Whitehat Lab
3.18K subscribers
507 photos
1 video
1 file
566 links
Авторский канал об информационной безопасности
Свежие CVE, Red Team инструменты, внутренняя инфраструктура и другое
Edu only

Автор: @exited3n
Download Telegram
Forwarded from OffensiveMentor
💀 go-responder

NTLMv2 hash capture tool in pure Go zero deps, single static binary.

Poisons LLMNR / NBT-NS / mDNS and captures over SMB, HTTP, FTP, LDAP, MSSQL, Kerberos and more


🐱 Git repo
Please open Telegram to view this post
VIEW IN TELEGRAM
👍8🔥2
⚙️ CDP Toolkit

Инструмент для работы через Chrome DevTools Protocol (CDP)
Beacon Object File (BOF) для активации CDP - CDP-Enable-BOF

It is built for penetration testing and red team workflows where you have access to a running browser's CDP endpoint and want to inspect browser state, collect artifacts, or browse through the user's browser context


🐱 Repo
🔗 Research

#cdp #chrome #devtools #redteam

✈️ Telegram 💬 MAX
Please open Telegram to view this post
VIEW IN TELEGRAM
1
Forwarded from 1N73LL1G3NC3
cups2root Linux LPE

Interactive root shell from a local account in the lpadmin group.
👍6❤1
💻 CVE-2026-49179: Active Directory WriteSPNScript Command Injection

Компонент (ntdsai.dll - WriteSPNScript function) Active Directory формирует команду на основе внешних данных, но не экранирует или некорректно экранирует специальные символы (8.8 по CVSS 3.1)
Для эксплуатации подойдет любой аутентифицированный пользователь, как импакт RCE от системы на DC

Уязвимы:
Windows Server с 2012 по 2025


💻 PoC

#cve #windows #ad #poc

✈️ Telegram 💬 MAX
Please open Telegram to view this post
VIEW IN TELEGRAM
👍9
Forwarded from OFFZONE
🙂 Лучше вкусного напитка в пятницу может быть только вкусный напиток + доклады с OFFZONE 2026

Ловите все записи докладов во ВКонтакте:

1️⃣ Main track
2️⃣ Fast track
3️⃣ AppSec.Zone
4️⃣ Threat.Zone
5️⃣ AI.Zone
6️⃣ Community track
7️⃣ AntiFraud.Zone

Презентации тоже загрузили, они доступны на сайте программы. Чтобы скачать презентацию, нажмите на интересующий доклад.

Доклады на YouTube выложили, но пока частично. Оставшиеся догрузим в среду и напишем об этом.
Please open Telegram to view this post
VIEW IN TELEGRAM
🔄🕸 humble v1.66

Быстрый анализатор HTTP заголовков, ориентированный на безопасность

В 🐧 Kali есть в репозиториях:

sudo apt install humble


Использование:

python3 humble.py -u https://www.spacex.com


🐱 Repo

#humble #web #pentest

✈️ Telegram 💬 MAX
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1
🔄 💻 evil-winrm-py 1.7.0

Аналог одноименной утилиты написанный на 😰 Python

Python-based tool for executing commands on remote Windows machines using the WinRM. It provides an interactive shell with enhanced features like file upload/download, command history, and colorized output. It supports various authentication methods including NTLM, Pass-the-Hash, Certificate, and Kerberos


Прикрутили поддержку MCP
Полный список изменений

Установка:

uv tool install evil-winrm-py[kerberos,mcp]==1.7.0


💻 Repo
💻 Docs

#soft #python #windows #winrm

✈️ Telegram 💬 MAX
Please open Telegram to view this post
VIEW IN TELEGRAM
👍3🔥2
demo.gif
44 MB
💻 GPOddity

The GPOddity tool aims to automate gPCFileSysPath attack vectors to exploit vulnerable Group Policy Objects, including through NTLM relaying


🐱 Repo
🔗 Exploiting Active Directory GPOs through NTLM relaying, and more!

#windows #gpo #ad

✈️ Telegram 💬 MAX
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥1
⚙️ CVE PoC Search Engine

Поисковик PoC'ов от наших китайских товарищей

A modern, standalone HTML-based search engine for CVE Proof of Concept (PoC). Almost every publicly available CVE PoC is included


🔗 https://secnotes.cn/searchpoc/
🐱 Repo

#cve #poc #search

✈️ Telegram 💬 MAX
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥2👌1
Forwarded from ZeroNights
📌 До ZeroNights 2026 осталась 1 неделя !

Время протестировать свою готовность к конференции.
Меняйте свой статус с "может быть"➡️ "я иду".

🖥 КУПИТЬ БИЛЕТЫ

30 сентября 2026, СПб.
Please open Telegram to view this post
VIEW IN TELEGRAM
5🔥3
Forwarded from SOLAR CTF 2026
Регистрация на SolarCTF открыта ☀️

Первые студенческие соревнования по кибербезопасности от «Солара» — возможность проверить свои навыки на практике, собрать команду и побороться за призы.

📍Что важно знать:
✦ Команды — до 5 человек

✦ Старт — 17 октября в 12:00 (МСК)

✦ Финиш — 18 октября в 12:00 (МСК)

✦ 24 часа на выполнение заданий


Общий призовой фонд — 300 000 ₽* + лимитированный мерч.

Участвовать можно, если тебе уже исполнилось 18 лет, ты студент, постоянно проживаешь на территории РФ и находишься в России во время соревнований.

Команды пока нет? Найти тиммейтов можно в чате SolarCTF

Собирай команду и регистрируйся на SolarCTF ❤️
🔥3