Hacker Notes
رفتن به کانال در Telegram
Notes about everything related to hacking! #RedTeam Contact: @ADExplorer
نمایش بیشتر373
مشترکین
اطلاعاتی وجود ندارد24 ساعت
اطلاعاتی وجود ندارد7 روز
+830 روز
آرشیو پست ها
373
Group Policy Nightmares
In the realm of IT administration, Group Policies serve as a powerful tool for centrally managing and controlling various aspects of an Active Directory network environment in a Windows-based operating system. They provide a way to enforce consistent settings and configurations across multiple computers and user accounts within a domain or organizational unit. In this (hopefully) series of posts, I’ll describe some of the most unusual, and potentially dangerous configurations, I’ve encountered over my years of experience. 😉https://decoder.cloud/2024/11/08/group-policy-security-nightmares-pt-1/ 🔗 @hackern0tes
373
Breaking Down Multipart Parsers: File upload validation bypass
Basically, all multipart/form-data parsers fail to fully comply with the RFC, and when it comes to validating filenames or content uploaded by users, there are always numerous ways to bypass validation. We'll test various bypass techniques against PHP, Node.js, and Python parsers, as well as popular WAFs and load balancers like HAProxy, FortiWeb, Barracuda, and even some OpenResty Lua multipart parsers.
https://blog.sicuranext.com/breaking-down-multipart-parsers-validation-bypass/
🔗 @hackern0tes373
Top 4 new attack vectors in web application targets
Table of contents 1) LLM prompt injection attacks 2) Prototype pollution 3) Client-side path traversals 4) Dependency confusion Conclusionhttps://blog.intigriti.com/hacking-tools/top-4-new-attack-vectors-in-web-application-targets 🔗 @hackern0tes
373
Silencing the EDR Silencers
By:
Jonathan Johnson
As many security practitioners know, tampering with Endpoint Detection and Response (EDR) products is a deep desire for threat actors and red teamers alike. I spoke about this briefly at BlackHat this year in my “EDR Blinded, Now What?” Huntress booth talk.https://www.huntress.com/blog/silencing-the-edr-silencers 🔗 @hackern0tes
373
CVE-2024-10114
The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.7.7. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token.
https://www.wordfence.com/threat-intel/vulnerabilities/id/71df23bf-8f51-4260-be1f-ed5bc29d4afe?source=cve
🔗 @hackern0tes
373
An Offer You Can Refuse: UNC2970 Backdoor Deployment Using Trojanized PDF Reader | Google Cloud Blog
UNC2970 is a cyber espionage group suspected to have a North Korea nexus.
https://cloud.google.com/blog/topics/threat-intelligence/unc2970-backdoor-trojanized-pdf-reader
#mandiant #threat
🔗 @hackern0tes
373
Detecting and Mitigating Active Directory Compromises
#NSA #ActiveDirectory #AD
This guidance – authored by the Australian Signals Directorate (ASD), the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), the Canadian Centre for Cyber Security (CCCS), the New Zealand National Cyber Security Centre (NCSC-NZ), and the United Kingdom’s National Cyber Security Centre (NCSC-UK) – aims to inform organisations about 17 common techniques used to target Active Directory as observed by the authoring agencies. This guidance provides an overview of each technique and how it can be leveraged by malicious actors, as well as recommended strategies to mitigate these techniques. By implementing the recommendations in this guidance, organisations can significantly improve their Active Directory security, and therefore their overall network security, to prevent intrusions by malicious actors.🔗 @hackern0tes
373
TA Phone Home: EDR Evasion Testing Reveals Extortion Actor's Toolkit
#EDR #Bypass
https://unit42.paloaltonetworks.com/edr-bypass-extortion-attempt-thwarted/
In a recent investigation involving an extortion attempt, we discovered a threat actor had purchased access to the client network via Atera RMM from an initial access broker. We discovered the threat actor used rogue systems to install the Cortex XDR agent onto a virtual system. They did this to test a new antivirus/endpoint detection and response (AV/EDR) bypass tool leveraging the bring your own vulnerable driver (BYOVD) technique.🔗 @hackern0tes
373
LOL Collection
Collection of Living Off The Lands !
https://lolapps-project.github.io
1️⃣ LOLAD
2️⃣ UNIX binaries
3️⃣ Windows binaries
4️⃣ LOLESXi
5️⃣ A collection of resources to thrive off the land
🔗 @hackern0tes
373
New SteelFox malware hijacks Windows PCs using vulnerable driver
A new malicious package called 'SteelFox' mines for cryptocurrency and steals credit card data by using the "bring your own vulnerable driver" technique to get SYSTEM privileges on Windows machines. [...]
🔗 @hackern0tes
373
🚨 CVE-2024-9488
The Comments – wpDiscuz plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.6.24. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token.
🔗 @hackern0tes
373
New LOL project, LOLAD
A collection of Active Directory techniques!👇
https://lolad-project.github.io/
🔗 @hackern0tes
373
Vulnerabilities in Open Source C2 Frameworks!
https://blog.includesecurity.com/2024/09/vulnerabilities-in-open-source-c2-frameworks/
PoCs of RCEs against open source C2 servers.
https://github.com/hyperreality/c2-vulnerabilities
🔗 @hackern0tes
373
Hiding C2 behind Microsoft Teams! ;)
Command and Control infrastructure that allows Red Teamers to execute system commands on compromised hosts through Microsoft Teams.https://github.com/cxnturi0n/convoC2 🔗 @hackern0tes
373
Kekz Headphones hardware and firmware reverse engineering (embedded)
https://nv1t.github.io/blog/kekz-headphones/
🔗 @hackern0tes
373
Living Off The Land ESXi
LOLESXi features a comprehensive list of binaries/scripts natively available in VMware ESXi that adversaries have utilised in their operations. The information on this site is compiled from open-source threat research.
#lolesxi #ESXi #vmware
@hackern0tes
373
CVE-2024-8956, #CVE-2024-8957: How to Steal a 0-Day #RCE (With a Little Help from an LLM)
https://www.labs.greynoise.io/grimoire/2024-10-31-sift-0-day-rce/
🔗 @hackern0tes
373
Repost from The Hacker News
⚠️ Researchers have uncovered EMERALDWHALE, a massive campaign exploiting exposed Git configurations to siphon over 15,000 credentials and clone 10,000 private repositories.
Read: https://thehackernews.com/2024/11/massive-git-config-breach-exposes-15000.html
373
NukeAMSI
A powerful tool designed to neutralize the Antimalware Scan Interface (AMSI) in Windows environments.
https://github.com/anonymous300502/Nuke-AMSI
🔗 @hackern0tes
