Skip to main content

Recently Updated Pages

Flammekueche

Recipes

[!IMPORTANT] Cette recette est basée sur la recette de Flam's (R) [!info] Prévoir environ 30 m...

Updated 5 hours ago by Arthur Reppelin

L'overflow __scanf

Red Team - Buffer Overflows Because life Sucks

On peut commencer par voir les protections associées à notre binaire : ┌──(arthur㉿LAPTOP-KSNUF8N7...

Updated 5 hours ago by Arthur Reppelin

FootHold

Red Team - Windows

Scan Initial Dans de nombreux cas, les machines Windows ne répondent pas aux requêtes ping. Un sc...

Updated 1 week ago by Arthur Reppelin

La méthode du trampoline (x86)

Red Team - Buffer Overflows Because life Sucks

Contrairement à la méthode du saut direct que nous avons vu précédemment dans BOF1 sur TryHackMe ...

Updated 1 week ago by Arthur Reppelin

ShellCode Injection

Red Team - Buffer Overflows Because life Sucks

Pour l'injection de shellcode, les étapes sont relativement similaires au détournement de fonctio...

Updated 2 weeks ago by Arthur Reppelin

Function HiJack

Red Team - Buffer Overflows Because life Sucks

Pour récupérer l'accès à une fonction, il nous faut : L'adresse de la fonction La taille du padd...

Updated 2 weeks ago by Arthur Reppelin

GDB

Red Team - Buffer Overflows Because life Sucks

Comme je n'étais pas hyper convaincu par le cours de TryHackMe, j'ai creusé ailleurs. Quoi qu'il ...

Updated 2 weeks ago by Arthur Reppelin

Other Attacks

Red Team - Windows Credentials Harvesting

In the previous tasks, the assumption is that we already had initial access to a system and were ...

Updated 2 weeks ago by Arthur Reppelin

Local Administrator Password Solution (LAPS)

Red Team - Windows Credentials Harvesting

This task discusses how to enumerate and obtain a local administrator password within the Active ...

Updated 2 weeks ago by Arthur Reppelin

Windows Credential Manager

Red Team - Windows Credentials Harvesting

This task introduces the Windows Credential Manager and discusses the technique used for dumping ...

Updated 2 weeks ago by Arthur Reppelin

Local Security Authority Subsystem Service (LSASS)

Red Team - Windows Credentials Harvesting

What is the LSASS? Local Security Authority Server Service (LSASS) is a Windows process that han...

Updated 2 weeks ago by Arthur Reppelin

Conclusion

Red Team - Windows Credentials Harvesting

Recap In this room, we discussed the various approaches to obtaining users' credentials, includi...

Updated 2 weeks ago by Arthur Reppelin

Domain Controller

Red Team - Windows Credentials Harvesting

This task discusses the required steps to dump Domain Controller Hashes locally and remotely. NT...

Updated 2 weeks ago by Arthur Reppelin

Local Windows Credentials

Red Team - Windows Credentials Harvesting

In general, Windows operating system provides two types of user accounts: Local and Domain. Local...

Updated 2 weeks ago by Arthur Reppelin

Credential Access

Red Team - Windows Credentials Harvesting

Credential Access Credential access is where adversaries may find credentials in compromised sys...

Updated 2 weeks ago by Arthur Reppelin

Managing Users

Red Team - Windows Active Directory - Basics

Your first task as the new domain administrator is to check the existing AD OUs and users, as som...

Updated 2 weeks ago by Arthur Reppelin

Active Directory

Red Team - Windows Active Directory - Basics

The core of any Windows Domain is the Active Directory Domain Service (AD DS). This service acts ...

Updated 2 weeks ago by Arthur Reppelin

Persistence through GPOs

Red Team - Windows Active Directory - Persisting

The last persistence technique we will review is persistence through Group Policy Objects (GPOs)....

Updated 2 weeks ago by Arthur Reppelin

Persistence through ACLs

Red Team - Windows Active Directory - Persisting

Sometimes, we need more than just persisting to normal AD groups. What if we want to persist to a...

Updated 2 weeks ago by Arthur Reppelin

Persistence through Tickets

Red Team - Windows Active Directory - Persisting

As discussed in the previous tasks, we often want to persist through service accounts with delega...

Updated 2 weeks ago by Arthur Reppelin