Post #155
1.48K
FileJacking – Initial Access with File System API
browser-based backdooring: FileJacking-PoC (GitHub)
browser-based backdooring: FileJacking-PoC (GitHub)
- 👾 7
SE Showing posts older than #158 · Back to latest
Forwarded from 1N73LL1G3NC3

• OSINT
• Password spraying
• GAL/OAB
• Архитектура работы
• ZDI-CAN-22101
• OWA CAP Bypass
• CVE-2020-0688
• ProxyLogon
• CVE-2021-26855 - Pre-auth SSRF
• CVE-2021-27065 - Post-auth Arbitrary-File-Write
• ProxyOracle
• CVE-2021-31196 - The Padding Oracle
• CVE-2021-31195 - XSS
• Обход HttpOnly
• ProxyShell
• CVE-2021-34473 - Pre-auth Path Confusion leads to ACL Bypass
• CVE-2021-34523 - Exchange PowerShell Backend Elevation-of-Privilege
• CVE-2021-31207 - Post-auth Arbitrary-File-Write
• ProxyNotShell
• ProxyRelay
• Relay атаки
Forwarded from Order of Six Angles

Ways of device ownership spoofing and more for persistent access to Intune
The summer is over, September is left behind and .NET 10 is coming closer and closer (in fact, it is so close that Stephen Toub has already published his amazing “Performance Improvements in .NET 10” novel), which means it is just about time to read something new about the upcoming release (for instance, the great “Exploring the .NET 10 preview” series by Andrew Lock).
However, if, by any chance, you are interested in something besides .NET 10, then this issue of .NET R&D Digest is here to provide you with various bits of software development 🙂
This issue includes bits of AI, software development, learning, C#, performance, security, C, programming languages, ruby, and of course .NET and .NET Internals.

Forwarded from Source Byte
Forwarded from RedTeam brazzers (Миша)
UnderConf.pptx10.5 MBSec Note Mosquito the new Infostealer arrives to Mexico there's blubank domain #stealer

This article aims at giving an introduction to the base principles of COM and DCOM protocols as well as a detailed network analysis of DCOM
See also:
DCOM Lateral movement PoC
Lateral Movement Using DCOM and DLL Hijacking