12.5K subscribers
550 photos
27 videos
24 files
889 links
This channel discusses:

— Offensive Security
— RedTeam
— Malware Research
— OSINT
— etc

Disclaimer:
t.iss.one/APT_Notes/6

Chat Link:
t.iss.one/APT_Notes_PublicChat
Download Telegram
CVE-2021-26084.sh
1.5 KB
Confluence RCE Exploit - CVE-2021-26084

#exploit #confluecne
BRAKTOOTH: Causing Havoc on Bluetooth Link Manager

https://asset-group.github.io/disclosures/braktooth/
Ever wondered what happens when you type in a URL in an address bar in a browser? Here is a brief overview...

#programming #web #sketchnotes
Gososerial - Dynamically Generates Ysoserial’s Payload

https://github.com/EmYiQing/Gososerial

#JavaDeserialization #Gososerial #Payload #Ysoserial
Kiterunner — Contextual Content Discovery Tool

Kiterunner is a tool that is capable of not only performing traditional content discovery at lightning fast speeds, but also bruteforcing routes/endpoints in modern applications.
Modern application frameworks such as Flask, Rails, Express, Django and others follow the paradigm of explicitly defining routes which expect certain HTTP methods, headers, parameters and values.
When using traditional content discovery tooling, such routes are often missed and cannot easily be discovered.
By collating a dataset of Swagger specifications and condensing it into our own schema, Kiterunner can use this dataset to bruteforce API endpoints by sending the correct HTTP method, headers, path, parameters and values for each request it sends.

https://github.com/assetnote/kiterunner

#kiterunner #discovery #tools
BackstabKill EDR Protected Processes

Tool capable of killing antimalware protected processes by leveraging sysinternals’ Process Explorer (ProcExp) driver, which is signed by Microsoft.

https://github.com/Yaxser/Backstab

#edr #bypass #kill #process #unload
Forwarded from PT SWARM
RCE on a backend IIS server via file upload with an atypical file extension.

More community curated payloads can be found at https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Upload%20Insecure%20Files/Extension%20ASP