offethhacker's profile picture.

Ethical Hacker

@offethhacker

Ethical Hacker أعاد

Google research created a dataset with rainbow tables for NetNTLMv1 with the 1122334455667788 challenge. research.google/resources/data… Dataset is available for download at: ▪️console.cloud.google.com/storage/browse… [Login required] ▪️gs://net-ntlmv1-tables

sekurlsa_pw's tweet image. Google research created a dataset with rainbow tables for NetNTLMv1 with the 1122334455667788 challenge. 
research.google/resources/data…
Dataset is available for download at:
▪️console.cloud.google.com/storage/browse… [Login required]
▪️gs://net-ntlmv1-tables

Ethical Hacker أعاد

How 1-click iOS exploit chains work (WebKit exploitation basics) youtu.be/o6mVgygo-hk?si…

ZygoSec's tweet image. How 1-click iOS exploit chains work (WebKit exploitation basics) youtu.be/o6mVgygo-hk?si…

Ethical Hacker أعاد

Some Chinese EDR company made a variant of crack.sh: ntlmv1.com


Ethical Hacker أعاد

Ever wanted to exhaustively list every ACE your user has on AD objects? Well, it’s now possible with DACLSearch. Whether for security research or making sure you didn't miss an interesting ACE, this tool is for you. 🔗 Repo link : github.com/cogiceo/DACLSe…


Ethical Hacker أعاد

TARMAGEDDON (CVE-2025-62518): RCE Vulnerability Highlights the challenges of open source abandonware edera.dev/stories/tarmag…


Ethical Hacker أعاد

One Dirk-jan (@_dirkjan) to save them all on Merill Fernando's (@merill) Entra ID show! 🔥 That's the podcast I can't miss 😀 youtube.com/watch?v=G_T79o…

mrgretzky's tweet card. I Found a Bug That Could Hack ANY Microsoft 365 Tenant - Here's What...

youtube.com

YouTube

I Found a Bug That Could Hack ANY Microsoft 365 Tenant - Here's What...


Ethical Hacker أعاد

#AppSec 1⃣ WSUS RCE (CVE-2025-59287) hawktrace.com/blog/CVE-2025-… ]-> PoC - gist.github.com/hawktrace/880b… // mitigation: requires replacing BinaryFormatter with secure serialization mechanisms, implementing strict type validation, and enforcing proper input sanitization on all cookie data…


Ethical Hacker أعاد

@_dirkjan found one of the most severe vulnerabilities ever discovered in Microsoft Entra ID. One that could have compromised every tenant in the cloud. In this episode, we unpack the story, the stress, and the mindset behind responsible disclosure. 🔥 We dive deep into his…

merill's tweet image. @_dirkjan found one of the most severe vulnerabilities ever discovered in Microsoft Entra ID.

One that could have compromised every tenant in the cloud.

In this episode, we unpack the story, the stress, and the mindset behind responsible disclosure. 🔥

We dive deep into his…


Ethical Hacker أعاد

More HW security goodness from Arm: community.arm.com/arm-community-… vMTE (Virtual Memory Tagging) allows to use MTE in a more flexible way, consuming less RAM. POE2 allows to build efficient in-process sandboxes and isolation. More-or-less improvement over x86 Memory Protection Keys.

First mention of x86 memory tagging (aka MTE) by both Intel and AMD (codename ChkTag): community.intel.com/t5/Blogs/Tech-… amd.com/en/blogs/2025/… 🤘🤘🤘



Ethical Hacker أعاد

Yes this blog post CVE-2023-35317 This blog post CVE-2025-59287 hawktrace.com/blog/CVE-2025-… Poc: gist.github.com/hawktrace/76b3…


Ethical Hacker أعاد

ksmbd - Exploiting CVE-2025-37947 Article by @73696e65 about locally exploiting CVE-2025-37947 — a page OOB write in the ksmbd module. Article: blog.doyensec.com/2025/10/08/ksm… Exploit: github.com/doyensec/KSMBD…

linkersec's tweet image. ksmbd - Exploiting CVE-2025-37947

Article by @73696e65 about locally exploiting CVE-2025-37947 — a page OOB write in the ksmbd module.

Article: blog.doyensec.com/2025/10/08/ksm…
Exploit: github.com/doyensec/KSMBD…

Ethical Hacker أعاد

🛠️ AsmLdr Shellcode loader for Windows x64 environments. Execute encrypted payloads while minimizing detection by advanced antivirus software, endpoint detection and response (EDR) systems, sandboxes, and debuggers Try: github.com/0xNinjaCyclone…


Ethical Hacker أعاد

I found it: “By September 2008 we had built a system that screened millions of crashes for security exploits.  Along the way I felt like I joined the world’s smallest profession—that of an exploit failure engineer.” web.archive.org/web/2016081818…


Ethical Hacker أعاد

Public proof-of-concepts combined in new ways create highly evasive malware. The techniques aren't novel but the execution is. Full technical breakdown with IOCs: expel.com/blog/along-for…


Ethical Hacker أعاد

Patch Diffing CVE-2024-23265: An iOS Kernel Memory Corruption Vulnerability - @8kSec 8ksec.io/patch-diffing-…


Ethical Hacker أعاد

Inspired by @TrustedSec article on remotely starting Windows services, enjoy our python unauthenticated EFS trigger developed with @Hypnoze57 Enjoy! github.com/Hypnoze57/rpc2…


Loading...

Something went wrong.


Something went wrong.