#petitpotam — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #petitpotam, aggregated by home.social.
-
Что общего между PetitPotam, NTLM Relay и PrintNighmare? Рассказываем, к чему может привести отсутствие обновлений
Команда Центра кибербезопасности УЦСБ продолжает рассказывать о самых интересных практиках пентеста. Напоминаем, что в прошлой статье мы писали о том, как нам удалось пробить периметр с двух точек: Windows- и Linux-серверов, а также захватить внутреннюю инфраструктуру компании. В этот раз мы покажем, как компрометация домена Active Directory (AD) может привести к полной остановке деятельности компании на неопределенное время. Надеемся, наши кейсы будут вам полезны, а этот опыт позволит избежать схожих проблем!
https://habr.com/ru/articles/787018/
#информационная_безопасность #пентест #activedirectory #petitpotam #ntlm_relay #printnightmare
-
New in #Metasploit: SugarCRM #RCE, login scanner and credential gatherer for Wowza Streaming Engine Manager, and three new methods for #PetitPotam.
Plus, admin/kerberos/forge_ticket now supports a new extra_sids option — which is useful for including cross-domain SIDs for forging external #Kerberos trust tickets as part of cross-trust domain escalation. The admin/kerberos/inspect_ticket has also been updated to support viewing these extra SID values.
More Kerberos and secrets dumping improvements in this week's wrap-up!
https://www.rapid7.com/blog/post/2023/03/10/metasploit-weekly-wrap-up-196/
-
New in #Metasploit: SugarCRM #RCE, login scanner and credential gatherer for Wowza Streaming Engine Manager, and three new methods for #PetitPotam.
Plus, admin/kerberos/forge_ticket now supports a new extra_sids option — which is useful for including cross-domain SIDs for forging external #Kerberos trust tickets as part of cross-trust domain escalation. The admin/kerberos/inspect_ticket has also been updated to support viewing these extra SID values.
More Kerberos and secrets dumping improvements in this week's wrap-up!
https://www.rapid7.com/blog/post/2023/03/10/metasploit-weekly-wrap-up-196/
-
It's happening! Go watch this guy hack on #PetitPotam in #Metasploit: https://www.twitch.tv/zerosteiner
-
It's happening! Go watch this guy hack on #PetitPotam in #Metasploit: https://www.twitch.tv/zerosteiner
-
Metasploit's holiday hacking challenge debuts in TryHackMe's Advent of Cyber series tomorrow, December 9: https://tryhackme.com/christmas
For double the holiday fun, @zeroSteiner is also streaming on Twitch tomorrow at 4:30 EST (US). Jump on the stream to watch him add new methods to our #PetitPotam module (for better authentication coercion): https://www.twitch.tv/zerosteiner
-
Metasploit's holiday hacking challenge debuts in TryHackMe's Advent of Cyber series tomorrow, December 9: https://tryhackme.com/christmas
For double the holiday fun, @zeroSteiner is also streaming on Twitch tomorrow at 4:30 EST (US). Jump on the stream to watch him add new methods to our #PetitPotam module (for better authentication coercion): https://www.twitch.tv/zerosteiner
-
#Petitpotam hat aus 2021 angerufen und möchte nochmals gepatcht werden #Windows #Sicherheit #Update Mai 2022
-
Microsoft Patch Tuesday, May 2022 Edition https://krebsonsecurity.com/2022/05/microsoft-patch-tuesday-may-2022-edition/ #MicrosoftPatchTuesdayMay2022 #TrendMicroZeroDayInitiative #LocalSecurityAuthortity #WindowsPrintSpooler #CVE-2022-26925 #CVE-2022-26937 #DustinChilds #SatnamNarang #TimetoPatch #GregWiseman #PetitPotam #Tenable #Rapid7 #adobe
-
heise+ | IT-Security: PetitPotam und andere Wege, die Kontrolle über das AD zu übernehmen
Ein Angriff auf die Standardkonfiguration vieler Windows-Netze ermöglicht es, die Rechte eines Domänenadministrators zu erlangen.
IT-Security: PetitPotam und andere Wege, die Kontrolle über das AD zu übernehmen -
Es gibt wichtige Sicherheitsupdates für unter anderem kritische Lücken in Azure, Edge und verschiedenen Windows-Versionen.
Patchday: Microsoft meldet abermals Attacken auf Windows -
Smashing Security podcast #238: Fashion captain, fraud family, and DEF CON. D’oh! https://grahamcluley.com/smashing-security-podcast-238/ #SmashingSecurity #Vulnerability #vulnerability #databreach #PetitPotam #Microsoft #Dataloss #Phishing #phishing #Podcast #Windows #DEFCON
-
Unser werktäglicher News-Überblick fasst die wichtigsten Nachrichten des Tages kurz und knapp zusammen.
Kurz informiert: Rohstoffmangel, Kartellwächter, PetitPotam, Ingenuity -
Forscher demonstrieren einen neuen Weg, sich zum König einer Windows-Domäne aufzuschwingen. Microsoft zuckt mit den Achseln und verweist auf Härtungsmaßnahmen.
Windows-Netze verwundbar für Relay-Angriff PetitPotam