
Finally released part 2 of my »Reversing
#WannaCry with#Ghidra« series! In this video we reverse engineer some of the integrated decryption methods and see how we can easily analyze C++ code in Ghidra.https://www.youtube.com/watch?v=Q90uZS3taG0 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
#FakeLogonScreen. A utility to fake the Windows logon screen in order to obtain the user's password. The password entered is validated against the#ActiveDirectory or local machine to make sure it is correct and is then saved to disk.#Pentesting#RedTeamhttps://github.com/bitsadmin/fakelogonscreen …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Aaron D proslijedio/la je Tweet
Really glad to finally get a blogpost out about this. Hopefully this is useful and gives Red Teamers ideas on how to use the BYOI concept in their own payloads. If anyone is interested in a few more follow up posts about this will gladly oblige :)https://www.blackhillsinfosec.com/red-teamers-cookbook-byoi-bring-your-own-interpreter/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Dropbox bug bounty program has paid out over $1,000,000. To celebrate this momentous occasion, the Dropbox Production Security team wanted to disclose, in-depth, five of our favorite reports we’ve ever received.
#BugBountyhttps://blogs.dropbox.com/tech/2020/02/dropbox-bug-bounty-program-has-paid-out-over-1000000/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Aaron D proslijedio/la je Tweet
We are announcing our new blog with a post about Teamviewer and storing user passwords encrypted and not hashed allow for easy plaintext retrieval from the Windows registry.https://whynotsecurity.com/blog/teamviewer/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Aaron D proslijedio/la je Tweet
When testing for SSRF, change the HTTP version from 1.1 to HTTP/0.9 and remove the host header completely. This has worked to bypass several SSRF fixes in the past.
#bugbountytip#bugbountytip#bugbountyHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
(Another Sudo bug). The discovered privilege escalation vulnerability, tracked as CVE-2019-18634, in question stems from a stack-based
#bufferoverflow issue that resides in Sudo versions before 1.8.26. Exploited when the "pwfeedback" option is enabled.https://thehackernews.com/2020/02/sudo-linux-vulnerability.html?m=1 …Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
The emails contain an Excel spreadsheets that once downloaded, asks the victim to enable macros. Now in the background, the (VBA) programming code for macros is being enabled for the
#tonedeaf malware to download to a directory.#phishing#westat#apt34https://threatpost.com/iran-hackers-us-gov-malware/152452/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
The API endpoint targeted allows people who have created new accounts to find their friends on Twitter. The API queries which users have a phone number associated with their accounts. Someone was using a large network of fake accounts to exploit this APIhttps://www.bleepingcomputer.com/news/security/twitter-fixed-issue-exploited-to-match-phone-numbers-to-accounts/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
SOAP API is made of an official standard while REST API is not. This makes REST API easy to use and deploy
#REST uses: HTTP, JSON , URL and XML#SOAP uses: mostly HTTP and XML REST is more popular among developers than SOAP. But SOAP has better securityhttps://medium.com/datadriveninvestor/api-security-testing-part-1-b0fc38228b93 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mr. Schulte, 31 years old, faces 11 criminal counts, including illegal gathering and transmission of national defense information—charges that derive from the Espionage Act, a statute that has been applied in other WikiLeaks cases.https://www.wsj.com/articles/ex-cia-engineer-goes-on-trial-for-massive-leak-11580741119?reflink=share_mobilewebshare …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Sun told Raytheon that he went to Singapore and the Philippines. However, after providing inconsistent information as to his travel itinerary, Sun eventually admitted that he had travelled to China, Cambodia, and Hong Kong.
#computercrimelawshttps://www.zdnet.com/article/raytheon-engineer-arrested-for-taking-us-missile-defense-data-to-china/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Aaron D proslijedio/la je Tweet
Some essential process execution/cmd lines to monitor for initial access/persist. powershell cmd rundll32 control wscript javaw csc regsvr32 reg certutil bitsadmin schtasks wmic eqnedt32 msiexec cmstp mshta hh curl installutil regsvcs/regasm at msbuild sc cscript msxsl runonce
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
#Movekit is an extension built into#CobaltStrike for lateral movement by leveraging the execute_assembly function with the SharpMove and SharpRDP .NET assemblies. Users can execute a command on a remote system through WMI, DCOM, RDP, etc.#CyberSecurityhttps://github.com/0xthirteen/MoveKit …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Aaron D proslijedio/la je Tweet
#FakeLogonScreen is a C# utility to steal a user's password using a fake Windows logon screen. This password will then be validated and saved to disk. Useful in combination with#CobaltStrike's execute-assembly command. https://github.com/bitsadmin/fakelogonscreen …pic.twitter.com/2pAOk9InLMHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Aaron D proslijedio/la je Tweet
Wow! "Resources for Beginner Bug Bounty Hunters" has over 1000 stars on GitHub now and we just pushed a new update! Check it out:https://github.com/nahamsec/Resources-for-Beginner-Bug-Bounty-Hunters/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Aaron D proslijedio/la je Tweet
The 30th HTB box I solve in preparation for the OSCP. Initial Foothold - XXE injection + lack of input validation on user supplied input into the pickle serialization library. Privilege Escalation - Root RSA private key in git history.https://medium.com/@ranakhalil101/hack-the-box-devoops-writeup-w-o-metasploit-afa7d5952117?source=friends_link&sk=dd991ffcf647caa6262609fa6df38832 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Aaron D proslijedio/la je Tweet
Windows Red Team Cheat Sheet 1. Recon 2. Elevation of Privileges 3. Lateral Movement 4. Golden and Silver Tickets 5. AD Attacks 6. Bypass-Evasion Techniques 7. Miscellaneous 8. Post exploitation - information gathering 9. Summary of tools https://morph3sec.com/2019/07/16/Windows-Red-Team-Cheat-Sheet/ …pic.twitter.com/oDXKA2bN4b
Ovo je potencijalno osjetljiv multimedijski sadržaj. Saznajte više
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.