Sign in

Mänu

@emanuelduss.ch
79 followers 108 following 26 posts

IT security. Linux & network protocols. Pentesting web applications, networks & AD infrastructures. Mostly technical stuff here. emanuelduss.ch

PostsRepliesMedia
Mänu @emanuelduss.ch · 30/08/2026
Nice, there is a new SSH client option -Z in OpenSSH 10.5 that prints the keys that will be tried for public key authentication in the order that they will be used. Manpage: man.openbsd.org/ssh.1#Z So you can see which public keys are disclosed to the remote system. #ssh #openssh
emanuel@x1:~
$ ssh -Z github.com
/home/emanuel/.ssh/id_ed25519_public ED25519 SHA256:2QVdTWNQ5KrMWJ2mqR7qp93Z/czwV/1BXuH+Xu6dVm8 explicit agent
/dev/null  explicit

emanuel@x1:~
$ ssh -Z gitlab.com
emanuel@x1 ED25519 SHA256:2QVdTWNQ5KrMWJ2mqR7qp93Z/czwV/1BXuH+Xu6dVm8 agent
/dev/null  explicit

emanuel@x1:~
$ ssh -Z 0x00.motd.ch
/home/emanuel/.ssh/id_ed25519_adm-emanuel ED25519 SHA256:kSHX4Ghvh4n64ibiJL838SxJXjdiS2PmJ5nS3iKYUEw explicit
/dev/null  explicit

emanuel@x1:~
$ ssh -Z foobar.example.net
/dev/null  explicit
030
Reposted by Mänu
Compass Security @compass-security.com · 25/08/2026
Pentesting passkeys? Security analyst @emanuelduss.ch shows two JS snippets for tampering with the WebAuthn APIs. Handy for checking if you can login using a security key without knowing the PIN. Check out the technical details and how he got there: blog.compass-security.com/2026/08/a-no...
021
Reposted by Mänu
Compass Security @compass-security.com · 04/08/2026
Pipeleek 1.0 is out 💧 Secret scanning across 7 CI/CD platforms, plus runner and Renovate bot exploitation. Want to see one leaked job log turn into repo takeover? Try our deliberately vulnerable GitLab Attack Lab. Happy leeking! blog.compass-security.com/2026/08/pipe... #DevSecOps #CICD
111
Reposted by Mänu
Synacktiv @synacktiv.com · 02/07/2026
#RBCD attacks in Impacket have been extended across an arbitrary number of domains! 🚀 Discover how to impersonate arbitrary identities through complex #ActiveDirectory forest trusts, including SPN-less exploitation. 📚 www.synacktiv.com/en/publicati... 🔨 github.com/synacktiv/im...
synacktiv.com
Exploring cross-domain & cross-forest RBCD: part 2
Exploring cross-domain & cross-forest RBCD: part 2
152
Reposted by Mänu
Adrienne Fichter @adfichter.eurosky.social · 02/06/2026
Frisch von der Presse: Du protestiert gegen neue Rechenzentren für Big Tech oder bist für Palästina? Dann solltest du die nächsten Abschnitte lesen. Es könnte ein Revival des Fichenstaats geben. Wo genau solche Aktivitäten in Datenbanken des Geheimdiensts landen www.republik.ch/2026/06/02/c...
republik.ch
Der Nachrichten­dienst profitiert vom Zeitgeist
Wie die Schweiz sich vom liberalen Rechtsstaat verabschiedet.
13126
Mänu @emanuelduss.ch · 27/05/2026
On sshlabs.compass-security.training you can find a presentation and a Docker-based hands-on lab in which you can learn how SSH works, how it can be attacked and how to protect it. #security #infosec #network #ssh #openssh #pentest
sshlabs.compass-security.training
SSH Labs - SSH Labs
Labs to learn about SSH security.
072
Reposted by Mänu
Compass Security @compass-security.com · 27/05/2026
SSH everywhere, misconfigurations somewhere. Our new SSH Labs let you get your hands dirty: slides, video, and a Docker-based lab. Created by our Security Analyst @emanuelduss.ch, learn how SSH breaks and how to fix it: blog.compass-security.com/2026/05/ssh-... #SSH #InfoSec #Security
072
Reposted by Mänu
TrendAI Zero Day Initiative @thezdi.bsky.social · 16/05/2026
Collision! Although successful on stage, Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller (@compasssecurity) of Compass Security targeted Anthropic Claude Code, hitting a one-vulnerability collision with a previous attempt and earning $20,000 & 2 Master of Pwn points. #Pwn2Own
085
Mänu @emanuelduss.ch · 16/05/2026
Fast Android File Access via SSHFS over Wi-Fi or USB (MTP Alternative): emanuelduss.ch/posts/fast-a... #android #mtp #sshfs
emanuelduss.ch
Fast Android File Access via SSHFS over Wi-Fi or USB (MTP Alternative)
Introduction The MPT protocol used to access files via USB on your phone is not that efficient. This post shows you an alternative to MTP for accessing your files on your mobile phone. It works by ins...
010
Mänu @emanuelduss.ch · 23/04/2026
Simple shell function that calls the ip.thc.org service to get subdomains or CNAMEs pointing to a subdomain, or IP addresses pointing to a subdomain: gist.github.com/emanuelduss/... For quick and dirty subdomain enumeration 😀 THX @hackerschoice.bsky.social for this nice service 🤘 #pentest #dns
010
Reposted by Mänu
Compass Security @compass-security.com · 03/03/2026
WinGet can be more than a package manager. We show how .𝚠𝚒𝚗𝚐𝚎𝚝 configs + a self-referencing LNK become a viable initial access payload when Microsoft Store is enabled. Includes detection queries & mitigation tips. blog.compass-security.com/2026/03/wing... #RedTeam #Windows #LOLBins #InitialAccess
043
Reposted by Mänu
Compass Security @compass-security.com · 10/02/2026
John Ostrowski (Compass Security) and Manuel Kiesel (Cyllective AG) worked together on CVE-2025-13154, a Lenovo Vantage LPE. Even after Microsoft closed a known primitive, collaboration led to a working PoC. blog.compass-security.com/2026/02/from... #Windows #CVE #SecurityResearch #PrivEsc
053
Mänu @emanuelduss.ch · 31/01/2026
This was a really cool and awesome course ❤️! I learned so much in these two days and did a lot of stuff I never did and never heard about before. It was cool when (after some nasty debugging 🫠) the encryption key could finally be sniffed 🤘. Thanks a lot for your training, you guys rock!
Open notebook from the backside where the mainboard can be seen, tiny wires are soldered on the SPI flash. These are soldered to a PCB which is connected to a logic analyzer.
062
Reposted by Mänu
cy//ective @cyllective.bsky.social · 17/01/2026
🚨 New blog post! Read about CVE-2025-13154, a privilege-escalation vulnerability in a Lenovo Vantage add-in called SmartPerformance. cyllective.com/blog/posts/l... #windows #cve #infosec #pentest
cyllective.com
Lenovo Vantage LPE/EoP (CVE-2025-13154)
A write-up of CVE-2025-13154, a privilege escalation vulnerability in Lenovo Vantage.
111
Mänu @emanuelduss.ch · 09/01/2026
This is probably the easiest way to perform reverse DNS lookups over IP address ranges using the built-in tool getent and bash brace expansion: getent hosts 130.59.{20,31}.{0..255} Useful if you are on a system/container with limited tools. #pentest #dns #linux
Output of the command showing multiple IP addresses and their hostnames assigned via reverse DNS entries.
040
Reposted by Mänu
The Hacker's Choice (1995) @hackerschoice.bsky.social · 17/12/2025
THC Release 💥: The world’s largest IP<>Domain database: ip.thc.org All forward and reverse IPs, all CNAMES and all subdomains of every domain. For free. Updated monthly. Try: curl ip.thc.org/1.1.1.1 Raw data (187GB): ip.thc.org/docs/bulk-da... (The fine work of messede 👌)
14620
Reposted by Mänu
💥 leonjza @leonjza.bsky.social · 07/12/2025
Two blog posts just dropped - one with the details on the bloatware pwning shenanigans I was up to earlier in the year, and another on pipetap, a new Windows named pipe proxy/tool. sensepost.com/blog/2025/pw... sensepost.com/blog/2025/pi...
032
Reposted by Mänu
Compass Security @compass-security.com · 02/12/2025
New video out! Security analyst John Ostrowski show the hands-on process behind discovering CVE-2025-24076 and CVE-2025-24994 described in our recent blog post. Watch here: youtu.be/YwNcTuHxnAI #security #pentest #windowsinternals #vulnresearch
youtu.be
300 Milliseconds to Admin: Mastering DLL Hijacking and Hooking to Win the Race
YouTube video by Compass Security
042
Reposted by Mänu
SpecterOps @specterops.io · 25/11/2025
NTLM relays failing because of EPA? 😒 Nick Powers & @tw1sm.bsky.social break down how to enumerate EPA settings across more protocols + drop new tooling (RelayInformer) to make relays predictable. Check out their blog for more: ghst.ly/4rqwpRs
ghst.ly
Less Praying More Relaying - Enumerating EPA Enforcement for MSSQL and HTTPS - SpecterOps
It's important to know if your NTLM relay will be prevented by integrity protections such as EPA, before setting up for and attempting the attack. In this post, we share how to solve this problem for ...
042
Reposted by Mänu
Compass Security @compass-security.com · 04/11/2025
Want to understand how Windows handles authentication and access tokens? Security analyst @emanuelduss.ch explains how they’re created, used, and abused - with live demos. 🎥Presentation: youtu.be/_ODdwpxXRR4?... #Security #Pentest #WindowsInternals
youtu.be
Windows Access Tokens - From Authentication to Exploitation
YouTube video by Compass Security
131
Mänu @emanuelduss.ch · 27/10/2025
802.11evil now shows a Wi-Fi QR code, sends router advertisements for IPv6 support, can set static routes via DHCP and disable Wi-Fi to only act as a router. See changelog: emanuelduss.ch/posts/create... #pentest #network #tls #mitm
emanuelduss.ch
Create Evil Wi-Fi Access Point (802.11evil)
Introduction In pentests, connecting devices to your own network can be very useful. This enables you to exfiltrate data, download tools, analyze the network traffic and even use a transparent HTTP pr...
010
Reposted by Mänu
SpecterOps @specterops.io · 23/10/2025
Credential Guard was supposed to end credential dumping. It didn't. Valdemar Carøe just dropped a new blog post detailing techniques for extracting credentials on fully patched Windows 11 & Server 2025 with modern protections enabled. Read for more: ghst.ly/4qtl2rm
ghst.ly
Catching Credential Guard Off Guard - SpecterOps
Uncovering the protection mechanisms provided by modern Windows security features and identifying new methods for credential dumping.
01710
Reposted by Mänu
TrendAI Zero Day Initiative @thezdi.bsky.social · 21/10/2025
📢 Confirmed! Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller of Compass Security combined an arbitrary file write & cleartext transmission of sensitive data to exploit the @home_assistant Green. Their third round win earns them $20,000 and 4 Master of Pwn points. #Pwn2Own
052
Reposted by Mänu
Compass Security @compass-security.com · 21/10/2025
#Pentest of gRPC-Web apps is tricky due to the binary format. We are releasing bRPC-Web, a @portswigger.net @burpsuite.bsky.social extension developed by our @muukong.bsky.social that helps manipulate #gRPC-Web traffic, even in absence of #protobuf schemas. blog.compass-security.com/2025/10/brpc...
073
Reposted by Mänu
Compass Security @compass-security.com · 15/10/2025
Learn about a FortiProxy Domain Fronting Protection bypass discovered by our analyst @emanuelduss.ch. Details in the advisory: www.compass-security.com/en/news/deta... Curious how web filters are evaded? Read his blog series: blog.compass-security.com/2025/03/bypa... #cve #pentest #bypass
compass-security.com
Vulnerability in FortiProxy
Security analyst Emanuel Duss identified a vulnerability in FortiProxy.
021
Reposted by Mänu
Catalin Cimpanu @campuscodi.risky.biz · 11/10/2025
Talks from the Balkan Computer Congress 2025 security conference, which took place last September, are available on YouTube www.youtube.com/playlist?lis...
youtube.com
BalCCon2k25 - YouTube
BalCCon2k25 - Against the current
062
Reposted by Mänu
d4d @zakfedotkin.bsky.social · 07/10/2025
I’m excited to announce that I’ll be presenting The Fragile Lock: Novel Bypasses for SAML Authentication at Black Hat Europe! In this talk, I’ll show how I was able to continuously bypass security patches to achieve complete auth bypass for major libraries. #BHEU @blackhatevents.bsky.social
0266
Reposted by Mänu
Compass Security @compass-security.com · 18/09/2025
The final episode of our Kerberos deep dive is live! RBCD opens new attack paths in Kerberos. Learn how misconfigs enable privilege escalation and how to defend. youtu.be/l97RDnzdrXY?... #Kerberos #ActiveDirectory
youtu.be
Kerberos Deep Dive Part 6 - Resource-Based Constrained Delegation
YouTube video by Compass Security
043
Reposted by Mänu
Dirk-jan @dirkjanm.io · 17/09/2025
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-gl...
dirkjanm.io
One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens
While preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful Entra ID vulnerability that I will probably ever find. One that could have allowed me to compromise ...
98737
Reposted by Mänu
Compass Security @compass-security.com · 16/09/2025
Episode 5 of our Kerberos deep dive is live. Constrained delegation isn’t bulletproof. See how attackers exploit it, and how to defend with monitoring & best practices. youtu.be/rnhr02eKU0I?... #Kerberos #ActiveDirectory
youtu.be
Kerberos Deep Dive Part 5 - Constrained Delegation
YouTube video by Compass Security
032
Reposted by Mänu
💥 leonjza @leonjza.bsky.social · 10/09/2025
I've been hacking on a new Windows Named Pipe tool called PipeTap which helps analyse named pipe communications. Born out of necessity while doing some vulnerability research on a target, its been super useful in reversing it's fairly complex protocol. :)
The proxy view for PipeTap, a Windows Named Pipe Analysis Tool
297
Reposted by Mänu
Compass Security @compass-security.com · 09/09/2025
Episode 3 of our Kerberos deep dive is live. AS-REP Roasting abuses accounts without pre-auth. Learn the risks, how attackers exploit it, and how to defend. youtu.be/56BjmyOTN5o?... #Kerberos #ActiveDirectory
youtu.be
Kerberos Deep Dive Part 3 - AS-REP Roasting
YouTube video by Compass Security
033
Reposted by Mänu
Compass Security @compass-security.com · 09/09/2025
We use @jameskettle.com Burp extension Collaborator Everywhere daily. Now our upgrades are in v2: customizable payloads, storage, visibility. Perfect for OOB bugs like SSRF. Find out more here: blog.compass-security.com/2025/09/coll... #AppSec #BurpSuite #Pentesting
086
Reposted by Mänu
Compass Security @compass-security.com · 04/09/2025
Episode 2 of our Kerberos deep dive is live. Kerberoasting lets attackers steal AD service account credentials. See how it works and how to protect your systems: youtu.be/PhNspeJ0r-4?... #Kerberos #ActiveDirectory
youtu.be
Kerberos Deep Dive Part 2 - Kerberoasting
YouTube video by Compass Security
054
Mänu @emanuelduss.ch · 04/09/2025
New blog post about fast and easy file sharing via IPv6 link-local addresses over a network cable and how it can be used to bypass & abuse some always-on corporate VPNs: emanuelduss.ch/posts/fast-a... #ipv6
emanuelduss.ch
Fast and Easy File Sharing via IPv6 Link-Local Addresses Over a Network Cable (and Bypass/Abuse Corporate VPNs)
Introduction There are a ton of ways to copy data between two systems. You can use a file sharing service on the Internet, transfer files via your self-hosted server or even use USB drives. This blog ...
000
Reposted by Mänu
Compass Security @compass-security.com · 03/09/2025
Kerberos powers auth in Windows and hides big security risks. We’re launching a 6-part deep dive: from protocol basics to attacks plus how to stop them. Starts today → blog.compass-security.com/2025/09/tami... → Subscribe to our channel! #Kerberos #ActiveDirectory
152
Reposted by Mänu
Compass Security @compass-security.com · 26/08/2025
Passwords are dead, long live passkeys! 🔑 In our latest blog, we go hands-on: real-life setups, plus tips for recovery and avoiding pitfalls. blog.compass-security.com/2025/08/into... #Passkeys #CyberSecurity #Authentication
043
Reposted by Mänu
SpecterOps @specterops.io · 14/08/2025
The DSInternals PowerShell module just got an upgrade! 🔥 Updates include: ✅ Golden dMSA Attack ✅ Full LAPS support ✅ Trust password & BitLocker recovery key extraction ✅ Read-only domain controller database compatibility Read more from Michael Grafnetter: ghst.ly/412rZ7F
ghst.ly
Juicing ntds.dit Files to the Last Drop - SpecterOps
Discover the latest enhancements to the DSInternals PowerShell module, including the Golden dMSA Attack and support for LAPS, trust passwords, or BitLocker recovery keys.
054
Mänu @emanuelduss.ch · 10/08/2025
Zscaler SAML SP Authentication Bypass via Certificate Cloning & Signature Spoofing (CVE-2025-54982) by @amberwolfsec.bsky.social: blog.amberwolf.com/blog/2025/au... #saml #zscaler
blog.amberwolf.com
Advisory - Zscaler SAML Authentication Bypass (CVE-2025-54982)
AmberWolf Security Research Blog
000
Reposted by Mänu
Catalin Cimpanu @campuscodi.risky.biz · 02/08/2025
China has started filtering and censoring internet traffic taking place over the QUIC protocol. The filtering started in April last year. The Great Firewall now decrypts QUIC packets at scale and uses a separate blocklist for QUIC traffic, separate from its main filters gfw.report/publications...
02917
Reposted by Mänu
SensePost @sensepost.com · 31/07/2025
Reverse engineering Microsoft’s SQLCMD.exe to implement Channel Binding support for MSSQL into Impacket’s mssqlclient.py. Storytime from Aurelien (@Defte_ on the bird site), including instructions for reproducing the test environment yourself. sensepost.com/blog/2025/a-...
A screenshot of two windows. The top is a view of the Microsoft SQL management GUI showing that “Extended Protection” is enabled for NTLM authentication. The bottom is a terminal showing an invocation of Impacket’s mssqlclient.py successfully connecting using channel binding.
0106
Reposted by Mänu
SpecterOps @specterops.io · 29/07/2025
BloodHound v8.0 is here! 🎉 This update introduces BloodHound OpenGraph, revolutionizing Identity Attack Path Management by exposing attack paths throughout your entire tech stack, not just AD/Entra ID. Read more from Justin Kohler: ghst.ly/bloodhoundv8 🧵: 1/7
1139
Reposted by Mänu
James Kettle @jameskettle.com · 30/07/2025
Not at Black Hat / DEF CON? You can still join the mission to kill HTTP/1.1: - Watch the livestream from #DEFCON at 16:30 PT on the 8th - Read the whitepaper on our website - Grab the HTTP Request Smuggler update & WebSecAcademy lab Follow for updates & links. It's nearly time!
portswigger.net
Upcoming Conference Talks - PortSwigger Research
Find details of upcoming talks from the PortSwigger Research team. We also have research papers and recordings available from previous conferences and events.
0112
Reposted by Mänu
SpecterOps @specterops.io · 30/07/2025
Entra Connect sync accounts can be exploited to hijack device userCertificate properties, enabling device impersonation and conditional access bypass. @hotnops.bsky.social explores cross-domain compromise tradecraft within the same tenant. Read more: ghst.ly/3ISMGN9
ghst.ly
Entra Connect Attacker Tradecraft: Part 3 - SpecterOps
How Entra Connect and Intune can be abused via userCertificate hijacking to bypass conditional access and compromise hybrid domains
196
Reposted by Mänu
Dirk-jan @dirkjanm.io · 30/07/2025
It's been almost a year since my last blog... So, here is a new one: Extending AD CS attack surface to the cloud with Intune certificates. Also includes ESC1 over Intune (in some cases). dirkjanm.io/extending-ad... Oh, and a new tool for SCEP: github.com/dirkjanm/sce...
dirkjanm.io
Extending AD CS attack surface to the cloud with Intune certificates
Active Directory Certificate Services (AD CS) attack surface is pretty well explored in Active Directory itself, with *checks notes* already 16 “ESC” attacks being publicly described. Hybrid attack pa...
0159
Reposted by Mänu
James Kettle @jameskettle.com · 14/07/2025
We've just released a massive update to Collaborator Everywhere! This is a complete rewrite by @compass-security.com which adds loads of features including in-tool payload customization. Massive thanks to Compass for this epic project takeover. Check out the new features:
1187
Reposted by Mänu
modzero @modzero.bsky.social · 29/06/2025
Teammate Leonid discovered a leaked credential that allowed anyone unauthorized access to all Microsoft tenants of orgs that use Synology's "Active Backup for Microsoft 365" (ABM), including sensitive data like Teams channel messages. 🤓 #synology #disclosure #modzero modzero.com/en/blog/when...
modzero.com
When Backups Open Backdoors: Accessing Sensitive Cloud Data via
12214
Reposted by Mänu
SpecterOps @specterops.io · 17/06/2025
Introducing the BloodHound Query Library! 📚 @martinsohn.dk & @joeydreijer.bsky.social explore the new collection of Cypher queries designed to help BloodHound users to unlock the full potential of the BloodHound platform by creating an open query ecosystem. ghst.ly/4jTgRQQ
ghst.ly
Introducing the BloodHound Query Library - SpecterOps
The BloodHound Query Library is a community-driven collection of BloodHound Cypher available at https://queries.specterops.io
01410
Reposted by Mänu
RedTeam Pentesting @redteam-pentesting.de · 11/06/2025
👀 We have also released a paper which really goes into the nitty-gritty for those who are interested 🕵️‍♀️: www.redteam-pentesting.de/publications... For those that only need a short overview, here's our advisory 🚨: www.redteam-pentesting.de/advisories/r...
redteam-pentesting.de
011
Reposted by Mänu
RedTeam Pentesting @redteam-pentesting.de · 11/06/2025
🚨 Our new blog post about Windows CVE-2025-33073 which we discovered is live: 🪞The Reflective Kerberos Relay Attack - Remote privilege escalation from low-priv user to SYSTEM with RCE by applying a long forgotten NTLM relay technique to Kerberos: blog.redteam-pentesting.de/2025/reflect...
blog.redteam-pentesting.de
A Look in the Mirror - The Reflective Kerberos Relay Attack
It is a sad truth in IT security that some vulnerabilities never quite want to die and time and time again, vulnerabilities that have long been fixed get revived and come right back at you. While rese...
173