Pokazywanie postów oznaczonych etykietą metasploit. Pokaż wszystkie posty
Pokazywanie postów oznaczonych etykietą metasploit. Pokaż wszystkie posty

sobota, 14 czerwca 2025

Palo Alto PostAuth CLI memory corruption bug - Metasploit module

Few days ago I posted some notes about the bug found in January in Palo Alto VM. Today you'll find some details about a working poc for Metasploit created for this bug. Here we go...

wtorek, 30 lipca 2024

Automating Network Pentests with Metasploit and Ruby

This time we'll continue the journey started in previous post to create a small 'semi-automated' tool to perform some 'basic' network pentests. For this case we'll focus (mostly;)) on CVE-2021-20039 for SonicWall SMA. Here we go...

środa, 24 lipca 2024

Reading Nmap Log In Ruby

From time to time during pentests we're using nmap to scan the target host(s). Today we'll try to read nmap's log using Ruby. Below you'll find few details about it. Here we go...

wtorek, 28 listopada 2023

Windows Embedded Eternally Blue

Few weeks ago I was asked to help a bit with exploitation of MS17_010 for one of the hosts found in the pentest project scope. Below you'll find more details about it. Here we go...

środa, 6 kwietnia 2022

Pentesting Pentesters with MSF Jump Host

Let's think about the scenario for a pentest/redteam project during which we are using 'our dedicated jump host'. "What if" someone will takeover this host? This time we'll try to check the potential results of this kind of attack. Here we go...

poniedziałek, 4 kwietnia 2022

Ansible - Quick Shot

I decided to create this small document to collect few basic ideas about Ansible and how it can be used during a ‘day-to-day’ scenarios for pentest and red team projects. If you’re already familiar with Ansible – this document more likely will be a small ‘cheat sheet’ if you’d like to use Ansible to perform some actions during the projects. Anyhow… Enjoy and have fun! ;) Here we go...

poniedziałek, 14 lutego 2022

Enter in 2022

It was an interesting beginning of the year. After a few talks with few friends during last year, last few weeks I spent creating a new small tool called EnterTerminal. More details about it you'll find below. Here we go... 

niedziela, 1 listopada 2020

Code16 - Notes Magazine - 01

Hi. I decided to change a way of posting this time. Below I presented a small surprise for you. Maybe you'll find it useful. Here we go...

wtorek, 14 sierpnia 2018

venome.sh - simple msfvenom "generator"

Sometimes I'm looking for a quick file to check the possibility of reverse-shell... This time I prepared a small bash-script to speed it up ;) Maybe you will find it useful...

piątek, 18 sierpnia 2017

Metasploit module for RCE in Trend Micro IMSVA 9.1

According to the story posted yesterday below you will find quick&dirty proof-of-concent module for Metasploit. Big thanks goes to Mehmet for his research. Poc is based mostly on his work.

piątek, 13 stycznia 2017

Kvasir CTF - Writeup


Man. I played few CTFs in my life. But this one, to be honest, was one of the best I’ve ever tried…;) Have fun.

poniedziałek, 22 sierpnia 2016

sobota, 20 sierpnia 2016

joomlash - new test in grabash.py

During couple of last few days I had a chance to check grabash code again. I am aware that this is still not even 'first' final version ;) so there is always something 'todo' or to fix to get better results from the scan. So, yeah, any feedback is welcome.

wtorek, 16 sierpnia 2016

Axis2 LFI module for CTF

Few weeks ago I tried to solve Axis2 CTF from VulnHub. It was a lot of fun. As far as there is a grabash, I decided to create small module for Metasploit to exploit LFI bug in that virtual machine...