Open in app

Sign In

Write

Sign In

AliBawazeEer
AliBawazeEer

54 Followers

Home

About

Feb 20, 2021

The TROJANIZED COMPONENT: DISSECTING THE BROWSER EXTENSION AND CTI GREAT EFFECTS

The TROJANIZED COMPONENT: DISSECTING THE BROWSER EXTENSION AND CTI GREAT EFFECTS Without question, 2020 was defined by the global coronavirus pandemic (GCP). So to speak Not only has the virus had huge public health consequences, social distancing and lockdown measures also have had profound economic impacts. …

Reverse Engineering

13 min read

The TROJANIZED COMPONENT: DISSECTING THE BROWSER EXTENSION AND CTI GREAT EFFECTS
The TROJANIZED COMPONENT: DISSECTING THE BROWSER EXTENSION AND CTI GREAT EFFECTS
Reverse Engineering

13 min read


Aug 17, 2020

PowerShell — Data Ex-filtration over DNS (OOB)

increasingly, companies considering security a top priority and ex-filtration of data are more restricted. The OOB techniques often useful in a blind vulnerability , as an attacker you don’t get the output of exploit in direct response , for instance in a web-app vulnerable to blind injection . …

Powershell Script

4 min read

PowerShell — Data Ex-filtration over DNS (OOB)
PowerShell — Data Ex-filtration over DNS (OOB)
Powershell Script

4 min read


Oct 22, 2018

Simple Executable HTTP Server for pentester

recently i was in engagement and needed to download large file from the compromised machine , i was unable to get it from TFTP neither from cert-util . i had to create a simple python script that launch mini HTTP web server and convert it to exe since it was…

Python

1 min read

Python

1 min read


Apr 18, 2018

TTY SHELL FROM ONE LINE OF PHP CODE

we all know how important to gain tty ( teletype terminal ) shell during a penetration testing. i had a scenario where the vulnerable webdav server is installed in virtualization environment and no routing enabled from the victim box to the outside network or lets say there is outbound firewall and reverse connection denied !!

Docker

1 min read

TTY SHELL FROM ONE LINE OF PHP CODE
TTY SHELL FROM ONE LINE OF PHP CODE
Docker

1 min read


Apr 17, 2018

Hashcat In Virtualization environment

we all know hashcat utilize gpu and to work with cpu in virtualbox or vmware you will need to install the following apt-get install libhwloc-dev ocl-icd-dev ocl-icd-opencl-dev apt-get install pocl-opencl-icd tested on PWK vm

1 min read

Hashcat In Virtualization environment
Hashcat In Virtualization environment

1 min read


Apr 11, 2018

using Mimikatz to get cleartext password from offline memory dump

requirements : new version of kali mimikatz : wget https://raw.githubusercontent.com/dfirfpi/hotoloti/master/volatility/mimikatz.py in case you found offline dump or you were able to dump lsas process using procdump The technique can be involves in pentesting by obtaining passwords in clear text from a server without running “malicious” code in it since mimikatz…

Mimikatz

2 min read

using Mimikatz to get cleartext password from offline memory dump
using Mimikatz to get cleartext password from offline memory dump
Mimikatz

2 min read


Feb 27, 2018

kaizen-ctf 2018 — Reverse Engineer usb keystrok from pcap file

yesterday was a great experience for me to attend all kind of joubert , one of the challenges i could not solve and understand in the reverse engineering section . this CTF challenge contain pcapng file and no hint provided only flag needed to earn the points .. for people…

Programming

4 min read

kaizen-ctf 2018 — Reverse Engineer usb keystrok from pcap file
kaizen-ctf 2018 — Reverse Engineer usb keystrok from pcap file
Programming

4 min read

AliBawazeEer

AliBawazeEer

54 Followers
Following
  • Teri Radichel

    Teri Radichel

  • Dr Mehmet Yildiz

    Dr Mehmet Yildiz

  • Prof Bill Buchanan OBE

    Prof Bill Buchanan OBE

  • Pentester Academy

    Pentester Academy

  • M'hirsi Hamza

    M'hirsi Hamza

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech