0-click RCE in Electron Applications
https://shabarkin.medium.com/0-click-rce-in-electron-applications-1c4f81a2cd6b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://shabarkin.medium.com/0-click-rce-in-electron-applications-1c4f81a2cd6b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
0-click RCE in Electron Applications
0-click RCE in Electron Applications
0-click RCE in Electron ApplicationsContinue reading on Medium » (https://shabarkin.medium.com/0-click-rce-in-electron-applications-1c4f81a2cd6b?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
0-click RCE in Electron Applications
0-click RCE in Electron Applications
LDAPFragger - Command And Control Tool That Enables Attackers To Route Cobalt Strike Beacon Data Over LDAP
http://www.kitploit.com/2022/05/ldapfragger-command-and-control-tool.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/05/ldapfragger-command-and-control-tool.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
LDAPFragger - Command And Control Tool That Enables Attackers To Route Cobalt Strike Beacon Data Over LDAP
LDAPFragger is a Command and Control tool that enables attackers to route Cobalt Strike (https://www.kitploit.com/search/label/Cobalt%20Strike) beacon data over LDAP using user attributes. For background information, read the release blog: http://blog.fox-it.com/2020/03/19/ldapfragger-command-and-control-over-ldap-attributes
Dependencies and installation Compiled with .NET 4.0, but may work with older and newer .NET frameworks (https://www.kitploit.com/search/label/Frameworks) as well Usage Active Directory domain --ldaps: Use LDAPS instead of LDAP -v: Verbose output -h: Display this message If no AD credentials (https://www.kitploit.com/search/label/Credentials) are provided, integrated AD authentication (https://www.kitploit.com/search/label/Authentication) will be used."> _ _ __ | | | | / _| | | __| | __ _ _ __ | |_ _ __ __ _ __ _ __ _ ___ _ __ | |/ _` |/ _` | '_ \| _| '__/ _` |/ _` |/ _` |/ _ \ '__| | | (_| | (_| | |_) | | | | | (_| | (_| | (_| | __/ | |_|\__,_|\__,_| .__/|_| |_| \__,_|\__, |\__, |\___|_| | | __/ | __/ | |_| |___/ |___/ Fox-IT - Rindert Kramer Usage: --cshost: IP address or hostname of the Cobalt Strike instance --csport: Port of the external C2 interface on the Cobalt Strike server -u: Username to connect to Active Directory -p: Password to connect to Active Directory -d: FQDN of the Active Directory domain --ldaps: Use LDAPS instead of LDAP -v: Verbose output -h: Display this message If no AD credentials are provided, integrated AD authentication will be used. Example usage:
___________________________
@hacking_Attack
@Hacking_Video
Dependencies and installation Compiled with .NET 4.0, but may work with older and newer .NET frameworks (https://www.kitploit.com/search/label/Frameworks) as well Usage Active Directory domain --ldaps: Use LDAPS instead of LDAP -v: Verbose output -h: Display this message If no AD credentials (https://www.kitploit.com/search/label/Credentials) are provided, integrated AD authentication (https://www.kitploit.com/search/label/Authentication) will be used."> _ _ __ | | | | / _| | | __| | __ _ _ __ | |_ _ __ __ _ __ _ __ _ ___ _ __ | |/ _` |/ _` | '_ \| _| '__/ _` |/ _` |/ _` |/ _ \ '__| | | (_| | (_| | |_) | | | | | (_| | (_| | (_| | __/ | |_|\__,_|\__,_| .__/|_| |_| \__,_|\__, |\__, |\___|_| | | __/ | __/ | |_| |___/ |___/ Fox-IT - Rindert Kramer Usage: --cshost: IP address or hostname of the Cobalt Strike instance --csport: Port of the external C2 interface on the Cobalt Strike server -u: Username to connect to Active Directory -p: Password to connect to Active Directory -d: FQDN of the Active Directory domain --ldaps: Use LDAPS instead of LDAP -v: Verbose output -h: Display this message If no AD credentials are provided, integrated AD authentication will be used. Example usage:
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
From network segment A, run --csport LDAPFragger --cshost --csport -u -p -d ">LDAPFragger --cshost --csport LDAPFragger --cshost --csport -u -p -d From network segment B, run -p -d ">LDAPFragger LDAPFragger -u -p -d LDAPS can be used with the --LDAPS flag, however, regular LDAP traffic is encrypted as well. Please do note that the default Cobalt Strike payload will get caught by most AVs.
Download LDAPFragger (https://github.com/fox-it/LDAPFragger)
___________________________
@hacking_Attack
@Hacking_Video
Download LDAPFragger (https://github.com/fox-it/LDAPFragger)
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - fox-it/LDAPFragger
Contribute to fox-it/LDAPFragger development by creating an account on GitHub.
0-click RCE in Electron Applications
0-click RCE in Electron ApplicationsContinue reading on Medium »
Read more...
0-click RCE in Electron ApplicationsContinue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Uptycs Announces New Cloud Identity and Entitlement Management (CIEM) Capabilities
Also adds support for Google Cloud Platform (GCP) and Microsoft Azure, and PCI compliance coverage.
___________________________
@hacking_Attack
@Hacking_Video
Uptycs Announces New Cloud Identity and Entitlement Management (CIEM) Capabilities
Also adds support for Google Cloud Platform (GCP) and Microsoft Azure, and PCI compliance coverage.
___________________________
@hacking_Attack
@Hacking_Video
Darkreading
Uptycs Announces New Cloud Identity and Entitlement Management (CIEM) Capabilities
Also adds support for Google Cloud Platform (GCP) and Microsoft Azure, and PCI compliance coverage.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
SAC Health System Impacted By Security Incident
Six boxes of paper documents were removed from the facility without authorization in early March.
___________________________
@hacking_Attack
@Hacking_Video
SAC Health System Impacted By Security Incident
Six boxes of paper documents were removed from the facility without authorization in early March.
___________________________
@hacking_Attack
@Hacking_Video
Darkreading
SAC Health System Impacted By Security Incident
Six boxes of paper documents were removed from the facility without authorization in early March.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
AutoRABIT Secures $26M in Series B Investment from Full In Partners to Expand DevSecOps Platform
AutoRABIT intends to direct the funding toward growth initiatives and product development.
___________________________
@hacking_Attack
@Hacking_Video
AutoRABIT Secures $26M in Series B Investment from Full In Partners to Expand DevSecOps Platform
AutoRABIT intends to direct the funding toward growth initiatives and product development.
___________________________
@hacking_Attack
@Hacking_Video
Darkreading
AutoRABIT Secures $26M in Series B Investment from Full In Partners to Expand DevSecOps Platform
AutoRABIT intends to direct the funding toward growth initiatives and product development.
hacking: security in practice
New Sophisticated Malware
submitted by /u/Free-Speech-101
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
New Sophisticated Malware
submitted by /u/Free-Speech-101
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
reddit
New Sophisticated Malware
Posted in r/hacking by u/Free-Speech-101 • 1 point and 0 comments
hacking: security in practice
What typical apps could someone access with your gmail password?
If someone were to get your google password, what other possible non-google apps could be accessed via this password?
Does 2FA prevent such access?
submitted by /u/Changed525
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
What typical apps could someone access with your gmail password?
If someone were to get your google password, what other possible non-google apps could be accessed via this password?
Does 2FA prevent such access?
submitted by /u/Changed525
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
reddit
What typical apps could someone access with your gmail password?
If someone were to get your google password, what other possible non-google apps could be accessed via this password? Does 2FA prevent such access?
hacking: security in practice
Signs of tampering?
I've been told that one of the signs that you might have been compromised is that the default apps to open certain files have changed.
I go to open up a pdf this morning and while it should have automatically opened up with firefox, it prompted me on what app I should use to open the pdf.
Yesterday I noticed that firefox has been updated and in the window prompt it did say "New" under firefox, implying that it's a new app?
I don't remember having to pick out default apps for opening files after each update. Maybe I'm being paranoid.
If I am possibly compromised, what are some other things I can look into to find out if I've been computer poisoned?
Thanks in advance for any advice.
submitted by /u/lostlikeyou
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Signs of tampering?
I've been told that one of the signs that you might have been compromised is that the default apps to open certain files have changed.
I go to open up a pdf this morning and while it should have automatically opened up with firefox, it prompted me on what app I should use to open the pdf.
Yesterday I noticed that firefox has been updated and in the window prompt it did say "New" under firefox, implying that it's a new app?
I don't remember having to pick out default apps for opening files after each update. Maybe I'm being paranoid.
If I am possibly compromised, what are some other things I can look into to find out if I've been computer poisoned?
Thanks in advance for any advice.
submitted by /u/lostlikeyou
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
reddit
Signs of tampering?
I've been told that one of the signs that you might have been compromised is that the default apps to open certain files have changed. I go to...