hacker_trick | Unsorted

Telegram-канал hacker_trick - Hacker tricks

3151

CVEs🔰 Tools🛠 RedTeam📕

Subscribe to a channel

Hacker tricks

LOLSpoof: is a an interactive shell program that automatically spoof the command line arguments of the spawned process
https://github.com/itaymigdal/LOLSpoof

Читать полностью…

Hacker tricks

The Dangers of Lateral Movement & Website Cross Contamination
https://blog.sucuri.net/2024/01/dangers-of-lateral-movement-website-cross-contamination

Читать полностью…

Hacker tricks

This repository contains proof-of-concept scripts for CVE-2023-45866, CVE-2024-21306, and CVE-2024-0230 Bluetooth vulnerabilities in Android, Linux, macOS, iOS and Windows can be exploited to pair an emulated Bluetooth keyboard and inject keystrokes without user confirmation
https://github.com/marcnewlin/hi_my_name_is_keyboard

Читать полностью…

Hacker tricks

Calling Home, Get Your Callbacks Through RBI
https://posts.specterops.io/calling-home-get-your-callbacks-through-rbi-50633a233999

Читать полностью…

Hacker tricks

Outlook Vulnerability Discovery and New Ways to Leak NTLM Hashes
https://www.varonis.com/blog/outlook-vulnerability-new-ways-to-leak-ntlm-hashes

Читать полностью…

Hacker tricks

F31: is a bash script that hardens your Kali Linux and allows you to minimize noise in the air
https://github.com/wearecaster/F31

Читать полностью…

Hacker tricks

Cobalt Strike Profiles for EDR Evasion + SourcePoint is a C2 profile generator for Cobalt Strike
https://github.com/EvilGreys/Cobalt-Strike-Profiles-for-EDR-Evasion

Читать полностью…

Hacker tricks

Phishing using Google Sheets for Red Team Engagements
https://infosecwriteups.com/phishing-using-google-sheets-for-red-team-engagements-ac79298ddb90

Читать полностью…

Hacker tricks

LOTL: This is a fileless living off the land reverse shell written in JScript and Powershell script
https://github.com/Null-byte-00/LOTL

Читать полностью…

Hacker tricks

Lateral Movement – Visual Studio DTE
https://pentestlab.blog/2024/01/15/lateral-movement-visual-studio-dte

Читать полностью…

Hacker tricks

A lightweight method to detect potential iOS malware
https://securelist.com/shutdown-log-lightweight-ios-malware-detection-method
iShutdown scripts: extracts, analyzes, and parses Shutdown.log forensic artifact from iOS Sysdiagnose archives
https://github.com/KasperskyLab/iShutdown

Читать полностью…

Hacker tricks

VBA: having fun with macros, overwritten pointers & R/W/X memory
https://adepts.of0x.cc/vba-hijack-pointers-rwa

Читать полностью…

Hacker tricks

DFSCoerce exe revisited version with custom authentication
https://github.com/decoder-it/DFSCoerce-exe-2

Читать полностью…

Hacker tricks

Hunting for SSRF Bugs in PDF Generators
https://www.blackhillsinfosec.com/hunting-for-ssrf-bugs-in-pdf-generators

Читать полностью…

Hacker tricks

CVE-2023-7028 | Account-Take-Over Gitlab
https://github.com/Vozec/CVE-2023-7028
CVE-2023-36003 (Windows LPE XAML diagnostics API)
https://github.com/m417z/CVE-2023-36003-POC
CVE-2024-20656: Windows LPE in the VSStandardCollectorService150 service
https://github.com/Wh04m1001/CVE-2024-20656

Читать полностью…

Hacker tricks

Security Brief: TA866 Returns with a Large Email Campaign
https://www.proofpoint.com/us/blog/threat-insight/security-brief-ta866-returns-large-email-campaign
Parrot TDS: A Persistent and Evolving Malware Campaign
https://unit42.paloaltonetworks.com/parrot-tds-javascript-evolution-analysis
Rapidly evolving IoT malware EnemyBot now targeting Content Management System servers and Android devices
https://cybersecurity.att.com/blogs/labs-research/rapidly-evolving-iot-malware-enemybot-now-targeting-content-management-system-servers

Читать полностью…

Hacker tricks

Google Chrome V8 CVE-2024-0517 Out-of-Bounds Write Code Execution
https://blog.exodusintel.com/2024/01/19/google-chrome-v8-cve-2024-0517-out-of-bounds-write-code-execution

Читать полностью…

Hacker tricks

How I passed the Intigriti 0124 Challenge
rodriguezjorgex/how-i-passed-the-intigriti-0124-challenge-b6c2d1cd1b7b" rel="nofollow">https://medium.com/@rodriguezjorgex/how-i-passed-the-intigriti-0124-challenge-b6c2d1cd1b7b

Читать полностью…

Hacker tricks

LiesGate: The idea came from an interesting project called MutationGate
In summary, the LiesGate code demonstrates advanced techniques related to system function manipulation, memory permission alterations, and execution context manipulation in a Windows environment, applicable in scenarios like reverse engineering, debugging, security testing, or malware development
https://github.com/CyberSecurityUP/LiesGate

Читать полностью…

Hacker tricks

Evil-M5Core2: is an innovative tool developed for ethical testing and exploration of WiFi networks
https://github.com/7h30th3r0n3/Evil-M5Core2

Читать полностью…

Hacker tricks

Yet another C++ Cobalt Strike beacon dropper with Ntdll unhooking, PPID spoofing and custom Process hollowing
https://github.com/ProcessusT/Venoma

Читать полностью…

Hacker tricks

Dark web threats and dark market predictions for 2024
https://securelist.com/darknet-predictions-for-2024

Читать полностью…

Hacker tricks

LLVM plugin to transparently apply stack spoofing and indirect syscalls to Windows x64 native calls at compile time
https://github.com/janoglezcampos/llvm-yx-callobfuscator

Читать полностью…

Hacker tricks

Reversing and Tooling a Signed Request Hash in Obfuscated JavaScript
https://buer.haus/2024/01/16/reversing-and-tooling-a-signed-request-hash-in-obfuscated-javascript

Читать полностью…

Hacker tricks

Hunting down the HVCI bug in UEFI
https://tandasat.github.io/blog/2024/01/15/CVE-2024-21305

Читать полностью…

Hacker tricks

MutationGate: is a new approach to bypass EDR's inline hooking by utilizing hardware breakpoint to redirect the syscall
https://github.com/senzee1984/MutationGate

Читать полностью…

Hacker tricks

ASLRn’t: How memory alignment broke library ASLR
https://zolutal.github.io/aslrnt

Читать полностью…

Hacker tricks

Crafting Malicious Pluggable Authentication Modules for Persistence, Privilege Escalation, and Lateral Movement
https://rosesecurityresearch.com/crafting-malicious-pluggable-authentication-modules-for-persistence-privilege-escalation-and-lateral-movement

Читать полностью…

Hacker tricks

swarm: Formerly known as axiom, swarm is the next generation of distributed cloud scanning and attack surface monitoring
https://github.com/swarmsecurity/swarm

Читать полностью…

Hacker tricks

Thousands of Sites with Popup Builder Compromised by Balada Injector
https://blog.sucuri.net/2024/01/thousands-of-sites-with-popup-builder-compromised-by-balada-injector

Читать полностью…
Subscribe to a channel