en
Feedback
ForenSec

ForenSec

Open in Telegram
2 479
Subscribers
No data24 hours
+47 days
+1830 days
Posts Archive
DrDisk Lab - Dosya İmza Tabanlı Kopyalama Aracı V2.0 ===================================================== Dosya İmza Tabanlı Kopyalama Aracı V2.0, dosyalarınızı güvenli bir şekilde kopyalamanızı sağlayan kullanıcı dostu bir çözümdür. ÖZELLİKLER ---------- • Gerçek zamanlı ilerleme takibi • Detaylı istatistikler • Türkçe arayüz DESTEKLENEN DOSYA TÜRLERİ ------------------------ • Resim Dosyaları: JPEG, PNG, GIF, BMP, TIFF, WebP • Belge Dosyaları: PDF, DOC/DOCX, XLS/XLSX, PPT/PPTX, TXT, RTF, CSV • Medya Dosyaları: MP3, WAV, MP4, AVI, MKV • Arşiv Dosyaları: ZIP, RAR, 7Z, TAR, GZ • Veritabanı Dosyaları: SQLite, MDB/ACCDB, DBF • Diğer: ISO, VHD/VHDX, EML, PST, MBOX SİSTEM GEREKSİNİMLERİ -------------------- • Windows 10 veya üzeri • Minimum 4GB RAM KULLANIM -------- 1. Kaynak klasörü seçin 2. Hedef klasörü seçin 3. "Başlat" düğmesine tıklayın 4. İşlem durumunu takip edin 5. Gerekirse "Durdur" düğmesi ile işlemi duraklatın 6. "Devam Et" düğmesi ile işlemi sürdürün

Operation successful 🫡 #Disaster #DisasterRecovery #RaidRecovery #DataRecovery #DFIR #CyberSecurity

Operation completed
+1
Operation completed

Evet nerde kalmıştık :)
Evet nerde kalmıştık :)

😅
+1
😅

🤫
🤫

Adli Bilişimde Kullanıcı Aktivitesinin İzleri #ShellBags #AdliBilişim #DigitalForensics #WindowsRegistry #SiberGüvenlik https://drdisklab.com/windows-shellbags

How to download large files from Tor or anonymize yourself while downloading files Install torsocks sudo apt install torsocks Use torsocks chained with wget torsocks wget --tries=0 --retry-connrefused --retry-on-host-error -retry-on-http-error=500,502 --continue --timeout=90 --progress=bar --show-progress --random-wait --append-output=/tmp/wget_background

Microsoft Configuration Manager (ConfigMgr / SCCM) 2403 Unauthenticated SQL injections (CVE-2024-43468) exploit It can be used to run arbitrary queries with the highest level of privileges on the Microsoft Configuration Manager site database. Such actions permit the take-over of the deployment and the execution of arbitrary commands on the underlying server. When KB29166583 is missing, all the following Microsoft Configuration Manager versions are vulnerable:
• < 2403 (5.00.9128.1024) • < 2309 (5.00.9122.1033) • < 2303 (5.00.9106.1037) • <= 2211 (*)
Blog: https://www.synacktiv.com/advisories/microsoft-configuration-manager-configmgr-2403-unauthenticated-sql-injections

Generative Artificial Intelligence 2024.pdf9.75 MB

Kaspersky TDSSKiller abuse to disable EDR software You can abuse TDSSKiller to interact with kernel-level services to disable
+1
Kaspersky TDSSKiller abuse to disable EDR software You can abuse TDSSKiller to interact with kernel-level services to disable EDR software running on the machine.   Removal of Malwarebytes Anti-Malware Service:
tdsskiller.exe -dcsvc MBAMService 
Removal of Microsoft Defender:
tdsskiller.exe -dcsvc windefend 
The "-dcsvc <service_name>" command deletes the specified service, removing the registry keys and executables associated with the service and software.

CVE-2024-7479 & CVE-2024-7481: TeamViewer User to Kernel LPE PoC: https://youtu.be/lUkAMAK-TPI exploit: https://github.com/PeterGabaldon/CVE-2024-7479_CVE-2024-7481
Affected: * from 15.0.0 before 15.58.4  * from 14.0.0 before 14.7.48796  * from 13.0.0 before 13.2.36225  * from 12.0.0 before 12.0.259312  * from 11.0.0 before 11.0.259311 
#lpe #pentest #redteam #exploit

Thor APT Scanner 10.7.17 - 29 Oct 2024 | Full version ( Not Cracked )

#xss_is

Zed Attack Proxy Cookbook #attack #hacking #eng

ZigStrike A robust shellcode #loader developed in Zig, offering a variety of #injection techniques and anti-sandbox features. It leverages compile-time capabilities for efficient #shellcode allocation, demonstrating proven success in bypassing advanced security solutions. ZigStrike includes a custom #payload builder, allowing users to easily select and construct payloads via a web application built with Python. Multiple Injection Techniques: • Local Thread • Local Mapping • Remote Mapping • Remote Thread hijacking Anti-Sandbox Protection: • TPM Presence Check • Domain Join Check Output Formats: • XLL (Excel Add-in) • DLL Advanced Features: • Base64 Shellcode Encoding • Compile-time String Processing • Memory Protection Handling • Process Targeting Blog: https://kpmg.com/nl/en/home/insights/2024/12/zig-strike-the-ultimate-toolkit-for-payload-creation-and-evasion.html

CVE-2024-49138: Windows LPE in CLFS.sys PATCHED: Dec 10, 2024 https://github.com/MrAle98/CVE-2024-49138-POC Tested on Windows
CVE-2024-49138: Windows LPE in CLFS.sys PATCHED: Dec 10, 2024 https://github.com/MrAle98/CVE-2024-49138-POC
Tested on Windows 11 23h2
#git #exploit #lpe #pentest #redteam

#Fortinet, #FortiOS ve #FortiProxy ürünlerinde tespit edilen CVE-2025-24472 adlı #ZeroDay güvenlik açığı hakkında kullanıcıları uyardı. Bu açık, saldırganların #CSF #proxy istekleriyle uzaktan süper yönetici yetkisi elde etmelerine olanak sağlıyor. Saldırı durumunda, saldırganlar güvenlik duvarlarını ele geçirerek kurumsal ağlara sızabilirler. Etkilenen Sürümler: - FortiOS: 7.0.0 – 7.0.16 - FortiProxy: - 7.0.0 – 7.0.19 - 7.2.0 – 7.2.12

Nerde ne amaçla kullanmak istediğin sana kalmış :)