CrackCodes 🇮🇳
15.9K subscribers
1.89K photos
387 videos
722 files
3.67K links
Official Websites: https://crackcodes.in |
For Bug Hunters: https://system32.ink

Admin: @MynK0x00
About Admin: prapattimynk.crackcodes.in


Be Secure~
जय श्री राम
Download Telegram
💥Home Grown Red Team: Let’s Make Some Malware In C:
Part 3

This post is going to be all about the dll!
💥OWASSRF: CrowdStrike Identifies New Exploit Method for Exchange Bypassing ProxyNotShell Mitigations

CrowdStrike recently discovered a new exploit method (called OWASSRF) consisting of CVE-2022-41080 and CVE-2022-41082 to achieve remote code execution (RCE) through Outlook Web Access (OWA). The new exploit method bypasses URL rewrite mitigations for the Autodiscover endpoint provided by Microsoft in response to ProxyNotShell.
After initial access via this new exploit method, the threat actor leveraged legitimate Plink and AnyDesk executables to maintain access, and performed anti-forensics techniques on the Microsoft Exchange server in an attempt to hide their activity.
#Analytics
Top 10 most exploited vulnerabilities in 2022

1. CVE-2022-30190: MS Office "Follina"

2. CVE-2021-44228: Apache Log4Shell

3. CVE-2022-22965: Spring4Shell

4. CVE-2022-1388: F5 BIG-IP

5. CVE-2022-0609: Google Chrome zero-day
https://blog.google/threat-analysis-group/countering-threats-north-korea
6. CVE-2017-11882: Old but not forgotten - MS Office bug

7. CVE-2022-41082, CVE-2022-41040: ProxyNotShell

8. CVE-2022-27925, CVE-2022-41352: Zimbra Collaboration Suite bugs


9. CVE-2022-26134: Atlassian Confluence RCE flaw

10. CVE-2022-30525: Zyxel RCE vulnerability
#Offensive_security
Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk, plus functions and strings obfuscation, duplicate lsass handle from existed processes
https://github.com/D1rkMtr/DumpThatLSASS
Forwarded from 卩ro 爪Cracker
​​chatgpt_chinese_prompt_hack

Use prompt hack to bypass OpenAI's content policy restrictions by golfzert

https://github.com/golfzert/chatgpt-chinese-prompt-hack
👍2
Forwarded from 卩ro 爪Cracker
​​hackGPT

OpenAI and #ChatGPT to do hackerish things by NoDataFound

https://github.com/NoDataFound/hackGPT
🏆1
Forwarded from 卩ro 爪Cracker
Forwarded from 卩ro 爪Cracker