Hacker, sysadmin and security researcher @OrangeCyberdef 💻 Calisthenic enthousiast 💪 and wannabe philosopher t.ly/9NPk0 📖 🔥 Hide&Sec 🔥

The grid
Dumping LSASS is old school. If an admin is connected on a server you are local admin on, just create a scheduled task asking for a certificate on his behalf, get the cert, get its privs. All automatized in the schtask_as module for NetExec 🥳🥳🥳
7
299
1,359
72,466
Aurélien Chalot retweeted
3 months of work later, MS-NEGOEX is merged into Impacket 🚀 First big step toward bringing Impacket on Entra ID-joined & hybrid machines. Next stop is PKU2U, after #2260 gets merged and soon after you will have SMB, LDAP & MSSQL on Azure with the tools you already know 👀 Be sure to check it out, research or/and build on it! Cant wait to see the sort of Azure offsec opportunities that may come out of this : ) github.com/fortra/impacket/p…
1
13
28
1,773
Yesterday we merged two new functionnalities on NXC for MSSQL. The ability to dump local database users' hashes. The new function lists both the login name, the algorithme used to hash the password and the hash allowing cracking them via hashcat/john:
3
32
181
7,545
As well as a function that allows listing databases' backups as well as their backup path and whether the backup is encrypted or not (which may help finding password, sensitive data and so on).
1
14
632
This is part of a much bigger project that I started a year ago in order to provide better offensive capabilities to NXC and there is much more to come! 🥳👀
9
535
Aurélien Chalot retweeted
Are you (like me) constantly running into your own Responder? The days are finally over!🚀 @Defte_ and I finally finished up a PR by bdrogja that let's you define exclusions such as "yourself". You can also exclude entire ranges or IPv6 addresses (if anyone uses those lol).
2
24
127
5,153
Please just give that person a reverser job or something this is just insane the level 🤣🤣🤣🤣🤣
FalconFlank : Crowdstrike Falcon 0day LPE is now public github.com/MSNightmare/Falco…
2
3
71
7,056
Aurélien Chalot retweeted
Be aware that your photos can be accessed without unlocking your phone when you receive a WhatsApp video call on Android. This is in plain sight. It's not hidden, not a secret feature. Not a hack. This has already been reported to Meta and Google. #Privacy #Security #Android17
84
244
3,444
630,552
Aurélien Chalot retweeted
Cet episode des "rires du Medef" est un tournant. Il vient adouber JLM en tant que seul défenseur des travailleurs/classe populaire Il vient le déclarer comme seul opposant au système eco/politique actuel Et il vient de souder toute une classe sociale derrière lui Game changer!
192
842
3,003
37,687
Aurélien Chalot retweeted
I've published UniBLEed, a fully wormable proximity Bluetooth RCE affecting Unitree's G1 humanoids. Blog spans cloud, mobile, firmware, Bluetooth & hardware. Two multi-bug RCE chains. 3 months into ~80 minutes, $6,700 in bounties. Go jailbreak your G1s!! boschko.ca/g1-ble-rce/
10
83
225
24,192
Aurélien Chalot retweeted
He copied a value out of the Windows Event Log. Pasted it into his special browser. And he was signed into Microsoft Entra as the user who had just authenticated. No password. No phishing link. No stolen private key. @MGrafnetter's Black Hat USA 2026 research...
30
373
1,978
243,846
This
This past week I’ve been asked several times by people of different ages “how do you research and publish so much?”. It’s awesome to be asked. I love sharing tips and I try to give my techniques for maintaining a research pipeline. But I also want to be honest about my reality. At times, it’s an unhealthy coping technique. I’m getting much better at it, but in the past I’ve not been so good. I’ve skirted psych wards on multiple occasions, been given a “multiple weeks off work with several therapy sessions” order, been on various psych meds, torpedoed family events and holidays etc... Social media highlights the wins, but I try and be honest about the lows too where I can. This industry is awesome, for many of us it gives us the chance to pursue our hobbies and passions. But it does encourage unhealthy routines. There is a reason that alcohol, drugs and mental health issues are embedded in infosec culture. And while sharing a new blog post or cool vuln can inspire people to want to be doing more, it shouldn’t come at the expense of a healthy mind. An old boss once said “we want you doing this for a long time, not doing a lot in a short time”.. I still think about this now. Stay healthy h4xx0rz!
1
5
1,364
Aurélien Chalot retweeted
Found a heap overflow vulnerability in Windows SMB that leads to RCE and reported it to MSRC in June. The vulnerability has now been addressed with CVE-2026-62800 in the August Patch Tuesday updates. msrc.microsoft.com/update-gu…
9
81
475
31,499
Aurélien Chalot retweeted
Exploit ResetNightmare with NetExec 🔥 CVE-2026-27912: a logical flaw in the Kerberos Change Password protocol lets an attacker with Generic Write on one account reset the password of ANY user/computer, including Domain Admins. Built a module to automate the full chain 🚀
3
63
284
14,819
Aurélien Chalot retweeted
Yeah for those asking: NetExec now detects CVE-2026-27912 (ResetNightmare) via the enum_cve module. Patch or check exposure 🚀
Funny that you ask, the PR by @azoxlpf just got merged today adding the detection😁
53
226
25,915
NetExec users, you might have found that on newer Windows systems, invalid SMB authentication resulted in a NETBIOS timeout error:
1
20
114
13,218
This is the result of a new security mechanism added by M$ to prevent password bruteforcing:
1
1
32
1,576
Because of that mechanism, failed authentication resulted in the NETBIOS timeout (more than 2 seconds which was our default value so far). But thanks to @Xed_sama , it's now patched on main branch. Time to update :)!
1
5
34
1,548
Did you know MSSQL databases can be exposed via Named pipes ? Welp using Impacket we can now connect to these github.com/fortra/impacket/p… Working on the integration on NXC 👀
2
37
193
12,454
That also means ntlmrelaying to unsigned SMB allows connecting to these databases
1
3
20
1,722
NXCDB users, the proto <proto> ; back ; proto <another_proto> era is over github.com/Pennyw0rth/NetExe… 🥳
2
23
1,514