Mor Davidovich

130 posts

Mor Davidovich banner
Mor Davidovich

Mor Davidovich

@dec0ne

Security Researcher | Red Teamer | Malware Developer

Katılım Temmuz 2020
388 Takip Edilen1.7K Takipçiler
Mor Davidovich retweetledi
MANSK1ES
MANSK1ES@mansk1es·
Check out my new blog post, "Weaponizing Background Images for Information Disclosure and LPE" where I walk through the AnyDesk vuln I found a few months ago (CVE-2024-12754/ZDI-24-1711): mansk1es.gitbook.io/AnyDesk_CVE-20…
English
2
21
69
5.5K
Mor Davidovich
Mor Davidovich@dec0ne·
@alisaesage I've wanted to get into fuzzers since I started in this field. Good resources are hard to find, so I always put that off. This could really help jump-start my learning process and expand my team's capabilities.
English
0
0
1
218
Mor Davidovich retweetledi
Alisa Esage Шевченко
Alisa Esage Шевченко@alisaesage·
Happy Solstice! Time to celebrate Truth and Justice. I appreciate your support; and I want to let you try one of my value-packed & expensive commercial masterclasses: ☀️ Masterclass: Hacking Fuzzers for Smarter Bughunting (on-demand video) #fuzzing" target="_blank" rel="nofollow noopener">zerodayengineering.com/training/maste… This class will give you a core level grasp of modern evolutionary coverage-guided fuzzing as pro hackers use it. It goes fast from fuzzing essentials to advanced customization & examining how code coverage works on CPU assembly level, 4 hours hands-on video. Free access from 21st to 23rd June (access conditions below)
English
68
78
162
47.3K
LuemmelSec
LuemmelSec@theluemmel·
Happy to share that I will try to run my own business as a side hustle starting at the beginning of next year. If you are a German follower and are interested or know someone, please feel free to reach out to me. Some info, details etc. can be found here: ds-itconsulting.de/index.html
LuemmelSec tweet media
English
17
10
64
9.1K
Mor Davidovich retweetledi
LuemmelSec
LuemmelSec@theluemmel·
One Box To Rule Them All Little write up of my way to tackle remote pentesting situations with a dropbox. This is about non covert systems that will allow you to carry out full fledged pentests when implanted into the customers network. luemmelsec.github.io/One-Box-To-Rul…
LuemmelSec tweet media
English
1
30
99
10.2K
Mor Davidovich retweetledi
Ido Veltzman
Ido Veltzman@Idov31·
I usually tend to avoid politics but nowadays it is impossible. To all the Hamas supporters that reading this post, all the people that shout "free Palestine!" take a moment to answer those questions: Who ruled Palestine and in which year was is conquered? (hint: no answer)
English
2
2
9
3.4K
Mor Davidovich retweetledi
Chris Thompson
Chris Thompson@_Mayyhem·
The entire SCCM hierarchy is vulnerable to takeover from any primary site because by design, there is no security boundary between sites in the same hierarchy. Check out my new post to learn more about how this can be abused, mitigated, and detected! posts.specterops.io/sccm-hierarchy…
English
3
129
291
29.9K
Mor Davidovich retweetledi
MalDev Academy
MalDev Academy@MalDevAcademy·
Our EXE loader is now available to everyone on GitHub: github.com/Maldev-Academy… We'll be uploading more repositories on our GitHub in the future.
English
1
120
440
42.1K
David
David@dmcxblue·
Came across an incredible article about phishing with RDP Files besides the technique used previously using a C# Loader this one is just with the RDP File alone, awesome work from @ShorSecLtd 👏👏👏 #redteam
GIF
English
2
18
74
10.7K
Mor Davidovich retweetledi
Adam Chester 🏴‍☠️
My Okta for Red Teamers post is up! We look at how Kerberos SSO works, how to intercept credentials via a fake AD Agent, decrypting AD Agent tokens, adding skeleton key's, and even how to deploy a janky SAML IdP server to auth as any user for good measure. trustedsec.com/blog/okta-for-…
English
24
372
911
98.5K
Mor Davidovich
Mor Davidovich@dec0ne·
@d_xedex Myabe try it with the --forest or --legacy flags, those flags should be used according to the zone type you saw during the --print-zones command. It would help to see the command you ran.
English
1
0
1
55
archedex
archedex@archedex·
@dec0ne I made sure it's the right zone, I also, tried other zones but I keep getting this error 🤔
English
1
0
0
16
Mor Davidovich
Mor Davidovich@dec0ne·
New blog post of mine and my first in our "The Path to DA" series where I share a cool attack path I exploited in a recent engagement to gain Domain Admin privileges. Hope you like it :) shorsec.io/blog/the-path-…
ShorSec Cyber Security@ShorSecLtd

🔥New Blog Post Alert! The next chapter in our "The Path to DA" series is now live: "(Relaying) To The Internet And Back". This entry, by @dec0ne, explores yet another route to DA, focusing on the intricacies of ADIDNS Abuse, LDAP relay, RBCD, and more. shorsec.io/blog/the-path-…

English
4
16
82
12.3K
Mor Davidovich
Mor Davidovich@dec0ne·
@d_xedex 😆 lol Achievement Unlocked! Just kidding. Hopefully, it was worth it
English
1
0
1
66
archedex
archedex@archedex·
@dec0ne Great, now because of your cool article I missed my train stop 😭
English
1
0
1
98
Mor Davidovich
Mor Davidovich@dec0ne·
@Idov31 Do you ever rest?! Always love reading your posts Amazing work bro🔥🔥🔥
English
1
0
1
238