RedForce

26 posts

RedForce banner
RedForce

RedForce

@RedForceSec

security consultancy company providing offensive security services for unlimited scale of business.

Katılım Eylül 2018
19 Takip Edilen920 Takipçiler
RedForce retweetledi
Bug Bounty Reports Explained
Bug Bounty Reports Explained@gregxsunday·
The video about blind SSRF in Google Cloud for which @david_nechuta got $31k is out! Watch it to see how it's sometimes possible to exfiltrate data with blind SSRFs. You can also test your own skills with hands-on lab 😎 Enjoy! youtu.be/ashSoc59z1Y
YouTube video
YouTube
English
3
96
292
0
RedForce
RedForce@RedForceSec·
Our team member @0x4148 just published the 2nd part of windows authentication attacks. This part covers Kerberos authentication process and technical analysis of widely used Kerberos attacks. blog.redforce.io/windows-authen… Happy reading
RedForce tweet media
English
0
7
14
0
RedForce
RedForce@RedForceSec·
We've just published the 1st part of the Windows authentication attacks series. blog.redforce.io/windows-authen… The series suppose to cover the NTLM/Kerberos authentication in detail as well as how their attacks work. Happy reading, and stay tuned for part 2.
RedForce tweet media
English
0
15
31
0
jericho
jericho@attritionorg·
@RedForceSec ah in the news, I was looking for a security / advisory page. thanks!
English
1
0
0
0
RedForce
RedForce@RedForceSec·
We have updated the article with another "UNPATCHED" vector to achieve RCE. Thanks @Zombiehelp54 for the heads up. #RCE-Update" target="_blank" rel="nofollow noopener">blog.redforce.io/attacking-help…
RedForce@RedForceSec

Attacking Helpdesks (Part 1): Remote Code Execution (#RCE) chain on #Deskpro with #Bitdefender as a case study. Full technical details to #exploit RCE inside. blog.redforce.io/attacking-help… #BugBounty #websecurity #infosecwriteup

English
3
10
21
0
jericho
jericho@attritionorg·
@RedForceSec "and last (and only) security advisory on their current website was in 2015" Is that behind the portal that requires registration? If not, could you link to that please? Not seeing it on their site.
English
1
0
1
0
RedForce
RedForce@RedForceSec·
@bad_packets @AboodNour Always a pleasure. If you need further information, please don't hesitate to reach out
English
0
0
1
0
RedForce retweetledi
Ahmed Aboul-Ela
Ahmed Aboul-Ela@aboul3la·
This will have huge impact!, another great example on how RCE can be achieved on OWA easily through ViewState deserialization attack. Red Teamers it's your chance now :) thezdi.com/blog/2020/2/24…
English
5
77
164
0
RedForce retweetledi
André Baptista
André Baptista@0xacb·
Just released viewgen, a ViewState tool capable of generating both signed and encrypted payloads with leaked validation keys or web.config files. All algorithms supported. TL;DR: Got a web.config file or LFI on ASP.NET? Pop a shell! github.com/0xACB/viewgen
English
11
351
854
0