Zer0day Lab
Open in Telegram
Information must flow free, money kill it provided with 🖤 by Zer0DayLab 🦊 Cres
Show more333
Subscribers
No data24 hours
No data7 days
No data30 days
Posts Archive
333
ELITEWOLF is on the hunt! NSA released a repository of signatures and analytics to secure Operational Technology
https://github.com/nsacyber/ELITEWOLF
#security #nsacyber
333
Visual Studio 1-click RCE: A New Exploitation Technique for Visual Studio Projects
https://github.com/cjm00n/EvilSln
#initial #fishing #redteam #pentest #git
333
BOFRYPTOR: ENCRYPTING YOUR BEACON DURING BOF EXECUTION TO AVOID MEMORY SCANNERS
https://www.securify.nl/blog/bofryptor-encrypting-your-beacon-during-bof-execution-to-avoid-memory-scanners/
POC:
https://github.com/securifybv/BOFRyptor
333
Cobalt Strike 4.9 Licensed
c0565d03d5f6335311927c6f93f3f5689804da596e6734b1ac26bf4b12cc85ed
verify.cobaltstrike.com333
MSIFortune - Local Privilege Escalation with MSI Installers
The repair function often triggers CustomActions, which can lead to several potential issues:
— Visible conhost.exe via a cmd.exe or other console binaries
— Visible PowerShell
— Directly actions from the installer with SYSTEM privileges
— Executing binaries from user writable paths
— DLL sideloading / search path abusing
— Missing PowerShell parameters, mostly -NoProfile
— Execution of other tools in an unsafe manner
Details:
https://badoption.eu/blog/2023/10/03/MSIFortune.html
#windows #msi #lpe333
Arsenal Kit 2023/09/19
https://verify.cobaltstrike.com/arsenal-kit.txt
df6b13fb04f267fa4424841526daea37c9bf804b996bcae9ccc4f3b007174802333
Local Privilege Escalation in the glibc's ld.so (CVE-2023-4911)
https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt
POC: https://github.com/leesh3288/CVE-2023-4911
#expdev #linux #lpe #Alexs3y
