Blog

Stay updated with the latest offensive security news, knowledge, and resources.

Latest Resources

Crossing the Log4j Horizon - A Vulnerability With No Return
Jan 10, 2022 Nicholas Anastasi

Crossing the Log4j Horizon - A Vulnerability With No Return

A vulnerability was recently disclosed for the Java logging library, Log4j. The vulnerability is wide-reaching and affects both open-source projects and enterprise software. VMWare announced shortly after the release of the issue that several of their products were affected. A proof of concept has been released for VMWare Horizon instances and allows attackers to execute code as an unauthenticated user...
Another Log4j on the fire: Unifi
Dec 28, 2021 Nicholas Anastasi

Another Log4j on the fire: Unifi

By now, you’re probably well aware of a recently disclosed vulnerability for the Java logging library, Log4j. The vulnerability is wide-reaching and affects Ubiquiti's Unifi Network Application. In this article, we’re going to break down the exploitation process and touch on some post-exploitation methods for leveraging access to the underlying operating system.
How to exploit Log4j vulnerabilities in VMWare vCenter
Dec 21, 2021 Nicholas Anastasi

How to exploit Log4j vulnerabilities in VMWare vCenter

A vulnerability was recently disclosed for the Java logging library, Log4j. The vulnerability is wide-reaching and affects both open source projects and enterprise software, meaning we need to understand how to ID and remediate it in our network environments. Shortly after the issue was disclosed, VMWare announced that several of their products were affected. A Proof of Concept has been released...
Never Stop Frontin’: Redirector and Proxy Setup Made Easy
Sep 09, 2021 Nicholas Anastasi

Never Stop Frontin’: Redirector and Proxy Setup Made Easy

Protecting your infrastructure from prying eyes is an important part of landing a phish and maintaining access to a client’s network. The process of setting up redirectors and reverse proxies has traditionally been difficult and hard to automate across different cloud platforms. Today, we’re going to solve that problem with our new repository, sneaky_proxy, which will allow you to automate your...
The ultimate tag team: PetitPotam and ADCS pwnage from Linux
Aug 10, 2021 Nicholas Anastasi

The ultimate tag team: PetitPotam and ADCS pwnage from Linux

PetitPotam and ADCS exploitation are nothing short of amazing. Exploitation is a breeze and results in full domain admin access. With these two TTPs, an attacker can hop on a network, exploit the vulnerability, do some command-line magic and have local administrator privileges on a domain controller in under 15 minutes. So far, no one has detailed the exploitation process fully...
Fix Cleartext Password Issues in Your Organization
Jul 21, 2021 Nicholas Anastasi

Fix Cleartext Password Issues in Your Organization

The key to our engagements often and unfortunately involve the discovery of credentials on internal network file shares. We’re going to show you how we find cleartext password storage problems and how to address them.
« 1 2 3 4 5 »