ZeroDay UZ (lab)
Open in Telegram
292
Subscribers
No data24 hours
No data7 days
No data30 days
Posts Archive
Ну это все... Портировали HVNC в BOF. Пока не тестил, но есть вопрос о работе в Linux
https://github.com/WKL-Sec/HiddenDesktop
#redteam #pentest #bof #cobaltstrike
Vulnerability Name: Oauth Misconfiguration Vulnerability
Severity: P3 (Medium)
Steps to Reproduce :
1). Go to https://www.fresha.com/auth?type=signup and Create a account using abc@gmail.com
2). Now Signup using Google account of abc@gmail.com
3). Change the email address from abc@gmail.com to bac@gmail.com
4). Verify the email change.
5). Now login using the Google account of abc@gmail.com.
Impact:
After the victim has changed the email, still the attacker has access to the account. Oauth should unlink once the user changes the email.
A Cobalt Strike profile, modified it, and bypassed Crowdstrike & Sophos without encrypting the shellcode. Also bypassed all published YARA rules, sleep detections, and string detections around a CS beacon.
Blog: https://whiteknightlabs.com/2023/05/23/unleashing-the-unseen-harnessing-the-power-of-cobalt-strike-profiles-for-edr-evasion/
#CyberSecurity #redteam #infosec
Для получения паролей пользователей SSH в открытом виде
https://github.com/jm33-m0/SSH-Harvester
#redteam #pentest #creds #git
Burp Suite Professional v2023.5.1 + JDK 18
NOTE -
Run this version With Java SE JDK 18
Released Friday, 19 May 2023
@zero_day_uz #pentest #security