en
Feedback
Pentester

Pentester

Open in Telegram

- Offensive Security (Red Teaming / PenTesting) - BlueTeam (OperationSec, TreatHunting, DFIR) - Reverse Engineering / Malware Analisys - Web Security

Show more
2 644
Subscribers
No data24 hours
+77 days
+3030 days
Posts Archive
Disable Windows Defender (+ UAC Bypass, + Upgrade to SYSTEM) https://github.com/EvilGreys/Disable-Windows-Defender-

ThievingFox - Remotely retrieving credentials from password managers and Windows utilities https://blog.slowerzs.net/posts/thievingfox/ https://github.com/Slowerzs/ThievingFox/

How to detect android malware using Random Forest Classifier and explain it use linearsvc https://github.com/liansecurityOS/android-malware-detection

Windows CLFS Driver Privilege Escalation This vulnerability targets the Common Log File System (CLFS) and allows attackers to escalate privileges and potentially fully compromise an organization’s Windows systems. In April 2023, Microsoft released a patch for this vulnerability and the CNA CVE-2023-28252 was assigned. Affects version: — Windows 11 21H2 (clfs.sys version 10.0.22000.1574); — Windows 11 22H2; — Windows 10 21H2; — Windows 10 22H2; — Windows Server 2022. Research: https://www.coresecurity.com/core-labs/articles/analysis-cve-2023-28252-clfs-vulnerability Exploit: https://github.com/duck-sec/CVE-2023-28252-Compiled-exe

CVE-2024-23897: Jenkins RCE https://github.com/binganao/CVE-2024-23897

Android-based PAX POS vulnerabilities (Part 1) - STM Cyber Blog https://blog.stmcyber.com/pax-pos-cves-2023/

Linux Kernel GSM Multiplexing Race Condition Local Privilege Escalation Vulnerability (CVE-2023-6546) https://github.com/Nassim-Asrir/ZDI-24-020/

CVE-2024-0204: Authentication Bypass in GoAnywhere MFT Script to create a new admin user in GoAnywhere MFT. https://github.com/horizon3ai/CVE-2024-0204 https://www.horizon3.ai/cve-2024-0204-fortra-goanywhere-mft-authentication-bypass-deep-

I Tried 100+ Hacking Tools. These Are The Best! https://www.youtube.com/watch?v=4WqymtvuWZQ

An introduction to reverse engineering .NET AOT applications https://harfanglab.io/en/insidethelab/reverse-engineering-ida-pro-aot-net/

Exploiting 0-click Android Bluetooth vulnerability to inject keystrokes without pairing - Mobile Hacker https://www.mobile-hacker.com/2024/01/23/exploiting-0-click-android-bluetooth-vulnerability-to-inject-keystrokes-without-pairing/

CVE-2024-0517: Google Chrome V8 Out-of-Bounds Write Code Execution PoC: https://blog.exodusintel.com/2024/01/19/google-chrome-v8-cve-2024-0517-out-of-bounds-write-code-execution/

Outlook Vulnerability Discovery and New Ways to Leak NTLM Hashes https://www.varonis.com/blog/outlook-vulnerability-new-ways-to-leak-ntlm-hashes

How to retrive all information about Windows Extended Rights via LDAP https://github.com/YuryStrozhevsky/extendedRights

CVE-2023-7028: Gitlab Account Takeover via Password Reset PoC 1: https://github.com/RandomRobbieBF/CVE-2023-7028 PoC 2: https://github.com/Vozec/CVE-2023-7028 * 16.1 prior to 16.1.5 * 16.2 prior to 16.2.8 * 16.3 prior to 16.3.6 * 16.4 prior to 16.4.4 * 16.5 prior to 16.5.6 * 16.6 prior to 16.6.4 * 16.7 prior to 16.7.2

Writeup for CVE-2023-39143: PaperCut WebDAV Vulnerability – Horizon3. ai https://www.horizon3.ai/writeup-for-cve-2023-39143-papercut-webdav-vulnerability/