996
订阅者
无数据24 小时
无数据7 天
无数据30 天
帖子存档
996
👩💻netfilter: nf_tables: prevent OOB access in nft_byteorder_eval(Exploited on Pwn2Own, CVE-2023-35001)
🟥Kernel : https://lore.kernel.org/netfilter-devel/20230705121515.747251-1-cascardo@canonical.com/T/
🫥Exp : https://github.com/synacktiv/CVE-2023-35001
⛔#Exp , #POC , #CVE , #Kernel , #Vulnerability
📱@APTANALYSIS
996
😊Converting Tokens to Session Cookies for Outlook Web Application
⭐️https://labs.lares.com/owa-cap-bypass
⛔#Outlook , #Bypass , #Token
📱@APTANALYSIS
996
👩💻NetNTLMv1 Downgrade to compromise
🐈Blog : https://www.r-tec.net/r-tec-blog-netntlmv1-downgrade-to-compromise.html
⛔#RedTeam , #Offensive , #Attacks
📱@APTANALYSIS
996
🔥Supernova (Shellcode Encryptor)
➡️Repo : https://github.com/nickvourd/Supernova
⛔#shellcode , #Encrypt
📱@APTANALYSIS
996
🖥Analysis CVE-2023-29357 : Microsoft SharePoint < 16.0.10399.2000 ValidateTokenIssuer Authentication Bypass Vulnerability
😈VNPT : https://sec.vnpt.vn/2023/08/phan-tich-cve-2023-29357-microsoft-sharepoint-validatetokenissuer-authentication-bypass-vulnerability/
⛓REF : https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29357
⛓REF : https://www.zerodayinitiative.com/advisories/ZDI-23-882/
⛔#SharePoint , #Privilege , #Vulnerability
📱@APTANALYSIS
996
👩💻Bypassing Defender’s LSASS dump detection and PPL protection In Go
🌩Link : https://tastypepperoni.medium.com/bypassing-defenders-lsass-dump-detection-and-ppl-protection-in-go-7dd85d9a32e6
⛔#Bypass , #Defender , #LSASS
📱@APTANALYSIS
996
🧠Mashing Enter to bypass full disk encryption with TPM, Clevis, dracut and systemd
☕️ Link : https://pulsesecurity.co.nz/advisories/tpm-luks-bypass
⛔#Bypass , #TPM
📱@APTANALYSIS
996
🔥Phishing with Visual Studio Code (Leveraging VSCode Extensions for Initial Access)
🐈 Link : https://www.mdsec.co.uk/2023/08/leveraging-vscode-extensions-for-initial-access/
⛔#VSCode , #review , #phishing
📱@APTANALYSIS
996
⭐️CVE-2023-34039 : VMWare Aria Operations SSH auth bypass
🌟Auth is possible with a fixed private key
🌟Key is version dependent
🌟Host key is the same for ALL version
🔴Host key :
SHA256:tpcfUoQB+n2Wf6tDNm/YPA7DSwwzFjx3B7cnRC2apZ0
➡️Not Tested :()
⛔#Bypass , #Vulnerability
📱@APTANALYSIS
996
🖥CVE-2023-32524 : Trend Micro Mobile Security (Enterprise) 9.8 SP5 (<= Critical Patch 3) Unauthenticated RCE
🟢POC/ ANALYSIS : https://blogs.jpcert.or.jp/en/2023/08/maldocinpdf.html
⛔#PoC , #Exploit , #Vulnerability , #ANALYSIS
📱@APTANALYSIS
996
😠Evil Lsass Twin
⭐️Tree : https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin
⛔#LSASS , #EvilTwin
📱@APTANALYSIS
996
⭐️Chariot
🌟A Deep Dive into Brute Ratel C4 payloads
🟢https://cybergeeks.tech/a-deep-dive-into-brute-ratel-c4-payloads/
🌟A step-by-step introduction to the use of ROP gadgets to bypass DEP
🟣https://cybergeeks.tech/a-step-by-step-introduction-to-the-use-of-rop-gadgets-to-bypass-dep/
🌟A technical analysis of the SALTWATER backdoor used in Barracuda 0-day vulnerability (CVE-2023-2868) exploitation
🟣https://cybergeeks.tech/a-technical-analysis-of-the-saltwater-backdoor-used-in-barracuda-0-day-vulnerability-cve-2023-2868-exploitation/
🌟A technical analysis of Pegasus for Android – Part 1,2,3
🟣https://cybergeeks.tech/a-technical-analysis-of-pegasus-for-android-part-1/
🟢https://cybergeeks.tech/a-technical-analysis-of-pegasus-for-android-part-2/
🟣https://cybergeeks.tech/a-technical-analysis-of-pegasus-for-android-part-3/
⛔#C4 , #Payload , #bypass , #CVE , #ANALYSIS , #Android , #Attacks
📱@APTANALYSIS
996
🍵Nessus For Windows
⚠️ Not Tested
⭐️Transfer all content to the server.
⭐️This content is published by pwn.
⛔#Nessus , #Scanners #Vuln_Scanners
📱@APTANALYSIS
996
Nessus WINDOWS 10.6.0+20230830 plugin set
Network security scanner.
resources but forgot to drop it here.
996
🔴🔴🔴MobinNet, Vulnerable forever (KZTech AirMaster AG3100* Router — Remote Code Execution Vulnerability )
🟢POC / WriteUp : https://medium.com/@aryanchehreghani/kztech-airmaster-ag3100-router-remote-code-execution-vulnerability-16d6cfe86886
⛔#Exploit , #PoC , #WriteUp , #vulnerabilities
📱@APTANALYSIS
996
⭐️Vcenter Comprehensive Penetration and Exploitation Toolkit
🙂Repo : https://github.com/W01fh4cker/VcenterKit
⛔#TOOLS , #Exploit
📱@APTANALYSIS
996
🖥MalDoc in PDF - Detection bypass by embedding a malicious Word file into a PDF file
😁Link : https://blogs.jpcert.or.jp/en/2023/08/maldocinpdf.html
⛔#Read
📱@APTANALYSIS
996
💰Google Extensions (Awarded $18833.7)
📌Link : https://ndevtk.github.io/writeups/2023/08/18/extensions/
👍Other : https://ndevtk.github.io/writeups/
⛔#Bug_Bounty , #Hunting
📱@APTANALYSIS
996
📌Automatically Generate Rulesets for Apache mod_rewrite or Nginx for Intelligent HTTP C2 Redirection ''Convert Cobalt Strike profiles to modrewrite scripts''
➡️Repo : https://github.com/threatexpress/cs2modrewrite
⛔#RedTeam . #Offensive , #C2
📱@APTANALYSIS
996
⭐️How I Escalated a Time-Based SQL Injection to RCE
🟫Write-Up : https://infosecwriteups.com/how-i-escalated-a-time-based-sql-injection-to-rce-bbf0d68cb398
⛔#Bug_Bounty , #Hunting , #Hackerone
📱@APTANALYSIS
