🔐 Мне очень нравятся атаки на #KeePass, поэтому держите подборку инструментов и ресерчей на тему:
- https://blog.harmj0y.net/redteaming/a-case-study-in-attacking-keepass/
- https://blog.harmj0y.net/redteaming/keethief-a-case-study-in-attacking-keepass-part-2/
- https://github.com/denandz/KeeFarce
- https://github.com/GhostPack/KeeThief
- https://snovvcrash.rocks/2022/06/01/keethief-syscalls.html
- https://github.com/Porchetta-Industries/CrackMapExec/pull/636
- https://github.com/Porchetta-Industries/CrackMapExec/pull/637
Мало кто знает, но защититься от большей части существующих векторов атак можно, используя опенсорсный форк KeePass – KeePassXC 😉
UPD. Забываем про KeePassXC 🤦🏻♂️
- https://blog.harmj0y.net/redteaming/a-case-study-in-attacking-keepass/
- https://blog.harmj0y.net/redteaming/keethief-a-case-study-in-attacking-keepass-part-2/
- https://github.com/denandz/KeeFarce
- https://github.com/GhostPack/KeeThief
- https://snovvcrash.rocks/2022/06/01/keethief-syscalls.html
- https://github.com/Porchetta-Industries/CrackMapExec/pull/636
- https://github.com/Porchetta-Industries/CrackMapExec/pull/637
Мало кто знает, но защититься от большей части существующих векторов атак можно, используя опенсорсный форк KeePass – KeePassXC 😉
UPD. Забываем про KeePassXC 🤦🏻♂️
🔥3
Offensive Xwitter
🔐 Мне очень нравятся атаки на #KeePass, поэтому держите подборку инструментов и ресерчей на тему: - https://blog.harmj0y.net/redteaming/a-case-study-in-attacking-keepass/ - https://blog.harmj0y.net/redteaming/keethief-a-case-study-in-attacking-keepass-part…
😈 [ an0n_r0, an0n ]
somehow CVE-2023-24055 has been assigned on #KeePass for an attack path published by @harmj0y and @tifkin_ 7 years ago in 2016: https://t.co/kmWcoLBReo (look at the section Exfiltration Without Malware – KeePass’ Trigger System). awesome!🙃
🔗 https://blog.harmj0y.net/redteaming/keethief-a-case-study-in-attacking-keepass-part-2/
🐥 [ tweet ][ quote ]
somehow CVE-2023-24055 has been assigned on #KeePass for an attack path published by @harmj0y and @tifkin_ 7 years ago in 2016: https://t.co/kmWcoLBReo (look at the section Exfiltration Without Malware – KeePass’ Trigger System). awesome!🙃
🔗 https://blog.harmj0y.net/redteaming/keethief-a-case-study-in-attacking-keepass-part-2/
🐥 [ tweet ][ quote ]