Introducing pyCobaltHound
https://www.reddit.com/r/redteamsec/comments/umj4wl/introducing_pycobalthound/
pyCobaltHound is an Aggressor script extension for Cobalt Strike which aims to provide a deep integration between Cobalt Strike and Bloodhound. https://blog.nviso.eu/2022/05/09/introducing-pycobalthound/ submitted by /u/A32AN (https://www.reddit.com/user/A32AN)
[link] (https://www.reddit.com/r/redteamsec/comments/umj4wl/introducing_pycobalthound/) [comments] (https://www.reddit.com/r/redteamsec/comments/umj4wl/introducing_pycobalthound/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/umj4wl/introducing_pycobalthound/
pyCobaltHound is an Aggressor script extension for Cobalt Strike which aims to provide a deep integration between Cobalt Strike and Bloodhound. https://blog.nviso.eu/2022/05/09/introducing-pycobalthound/ submitted by /u/A32AN (https://www.reddit.com/user/A32AN)
[link] (https://www.reddit.com/r/redteamsec/comments/umj4wl/introducing_pycobalthound/) [comments] (https://www.reddit.com/r/redteamsec/comments/umj4wl/introducing_pycobalthound/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Introducing pyCobaltHound
pyCobaltHound is an Aggressor script extension for Cobalt Strike which aims to provide a deep integration between Cobalt Strike and Bloodhound....
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Printix 1.3.1106.0 Privilege Escalation
https://4.bp.blogspot.com/-gQsa2Au6OFw/WWlvKe9cGFI/AAAAAAAAIME/7MuhuX3Jqy0CeEu0oyVXmXST8BDpKvIGgCLcBGAs/s1600/h15.png
A "Creation of Temporary Files in Directory with Insecure Permissions" vulnerability in PrintixService.exe in Printix's "Printix Secure Cloud Print Management" versions 1.3.1106.0 and below allows any logged in user to elevate any executable or file to the SYSTEM context. This is achieved by exploiting race conditions in the creation of the Installer's temp.ini file.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Printix 1.3.1106.0 Privilege Escalation
https://4.bp.blogspot.com/-gQsa2Au6OFw/WWlvKe9cGFI/AAAAAAAAIME/7MuhuX3Jqy0CeEu0oyVXmXST8BDpKvIGgCLcBGAs/s1600/h15.png
A "Creation of Temporary Files in Directory with Insecure Permissions" vulnerability in PrintixService.exe in Printix's "Printix Secure Cloud Print Management" versions 1.3.1106.0 and below allows any logged in user to elevate any executable or file to the SYSTEM context. This is achieved by exploiting race conditions in the creation of the Installer's temp.ini file.
SHA-256 |
962985a116482c4dadbf77096ef08deaadaf5eff443d79735b06e3812d725e3eDownload
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Printix 1.3.1106.0 Privilege Escalation
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Spring4Shell Spring Framework Class Property Remote Code Execution
___________________________
@hacking_Attack
@Hacking_Video
Spring4Shell Spring Framework Class Property Remote Code Execution
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Spring4Shell Spring Framework Class Property Remote Code Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Printix 1.3.1106.0 Privileged API Abuse
https://3.bp.blogspot.com/-ZdpKmdYlHbY/WWlu_uhv-yI/AAAAAAAAIKA/GrhbPhfNXpolamaXsSLRo9Cb0FKriXUgQCLcBGAs/s1600/h12.png
An "Incorrect Use of a Privileged API" vulnerability in PrintixService.exe in Printix's "Printix Secure Cloud Print Management" versions 1.3.1106.0 and below allows a local or remote attacker the ability change all HKEY Windows Registry values as SYSTEM context via the UITasks.PersistentRegistryData parameter.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Printix 1.3.1106.0 Privileged API Abuse
https://3.bp.blogspot.com/-ZdpKmdYlHbY/WWlu_uhv-yI/AAAAAAAAIKA/GrhbPhfNXpolamaXsSLRo9Cb0FKriXUgQCLcBGAs/s1600/h12.png
An "Incorrect Use of a Privileged API" vulnerability in PrintixService.exe in Printix's "Printix Secure Cloud Print Management" versions 1.3.1106.0 and below allows a local or remote attacker the ability change all HKEY Windows Registry values as SYSTEM context via the UITasks.PersistentRegistryData parameter.
SHA-256 |
e26119f8d98f860e7ac7059a0d25e15dfc9acdbc0d49faa1f612da8efaf64cdcDownload
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Printix 1.3.1106.0 Privileged API Abuse
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
RCE via Dependency Confusion
https://sm4rty.medium.com/rce-via-dependency-confusion-e0ed2a127013?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://sm4rty.medium.com/rce-via-dependency-confusion-e0ed2a127013?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
RCE via Dependency Confusion
Hey there, I am Samrat Gupta aka Sm4rty, a Security Researcher and a Bug Bounty Hunter. In this Blog I will be sharing my recent finding…
Hey there, I am Samrat Gupta aka Sm4rty, a Security Researcher and a Bug Bounty Hunter. In this Blog I will be sharing my recent finding…Continue reading on Medium » (https://sm4rty.medium.com/rce-via-dependency-confusion-e0ed2a127013?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
RCE via Dependency Confusion
Hey there, I am Samrat Gupta aka Sm4rty, a Security Researcher and a Bug Bounty Hunter. In this Blog I will be sharing my recent finding…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Onapsis Announces New Offering to Jumpstart Security for SAP Customers
Company delivers new vulnerability management offering to help resource-constrained organizations combat increasing attacks on mission-critical SAP applications .
___________________________
@hacking_Attack
@Hacking_Video
Onapsis Announces New Offering to Jumpstart Security for SAP Customers
Company delivers new vulnerability management offering to help resource-constrained organizations combat increasing attacks on mission-critical SAP applications .
___________________________
@hacking_Attack
@Hacking_Video
Darkreading
Onapsis Announces New Offering to Jumpstart Security for SAP Customers
Company delivers new vulnerability management offering to help resource-constrained organizations combat increasing attacks on mission-critical SAP applications .
Dark Reading: Attacks/Breaches
Arctic Wolf Launches Arctic Wolf Labs Focused on Security Operations Research and Intelligence Reporting
New research-focused division focused on advancing innovation in the field of security operations.
___________________________
@hacking_Attack
@Hacking_Video
Arctic Wolf Launches Arctic Wolf Labs Focused on Security Operations Research and Intelligence Reporting
New research-focused division focused on advancing innovation in the field of security operations.
___________________________
@hacking_Attack
@Hacking_Video
Darkreading
Arctic Wolf Launches Arctic Wolf Labs Focused on Security Operations Research and Intelligence Reporting
New research-focused division focused on advancing innovation in the field of security operations.
Dark Reading: Attacks/Breaches
Cybercriminals Are Increasingly Exploiting Vulnerabilities in Windows Print Spooler
Kaspersky researchers discovered that cybercriminals made approximately 65,000 attacks between July 2021 and April 2022.
___________________________
@hacking_Attack
@Hacking_Video
Cybercriminals Are Increasingly Exploiting Vulnerabilities in Windows Print Spooler
Kaspersky researchers discovered that cybercriminals made approximately 65,000 attacks between July 2021 and April 2022.
___________________________
@hacking_Attack
@Hacking_Video
Darkreading
Cybercriminals Are Increasingly Exploiting Vulnerabilities in Windows Print Spooler
Kaspersky researchers discovered that cybercriminals made approximately 65,000 attacks between July 2021 and April 2022.
How to best get started with pentesting both learning and with tooling and setting up a suite
https://www.reddit.com/r/Pentesting/comments/umka8w/how_to_best_get_started_with_pentesting_both/
I’ve done like one or two of the easier hackthebox machines and feel like I was definitely a bit over my head. I also have heard that it is best practice to not run any of the tools directly on your OS. I’m curious what the standard practices are. Should I make a kali bootable usb, or a VM, or something else? Also, I want to learn pentesting for both offensive and defensive purposes. I’d like to host my own webapp but want to be aware of potential attack vectors. I know this is a lot but I figured there might be some professionals in this sub with some advice. submitted by /u/regular_guy_anon (https://www.reddit.com/user/regular_guy_anon)
[link] (https://www.reddit.com/r/Pentesting/comments/umka8w/how_to_best_get_started_with_pentesting_both/) [comments] (https://www.reddit.com/r/Pentesting/comments/umka8w/how_to_best_get_started_with_pentesting_both/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/umka8w/how_to_best_get_started_with_pentesting_both/
I’ve done like one or two of the easier hackthebox machines and feel like I was definitely a bit over my head. I also have heard that it is best practice to not run any of the tools directly on your OS. I’m curious what the standard practices are. Should I make a kali bootable usb, or a VM, or something else? Also, I want to learn pentesting for both offensive and defensive purposes. I’d like to host my own webapp but want to be aware of potential attack vectors. I know this is a lot but I figured there might be some professionals in this sub with some advice. submitted by /u/regular_guy_anon (https://www.reddit.com/user/regular_guy_anon)
[link] (https://www.reddit.com/r/Pentesting/comments/umka8w/how_to_best_get_started_with_pentesting_both/) [comments] (https://www.reddit.com/r/Pentesting/comments/umka8w/how_to_best_get_started_with_pentesting_both/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to best get started with pentesting both learning and with...
I’ve done like one or two of the easier hackthebox machines and feel like I was definitely a bit over my head. I also have heard that it is best...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
When a responsible disclosure goes south
https://cdn-images-1.medium.com/max/600/0*z4zIsSjXjGC8F4Ir.jpg
Screwing up a disclosure
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
When a responsible disclosure goes south
https://cdn-images-1.medium.com/max/600/0*z4zIsSjXjGC8F4Ir.jpg
Screwing up a disclosure
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
When a responsible disclosure goes south
Screwing up a disclosure
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Governance Hacking: Swallowing Your Own Poison Pill
https://cdn-images-1.medium.com/max/1280/1*suZrQxCxpWOViO-xJHB-_Q.jpeg
Beanstalk lost 76M in digital assets because of a governance flaw, and your DAO can too.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Governance Hacking: Swallowing Your Own Poison Pill
https://cdn-images-1.medium.com/max/1280/1*suZrQxCxpWOViO-xJHB-_Q.jpeg
Beanstalk lost 76M in digital assets because of a governance flaw, and your DAO can too.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Governance Hacking: Swallowing Your Own Poison Pill
Beanstalk lost 76M in digital assets because of a governance flaw, and your DAO can too.