|
Kristoffer Arfvidson
@
krarf
|
|
Cloud Security & Solutions Architect, .Net developer and an interest to learn about almost everything :)
|
|
|
318
Tweetovi
|
286
Pratim
|
62
Osobe koje vas prate
|
| Tweetovi |
| Kristoffer Arfvidson proslijedio/la je tweet | ||
|
B:\a.zza
@mcbazza
|
4. velj |
|
Last nights SMB one-liner that helped me loot an SMB share:
smbclient '\\server\share' -N -c 'prompt OFF;recurse ON;cd 'path\to\directory\';lcd '~/path/to/download/to/';mget *'
|
||
|
|
||
| Kristoffer Arfvidson proslijedio/la je tweet | ||
|
netbiosX
@netbiosX
|
4. velj |
|
|
||
|
|
||
| Kristoffer Arfvidson proslijedio/la je tweet | ||
|
Adam the Automator
@adbertram
|
19 h |
|
Are you sure that script you ran on all of your servers actually did what you intended? Be sure in my @pluralsight course Infrastructure Testing with Pester course where I cover how to use @PSPester and #PowerShell to create in-depth infrastructure tests. buff.ly/34PHlwV
|
||
|
|
||
| Kristoffer Arfvidson proslijedio/la je tweet | ||
|
Florian Hansemann
@CyberWarship
|
13 h |
|
SpiderFoot, the most complete OSINT collection and reconnaissance tool
#infosec #pentest #OSINT #bugbounty
github.com/smicallef/spid… pic.twitter.com/Mdc1ITucJ2
|
||
|
|
||
| Kristoffer Arfvidson proslijedio/la je tweet | ||
|
David Rowe
@davidprowe
|
4. velj |
|
Adding a Backdoor to AD in 400 Milliseconds
hubs.ly/H0mSZ8r0
|
||
|
|
||
| Kristoffer Arfvidson proslijedio/la je tweet | ||
|
DirectoryRanger
@DirectoryRanger
|
21 h |
|
#Windows Red Team Cheat Sheet
morph3sec.com/2019/07/16/Win…
|
||
|
|
||
|
Kristoffer Arfvidson
@krarf
|
3. velj |
|
Today, I'm standing @ #Swetugg a .net conference in #Stockholm #Sweden if you are here, come by our stand. #If #Microsoft #DotNet #Azure #Cloud #Developer pic.twitter.com/t9UwZGWtHj
|
||
|
|
||
| Kristoffer Arfvidson proslijedio/la je tweet | ||
|
Binni Shah
@binitamshah
|
1. velj |
|
Regex cheatsheet for the haters : github.com/geongeorge/i-h… cc @geongeorgek pic.twitter.com/YO6GwTEHk2
|
||
|
|
||
| Kristoffer Arfvidson proslijedio/la je tweet | ||
|
DirectoryRanger
@DirectoryRanger
|
1. velj |
|
Windows 10 UAC bypass for all executable files which are autoelevate true.
github.com/sailay1996/UAC…
|
||
|
|
||
| Kristoffer Arfvidson proslijedio/la je tweet | ||
|
Adrianne Jeffries
@adrjeffries
|
28. sij |
|
Amazon appears to be tracking every tap on Kindle. I just got my data back and there are 90K rows of this pic.twitter.com/wVCSXCTVwv
|
||
|
|
||
| Kristoffer Arfvidson proslijedio/la je tweet | ||
|
Huy
@DebugPrivilege
|
30. sij |
|
I would suggest everyone to take a look at @mburns7 his blog post about Windows Firewall, where he covers into the details on how you can mitigate lateral movement in AD medium.com/think-stack/pr…
|
||
|
|
||
| Kristoffer Arfvidson proslijedio/la je tweet | ||
|
Binni Shah
@binitamshah
|
30. sij |
|
PlaystoreDownloader : A command line tool to download Android applications directly from the Google Play Store : github.com/ClaudiuGeorgiu… (not affiliated with Google in any way) pic.twitter.com/h2WfXYe3bH
|
||
|
|
||
| Kristoffer Arfvidson proslijedio/la je tweet | ||
|
The Hacker News
@TheHackersNews
|
29. sij |
|
Great News! "Off-Facebook Activity" tool is now available to everyone.
Learn how to find which 3rd-party 'websites you visited' or 'apps you used' have shared your activity data with #Facebook and also how to delete it.
Read: thehackernews.com/2020/01/off-fa…
#infosec
#privacy
#tech pic.twitter.com/oucFlnasIp
|
||
|
|
||
| Kristoffer Arfvidson proslijedio/la je tweet | ||
|
Leandro Barragan
@lean0x2f
|
28. sij |
|
[Educational] One of the best blog posts that I ever read about going from 0 to unauth RCE in f**king Mikrotik OS step by step: medium.com/@maxi./finding…
|
||
|
|
||
| Kristoffer Arfvidson proslijedio/la je tweet | ||
|
DirectoryRanger
@DirectoryRanger
|
29. sij |
|
Driver loader for bypassing #Windows x64 Driver Signature Enforcement
github.com/hfiref0x/TDL
|
||
|
|
||
| Kristoffer Arfvidson proslijedio/la je tweet | ||
|
DirectoryRanger
@DirectoryRanger
|
30. sij |
|
#Windows Event Log to the Dark Side - Storing Payloads and Configurations
medium.com/@5yx/windows-e…
|
||
|
|
||
|
Kristoffer Arfvidson
@krarf
|
29. sij |
|
Raspberry pi 4 ? :)
But yes, you'll have to deal with libreoffice :/
|
||
|
|
||
| Kristoffer Arfvidson proslijedio/la je tweet | ||
|
Jai Minton
@CyberRaiju
|
28. sij |
|
Some Lateral Movement Methods:
-Pass the Hash/Relay ((Net-)NTLM)
-Pass the Ticket (Silver/Golden)
-RDP (Legit creds)
-Remote Services (VNC/SSH)
-(D)COM (Remote sched tasks, Services, WMI)
-Remote Service Vuln (EB)
-Admin Shares (PSExec)
-Webshell (Chopper)
-WinRM (PS Remoting)
|
||
|
|
||
| Kristoffer Arfvidson proslijedio/la je tweet | ||
|
Jin Wook Kim
@wugeej
|
29. sij |
|
SQL Injection WAF bypass techniques
1.Nullbyte:
%00' UNION SELECT password FROM Users WHERE username-'tom'--
2. SQL Comments:
'/**/UN/**/ION/**/SEL/**/ECT/**/password/**/FR/OM/**/Users/**/WHE/**/RE/**/usersame/**/LIKE/**/'tom'--
incogbyte.github.io/sqli_waf_bypas…
|
||
|
|
||
| Kristoffer Arfvidson proslijedio/la je tweet | ||
|
Catalin Cimpanu
@campuscodi
|
29. sij |
|
The UN got hacked and they tried to keep it quiet
thenewhumanitarian.org/investigation/… pic.twitter.com/L8s1g5ecWJ
|
||
|
|
||