Quanto maior a complexidade no quesito de responsabilidades, maior a superfície de ataque. 2021 bateu recorde em ataques 0day. Vamos ver 2022...
Exploiting Tomcat and Coyote:
https://charlesreid1.com/wiki/Metasploitable/Apache/Tomcat_and_Coyote
Apache and Tomcat default pass:
https://github.com/netbiosX/Default-Credentials/blob/master/Apache-Tomcat-Default-Passwords.mdown
https://charlesreid1.com/wiki/Metasploitable/Apache/Tomcat_and_Coyote
Apache and Tomcat default pass:
https://github.com/netbiosX/Default-Credentials/blob/master/Apache-Tomcat-Default-Passwords.mdown
Executar payload como se fosse um ScreenSaver:
https://twitter.com/pegabizu/status/1519637165667454979?t=eGDSHM4U9XPdHLd2MM2wnA&
rundll32.exe desk.cpl,InstallScreenSaver C:\temp\file.scr
https://twitter.com/pegabizu/status/1519637165667454979?t=eGDSHM4U9XPdHLd2MM2wnA&
Twitter
Rafael S Marques
@Wietze @VakninHai @pabraeken Guys, I published this technique literally decades ago... 29a issue 7. vxug.fakedoma.in/zines/29a/29a7… @vxunderground
Use nmap over proxychains+tor
https://odysee.com/@HackerSploit:26/anonymize-your-traffic-with-proxychains:e
https://odysee.com/@HackerSploit:26/anonymize-your-traffic-with-proxychains:e
Odysee
Anonymize Your Traffic With Proxychains & Tor
In this video, we will take a look at how to anonymize your traffic with Proxychains and the Tor service to stay anonymous while hacking.
proxychains - a tool that forces any TCP connection made by an...
proxychains - a tool that forces any TCP connection made by an...
Professionalism in the cyber crime.
https://thehackernews.com/2022/05/experts-analyze-conti-and-hive.html
https://thehackernews.com/2022/05/experts-analyze-conti-and-hive.html
/archive/
Professionalism in the cyber crime. https://thehackernews.com/2022/05/experts-analyze-conti-and-hive.html
Como assim esse site não tem meta tag de preview
Forwarded from 0lab channel ™ (RSM-56)
CISO Advisor
Rede Tor fica mais veloz com controle de congestionamento
O Projeto Tor publicou detalhes sobre um sistema recém-introduzido chamado de Controle de Congestionamento que promete eliminar os limites de velocidade na rede. O novo sistema está funcionando na…
Curated list of Unix binaries that can be used to bypass local security restrictions in misconfigured systems.
https://gtfobins.github.io/
https://gtfobins.github.io/
Desofuscando endereços de email protegidos pela Cloudflare, muito interessante.
https://blog.jse.li/posts/cloudflare-scrape-shield/
https://blog.jse.li/posts/cloudflare-scrape-shield/
blog.jse.li
An Analysis of Cloudflare's Email Address Obfuscation | Jesse Li
It's a hex encoded string where the first byte (the key), is XORed against each subsequent byte to decrypt the email address. This is not a vulnerability.
The best articles from /r/oscp
https://libredd.it/r/oscp/comments/owfcl3/i_passed_oscp_and_here_is_how_you_shouldnt_do_it/
https://libredd.it/r/oscp/comments/ng6k5t/from_35_point_fail_to_100_point_pass_how_to_avoid/
https://libredd.it/r/oscp/comments/rs38pm/a_different_kind_of_root_how_a_dentist_passed_the/
https://libredd.it/r/oscp/comments/owfcl3/i_passed_oscp_and_here_is_how_you_shouldnt_do_it/
https://libredd.it/r/oscp/comments/ng6k5t/from_35_point_fail_to_100_point_pass_how_to_avoid/
https://libredd.it/r/oscp/comments/rs38pm/a_different_kind_of_root_how_a_dentist_passed_the/
Discussão sobre redes monitoradas e possíveis formas de silenciosamente bypassar a Intrusion Detection System:
https://security.stackexchange.com/questions/193109/websocket-vpn-and-mitm-gateways
https://security.stackexchange.com/questions/193109/websocket-vpn-and-mitm-gateways
Information Security Stack Exchange
Websocket VPN and MitM Gateways
A number of solutions are available for tunnelling IP over
Websockets to masquerade a VPN as browser traffic. How well
are these connections isolated though? Specifically, if the
browser happens to...
Websockets to masquerade a VPN as browser traffic. How well
are these connections isolated though? Specifically, if the
browser happens to...
See how many IP addresses your fail2ban banned:
sudo zgrep 'Ban' /var/log/fail2ban.log*
encrypted reverse shell com openssl lol
https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Reverse%20Shell%20Cheatsheet.md#openssl
https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Reverse%20Shell%20Cheatsheet.md#openssl
GitHub
PayloadsAllTheThings/Methodology and Resources/Reverse Shell Cheatsheet.md at master · swisskyrepo/PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF - swisskyrepo/PayloadsAllTheThings