Ron Bowes · @iagox86
1068 followers · 293 posts · Server infosec.exchange

As I'm gathering screenshots my presentation, I look over at my other monitor and realize just how cool and are

#northsec #metasploit #meterpreter

Last updated 1 year ago

Vidmo :donor: :mastodon: · @VidmoOreda
633 followers · 2489 posts · Server infosec.exchange

OK well nice! has kerberos and AD modules... and nice work with support. Nice work @HackingDave ! You're flexing those muscles! :)

#metasploit #meterpreter

Last updated 2 years ago

Metasploit · @metasploit
3680 followers · 33 posts · Server infosec.exchange

Also new in MSF 6.3: A sixth getsystem technique (EfsPotato), Mimipenguin support for better Linux credential extraction, datastore overhaul, customizable option specification for module authors, and support for running Cobalt Strike Beacon Object Files

#metasploit #meterpreter

Last updated 2 years ago

Metasploit · @metasploit
3654 followers · 26 posts · Server infosec.exchange

Weekly wrap-up: Python updates, an adapter to run Python payloads on Windows, and a Cacti unauthenticated command injection rapid7.com/blog/post/2023/01/2

#metasploit #meterpreter

Last updated 2 years ago

usl · @usl
18 followers · 71 posts · Server social.tchncs.de
· @twitter
1 followers · 36634 posts · Server mstdn.skullb0x.io

Referenced link: hubs.la/Q01z2t0t0
Originally posted by Metasploit Project / @metasploit@twitter.com: twitter.com/TrustedSec/status/

RT by @metasploit: In this guide from @GuhnooPlusLinux, you'll learn how the new extension allows BOFs to be used from a session. Discover new attacks made possible in Meterpreter and avoid common errors. hubs.la/Q01z2t0t0

#BOFLoader #meterpreter

Last updated 2 years ago

blog on using inside . “Operators Guide to the Meterpreter BOFLoader”

trustedsec.com/blog/operators-

#trustedsec #bof #meterpreter

Last updated 2 years ago

philliptombs · @philliptombs
36 followers · 51 posts · Server blacktwitter.io

Metasploit: Meterpreter - I have just completed this room! Check it out: tryhackme.com/room/meterpreter testing # post-exploitation via @RealTryHackMe

#metasploit #meterpreter #windows #penetration #security #tryhackme

Last updated 2 years ago

I Give A Fit · @igiveafit
27 followers · 145 posts · Server kolektiva.social

Metasploit: Meterpreter - I have just completed this room! Check it out: tryhackme.com/room/meterpreter testing # post-exploitation via @RealTryHackMe

#tryhackme #security #penetration #windows #meterpreter #metasploit

Last updated 2 years ago

Metasploit: Meterpreter - I have just completed this room! Check it out: tryhackme.com/room/meterpreter testing # post-exploitation via @RealTryHackMe

#tryhackme #security #penetration #windows #meterpreter #metasploit

Last updated 2 years ago

54m · @inactivebit
69 followers · 99 posts · Server infosec.exchange
54m · @inactivebit
66 followers · 93 posts · Server infosec.exchange
Jim Jones · @GreatBigTable
508 followers · 1358 posts · Server mastodon.social

I remain behind on the challenge, but I am not giving up.

Yesterday, I completed days 15 and 16 which both focused on secure web application programming.

Day 15 uses unrestricted web uploads to pop a remote shell.

Day 16 focuses on .and includes an integrated mitigation exercise for , which was a nice surprise.

#tryhackme #adventofcode2022 #metaspoit #meterpreter #sqlinjection #php #infosec

Last updated 2 years ago

· @twitter
1 followers · 30031 posts · Server mstdn.skullb0x.io

Originally posted by Metasploit Project / @metasploit@twitter.com: twitter.com/autumnwhisperz/sta

RT by @metasploit: Just completed Day 9 of the Advent of Cyber 2022. It wasn’t easy, and there was a lot to get into!

#tryhackme #infosec #kali #linux #Metasploit #meterpreter

Last updated 2 years ago

Metasploit · @metasploit
2708 followers · 14 posts · Server infosec.exchange

Fresh Framework release with for RCE in Gitea and VMware NSX Manager, plus payload improvements and a link to @zeroSteiner's Twitch session on writing commands. rapid7.com/blog/post/2022/11/1

#metasploit #exploits #python #meterpreter

Last updated 2 years ago

Ron Bowes · @iagox86
861 followers · 123 posts · Server infosec.exchange

I'm excited to share of my work that came out today! Specifically, a handful of vulnerabilities in devices that I worked on through the summer, and worked with the vendor to get patched (F5 was awesome to work with, btw!).

I wrote a super detailed #blog post, and also wrote a full PoC. modules (both for the exploits and some post-exploitation data-gathering) are incoming as well!

The most important of the issues is via a vulnerability in the interface (), which is pretty cool (though requires a confluence of conditions to actually matter). I also had to bypass to actually exploit this on the path I chose, which is kinda cool.

The other is authenticated RCE, to which they assigned , though even I, the person who found it, doesn't really think it's a big deal. It's a nice way to get a session on your test box, at least?

I also published a bunch of my #tools for analyzing F5, including scripts to build, parse, and requests to their proprietary (I think?) database protocol (these require a valid login to use, but there's no user separation so there's a bit of ).

I'll also be speaking about this research in much more detail (as much as I can in 45 minutes :) ) in my talk on Dec 2!

#f5 #BIGIP #blog #metasploit #rce #csrf #soap #cve_2022_41622 #selinux #cve_2022_41800 #meterpreter #tools #mitm #LPE #Hushcon

Last updated 2 years ago

ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online

[Shameless Plug] Unser NetHack Video für diese Woche ist live. Heute nutzen wir Port-Forwarding in Meterpreter, greifen auf den lokalen MySQL-Dienst unseres Zielsystems zu und werfen einen Blick auf die MySQL-Logins.

youtu.be/MmoMKfMcBdM

#meterpreter #portforward #mysql #ethical #hacking

Last updated 6 years ago