Florian

430 posts

Florian

Florian

@flgy

Synacktiv Katılım Nisan 2011
247 Takip Edilen237 Takipçiler
Florian retweetledi
Synacktiv
Synacktiv@Synacktiv·
🧑‍🎓 Boost your offensive Active Directory skills with our Entry & Advanced trainings. Hands-on labs with dozens of machines + latest research from DEFCON, x33fcon & more! Seats are limited, don’t miss out! 🔗 Entry: synacktiv.com/en/offers/trai… 🔗 Advanced: synacktiv.com/en/offers/trai…
Synacktiv tweet mediaSynacktiv tweet media
English
0
11
20
2.9K
Florian retweetledi
Synacktiv
Synacktiv@Synacktiv·
Want to master cutting-edge techniques for attacking Azure? Join us this summer at @BlackHatEvents in Vegas for a deep dive into red teaming on Azure, M365, Azure DevOps, and hybrid infrastructures. Early bird tickets available until May 23rd! #azure-intrusion-for-red-teamers-44458" target="_blank" rel="nofollow noopener">blackhat.com/us-25/training…
Synacktiv tweet media
English
0
8
26
2.8K
Florian retweetledi
Synacktiv
Synacktiv@Synacktiv·
It's @_barbhack_ time! @croco_byte is on stage to present OU exploitation in AD environments.
Synacktiv tweet media
English
1
8
39
3.6K
Florian retweetledi
Synacktiv
Synacktiv@Synacktiv·
In our latest blogpost, @croco_byte explores the inner workings of SCCM policies and introduces SCCMSecrets.py, a tool targeting secret policies in order to exploit misconfigurations, harvest credentials, and pivot across collections by impersonating legitimate clients. synacktiv.com/publications/s…
English
0
56
132
11.5K
Florian retweetledi
Hugow
Hugow@hugow_vincent·
Here is the second part of my GitHub action exploitation series. You will find some exploitation scenarios on popular projects like Microsoft, Apache, FreeRDP, AutoGPT, Ant-Design, Cypress and others 👨‍💻
Synacktiv@Synacktiv

Want to know how we prevented some CI/CD supply chain attacks against Microsoft, FreeRDP, AutoGPT, Ant-Design, Cypress, Excalidraw and others? Read the second article in our series on exploiting GitHub Actions by @hugow_vincent. synacktiv.com/publications/g…

English
0
2
7
497
Florian retweetledi
Synacktiv
Synacktiv@Synacktiv·
For @WEareTROOPERS second day, @Scouty__ and Paul are presenting their research on Kubernetes bootstrap tokens and AKS
Synacktiv tweet media
English
0
14
22
4.4K
Florian
Florian@flgy·
@xarkes_ “Text editor: Helix” ❤️
Filipino
1
0
1
154
xarkes
xarkes@xarkes_·
It's Sunday, you want to binge-watch something but still want to be coding while doing it, and yet you only have one screen? Do like me: xarkes.com/b/coding-while…
xarkes tweet media
English
1
0
4
525
Florian retweetledi
Hexacon
Hexacon@hexacon_fr·
☁️ Whether it's on premises or in the cloud, a domain is a domain. 💪 Flex your intrusion muscles with @tiyeuse and @hugow_vincent's training! ➡️ hexacon.fr/trainer/vincen… 📆 30/09-03/10 2024 📍Espace Vinci, Rue des Jeuneurs, Paris
Hexacon tweet media
English
0
12
29
3.4K
Florian retweetledi
Synacktiv
Synacktiv@Synacktiv·
A while ago during a security assessment, @0hexit identified multiple vulnerabilities on the PRTG Network Monitor application version 21.3.69.1333, allowing an attacker to perform XSS attacks. Read the technical details in the advisory: synacktiv.com/sites/default/…
Synacktiv tweet media
English
0
5
27
4K
Florian retweetledi
Synacktiv
Synacktiv@Synacktiv·
We have updated nord-stream, our #CI/CD secrets extraction tool to support GitLab. Turns out it is way easier to dump all the creds on GitLab, check out the updated version of our blogpost to understand why. synacktiv.com/publications/c…
English
2
13
40
9.3K
Florian retweetledi
Synacktiv
Synacktiv@Synacktiv·
Good news, Synacktiv 2023 trainings are open! Come and get trained by our best ninjas about pentesting Active Directory environments over 5 days, from 27 to 31/03 in our Parisian offices. 🇫🇷 More details here: synacktiv.com/offres/formati… Register at sales@synacktiv.com
GIF
English
0
15
22
10.1K
Florian
Florian@flgy·
@blueshhit You should use the mighty Socat instead anyway ;)
English
0
0
2
0
Antoine Gql
Antoine Gql@_bluesheet·
[2/2] "-p source_port [...] It is an error to use this option in conjunction with the -l option." As a result: `nc -nvl 8888` works as well as `nc -nvlp 8888`, is shorter and complies with the best practices. So why do we keep seeing the latter in every blogpost / video ?
English
1
0
2
0
Antoine Gql
Antoine Gql@_bluesheet·
[1/2] Today, I read the netcat man page (linux.die.net/man/1/nc) and I had a lightbulb moment: "-l' Used to specify that nc should listen for an incoming connection [...]. It is an error to use this option in conjunction with the -p, -s, or -z options."
English
1
0
9
0
Florian retweetledi
Synacktiv
Synacktiv@Synacktiv·
Through a case study inspired by a recent intrusion test, @ROLANDQuentin2 provides an overview of the different techniques allowing to smuggle PHP payloads into PNG files. Discover how to reliably inject PHP code into images, even in tricky situations! synacktiv.com/publications/p…
English
2
35
89
0