Michael Kruger

92 posts

Michael Kruger banner
Michael Kruger

Michael Kruger

@_cablethief

Security analyst. Random code bits at https://t.co/S7I4BYjc2V

South Africa Bergabung Ekim 2010
358 Mengikuti619 Pengikut
Alex Neff
Alex Neff@al3x_n3ff·
NetExec has a new Module: Timeroast🔥 In AD environments, the DC hashes NTP responses with the computer account NT hash. That means that you can request and brute force all computer accounts in a domain from an UNAUTHENTICATED perspective! Implemented by @Disgame_ 1/3🧵
Alex Neff tweet media
English
10
274
926
96.7K
Michael Kruger me-retweet
_leon_jacobs(💥)
_leon_jacobs(💥)@leonjza·
The fact that @AndresFreundTec didn't just write the whole xz thing off as "It's probably DNS" is honestly amazing.
English
0
2
8
814
Michael Kruger me-retweet
Matt Linton
Matt Linton@0xMatt·
Every once in a while I'm reminded that dnsmasq, a lightweight DNS and DHCP server that's bundled into *almost every IOT thing and Linux distro*, is a hobby project maintained by one guy in the UK named Simon. Nobody pays him and he doesn't get near the thanks he deserves.
English
45
682
5.6K
457.3K
Michael Kruger
Michael Kruger@_cablethief·
A quick Docker hostapd-mana RADIUS service for capturing creds using an external device: github.com/sensepost/bera… Bonus: Certificates with Lego and CF DNS are so convenient go-acme.github.io/lego/usage/cli… Bonus Bonus: join us at BH for further WiFi shenanigans #unplugged-modern-wi-fi-hacking-30636" target="_blank" rel="nofollow noopener">blackhat.com/us-23/training…
English
1
26
38
7.2K
Michael Kruger
Michael Kruger@_cablethief·
Excited to teach wireless hacking and try to convince more people that using wpa_sycophant is easier than it seems (most of the time 😝).
SensePost Training | Orange Cyberdefense@sensepost_train

The airwaves are constantly abuzz with signals.📶Wondering how to make sense of the 2.4 & 5GHz Wi-Fi frequency ranges? Come join our esteemed Wi-Fi training at #BlackHatUSA Visit ow.ly/Xmru50NHg4o for more info on the course & for bookings 🐦 Early bird tickets end 26 May

English
0
17
28
3.4K
Michael Kruger me-retweet
Orange Cyberdefense's SensePost Team
The RID500 Admin account doesn't benefit from Protected User Group restrictions. This is a MS WONTFIX & means you can authenticate as Admin using RC4 KRB or perform any KRB delegation attack if you impersonate the RID500 Admin. The latest find by @Defte_ sensepost.com/blog/2023/prot…
English
3
87
167
33.3K
Michael Kruger me-retweet
Dominic White 👾
Dominic White 👾@singe·
Another 0xC0FFEE session tonight with two guest speakers: Jeandre Mitton talking about using Pre/Post Scripts with Postman for CAPTCHA bypass and @leonjza talking about the LightNeuron malicious mail transport agent he built for MITRE ATT&CK purple teaming. 1/2
GIF
English
3
7
15
1.9K
Dominic White 👾
Dominic White 👾@singe·
Earlier today I though I’d found a 4x speed up on ntcrack. It turns out I was creating and array then clearing it and my quick test case of cracking the first hash of a wordlist passing had me miss it. I thought I had gotten lucky. @_cablethief those fireworks set themselves off!
English
2
0
7
0