Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @splinter_code
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @splinter_code
-
Prikvačeni tweet
#Juicypotato knocked to our door and wanted to get listen and ... we kindly answered! From Service Account to SYSTEM again cc@decoder_it 0xea31(@DonkeysTeam)https://decoder.cloud/2019/12/06/we-thought-they-were-potatoes-but-they-were-beans/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Antonio Cocomazzi proslijedio/la je Tweet
Had fun playing with
@tiraniddo fantastic ntobjectmanager :-)https://decoder.cloud/2020/02/05/the-strange-rpc-interface-ms-are-you-trolling-me/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Antonio Cocomazzi proslijedio/la je Tweet
Seems that league of legends has an anti cheat kernel driver now - interesting to find out what will do - https://euw.leagueoflegends.com/en-gb/news/dev/dev-null-anti-cheat-kernel-driver/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Antonio Cocomazzi proslijedio/la je Tweet
#RomHack2020 is looking for speakers The Call for Papers#CFP closes on May 3rd (23:59 CEST) Theme: Attack and Defense The focus is on pratical knowledge Presentation slots are 45 minutes Check RomHack website to get more info and submit your proposal https://www.romhack.io/cfp-2020.html pic.twitter.com/f2q63DrXI8
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Antonio Cocomazzi proslijedio/la je Tweet
Can your EDR detect symbolic link callback rootkits? Because ours sure as heck can't.
@aionescu and I wrote about these! https://windows-internals.com/dkom-now-with-symbolic-links/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Antonio Cocomazzi proslijedio/la je Tweet
SettingSyncHost.exe as a LolBin http://www.hexacorn.com/blog/2020/02/02/settingsynchost-exe-as-a-lolbin/ …
#LOLBIN cd %TEMP% & c:\windows\system32\SettingSyncHost.exe -LoadAndRunDiagScript foopic.twitter.com/dOM4EHq4ZuHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Antonio Cocomazzi proslijedio/la je Tweet
From Hyper-V Admin to SYSTEM : https://decoder.cloud/2020/01/20/from-hyper-v-admin-to-system/ … cc
@decoder_it Small POC in powershell exploiting hardlinks during the VM deletion process :https://github.com/decoder-it/Hyper-V-admin-EOP …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Antonio Cocomazzi proslijedio/la je Tweet
For today "side lolbin" let's say thanks to: ZOHO Corporation private Limited with their dctask64.exe. Keep injecting all the dll we want with: dctask64.exe injectDll <dllpath> <PID> bonus point: we have the outputs!!! cc
@Oddvarmoe@Hexacorn https://www.virustotal.com/gui/file/a1b55abba46db5836ab3050bd754aed462e7361744e7f9f6ab55427ecb35d761/relations …pic.twitter.com/x1B6bNQk6J
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Antonio Cocomazzi proslijedio/la je Tweet
we have an update to DTrace on Windows. with the latest 20H1 insider build, no more KD required to use dtrace on windows. plus arm64 MSI.https://techcommunity.microsoft.com/t5/windows-kernel-internals/dtrace-on-windows-20h1-updates/ba-p/1127929 …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Antonio Cocomazzi proslijedio/la je Tweet
Be a regular user, face "Access Denied" when starting a system service, inject false ETW trigger to make it starting anyway. Fully working PoC for wersvc: https://github.com/gtworek/PSBits/blob/master/Services/StartByEtw.c …
#WindowsInternals#securitypic.twitter.com/SqyGbYxJE2
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Antonio Cocomazzi proslijedio/la je Tweet
Full analysis and exploit for Windows kernel ws2ifsl use-after-free (CVE-2019-1215) by our researcher
@flxflndy https://labs.bluefrostsecurity.de/blog/2020/01/07/cve-2019-1215-analysis-of-a-use-after-free-in-ws2ifsl/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Antonio Cocomazzi proslijedio/la je Tweet
As promised, a short post on Hyper-V admin privesc: https://decoder.cloud/2020/01/20/from-hyper-v-admin-to-system/ … /cc
@padovah4ck@mkolsekHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Antonio Cocomazzi proslijedio/la je Tweet
"Analyzing Modern Malware Techniques - Part 1" by
@danusminimushttps://0x00sec.org/t/analyzing-modern-malware-techniques-part-1/18663 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Antonio Cocomazzi proslijedio/la je Tweet
"
#ShadowMove: a Stealthy Lateral Movement Strategy" is now available to read Read if interested to see a new practical lateral movement https://usenix.org/conference/usenixsecurity20/presentation/niakanlahiji … Demo (TDS (MS SQL) & FTP): https://uofi.app.box.com/folder/93023403411 … Prototype will be released soon@MITREattack@USENIXSecurityPrikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Antonio Cocomazzi proslijedio/la je Tweet
Want to make service removal really fun? Create a service with a unicode name. The service will run but won't show in sc.exe, services.msc, or taskmgr.exe and will sometimes cause a critical error while trying to find it with PowerShell/WMI. Unicode wins again.
pic.twitter.com/qiAoSya623
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Antonio Cocomazzi proslijedio/la je Tweet
I've been poking around the Windows kernel a lot lately and one of my favorite samples I've referenced is Mimikatz's driver, Mimidrv. I took some time and documented all of its functions and included some write-ups on important kernel structures. Post: https://posts.specterops.io/mimidrv-in-depth-4d273d19e148 … 1/3
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Antonio Cocomazzi proslijedio/la je Tweet
Here's the Gist to do both BlockDLLs and PPID Spoof: https://gist.github.com/rasta-mouse/af009f49229c856dc26e3a243db185ec … Both ALWAYS_ON & ALLOW_STORE seem to work. On my machine, MSEdge runs with ALLOW_STORE, so maybe better for blending in?https://twitter.com/_RastaMouse/status/1216295601673048064 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Antonio Cocomazzi proslijedio/la je Tweet
From Hyper-V admin to full system compromise.. coming soon ;-) cc
@padovah4ckpic.twitter.com/gHUK85FcY1
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
splintercode just got 1st blood owning system on Monteverde ! https://www.hackthebox.eu di
@hackthebox_euHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Antonio Cocomazzi proslijedio/la je Tweet
I'm very excited to share my blogpost series (including PoC code) about a remote, interactionless iPhone exploit over iMessage: https://googleprojectzero.blogspot.com/2020/01/remote-iphone-exploitation-part-1.html …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Antonio Cocomazzi proslijedio/la je Tweet
Have reproduced Citrix SSL VPN pre-auth RCE successfully on both local and remote. Interesting bug!https://www.tripwire.com/state-of-security/vert/citrix-netscaler-cve-2019-19781-what-you-need-to-know/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.