mpgn

@mpgn.bsky.social

Flibustier du net ̿ ̿̿'̿'\̵͇̿̿\=(•̪●)=/̵͇̿̿/'̿̿ ̿ ̿ ̿ Podcast Hack'n Speak http://anchor.fm/hacknspeak Github https://github.com/mpgn

This looks off to you? Yeah... In the default configuration, NFS exposes THE ENTIRE FILE SYSTEM and not only the exported directory! This means that you can read every file on the system that is not root:root owned, e.g. /etc/shadow. But it can get even worse 1/4🧵

NFS escape to the root directory with NetExecNFS downloading the /etc/shadow file from a system with default NFS configs

🔐 Purple Team job alert ! 🛡️🚨🔥 Lucca ouvre un poste dans sa team sécu ! TL;DR : Du web, du k8s Talos, des millions de users, un prog de bounty mature, un ADN branché scalabilité dans une boîte qui cultive la transparence, l'expertise et la culture du challenge. Bref, vous en saurez plus ici :👇

Lucca - Confirmed / Senior Security Engineer - Purple Team

🎓 3 à 8 ans d'expérience requis en pentest et/ou red team 💼 Bac+5 💰 Salaire prévu entre 63 et 75K€ fixes bruts par an, selon l'expérience 📍 Nantes, Marseille, Paris ou Full remote (localisation en Fra...

jobs.lever.co

Generate a valid krb5 conf file directly from netexec 🔥 Not that NXC needs it, but sometimes you gotta help other tools for them to work. 😂

Bild

DCsync a domain when you find a user in the Backup Operators group using netexec, very simple and no need for a custom smb server 😛🏆

Bild

So you want to exploit ADCS ESC8 with only netexec and ntlmrelayx ? Fear not my friend, I will show you how to do it 👇 NetExec now supports "Pass-the-Cert" as an authentication method, thanks to @dirkjanm.io original work on PKINITtools ⛱️

BildBild

Few BloodHound python updates: LDAP channel binding is now supported with Kerberos auth (native) or with NTLM (custom ldap3 version). Furthermore, the BH CE collector now has its own pypi package and command. You can have both on the same system with pipx. github.com/dirkjanm/Blo...

GitHub - dirkjanm/BloodHound.py: A Python based ingestor for BloodHound

A Python based ingestor for BloodHound. Contribute to dirkjanm/BloodHound.py development by creating an account on GitHub.

github.com

I updated the diagram representing the different Point and Print configurations and their exploitation on my blog. Hopefully, this should provide a better understanding of the whole "PrintNightmare" situation to both defenders and red teamers. 🤞

Diagram representing the various Windows Point and Print configurations that reintroduce the PrintNightmare exploit variants.

Thanks to Xiaolichan, NXC is now capable of scanning your network without attempting SMBv1 first by using the flag --no-smbv1. This reduces unexpected errors and scan time on large networks. 👺 A new module has also been added to scan hosts vulnerable to the Remove-MIC vulnerability 🔥

Bild

If you want to first blood a windows box in @hackthebox.bsky.social every minute counts ! 🩸 I've added a special flag --generate-hosts-file so you just have to copy past into your /etc/hosts file and be ready to pwn as soon as possible 🔥

Bild