#privesc — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #privesc, aggregated by home.social.
-
Researcher publicly disclosed an NTLM reflection bypass, CVE-2026-24294, with PoC exploit code. It gives SYSTEM on Windows Server 2025. Patch now.
#NTLM #NTLMReflection #CVE202624294 #Windows #PrivEsc #Cybersecurity #Infosec
-
Researcher publicly disclosed an NTLM reflection bypass, CVE-2026-24294, with PoC exploit code. It gives SYSTEM on Windows Server 2025. Patch now.
#NTLM #NTLMReflection #CVE202624294 #Windows #PrivEsc #Cybersecurity #Infosec
-
-
-
Just published a proof-of-concept exploit for CVE-2025-32463, a new Linux privilege escalation vulnerability affecting sudo discovered and disclosed by Stratascale about 2 weeks ago.
The PoC is available on GitHub. A full technical writeup will be published on my blog soon.
GitHub: https://github.com/morgenm/sudo-chroot-CVE-2025-32463
#CyberSecurity #ExploitDev #Linux #CVE #PrivilegeEscalation #Infosec #Exploit #Rust #PrivEsc
-
Just published a proof-of-concept exploit for CVE-2025-32463, a new Linux privilege escalation vulnerability affecting sudo discovered and disclosed by Stratascale about 2 weeks ago.
The PoC is available on GitHub. A full technical writeup will be published on my blog soon.
GitHub: https://github.com/morgenm/sudo-chroot-CVE-2025-32463
#CyberSecurity #ExploitDev #Linux #CVE #PrivilegeEscalation #Infosec #Exploit #Rust #PrivEsc
-
Cool and very well done #38c3 talk about privilege escalation vulnerabilities in endpoint security products via COM Hijacking/named pipe communications and RPC by 0x4d5a and k0lj4.
- Talk: https://media.ccc.de/v/38c3-der-schlssel-zur-compromittierung-local-privilege-escalation-schwachstellen-in-av-edrs
- Slides: https://github.com/0x4d5a-ctf/38c3_com_talk -
Jak można było przejąć tysiące urządzeń z systemem Linux – czyli o niefrasobliwych nawykach pentesterów
Uruchamianie programów w formie skryptów oraz binariów to chleb powszedni pentesterów i administratorów. Rozsądek, profesjonalizm oraz dobre praktyki nakazują, aby dokonywać wnikliwego sprawdzenia zawartości uruchamianych programów, by nie wyrządzić szkody w zarządzanym, używanym lub testowanym systemie. Przykład historyczny Wyśmiewani w gronie ludzi zajmujących się bezpieczeństwem tzw. script kiddies już lata...
#WBiegu #Enumeracja #Konto #Linux #Privesc #Supplychain #Windows
-
Jak można było przejąć tysiące urządzeń z systemem Linux – czyli o niefrasobliwych nawykach pentesterów
Uruchamianie programów w formie skryptów oraz binariów to chleb powszedni pentesterów i administratorów. Rozsądek, profesjonalizm oraz dobre praktyki nakazują, aby dokonywać wnikliwego sprawdzenia zawartości uruchamianych programów, by nie wyrządzić szkody w zarządzanym, używanym lub testowanym systemie. Przykład historyczny Wyśmiewani w gronie ludzi zajmujących się bezpieczeństwem tzw. script kiddies już lata...
#WBiegu #Enumeracja #Konto #Linux #Privesc #Supplychain #Windows
-
Absurdalnie prosta do wykorzystania krytyczna podatność w urządzeniach od Palo Alto (unauth RCE jako root). Luka jest już wykorzystywana przez atakujących.
Kolejne zaskakująco proste podatności w PAN-OS są używane przez zewnętrznych aktorów. Badacze z grupy WatchTowr sprawdzili, jakich metod używają przestępcy oraz jakie środki zaradcze podjął producent.
#WBiegu #Authbypass #Paloalto #Privesc #Sslvpn #Unauthrce #Websec
-
🆕 New blog post! "The PrintNightmare is not Over Yet"
ℹ️ In this article, I take a look back at a previous post I wrote earlier this year about PrintNightmare. It turns out the Point and Print configuration I recommended at the end is still prone to Man-in-the-Middle attacks. So, I discuss that here, as well as additional mitigation I considered.
Props to @parzel and @l4x4 who both reported this issue to me.
-
🆕 New blog post! "The PrintNightmare is not Over Yet"
ℹ️ In this article, I take a look back at a previous post I wrote earlier this year about PrintNightmare. It turns out the Point and Print configuration I recommended at the end is still prone to Man-in-the-Middle attacks. So, I discuss that here, as well as additional mitigation I considered.
Props to @parzel and @l4x4 who both reported this issue to me.
-
Another cool blog post by @sploutchy (Compass Security)
"COM Cross-Session Activation"
Quick read, and straight to the point. This article provides a real-life example (Google Updater service here) showing one way to exploit a COM class for local privilege escalation on Windows. 👌
👉 https://blog.compass-security.com/2024/10/com-cross-session-activation/
-
How COM Cross-Session Activation on Windows works and how it can be used for privilege escalation with an example of Google Chrome: https://blog.compass-security.com/2024/10/com-cross-session-activation/ #windows #privesc #pentest
-
Autobloody dockerized
"This tool automates the AD privesc between two AD objects, the source (the one we own) and the target (the one we want) if a privesc path exists in BloodHound database."
-
Recent privilege escalation vulnerabilities in GNU C Library #glibc widely used in many #Linux distributions such as #Debian, #Ubuntu, #Fedora and others.
CVE-2023-6246 #privesc #vuln can be triggered via #syslog by using long program name or ident parameter in openlog().
Another vulnerability is in #qsort function. While real-world affected programs are currently not known, this vulnerability is pretty old - since 1992 until now.
This is just another reason to consider using Linux distribution without glibc, for example #Alpine Linux with #musl
-
Recent privilege escalation vulnerabilities in GNU C Library #glibc widely used in many #Linux distributions such as #Debian, #Ubuntu, #Fedora and others.
CVE-2023-6246 #privesc #vuln can be triggered via #syslog by using long program name or ident parameter in openlog().
Another vulnerability is in #qsort function. While real-world affected programs are currently not known, this vulnerability is pretty old - since 1992 until now.
This is just another reason to consider using Linux distribution without glibc, for example #Alpine Linux with #musl
-
New #Linux #glibc flaw lets attackers get root on major distros
#Privesc #cybersecurity
https://www.bleepingcomputer.com/news/security/new-linux-glibc-flaw-lets-attackers-get-root-on-major-distros/ -
Krytyczna luka w Visual Studio załatana – błąd pozwalał na eskalację uprawnień do NT AUTHORITY\SYSTEM
Środowiska developerskiego Visual Studio nie trzeba przedstawiać. To bardzo zaawansowane narzędzie od Microsoft, skrywające wiele ficzerów przydatnych programistom, a także pentesterom i badaczom bezpieczeństwa. W ostatni Patch Tuesday Microsoft wypuścił łatkę na podatność umożliwiającą eskalacja uprawnień (privilege escalation), która otrzymała identyfikator CVE-2024-20656. Autorem znaleziska jest Filip Dragovic z MDsec. W...
-
“The goal in #cloud #pentesting is not to get to IAM administrative access. The goal as a consultant is to ask the client where the most sensitive data is located. If you are an in-house #pentester or Red Teamer, the goal is to work with business units across your organization to ask where the sensitive data is located. That is where you focus your time and effort to get to that data by any means necessary, such as identifying misconfigurations or performing #privesc.”
-
“The goal in #cloud #pentesting is not to get to IAM administrative access. The goal as a consultant is to ask the client where the most sensitive data is located. If you are an in-house #pentester or Red Teamer, the goal is to work with business units across your organization to ask where the sensitive data is located. That is where you focus your time and effort to get to that data by any means necessary, such as identifying misconfigurations or performing #privesc.”
-
I have an #exploit that takes 4 hours to trigger, with no obvious way to speed it up. Oh well, at least it should still give me #privesc to local SYSTEM. #infosec #hacking #exploitdevelopment
-
I have an #exploit that takes 4 hours to trigger, with no obvious way to speed it up. Oh well, at least it should still give me #privesc to local SYSTEM. #infosec #hacking #exploitdevelopment
-
-
-
Independence Day sale active now for the next 5 days! Get all my courses / bundles for 50% off using coupon code MURICA2023 😉
My Site: https://courses.tib3rius.com/p/privilege-escalation-for-oscp-and-beyond-bundle?coupon_code=MURICA2023
@Hackers_Academy: https://hackersacademy.com/courses/privilege-escalation-oscp-windows-linux-bundle?coupon=MURICA2023Udemy:
https://www.udemy.com/course/windows-privilege-escalation/?couponCode=MURICA2023
https://www.udemy.com/course/linux-privilege-escalation/?couponCode=MURICA2023Please share! #OSCP #InfoSec #CyberSecurity #PrivEsc
-
Independence Day sale active now for the next 5 days! Get all my courses / bundles for 50% off using coupon code MURICA2023 😉
My Site: https://courses.tib3rius.com/p/privilege-escalation-for-oscp-and-beyond-bundle?coupon_code=MURICA2023
@Hackers_Academy: https://hackersacademy.com/courses/privilege-escalation-oscp-windows-linux-bundle?coupon=MURICA2023Udemy:
https://www.udemy.com/course/windows-privilege-escalation/?couponCode=MURICA2023
https://www.udemy.com/course/linux-privilege-escalation/?couponCode=MURICA2023Please share! #OSCP #InfoSec #CyberSecurity #PrivEsc
-
#^Hacking Campaign Actively Exploiting Ultimate Member Plugin - WPScan WordPress SecurityRecently, Automattic’s WP.cloud and Pressable.com platforms identified a trend in compromised sites, where rogue new administrator accounts kept appearing in the affected sites. After some investigation, we witnessed a post on the WordPress.org support forums by Slavic Dragovtev discussing a potential security issue, specifically a Privilege Escalation vulnerability, with the Ultimate Member plugin (200,000+ active installs). Worryingly, there were indications that this issue was being actively exploited by malicious actors.
In response to the vulnerability report, the creators of the plugin promptly released a new version, 2.6.4, intending to fix the problem. However, upon investigating this update, we found numerous methods to circumvent the proposed patch, implying the issue is still fully exploitable.
This is a nasty one! If you have a WordPress site with the Ultimate Member plugin installed, disable it immediately until the fix in version 2.6.7 has been confirmed.
Update: The latest version 2.6.7 has been confirmed to fix the issue. Anyone running the plugin should upgrade immediately, this vulnerability is being actively exploited!
Update 2: Also check the official advisory from the plugin vendor for further actions to take after the plugin has been updated: https://docs.ultimatemember.com/article/1866-security-incident-update-and-recommended-actions
#WordPress #WPScan #infosec #security #privesc -
Another #cloudsecurity tool on our #Cloud 9 list: #GitOops! Use this #pentesting tool to find #privesc paths as well as for lateral movement in #GitHub.
Read our full list ☁ ⬇
https://bfx.social/43C7Dkn -
Another #cloudsecurity tool on our #Cloud 9 list: #GitOops! Use this #pentesting tool to find #privesc paths as well as for lateral movement in #GitHub.
Read our full list ☁ ⬇
https://bfx.social/43C7Dkn -
I just looked into this and would recommend using https://github.com/CISOfy/Lynis or some other alterntive instead of rkhunter
rkhunter is a bit too basic. It does not seem to reach out to download new signatures at all. This is blessing insofar that the download of it I found was from 2017, so the website where it downloads its signatures could have been taken over by somebody else in the meantime and been used to hack people running it.
Unfortunately, this also means the signatures it uses are from 2017. Meaning, rkhunter won't flag on any malware that came out in the last 6 years.
I also got a fair number of false positives on a fresh install of kali like @CyberMatt1
#Lynis did great, on the other hand:
- Didnt allow me to run it in a way that allows it to become a #privesc vector (run as root, files owned by user -> cronjob run this -> privesc)
- Recommended installing a lot of best practice debian hardening packages like fail2ban
- 48 Suggestions of stuff to improve. Some of it was because I ran it on a desktop vm linux distro instead of a server. Makes sense! -
:hacker_z: :hacker_o: :hacker_d: :hacker_s: :hacker_e: :hacker_c: 0xD :verified: @[email protected] ·Dirty Pipe: CVE-2022-0847 - I have just completed this room! Check it out: https://tryhackme.com/room/dirtypipe #tryhackme #dirty pipe #CVE-2022-0847 #Linux #Kernel #Privesc #Walkthrough #Tutorial #Beginner #MuirlandOracle #dirty #pipe #dirtypipe via @RealTryHackMe
-
:hacker_z: :hacker_o: :hacker_d: :hacker_s: :hacker_e: :hacker_c: 0xD :verified: @[email protected] ·Vulnversity - I have just completed this room! Check it out: https://tryhackme.com/room/vulnversity #tryhackme #recon #privesc #webappsec #video #vulnversity via @RealTryHackMe
-
:hacker_z: :hacker_o: :hacker_d: :hacker_s: :hacker_e: :hacker_c: 0xD :verified: @[email protected] ·Linux PrivEsc - I have just completed this room! Check it out: https://tryhackme.com/room/linuxprivesc #tryhackme #privesc #privilege escalation #linux #linux privilege escalation #tib3rius #linuxprivesc via @RealTryHackMe
-
POC for Linux privilege escalation Vulnerability "CVE-2022-2602": DirtyCred File Exploitation applied on an io_uring UAF
Poc:
https://github.com/kiks7/CVE-2022-2602-Kernel-Exploit#infosec #privesc #linux #linuxexploits #kernelexploitation #binaryexploitation #exploitation
-
POC for Linux privilege escalation Vulnerability "CVE-2022-2602": DirtyCred File Exploitation applied on an io_uring UAF
Poc:
https://github.com/kiks7/CVE-2022-2602-Kernel-Exploit#infosec #privesc #linux #linuxexploits #kernelexploitation #binaryexploitation #exploitation
-
Several #vulnerabilities were identified in Avicena Medical Laboratory by Bishop Fox Researcher Dardan Prebreza. The issues were as follows:
- A critical remote incorrect access control vulnerability that could be exploited to retrieve ~166,000 COVID-19 test results
- A low-risk bug involving vulnerable software that could lead to #privesc
See the technical write-up for more info: https://bishopfox.com/blog/160k-covid-19-records
-
Several #vulnerabilities were identified in Avicena Medical Laboratory by Bishop Fox Researcher Dardan Prebreza. The issues were as follows:
- A critical remote incorrect access control vulnerability that could be exploited to retrieve ~166,000 COVID-19 test results
- A low-risk bug involving vulnerable software that could lead to #privesc
See the technical write-up for more info: https://bishopfox.com/blog/160k-covid-19-records
-
Die eigentliche Meldung ist nicht wirklich überraschend.
Aber ein heimlich gefixter "Anti-#Rootkit-Treiber" mit eingebautem #PrivEsc-Service, wie soll das noch getoppt werden?
#InfoSec #AntiVirus Desaster
-
Die eigentliche Meldung ist nicht wirklich überraschend.
Aber ein heimlich gefixter "Anti-#Rootkit-Treiber" mit eingebautem #PrivEsc-Service, wie soll das noch getoppt werden?
#InfoSec #AntiVirus Desaster
-
CertPotato – Using #ADCS to #privesc from virtual and network service accounts to local system
-
This looks like a nasty one! I've always been suspicious of snap and the general direction Ubuntu has been headed in this regard. I doubt this'll be the last we hear about these types of flaws.
#cybersecurity #cybersecuritynews #privesc #Linux #Ubuntu
https://securityaffairs.co/wordpress/139209/hacking/three-linux-bugs-full-root-privileges.html
-
OK, so I'm going to drop a nice #ZeroDay here. At least I think it's 0day, but for bring your own vulnerable driver purposes it's still not blocklisted (despite reporting it months ago, maybe MS only adds drivers that are actively exploited):
BattlEye Anti-Cheat
BEDAISY.SYSPPL privesc:- Have the string
"top BEService&pi"somewhere in your executable PE image. You can just write it to .data if you want. - Load bedaisy.
- Open its
\\?\GLOBALROOT\Device\BattlEyedevice. - Write a 9-byte zerofilled buffer to it.
- Congratulations, you just got WinTCB PPL, go tamper with
lsassor whatever.
- Have the string