manas3c's profile picture. 0x1

mjutsu

@manas3c

0x1

mjutsu reposted

"TakeMyRDP: A keystroke logger targeting the Remote Desktop Protocol (RDP) related processes, It utilizes a low-level keyboard input hook, allowing it to record keystrokes in certain contexts" #infosec #pentest #redteam github.com/TheD1rkMtr/Tak…

CyberWarship's tweet image. "TakeMyRDP: A keystroke logger targeting the Remote Desktop Protocol (RDP) related processes, It utilizes a low-level keyboard input hook, allowing it to record keystrokes in certain contexts"

#infosec #pentest #redteam 
github.com/TheD1rkMtr/Tak…

mjutsu reposted

Constantly updated list of links to blog posts, write-ups and papers related to cybersecurity (mostly reverse engineering and exploitation) github.com/0xor0ne/awesom… #cybersecurity #infosec

0xor0ne's tweet image. Constantly updated list of links to blog posts, write-ups and papers related to cybersecurity (mostly reverse engineering and exploitation) 

github.com/0xor0ne/awesom…

#cybersecurity #infosec
0xor0ne's tweet image. Constantly updated list of links to blog posts, write-ups and papers related to cybersecurity (mostly reverse engineering and exploitation) 

github.com/0xor0ne/awesom…

#cybersecurity #infosec

mjutsu reposted

Mark your calendar for OffSec's upcoming End-of-Year CTF! offs.ec/3G0lkjg


mjutsu reposted

Félicitations 🥳🎉🥳 à notre équipe qui ne cesse de nous représenter à l'international 🇹🇬 #cyber #CyberSecurity #share #October

RedTeamTG's tweet image. Félicitations 🥳🎉🥳 à notre équipe qui ne cesse de nous représenter à l'international 🇹🇬
#cyber #CyberSecurity #share #October

mjutsu reposted

MonitorsTwo retires on @hackthebox_eu. It starts with a CVE in Cacti where I get to look at a bunch of broken POCs and exploit manually. There's also a Docker CVE that lets me abuse the metadata between host and container to get root. 0xdf.gitlab.io/2023/09/02/htb…


mjutsu reposted
RedTeamTG's tweet image.

mjutsu reposted

Nous vous souhaitons un excellent début du mois d'août ! Que ce nouveau mois soit rempli de succès, de défis relevés avec brio, et d'opportunités qui se présentent à vous. #Redteam #redteamtg #helloaugust #infosec #cybersecurity #hacking #WeAreTogolese #offsec #Togo #TT228

RedTeamTG's tweet image. Nous vous souhaitons un excellent début du mois d'août ! Que ce nouveau mois soit rempli de succès, de défis relevés avec brio, et d'opportunités qui se présentent à vous.
#Redteam #redteamtg #helloaugust #infosec #cybersecurity #hacking #WeAreTogolese #offsec #Togo #TT228

mjutsu reposted

We're giving away an OSCP voucher to our community.🎉 To participate : 1. Follow us on Twitter. 2. Retweet this post. 3. Like this tweet. It's that simple! By completing these steps, you'll be eligible to win. Also, register now at threatcon.io/pricing. #offsec #giveaway

THREAT_CON's tweet image. We're giving away an OSCP voucher to our community.🎉

To participate :
1. Follow us on Twitter.
2. Retweet this post.
3. Like this tweet.

It's that simple! By completing these steps, you'll be eligible to win.
Also, register now at threatcon.io/pricing.
#offsec #giveaway

mjutsu reposted

I am proud of what I do and what we do and the goal we want to achieve. The @RedTeamTG is making its way. Thank you all mentors for the advice, suggestions and help, without forgetting the opportunities given. Thanks @manas3c @Isid0r3 @ashiahanim_ay


mjutsu reposted

You can use the Windows Search Protocol to coerce authentication from hosts running the Windows Search Service (Win10/11 only by default) as a regular domain user. Haven't been able to do WebDAV with it though so usefulness is limited. PoC: github.com/slemire/WSPCoe…


mjutsu reposted

Title:- Openfire Admin Console Auth Bypass CVE-2023-32315 🪲 What are you looking go checkout... dork:- http.title:"openfire console" poc: "{{base uri}}/setup/setup-s/%u002e%u002e/%u002e%u002e/log.jsp" #bugbountytip #BugBounty #Hacking #CVE #CyberSecurity #infosec

alone_breecher's tweet image. Title:- Openfire Admin Console Auth Bypass
 CVE-2023-32315 🪲

What are you looking go checkout...

dork:- http.title:"openfire console"

poc: "{{base uri}}/setup/setup-s/%u002e%u002e/%u002e%u002e/log.jsp"

#bugbountytip #BugBounty #Hacking #CVE #CyberSecurity #infosec
alone_breecher's tweet image. Title:- Openfire Admin Console Auth Bypass
 CVE-2023-32315 🪲

What are you looking go checkout...

dork:- http.title:"openfire console"

poc: "{{base uri}}/setup/setup-s/%u002e%u002e/%u002e%u002e/log.jsp"

#bugbountytip #BugBounty #Hacking #CVE #CyberSecurity #infosec

mjutsu reposted

We're proud to sponsor @NahamSec's #NahamCon2023! offs.ec/3J6WYqa ℹ️ NahamCon is a free virtual security conference! Join workshops, listen to speakers, and compete in a CTF. 2️⃣ winners will each receive a PEN-200 #OSCP 90-day course and certification bundle.

offsectraining's tweet image. We're proud to sponsor @NahamSec's #NahamCon2023! offs.ec/3J6WYqa

ℹ️ NahamCon is a free virtual security conference! Join workshops, listen to speakers, and compete in a CTF. 
2️⃣ winners will each receive a PEN-200 #OSCP 90-day course and certification bundle.

mjutsu reposted

the real CTF skill is Mergers & Acquisitions

gf_256's tweet image. the real CTF skill is Mergers & Acquisitions

mjutsu reposted

AllForOne This repository contains a Python script that allows bug bounty hunters and security researchers to collect all Nuclei YAML templates from various public repositories, helping to streamline the process of downloading multiple templates usin… t.me/hackgit/8838


mjutsu reposted

Red team/Bug bounty tips If you want to get a list of all employees (emails, names) that belongs to your target company! Try to find Jira Servicedesk, sometimes there is a misconfiguration that allows you to signup using your personal email! and get access to internal dashboards

silentgh00st's tweet image. Red team/Bug bounty tips
If you want to get a list of all employees (emails, names) that belongs to your target company! 
Try to find Jira Servicedesk, sometimes there is a misconfiguration that allows you to signup using your personal email! and get access to internal dashboards

mjutsu reposted

6. Best ways to regulate AI • Create a new agency to license & regulate AI models. • Create safety standards for AI models that identify & mitigate dangerous capabilities. • Require independent audits from experts to ensure compliance with safety standards.


mjutsu reposted

I'm sharing a tool to automate AD enumeration using PowerView (by @harmj0y ), link below. It was written and tested within the CRTO lab (by @zeropointsecltd ) github.com/Leo4j/Invoke-A…

L3o4j's tweet image. I'm sharing a tool to automate AD enumeration using PowerView (by @harmj0y ), link below.
It was written and tested within the CRTO lab (by @zeropointsecltd )
github.com/Leo4j/Invoke-A…

Loading...

Something went wrong.


Something went wrong.