
Steve Borosh
@rvrsh3ll
The future is not set. There is no fate, but what we make for ourselves. - John Connor
ID: 1763744467797098496
https://futuresec.io 02-03-2024 01:53:59
3,3K Tweet
915 Takipçi
569 Takip Edilen












I released a tool a couple years back at DEF CON that lets you check if an email exists as a guest in a tenant. github.com/nyxgeek/guestl… You can include an AWS key for fireprox rotation (thnx Mike Felch (Stay Ready) !) as this endpoint is prone to false positives after 50-100 attempts.


NetExec now has native checks for LDAP signing and channel binding capabilities of the target DC, thanks to the implementation of Thomas Seigneuret 🚀 I also fixed querying LDAP with non-ASCII characters, so you can finally query groups such as "Dämonen-Administratoren"🎉


Unconstrained Delegation on a gMSA and Webclient / NTLMv1 active on servers that can retrieve the credentials of a gMSA with unconstrained delegation can lead to a complete domain compromise from domain users. nothingspecialforu.github.io/UCgMSAExploita… Micah Van Deusen, Dirk-jan, nice tools :)

