Florian

430 posts

Florian

Florian

@flgy

Synacktiv เข้าร่วม Nisan 2011
247 กำลังติดตาม237 ผู้ติดตาม
Florian รีทวีตแล้ว
Synacktiv
Synacktiv@Synacktiv·
🧑‍🎓 Boost your offensive Active Directory skills with our Entry & Advanced trainings. Hands-on labs with dozens of machines + latest research from DEFCON, x33fcon & more! Seats are limited, don’t miss out! 🔗 Entry: synacktiv.com/en/offers/trai… 🔗 Advanced: synacktiv.com/en/offers/trai…
Synacktiv tweet mediaSynacktiv tweet media
English
0
11
20
2.9K
Florian รีทวีตแล้ว
Synacktiv
Synacktiv@Synacktiv·
Want to master cutting-edge techniques for attacking Azure? Join us this summer at @BlackHatEvents in Vegas for a deep dive into red teaming on Azure, M365, Azure DevOps, and hybrid infrastructures. Early bird tickets available until May 23rd! #azure-intrusion-for-red-teamers-44458" target="_blank" rel="nofollow noopener">blackhat.com/us-25/training…
Synacktiv tweet media
English
0
8
26
2.8K
Florian รีทวีตแล้ว
Synacktiv
Synacktiv@Synacktiv·
GitLab recently released a patch for the Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409). Our ninjas @alexisdanizan and @b1two_ analyzed the patch and wrote the exploit code! github.com/synacktiv/CVE-…
English
0
35
127
8.1K
Florian รีทวีตแล้ว
Synacktiv
Synacktiv@Synacktiv·
It's @_barbhack_ time! @croco_byte is on stage to present OU exploitation in AD environments.
Synacktiv tweet media
English
1
8
39
3.6K
Florian รีทวีตแล้ว
Synacktiv
Synacktiv@Synacktiv·
In our latest blogpost, @croco_byte explores the inner workings of SCCM policies and introduces SCCMSecrets.py, a tool targeting secret policies in order to exploit misconfigurations, harvest credentials, and pivot across collections by impersonating legitimate clients. synacktiv.com/publications/s…
English
0
56
132
11.5K
Florian รีทวีตแล้ว
Hugow
Hugow@hugow_vincent·
Here is the second part of my GitHub action exploitation series. You will find some exploitation scenarios on popular projects like Microsoft, Apache, FreeRDP, AutoGPT, Ant-Design, Cypress and others 👨‍💻
Synacktiv@Synacktiv

Want to know how we prevented some CI/CD supply chain attacks against Microsoft, FreeRDP, AutoGPT, Ant-Design, Cypress, Excalidraw and others? Read the second article in our series on exploiting GitHub Actions by @hugow_vincent. synacktiv.com/publications/g…

English
0
2
7
497
Florian รีทวีตแล้ว
Synacktiv
Synacktiv@Synacktiv·
For @WEareTROOPERS second day, @Scouty__ and Paul are presenting their research on Kubernetes bootstrap tokens and AKS
Synacktiv tweet media
English
0
14
22
4.4K
Florian
Florian@flgy·
@xarkes_ “Text editor: Helix” ❤️
Filipino
1
0
1
154
xarkes
xarkes@xarkes_·
It's Sunday, you want to binge-watch something but still want to be coding while doing it, and yet you only have one screen? Do like me: xarkes.com/b/coding-while…
xarkes tweet media
English
1
0
4
525
Florian รีทวีตแล้ว
Nicolas Krassas
Nicolas Krassas@Dinosn·
A PowerShell script to perform PKINIT authentication with the Windows API from a non domain-joined machine. github.com/synacktiv/Invo…
English
0
4
3
2.3K
Florian รีทวีตแล้ว
Hexacon
Hexacon@hexacon_fr·
☁️ Whether it's on premises or in the cloud, a domain is a domain. 💪 Flex your intrusion muscles with @tiyeuse and @hugow_vincent's training! ➡️ hexacon.fr/trainer/vincen… 📆 30/09-03/10 2024 📍Espace Vinci, Rue des Jeuneurs, Paris
Hexacon tweet media
English
0
12
29
3.4K
Florian รีทวีตแล้ว
Synacktiv
Synacktiv@Synacktiv·
A while ago during a security assessment, @0hexit identified multiple vulnerabilities on the PRTG Network Monitor application version 21.3.69.1333, allowing an attacker to perform XSS attacks. Read the technical details in the advisory: synacktiv.com/sites/default/…
Synacktiv tweet media
English
0
5
27
4K
Florian รีทวีตแล้ว
Synacktiv
Synacktiv@Synacktiv·
We have updated nord-stream, our #CI/CD secrets extraction tool to support GitLab. Turns out it is way easier to dump all the creds on GitLab, check out the updated version of our blogpost to understand why. synacktiv.com/publications/c…
English
2
13
40
9.3K
Florian รีทวีตแล้ว
Synacktiv
Synacktiv@Synacktiv·
Good news, Synacktiv 2023 trainings are open! Come and get trained by our best ninjas about pentesting Active Directory environments over 5 days, from 27 to 31/03 in our Parisian offices. 🇫🇷 More details here: synacktiv.com/offres/formati… Register at sales@synacktiv.com
GIF
English
0
15
22
10.1K
Florian รีทวีตแล้ว
Synacktiv
Synacktiv@Synacktiv·
Watchout! CVE-2023-22809 on Sudo was patched today to prevent a privilege escalation on sudoedit. Read the security advisory by @aevy__ and @v1csec: synacktiv.com/sites/default/…
Synacktiv tweet media
English
7
153
300
49.9K
Florian
Florian@flgy·
@blueshhit You should use the mighty Socat instead anyway ;)
English
0
0
2
0
Antoine Gql
Antoine Gql@_bluesheet·
[2/2] "-p source_port [...] It is an error to use this option in conjunction with the -l option." As a result: `nc -nvl 8888` works as well as `nc -nvlp 8888`, is shorter and complies with the best practices. So why do we keep seeing the latter in every blogpost / video ?
English
1
0
2
0
Antoine Gql
Antoine Gql@_bluesheet·
[1/2] Today, I read the netcat man page (linux.die.net/man/1/nc) and I had a lightbulb moment: "-l' Used to specify that nc should listen for an incoming connection [...]. It is an error to use this option in conjunction with the -p, -s, or -z options."
English
1
0
9
0
Florian รีทวีตแล้ว
Synacktiv
Synacktiv@Synacktiv·
Through a case study inspired by a recent intrusion test, @ROLANDQuentin2 provides an overview of the different techniques allowing to smuggle PHP payloads into PNG files. Discover how to reliably inject PHP code into images, even in tricky situations! synacktiv.com/publications/p…
English
2
35
89
0