Toffy (@toffyrak) 's Twitter Profile
Toffy

@toffyrak

ID: 1763356333149999104

calendar_today01-03-2024 00:12:41

4 Tweet

76 Followers

188 Following

Yuval Gordon (@yug0rd) 's Twitter Profile Photo

๐Ÿš€ We just released my research on BadSuccessor - a new unpatched Active Directory privilege escalation vulnerability It allows compromising any user in AD, it works with the default config, and.. Microsoft currently won't fix it ๐Ÿคทโ€โ™‚๏ธ Read Here - akamai.com/blog/security-โ€ฆ

๐Ÿš€ We just released my research on BadSuccessor - a new unpatched Active Directory privilege escalation vulnerability
It allows compromising any user in AD, it works with the default config, and.. Microsoft currently won't fix it ๐Ÿคทโ€โ™‚๏ธ
Read Here - akamai.com/blog/security-โ€ฆ
Toffy (@toffyrak) 's Twitter Profile Photo

๐Ÿ” New research on a niche technique to abuse "GPP Local Users and Groups" to elevate privileges locally through sAMAccountName hijacking. This research comes with a new GPOHound update to detect this misconfiguration. ๐Ÿ”— Read more: cogiceo.com/en/whitepaper_โ€ฆ

๐Ÿ” New research on a niche technique to abuse "GPP Local Users and Groups" to elevate privileges locally through sAMAccountName hijacking.

This research comes with a new GPOHound update to detect this misconfiguration.

๐Ÿ”— Read more: cogiceo.com/en/whitepaper_โ€ฆ
Assetnote (@assetnote) 's Twitter Profile Photo

Sometimes, SQL injection is still possible, even when prepared statements are being used. Our researcher hashkitten has written up a blog post about a novel technique for SQL Injection in PDOโ€™s prepared statements: slcyber.io/assetnote-secuโ€ฆ

Alex Neff (@al3x_n3ff) 's Twitter Profile Photo

Session enumeration is only possible with admin privileges? That is a problem of the past thanks to the new --reg-sessions core functionality of NetExec, made by Toffy๐Ÿ”ฅ

Session enumeration is only possible with admin privileges? That is a problem of the past thanks to the new --reg-sessions core functionality of NetExec, made by <a href="/toffyrak/">Toffy</a>๐Ÿ”ฅ