Exploiting Log4Shell (Log4J) in 2025
https://www.intigriti.com/researchers/blog/hacking-tools/exploiting-log4shell-log4j
#web #Log4J #Log4Shell
https://www.intigriti.com/researchers/blog/hacking-tools/exploiting-log4shell-log4j
#web #Log4J #Log4Shell
Intigriti
Log4Shell (Log4J): Advanced Exploitation Guide
Learn how to identify and hunt for Log4Shell (Log4J) in 2025 using different testing methods. Read the article now!
Forwarded from 1N73LL1G3NC3
DllShimmer
Weaponize DLL hijacking easily. Backdoor any function in any DLL without disrupting normal process operation.
Weaponize DLL hijacking easily. Backdoor any function in any DLL without disrupting normal process operation.
Forwarded from Ralf Hacker Channel (Ralf Hacker)
Новый сканер для обнаружения уязвимостей к NTLM релеям
https://github.com/depthsecurity/RelayKing-Depth/
Есть статья в блоге: https://www.depthsecurity.com/blog/introducing-relayking-relay-to-royalty/
#soft #git #ad #pentest #relay
https://github.com/depthsecurity/RelayKing-Depth/
* Сканирует по SMB, LDAP/S, MSSQL, HTTP/S, RPC, WinRM
* Находит WebDAV WebClient, CVE-2025-33073 (NTLM reflection), NTLMv1 + всякие PrinterBug, PetitPotam и т.п.
* Поддерживает аудит всего домена
* Составляет список таргетов для ntlmrelayx и других софтин.
* Сохраняет отчет в plaintext/JSON/CSV/Markdown
Есть статья в блоге: https://www.depthsecurity.com/blog/introducing-relayking-relay-to-royalty/
#soft #git #ad #pentest #relay
🔥1