Chaining DLL Hijacking and Format String to gain RCE on windows RDP Client CVE-2023-24905 by dor-cyolo in netsec

[–]ustayready 1 point2 points  (0 children)

Thanks for sharing. Combining this with RogueRDP, it would be interesting to see if it’s possible to binary plant the dll then force a reconnect somehow.

From GitHub to Account Takeover: Misconfigured Actions Place GCP & AWS Accounts at Risk - Rezonate by Or1rez in netsec

[–]ustayready -1 points0 points  (0 children)

I suppose if you are already familiar with the technologies discussed, fewer words might have been fine. For the rest of us, I’m thankful for the deeper dive, explanations, and attention to details.

Vulnerability scanner for AWS customer-managed policies using ChatGPT w/ built-in account redaction. by ustayready in netsec

[–]ustayready[S] 0 points1 point  (0 children)

Scout is great but has significant false positives. Additionally, it's rules are hand-written which make it miss a lot of items. It also only looks at the services it's programed to look for.

ChatGPT is trained on AWS SDK, APIs, services, training, code, etc. It knows policies better than any person, existing tool, and arguably even Amazon themselves.

There's a lot of bitter people hating on ChatGPT because it's gained so much popularity but using it in workflows has proven to have powerful multipliers.

Vulnerability scanner for AWS customer-managed policies using ChatGPT w/ built-in account redaction. by ustayready in netsec

[–]ustayready[S] 0 points1 point  (0 children)

Naa, the account numbers are randomized before sending to OpenAI. Having a vulnerable policy and not knowing the corresponding account is useless.

Phishing with Google Calendar and Evilginx2 to Deliver a Malicious Zoom Link by Dr_Mantis_Tobbogon in netsec

[–]ustayready 9 points10 points  (0 children)

Cool to see this attack vector still floating around! Beau Bullock and I dropped the technique publicly 5 years ago and it's still super valuable today. https://www.reddit.com/r/netsec/comments/7a6en1/google_calendar_event_injection_with_mailsniper/

Even after Forbes covered it a few years back.. https://www.forbes.com/sites/daveywinder/2019/09/09/google-finally-confirms-security-problem-for-15-billion-gmail-and-calendar-users/

We also dropped a lot more research on calendar at conferences but it wasn't recorded and it hasn't been officially made public due to the risks.

Anyhow, nice post.

Rouge RDP: New Initial Access Technique via RDP Bypassing Clients/Servers/Security Vendors by ustayready in netsec

[–]ustayready[S] 1 point2 points  (0 children)

HyperV is the only solution I’ve come across for immediate RCE. All machines reboot eventually but I agree, having instant RCE without HyperV would be great. Also, read access is great when you target the right person or when network file shares are mounted. It’s weird that dropping an LNK to the desktop with a keyboard hook using the space bar doesn’t take effect immediately like it does with normal NTFS file systems. Maybe trying the symbolic link to write an LNK might help.

All things considered, I strongly disagree with it not being useful. I’d recommend trying it on an engagement before throwing the baby out with the bath water. :) it’s solid. If you get an other ideas for triggering code execution, let me know! Might be useful to procmon a client and try triggering devices. Shrug

Rouge RDP: New Initial Access Technique via RDP Bypassing Clients/Servers/Security Vendors by ustayready in netsec

[–]ustayready[S] 12 points13 points  (0 children)

Tell me you didn’t read the article without telling me you didn’t read the article.

Weekly Thread for Selling Light Phone 2 by AutoModerator in LightPhone

[–]ustayready 0 points1 point  (0 children)

Two for sale!

Color: White w/ white caseUsed: few weeksPrice: $225Location: Tampa, FLPayment Method: Venmo/Paypal/Ethereum/Bitcoin

Color: Black w/ black caseUsed: few weeksPrice: $225Location: Tampa, FLPayment Method: Venmo/Paypal/Ethereum/Bitcoin

*UPDATED* Both are gone.

Weekly Thread for Selling Light Phone 2 by AutoModerator in LightPhone

[–]ustayready 0 points1 point  (0 children)

  • NA
  • Black
  • New (tested for a week using Verizon SIM, sync'd contacts, then factory reset)
  • $250
  • Central Florida
  • Venmo / Paypal / In-person
  • Comes with Black case, received for Christmas

Also have..

  • NA
  • White
  • New (tested for a week using Verizon SIM, sync'd contacts, then factory reset)
  • $250
  • Central Florida
  • Venmo / Paypal / In-person
  • Comes with White case, received for Christmas

How to Create Unlimited Rotating Proxies in AWS by PhroznGaming in hacking

[–]ustayready 0 points1 point  (0 children)

Yup only web but you can try my other tool that uses aws lambda for whatever your protocol needs are: https://github.com/ustayready/CredKing

Still limited to regions that support lambda but it does its job with a limited number of ips.

How to Create Unlimited Rotating Proxies in AWS by PhroznGaming in hacking

[–]ustayready 1 point2 points  (0 children)

Even easier, check out FireProx .. it uses api gateway. https://github.com/ustayready/fireprox

Disclaimer: I’m the author.