home.social

#certificate — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #certificate, aggregated by home.social.

  1. Ledger — прохождение сложной машины от Tryhackme

    Ledger — это сложная машина Windows на TryHackMe, в центре которой находится неправильная конфигурация служб сертификатов Active Directory (AD CS). Первоначальная разведка выявляет контроллер домена ( labyrinth.thm.local ) с включенной аутентификацией SMB null и LDAP, раскрывающим учетные данные пользователя в примечаниях. Через certipy-ad находим шаблон сертификата ServerAuth , который уязвим к ESC1 , что позволяет любому аутентифицированному пользователю запросить сертификат, выдавая себя за администратора домена. Хэш NT администратора извлекается из поддельного сертификата, а psexec предоставляет командную оболочку NT AUTHORITY SYSTEM. Альтернативный путь эксплуатации через аутентификацию LDAP Schannel для случаев, когда Kerberos PKINIT не срабатывает.

    habr.com/ru/articles/1032298/

    #active_directory #certificate #esc #windows #nmap #cvss_v3 #mitre_attack #certipy #psexec #ldap

  2. IQ Tests for Children, Teens, and Adults: Which Type of Test Is Best for Each Age Group?

    As a clinical and forensic psychologist, one of the most common questions from parents and adults is not simply “What is my IQ?”, but “Which IQ test should we actually use at this age, and does it really matter?”.

    iqcertificate.org/blog/iq-test

    #iqtest #children #adult #psychologist #education #teen #school #certificate

  3. RE: infosec.exchange/@paulehoffman

    Side note: this is why things like "multi-perapective corroboration" for domain validation do not work.

    When every single packet to .ir nameservers and servers inside Iran pass through two (yes, 2!) gateways, then those controlling the gateways can acquire a valid domain validation certificate for any .ir domain or any server located in Iran.

    #x509 #dns #dnssec #certificate

  4. RE: abyssdomain.expert/@filippo/11

    An archive of all CT-logged certificates with all the tools needed for an analysis! No more scraping.

    #ctlog #x509 #certificate

  5. "The forged certification marks that are different on each part in the component series is your trusted sign of Qwality."

    #qwality #certification #forged #certificate #Chinesium #SafetyThird #electronic #component #AliExpress

  6. 在 Linux 下 MITM 的 httptap

    這兩天看到的有趣東西,可以在 Linux 在自動幫你塞 root CA,然後自動 MITM 攔截 HTTPS 連線的工具:「Httptap: View HTTP/HTTPS requests made by any Linux program (github.com/monasticacademy)」,

    blog.gslin.org/archives/2025/0

    #Computer #Linux #Murmuring #Network #OS #Security #Software #WWW #authority #ca #certificate #device #https #httptap #in #linux #man #middle #mitm #network #root #security #stack #tcp #the #traffic #tun

  7. Let's Encrypt 簽發新的 Intermediate CA

    Let's Encrypt 宣佈簽發新的 Intermediate CA:「New Intermediate Certificates」。

    這次用 ISRG Root X1 簽了很多東西出來:

    On Wednesday, March 13, 2024, Let’s Encr

    blog.gslin.org/archives/2024/0

    #Computer #Murmuring #Network #Privacy #Security #Service #authority #ca #certificate #ecdsa #intermediate #isrg #key #letsencrypt #p384 #pinning #privacy #root #rsa #security #x1 #x2

  8. "Reskilling. Upskilling. Certificates. Certifications. Badges. Licenses. Microcredentials. Alternative credentials. Digital credentials.So many terms. So little agreement on what they mean, least of all in #HigherEd."
    insidehighered.com/news/2023/0
    #Microcredentials #Degree #Students #Education #Universities #University #Certificate #Badge #Reskilling #Upskilling

  9. Hmm, strange, some apps won't start anymore ? Some #certificate bullshit again ? #N950 #N9 #meego #maemo