Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @buffaloverflow
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @buffaloverflow
-
Notes on how NetScaler passwords are hashed. (But don't use my crappy rule now
@hashcat has added support
)https://gist.github.com/8d888e9169a3513479af69fc11a459a3 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ok AES-256 encrypted LDAP passwords in ns.conf in ADC/NetScaler have been broken. You need to change those too.https://twitter.com/dozernz/status/1217073075058987008 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rich Warren proslijedio/la je Tweet
https://github.com/dozernz/assorted-pub/blob/master/citrix-ns.md … This is how is used to be done, IIRC theyve changed it since 10.5 at some point. Easier way is to copy the encrypted value into your own local Netscaler and just set it to auth against a ncat listener or something
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
If you see the attacker reading /var/nstmp/sess_* then they just stole authenticated cookies which can be re-used
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
CVE-2019-19781 post-exploitation notes: If you are seeing attackers reading your /flash/nsconfig/ns.conf file then you need to change all passwords. The SHA512 passwords are easily crackable with hashcat.pic.twitter.com/mNMaTT1oCE
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Dear followers, please can someone with a known vulnerable NetScaler run this check for me? Make the following request against the VIP (not management interface): POST /vpns/portal/scripts/newbm.plhttps://twitter.com/buffaloverflow/status/1216497987020521472 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Odd thing about some of the Citrix ADC/NetScaler exploits/scanners.. the ones written in python use the requests module, which normalizes the path so /vpn/../vpns/ => /vpns/ Does that mean people are getting false negatives on the vuln check, or that /../ is really not needed?pic.twitter.com/JgJqMovifm
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
And (I cant believe anyone would do this, but) if you expose your management interface to the internet, don't bother looking for ../ in the request path. It can be exploited without traversal. Just apply the mitigation and go enjoy your weekend
https://twitter.com/buffaloverflow/status/1216020432639471617 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
RE: CVE-2019-19781 detections (Citrix NetScaler/ADC RCE) Although the vulnerable code mandates the the first request *must* be a POST request - the second request can be a HEAD or even a PUT and will still get processed by the template engine.pic.twitter.com/hCWERiETjX
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rich Warren proslijedio/la je Tweet
Multiple exploits were released overnight for CVE-2019-19781 in Citrix ADC/Netscaler - we should all prepare for mass exploitation by a variety of actors as we saw with the various VPN issues last year - details here:https://www.reddit.com/r/blueteamsec/comments/en4m7j/multiple_exploits_for_cve201919781_citrix/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Been running a honeypot for this bug for a few days now. Last 24 hours there has been an increase in internet wide scanninghttps://twitter.com/buffaloverflow/status/1215588278956634112 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Detection: Exploited with 1 POST + 1 GET reqest. As mentioned before, you can look for "/vpns/" in the path, but also "../" in header values for the POST. Probably shouldn't say *which* header at this point. This will be followed by a GET request for a file ending in ".xml".https://twitter.com/buffaloverflow/status/1215588278956634112 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Exploit for Citrix NetScaler CVE-2019-19781. Very interesting bug(s)! 'touch /tmp/CVE-2019-19781' because I'm lazy/busy
pic.twitter.com/LbTYcUMqXX
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Legit just got my first "happy 50th birthday" email. Happy birthday y'all

Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Really enjoyed the
#ATTACKcon livestream coverage that I got to see. Hoping to catch up when I have some free time.Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Thanks
@ItsReallyNick Humbled
I always dreamed about what it would be like to maybe win one of these someday! Imma let you finish.. but, Nick shares the spiciest #GuardrailsOfTheGalaxy tweets of all time!
https://twitter.com/ItsReallyNick/status/1189622906369781762 …pic.twitter.com/Ltw5FXZomQHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Saw some peeps saying this doesn't work anymore... it does! Maybe you are just getting tripped up by Defender emulation (Foretype anyone?
). All I can say is, make sure you've checked out @0xAlexei's truly excellent Defender research
https://twitter.com/KyleHanslovan/status/1183014870700220416 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rich Warren proslijedio/la je Tweet
Just merged
@buffaloverflow PR into master. Nice feature, thanks a lot Rich!https://twitter.com/buffaloverflow/status/1178744119054815232 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Added support for SMB2 snapshot listing/browsing/downloading to impacket. Cool feature for dumping NTDS etc. over pure SMB https://github.com/rxwx/impacket pic.twitter.com/cj38iDRqYd
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.