Joined October 2011
48 Photos and videos
itsmenaga (๐Ÿ’ฅ,๐Ÿ’ฅ) retweeted
You got access to vsphere and want to compromise the Windows hosts running on that ESX? ๐Ÿ’ก 1) Create a clone into a new template of the target VM 2) Download the VMDK file of the template from the storage 3) Parse it with Volumiser, extract SAM/SYSTEM/SECURITY (1/3)
7
104
482
38,252
itsmenaga (๐Ÿ’ฅ,๐Ÿ’ฅ) retweeted
22 Aug 2025
Letโ€™s make Active Directory security education available to all! List your favorite Active Directory security resources. Plz share for reach!
34
95
767
78,428
itsmenaga (๐Ÿ’ฅ,๐Ÿ’ฅ) retweeted
๐Ÿ”ฅ Super excited to soon present my lifetime project publicly๐Ÿคฉ - 4yrs of R&D 1y in commercial sale - Weaponization of 95 file types - 140kLOC - 20 tools - 10 shellcode exec techniques (ts) - 8 MSI ts - 20 LNK ts - 30 script/macro ts โšก Battle tested, low-profile arsenal
27
128
756
57,779
itsmenaga (๐Ÿ’ฅ,๐Ÿ’ฅ) retweeted
17 Sep 2024
๐Ÿ’ฅ ANNOUNCEMENT: Opik v1.0 is released! ๐Ÿ’ฅ Opik is an open source LLM evaluation framework for: ๐Ÿ”ฅ Implementing LLM-based metrics ๐Ÿชฒ Logging/debugging LLM traces ๐Ÿ’ฏ Scoring, annotating, and versioning LLM data And so much more. Check out the repo below.
144
608
4,287
14,233,609
itsmenaga (๐Ÿ’ฅ,๐Ÿ’ฅ) retweeted
โšก 6000 Private Nuclei Templates โšก โœ…Download Now - t.me/brutsecurity/831 #bugbounty #bugbountytips #ethicalhacking #infosec #CyberSecurity
6
64
219
20,136
itsmenaga (๐Ÿ’ฅ,๐Ÿ’ฅ) retweeted
27 Aug 2024
1-Subdomainer(contain sudfinder,amass whois mode,amass passive mode,crt/.sh,GitHub,gobuster,knockpy,) 2-chaos(Archived Data) 3-frogy(wayback,bbot,subfinder,findomain,crt.sh) 4-assetfinder (certspotter,hackertarget,threatcrowd,wayback ,bufferover,facebook)
2
19
95
7,242
itsmenaga (๐Ÿ’ฅ,๐Ÿ’ฅ) retweeted
If you have access to #jenkins dashboard use below Script Console cmd for poc ``` def passwdFile = new File("/etc/passwd") println passwdFile.text ``` #P1 #bugbountytips #bugbounty
14
75
415
26,948
itsmenaga (๐Ÿ’ฅ,๐Ÿ’ฅ) retweeted
Made a new tool for a test I was doing. Decided to share with everyone, added it to my toolbox, for sure. It's like having X-ray vision into JS files. Crazy, some of the endpoints it pulled out that were never seen before. github.com/nullenc0de/gofuzz Example:
7
119
483
39,037
itsmenaga (๐Ÿ’ฅ,๐Ÿ’ฅ) retweeted
I decided to take it a step further and make this a @nuclei template. nuclei -target ./ -t /tmp/appdata.yaml Looks like scary things are in appdata. gist.github.com/nullenc0de/4โ€ฆ
If you're still getting comfortable with assembly code, you might find it easier to start by exploring the AppData folder (C:\Users\USER\AppData\Local). Look for configuration files or .jar/.bat files that might be present. Often, modifying these files can lead to an easy RCE.
1
27
148
13,315
itsmenaga (๐Ÿ’ฅ,๐Ÿ’ฅ) retweeted
Thrilled to release my latest research on Apache HTTP Server, revealing several architectural issues! blog.orange.tw/2024/08/confuโ€ฆ Highlights include: โšก Escaping from DocumentRoot to System Root โšก Bypassing built-in ACL/Auth with just a '?' โšก Turning XSS into RCE with legacy code from 1996

38
649
1,890
232,624
itsmenaga (๐Ÿ’ฅ,๐Ÿ’ฅ) retweeted
Dang @defparam's new Lemma project looks nuts.
8
21
172
13,590
itsmenaga (๐Ÿ’ฅ,๐Ÿ’ฅ) retweeted
My notes from labbing AD Certificate Service exploitation. Thereโ€™s lots of great resources on this but I wanted to share my walkthrough on how to create a vulnerable certificate, common errors and how to exploit using either Certipy or Certify. github.com/myexploit/LAB/bloโ€ฆ
39
112
8,045
itsmenaga (๐Ÿ’ฅ,๐Ÿ’ฅ) retweeted
I wrote a fun write-up on ADCS exploitation, including explanations and custom built examples of practical exploitation for all 13 ESC vulnerabilities. It's available on my blog: logan-goins.com/2024-05-04-Aโ€ฆ Hope this helps anyone who's interested in #activedirectory security :)
12
269
784
55,175
itsmenaga (๐Ÿ’ฅ,๐Ÿ’ฅ) retweeted
Itโ€™s always worth checking for non-production route names such as: qa devenv devenv1 devenv2 devenv3 preprod pre-prod test testing staging stage dev development deploy slave master review prod uat prep version2 github.com/codingo/DNSCewl/bโ€ฆ
3
35
215
9,822
itsmenaga (๐Ÿ’ฅ,๐Ÿ’ฅ) retweeted
19 Jun 2024
[Blog Post] Sign-in with World ID: XSS and ATO via OIDC Form Post Response Mode ๐Ÿ‘‰ security.lauritz-holtmann.deโ€ฆ ๐Ÿ‘‰ hackerone.com/reports/251580โ€ฆ #BugBounty #OIDC #OAuth #XSS (1/2)
1
20
61
7,132
itsmenaga (๐Ÿ’ฅ,๐Ÿ’ฅ) retweeted
Replying to @MPECSInc
This is a great breakdown Philip! Any tools you recommend for Active Directory? Maybe we're missing some on our list: pentestlist.com/categories/iโ€ฆ

2
3
1,371
itsmenaga (๐Ÿ’ฅ,๐Ÿ’ฅ) retweeted
17 Jun 2024
ACTIVE DIRECTORY SECURITY: JUMP SERVER PREP and TIPS Always use a Jump Server when managing Infrastructure. Tech's access machine should be a Privileged Access Workstation (PAW). 1: Elevate PowerShell and install all RSAT tools: # TODO Install all needed Management Tools Get-WindowsFeature *RSAT* | Install-WindowsFeature -IncludeAllSubFeature -Restart 2: User accessing the Jump Server should _not_ be a local admin. Use a domain Standard User account in the Remote Desktop Users group on the Jump Server. 3: Get used to right clicking and Run as Admin (sudo) to access those consoles. 4: Quickies I: Right click and run Server Manager as admin to gain access to all of the consoles. II: Either do the same for a PowerShell console or run PowerShell from the above Server Manager instance. III: Memorize key *.CPL (Control Panel Applet). Example: NCPA.CPL [ENTER] IV: Memorize key WIN __ keystrokes V: Hit Start and just start typing to initiate a search VI: TaskMgr.EXE VII: DiskMgmt.MSC VIII: CompMgmt.MSC IX: CTRL SHFT ENTER = Run As Admin * Segmentation here is key. Infrastructure should be in its own ADDS Forest/Domain with _zero trusts_. Jump Server should only accept incoming calls from PAWs.
4
49
303
35,543
itsmenaga (๐Ÿ’ฅ,๐Ÿ’ฅ) retweeted
18 Jun 2024
OpenCTI: Open Cyber Threat Intelligence Platform meterpreter.org/opencti-openโ€ฆ

110
387
27,760
itsmenaga (๐Ÿ’ฅ,๐Ÿ’ฅ) retweeted
13 Jun 2024
BREADS: BREaking Active Directory Security meterpreter.org/breads-breakโ€ฆ

65
182
11,109