HoangSpecial

82 posts

HoangSpecial

HoangSpecial

@SpecialHoang

Security Researcher | Pentester | Red Team | APT69

Philadelphia, PA Katılım Aralık 2018
46 Takip Edilen1.3K Takipçiler
HoangSpecial
HoangSpecial@SpecialHoang·
@timmisiak look at rsp for example is great. The stack window is there but most the time I want to scroll further and beyond alongside with a more intuitive understanding of where I am in the stack is the only reason I am still on windbg :(. Thanks again for the great product!
English
1
0
0
0
HoangSpecial
HoangSpecial@SpecialHoang·
@timmisiak Thanks for the reply Tim! I appreciate it. One last suggestion (and maybe I am a coconut and haven't figure it out yet) but the ability to view memory as other forms (Pointer and Symbol to be specific) would be godsend. The ability to scroll &
English
1
0
0
0
HoangSpecial
HoangSpecial@SpecialHoang·
@timmisiak big fan of windbgx. Everything is much better and more fluid. However, just a feedback and it is that hotkey-only new windows suck. I had to ask tons of people after googling resulting in nothing useful (it was ctrl + shift + m). Would love a more intuitive way!
English
1
0
0
0
HoangSpecial
HoangSpecial@SpecialHoang·
@layle_ctf @ColtonSkees Because DB and CE's job is to provide hackers with a hacking tool. Not adding more and more security on top of already existing ones. Plus, it is open source. So this will require DB to: 1. wild goose chase on an open source software to keep you happy. 2. everyone signs their own
English
2
0
0
0
Layle
Layle@layle_ctf·
Did you ever want to load dbk64.sys yourself and abuse the fact that it's a signed driver? Maybe call the builtin kernel read/write (and many more!) routines because you don't have a driver signing certificate? You can do that now! Check it out ;) GitHub: github.com/ioncodes/ceload
Layle tweet media
English
5
83
276
0
HoangSpecial
HoangSpecial@SpecialHoang·
@layle_ctf But why tho? DarkByte wrote one of the greatest tool that every game hacker relies on and give it out for free. Why wouldn't you honor his wishes to keep things safe?
English
0
0
0
0
HoangSpecial
HoangSpecial@SpecialHoang·
Are there any Write-What-Where primitive left in W10 x64 1909? Seem like Gh?4 RGNOBJ is the only one intact and I'm not even sure if that is usable as a primitive. @msftsecurity, give back my GDI objects!
English
0
0
4
0
HoangSpecial retweetledi
Leo Loobeek
Leo Loobeek@leoloobeek·
New COM post (and PoC) just published. This one journeys into COM server development, building a component for offensive use cases that can then be loaded with registration-free COM. Feedback welcome. adapt-and-attack.com/2020/05/12/bui…
English
6
150
287
0
HoangSpecial retweetledi
Faisal Tameesh
Faisal Tameesh@primal0xF7·
During a recent long-term red team op, we bypassed CloudFlare to obtain a foothold on a subsidiary. AD forest exploitation followed, which allowed for compromising the parent company. This post focuses on bypassing CloudFlare WAF. aon.com/cyber-solution…
English
0
11
17
0
HoangSpecial
HoangSpecial@SpecialHoang·
@vysecurity When your opponent is a kernel level anticheat that disregards usability, privacy, stability, and compatibility, Modern EDR Solutions (TM) looks cute in comparison.
English
0
0
4
0
HoangSpecial
HoangSpecial@SpecialHoang·
@n4r1B Amazing work. Loves the attention to detail and how far you go into each of WD's module and structure =)
English
0
0
2
0
HoangSpecial
HoangSpecial@SpecialHoang·
@BillDemirkapi Similarly, I also happen to get to use forced exception through pointer destruction which is another nice trick to pair up with VEH. AGAIN, sorry for necroing this haha.
English
0
0
1
0
HoangSpecial
HoangSpecial@SpecialHoang·
@BillDemirkapi Sorry for replying to something a year back, was scrolling through my Twitter and realized I never replied, my fault. I think you know this by now that a lot of games do anticheat do use DR register as a way to stop debuggers from placing hwbp but your comment is correct =).
English
1
0
1
0
HoangSpecial
HoangSpecial@SpecialHoang·
Ever want to hook functions stealthily? Check out my new blog! Vectored Exception Handling Hooking! @fsx30/vectored-exception-handling-hooking-via-forced-exception-f888754549c6" target="_blank" rel="nofollow noopener">medium.com/@fsx30/vectore…
English
1
46
64
0
HoangSpecial
HoangSpecial@SpecialHoang·
@jasc22 @TomahawkApt69 @NCCGroupInfosec @leoloobeek If you can show me the code. It have a custom cmd that you can use, just ends with &. This should let you execute anything in cmd as admin. Sorry for the late reply, holiday and travel. Do let me know if you need more help we can hit up DM.
English
0
0
0
0
jasc22
jasc22@jasc22·
@SpecialHoang @TomahawkApt69 @NCCGroupInfosec @leoloobeek Hey @SpecialHoang, thanks for an excellent finding. I tested this on 1803 and am able to add a regular user to the local admin group but not able to add a new user. I modified the code to add a new user and tested it but that did not work either. Appreciate your thoughts on this.
English
1
0
1
0
HoangSpecial
HoangSpecial@SpecialHoang·
@vm_call This was always a known thing in project's file is it not? Just give a quick look around project file and solution file before opening.
English
0
0
1
0