Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @MrUn1k0d3r
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @MrUn1k0d3r
-
Released a little tool to perform lateral movement that hide the command you are executing by registering a protocol handler. The protocol handler is executed over WMI by simply running start customhandler:// https://github.com/Mr-Un1k0d3r/PoisonHandler …
#redteam#pentest
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mr.Un1k0d3r proslijedio/la je Tweet
Trustwave
@SpiderLabs Principal Consultant,@MrUn1k0d3r, has announced the release of a new open source tool aimed at aiding Red Team engagements. https://trus.tw/b3a2e#cybersecurity#infosecHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mr.Un1k0d3r proslijedio/la je Tweet
Evading WinDefender ATP credential-theft: a hit after a hit-and-miss start. tl;dr PssCaptureSnapshot syscall clones the process then you don't need to do ReadProcessMemory against the original process and avoid LSASS read detection.https://www.matteomalvica.com/blog/2019/12/02/win-defender-atp-cred-bypass/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
SCShell now have a linux python utility that relies on
@agsolino impacket project. You can pass the hash too. https://github.com/Mr-Un1k0d3r/SCShell/blob/master/scshell.py … Made a pull request to add it to the impacket project.
#redteam#PentestingHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Interesting way to move laterally using the service manager without registering a service or writing a file to disk. C# and Powershell version will be release soon. https://github.com/Mr-Un1k0d3r/SCShell … Thanks to ChangeServiceConfigA
#redteam#PentestingHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mr.Un1k0d3r proslijedio/la je Tweet
NTLM reflection is back to haunt windows. Read about Ghost Potato here (this time with a fixed link):https://shenaniganslabs.io/2019/11/12/Ghost-Potato.html …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
This is major step for me. My online
@RingZer0_CTF now have a real identity.
#ctfplayerhttps://twitter.com/RingZer0_CTF/status/1182298496264790016 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
More C# utility. WMI utility allow you to run WMI query directly in C#. Can be used with execute-assembly. https://github.com/Mr-Un1k0d3r/RedTeamCSharpScripts/blob/master/wmiutility.cs …
#redteam#Pentesting
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Procdump alternative that may come handy during
#redteam https://github.com/Mr-Un1k0d3r/MiniDump … There is a C and a C# version that can be used with execute-assembly
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mr.Un1k0d3r proslijedio/la je Tweet
#Microsoft#Teams | Exe Sideloading aka Exe proxying attack technique, Most of the#Nuget/#Squirrel applications affected, No need of installation. Medium : https://link.medium.com/Ug5hOf9LOZ Youtube : https://www.youtube.com/watch?v=3aZM0Rfjgy4 … Thanks to@Hexacorn ,@MrUn1k0d3r#blueteam#Redteam#dfirPrikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mr.Un1k0d3r proslijedio/la je Tweet
Without further delay,
@0xDezzy and I will now be releasing our Red Teamer's Guide to Pulse Secure SSL VPN. https://medium.com/@alyssa.o.herrera/pulse-secure-ssl-vpn-post-auth-rce-to-ssh-shell-2b497d35c35b …#redteam@orange_8361@GossiTheDog@bad_packetsHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mr.Un1k0d3r proslijedio/la je Tweet
MiniDumpWriteDump via COM+ Services DLL (rundll32 C:\windows\system32\comsvcs.dll MiniDump "[lsass_pid] dump.bin full")https://modexp.wordpress.com/2019/08/30/minidumpwritedump-via-com-services-dll/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Come join me at 3PM at
@SpiderLabs#BHUSA booth #1046 I will be presenting some interesting red team tricks that we are using during our red team engagements. See you soon
#Pentesting#redteamHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
LDAP utility written in C# that can be used with execute-assembly to query AD information. https://github.com/Mr-Un1k0d3r/RedTeamCSharpScripts …
#redteam#pentesting
pic.twitter.com/4GYjcSVD4w
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Mr.Un1k0d3r proslijedio/la je Tweet
Introducing InveighZero, a C# LLMNR/NBNS/mDNS/DNS spoofer/man-in-the-middle tool: https://github.com/Kevin-Robertson/InveighZero … Bonus, also just released Inveigh 1.5: https://github.com/Kevin-Robertson/Inveigh … Stop by the
@NetSPI#BlackHat2019 booth to learn more and get stickers
pic.twitter.com/0uqBzYtrbY
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Apparently I will be in Las Vegas for my very first
#BlackHat2019 experience. I will be presenting some of my Red Team material at@SpiderLabs booth. Looking forward to meet some of you and 30000 billions grasshoppers.
#RedTeam#pentestingHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
I've slowly started to port some of my tools to C# so it can be used with Cobalt Strike execute-assembly or standalone executable. LDAP query to get Active Directory data for now.
#redteam#pentestinghttps://github.com/Mr-Un1k0d3r/RedTeamCSharpScripts …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Keep in mind that most electron app expose the Updater.exe since it is part of the electron ecosystem. Which means that popular app such as Slack and Discord can be used too.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
My official blog post regarding Teams Updater arbitrary execution. More details on the mitigation already in place regarding Teams Updater. Also why using %appdata% is bad. https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/executing-code-using-microsoft-teams-updater/ … Much love to
@reegun21
#redteam#PenTestPrikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Copy your payload into %userprofile%\AppData\Local\Microsoft\Teams\current\ Then %userprofile%\AppData\Local\Microsoft\Teams\Update.exe --processStart payload.exe --process-start-args "whatever args" Trusted signed binary will run the payload for you
#RedTeam#PentestingHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.