Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @simakov_marina
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @simakov_marina
-
Marina Simakov proslijedio/la je Tweet
#PingCastle 2.8.0.0 released !!! https://pingcastle.com/download/ 4 clicks and 2 <enter>, that what's between you and the hard truth of your AD security. Example of report: https://pingcastle.com/PingCastleFiles/ad_hc_test.mysmartlogon.com.html … github: https://github.com/vletoux/pingcastle … Changelog: https://raw.githubusercontent.com/vletoux/pingcastle/2.8.0.0/changelog.txt …pic.twitter.com/1oQXuIJcdiHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Marina Simakov proslijedio/la je Tweet
Just published a blog explaining the root cause of the recent
#win10 crypto vulnerability (CVE-2020-0601 /#curveball ?) using some "Load Bearing Analogies" to make it more accessible. CC:@tqbf@grittygrease@dakamihttps://medium.com/zengo/win10-crypto-vulnerability-cheating-in-elliptic-curve-billiards-2-69b45f2dcab6 …Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Marina Simakov proslijedio/la je Tweet
As users access applications in hybrid environments, the need to protect these two components become paramount. Join me and
@maldermania as we dive-in with our sponsor@preemptsecurity! Register & Watch Now: https://attendee.gotowebinar.com/register/4706023419152523532?source=SW …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Marina Simakov proslijedio/la je Tweet
I'm happy to share that the talk I've submitted with
@simakov_marina "Advanced Credential Relaying Techniques and How to Thwart Them" got accepted to@WEareTROOPERS. You don't want to miss this talk if you're interested with what is the latest in#NTLM relay...Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Marina Simakov proslijedio/la je Tweet
The
@defcon talk I gave with@simakov_marina on#NTLM relay is now available online! https://youtu.be/vIISsfLh4iM If you haven't seen it live and you're interested in#ActiveDirectory security you should definitely check it out!Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
You can use the free AD hygiene tool
#PreemptLite to analyze your network and discover all machines which don't enforce SMB signing. Enforcing SMB signing on DCs alone (which is the default config) is not enough. https://www.preempt.com/preempt-platform/preempt-lite/ …https://twitter.com/byt3bl33d3r/status/1195064478225911809 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Marina Simakov proslijedio/la je Tweet
NTLM reflection is back to haunt windows. Read about Ghost Potato here (this time with a fixed link):https://shenaniganslabs.io/2019/11/12/Ghost-Potato.html …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Marina Simakov proslijedio/la je Tweet
While we currently see only coin miners being dropped, we agree w/ the research community that CVE-2019-0708 (BlueKeep) exploitation can be big. Locate and patch exposed RDP services now. Read our latest blog w/ assist from
@GossiTheDog &@MalwareTechBloghttps://www.microsoft.com/security/blog/2019/11/07/the-new-cve-2019-0708-rdp-exploit-attacks-explained/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Marina Simakov proslijedio/la je Tweet
Even though more than two years had passed, this is still a relevant attack vector...https://twitter.com/DirectoryRanger/status/1192332110507450368 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Marina Simakov proslijedio/la je Tweet
Just got into the Github Sponsorship program. If you’re a medium/large orginazation that uses some of my tools commercially on a regular basis , please consider donating as I’ve put in a considerable amount of effort to make them and provide them for free.https://github.com/sponsors/byt3bl33d3r …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Marina Simakov proslijedio/la je Tweet
After more than half a year of work, check out our latest paper Light Commands: Laser-Based Audio Injection on Voice-Controllable Systems. More details at https://lightcommands.com Joint work with Takeshi Sugawara, Benjamin Cyr, Daniel Genkin, and
@DrKevinFu#lightcommandspic.twitter.com/kvuudoVMdR
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Marina Simakov proslijedio/la je Tweet
October ATT&CK update is now live! Lots of new information in Enterprise, Mobile, Groups, and Software. The biggest change is the addition of ATT&CK for Cloud! Thanks to all our contributors that helped with this update and with Cloud! Update notes: https://attack.mitre.org/resources/updates/ …pic.twitter.com/X4gAIESgKI
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Marina Simakov proslijedio/la je Tweet
[Blog] Office 365 was vulnerable to network attacks due to a vulnerability in Microsoft Teams. Here's a demo of an attacker obtaining access to all emails and OneDrive/SharePoint files if the victim joins an attacker controlled network. Details: https://dirkjanm.io/office-365-network-attacks-via-insecure-reply-url/ …pic.twitter.com/jqwcil2KwD
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Marina Simakov proslijedio/la je Tweet
As promised, here is
@donnymaasland's blog about bypassing McAfee's password and admin check which lets you export and import the configuration. This allows viewing exclusions, adding your own or changing the protection password. https://dmaasland.github.io/posts/mcafee.html …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Marina Simakov proslijedio/la je Tweet
Microsoft NTLM vulnerabilities could lead to full domain compromise - http://bit.ly/2MxRkiA -
@preemptsecurity@YaronZi@simakov_marina#NTLM#vulnerability@msftsecurity#cybersecuritypic.twitter.com/UG6BEim5st
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
If you liked the Drop The MIC vulnerability, be sure to check Drop The MIC 2 to see how we bypassed the original fix + an additional vulnerability abusing any client sending LMv2 responses to bypass the MIC, EPA & more.
@YaronZi@preemptsecurityhttps://www.preempt.com/blog/drop-the-mic-2-active-directory-open-to-more-ntlm-attacks/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
After issuing an advisory to turn on LDAP signing & channel binding,
#Microsoft is changing the default configuration (starting January 2020) to enable those settings. Really excited about this change! Especially after our latest NTLM Relay talks https://support.microsoft.com/en-us/help/4520412/2020-ldap-channel-binding-and-ldap-signing-requirement-for-windows …@YaronZiHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
If you weren’t in Vegas for
#BHUSA and#DEFCON,@YaronZi and I will be presenting the results of our NTLM research in a webinar this Tuesday, everyone is welcome, Q&A at the end included
https://www.preempt.com/events/webinar-how-we-bypassed-all-ntlm-relay-mitigations/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Marina Simakov proslijedio/la je Tweet
Muscular Dystrophy killed my mother, her brother, and her father. Now it's killing my sister. Here's my ask: if you have benefited from
#BloodHound, don't buy me a beer. Instead, donate whatever amount you can to MDA using this link:https://mda.donordrive.com/index.cfm?fuseaction=donorDrive.team&teamID=5703 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Marina Simakov proslijedio/la je Tweet
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV190023 … great to see
#microsoft is taking action to reduce#NTLM attack surface by advising customers to enable LDAP relay mitigations. We talked about these issues at our@defcon and@BlackHatEvents talks.@simakov_marinaHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.