4 580
Subscribers
No data24 hours
-157 days
-8530 days
Posts Archive
4 580
Phishing for Primary Refresh Tokens and Windows Hello keys
Through analyzing the token flows used during the Windows setup, I found out that the process starts by signing in to a specific application, which gives Windows an access token and a refresh token. The access tokens can be used to join the device to Azure AD and set up the device identity. After the device registration, the refresh token which was issued without a device, is used with the new device identity to request a Primary Refresh Token. To me this is quite a clear violation of the token security architecture. We can use a regular refresh token, that is not tied to a device but is tied to a specific app, to first register a device and then request a more powerful token that can be used in any sign-in scenario.
If you want to read up on this technique, here are some references:
☢️ https://aadinternals.com/post/phishing/
☢️ https://0xboku.com/2021/07/12/ArtOfDeviceCodePhish.html
☢️ https://github.com/secureworks/squarephish
☢️ https://www.blackhillsinfosec.com/dynamic-device-code-phishing/
☢️ https://gist.github.com/rvrsh3ll/b8bfc113acf5726746929bef2e620f8d
☢️ https://github.com/rvrsh3ll/TokenTactics
DeviceCode2WinHello
A small script that automates Entra ID persistence with Windows Hello For Business key
4 580
🌐 The Pool Party You Will Never Forget: New Process Injection Techniques Using Windows Thread Pools
See how SafeBreach Labs Researchers developed a brand new set of highly flexible process injection techniques that are able to completely bypass leading endpoint detection and response (EDR) solutions.
💉 PoolParty
A collection of fully-undetectable process injection techniques abusing Windows Thread Pools.
PoolParty Variants:
1 - Overwrite the start routine of the target worker factory
2 - Insert TP_WORK work item to the target process's thread pool
3 - Insert TP_WAIT work item to the target process's thread pool
4 - Insert TP_IO work item to the target process's thread pool
5 - Insert TP_ALPC work item to the target process's thread pool
6 - Insert TP_JOB work item to the target process's thread pool
7 - Insert TP_DIRECT work item to the target process's thread pool
8 - Insert TP_TIMER work item to the target process's thread pool
4 580
Repost from 𝖢reatorz 𝖠cademy ♞
+1
Those Who don't Star Mining PI Coin Star Now
Using Below Link
https://minepi.com/itxuserdied
4 580
👩🚒 Spotify Mod for Windows 👩🚒
1️⃣ First Install the Latest Official Version (Do not install it from the Microsoft Store)
2️⃣ 🎵 Run the following command in PowerShell:
iex "& { $(iwr -useb 'https://raw.githubusercontent.com/SpotX-Official/spotx-official.github.io/main/run.ps1') } -new_theme"
3️⃣ Enjoy Free Spotify Premium!
🖥 GitHub:
[SpotX Official GitHub]
Enjoy an enhanced Spotify experience! 🎧
4 580
📒 Scott Stockdale - 180 Days of Freelance Writing (Ebook)
✔️Sales page : https://scottstockdale.gumroad.com/l/180days
🔥 I wanted to show aspiring freelancers what it takes to land clients, get paid, and everything in between!
🔥 PDF book containing: My LinkedIn posts from the past 180 days - My popular templates - My Facebook Q&A posts - Six monthly income reports + Juicy bonuses !
⬇️Download Ebook below
4 580
VMware Workstation 17 Pro
Price: $199.00 but FREE for you
Keys:
AZ510-6TF8P-4840Z-HQQ7E-Z3KC4
GF340-0EY1P-M8EHY-4YP7G-YYUE0
CV79H-23F10-08DGP-UMN5X-XLUY0
YG1MA-FAE4J-080RP-GPQ7T-PY894
YC7NA-28Z9Q-489QY-R6XQE-NQAXF
AV5TH-69DE6-H80ZZ-VFN59-ZGAT6
ZY35K-DAY12-485EZ-GZQGE-XZAD0
ZA5RH-4HX41-48D6Z-5QY79-XVUG8
FY5H0-86D0M-48DZZ-PNWZC-NVUU6
FG1JU-4DE9H-481AZ-PEPEX-NCKEF
VZ7T0-A7D8N-088TP-RPY7T-WLHFD
ZY5T2-F4G9H-480XP-1FXGG-QYUW6
GZ5R8-F8W03-M8D8Q-2GM5V-W3URD
VC7XK-05F0Q-484XY-CZPNE-MF2Z2
YY54K-FNY8Q-480JZ-VYW5C-ZFRZD
AY7E8-AFEEQ-080QZ-8MQEC-MG0Y2
VZ34K-6AG01-M816Q-A7WNX-MV2T6
AU5MK-6ZD0M-480LY-2YNZC-P3HVA
FV7JK-88G92-M84CY-XENZV-P28TF
CF3DH-A6D02-085XY-FGP7E-QUARF
VY3RH-FFYD3-08EEY-UYNNZ-ZQHV0
4 580
[ Specula - Turning Outlook Into a C2 With One Registry Change ]
There exist a few singular Registry changes that any non-privileged user can make that transform the Outlook email client into a beaconing C2 agent. Given that outlook.exe is a trusted process, this allows an attacker persistent access to a network that we have found often goes unnoticed. This technique has been reported on before and despite that continues to be a weak point in many otherwise very well-guarded networks.
Blog (with detection and prevention guides): https://trustedsec.com/blog/specula-turning-outlook-into-a-c2-with-one-registry-change
☢️ Tool: https://github.com/trustedsec/specula
☢️ Wiki: https://github.com/trustedsec/specula/wiki
Written by Christopher Paschen and Oddvar MoeCredit : TrustedSec Thanks
4 580
CLICKMINDED📰
SEO SOP TOOLKIT
Your one reaction
Medicine of our hardwork
✨Share & Support Us
4 580
✔️ CLICKMINDED — SEO SOP TOOLKIT
👑 What You’ll Get 👑
This is a comprehensive training and resource bundle designed for digital marketers, SEO professionals, and business owners seeking to master search engine optimization. This toolkit is essentially a collection of templates, guidelines, and processes that demystify the complexities of SEO. It offers a structured approach to executing SEO tasks, ensuring consistency in implementation while maximizing effectiveness. From keyword research and on-page optimization to content strategy and link building, this toolkit covers a wide range of SEO techniques, and provides the necessary tools, and strategies to enhance their SEO efforts effectively.
🧑💻 Sales page
https://www.clickminded.com/seo-toolkit-sp/
☁️ Mega folder
https://mega.nz/folder/3uQTEDYC#1024xwBHZEDtr0iJXrahTw
Files Uploaded Below 👇🏻
4 580
🗿 Rootkits Complete Course 🗿
⚙ Rootkits (Part 1): Introduction and Overview ⚙ Rootkits (Part 2): High-Level Techniques ⚙ Rootkits (Part 3): Direct Kernel Object Manipulation ⚙ Rootkits (Part 4): Import Address Table Hooking ⚙ Rootkits (Part 5): Inline Function Patching -- Detours ⚙Rootkits (Part 6): Defense via Cross-View Detection ⚙ Rootkits (Part 7): Signature-Based Defense ⚙
Rootkits (Part 8): Defense via Hook DetectionThanks
4 580
Repost from ʜᴀᴄᴋꜱ 4 ʜᴀᴄᴋᴇʀꜱ
🖥 Find and execute WinAPI functions with Assembly
If you want to take a happy little journey through PEB structs, PE headers and kernel32.dll Export Table to spawn some "calc.exe" on x64 using Assembly, here it is.
📚 What you will learn:
— WinAPI function manual location with Assembly;
— PEB Structure and PEB_LDR_DATA;
— PE File Structure;
— Relative Virtual Address calculation;
— Export Address Table (EAT);
— Windows x64 calling-convention in practice;
— Writing in Assembly like a real Giga-Chad...
☢️ Source:
https://print3m.github.io/blog/x64-winapi-shellcoding
Thanks
4 580
updated exploit development resources for learning:
https://github.com/0xZ0F/Z0FCourse_ReverseEngineering
https://crackmes.one
https://0xresetti.github.io
https://github.com/jeffssh/exploits
https://malwareunicorn.org/workshops/re101.html#0
https://www.youtube.com/watch?v=qSnPayW6F7U
https://twitter.com/pedrib1337/status/1696169136991207844?s=46
https://www.pentesteracademy.com/course?id=3
https://nora.codes/tutorial/an-intro-to-x86_64-reverse-engineering/
https://www.reddit.com/r/ExploitDev/comments/7zdrzc/exploit_development_learning_roadmap/
https://github.com/Cryptogenic/Exploit-Writeups
https://www.youtube.com/@pwncollege/videos
https://repo.zenk-security.com/Magazine%20E-book/Hacking-%20The%20Art%20of%20Exploitation%20(2nd%20ed.%202008)%20-%20Erickson.pdf
http://www.phrack.org/issues/49/14.html#article
https://github.com/justinsteven/dostackbufferoverflowgood
https://github.com/FabioBaroni/awesome-exploit-development
https://github.com/CyberSecurityUP/Awesome-Exploit-Development
https://github.com/RPISEC/MBE
https://github.com/hoppersroppers/nightmare
https://github.com/shellphish/how2heap
https://www.youtube.com/watch?v=tMN5N5oid2c
https://dayzerosec.com/blog/2021/02/02/getting-started.html
https://github.com/Tzaoh/pwning
Thanks
4 580
Repost from 𝖢reatorz 𝖠cademy ♞
🐶 Blackhat Hacking Basics to Some Money Earning Ways
▫️about : click here
▫️duration : 5hr+
▫️topic : blàckhathàcking
▫️uploader : mrdrastic
🫡 Your One Reaction, Medicine of Our HardWork......👤 Share us : @HackGyan
4 580
👩💻 Prompt Engineering Tutorial – Master Chat GPT and LLM Responses
Learn prompt engineering techniques to get better results from Chat GPT and other LLMs.⭐️ Contents ⭐️ ⌨️ (00:00) Introduction ⌨️ (01:31) What is Prompt Engineering? ⌨️ (02:17) Introduction to AI ⌨️ (03:52) Why is Machine learning useful? ⌨️ (06:36) Linguistics ⌨️ (08:04) Language Models ⌨️ (14:35) Prompt Engineering Mindset ⌨️ (15:38) Using GPT-4 ⌨️ (20:41) Best practices ⌨️ (31:20) Zero shot and few shot prompts ⌨️ (35:06) AI hallucinations ⌨️ (36:43) Vectors/text embeddings ⌨️ (40:28) Recap 🔤 Share to support and show Love
4 580
☠️ How To Set-up Port forwarding |How to 🎀
Hack Android Out Of Network | How To Set-up Port Forwarding of Any Rat ☠️
THIS IS VERY USEFUL VIDEO IF YOU DONT KNOW WHAT IS PORT FORWARDING THAN YOU CANT USE ANY RÃT
