tangled.org/@mackuba.eu/...
tangled.org/@mackuba.eu/...
www.youtube.com ->
Very nice presentation about #IBMi security, including post-exploitation steps and lateral movement via pass-the-hash!
Original->
www.youtube.com ->
Very nice presentation about #IBMi security, including post-exploitation steps and lateral movement via pass-the-hash!
Original->
Web session management compromise is the new stateful firewall bypass.
SAML assertions and JSON web tokens? These are the new pass-the-hash attacks.
The new is now. Same as it ever was.
Web session management compromise is the new stateful firewall bypass.
SAML assertions and JSON web tokens? These are the new pass-the-hash attacks.
The new is now. Same as it ever was.
Someone in the comments made a new saying we should say when these greedy billionaires lose more.
And I wanna make it a hash tag trend here! So everyone who hates Trump and his billionaire buds say...
#GoTrumpGetDumped
Please pass it around! If you want too. ^^
Someone in the comments made a new saying we should say when these greedy billionaires lose more.
And I wanna make it a hash tag trend here! So everyone who hates Trump and his billionaire buds say...
#GoTrumpGetDumped
Please pass it around! If you want too. ^^
2016 - I don't need to hash this out.
2016 - I don't need to hash this out.
You KNOW when a Play is happening in a physical game, and you can slow down and hash things out.
You KNOW when a Play is happening in a physical game, and you can slow down and hash things out.
[is immediately dragged off to the Victor Frankenstein Memorial Asylum For Those What Want To Play God]
A history mystery solved: where do potatoes come from?
Nine million years ago, as the Andes were rising, a tomato cross pollinated a plant from the S. etuberosum lineage. Each plant contributed a gene, that together enabled underground stems to form tubers.
www.sciencenews.org/article/pota...
[is immediately dragged off to the Victor Frankenstein Memorial Asylum For Those What Want To Play God]
Still using the same local admin password across systems?
Adversaries don’t need to dump creds, they just pass the hash to every other machine.
✅ Use LAPS, use gMSAs and stop sharing admin creds.
Still using the same local admin password across systems?
Adversaries don’t need to dump creds, they just pass the hash to every other machine.
✅ Use LAPS, use gMSAs and stop sharing admin creds.
youtu.be/pQ9pYwCKopE?...
youtu.be/pQ9pYwCKopE?...
Usually nothing hard, since they have an example script how to do it - Pass it the version and hash and you're good to go.
Why the fuck do I always have to provide a hash tho?
Usually nothing hard, since they have an example script how to do it - Pass it the version and hash and you're good to go.
Why the fuck do I always have to provide a hash tho?
Why steal passwords when you can just take the hash? With Pass the Hash, attackers authenticate by reusing hashed credentials, bypassing the need for plaintext passwords.
Keep those doors locked, or I’ll be finding more than your house keys.
Why steal passwords when you can just take the hash? With Pass the Hash, attackers authenticate by reusing hashed credentials, bypassing the need for plaintext passwords.
Keep those doors locked, or I’ll be finding more than your house keys.
- Null session enum
- Password in description
- Password spray
- Coerced Authentication
- Pass-the-Hash
- Kerberoasting
- NTLM Relay to SMB, HTTP & LDAP
- And more!
Watch now! (🔗 link in comments)
- Null session enum
- Password in description
- Password spray
- Coerced Authentication
- Pass-the-Hash
- Kerberoasting
- NTLM Relay to SMB, HTTP & LDAP
- And more!
Watch now! (🔗 link in comments)
The effects are good, but I’d say take a hard pass on this one, and get their Black Cherry Punch or Cali B hash instead.
The effects are good, but I’d say take a hard pass on this one, and get their Black Cherry Punch or Cali B hash instead.
(Permission to post pic obtained in triplicate)
(Permission to post pic obtained in triplicate)