Aggregator
企业安全从业者职业发展的几个关键思考
最强编程模型 Claude 4 发布;雷军:小米 YU7 不可能 19.9 万;微信员工澄清朋友圈广告评论|极客早知道
疑似俄罗斯APT28组织在全球攻击活动中利用0Day漏洞——每周威胁情报动态第223期 (05.16-05.22)
FindGPPPasswords: Uncover Group Policy Preferences Passwords
FindGPPPasswords A cross-platform tool to find and decrypt Group Policy Preferences passwords from the SYSVOL share using low-privileged domain accounts. Features Only requires a low privileges domain user account. Automatically gets the list of all...
The post FindGPPPasswords: Uncover Group Policy Preferences Passwords appeared first on Penetration Testing Tools.
CVE-2007-1111 | ActiveCalendar data/y_3.php css cross site scripting (EDB-29646 / XFDB-32690)
从 UUID 伪装到 Shellcode 执行,通过 UUID 编码绕过本地安全防护
福利 | 加入最专业、最全面的 [ .NET 代码审计 ] 体系化视频学习社区
.NET WebShell 绕过 EDR 监控,不调用 cmd.exe 也能实现命令执行
朝鲜Konni APT组织针对韩国金融行业定向钓鱼攻击
PowerHuntShares: inventory, analyze, and report excessive privileges configured on Active Directory domains
PowerHuntShares PowerHuntShares is designed to automatically inventory, analyze, and report excessive privilege assigned to SMB shares on Active Directory domain joined computers. It is intended to help IAM and other blue teams gain a...
The post PowerHuntShares: inventory, analyze, and report excessive privileges configured on Active Directory domains appeared first on Penetration Testing Tools.