Blog | Page 2 of 11 | Ptrace Security GmbH

Blog

IT Security News Bulletin #80

IT Security News Bulletin #80

Latest Infosec News and Articles Remote Desktop Penetration Testing (Port 3389)  https://www.hackingarticles.in/remote-desktop-penetration-testing-port-3389/  PrintNightmare Network Analysis https://www.hackingarticles.in/remote-desktop-penetration-testing-port-3389/  Google dork cheatsheet https://gist.github.com/sundowndev/283efaddbcf896ab405488330d1bbc06  Invoke-DNSteal - Simple And Customizable DNS Data Exfiltrator https://www.kitploit.com/2021/07/invoke-dnsteal-simple-and-customizable.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+PentestTools+%28PenTest+Tools%29 VNC Penetration Testing https://www.hackingarticles.in/vnc-penetration-testing/ Fuzzing ImageMagick

IT Security News Bulletin #79

IT Security News Bulletin #79

Latest Infosec News and Articles IDOR (Insecure Direct Object Reference) https://notes.mufaddal.info/web/idor NExfil: OSINT tool written in python for finding profiles by username  https://securityonline.info/nexfil-osint-tool-written-in-python-for-finding-profiles-by-username/ Exploiting insecure deseralization vulnerabilties found in the wild  https://macrosec.tech/index.php/2021/06/22/exploiting-insecure-deserialization-vulnerabilities-found-in-the-wild/  Buffer

IT Security News Bulletin #78

IT Security News Bulletin #78

Latest Infosec News and Articles Proxy Windows Tooling via SOCKS https://posts.specterops.io/proxy-windows-tooling-via-socks-c1af66daeef3 How We Are Able To Hack Any Company By Sending Message - $20,000 Bounty [CVE-2021–34506] https://cyberxplore.medium.com/how-we-are-able-to-hack-any-company-by-sending-message-including-facebook-google-microsoft-b7773626e447 Binary instrumentation framework based on

IT Security News Bulletin #77

IT Security News Bulletin #77

Latest Infosec News and Articles YARA Rules Guide: Learning this Malware Research Tool https://www.varonis.com/blog/yara-rules/ Deep Dive into AWS Penetration Testing https://infosecwriteups.com/deep-dive-into-aws-penetration-testing-a99192a26898?source=rss----7b722bfd1b8d---4 emp3r0r v0.9.27 releases: linux post exploitation framework https://securityonline.info/emp3r0r-v0-9-27-releases-linux-post-exploitation-framework/ Web Applications and Internal

IT Security News Bulletin #76

IT Security News Bulletin #76

Latest Infosec News and Articles Finding SSRF via HTML Injection inside a PDF file on AWS EC2  https://blog.appsecco.com/finding-ssrf-via-html-injection-inside-a-pdf-file-on-aws-ec2-214cc5ec5d90  Attacking Azure, Azure AD, and Introducing PowerZure https://posts.specterops.io/attacking-azure-azure-ad-and-introducing-powerzure-ca70b330511a Memory Analysis For Beginners With Volatility

IT Security News Bulletin #75

IT Security News Bulletin #75

Latest Infosec News and Articles Memory Analysis For Beginners With Volatility Part 2  https://infosecwriteups.com/memory-analysis-for-beginners-with-volatility-coreflood-trojan-part-2-42bdb46683f2 Exploiting Windows RPC to bypass CFG mitigation: analysis of CVE-2021-26411 in-the-wild sample https://iamelli0t.github.io/2021/04/10/RPC-Bypass-CFG.html A repository of sysmon configuration

IT Security News Bulletin #74

IT Security News Bulletin #74

Latest Infosec News and Articles How to Exploit Active Directory ACL Attack Paths Through LDAP Relaying Attacks  https://www.praetorian.com/blog/how-to-exploit-active-directory-acl-attack-paths-through-ldap-relaying-attacks/  Detecting Network Attacks with Wireshark https://www.infosecmatter.com/detecting-network-attacks-with-wireshark/ Bypass Cloudflare bot protection using Cloudflare Workers https://github.com/jychp/cloudflare-bypass Active

Weekly IT Security News Bulletin #73

Weekly IT Security News Bulletin #73

Latest Infosec News and Articles Exploit to SYSTEM for CVE-2021-21551 https://github.com/waldo-irc/CVE-2021-21551 ExifTool CVE-2021-22204 - Arbitrary Code Execution https://devcraft.io/2021/05/04/exiftool-arbitrary-code-execution-cve-2021-22204.html How to Silver Ticket Attack Active directory https://sheerazali.com/how-to-silver-ticket-attack-active-directory/ From theory to practice: analysis and PoC

IT Security News Bulletin #72

IT Security News Bulletin #72

Latest Infosec News and Articles OAuth 2.0 Hacking Simplified — Part 1 — Understanding Basics  https://infosecwriteups.com/oauth-2-0-hacking-simplified-part-1-understanding-basics-ad323cb4a05c?source=post_internal_links---------0---------------------------- DogWhisperer’s SharpHound Cheat Sheet https://insinuator.net/2021/05/dogwhisperers-sharphound-cheat-sheet/ Offensive Security Guide to SSH Tunnels and Proxies https://posts.specterops.io/offensive-security-guide-to-ssh-tunnels-and-proxies-b525cbd4d4c6 Misconfigured JSF ViewStates

IT Security News Bulletin #71

IT Security News Bulletin #71

Latest Infosec News and Articles Red Team utilities https://exploitpack.gitbook.io/exploit-pack-manual-pages/red-team-utilities Relaying Potatoes: Another Unexpected Privilege Escalation Vulnerability in Windows RPC Protocol https://labs.sentinelone.com/relaying-potatoes-dce-rpc-ntlm-relay-eop/ Just another "Won't Fix" Windows Privilege Escalation from User to Domain

>