Latest posts

Ralf Hacker Channel
18 Sept, 16:38
forwarded from @p0x3k_1n73ll1g3nc3
cups2root Linux LPEInteractive root shell from a local account in the lpadmin group.


Ralf Hacker Channel
8 Sept, 21:58
Продолжаетсяhttps://github.com/MSNightmare/ShieldCrashWindows Defender 0day Vulnerability#ad #lpe #exploit #git


Ralf Hacker Channel
3 Sept, 05:49
Он опять это сделал) https://github.com/MSNightmare/ShieldBreak Windows Defender LPE 0day #lpe #ad #exploit #git



Ralf Hacker Channel
13 Aug, 09:05
forwarded from @p0x3k_1n73ll1g3nc3
VHDVomitA tool to search SMB shares for VHD/VMDK/VHDX backup files, mount them and dump sensitive data including NTDS.dit, SYSTEM, and SAM hives.vbkVomitExtract hashes from Veeam .vbk backup. Reads the VBK directly, finds the NTFS volume inside, walks the MFT, reassembles ntds.dit + SAM/SECURITY/SYSTEM, and runs impacket secretsdump.VeeamThiefRogue vSphere server for capturing Veeam Backup & Replication credentials.Blog: https://adversaryco.com/blog/breaking-bad-backups



Ralf Hacker Channel
11 Aug, 22:19
NightmareEclipse продолжает свой крестовый поход против Microsoft. После позавчерашнего LPE RoguePlanet, уже сегодня он опубликовал обход BitLocker. Все PoC'и автор выкладывает тут, после того как Microsoft удалил его аккаунты на Github и Gitlab. И того


Ralf Hacker Channel
24 Jul, 09:15
forwarded from @apt_notes
🔒 Certighost (CVE-2026-54121) — AD CS Domain Controller ImpersonationLow-privileged domain user can impersonate a Domain Controller via an AD CS enrollment chase fallback. By supplying cdc (Client DC) and rmd (Remote Domain) request attributes, an attacker forces the Enterprise CA to query an attacker-controlled host over SMB and LDAP.The CA then blindly trusts the returned directory objects (objectSid + dNSHostName of a real DC) and issues a certificate containing strong identity mapping for the Domain Controller. This allows successful PKINIT authentication as the DC.🔗 Research: https://gist.github.com/H0j3n/a5ef2609b5f2944ac2390a191a534c26🔗 Source: https://github.com/aniqfakhrul/CVE-2026-54121#ad #adcs #pkinit #machineaccountquota


Ralf Hacker Channel
26 Jun, 17:39
forwarded from @apt_notes
DirtyClone — CVE-2026-43503A Linux kernel local privilege escalation and page-cache write. DirtyClone is the fourth public member of the DirtyPipe / DirtyFrag family: it forces the kernel to run an in-place ESP (IPsec) decrypt over a file-backed page-cache page the attacker only has read access to, mutating that page in RAM. With the AES-CBC key/IV chosen so the decrypt writes attacker-controlled bytes, /usr/bin/su is rewritten with a tiny setuid(0)+execve("/bin/sh") ELF and invoking it yields root.🔗 Research: https://research.jfrog.com/post/dissecting-and-exploiting-linux-lpe-variant-dirtyclone-cve-2026-43503/🔗 Exploit: https://github.com/rafaeldtinoco/security/tree/main/exploits/dirtyclone#linux #lpe #kernel #dirty
Ralf Hacker Channel
23 Jun, 18:40
forwarded from @p0x3k_1n73ll1g3nc3
🔑 Onelogon: Taking over Active Directory Accounts via NetlogonWe analyzed Netlogon, bypassed the Zerologon patch, resulting in a full auth bypass. An attacker can leverage this to compromise computer accounts, or even the entire AD. Non-standard config must be present thoExploit: https://github.com/rub-softsec/onelogon https://github.com/Pennyw0rth/NetExec/pull/1291From: https://x.com/al3x_n3ff/status/2069482623672435049?s=46



Ralf Hacker Channel
14 Jun, 12:28
Крутая работа! https://maorsabag.github.io/posts/adaptix-stealthpalace/sleeping-beauty/ Если ты не вникал в блог Crystal Palace, но планировал, то данный ресерч просто must have для понимания, как можно использовать этот проект за рамками Cobalt Strike.MaorSabag's BlogSleeping Beauty II: CFG, CET, and Stack SpoofingA tale of CFG bitmaps, shadow stacks, and teaching an implant to sleep in places it was never meant to survive.
Ralf Hacker Channel
11 Jun, 11:04
NightmareEclipse продолжает свой крестовый поход против Microsoft. После позавчерашнего LPE RoguePlanet, уже сегодня он опубликовал обход BitLocker.Все PoC'и автор выкладывает тут, после того как Microsoft удалил его аккаунты на Github и Gitlab. И того, полный список:1. GreatXML - Обход BitLocker через MS Defender. Unpatched2. RoguePlanet - LPE через Race condition в MS Defender. Unpatched3. MiniPlasma - LPE через драйвер cldflt.sys. Patched Jun, 9.4. GreenPlasma - LPE через CTFMON (CVE-2026-45586) Patched Jun, 9.5. YellowKey - Обход BitLocker через WinRE (CVE-2026-45585) Patched May, 19.6. BlueHammer - LPE через компоненты MS Defender (CVE-2026-33825). Patched Apr, 19.7. RedSun - LPE через MS Defender (TOCTOU + CfAPI). Patched May, 19.8. UnDefend - Деактивация обновлений MS Defender (DoS). Patched May, 19.
Ralf Hacker Channel
9 Jun, 20:06
Лучше чем на скрине не опишешь. На самом деле очень серьезная бага🤔https://labs.infoguard.ch/posts/ghost-sender/Особенно интересен ресерч по той причине, что как не раз бывало Майкрософт назвали это архитектурным ограничением, а не уязвимостью, так что фикса не будет🙈 по крайней мере в ближайшее время...#phishing #pentest #redteam


Ralf Hacker Channel
9 Jun, 18:40
Классная статья по Module Stomping с хорошим data driven подходомhttps://medium.com/@toneillcodes/advanced-evasion-tradecraft-precision-module-stomping-b51feb0978fe#pentest #redteam #injectMediumAdvanced Evasion Tradecraft: Precision Module StompingMapping process memory for calculated, stable execution
Ralf Hacker Channel
8 Jun, 21:03
Microsoft Defender now monitors RPC activityhttps://techcommunity.microsoft.com/blog/microsoftdefenderatpblog/microsoft-defender-now-monitors-rpc-activity/4523368#infoTECHCOMMUNITY.MICROSOFT.COMMicrosoft Defender now monitors RPC activity | Microsoft Community HubRemote procedure call (RPC) is a protocol commonly abused by attackers that allows functions implemented in a separate process, and potentially on a remote...
Ralf Hacker Channel
15 May, 15:26
Ресурс redteam.community продолжает развиваться, и вот недавно там появился раздел с конференциями, где собирают все доклады с прошедших ивентов, и есть анонсы на будущие))Еще там много других ресурсов, лаб, а в разработке новые разделы, так что можно следить)#info
Ralf Hacker Channel
1 May, 13:23
Набор IOC для impacket. Репозиторий свежий, с хорошим описанием и скринамиhttps://github.com/ThatTotallyRealMyth/Impacket-IoCs#blueteam #redteam #impacketGitHubGitHub - ThatTotallyRealMyth/Impacket-IoCs: This repo contains the results of an internal re-write of impacket I undertook at my…This repo contains the results of an internal re-write of impacket I undertook at my current company. It contains some of the IoCs found within the library - ThatTotallyRealMyth/Impacket-IoCs
Ralf Hacker Channel
30 Apr, 09:06
forwarded from @ptswarm
🧑🚒 Our researcher Mikhail Sukhov shares his knowledge and experience in analyzing FreeIPA environments.He also introduces his new tool, IPAHound 💪Go ’n see the details ➡️ https://swarm.ptsecurity.com/thinking-in-graphs-with-ipahound/


Ralf Hacker Channel
28 Apr, 19:16
Сейчас на почту пришло: Warp is now open-source.https://github.com/warpdotdev/warpКрутой терминал, особенно если не включать всякую AI-хрень😁Там много всякого, но мне две фичи важны (на линухе): 1. Сохранение всего ввода вывода во всех разделах и вкладках терминала даже при выключении компа 2. Удобное ведение истории команд, кроме общей, еще и отдельные для каждого рабочего каталога, откуда команды выполняются#soft #git #terminalGitHubGitHub - warpdotdev/warp: Warp is an agentic development environment, born out of the terminal.Warp is an agentic development environment, born out of the terminal. - warpdotdev/warp
Ralf Hacker Channel
17 Apr, 10:39
forwarded from @pentestnotes
Meld-Encrypt: Шифрование файлов и заметок в Obsidian. 👊Многие специалисты, включая меня, используют Obsidian для ведения своих заметок, в том числе очень даже чувствительных. И вроде всё хорошо, obsidian удобен, НО! У него до сих пор нет встроенного шифрования и функций безопасности! А существующие плагины не такие классные, как хотелось бы.Поэтому я сделал форк довольно популярного Obsidian Encrypt и добавил в него функционал, которого лично мне не хватало во время работы.Что нового по сравнению с оригиналом:➡️ Появилась поддержка шифрования файлов ➡️ Шифрование всего контента в заметке одним нажатием ➡️ Шифрование директорий ➡️ Удобный просмотр зашифрованного контента ➡️ Улучшенный


Ralf Hacker Channel
16 Mar, 22:18
CVE-2026-24291: Windows LPE (RegPwn)Exploit: https://github.com/mdsecactivebreach/RegPwnBlog: https://www.mdsec.co.uk/2026/03/rip-regpwn/BOF: https://github.com/Flangvik/RegPwnBOFTested versions: Windows 11 25h2 Windows 11 24h2 Windows 10 21h2 Windows Servers 2016/2019/2022Patched: Mar 10, 2026#lpe #pentest #redteam #ad #cveGitHubGitHub - mdsecactivebreach/RegPwnContribute to mdsecactivebreach/RegPwn development by creating an account on GitHub.
Ralf Hacker Channel
14 Mar, 22:44
Еще один пост по Crystal Palace, более комплексный и подробныйhttps://lorenzomeacci.com/bypassing-edr-in-a-crystal-clear-wayThis blog takes you from how C2 payloads actually work under the hood all the way to building a fully evasive reflective loader that bypasses one of the best EDR's, covering module overloading with .pdata registration, NtContinue entry transfer, API call stack spoofing with Draugr, sleep masking, and Crystal Palace YARA signature removal. Every technique explained from why it exists, not just how it works.#evasion #redteam #pentest #dev

Related Channels
Other channels in the same section of the catalogue.
