My friend Ron use to say lobster was worse food he ever ate, but then he found out you don’t have to eat shell and believe me he change a tune about lobster after that
#CrackIt#NoShell#LessonLearn
The "no shell" activity cluster was seen exploiting the SharePoint vuln on 17th - one day ahead of others - using no filesystem artifacts. Very cool finding by @TomHegel and friends at @LabsSentinel#toolshell#noshell Link to the blog below ->
It's been 5 years since my last physical international talk at @BSidesLV 2018 (Invoke-NoShell 🤩)
This time I'm going for both BSides and Arsenal
(DEFCON CFP results wen?)
The good part of -J is that it doesn't start an interactive session or run your login shell on the proxy host. This means you can set default shell to /bin/noshell and stop people from accidentally working on the login node
Basic but good tip I recently used in the real world. Got command injection, couldn't get a shell due to noshell for my user had CF Lite speed waf so couldn't view /etc/passwd to Bypass I used /e*c/p*s*we #BugBounty#bugbountytips#cybersec
🚨BREAKING: Siccar Point Energy has paused the Cambo oil field🚨
This is HUGE news. Now the UK government needs a real plan for a #JustTransition for industry workers & communities and to rule out new oil & gas projects once and for all #StopCambobbc.co.uk/news/uk-scotland-5…
It's surprisingly hard to get the real patch version of OTP. This works for me:
$ erl -eval '{ok, Version} = file:read_file(filename:join([code:root_dir(), "releases", erlang:system_info(otp_release), "OTP_VERSION"])), io:fwrite(Version), halt().' -noshell
#myelixirstatus
(Ignore the username noshell, it's account I created specifically to test some behaviors with /bin/false and /usr/sbin/nologin -- It currently is set to /bin/bash for the purposes of this demonstration)