Need some cleartext password from TGT or NTLM hash? Always useful on internal penetration testing. Nice work @malcrove their blog post - malcrove.com/seamlesspass-le…
One interesting tool to compile with Nuitka is SeamlessPass from @malcrove, particularly with Conditional Access policies for trusted locations and managed devices where you need to likely pivot to a Windows machine to auth.
github.com/Malcrove/Seamless…x.com/FuzzySec/status/184884…
I guess 6% of respondents are fibbing here.. The machine account hash for AZUREADSSOACC is a tier one asset in your organization, if compromised the attacker can impersonate any account in azure (tickets generated offline) and you have very very poor visibility of this in logs
Congratulations to the winners of Ramadan Cyber Wargames 2021 👏
We consider all the participants are winners of knowledge.
Please keep an eye on your email for a surprise soon 📧
Insecure Java Deserialization leading to RCE (CVE-2021-27335) in one of the common Banking Applications discovered by one of @malcrove team members:
malcrove.com/kollectapps-ins…
@malcrove / CTF.ae will be conducting an Online capture the flag competiton in Play Secure Conference - London. Register now and compete with CTF players from all around the globe.
playsecure.ctf.ae/register