https://tryhackme.com/path/outline/webappredteaming
New learnig path Web App Red Teaming by Tryhackme
#Web #Pentest #Tryhackme
New learnig path Web App Red Teaming by Tryhackme
#Web #Pentest #Tryhackme
❤1
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278
Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2021-42278
https://github.com/Ridter/noPac
https://www.secureworks.com/blog/nopac-a-tale-of-two-vulnerabilities-that-could-end-in-ransomware
Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2021-42278
https://github.com/Ridter/noPac
https://www.secureworks.com/blog/nopac-a-tale-of-two-vulnerabilities-that-could-end-in-ransomware
GitHub
GitHub - Ridter/noPac: Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user
Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user - GitHub - Ridter/noPac: Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domai...
Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2021-42287
https://github.com/cube0x0/noPac
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42287
CVE-2021-42287
https://github.com/cube0x0/noPac
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42287
GitHub
GitHub - cube0x0/noPac: CVE-2021-42287/CVE-2021-42278 Scanner & Exploiter.
CVE-2021-42287/CVE-2021-42278 Scanner & Exploiter. - cube0x0/noPac
Forwarded from Social Engineering
• Автор этого материала собрал очень объемный гайд по пентесту CMS Bitrix, который включает в себя большое кол-во техник и различных методов. Вот содержание:
- Основы битриксологии:
- Определение версии;
- Множественные эндпоинты для авторизации:
- Интересные эндпоинты;
- Content Spoofing;
- Account Enumeration;
- Non-legitimate registration;
- Open Redirect;
- XSS уязвимости;
- SSRF;
- LFI;
- RCE:
- BDU:2024-01501:
- WAF Bypass;
- LPE;
- Bitrix24:
- Уязвимые модули:
- Поиск интересных директорий и файлов.
- Сканер под bitrix - “huitrix”:
- References:
S.E. ▪️ infosec.work ▪️ VT
Please open Telegram to view this post
VIEW IN TELEGRAM
Wayback Machine Alternatives
Many of the tools in the list are primarily aimed at preserving pages. However, you can try searching for data saved by others using Google: "keyword site:pagefreezer.com" (similarly for other tools domains).
https://www.link-assistant.com/news/wayback-machine-alternatives.html
Many of the tools in the list are primarily aimed at preserving pages. However, you can try searching for data saved by others using Google: "keyword site:pagefreezer.com" (similarly for other tools domains).
https://www.link-assistant.com/news/wayback-machine-alternatives.html