Obtaining Domain Admin from Azure AD by abusing Cloud Kerberos Trust |
|
|
|
Anonymised Penetration Test Report |
|
|
|
Protected Users: you thought you were safe uh? |
|
|
|
From CVE-2022-33679 to Unauthenticated Kerberoasting |
|
|
|
From Zero to Hero Part 2: From SQL Injection to RCE on Intel DCM (CVE-2022-21225) |
|
|
|
From Zero to Hero Part 1: Bypassing Intel DCM’s Authentication by Spoofing Kerberos and LDAP Responses (CVE-2022-33942) |
|
|
|
RC4 Is Still Considered Harmful |
|
|
|
New Attack Paths? AS Requested Service Tickets |
|
|
|