simple question, do you need the firewall rule shadow to get that shadow:1 session ?pic.twitter.com/fhOwB03UCy
U tweetove putem weba ili aplikacija drugih proizvođača možete dodati podatke o lokaciji, kao što su grad ili točna lokacija. Povijest lokacija tweetova uvijek možete izbrisati. Saznajte više
simple question, do you need the firewall rule shadow to get that shadow:1 session ?pic.twitter.com/fhOwB03UCy
That's a good point, for testing purpose I removed FW due to RemoteRPC issue then I suppose that the answer should be yes. This kind of attack can be useful in a network where admins use this feature for admin. tasks (you also have this kind of issue using WinRM for example)
It's a cool trick :)https://gist.github.com/bohops/f722f1a54d9ac1070350bdcaf2da618b …
You're welcome ! Hope that it will be helpful when pentesters will be blocked by multi-session limitation or when you know "don't warn user that I access his RDP session" :Ppic.twitter.com/64vDJ7E0np
Is it bad that I use this exact process to do remote assistance for my users that can’t remember how to initiate our screen sharing tools?
Not so bad, you just be aware about the risk and monitor malicious activities for example (you also can use à dedicated user etc...) But this is the perfect example that this may occur in real life
https://twitter.com/cyb3rops/status/1220731638847606786 … PS: next time, if you actually give a damn about security, please do everyone the courtesy of publishing signatures and/or detection rules when you publish or promote an offensive technique.pic.twitter.com/va6xjIAXv9
What if I publish nothing? Do you really think that you're secure if issue are under the carpet dude?
Do your job (like florian
), I do mine and... enjoy life, no troll ;)
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.