Long time no see! After 3 years of no new blog posts and also no conference talks from my side, I decided it’s time to write again. I’ll start easy with a fun story that happened a while ago. I gave a short lightning talk about this on Alligatorcon 2024 , but as it may be of greater interest, ChatGPT and I wrote a little more elaborate version that consists of full sentences. If you…
This post is a short notice about vulnerabilities in VMware products I found earlier this year. During a penetration test of a freshly built environment, I took a closer look at VMware Unified Access Gateway (UAG) in combination with devices enrolled and managed via VMware Unified Endpoint Management (UEM). I found a reflected XSS vulnerability on VMware’s authenticator vmwareidentity.de…
TL;DR : I’ll shine a light on Gophish and how to modify it to change behavior or introduce/remove functionality. At the end of this post, you’ll know how to host custom 404 pages in Gophish and how to abuse HTTP basic auth instead of login forms embedded on the landing page to obtain juicy creds. A few days ago I tweeted one of my modifications to Gophish: After low click rates in my…
TL;DR : In some circumstances, you may find usable Kerberos TGTs on a system you compromised - these allow you to impersonate a user that already changed its password (e.g. because the user got suspicious or a PAM solution is in place). Intro On a recent project, I was tasked with the usual goal: Start from the ground and find a way to take over the company - in the end, if possible, somehow…
TL;DR: If the remote server allows Restricted Admin login, it is possible to login via RDP by passing the hash using the native Windows RDP client mstsc.exe . (You’ll need mimikatz or something else to inject the hash into the process) On engagements it is usually only a matter of time to get your hands on NTLM hashes. These can usually be directly used to authenticate against other services…
Mir ist zwar das Tool pandoc als universeller Dokumentconverter schon länger ein Begriff, aber ich bin erst vor kurzem wieder darauf aufmerksam geworden, und zwar um damit Präsentationen in Markdown (oder reStructuredText, Docbook, whatever) zu erstellen und diese dann zu LaTeX Beamer Präsentationen zu konvertieren. Es werden aber auch andere Formate unterstützt, zum Beispiel HTML5 Präsentationen…
Ich betreibe seit längerem auf einem ansonsten ungenutzten Raspberry Pi meinen eigenen DNS-Resolver. Auf dem Raspberry Pi läuft dabei Arch Linux und unbound als DNS Resolver. Natürlich könnte man auch einen anderen Resolver, bspw. von Google oder dem Telco nehmen, aber auf der einen Seite läuft man dann Gefahr, dass alle DNS-Anfragen getrackt werden, Antworten manipuliert werden oder man sogar auf…
Klassiker im Alltag eines Terminal-Nutzers: Das sudo vergessen. Viele gehen dann in der History zurück, scrollen von Hand an den anfang und tippen halt sudo noch davor hin. Etwas bequemer ist da schon sudo !! , wobei mir das auch noch zu viel Schreibarbeit ist. Inspiriert von einem askubuntu-Thread habe ich mir den pls -Befehl definiert. Dazu einfach folgendes ans Ende der ~/.zshrc schreiben:…
Ich wollte mir mal Windows 10 außerhalb einer virtuellen Umgebung anschauen - mein Laptop hat leider kein DVD-Laufwerk, weswegen ich die Installation vom USB-Stick durchführen muss. Prinzipiell ist das meiner Meinung nach sowieso immer der way-to-go, da man den Stick wiederverwenden kann und alles sowieso schneller geht als von der DVD. Bei iso-Dateien von Linux-Distributionen hat bisher immer ein…
Bisher habe ich für alle Seiten, bei denen ich mich registriert habe, eine eigene E-Mail Adresse mit Weiterleitung auf ein Sammelpostfach angelegt. Das hat den Vorteil, dass man Emails relativ leicht sortieren kann, man sofort sieht wo der Spam her kommt und man sich einer solchen Adresse auch wieder relativ schnell entledigen kann. Das Anlegen einer neuen E-Mail Adresse ist in meinem Fall auch…
Hi, I’m Michael. I started my B.Sc. in Computer Science at Technische Universität München (TUM) in 2013 and graduated in 2016 (B.Sc.) and 2019 (M.Sc.). From 2014 to 2016 I worked at research institute as research assistant and got my hands dirty with Android security and the development of a vulnerability scanner for Android applications. From 2016 to 2026 I was doing penetration testing,…
As one of my hobbies, I collect stuff that is turing complete . The original idea comes from Andreas Zwinkau’s “Accidentally Turing-Complete” . Here is his list: C++ Templates X86 MMU Magic: The Gathering HTML5 + CSS3 Minecraft SQL (with Common Table Expressions and Windowing) C Preprocessor (if executed in a loop) Apache Rewrite Rules Pokemon Yellow Scala Type System MediaWiki…