ZeroDay UZ (lab)
Open in Telegram
292
Subscribers
No data24 hours
No data7 days
No data30 days
Posts Archive
Intelligence X Certificate (intelx.io) #leak
https://www.conholdate.app/viewer/view/y0b735UAEzz4/intelx.eml
intelx.io researcher API - 248
Key -
79dd7f59-55bb-4776-b1c7-ecdb9be20914
https://2.intelx.io/file/view?f=0&storageid={s_id}&bucket=leaks.private.general&k=79dd7f59-55bb-4776-b1c7-ecdb9be20914&license=researcher
Key - 9895c75d-2c11-47f6-bf6e-b582c41324dc
https://api.intelx.io/file/view?f=0&storageid={s_id}&bucket=leaks.logs&k=9895c75d-2c11-47f6-bf6e-b582c41324dc&license=researcher#Jenkins #RCE #CVE-2024-23897
https://github.com/kohsuke/args4j
https://github.com/binganao/CVE-2024-23897
CrowdStrike Falcon "Id" & "SecretToken"
falcon_windows_install.ps1 -FalconClientId <string> -FalconClientSecret <string>CVE-2024-20656: Windows LPE in the VSStandardCollectorService150 service
Blog: https://www.mdsec.co.uk/2024/01/cve-2024-20656-local-privilege-escalation-in-vsstandardcollectorservice150-service/
PoC: https://github.com/Wh04m1001/CVE-2024-20656
#lpe #exploit #redteam #pentest
CVE-2023-36003 (Windows LPE XAML diagnostics API)
Blog: https://m417z.com/Privilege-escalation-using-the-XAML-diagnostics-API-CVE-2023-36003/
PoC: https://github.com/m417z/CVE-2023-36003-POC
Исправлено в патче от 12 декабря
#lpe #ad #pentest #redteam
GTFONow
Automatic privilege escalation on unix systems by exploiting misconfigured setuid/setgid binaries, capabilities and sudo permissions. Designed for CTFs but also applicable in real world pentests.
https://github.com/Frissi0n/GTFONow