Found 1481 bookmarks
Newest
Windows 10^H^H Symbolic Link Mitigations
Windows 10^H^H Symbolic Link Mitigations
Posted by James Forshaw, abusing symbolic links like it’s 1999. For the past couple of years I’ve been researching Windows elevation of ...
·googleprojectzero.blogspot.co.uk·
Windows 10^H^H Symbolic Link Mitigations
Introducing bstrings, a Better Strings utility!
Introducing bstrings, a Better Strings utility!
Do you like strings? Do you like to find strings? How about in binary data? What about via regular expressions? ME TOO! bstrings works l...
·binaryforay.blogspot.ru·
Introducing bstrings, a Better Strings utility!
10 Places to Stick Your UNC Path
10 Places to Stick Your UNC Path
Doing an assessment and want to capture some hashes? Here's 10 methods you can try to get a user to authenticate to you over SMB.
·blog.netspi.com·
10 Places to Stick Your UNC Path
Compromised by Endpoint Protection
Compromised by Endpoint Protection
In a recent research project, Markus Wulftange of Code White discovered several critical vulnerabilities in the Symantec Endpoint Protection...
·codewhitesec.blogspot.nl·
Compromised by Endpoint Protection
xoreaxeaxeax/sinkhole
xoreaxeaxeax/sinkhole
sinkhole - Architectural privilege escalation on x86
·github.com·
xoreaxeaxeax/sinkhole
The Art of Transforming Network into Networking -
The Art of Transforming Network into Networking -
NetFormation helps businesses navigate digital transformation via Level 3’s unique network with a focus on growth, efficiency, innovation and connections
·blog.level3.com·
The Art of Transforming Network into Networking -
Ongoing analysis of unknown exploit targeting Office 2007-2013 UTAI MS15-022
Ongoing analysis of unknown exploit targeting Office 2007-2013 UTAI MS15-022
NB: This blog post will be updated in the upcoming days with more information Introduction A few days before the publishing of this blog post I came across an unknown RTF exploit sample which I cou…
·blog.ropchain.com·
Ongoing analysis of unknown exploit targeting Office 2007-2013 UTAI MS15-022
Abusing Chrome's XSS auditor to steal tokens
Abusing Chrome's XSS auditor to steal tokens
Detecting XSS auditor James pointed out to me that XSS auditor in Chrome has a block mode and I thought it might be interesting to see if this could be exploited in some way. When the http header is s
·blog.portswigger.net·
Abusing Chrome's XSS auditor to steal tokens