· @twitter
1 followers · 54808 posts · Server mstdn.skullb0x.io

Referenced link: gist.github.com/zblurx/009633b
Originally posted by Rob Fuller / @mubix@twitter.com: twitter.com/_zblurx/status/165

RT by @mubix: I managed to implement password extraction with gist.github.com/zblurx/009633b
Thanks @BoreanJordan for dpapi-ng, helped a lot on the kek computing part.
I am going to make a PR to Impacket really soon to implement MS-GKDI (and fix endpoint mapper)

#LAPSv2 #Impacket

Last updated 1 year ago

Regarding the recently disclosed vulnerability, a neat tool for remotely determining installed services or if the vulnerable psexec service exists(if not cleaned up properly). It checks if certain named pipes exist which doesn’t require administrative privileges. You still need some form of basic authentication / trust / credentials (even unprivileged) like a valid domain user account. github.com/tothi/serviceDetect

#Impacket #psexec

Last updated 2 years ago

Swissky :verified: · @swissky
900 followers · 284 posts · Server infosec.exchange

RT @bugch3ck
Disclosed today at @Disobey_fi - psexec from expose the target system for authenticated command execution as SYSTEM. That means any user that can authenticate over the network (usually Domain Users) can run code as SYSTEM over the network.

#Impacket

Last updated 2 years ago

Jonas Vestberg · @bugch3ck
303 followers · 147 posts · Server infosec.exchange

Disclosed today at the conference - psexec from expose the target system for authenticated command execution as SYSTEM. That means any user that can authenticate over the network (usually Domain Users) can run code as SYSTEM over the network.

#disobey #Impacket

Last updated 2 years ago

Jonas Vestberg · @bugch3ck
299 followers · 146 posts · Server infosec.exchange

So next saturday I'll be dropping some vulns in the framework as part of my
talk. If you are using or building services around impacket, watch out for PRs in the following days.

#Impacket #disobey

Last updated 2 years ago

Swissky :verified: · @swissky
885 followers · 253 posts · Server infosec.exchange

RT @snovvcrash
🧵 (1/) Bypassing IDS DCSync Signature for

I’ve been asked lately to bypass a private IDS rule for ’s DCSync operation and I’ve immediately remembered this Charlie’s question ⬇️ twitter.com/_nwodtuhs/status/1

#secretsdump #Impacket

Last updated 2 years ago

Mänu · @emanuelduss
113 followers · 24 posts · Server infosec.exchange

Impacket is back: The Impacket project has found a new home: 0xdeaddood.rocks/2023/01/14/we

#Impacket #pentesting

Last updated 2 years ago

54m · @inactivebit
11 followers · 30 posts · Server infosec.exchange

Impacket is a collection of Python classes for working with network protocols: github.com/fortra/impacket

#infosec #Impacket

Last updated 2 years ago

abyssal_dk · @abyssal_dk
29 followers · 58 posts · Server infosec.exchange
c0nsid3rate 🌱 · @c0nsid3rate
185 followers · 326 posts · Server infosec.exchange

Can't say enough about Python virtual environments for running things like impacket, etc.

#python #Impacket #pentesting #oscp

Last updated 2 years ago

bencrypted · @bencrypted
25 followers · 19 posts · Server infosec.exchange