w0rk3r's Windows Hacking Library
Open in Telegram
Manual job, I'm not a bot ;) @BlueTeamLibrary @W0rk3r
Show moreThe country is not specifiedTechnologies & Applications42 664
1 663
Subscribers
No data24 hours
No data7 days
No data30 days
Posts Archive
Reverse RDP Attack: The Hyper-V Connection
https://research.checkpoint.com/reverse-rdp-the-hyper-v-connection
@WindowsHackingLibrary
Hide *Exploitable* Extended-Rights (including DCSync privs) to remain persistence
https://medium.com/@huykha/hide-exploitable-extended-rights-to-remain-persistence-92a2e1d3670d
@WindowsHackingLibrary
Introducing Pingback Payloads
https://blog.rapid7.com/2019/08/01/introducing-pingback-payloads
@WindowsHackingLibrary
Analysing RPC With Ghidra and Neo4j
https://blog.xpnsec.com/analysing-rpc-with-ghidra-neo4j
@WindowsHackingLibrary
Credential theft without admin or touching LSASS with Kekeo by abusing CredSSP / TSPKG (RDP SSO)
https://clement.notin.org/blog/2019/07/03/credential-theft-without-admin-or-touching-lsass-with-kekeo-by-abusing-credssp-tspkg-rdp-sso
@WindowsHackingLibrary
CVE-2019–13382: Local Privilege Escalation in SnagIt
https://posts.specterops.io/cve-2019-13382-local-privilege-escalation-in-snagit-abe5f31c349
@WindowsHackingLibrary
Calling Syscalls Directly from Visual Studio to Bypass AVs/EDRs
https://ired.team/offensive-security/defense-evasion/using-syscalls-directly-from-visual-studio-to-bypass-avs-edrs
@WindowsHackingLibrary
eternalrelayx.py — Non-Admin NTLM Relaying & ETERNALBLUE Exploitation
https://medium.com/@technicalsyn/eternalrelayx-py-non-admin-ntlm-relaying-eternalblue-exploitation-dab9e2b97337
@WindowsHackingLibrary
The Return of Aggressor
https://rastamouse.me/2019/06/the-return-of-aggressor
@WindowsHackingLibrary
CVE-2019-1040 scanner
Checks for CVE-2019-1040 vulnerability over SMB. The script will establish a connection to the target host(s) and send an invalid NTLM authentication. If this is accepted, the host is vulnerable to CVE-2019-1040 and you can execute the MIC Remove attack with ntlmrelayx.
Note that this does not generate failed login attempts as the login information itself is valid, it is just the NTLM message integrity code that is absent, which is why the authentication is refused without increasing the badpwdcount.
https://github.com/fox-it/cve-2019-1040-scanner
@WindowsHackingLibrary
UNC Path Injection with Microsoft Access
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/unc-path-injection-with-microsoft-access
@WindowsHackingLibrary
DACL Permissions Overwrite Vulnerability in Check Point VPN
https://bordplate.no/blog/en/post/check-point-file-permissions-overwrite
@WindowsHackingLibrary
Stealthy & Targeted Implant Loaders
https://attactics.org/2019/06/21/stealthy-targeted-implant-loaders
@WindowsHackingLibrary
In NTDLL I Trust – Process Reimaging and Endpoint Security Solution Bypass
https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/in-ntdll-i-trust-process-reimaging-and-endpoint-security-solution-bypass
@WindowsHackingLibrary
Introducing Slackor, a Remote Access Tool Using Slack as a C2 Channel
https://www.coalfire.com/The-Coalfire-Blog/June-2019/Introducing-Slackor
Tool:
https://github.com/Coalfire-Research/Slackor
@WindowsHackingLibrary
Red Team Tactics: Combining Direct System Calls and sRDI to bypass AV/EDR
https://outflank.nl/blog/2019/06/19/red-team-tactics-combining-direct-system-calls-and-srdi-to-bypass-av-edr
@WindowsHackingLibrary
API Series: SetThreadContext
https://medium.com/tenable-techblog/api-series-setthreadcontext-d08c9f84458d
@WindowsHackingLibrary
Anti-VM Techniques with MSAcpi_ThermalZoneTemperature
https://medium.com/@DebugActiveProcess/anti-vm-techniques-with-msacpi-thermalzonetemperature-32cfeecda802
@WindowsHackingLibrary
Sliver: A general purpose cross-platform implant framework that supports C2 over Mutual-TLS, HTTP(S), and DNS.
https://github.com/BishopFox/sliver
@WindowsHackingLibrary
