New in #Metasploit: SugarCRM #RCE, login scanner and credential gatherer for Wowza Streaming Engine Manager, and three new methods for #PetitPotam.
Plus, admin/kerberos/forge_ticket now supports a new extra_sids option — which is useful for including cross-domain SIDs for forging external #Kerberos trust tickets as part of cross-trust domain escalation. The admin/kerberos/inspect_ticket has also been updated to support viewing these extra SID values.
More Kerberos and secrets dumping improvements in this week's wrap-up!
https://www.rapid7.com/blog/post/2023/03/10/metasploit-weekly-wrap-up-196/
#metasploit #rce #PetitPotam #kerberos
It's happening! Go watch this guy hack on #PetitPotam in #Metasploit: https://www.twitch.tv/zerosteiner
Metasploit's holiday hacking challenge debuts in TryHackMe's Advent of Cyber series tomorrow, December 9: https://tryhackme.com/christmas
For double the holiday fun, @zeroSteiner is also streaming on Twitch tomorrow at 4:30 EST (US). Jump on the stream to watch him add new methods to our #PetitPotam module (for better authentication coercion): https://www.twitch.tv/zerosteiner
#Petitpotam hat aus 2021 angerufen und möchte nochmals gepatcht werden #Windows #Sicherheit #Update Mai 2022
#update #sicherheit #windows #PetitPotam
#PetitPotam : dans l’attente d’un patch de #Microsoft, une solution de contournement pour bloquer les appels distants #EFSRPC !
#PetitPotam #microsoft #EFSRPC #securite #ntlm
#PetitPotam : le protocole #EFSRPC de #Windows mis à mal par une attaque de type relais #NTML ! (ce qui ne va pas, c’est le planté de bâton…)
#PetitPotam #EFSRPC #windows #NTML #internet #reseau #NTMLRelay