Marcos Díaz

91 posts

Marcos Díaz banner
Marcos Díaz

Marcos Díaz

@Calvaruga

España 参加日 Kasım 2009
1.7K フォロー中136 フォロワー
Marcos Díaz がリツイート
BlackArrow
BlackArrow@BlackArrowSec·
Just over 24 hours until @_kripteria takes the stage at @h_c0n to revisit the design and methodology of attack graphs in Active Directory, showcasing new approaches with Neo4LDAP.
BlackArrow tweet media
English
0
9
17
1.1K
Marcos Díaz がリツイート
Inés
Inés@ineesdv·
Tangled is a social engineering platform that weaponizes calendar event processing in Outlook and Gmail to deliver spoofed meeting invites that are automatically added to a user's calendar without interaction. github.com/ineesdv/Tangled Technical breakdown: tarlogic.com/blog/abusing-c…
English
2
45
148
9.2K
Marcos Díaz がリツイート
BlackArrow
BlackArrow@BlackArrowSec·
Meetings You Didn’t Plan, But We Did In this post, @ineesdv breaks down how calendar event processing in Outlook and Gmail can be abused to deliver spoofed meeting invites that are automatically added to a user's calendar without interaction ➡️Read more: tarlogic.com/blog/abusing-c…
BlackArrow tweet media
English
0
20
21
3K
Marcos Díaz がリツイート
BlackArrow
BlackArrow@BlackArrowSec·
Enhanced version of secretsdump from #Impacket to dump credentials without touching disk. This feature takes advantage of the WriteDACL privileges held by local administrators to provide temporary read permissions on registry hives. github.com/fortra/impacke…
English
3
127
305
24.1K
Marcos Díaz がリツイート
Nick Frichette
Nick Frichette@Frichette_n·
As someone involved in the AWS offsec space, I want to share why I strongly do NOT recommend the HackTricks AWS Red Team Expert course. The author of it is a plagiarist, stealing content from other creators and is directly profiting off of it through sponsorships. A 🧵
English
7
75
327
119.7K
Marcos Díaz がリツイート
Tarlogic
Tarlogic@Tarlogic·
🖱Did you know that your wireless mouse can be spoofed to take control of your computer? The @Tarlogic Innovation team has developed #BSAM, the first methodology to audit #Bluetooth devices and avoid situations like that 👇 tarlogic.com/news/bsam-blue…
English
0
10
11
964
Marcos Díaz がリツイート
BlackArrow
BlackArrow@BlackArrowSec·
Watchguard has fixed 4 vulnerabilities in Watchguard EPDR discovered by our researchers @antuache and @Calvaruga. These vulnerabilities can be used to turn-off the defensive capabilities of the product and achieve privilege escalation. ➡️ Advisories: watchguard.com/es/wgrd-psirt/…
BlackArrow tweet media
English
0
14
23
3.3K
Marcos Díaz がリツイート
BlackArrow
BlackArrow@BlackArrowSec·
In our latest post, @xassiz introduces a new technique to obtain cleartext passwords from MSSQL by abusing linked servers through the ADSI provider. ➡️ Read more: tarlogic.com/blog/linked-se…
BlackArrow tweet media
English
1
35
40
6.6K
Marcos Díaz がリツイート
Barbanza Clínica Mares Rugby Club
Boas Xente! Dende o Barbanza RC queremos acercar o mundo do rugby a maior xente posible polo que este sabado 6 de Maio imos montar un pequeno adestramento e comida posterior. Se algun dia pensaches en probar este marabilloso deporte, este é o teu momento! (1/2)
Barbanza Clínica Mares Rugby Club tweet media
Português
1
15
16
1.8K
Marcos Díaz がリツイート
BlackArrow
BlackArrow@BlackArrowSec·
Have you ever tried exploiting a Spring Boot Actuators RCE but the restart endpoint was disabled? ⬇️ Abuse this behaviour using this #TrickOrThreat by @antuache
BlackArrow tweet media
English
0
15
27
4.1K
Marcos Díaz がリツイート
MDSec
MDSec@MDSecLabs·
AutoDial(dll)ing Your Way - Lateral Movement and LSASS SSP using AutodialDLL, a new blog post and tool release (DragonCastle) by @TheXC3LL mdsec.co.uk/2022/10/autodi…
MDSec tweet media
English
7
110
231
0
Marcos Díaz がリツイート
X-C3LL
X-C3LL@TheXC3LL·
I just discovered that people copy texts from internet into a github book, then ask money and sponsors because of the great effort of doing ctrl + c && ctrl + v. What a trick!
English
3
2
21
0
Marcos Díaz がリツイート
BlackArrow
BlackArrow@BlackArrowSec·
We've extended @nopfor\ntlm_challenger with MSSQL support! This is useful when network segmentation prevents from reaching the SMB port ➡️ github.com/nopfor/ntlm_ch…
BlackArrow tweet media
English
0
18
25
0