Red Teamer

Joined May 2012
58 Photos and videos
fortunato lodari retweeted
Una decisione che lascia senza parole. Ascoltate bene cosa è successo
2,746
2,265
14,970
1,156,928
fortunato lodari retweeted
Ancora truffe sul Superbonus, ancora soldi sottratti agli italiani. È l’eredità delle trovate elettorali di Conte che la Nazione continua a pagare a caro prezzo.
537
252
1,110
49,788
GIUDA betrayed again, how to get a new and fresh TGT (or a TGS - if you settle for little) on behalf of another logged user on a Windows machine. How it works: lnkd.in/dYDxq5nx #redteam #giuda #kerberos thx to MzHmO@github
7
28
1,997
fortunato lodari retweeted
🔴 condividete, per favore
8
126
84
15,792
Have you tried compiling C sources with Embarcadero C compiler instead of using common compilers? OpenProcessToken DuplicateTokenEx CreateProcessWithTokenW virustotal analysis: the first compiled with Visualstudio and the second with Borland C #redteam
4
392
The best C2? Microsoft Azure ARC Automation Account Hybrid Runbook Worker. Undetectable and signed #redteam #c2
4
28
183
26,154
AD: Local Admin to Domain Admin It doesn't matter if you don't see active sessions, always look in the Kerberos cache. query session VS klist sessions Don't attempt an LSASS DUMP, move on! GIUDA 2023090500 Now FUD again github.com/foxlox/GIUDA #redteam #adprivesc #kerberos #lsass
4
177
486
35,411
Good job! #redteam #hacker
I recently got inspired by a neat trick by @flodari where he managed to carry out a RBCD LPE on a Windows machine with just some regular domain creds. There is nothing new in these techniques but I hadn't seen the idea before so I decided to see if it could also be done via a C2
2
7
806
Are you tired of failing to create DNS Entry for DavRelay? LPE with: ssh -R addcomputer.py Proxychains Proxylite PetitPotam rbcd_relay no AV/EDR detection, only SIEM (if) checks on LDAP changes #redteam #LPE #DAVRelay #FUD
1
8
38
2,162
fortunato lodari retweeted
As mentioned yesterday, the Task Manager Secret can be transformed into an automated UAC bypass through some UI hacks. Source code at --> gist.github.com/antonioCoco/… DISCLAIMER : - This is not a new UAC bypass and the UIAccess token stealing has been known since 2019. Discovered by James Forshaw and implemented also in UACMe method 55 - The code has been tested only on Win10, it might not work with the Win11 task manager - UAC bypasses relying on UI automation like this are unreliable, there are many known UAC bypasses better and more stable than this. Little demo below 👇
Cool, now combine it with a UIPI bypass like this --> tiraniddo.dev/2019/02/access… and you can bypass UAC through UI automation, i.e. SendInput()
60
146
25,799
fortunato lodari retweeted
18 Aug 2023
I just got fired from my job today without warning. 😬 Really crazy. Anyway... If anyone is looking for a pentester, red teamer, or likes my public work, please don't hesitate to reach out. Thanks in advance everyone. 😔
22
86
234
93,295
fortunato lodari retweeted
An upgraded C port, neat 👀 github.com/MzHmO/TGSThief
AD Privesc Kerberos TGS and SeTcbPrivilege If you have SeTcbPrivilege, you can ask TGS on behalf of ALL logged users on your machine WITHOUT Password ...and if there is a Domain Admin logged? Zero detection by EDR/AV github.com/foxlox/GIUDA.git #redteam #SeTcbPrivilege
1
54
150
18,854
#amazing #LSASS dump fully undetected #redteam
1
1
7
502
AD Privesc Kerberos TGS and SeTcbPrivilege If you have SeTcbPrivilege, you can ask TGS on behalf of ALL logged users on your machine WITHOUT Password ...and if there is a Domain Admin logged? Zero detection by EDR/AV github.com/foxlox/GIUDA.git #redteam #SeTcbPrivilege
4
249
594
67,874
From Local Admin to Domain Admin If you're a local admin and want to duplicate someone's Token and run a command for them, write everything in Delphi. I've tested the code with most of the AV/EDRs. Please give me feedback. github.com/foxlox/hypobrychi… #redteam #DuplicateTokenEx
5
65
203
19,999
fortunato lodari retweeted
URGENTE - Si chiede la condivisione. Grazie
URGENTE [11.06-02:40] in corso ricerche di MINORE #SCOMPARSA (5 anni) Via Claudio Monteverdi #Novoli #Cascine #Firenze Intorno alle 13:00 del 10.06.22 Chi avesse informazioni informi le Forze dell’Ordine Informazioni e aggiornamenti: goo.gl/tKHsXK
32
1,072
494
119,299
fortunato lodari retweeted
URGENTE [11.06-02:40] in corso ricerche di MINORE #SCOMPARSA (5 anni) Via Claudio Monteverdi #Novoli #Cascine #Firenze Intorno alle 13:00 del 10.06.22 Chi avesse informazioni informi le Forze dell’Ordine Informazioni e aggiornamenti: goo.gl/tKHsXK
51
1,652
1,278
383,091
fortunato lodari retweeted
Working on autoupdate an app written in .net running under low privilege model (applicationpool). Problem: -not allowed to overwrite running files -not allowed to stop IIS (net stop) or other cmd (appcmd) Solution: -rename existing files -force a reload by !!editing web.config!!
2
14
2,400