Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @StanHacked
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @StanHacked
-
Prikvačeni tweet
Evil Clippy: our new tool for creating malicious MS Office documents. Can hide VBA macros, stomp VBA code (via P-Code) and confuse many macro security analysis tools. Read our blog post for details: https://outflank.nl/blog/2019/05/05/evil-clippy-ms-office-maldoc-assistant/ …pic.twitter.com/HbY8uOQYTS
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
If
@tiraniddo's DotnetToJScript is blocked on newer versions of Windows or if it gets flagged by AMSI, you can use Excel automation via a COM object as an alternative to execute shellcode from JScript or VBScript w/o touching disk. PoC for x86 & x64 here:https://github.com/outflanknl/Scripts/blob/master/ShellcodeToJScript.js …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Stan Hegt proslijedio/la je Tweet
Okay here it is, Zipper a new
@OutflankNL file and folder compression utility for CobaltStrike. Blue Teams/Hunters/Defenders: Lookout for non file-compression related processes creating (random named) zipfiles within temp folders.https://github.com/outflanknl/Zipper …Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Stan Hegt proslijedio/la je Tweet
Spray-AD, a new
@OutflankNL Kerberos password spraying tool for Cobalt Strike that might come in handy when assessing Active Directory environments for weak passwords (generates event IDs 4771 instead of 4625).https://github.com/outflanknl/Spray-AD …Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Video recording of my presentation with
@ptrpieter at Black Hat Asia 2019 is online. MS Office in Wonderland: 50 minutes of offensive tradecraft with Word and Excel. Exploiting fields, Power Query, VBA stomping, Excel4 macros, AMSI bypasses and more fun.https://youtu.be/9ULzZA70DzgHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Stan Hegt proslijedio/la je Tweet
Just published some thoughts on red teaming, how to approach it, procure it and get in to it...https://link.medium.com/eV1myC6NM2
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Cool! My lightning talk submission for
@WEareTROOPERS is accepted: "The caveats of implementing smart cards and MFA in Active Directory". 25 Minutes packed with nasty security details of AD, Kerberos and NTLM. Looking forward to another edition of this awesome conference!#TR20Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Happy to announce that I'll be speaking at
@nullcon Goa 2020 on attacking developers via malicious code. Expect a journey into COM, typelibs and inner workings of Visual Studio. This research builds on the shoulders of giants@tiraniddo and@tombkeeper. https://nullcon.net/website/goa-2020/speakers/stan-hegt.php …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Stan Hegt proslijedio/la je Tweet
Final slides of my presentation yesterday at Black Hat Europe 2019, about malicious VBA macros and recent advances in the attack & defence sides: https://www.decalage.info/bheu2019 Featuring
#oletools/olevba, ViperMonkey, MacroRaptor, EvilClippy#BHEU#BHEU2019pic.twitter.com/iT8iqvIM8E
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Stan Hegt proslijedio/la je Tweet
NTLM reflection is back to haunt windows. Read about Ghost Potato here (this time with a fixed link):https://shenaniganslabs.io/2019/11/12/Ghost-Potato.html …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Stan Hegt proslijedio/la je Tweet
@domchell I've done a dirty update on SharpShooter to provide 64-bit compatibility for SLK Macros (based on@StanHacked and@PhilipTsukerman work
).
https://github.com/spamv/SharpShooter …
Let me know if you'd like a PR in the original repo.Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Stan Hegt proslijedio/la je Tweet
There's a new Excel 0day which may allow for the automatic & silent execution of embedded macros on macOS
New blog post: "[0day] Abusing XLM Macros in Slk Files" https://www.patreon.com/posts/31418067 
Shoutouts to @ptrpieter/@stanhacked for initial bug discovery & their analysis
pic.twitter.com/YraSrdX41T
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Stan Hegt proslijedio/la je Tweet
For example, if you're unfortunate enough to still be using macOS Sierra (10.12.x), Safari will launch Excel to open an arbitrary file with zero user interaction. This makes for a complete drive-by download situation.pic.twitter.com/7tzrZ9U101
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Stan Hegt proslijedio/la je Tweet
Lol, another SLK/XML macro warning bypass. Recommendation do NOT “Disable all macros without notification” on excel4mac, this setting enabled direct execution of any Xlm macro.. Nice find
@wdormannhttps://kb.cert.org/vuls/id/125336/Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Our new
@OutflankNL blog post on abusing the SYLK file format. This 1980s file type can host macros in modern versions of MS Office / Excel without hitting protected mode. Post includes recommendations for mitigation (note: active abuse in the wild).https://outflank.nl/blog/2019/10/30/abusing-the-sylk-file-format/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Stan Hegt proslijedio/la je Tweet
New
@OutflankNL C# Tradecraft -> SharpHide. A nice persistence trick to confuse DFIR investigation. Uses NtSetValueKey native API to create a hidden (null terminated) registry key.https://github.com/outflanknl/SharpHide …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Stan Hegt proslijedio/la je Tweet
New
@OutflankNL blog and Recon-AD tool: Active Directory Recon using ADSI and Reflective DLLshttps://outflank.nl/blog/2019/10/20/red-team-tactics-active-directory-recon-using-adsi-and-reflective-dlls/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Net-GPPPassword,
@OutflankNL's C#/.NET port of@obscuresec's PowerShell-based Get-GPPPassword. Retrieves plaintext password for accounts pushed through Group Policy Preferences. The technique is dated, but still valuable in some of our gigs.https://github.com/outflanknl/Net-GPPPassword …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Just heard that my latest vulnerability submission is eligible for max bounty (15,000 USD) in the MS Office bounty program. Thanks
@msftsecresponse! Hope this motivates others to find bugs, disclose them to vendors and make the world a bit safer. Write-up will follow after fix.Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Stan Hegt proslijedio/la je Tweet
Posted some VBA code for loading a DotNet assembly directly using mscorlib + Assembly.Load by manually accessing the VTable of the IUnknown. Hopefully it saves someone else some time, but it's not the cleanest approach I was hoping for.https://gist.github.com/monoxgas/1b36031c5593ebfed3229f4424f77090 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.