Replying to @exploitph @_batsec_
also, this one
1
2
236
Chomsky describes my position nicely, even brings up the same analogy of the flat earther I mentioned: piped.video/Ui1vmS9Yz5M
456
after some research with @4ndr3w6S and @jsecurity101 we discovered that netsync still works, and you can also use it to sync trust passwords
2
25
121
17,877
Replying to @m3g9tr0n
Our jobs are certainly safe for the foreseeable future mate 🤣
1
1
517
but it's ok for people to roast men for years for losing their hair (which is much more difficult to reverse btw) piped.video/qdRN6yeM8yY
Replying to @hackerfantastic
from my 2 favourite people to yours
2
Thanks, I did mention that mitigation right at the top of the mitigation section. It's worth noting that this doesn't mitigate then issue, it merely stops low privileged users from being able to create machine accounts, you can still abuse it with control of a user or computer
1
7
Replying to @_nwodtuhs
updated it, didn't add about the ServicePrincipalName because that's not required to change the samaccountname, it's 1 method to potentially obtain the credential but there are many potential ways to do that and TBH this post isn't about that
1
2
Replying to @d3tm4r
This documentary was really poorly made, heavily bias: piped.video/Pki7mOenq_Y
Replying to @HackingDave @d3tm4r
I think this is a great breakdown TBH and love all of @TheBioneer's stuff piped.video/oxzdNeXXRrw
1
Replying to @SteveSyfuhs
That's what I thought, but there's no subsession key. So I guess I understand this and it must be the key I'm trying to decrypt it with (session key in the AP-REQ), but I'm somehow doing the decrpytion incorrectly... :-/
1
Replying to @SteveSyfuhs
The key in the enc-part of the AP-REQ? That's what I've been trying to use, unsuccessfully...
1
@SecurityTube Advert for ST in this lecture given for the OffSec course offered by Florida college last year: piped.video/watch?v=pbWTrF_K…
3
2