Tag: windows
Invisi-Shell Bypasses all of Powershell Security Features
Hide your powershell script in plain sight! Invisi-Shell bypasses all of Powershell security features (ScriptBlock logging, Module logging, Transcription, AMSI) by hooking .Net assemblies. The hook is performed via CLR Profiler API. Work In Progress […]
Dirble a Website Directory Scanning Tool for Windows and Linux.
Introduction Dirble is a website directory scanning tool for Windows and Linux. It’s designed to be fast to run and easy to use. How to Use Download one of the precompiled binaries for Linux, Windows, […]
BarcodeOCR 19.3.6 – ‘BarcodeOCR’ Unquoted Service Path
# Exploit Title: BarcodeOCR 19.3.6 – ‘BarcodeOCR’ Unquoted Service Path # Discovery Date: 2020-07-31 # Response from BarcodeOCR Support: 08/03/2020 # Exploit Author: Daniel Bertoni # Vendor Homepage: https://www.barcode-ocr.com/ # Version: 19.3.6 # Tested on: […]
AutoRDPwn Post Exploitation Framework
AutoRDPwn is a post-exploitation framework created in Powershell, designed primarily to automate the Shadow attack on Microsoft Windows computers. This vulnerability (listed as a feature by Microsoft) allows a remote attacker to view his victim’s […]
FTPDummy! 4.80 Local Buffer Overflow
# Exploit Title: FTPDummy! 4.80 – Local Buffer Overflow (SEH) # Date: 2020-07-22 # Author: Felipe Winsnes # Software Link: http://www.dummysoftware.com/ftpdummy.html # Version: 4.80 # Tested on: Windows 7 (x86) # Blog: https://whitecr0wz.github.io/ # Proof […]
LDAP Search -Bruteforce Passwords, Enumerate Users, Groups, and Computers from Windows Domains.
Overview LDAP_Search can be used to enumerate Users, Groups, Computers, Domain Policies, and Domain Trusts within a Windows environment. Authentication can be performed using traditional username and password, or NTLM hash. In addition, this tool […]
Microsoft Windows 10 – Local Privilege Escalation (UAC Bypass)
# Exploit Title: Windows 10 UAC Bypass by computerDefault # Date: 2018-10-18 # Exploit Author: Fabien DROMAS – Security consultant @ Synetis # Twitter: st0rnpentest # # Vendor Homepage: www.microsoft.com # Version: Version 10.0.17134.285 # […]