Sign in

NioZ

@niozow.bsky.social
3 followers 20 following 0 posts
PostsRepliesMedia
Reposted by NioZ
Synacktiv @synacktiv.com · 27/05/2026
🔒 Think you can crack them all? Join #Synacktiv at @le-hack.bsky.social and take on a challenge at our stand, crafted by @niozow.bsky.social 🚀 One laptop. Multiple flags. Encrypted safes. Break in, unlock everything, and recover every secret before time runs out ⏱️💻 See you at stand 22!
001
Reposted by NioZ
Synacktiv @synacktiv.com · 02/02/2026
In our latest article, @niozow.bsky.social dives into the inner workings of #Windows access tokens, privileges and logon rights. As these rights often constitute a blind spot for AD enumeration tools, the article describes our PRs to integrate them into BloodHound ⬇️ www.synacktiv.com/en/publicati...
synacktiv.com
Beyond ACLs: Mapping Windows Privilege Escalation Paths with
Beyond ACLs: Mapping Windows Privilege Escalation Paths with
013
Reposted by NioZ
Clément Labro @itm4n.bsky.social · 15/06/2025
🆕 New blog post! "Offline Extraction of Symantec Account Connectivity Credentials (ACCs)" Following my previous post on the subject, here is how to extract ACCs purely offline. 👉 itm4n.github.io/offline-extr... #redteam #pentesting
Screenshot showing the output of the proof-of-concept tool "SMAStorageDump", where ACCs are dully decrypted.
3114
Reposted by NioZ
SpecterOps @specterops.io · 19/05/2025
Did you miss #SOCON2025? Did you have a favorite talk you'd like to rewatch? 🎥 All presentations from SO-CON 2025 are now live at ghst.ly/socon25-talks. 💻 Slides for each talk are available at ghst.ly/socon25-slides.
055
Reposted by NioZ
James Kettle @jameskettle.com · 14/05/2025
I'm thrilled to announce "HTTP/1 Must Die! The Desync Endgame", at #BHUSA! This is going to be epic, check out the abstract for a teaser ↓
23918
Reposted by NioZ
Gareth Heyes @garethheyes.co.uk · 25/04/2025
Firefox treats multipart/x-mixed-replace like HTML. Chrome doesn’t. That tiny difference? It can turn a "non-exploitable" XSS into a real one. Abuse boundary handling, bypass filters, and make your payload land. thespanner.co.uk/making-the-u...
thespanner.co.uk
Making the Unexploitable Exploitable with X-Mixed-Replace on Firefox - The Spanner
In this post, we’ll look at an interesting difference in how Firefox and Chrome handle the multipart/x-mixed-replace content type. While Chrome treats it as an image, Firefox renders it as HTML - some...
0188
Reposted by NioZ
Synacktiv @synacktiv.com · 27/02/2025
In our latest article, @croco-byte.bsky.social and @scaum.bsky.social demonstrate a trick allowing to make Windows SMB clients fall back to WebDav HTTP authentication, enhancing the NTLM and Kerberos relaying capabilities of multicast poisoning attacks! www.synacktiv.com/publications...
synacktiv.com
Taking the relaying capabilities of multicast poisoning to the next level: tricking Windows SMB clients into falling back to WebDav
0105
Reposted by NioZ
Clément Labro @itm4n.bsky.social · 19/02/2025
In this blog post, I explain how I was able to create a PowerShell console in C/C++, and disable all its security features (AMSI, logging, transcription, execution policy, CLM) in doing so. 💪 👉 blog.scrt.ch/2025/02/18/r...
Screenshot showing the execution of the proof-of-concept named PowerChell in comparison to a typical PowerShell prompt. In particular, it shows that PowerChell is able to bypass the Constrained Language Mode (CLM).
24319
Reposted by NioZ
PortSwigger Research @portswiggerres.bsky.social · 04/02/2025
The results are in! We're proud to announce the Top 10 Web Hacking Techniques of 2024! portswigger.net/research/top...
portswigger.net
Top 10 web hacking techniques of 2024
Welcome to the Top 10 Web Hacking Techniques of 2024, the 18th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year
26636
Reposted by NioZ
The Hacker's Choice (1995) @hackerschoice.bsky.social · 03/02/2025
THC RELEASE: Article - Practical HTTPS Interception - exploiting the cleartext ACME-HTTP-AUTH loophole (Let's Encrypt, ...) to retrieve valid HTTPS certificates. #tls #https blog.thc.org/practical-ht...
033
Reposted by NioZ
Thomas Ptacek @sockpuppet.org · 03/02/2025
This is smart. I had to read it twice to figure out why they weren't just using eBPF, but it works for non-superusers: it dynamically creates network namespaces, tun devices, and an intercepting CA (like Burp) to capture all the HTTP requests made by a Linux program. github.com/monasticacad...
github.com
GitHub - monasticacademy/httptap: View HTTP/HTTPS requests made by any Linux program
View HTTP/HTTPS requests made by any Linux program - monasticacademy/httptap
24312
Reposted by NioZ
James Forshaw @tiraniddo.dev · 30/01/2025
New blog post on the abuse of the IDispatch COM interface to get unexpected objects loaded into a process. Demoed by using this to get arbitrary code execution in a PPL process. googleprojectzero.blogspot.com/2025/01/wind...
googleprojectzero.blogspot.com
Windows Bug Class: Accessing Trapped COM Objects with IDispatch
Posted by James Forshaw, Google Project Zero Object orientated remoting technologies such as DCOM and .NET Remoting make it very easy ...
26541
Reposted by NioZ
d4d @zakfedotkin.bsky.social · 22/01/2025
Hot out of the oven! The Cookie Sandwich – a technique that lets you bypass the HttpOnly protection! This isn't your average dessert; it’s a recipe for disaster if your app isn’t prepared: portswigger.net/research/ste...
portswigger.net
Stealing HttpOnly cookies with the cookie sandwich technique
In this post, I will introduce the "cookie sandwich" technique which lets you bypass the HttpOnly flag on certain servers. This research follows on from Bypassing WAFs with the phantom $Version cookie
03413
Reposted by NioZ
Clément Labro @itm4n.bsky.social · 20/01/2025
Really great blog post about bypassing BitLocker using "PXE soft reboot" (even if PXE boot is disabled in the BIOS). "Windows BitLocker -- Screwed without a Screwdriver" 👉 neodyme.io/en/blog/bitl... 👉 media.ccc.de/v/38c3-windo...
neodyme.io
Windows BitLocker -- Screwed without a Screwdriver
Breaking up-to-date Windows 11 BitLocker encryption -- on-device but software-only
1157