Pentester
Open in Telegram
- Offensive Security (Red Teaming / PenTesting) - BlueTeam (OperationSec, TreatHunting, DFIR) - Reverse Engineering / Malware Analisys - Web Security
Show more2 644
Subscribers
No data24 hours
+77 days
+3030 days
Posts Archive
2 644
Apache Superset Part II: RCE, Credential Harvesting and More
https://www.horizon3.ai/apache-superset-part-ii-rce-credential-harvesting-and-more/
2 644
Leveraging VSCode Extensions for Initial Access
https://www.mdsec.co.uk/2023/08/leveraging-vscode-extensions-for-initial-access/
2 644
Vcenter Comprehensive Penetration and Exploitation Toolkit
https://github.com/W01fh4cker/VcenterKit
2 644
Living Off the Foreign Land
Part 1/3: Setup Linux VM for SOCKS routing
https://blog.bitsadmin.com/living-off-the-foreign-land-windows-as-offensive-platform
Part 2/3: Configuring the Offensive Windows VM
https://blog.bitsadmin.com/living-off-the-foreign-land-windows-as-offensive-platform-part-2
Using Windows as Offensive Platform
https://blog.bitsadmin.com/living-off-the-foreign-land-windows-as-offensive-platform-part-3
2 644
Cross Platform Telegram based RAT that communicates via telegram to evade network restrictions
https://github.com/machine1337/TelegramRAT
2 644
2 644
This allows you to spoof emails from any of the +2 Million domains using MailChannels. It also gives you a slightly higher chance of landing a spoofed emails from any domain that doesn't have an SPF & DMARC due to ARC adoption.
https://github.com/byt3bl33d3r/SpamChannel
2 644
Diving into Windows Remote Access Service for Pre-Auth Bugs
https://i.blackhat.com/BH-US-23/Presentations/US-23-YukiChen-Diving-into-Windows-Remote-Access.pdf
2 644
100 Methods for Container Attacks(RTC0010)
https://redteamrecipe.com/100-Method-For-Container-Attacks/
2 644
Proof of Concept for CVE-2023-38646
This vulnerability has been declared as critical, because it allows an unauthenticated attacker to execute arbitrary commands with the same privileges as the Metabase server. This vulnerability means the Metabase server can become a potential entry point for malicious attacks, which could compromise the integrity of the whole system it operates on.
https://github.com/Zenmovie/CVE-2023-38646
2 644
It's a tool to interact with remote hosts using the Windows Search Protocol and coerce authentication. The target host will connect over SMB to the listener host using the machine account.
https://github.com/slemire/WSPCoerce
2 644
KRBUACBypass
By adding a KERB-AD-RESTRICTION-ENTRY to the service ticket, but filling in a fake MachineID, we can easily bypass UAC and gain SYSTEM privileges.
Research:
https://www.tiraniddo.dev/2022/03/bypassing-uac-in-most-complex-way.html
Source:
https://github.com/wh0amitz/KRBUACBypass
2 644
Escalating Privileges via Third-Party Windows Installers
https://www.mandiant.com/resources/blog/privileges-third-party-windows-installers
https://github.com/mandiant/msi-search
2 644
Critical Zero-Day Vulnerability in Citrix NetScaler ADC and NetScaler Gateway
https://www.rapid7.com/blog/post/2023/07/18/etr-critical-zero-day-vulnerability-in-citrix-netscaler-adc-and-netscaler-gateway/
2 644
RMM – ScreenConnect: Client-Side Evidence
https://dfirtnt.wordpress.com/2023/07/14/rmm-screenconnect-client-side-evidence/
