ch
Feedback
Hacker Notes

Hacker Notes

前往频道在 Telegram

Notes about everything related to hacking! #RedTeam Contact: @ADExplorer

显示更多
373
订阅者
无数据24 小时
无数据7 天
+830 天
帖子存档
Group Policy Nightmares
In the realm of IT administration, Group Policies serve as a powerful tool for centrally managing and controlling various aspects of an Active Directory network environment in a Windows-based operating system. They provide a way to enforce consistent settings and configurations across multiple computers and user accounts within a domain or organizational unit. In this (hopefully) series of posts, I’ll describe some of the most unusual, and potentially dangerous configurations, I’ve encountered over my years of experience. 😉
https://decoder.cloud/2024/11/08/group-policy-security-nightmares-pt-1/ 🔗 @hackern0tes

Breaking Down Multipart Parsers: File upload validation bypass
Basically, all multipart/form-data parsers fail to fully comply with the RFC, and when it comes to validating filenames or content uploaded by users, there are always numerous ways to bypass validation. We'll test various bypass techniques against PHP, Node.js, and Python parsers, as well as popular WAFs and load balancers like HAProxy, FortiWeb, Barracuda, and even some OpenResty Lua multipart parsers.
https://blog.sicuranext.com/breaking-down-multipart-parsers-validation-bypass/ 🔗 @hackern0tes

Top 4 new attack vectors in web application targets
Table of contents 1) LLM prompt injection attacks 2) Prototype pollution 3) Client-side path traversals 4) Dependency confusion Conclusion
https://blog.intigriti.com/hacking-tools/top-4-new-attack-vectors-in-web-application-targets 🔗 @hackern0tes

Silencing the EDR Silencers By: Jonathan Johnson
As many security practitioners know, tampering with Endpoint Detection and Response (EDR) products is a deep desire for threat actors and red teamers alike. I spoke about this briefly at BlackHat this year in my “EDR Blinded, Now What?” Huntress booth talk.
https://www.huntress.com/blog/silencing-the-edr-silencers 🔗 @hackern0tes

CVE-2024-10114 The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.7.7. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token. https://www.wordfence.com/threat-intel/vulnerabilities/id/71df23bf-8f51-4260-be1f-ed5bc29d4afe?source=cve 🔗 @hackern0tes

An Offer You Can Refuse: UNC2970 Backdoor Deployment Using Trojanized PDF Reader | Google Cloud Blog UNC2970 is a cyber espionage group suspected to have a North Korea nexus. https://cloud.google.com/blog/topics/threat-intelligence/unc2970-backdoor-trojanized-pdf-reader #mandiant #threat 🔗 @hackern0tes

Detecting and Mitigating Active Directory Compromises #NSA #ActiveDirectory #AD
This guidance – authored by the Australian Signals Directorate (ASD), the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), the Canadian Centre for Cyber Security (CCCS), the New Zealand National Cyber Security Centre (NCSC-NZ), and the United Kingdom’s National Cyber Security Centre (NCSC-UK) – aims to inform organisations about 17 common techniques used to target Active Directory as observed by the authoring agencies. This guidance provides an overview of each technique and how it can be leveraged by malicious actors, as well as recommended strategies to mitigate these techniques. By implementing the recommendations in this guidance, organisations can significantly improve their Active Directory security, and therefore their overall network security, to prevent intrusions by malicious actors.
🔗 @hackern0tes

TA Phone Home: EDR Evasion Testing Reveals Extortion Actor's Toolkit #EDR #Bypass https://unit42.paloaltonetworks.com/edr-bypass-extortion-attempt-thwarted/
In a recent investigation involving an extortion attempt, we discovered a threat actor had purchased access to the client network via Atera RMM from an initial access broker. We discovered the threat actor used rogue systems to install the Cortex XDR agent onto a virtual system. They did this to test a new antivirus/endpoint detection and response (AV/EDR) bypass tool leveraging the bring your own vulnerable driver (BYOVD) technique.
🔗 @hackern0tes

LOL Collection Collection of Living Off The Lands ! https://lolapps-project.github.io 1️⃣ LOLAD 2️⃣ UNIX binaries 3️⃣ Windows binaries 4️⃣ LOLESXi 5️⃣ A collection of resources to thrive off the land 🔗 @hackern0tes

New SteelFox malware hijacks Windows PCs using vulnerable driver A new malicious package called 'SteelFox' mines for cryptocurrency and steals credit card data by using the "bring your own vulnerable driver" technique to get SYSTEM privileges on Windows machines. [...] 🔗 @hackern0tes

🚨 CVE-2024-9488 The Comments – wpDiscuz plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.6.24. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token. 🔗 @hackern0tes

New LOL project, LOLAD A collection of Active Directory techniques!👇 https://lolad-project.github.io/ 🔗 @hackern0tes
New LOL project, LOLAD A collection of Active Directory techniques!👇 https://lolad-project.github.io/ 🔗 @hackern0tes

Hiding C2 behind Microsoft Teams! ;)
Command and Control infrastructure that allows Red Teamers to execute system commands on compromised hosts through Microsoft Teams.
https://github.com/cxnturi0n/convoC2 🔗 @hackern0tes

Kekz Headphones hardware and firmware reverse engineering (embedded) https://nv1t.github.io/blog/kekz-headphones/ 🔗 @hackern0tes

Evil MSI. A story about vulnerabilities in MSI Files Published in 2024 🔗 @hackern0tes

Living Off The Land ESXi LOLESXi features a comprehensive list of binaries/scripts natively available in VMware ESXi that adversaries have utilised in their operations. The information on this site is compiled from open-source threat research. #lolesxi #ESXi #vmware @hackern0tes

CVE-2024-8956, #CVE-2024-8957: How to Steal a 0-Day #RCE (With a Little Help from an LLM) https://www.labs.greynoise.io/grimoire/2024-10-31-sift-0-day-rce/ 🔗 @hackern0tes

Repost from The Hacker News
⚠️ Researchers have uncovered EMERALDWHALE, a massive campaign exploiting exposed Git configurations to siphon over 15,000 credentials and clone 10,000 private repositories. Read: https://thehackernews.com/2024/11/massive-git-config-breach-exposes-15000.html

NukeAMSI A powerful tool designed to neutralize the Antimalware Scan Interface (AMSI) in Windows environments. https://github.com/anonymous300502/Nuke-AMSI 🔗 @hackern0tes