Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @ReneFreingruber
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @ReneFreingruber
-
Prikvačeni tweet
Here is my review of the "Active Directory lab" from Pentester Academy: https://apt29a.blogspot.com/2020/02/pentester-academy-active-directory-lab.html …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rene Freingruber proslijedio/la je Tweet
Extending BloodHound: Part 1 - GPOs and User Right Assignmenthttps://riccardoancarani.github.io/2020-02-06-extending-bloodhound-pt1/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rene Freingruber proslijedio/la je Tweet
We've added a brand new topic on DOM-based vulnerabilities. The topic contains 7 labs, plus there are 2 new labs in the existing XSS topic.https://portswigger.net/web-security/dom-based?utm_source=twitter&utm_medium=social&utm_campaign=dom-based …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rene Freingruber proslijedio/la je Tweet
The AFL++ website is up: https://aflplus.plus/ Very naive ATM, I'm open to suggestions.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rene Freingruber proslijedio/la je Tweet
If you use the cs2modrewrite project to build your C2 redirector rules, it is now updated to support CS <=4.0 profiles (multi-variants).
#specterops#redteam@joevesthttps://github.com/threatexpress/cs2modrewrite …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rene Freingruber proslijedio/la je Tweet
Load encrypted PE from XML Attribute. MSBuild is still the best.
https://github.com/XwingAngel/PELoader/ …
MSBuild sets Property then calls Execute.
Use this example to decouple payloads & prove that all security products have a "Single File Bias".
Decouple payloads to subvert detection.pic.twitter.com/648rujlLQn
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rene Freingruber proslijedio/la je Tweet
A day prior to the Travelex hack, its parent company was worth $2.1 Billion. A month later it is now worth $764 Million. The CEO owns 63% of the shares, which puts his personal loss around $850 Million.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rene Freingruber proslijedio/la je Tweet
Pushed a new Rubeus release after getting some additional feedback from our most recent AT:RTO students. The full changes are detailed here https://github.com/GhostPack/Rubeus/blob/master/CHANGELOG.md#150---2020-01-31 … . To highlight a few new features- "/nowrap" globally prevents base64 blobs from line-wrapping, (1/4)
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rene Freingruber proslijedio/la je Tweet
Just published a follow-up to my Adobe Reader symbols story on the Project Zero blog. Turns out there's even more debug metadata to be found in some old (and new) builds, including private CoolType symbols. Enjoy! https://googleprojectzero.blogspot.com/2020/01/part-ii-returning-to-adobe-reader.html …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rene Freingruber proslijedio/la je Tweet
The biggest
#infosec data breaches in recent years visualized. Including an convenient download as CSV file, in case you want to play around with the data. https://informationisbeautiful.net/visualizations/worlds-biggest-data-breaches-hacks … via@infobeautifulpic.twitter.com/sC484Wxn0Z
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rene Freingruber proslijedio/la je Tweet
Qualys Security Advisory: LPE and RCE (CVE-2020-7247) in OpenSMTPD, OpenBSD's mail server. Erroneous logic in smtp_mailaddr() which validates user and domain. More details and PoC at: https://www.openwall.com/lists/oss-security/2020/01/28/3 … PS: "Did you ever play tic-tac-toe?"
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rene Freingruber proslijedio/la je Tweet
Curl.exe is the new rundll32.exe — LOLbinhttps://medium.com/@reegun/curl-exe-is-the-new-rundll32-exe-lolbin-3f79c5f35983 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rene Freingruber proslijedio/la je Tweet
SVG animate XSS vector by
@garethheyeshttps://portswigger.net/research/svg-animate-xss-vector …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rene Freingruber proslijedio/la je Tweet
So I created this Burp Teams https://github.com/hackvertor/burp-teams … it allows you to share repeater/intruder/comparer tabs. It uses nodejs for the server with http://socket.io . But I then found out someone already did this so it won’t be on the BApp store. On the plus side I learnt lots.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rene Freingruber proslijedio/la je Tweet
Check out our new page on escaping the AngularJS sandbox, including new vulnerability labs.https://portswigger.net/web-security/cross-site-scripting/contexts/angularjs-sandbox …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rene Freingruber proslijedio/la je Tweet
Big change coming to Windows Server this March - insecure LDAP requests will be rejected by default. That's a change in behaviour which will absolutely break things in some orgs How to get in front of the issue:https://opensecurity.global/forums/topic/249-preventing-ldap-apocalypse-in-march-2020-ldap-signing-requirements/ …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rene Freingruber proslijedio/la je Tweet
If
@tiraniddo's DotnetToJScript is blocked on newer versions of Windows or if it gets flagged by AMSI, you can use Excel automation via a COM object as an alternative to execute shellcode from JScript or VBScript w/o touching disk. PoC for x86 & x64 here:https://github.com/outflanknl/Scripts/blob/master/ShellcodeToJScript.js …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rene Freingruber proslijedio/la je Tweet
As I have no cool new findings, lets start the year with an old IE bug - bypassing Content-Disposition: attachment with mhtml: https://insert-script.blogspot.com/2020/01/internet-explorer-mhtml-why-you-should.html …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rene Freingruber proslijedio/la je Tweet
And another review of Pentester Academy's Global Central Bank course and PACES certification. https://chryzsh.github.io/pta-gcb/ Thank you
@nikhil_mitt and@SecurityTubeHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rene Freingruber proslijedio/la je Tweet
#lsassy v2 is out
Dump credentials on multiple hosts
New dumping method using #dumpert (@OutflankNL) thanks to@Blurbdust
Can be used as a #library in other python project
Fully documented wiki !
Needs some testing, open issues if need be
https://github.com/Hackndo/lsassy Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.