Tags
Browse by subject- AWS (1)
- Attack-Paths (1)
- CVE (1)
- Containers (1)
- Exploit (1)
- FreeIPA (5)
- Identity (1)
- Kerberos (3)
- LDAP (1)
- Lab (1)
- Linux (1)
- Mod-Rewrite (1)
- OneLogin (1)
- Persistence (1)
- Phishing (3)
- Priv-Esc (1)
- SAML (1)
- Server-Setup (3)
- Vulnerability-Research (2)
- WMI (1)
- Wifi (1)
AWS 1
Attack-Paths 1
CVE 1
Containers 1
Exploit 1
FreeIPA 5
-
Attacking FreeIPA — Part IV: CVE-2020–10747
A detailed examination of FreeIPA role boundaries, privilege escalation behavior, and the issue originally assigned CVE-2020-10747.
-
Attacking FreeIPA — Part III: Finding A Path
Combining FreeIPA enumeration and credential access into a complete attack path through a purpose-built lab environment.
-
Building a FreeIPA Lab
Building a repeatable FreeIPA research environment in containers, from domain setup through enrolled clients and test identities.
-
Attacking FreeIPA — Part II: Enumeration
Enumerating the users, hosts, groups, policies, and trust relationships that reveal attack paths through a FreeIPA environment.
-
Attacking FreeIPA — Part I: Authentication
Host indicators and authentication material in FreeIPA environments, including keytab files, CCACHE tickets, and credentials held in the Linux kernel keyring.
Identity 1
Kerberos 3
-
Attacking FreeIPA — Part III: Finding A Path
Combining FreeIPA enumeration and credential access into a complete attack path through a purpose-built lab environment.
-
Attacking FreeIPA — Part II: Enumeration
Enumerating the users, hosts, groups, policies, and trust relationships that reveal attack paths through a FreeIPA environment.
-
Attacking FreeIPA — Part I: Authentication
Host indicators and authentication material in FreeIPA environments, including keytab files, CCACHE tickets, and credentials held in the Linux kernel keyring.
LDAP 1
Lab 1
Linux 1
Mod-Rewrite 1
OneLogin 1
Persistence 1
Phishing 3
-
Spear Phishing 101
An end-to-end field guide to the infrastructure, delivery, payload, and operational details behind an authorized spear-phishing campaign.
-
Mod_Rewrite Automatic Setup
Automating an Apache mod_rewrite redirector for resilient red team command-and-control infrastructure.
-
Mail Servers Made Easy
A repeatable Postfix and Dovecot mail-server build for authorized phishing infrastructure, including TLS and the DNS records required for delivery.
Priv-Esc 1
SAML 1
Server-Setup 3
-
Spear Phishing 101
An end-to-end field guide to the infrastructure, delivery, payload, and operational details behind an authorized spear-phishing campaign.
-
Mod_Rewrite Automatic Setup
Automating an Apache mod_rewrite redirector for resilient red team command-and-control infrastructure.
-
Mail Servers Made Easy
A repeatable Postfix and Dovecot mail-server build for authorized phishing infrastructure, including TLS and the DNS records required for delivery.
Vulnerability-Research 2
-
OneLogin, Many Issues: How I Pivoted from a Trial Tenant to Compromising Customer Signing Keys
How flaws in OneLogin’s AD Connector exposed credentials, signing keys, and customer API material—enabling valid JWT generation and arbitrary user impersonation.
-
Attacking FreeIPA — Part IV: CVE-2020–10747
A detailed examination of FreeIPA role boundaries, privilege escalation behavior, and the issue originally assigned CVE-2020-10747.