Jump to content

WarLord

Active Members
  • Posts

    649
  • Joined

  • Last visited

  • Days Won

    28

Everything posted by WarLord

  1. Absolut. Pot sa dispara dejaba, sau nu. Am zis sa le pun pe net pentru doritori. Am strans de toate. Spor!
  2. https://nitro.download/view/93C7AA7AC7E3966/Acronis.Backup.%26.Recovery.Server.With.Universal.Restore.v11.0.17318.en.rar https://nitro.download/view/EED4E4036CACF48/Adobe_Premiere_Pro_CC_Fundamentals.rar https://nitro.download/view/9507B3186B73BBD/Adobe_Premiere_Pro_CS6.rar https://nitro.download/view/FC83D298AFC6DF2/Angular_Js_-_Get_Started.rar https://nitro.download/view/A7D583CCE0E4AC2/Build_Your_Own_NetApp_Storage_Lab.rar https://nitro.download/view/CB1B4C513AB5C28/burp_pack.zip https://nitro.download/view/957B14E0900D4C3/BurpSuite.app.zip https://nitro.download/view/953B666F88674C0/CCNA_Study_Guide_%2B_Ebook_%2B_Network_Visualizer_5.0_w_crack https://nitro.download/view/6A3E1F2AD95D2AF/Check_Point_Certified_Security_Administrator_Install_%26_Deploy.rar https://nitro.download/view/AC30417859774D1/Citrix_XenServer_WMVs.rar https://nitro.download/view/6856F6ACF8194E4/Color_Correction_and_Grading_in_Adobe_Premiere_Pro_and_SpeedGrade.rar https://nitro.download/view/50FEA3ACF7EFBB6/CompTIA_CSA%2B_Study_Guide_Exam_CS0-001.zip https://nitro.download/view/692E19A2A46E05F/CompTIA-PenTest-Certification-All-in-One-Exam-Guide_Exam-PT0-001_Technet24.rar https://nitro.download/view/123758C7447B976/Django_Fundamentals.rar https://nitro.download/view/015F1E37272A01C/Infinite_Skills_-_Video_And_Animation_With_Adobe_Photoshop.rar https://nitro.download/view/D1593FCD5D504A6/Infinite_Skills._Advanced_HTML5_Training.rar https://nitro.download/view/1C35B1D07875E2C/Introduction_to_CSS_for_Designers.rar https://nitro.download/view/253778FB9CA1BD1/Introduction_to_Firewalls.rar https://nitro.download/view/71B796044E37076/Introduction_to_HTML_for_Designers.rar https://nitro.download/view/92AC8C1A8099F15/Introduction_to_jQuery_for_Designers.rar https://nitro.download/view/7C047767CFED677/ITPro_TV_-_OpenVPN_in_Linux.rar https://nitro.download/view/2CEC8928F9D4D84/Lynda_-_Computer_Forensics_Essential_Training_(Aug_20%2C_2014).rar https://nitro.download/view/EBF1414DB0FE3D6/Lynda_-_Internet_Marketing_Basics_-_MG.rar https://nitro.download/view/351B29DE0D3D115/Penetration_Testing_with_Backtrack_3.2.rar https://nitro.download/view/700736A9846DA26/Sybex-CCNA-Cloud-Complete-Study-Guide_Exam-210-451-and-Exam-210-455_Technet24.rar https://nitro.download/view/D2C66FBEF1D73E9/Acunetix-v8.0.rar https://nitro.download/view/A8715D6E00B68F6/CompTIA-Cloud-Certification-Practice-Exams-Exam-CV0-002_Technet24.rar
  3. Daca cautati ceva anume, PM me.
  4. https://nitro.download/view/8B3EAE632DF4DA5/Pluralsight_-_Advanced_Malware_Analysis_-_Combating_Exploit_Kits.rar https://nitro.download/view/CF61C21F87C18AF/Pluralsight_-_Automated_Web_Testing_with_Selenium.rar https://nitro.download/view/89BE4DCFCB74438/Pluralsight_-_Ethical_Hacking_-_Sniffing.rar https://nitro.download/view/11253678B35572E/Pluralsight_-_Exploit_Development_and_Executin_with_Metasploit.rar https://nitro.download/view/742D42D7DF676F0/Pluralsight_-_Python_Beyond_The_Basics.rar https://nitro.download/view/3B68728B423A8EE/Pluralsight_-_Raspberry_Pi_for_Developers_Tutorial-kEISO.rar https://nitro.download/view/62AAB424BEA0E7A/Pluralsight_-_VMware_Virtual_SAN_(VSAN)_Fundamentals.rar https://nitro.download/view/093F8AE3D8337C5/Pluralsight_C%23_From_Scratch__OGNADROL_.rar https://nitro.download/view/6D325666B0F58AD/PluralSight_C%23_From_Scratch_Part_2.rar https://nitro.download/view/19224A472C05F9E/PLURALSIGHT_CREATE_A_WINDOWS_10_IMAGE_TUTORIAL.rar https://nitro.download/view/B94C3C7C18EF4CB/PluralSight_Electronics_Fundamentals_Tutorial.rar https://nitro.download/view/031181B896F67E4/PLURALSIGHT_INTRODUCTION_TO_BROWSER_SECURITY_HEADERS_TUTORIAL.rar https://nitro.download/view/514645DCD3BFC7D/PluralSight_Network_Operations_for_Comptia_NetworkPlus_N10-006_Tutorial.rar https://nitro.download/view/D4ACF26D065A42F/PLURALSIGHT_SOCIAL_MEDIA_MARKETING_FOR_YOUR_STARTUP_TUTORIAL.rar https://nitro.download/view/B75D9428CF90A0B/PLURALSIGHT_UNDERSTANDING_ENTERPRISE_ARCHITECTURE_TUTORIAL.rar https://nitro.download/view/377EF4EF1A81457/Pluralsight-CCIE_Routing_and_Switching__Implement_IPv4_and_IGPs.rar https://nitro.download/view/1B5BD178D2E7A12/PLURALSIGHT.ETHICAL.HACKING.HACKING.WEB.APPLICATIONS.TUTORIAL-kEISO.tar https://nitro.download/view/AB2018DFAA59623/PLURALSIGHT.ETHICAL.HACKING.HACKING.WEB.APPLICATIONS.TUTORIAL.rar https://nitro.download/view/3D42EEA91581060/PLURALSIGHT.ETHICAL.HACKING.HACKING.WEB.SERVERS.TUTORIAL-kEISO.rar https://nitro.download/view/C5046EA35D1584A/PLURALSIGHT.ETHICAL.HACKING.HACKING.WEB.SERVERS.TUTORIAL-kEISO.tar https://nitro.download/view/5450A7AC512557F/PLURALSIGHT.ETHICAL.HACKING.SQL.INJECTION.TUTORIAL-kEISO.rar https://nitro.download/view/6A49ADC990A028E/PLURALSIGHT.ETHICAL.HACKING.SQL.INJECTION.TUTORIAL-kEISO.tar https://nitro.download/view/C4B79FEFEE306C9/PLURALSIGHT.ETHICAL.HACKING.SYSTEM.HACKING.TUTORIAL-kEISO.tar https://nitro.download/view/0E4C97611808DC7/PLURALSIGHT.PENETRATION.TESTING.AND.ETHICAL.HACKING.WITH.KALI.LINUX.TUTORIAL-kEISO.tar https://nitro.download/view/E6CE492B8BF25D6/Pluralsight.Windows.Registry.Troubleshooting-XQZT.rar https://nitro.download/view/FC75150EFBCFD6F/CBT_Nuggets_-_Microsoft_Visio_2010_for_IT_Professionals.rar https://nitro.download/view/7A3841C0EC04228/CBT_Nuggets_70-413_Designing_and_Implementing_a_Server_Infrastructure.rar https://nitro.download/view/7B9C581570272E1/CCA_Citrix_Certified_Administrator.iso https://nitro.download/view/80E695705D0B63F/CEH_Certified_Ethical_Hacker.iso https://nitro.download/view/564E0AB33C5D1B8/CISA_Certified_Information_Systems_Auditor.iso https://nitro.download/view/ACED94F8309BE38/CISM_Certified_Information_Security_Manager.iso https://nitro.download/view/1555EB149E93851/CISSP_Certified_Information_Systems_Security_Professional.iso https://nitro.download/view/6C24B7C5D60BD9A/CIW_Certified_Internet_Web_Professional_-_CIW_Foundations.rar https://nitro.download/view/EFD25D3951F3FDB/CIW_Certified_Internet_Web_Professional_-_JavaScript_Fundamentals.iso https://nitro.download/view/2CB79F2A130ABCC/CWNA_Certified_Wireless_Network_Administrator.iso https://nitro.download/view/E7EFDB6C29CB0B7/CWNE_Certified_Wireless_Network_Expert.iso https://nitro.download/view/ED7957237F0BF61/en_windows_7_ultimate_x86_dvd.iso https://nitro.download/view/20D1450ECB0E442/ITIL_Information_Technology_Infrastructure_Library.iso https://nitro.download/view/492F25D47CADB00/LPIC-1_Linux_Professional_Institute_Certification.rar https://nitro.download/view/4E6856E20F9C1C1/LPIC-2_Linux_Professional_Institute_Certification.rar https://nitro.download/view/C801F865F23A342/OCA-DBA_Oracle_Certified_Associate_-_Database_Administrator.iso https://nitro.download/view/F8968F7D0E994A7/PMP_Project_Management_Professional.iso https://nitro.download/view/B3E7ADC45AF20F7/RHCE_1_Red_Hat_Certified_Engineer.iso https://nitro.download/view/BC4B21E813783EF/RHCE_2_Red_Hat_Certified_Engineer.iso https://nitro.download/view/EEE78BE9F42A40F/SCJP_Sun_Certified_Java_Programmer.iso https://nitro.download/view/F90D5961C27E393/SSCP_Systems_Security_Certified_Practitioner.iso https://nitro.download/view/E220E29940B4453/VBScript_Visual_Basic_Scripting.iso https://nitro.download/view/F9440DDFA2B2B12/VCP_VMware_Certified_Professional.iso https://nitro.download/view/05007C64BC75D74/Wireless%23.rar https://nitro.download/view/8619B2205D3CD87/ZCE_Zend_Certified_Engineer_PHP_5.iso https://nitro.download/view/B682A7014416489/Agile_Project_Management.iso https://nitro.download/view/A8DA7BDAB60450E/C%23_C-Sharp.iso https://nitro.download/view/4F03A66A39258AF/CIW_Certified_Internet_Web_Professional_-_Perl_Fundamentals.rar https://nitro.download/view/4ADE0DD5F66690B/CWNA_Update.rar https://nitro.download/view/B8255A92973F557/End_User_Security.rar
  5. Parca stiam ca in Romania e lege ca nu se plateste impozit pe venit din chirie! Chiar credeti ca proprietarii apartamentelor care au dau 50-100 de mii de euro pe apartamente vor sta cu mainile in buzunar? Sau ca romanii care si-au 'parcat' banii in apartamente chirii nu vor avea o vorba sau doua de spus? Apoi chiar credeti ca Johannis va promulga o asemenea lege cand si el are cateva case in chirie? Problema ca si in America, e ca nu se prea construieste si daca se construieste e super scump ca toti builderii vor sa faca profit de 50%. Apoi ce se vinde mai ales acum in timp de inflatie e mult prea scump pentru o familie tanara cu 1-2 copii; asa ca traiesc cu parintii sau in chirii. Sistemul ala de independenta se schimba si la Americani: adica batranii vor sa ramana in casele lor si sa moara in ele si la batranete invita copiii sa traiasca cu ei, asa isi mai vad si ei nepotii si is mai ajutati financiar. Din cauza inflatiei pensionarii sunt pe venit fix, adica cel mai rau lovit de cresterile de preturi. Cei inca in campul muncii mai au ceva mariri de salariu dar nu prea si atunci fac sacrificii si se muta cu parintii sau nu mai fac copii. E o lipsa de cel putin 5 mil de locuinte in America si nici daca se da drumul la construit nici asta nu va face sa scada preturile . Cand dau drumul la emigranti preturile urca tot mai sus si asa. Capitalismul a devenit un sistem avar si depasit si toti banii nu se pot concentra doar cu cei din 5-10% din populatia bogata. Apoi nu cred ca Romania sub control american va renunta la un asemenea sistem mizer si nesatul. Si apoi sa il inlocuiasca cu ce alt sistem? Resource based? Problema e de inegalitate din cauza celor bogati care au cumparat puterea politica si astfel se promulga legi impotriva populatiei si in favorul si protectia celor bogati. Ar fi multe de spus dar trebuie sa incepem prin a taxa serios pe cei bogati si ultra bogati, nu numai indivizii dar si firmele, si trebuie facuti responsabili pentru orice nedreptate economica, sociala sau financiara. Si inca ceva, 'problema' suprapopulatiei si saraciei nu e una a omului alb, ci din contra.
  6. Cel mai bun sfat!!! Invatatul continua si dupa scoala si dupa serviciu!
  7. Incident Response and Handling. Super fain. Nu numai ca trebuie sa intelegi tehnici offensive dar si defensive, apoi cautat in loguri pe Windows si Linux.
  8. Haha, toata lumea pe offensive, dar stim sa facem defensive? Tot info sec-ul e un IT bine facut si industria are nevoie de IT-isti buni carora sa le pese de sisteme, apoi avem nevoie de 'boots on the ground' pe partea de defensive, implementari sisteme, cloud implementari si cloud securitate, etc. Nu visati la bani buni daca nu aveti partea IT-ului bine cunoscuta cu vreo 10 ani de experienta minim, adica sa incepi de la helpdesk si sa urci pana la securitate dupa vreo 10 ani, nu amagiti oamenii ca fac burnout. Pentru developeri e lucru mult si f bine platit pe partea de cloud: Google si AWS. Am vorbit cu un head hunter - $150k cu vreo 3 ani de experienta pe cloud si proiecte f faine, mai faine decat in offensive. Te mananca viermii pana stai o saptamana pe un pentest report.
  9. Nytro, super fain. E CTF-ul asa in stil OffSec cu raport scris la sfarsit, sau cu flaguri? Merge orice, chiar si vms de la firme serioase ca OffSec? :D
  10. I am pretty chill bro. Nu lua totul ca atac personal, ca n-am nimic de impartit cu tine. Si da, am inteles la ce te refereai, dar totusi, cu asa cereri unul interesat crede ca esti mofturos, si nici nu se chinuie sa aplice. Daca esti dezamagit cu o firma, mergi la alta, ca doar ii ca la piata, nu?!
  11. Si tu cauti unicorni mah? Sunt multi angajatori ca si tine si nu va dati seama cat de rau stricati industria IT cu asteptari din astea.
  12. "Nu cititi curs, invatati scenarii. Nu invatati comenzi ci luati un scenariu si rezolvati-l de la cap la coada. Nu va axati pe cursuri/certificari care sunt vendor propietary, cum este Cisco. ...Invatati cum functioneaza lucrurile si mai ales de ce." CORECT! Invatati scenarii. 100-1000 de acord cu asta. Practica si iar practica gandita. Asa ca si militarii. Aia nu invata din carte teoretic cum sa traga cu arma, sau teoretic cum se infiltreaza/ataca o tara, ci practic, pe campul de lupta si prin exercitii!
  13. Merita de inceput ca sa-ti dezvolti un vocabular sa poti prezenta o idee un manager sau coleg din domeniu, etc. Dar cu certificatele de inceput nu faci prea multa treaba. Daca gasesti un Security+ care sa te invete practic ce inseamna fiecare lucru/idee/notiune atunci DA, pentru ca in momentul ala inveti practic cum si ce. Poti sa faci tu research-ul tau, acasa cu VMware workstation si masini virtuale, pe care oricum ca ITist trebuie sa il ai, dar dureaza luni de zile pana aflii raspunsurile la intrebarile tale critice si practice. Eventual daca prezinti bine situatia la un interviu, poti sa spui ca ai facut tu research-ul acasa in laborator, in reteaua ta de acasa, explici, comentezi, aduci contra argumente la inverviu sa arati ca stii ce pula ta vorbesti, si daca gasesti un manager din ala care sa aprecieze setea ta pentru cunostinte ai spart gheata si iei un job. Nu stiu cum is managerii romani, dar cum observa multi, managerii romani is destul de distrusi si pretentiosi. Din carti inveti multa teorie, si putina practica, de aia se pune accentul pe 'experienta' lui peste. Apoi nu uita ca Security+ expira in 3 ani. Eu am deja Security+ (2017), si invat acuma pentru CySA+, beta examen pe care il am pe data de Decembrie 20. Daca il iau imi reinnoiesc Network+, Security+ si am si CySA+. Ureaza-mi bafta Nimeni nu-ti poate lua cunostinta pe care o ai, dar daca nu o pui in practica in cateva luni de zile, incepi sa scartaii. Faptul ca ai facut niste certificate trebuie sa arate ca ai macar sete de cunostinta de felul ala, ca ti-ar placea sa faci asa ceva, ca ai ceva idei. Cunostintele de baza ar trebui sa arate un manager ca vi cu ceva cunostinte la bord, si ca acuma el ca lider/sef/manager poate sa te cladeasca. Dar multi cretini din industria de security nu le trebuie numai unicorni si cai verzi pe pereti. E jale in industria de security, cu 2 milioane de locuri de munca vacante, si managerii de cacat se plang ca nu gasesc oameni. Se afla oameni, dar nu unicorni din aia care vor ei. Lucrurile se vor schimba in 2020 pentru ca se va incepe la un nou trend in care managerii, din cauza industriei, vor fi nevoiti sa angajeze entry-level si sa ii cladeasca, sau vor trebuie sa plateasca salarii exagerate celor care sunt deja cu experienta dar fac mofturi la salarii. Asa ca pune mana si invata ca iti va prinde bine, ori in tara ori inafara tarii. Iti doresc succes si revino cu denumeriri si probleme pe care le intalnesti in timpul studiilor. Sper ca gasesc oameni de treaba, care sa te ajute sa inveti, si sa nu ai de-a face cu aroganta unora care o ajuns mare haxori si o uitat de unde o inceput care iti arunca vorbele de parca vorbesc cu un caine. Numai bine.
  14. Hai mah nu te ambala in halul ala ca noi doi nu avem nimic unul cu celalalt. Treaba lui ala ce vrea sa faca, dar mai intelept ar fi sa nu inceapa la drum pana nu isi face experienta in IT de cativa ani buni.
  15. @vatman32 - tu crezi ca toti analistii dezvolta 0 days? Si numai daca poti sa dezvolati un 0 day esti haxor? exagerezi putin Dar un cybersec analist trebuie sa inteleaga mentalitatea de haxor oricum, la fel si un sys admin/engineer. Nu e nevoie sa dam exemple de unicorni din aia care la 50 de ani si-o schimbat cariera din lopatar in web developer
  16. Chiar sunt curios cum merg lucrurile in Romania pe domeniul Info Sec. Adica IT-ul aud ca o duce destul de bine, incepand cu salarii de vreo 500 de euro la novice, dar astia care fac upgrade-ul din sysadmin/helpdesk/etc in InfoSec, cum sunt salariile? Se moare fara diploma de facultate? Ii impresioneaza certificatele pe angajatori? Ce se cere mai mult: blue teamers, red teamers, o amestecata din aia de purple teamers?
  17. Ce-o vrut sa zica ii ca daca vrea sa ii impresioneze pe aia de la angajari, sa duca ceva de-acasa, ceva proiect la ce-o lucrat, ceva practic, decat niste hartii si teorie din certificate.
  18. Exact parerea mea gigiRoman. Omul de-abia si-a terminat CCNA-ul si vrea sa sa se faca cybersec analist, si @vatman il ia cu chestii de development: panel web, stocare in baze de date, APIs, sisteme cache, uz abuziv de procesoare in development, cunostinte de baze de stocare de date. Eu zic omului sa se faca sys admin/inginer daca ii place IT-ul si sa lase labareala din Info Sec. Si mai ales, sa invate 1-2 domenii la care ii bun ca de ex retele si inca ceva si apoi sa treaca in Info Sec daca ii place inca labareala. Sa lase visele alea de mare haxor ca se pierde pe drum si o da in disperare si nebunie ca multi din Info Sec care is cu nervii la pamant. Sunt destule joburi in IT si dupa 8-10 ore mergi acasa si ai viata de familie si prieteni. Nu-ii trebuie adictie la calculatoare.
  19. CBT-Getting-Started-with-Palo-Alto-Firewalls-v8.x https://mega.nz/#F!M2ARlKbT!P5-pS0E-QZroCEe4kz1Wqw!wzYFnSIA
  20. https://www.jollyfrogs.com/osee-awestralia-2018-preparations/ OSEE - AWEstralia 2018 preparations Living in Australia, the total cost of attending the AWE training in Vegas, including flights and hotel would exceed AUD 10,000$. So instead I decided to ask the Offensive Security trainers if they wanted to come and deliver the AWE training in my home town of Brisbane, Australia. I was able to rally together a few large companies interested in participating in the training. We now have over 25 interested people - enough for Offensive Security to come to Brisbane and host the training right here in Australia! Since the training is called Advanced Windows Exploitation (AWE), we call the training AWEstralia 2018 - it will be a lot of fun! This post is to help myself and other participants prepare for the AWE exam. Many thanks to Alpine for helping put together this guide. This guide was written based on existing AWE (OSEE) reviews and the official AWE syllabus topics. We're in the preparation stages now - lots of learning and finding good resources to prepare for the onslaught of AWE. Offensive Security has not yet confirmed a date for 2018 but we expect them to confirm very soon. The date will be around May 2018 and the course will be held in Brisbane Australia. If you'd like to join us, please contact me on TheFrog at jollyfrogs -dot -com. WinDBG usage AWE students are expected to know how to use the WinDBG debugger WinDBG general information: https://docs.microsoft.com/en-us/windows-hardware/drivers/debugger/ WinDBG configuration: https://docs.microsoft.com/en-us/windows-hardware/drivers/debugger/getting-started-with-windows-debugging WinDBG configuration in VMWare: http://silverstr.ufies.org/lotr0/windbg-vmware.html WinDBG configuration in VirtualBox: https://hshrzd.wordpress.com/2017/05/28/starting-with-windows-kernel-exploitation-part-1-setting-up-the-lab/ WinDBG Lab: https://docs.microsoft.com/en-us/windows-hardware/drivers/debugger/debug-universal-drivers---step-by-step-lab--echo-kernel-mode- WinDBG Useful commands reference: https://briolidz.wordpress.com/2013/11/17/windbg-some-debugging-commands/ Module 0x01 Custom Shellcode Creation http://www.securitytube-training.com/online-courses/securitytube-linux-assembly-expert/index.html http://www.securitytube-training.com/online-courses/x8664-assembly-and-shellcoding-on-linux/index.html SLAE32 and SLAE64 discount code https://www.fuzzysecurity.com/tutorials/expDev/6.html https://blahcat.github.io/2017/08/14/a-primer-to-windows-x64-shellcoding/ The Shellcoder's Handbook http://sh3llc0d3r.com/windows-reverse-shell-shellcode-ii/ http://blog.harmonysecurity.com/2009/06/retrieving-kernel32s-base-address.html http://nagareshwar.securityxploded.com/2013/09/21/using-peb-to-get-base-address-of-kernelbase-dll/ http://www.rohitab.com/discuss/topic/38717-quick-tutorial-finding-kernel32-base-and-walking-its-export-table/ http://www.hick.org/code/skape/papers/win32-shellcode.pdf http://expdev-kiuhnm.rhcloud.com/2015/05/22/shellcode/ https://www.offensive-security.com/vulndev/fldbg-a-pykd-script-to-debug-flashplayer/ https://exploit.courses/files/bfh2017/day6/0x60_WindowsExploiting.pdf https://secure2.sophos.com/de-de/medialibrary/PDFs/other/Comprehensive-Exploit-Prevention.ashx Module 0x02 DEP/ASLR/EMET Bypass and Sandbox Escape via Flash HeapSpray https://www.offensive-security.com/vulndev/disarming-and-bypassing-emet-5-1/ https://www.offensive-security.com/vulndev/disarming-emet-v5-0/ https://www.offensive-security.com/vulndev/disarming-enhanced-mitigation-experience-toolkit-emet/ https://www.blackhat.com/presentations/bh-europe-07/Sotirov/Whitepaper/bh-eu-07-sotirov-WP.pdf https://www.corelan.be/index.php/2011/12/31/exploit-writing-tutorial-part-11-heap-spraying-demystified/ https://www.fuzzysecurity.com/tutorials/expDev/8.html https://www.fuzzysecurity.com/tutorials/expDev/11.html https://www.corelan.be/index.php/2016/07/05/windows-10-x86wow64-userland-heap/ https://www.corelan.be/index.php/2013/01/18/heap-layout-visualization-with-mona-py-and-windbg/ https://www.corelan.be/index.php/2013/02/19/deps-precise-heap-spray-on-firefox-and-ie10/ http://gsec.hitb.org/sg2016/sessions/look-mom-i-dont-use-shellcode-a-browser-exploitation-case-study-for-internet-explorer-11/ https://github.com/shellphish/how2heap https://0x00sec.org/t/heap-exploitation-abusing-use-after-free/3580 http://expdev-kiuhnm.rhcloud.com/2015/06/02/ie11-part-1/ http://expdev-kiuhnm.rhcloud.com/2015/06/02/ie11-part-2/ http://expdev-kiuhnm.rhcloud.com/2015/06/01/ie10-use-free-bug/ https://sites.google.com/site/zerodayresearch/smashing_the_heap_with_vector_Li.pdf http://blog.morphisec.com/exploit-bypass-emet-cve-2015-2545 http://casual-scrutiny.blogspot.sg/2015/01/simple-emet-eaf-bypass.html Module 0x03 32-bit Kernel Driver Exploitation https://www.offensive-security.com/vulndev/ms11-080-voyage-into-ring-zero/ https://github.com/hacksysteam/HackSysExtremeVulnerableDriver https://theevilbit.blogspot.sg/2017/09/pool-spraying-fun-part-1.html https://theevilbit.blogspot.in/2017/09/windows-kernel-pool-spraying-fun-part-2.html https://theevilbit.blogspot.in/2017/09/windows-kernel-pool-spraying-fun-part-3.html https://www.fuzzysecurity.com/tutorials/expDev/14.html https://www.fuzzysecurity.com/tutorials/expDev/15.html https://www.fuzzysecurity.com/tutorials/expDev/19.html https://www.whitehatters.academy/intro-to-windows-kernel-exploitation-2-windows-drivers/ https://foxglovesecurity.com/2017/08/25/abusing-token-privileges-for-windows-local-privilege-escalation/ https://glennmcgui.re/introduction-to-windows-kernel-exploitation-pt-1/ https://glennmcgui.re/introduction-to-windows-kernel-driver-exploitation-pt-2/ http://srcincite.io/blog/2017/09/06/sharks-in-the-pool-mixed-object-exploitation-in-the-windows-kernel-pool.html https://github.com/hatRiot/token-priv https://rootkits.xyz/blog/2017/06/kernel-setting-up/ https://rootkits.xyz/blog/2017/08/kernel-stack-overflow/ https://rootkits.xyz/blog/2017/09/kernel-write-what-where/ Module 0x04 64-bit Kernel Driver Exploitation http://trackwatch.com/windows-kernel-pool-spraying/ https://blahcat.github.io/2017/08/31/arbitrary-write-primitive-in-windows-kernel-hevd/
      • 5
      • Upvote
      • Thanks
  21. Se pare ca vin strainii pe site Azi maine vorbim cu totii engleza pe aici.
  22. @SilenTx0 - nu ai cumva si cursul PTX de la eLearnSec?
  23. Merge daca o tastez, dar nu merge daca ii dau cu grija copy&paste. Nu are spatiu. Merci
  24. Nu merge parola. De ce?
  25. Si ce cursuri erau? Am zis sa le luati cat is calde
×
×
  • Create New...