Two vulnerabilities impacting Aviatrix Controller 7.2.5012 and prior versions were discovered by Mandiant Red Team ‼️
Learn how they exploited Aviatrix Controller through authentication bypass, unsafe file upload, and argument injection: bit.ly/448JV0Z
Got accepted to speak at @TheOffensiveX. Man, this will be so much fun. Heard so much amazing things about this conference. Really excited about this one!
Today, the United States launched a trade war against Canada: their closest partner and ally — their closest friend.
Canadians are reasonable, but we will not back down from a fight.
Not when our country is at stake.
🚀 Today I'm launching ArgFuscator: an open-source platform documenting command-line obfuscation tricks AND letting you generate your own
🔥 68 executables supported out of the box - use right away, make tweaks, or create your own
👉 Now available at argfuscator.net
#LOLBAS project update:
Entries now have placeholders for paths, URLs, and more. This makes it easier to visually see what parts are "variable", and for LOLBAS API users (lolbas-project.github.io/api/) it'll be easier to use with automation.
Check it out:
⭐ lolbas-project.github.io
@Oddvarmoe I did test it out but didn't get to use it on an engagement. It still worked great and didn't affect Outlook much. Just made some custom changes out of the box to make it more opsec safe!
Finally published Part 2 of my small "Malware Development Introduction" series (aka malware dev 101).
This post covers intro to process injection, practical malware evasion concepts in C++/C#, and various resources I use.
wsummerhill.github.io/redteam/2024/1…