Github tools
2.73K subscribers
33 photos
2 videos
58 files
361 links
Github useful scripts and tools
Download Telegram
MeTube

MeTube is a web interface for yt-dlp, a fork of youtube-dl, that allows users to download videos from YouTube and many other sites.

It supports playlists and can be run using Docker or docker-compose.

Notably, MeTube includes special configurations for iOS compatibility and extensions for Chrome and Firefox browsers, making it easy to integrate and download videos directly from the browser.

https://github.com/alexta69/metube
MaLDAPtive.pdf
31.9 MB
"MaLDAPtive: Diving Deep Into LDAP Obfuscation, Deobfuscation & Detection", 2024.
]-> https://github.com/MaLDAPtive/Invoke-Maldaptive
Shwmae (shuh-my) is a Windows Hello abuse tool that was released during DEF CON 32 as part of the Abusing Windows Hello Without a Severed Hand talk. The purpose of the tool is to abuse Windows Hello from a privileged user context.

https://github.com/CCob/Shwmae
1👍1
👻 Ghost in the PPL: BYOVDLL

This blog post explores bypassing LSA Protection in Userland through the "Bring Your Own Vulnerable DLL" (BYOVDLL) technique. It also delves into the successful exploitation of vulnerabilities in the CNG Key Isolation service and the methods employed to load vulnerable DLLs within protected processes.

🔗 Source:
https://itm4n.github.io/ghost-in-the-ppl-part-1/

#lsa #lsass #ppl #dll #maldev
🖼️ Manipulating Shim and Office for Code Injection

Office Injector - Invokes an RPC method in OfficeClickToRun service that will inject a DLL into a suspended process running as NT AUTHORITY\SYSTEM launched by the task scheduler service, thus achieving privilege escalation from administrator to SYSTEM.

Shim Injector - Writes an undocumented shim data structure into the memory of another process that causes apphelp.dll to apply the “Inject Dll” fix on the process without registering a new SDB file on the system, or even writing such file to disk.

DefCon Presentation

🔗 Source:
https://github.com/deepinstinct/ShimMe

#windows #office #rpc #inject #lpe
👍2
WiFi Exploitation Framework

Поддерживаемые атаки:

  -  Deauthentication attack
- WIDS Confusion attack
- Authentication attack
- Beacon Flood attack
- TKIP attack (Michael Shutdown Exploitation)
- Pixie Dust attack
- Null Pin attack
- PIN Bruteforce attack
- ARP Replay attack
- HIRTE attack
- Caffe Latte attack
- Fake Authentication attack
- WPA/WPA2 handshake capture attack
- PMKID attack
- EvilTwin attack



🥔 https://github.com/D3Ext/WEF
Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)

Dropped a new tool at DEF CON 32! Loot SCCM Distribution points via HTTP with

We've found credentials, certificates, custom apps, keystores, etc. What will you find?

🔗
https://github.com/badsectorlabs/sccm-http-looter
Protect-Images-from-AI-PixelGuard:

PixelGuard protects images from AI scraping and unauthorized use in AI training, such as facial recognition models or style transfer algorithms. It employs multiple invisible protection techniques that mostly imperceptible to the eye but can interfere with AI processing.

https://github.com/captainzero93/Protect-Images-from-AI-PixelGuard
windows-api-function-cheatsheets:

A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management, dynamic-link library (DLL) management, synchronization, interprocess communication, Unicode string manipulation, error handling, Winsock networking operations, and registry operations.

https://github.com/7etsuo/windows-api-function-cheatsheets