Do I have any friends that have experience writing a Windows Credential Provider? I know a cool authentication startup looking for help hacking together a quick proof of concept. They have a little budget. Please share for reach, thank you! DM me and I'll connect you with them.
I frequently get asked for advice on starting a career in Cyber Security. I decided to turn a recent request into a blog post. Always open to feedback
blog.leetsys.com/2020/07/06/…#careeradvice
CyBeer is a great way to keep in touch with the community in between conferences! This month on top of the awesome guest speakers, we'll have a lot of great news about the next #ANYCon
Don't miss it!
We'll also have some exclusive announcements and discussion about #ANYCon2020 at the next meetup!
Register for FREE here! (drink cover optional)
cybeer-february2020.eventbri…
After discussing with the team, I've decided to start writing Cyber Security Haikus. My first one:
A Password Chosen,
The Changing Season in Mind,
CSO Sheds a Tear.
#ANYCon 2020 - September 19/20 at the Albany Capital Center.
Check our latest news posting for more info - anycon.info/news/kickstartin…
What are you looking forward to the most about this year's con?
Did you know you can enumerate all DNS records including DHCP registered hosts via LDAP in #Activedirectory!?
Even better than a DNS Zone Transfer. You can also identify additional DNS Zones from AD. Plenty more to come.
Added to ldapper:
github.com/tdubs/ldapper#redteam
Added a ton of features and a few bug fixes to ldapper. Can now query if LAPS is configured, pull cleartext creds from LAPS, obtain Domain SID, account status, and more. More to come soon.
#activedirectory#hackinggithub.com/tdubs/ldapper
Added the ability to enumerate Exchange Servers from LDAP to ldapper. Super interesting stuff under CN=Configuration, under the BaseDN need to explore for additional nuggets to enumerate. If you know of one worth adding DM me and I will add to the script.
github.com/tdubs/ldapper/
Sharing a tool I wrote to assist during red team engagements. Allows you to manually select different payloads to deliver for each request to your phishing site. Or automate based on remote subnet, credentials, user agent, etc. Will add more features soon
github.com/tdubs/PhishMaestr…
How to create a multi-billion dollar company in 3 easy steps.
1) Market yourselves as radical anti-corporate
2) Prove it by removing the Esc key, giving you crazy street cred
3) Bring the Esc key back because, well.... it's the freaking Escape key!
support.apple.com/en-us/HT20…
Added a feature to ldapper to enumerate Service Principal Names from Active Directory, to identify opportunities for Kerberoasting, all from the Linux cli.
github.com/tdubs/ldapper
CONGRATS! To #anyconsec#ANYCon for a very successful 3rd ANYcon!! Great time, great venue, great ppl, great villages, great talks and.... GREAT location! Huge congrats to all for putting it on and all who participated! Can't wait for next year! Wooo Hooo!!!!
Amazing CTF put together by @anyconsec. Currently sat in 5th place as it closes for the night. Hope to make it back into the top 3 tomorrow! Good luck everyone!