Forwarded from 1N73LL1G3NC3
Exploit for CyberPanel RCE found on v2.3.6
Blog: https://dreyand.rs/code/review/2024/10/27/what-are-my-options-cyberpanel-v236-pre-auth-rce
Query:
HUNTER:
FOFA:
Zoomeye:
Blog: https://dreyand.rs/code/review/2024/10/27/what-are-my-options-cyberpanel-v236-pre-auth-rce
Query:
HUNTER:
/product.name="CyberPanel"
FOFA:
app="CyberPanel"
Zoomeye:
“images/cyberpanel-banner”
Forwarded from Caster
Релиз моей статьи о пивотинге с использованием TailScale
Caster - Bipolar Disorder
Genre: Offensive, Experimental
Label: exploit.org
Release Date: 15 November 2024
Performed by: Caster
Written by: Magama Bazarov
Mastered by: Magama Bazarov, Anastasia Graves
Cover Man: Magama Bazarov (Sony ILCE-7M3, f/5.6, 1/3 sec)
Cover Edit: Caster
https://blog.exploit.org/caster-bipolar-disorder
Caster - Bipolar Disorder
Genre: Offensive, Experimental
Label: exploit.org
Release Date: 15 November 2024
Performed by: Caster
Written by: Magama Bazarov
Mastered by: Magama Bazarov, Anastasia Graves
Cover Man: Magama Bazarov (Sony ILCE-7M3, f/5.6, 1/3 sec)
Cover Edit: Caster
https://blog.exploit.org/caster-bipolar-disorder
👍1
Forwarded from Dword
Disable
reg add "HKLM\System\CurrentControlSet\Control\Lsa" /t REG_DWORD /v DisableRestrictedAdmin /d 0 /f
reg add "HKLM\System\CurrentControlSet\Control\Lsa" /t REG_DWORD /v DisableRestrictedAdmin /d 0 /f
Forwarded from Albert Einstein
ИИ-ассистент для преступника — Venice.ai сгенерирует любой вирус или шпионку. И не задаст ни одного вопроса
https://www.securitylab.ru/news/559549.php
https://www.securitylab.ru/news/559549.php
SecurityLab.ru
ИИ-ассистент для преступника — Venice.ai сгенерирует любой вирус или шпионку. И не задаст ни одного вопроса
Это первый чат-бот, который делает зло удобным, быстрым и кастомным. За $18 в месяц.
Forwarded from Cyber Guardians
Stealth Syscall Execution:
Bypassing ETW, Sysmon, and EDR Detection
https://www.darkrelay.com/post/stealth-syscall-execution-bypass-edr-detection
@IRCyberGuardians
Bypassing ETW, Sysmon, and EDR Detection
https://www.darkrelay.com/post/stealth-syscall-execution-bypass-edr-detection
@IRCyberGuardians
DarkRelay
Stealth Syscalls & EDR Bypass: How Direct Syscalls Evade Hooks | DarkRelay
How EDR user-mode hooks work, why direct/indirect syscalls bypass them, and defensive detection ideas. Technical walkthrough for Windows security research.
Forwarded from Dword
➤ Hide icon (System Tray)
reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoTrayItemsDisplay /t REG_DWORD /d 1 /f
taskkill /f /im explorer.exe & start explorer.exe
reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoTrayItemsDisplay /t REG_DWORD /d 1 /f
taskkill /f /im explorer.exe & start explorer.exe
Forwarded from 💻ӉѦСҠіИԌ ҬЄѦӍ Difusion
CobaltStrike-Toolset.
Aggressor Script, Kit, Malleable C2 Profiles, External C2 and so on.
https://github.com/QAX-A-Team/CobaltStrike-Toolset
Aggressor Script, Kit, Malleable C2 Profiles, External C2 and so on.
https://github.com/QAX-A-Team/CobaltStrike-Toolset
GitHub
GitHub - QAX-A-Team/CobaltStrike-Toolset: Aggressor Script, Kits, Malleable C2 Profiles, External C2 and so on
Aggressor Script, Kits, Malleable C2 Profiles, External C2 and so on - QAX-A-Team/CobaltStrike-Toolset
Forwarded from X4r3ve
Search for computers that allow multiple RDP sessions. By default, Windows Server versions have the fSingleSessionPerUser value set to 0, allowing multiple users to log into the server via RDP. On workstations like Windows 10/11, the fSingleSessionPerUser value is set to 1, meaning only one user can log in via RDP at a time.
netexec smb ips_445.txt -u user -p passw0rd -x 'reg query "HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fSingleSessionPerUser'
❤1👍1
Forwarded from X4r3ve
Enables workstations to accept multiple RDP sessions. Running this will cause the RDP service to restart, interrupting established RDP connections.
netexec smb ips_445.txt -u user -p passw0rd -x 'reg add "HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fSingleSessionPerUser /t REG_DWORD /d 0 /f && sc.exe stop TermService && sc.exe start TermService'
👍1
Forwarded from 1N73LL1G3NC3
Collect infrastructure and permissions data from vCenter and export it as a BloodHound‑compatible graph using Custom Nodes/Edges
Please open Telegram to view this post
VIEW IN TELEGRAM
Forwarded from 巴伦和他的哥哥姐姐叔叔阿姨们
🟥 Hyperliquid 实时监控(持续)
—— 将「内幕地址」的 充值 / 提现 / 开仓 / 平仓 / 杠杆调整 同步到 Channel
🎯 监控目标
• 充值、提现、开/平仓、杠杆调整
• 触发即推送,附带交易方向、币对、金额、杠杆、仓位价值、Tx 链接
📏 触发规则
• 🆕 空白地址(首次出现)
• 💰 大额入款(≥ 10,000,000 USDT)
• ⚙️ 高杠杆(≥ 10×)
• 📦 大仓位合约操作
🛰️ 备注
• 0xb317d2bc2d3d2df5fa441b5bae0ab9d8b07283ae 在 2025/10/15 02:02:56 获利了结并提款。但依旧持续监控
—— 将「内幕地址」的 充值 / 提现 / 开仓 / 平仓 / 杠杆调整 同步到 Channel
🎯 监控目标
• 充值、提现、开/平仓、杠杆调整
• 触发即推送,附带交易方向、币对、金额、杠杆、仓位价值、Tx 链接
📏 触发规则
• 🆕 空白地址(首次出现)
• 💰 大额入款(≥ 10,000,000 USDT)
• ⚙️ 高杠杆(≥ 10×)
• 📦 大仓位合约操作
🛰️ 备注
• 0xb317d2bc2d3d2df5fa441b5bae0ab9d8b07283ae 在 2025/10/15 02:02:56 获利了结并提款。但依旧持续监控