NULLKrypt3rs

34 posts

NULLKrypt3rs

NULLKrypt3rs

@NULLKrypt3rs

CTF Team || IIIT-Allahabad

Allahabad, India Katılım Kasım 2018
138 Takip Edilen93 Takipçiler
NULLKrypt3rs retweetledi
HTTPVoid
HTTPVoid@httpvoid0x2f·
Thread - Confluence Blind OGNL Injection analysis from our limited java knowledge. From vulnerable sink to becoming admin of the confluence instance. #CVE-2022-26134. Tested on latest vulnerable version 7.18.0.
English
3
151
444
0
NULLKrypt3rs retweetledi
Anton
Anton@ByQwert·
Open redirect vulnerability and how to use it "correctly" in bug bounty 🙃 link.medium.com/ftOSGKkZtqb
English
32
398
1.1K
0
NULLKrypt3rs retweetledi
Imran Huda(Ahhad)
Imran Huda(Ahhad)@imranHudaA·
Interesting account takeover of the day. The site was hosting their pentest.test.com on amazonaws While resetting my password I have noticed that the host was getting passed in json body
Imran Huda(Ahhad) tweet media
English
12
70
286
0
NULLKrypt3rs retweetledi
Charlie Bromberg « Shutdown »
Here are the slides for my talk « Delegating Kerberos to bypass Kerberos delegation limitation » 😈 at @1ns0mn1h4ck #INS22 #talk" target="_blank" rel="nofollow noopener">thehacker.recipes/ad/movement/ke…
Charlie Bromberg « Shutdown » tweet mediaCharlie Bromberg « Shutdown » tweet mediaCharlie Bromberg « Shutdown » tweet mediaCharlie Bromberg « Shutdown » tweet media
English
16
233
593
0
NULLKrypt3rs retweetledi
Yarden Shafir
Yarden Shafir@yarden_shafir·
Trying to learn security research and getting overwhelmed by all the details? I just published a guide showing my process for step-by-step analysis of a security feature: windows-internals.com/an-exercise-in…
Yarden Shafir tweet media
English
20
573
2.1K
0
NULLKrypt3rs retweetledi
FrenchYeti
FrenchYeti@FrenchYeti·
New Interruptor 0.1 release 🔥 add Follow Thread 🥳, Kernel API constants usable by their names into hooks🥰, configurable output, smart modules/interrupts filtering github.com/FrenchYeti/int…
FrenchYeti tweet media
English
0
13
45
0
NULLKrypt3rs retweetledi
Rémi GASCOU (Podalirius)
Rémi GASCOU (Podalirius)@podalirius_·
[#thread 🧵] Last week in #Microsoft #PatchTuesday, a critical vulnerability was patched that theoretically allows attackers to achieve Remote Code Execution on a target #IIS server (CVE-2022-21907). I'll explain how it works in this thread ⬇️
Rémi GASCOU (Podalirius) tweet media
English
2
38
125
0
NULLKrypt3rs retweetledi
Rémi GASCOU (Podalirius)
Rémi GASCOU (Podalirius)@podalirius_·
I'm proud to present a new tool, #LDAPmonitor! With this you can monitor creation, deletion and changes to LDAP objects live during your pentest or system administration! Lots of authentication types are supported, and output can be saved to a file. github.com/p0dalirius/LDA…
English
12
191
475
0
NULLKrypt3rs retweetledi
Abhishek Karle
Abhishek Karle@AbhishekKarle3·
My recent Bounties 🤑
Abhishek Karle tweet media
English
2
2
67
0
NULLKrypt3rs retweetledi
Nikhith
Nikhith@Nikhith_·
Revisiting an old bug which paid off really well during a previous Red Team op. The good old Microsoft Exchange unauthenticated email relay. This was particularly impactful. Here's why: 🌶️Unauthenticated 🌶️No phishing infra needed 🌶️Emails land directly in user's inbox (1/4)
English
2
9
37
0
NULLKrypt3rs retweetledi
Rasta Mouse
Rasta Mouse@_RastaMouse·
@l42Y_ Works fine for me.
English
1
1
2
0
NULLKrypt3rs retweetledi
Hack In The North
Hack In The North@hintIIITA·
Hola folks, With Hacka-demic in close sight, we are glad to announce the prizes and goodies awaiting the winners. Hoping the poll has added flavors to your curiosity on the possible themes, we are more than excited to witness your take on our themes. (1/2)
Hack In The North tweet media
English
1
15
30
0