Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @Fabiothebest89
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @Fabiothebest89
-
Prikvačeni tweet
New book: Beginner’s Guide to Information Security: Kickstart your security career with insight from InfoSec expertshttp://www.pentest.guru/index.php/2016/08/09/new-book-beginners-guide-to-information-security-kickstart-your-security-career-with-insight-from-infosec-experts/#.V6nNAqb6qJk.twitter …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Fabio Baroni proslijedio/la je Tweet
New blog post is up starting a series of looking at just how Mimikatz achieves its magic, beginning with WDigest (and ending with a bit of lsass DLL loading fun).https://blog.xpnsec.com/exploring-mimikatz-part-1/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Fabio Baroni proslijedio/la je Tweet
Defenders should deploy this settings: HKLM\SYSTEM\CurrentControlSet\Control\Lsa Dword: RunAsPPL Value: 1 Protects dumping of Lsass with a simple registry value. Encountered that on an engagement recently.
Mimikatz driver needed to bypass
Detailshttps://docs.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Fabio Baroni proslijedio/la je Tweet
Introducing SysWhispers, a tool that helps with AV/EDR evasion by using direct system calls to bypass user-mode API hooks. It works by generating header/ASM pairs supporting all core syscalls from Windows XP to 10. Check it out here with examples:https://github.com/jthuraisamy/SysWhispers …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Fabio Baroni proslijedio/la je Tweet
If you have AppLocker deployed, be aware that most times when Windows 10 is updated/upgraded, it creates a TASKS_MIGRATED folder under C:\windows\system32 that has the CREATOR OWNER, meaning that users can create and execute files from the folder and bypassing AppLocker
pic.twitter.com/YLUxRxDyxr
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Fabio Baroni proslijedio/la je Tweet
I spent some time learning about blockdlls and parent process spoofing from
@_RastaMouse and@_xpn_ . Using a recent sample from SubTee, I modified it to spoof the parent process and inject x64 shellcode from a dll on UNC into hidden iexplore.exe. https://gist.github.com/rvrsh3ll/54088dcd81a09e99421a8c5692124705 …pic.twitter.com/V93FAn6iIFHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Fabio Baroni proslijedio/la je Tweet
#BlueTeam command-line MSBuild.exe detection's got your#RedTeam down? How about MSBuild without MSBuild.exe? https://s5.gifyu.com/images/msbuild_api.gif …https://github.com/rvrsh3ll/MSBuildAPICaller …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Fabio Baroni proslijedio/la je Tweet
Dear
@NETGEAR, Putting the private key for a CA blessed certificate in firmware is a bad idea.@nstarke and I found a couple a couple terrible things. https://gist.github.com/nstarke/a611a19aab433555e91c656fe1f030a9 …pic.twitter.com/oOIs8kpoUm
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Fabio Baroni proslijedio/la je Tweet
Happy to announce that you now can find the lecture notes for my Hardware and Embedded Systems Security course online, including tex sources:https://github.com/david-oswald/hwsec_lecture_notes …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Fabio Baroni proslijedio/la je Tweet
my new current project. automatic ropchain generation! https://github.com/d4em0n/exrop pic.twitter.com/nkXB9FhUra
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Fabio Baroni proslijedio/la je Tweet
And... Wafw00f 2.0 is out. Major rewrite and so many new detections. Thanks
@0xInfection for all the hard work!https://twitter.com/0xInfection/status/1205530525068226561 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Fabio Baroni proslijedio/la je Tweet
Are you ready to takeover subdomains? ;) I have developed a tool to scan subdomain takeover vulnerabilities. Found 300+ vulnerable subdomains on Twitter,Yahoo,Pinterest,Periscope,Spotify,HarvardUni,StanfordUni,BerkeleyUni,YaleUni,PrincetonUni... Its free!https://hackking.net/subdomain-takeover-scanner/ …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Fabio Baroni proslijedio/la je Tweet
Pretty good workshop, describing Windows drivers DSE bypassing! https://github.com/theevilbit/workshops/tree/master/DSE%20Bypass%20Workshop … It allows run LiveCloudKd with own hvmm.sys driver on Windows Server 2019 with Dec 2019 patches and Secure Boot enabled.pic.twitter.com/G70ZAU0j1l
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Fabio Baroni proslijedio/la je Tweet
My PhD thesis "Software-based Side-Channel Attacks and Defenses in Restricted Environments" is finally available online: https://misc0110.net/web/files/phd_thesis.pdf … I really enjoyed my last 3 years working on it, also due to my great colleagues, especially
@lavados,@mlqxyz, and@BloodyTangerinepic.twitter.com/po1M8T85Zy
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Fabio Baroni proslijedio/la je Tweet
So I translated to myself
@AmarSaar's article on Exploitation and the internals of Windows 10 RS5#LFH (Userspace), and Saar suggested I'll upload it for everyone, so why not :) I hope this helps as it helped me, thank you Saar!https://github.com/peleghd/Windows-10-Exploitation/blob/master/Low_Fragmentation_Heap_(LFH)_Exploitation_-_Windows_10_Userspace_by_Saar_Amar.pdf …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Fabio Baroni proslijedio/la je Tweet
Want to learn how to do well in your
#infosec#interview? Here's a guide from@Fabiothebest89http://ow.ly/ebZU30nU6YcHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Fabio Baroni proslijedio/la je Tweet
Need privilege escalation? Have access to SMB and NFS shares? Automate looking for credentials! 1) pip3 install -r requirements.txt sudo apt-get install cifs-utils 2) git clone https://github.com/nikallass/sharesearch.git … 3) python3 http://sharesearch.py -p all -w -v -H hosts.lst -C creds.lstpic.twitter.com/7kvsSeNs1D
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Fabio Baroni proslijedio/la je Tweet
#powershellveryless C# (CL +AMSI bypass), here the quick&dirty code:https://github.com/decoder-it/powershellveryless …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Fabio Baroni proslijedio/la je TweetHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Fabio Baroni proslijedio/la je Tweet
This ZoomEye dork reveals current Cobalt Strike C&C servers: https://www.zoomeye.org/searchResult?q=%22HTTP%2F1.1%20404%20Not%20Found%20%20%20Content-Type%3A%20text%2Fplain%20Date%3A%22%20%2B%22Content-Length%3A%200%22%20-Connection … There are about 3,600, 86% of which are also found on Fox-IT's listpic.twitter.com/wXrqEh1aT2
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Fabio Baroni proslijedio/la je Tweet
Want to learn how to do well in your
#infosec#interview? Here's a guide from@Fabiothebest89http://ow.ly/GE6030nRvXZHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.