Andre Marques

61 posts

Andre Marques banner
Andre Marques

Andre Marques

@_zc00l

Developer of Insecurity. Former Law student went to hacking. Working in Red Team for Morphus.

Sao Paulo, Brazil Katılım Nisan 2018
187 Takip Edilen625 Takipçiler
Andre Marques
Andre Marques@_zc00l·
@ichitake9 Will check that, but I am pretty sure that you're right... I even remember patching this code after awhile that it has been posted but can't remember what exactly I have modified. Anyway, thanks for noting and reporting. Will change that on the blog.
English
0
0
1
0
Andre Marques
Andre Marques@_zc00l·
@Pawp81 @ZHacker13 @l33ksss These days the offensive community is so acid about release of tools and information that I have become relutant of posting anything... A shame, because I think even some "incorrect" information can lead us to discover the "correct" one together, as it happened with AMSI for me.
English
0
0
1
0
Andre Marques
Andre Marques@_zc00l·
@Pawp81 @ZHacker13 @l33ksss Yes, I was wrong in many assumptions in that post. But I guess it is not completely useless and has served it's purpose of disseminating on how to circumvent that and execute your scripts. Which is why I had released it to public first place.. to help people.
English
0
0
2
0
👩🏻‍💻 Jane Scott 🇦🇺
Hey hackers! 🤗 I'm trying to see something. 🚧🔨👷🏻‍♀️💻 What is the language of the most recent script/program/exploit you wrote or used IN PRACTICE? Not talking your favorite one, or the best one: just the LAST one you used, on the ground, at the coalface. Please RT for reach!
English
54
75
92
0
Andre Marques
Andre Marques@_zc00l·
Now that it's no longer a 0day, check my post about "Coding a reliable CVE-2019-0841 bypass" to craft a LPE exploit that works for all versions of Microsoft Edge in Windows 10. 0x00-0x00.github.io/research/2019/…
English
2
93
189
0
Andre Marques
Andre Marques@_zc00l·
@_RastaMouse Yes, my VMWare Workstation 14 freezes when I plug any USB to my host. Tried to downgrade, nothing changed. Now I move to VirtualBox when I need USB for VMs...
English
0
0
0
0
Rasta Mouse
Rasta Mouse@_RastaMouse·
Anybody else finding VMware Workstation quite buggy on 1903? Particularly copying files from host to guest.
English
13
2
17
0
Nikhil Mittal
Nikhil Mittal@nikhil_mitt·
You asked, we did! After months of hard work, super glad to finish Attacking and Defending Active Directory :D A video course and live lab at PentesterAcademy @SecurityTube Registrations open soon!
English
10
32
111
0
Andre Marques
Andre Marques@_zc00l·
@_xpn_ @byt3bl33d3r Hmmm, so it is still viable by patching AMSI before loading assemblies. Thanks for testing it already!
English
0
0
1
0
Adam Chester 🏴‍☠️
@byt3bl33d3r So it passes the argument from Assembly.Load into AMSI to allow Defender (other AVs also available) to scan. Assembly.Load still works fine, but if AMSI picks up malware, an exception is thrown back to .NET
English
3
1
5
0
Adam Chester 🏴‍☠️
Quickly playing around with the .NET AMSI port (Early Release) and it looks like it is possible to bypass the added protections in similar ways to its Powershell counterpart youtu.be/avjPW_ea6QQ
YouTube video
YouTube
English
8
71
142
0