Offensive Xwitter
21K subscribers
915 photos
49 videos
21 files
2.09K links
~$ socat TWITTER-LISTEN:443,fork,reuseaddr TELEGRAM:1.3.3.7:31337

Disclaimer: https://xn--r1a.website/OffensiveTwitter/546
Download Telegram
This media is not supported in your browser
VIEW IN TELEGRAM
😈 [ konrad @konradgajdus ]

I made a donut using the C standard library:

πŸ”— https://github.com/konrad-gajdus/donut

πŸ₯ [ tweet ]

красивоС
🍌15πŸ₯±6πŸ‘4🀯2πŸ”₯1
This media is not supported in your browser
VIEW IN TELEGRAM
😈 [ JiΕ™Γ­ Vinopal @vinopaljiri ]

Inspired by @0gtweet, I created PoC: EXE-or-DLL-or-ShellCode that can be:

Executed as a normal #exe
Loaded as #dll + export function can be invoked
Run via "rundll32.exe"
Executed as #shellcode right from the DOS (MZ) header that works as polyglot stub

πŸ”— https://github.com/Dump-GUY/EXE-or-DLL-or-ShellCode

πŸ₯ [ tweet ]
πŸ‘5πŸ€”1
😈 [ Sam ☁️πŸͺ΅ @Sam0x90 ]

Interesting ZIP trick with __Macosx__ folder and LNK executing ftp script to execute embedded pythonw.exe

zip > docx LNK > ftp.exe > disguised pythonw.exe > CS shellcode

πŸ”— https://www.ctfiot.com/203334.html

πŸ₯ [ tweet ]
πŸ‘10
😈 [ Het Mehta @hetmehtaa ]

Reversing a VPN client to hijack sessions

πŸ”— https://rotarydrone.medium.com/decrypting-and-replaying-vpn-cookies-4a1d8fc7773e

πŸ₯ [ tweet ]
πŸ”₯9
This media is not supported in your browser
VIEW IN TELEGRAM
😈 [ John Hammond @_JohnHammond ]

Well, this was a stupid insomnia project, but... πŸ˜‚

Playground code is here:

πŸ”— https://github.com/JohnHammond/recaptcha-phish

πŸ₯ [ tweet ][ quote ]

Π·Π°Π²ΠΈΡ€ΡƒΡΠΈΠ»ΠΎΡΡŒ, ΠΏΡ€ΠΈΠΊΠΎΠ»ΡŒΠ½ΠΎ
😁18πŸ‘1πŸ₯±1
Offensive Xwitter
😈 [ JiΕ™Γ­ Vinopal @vinopaljiri ] Inspired by @0gtweet, I created PoC: EXE-or-DLL-or-ShellCode that can be: Executed as a normal #exe Loaded as #dll + export function can be invoked Run via "rundll32.exe" Executed as #shellcode right from the DOS (MZ) header…
😈 [ Kurosh Dabbagh @_Kudaes_ ]

Somebody asked if you can run a dll directly without rundll32 as you would do with an exe. You just need to remove the IMAGE_FILE_DLL flag from IMAGE_FILE_HEADER->Characteristics, which can be done with the option -e. Don't see much use for it tho ^^

πŸ”— https://github.com/Kudaes/CustomEntryPoint

πŸ₯ [ tweet ]
πŸ‘18
😈 [ Usman Sikander @UsmanSikander13 ]

Basics to advanced process injection. Covering 25 techniques:

πŸ”— https://github.com/Offensive-Panda/ProcessInjectionTechniques

πŸ₯ [ tweet ]
πŸ‘14
😈 [ Aleem Ladha @LadhaAleem ]

I've fully automated the lab used for @_leHACK_ Active Directory 2024 workshop done by @mpgn_x64 and it's available for everyone ! πŸ”₯
Also big kudos to @M4yFly for the playbooks and NetExec dev teams for this awesome tool !
Hope you enjoy, more to come

πŸ”— https://github.com/Pennyw0rth/NetExec-Lab

πŸ₯ [ tweet ]
πŸ‘9πŸ”₯7πŸ€”2🀯2
😈 [ Koen Van Impe β˜• @cudeso ]

Interesting approach shared by @Wietze on manipulating argv[0] to mislead security tools and analysts. A clever tactic for obfuscation!

πŸ”— https://www.wietzebeukema.nl/blog/why-bother-with-argv0

πŸ₯ [ tweet ]
πŸ‘12πŸ”₯1🀯1
😈 [ Nikhil Hegde @ka1do9 ]

In this one, I go into great detail about how malware walks the Process Environment Block (PEB) to find particular DLLs and parses their export table to find address of functions.

πŸ”— https://nikhilh-20.github.io/blog/peb_phobos_ransomware/

πŸ₯ [ tweet ]
πŸ‘9πŸ”₯6
😈 [ Justin Elze @HackingLZ ]

Pwning C2 frameworks

πŸ”— https://blog.includesecurity.com/2024/09/vulnerabilities-in-open-source-c2-frameworks/

πŸ₯ [ tweet ]
πŸ‘6πŸ”₯3
😈 [ konrad @konradgajdus ]

From Theory to Code: Implementing a Neural Network in 200 Lines of C

πŸ”— http://x.com/i/article/1837064930832404482

πŸ₯ [ tweet ]
🀯3
😈 [ Orange Cyberdefense Switzerland @orangecyberch ]

πŸ’»πŸ›‘οΈ In this series of blog posts, ClΓ©ment Labro (itm4n) one of our ethical hacker, explores yet another avenue for bypassing LSA Protection in Userland.

Blog series:
πŸ”— https://itm4n.github.io/ghost-in-the-ppl-part-1/
πŸ”— https://itm4n.github.io/ghost-in-the-ppl-part-2/
πŸ”— https://itm4n.github.io/ghost-in-the-ppl-part-3/

Code:
πŸ”— https://github.com/itm4n/PPLrevenant
πŸ”— https://github.com/itm4n/Pentest-Windows/tree/main/NdrServerCallAll

πŸ₯ [ tweet ]
πŸ‘10πŸ”₯3
😈 [ Remko Weijnen @RemkoWeijnen ]

Proof of Concept to leverage Windows App to create an LSASS dump

πŸ”— https://github.com/rweijnen/createdump

πŸ₯ [ tweet ]
πŸ₯±5πŸ”₯4πŸ‘1
😈 [ DSAS by INJECT @DevSecAS ]

Recursive Loader

Explanation of code: The following code is inspired by APT Linux/Kobalos. Kobalos was malware, suspected to be tied to the Chinese government, which was fully recursive. It was novel malware.

πŸ”— https://github.com/Evi1Grey5/Recursive-Loader

πŸ₯ [ tweet ]
πŸ‘11
😈 [ Will @BushidoToken ]

I am happy to share another new resource I recently made called The Russian APT Tool Matrix πŸ‡·πŸ‡Ί

πŸ”— https://blog.bushidotoken.net/2024/09/the-russian-apt-tool-matrix.html
πŸ”— https://github.com/BushidoUK/Russian-APT-Tool-Matrix

πŸ₯ [ tweet ]

ΠΈΡ‰Π΅ΠΌ сСбя, ΠΏΠ°Ρ†Π°Π½Ρ‹
πŸ‘8πŸ₯±6😁3🍌3😒1
😈 [ Check Point Research @_CPResearch_ ]

10 years of DLL hijacking - featuring abused executables that shouldn't have existed, exported and malicious DLLs with discount bin "packing." Includes a PoC for app developers to pre-emptively stop hijacking without dealing with a certificate authority.

πŸ”— https://research.checkpoint.com/2024/10-years-of-dll-hijacking-and-what-we-can-do-to-prevent-10-more/

πŸ₯ [ tweet ]
πŸ‘6
😈 [ Fox-IT @foxit ]

Check out our latest blog from our Red Team about EDR evasion through malware virtualisation:

πŸ”— https://blog.fox-it.com/2024/09/25/red-teaming-in-the-age-of-edr-evasion-of-endpoint-detection-through-malware-virtualisation/

πŸ₯ [ tweet ]
πŸ”₯2