SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							791df64dfe
							
						
					 | 
					
						
						
							
							Merge pull request #1342 from HackTricks-wiki/update_ZipLine_Campaign__A_Sophisticated_Phishing_Attack__20250826_183503
						
						
						
						
						
						
						
						ZipLine Campaign A Sophisticated Phishing Attack Targeting U... 
						
						
					 | 
					
						2025-08-29 00:02:10 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							e5e30fa2f0
							
						
					 | 
					
						
						
							
							Merge pull request #1343 from HackTricks-wiki/update_GhostPack_Certify__Abusing_Active_Directory_Certif_20250827_012301
						
						
						
						
						
						
						
						GhostPack/Certify Abusing Active Directory Certificate Servi... 
						
						
					 | 
					
						2025-08-29 00:02:02 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							4d52d6a76e
							
						
					 | 
					
						
						
							
							Merge pull request #1344 from HackTricks-wiki/research_update_src_windows-hardening_windows-local-privilege-escalation_roguepotato-and-printspoofer_20250827_012537
						
						
						
						
						
						
						
						Research Update Enhanced src/windows-hardening/windows-local... 
						
						
					 | 
					
						2025-08-28 22:02:25 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							9040f9c367
							
						
					 | 
					
						
						
							
							Merge pull request #1349 from HackTricks-wiki/update_HTB__Rainbow_20250827_150727
						
						
						
						
						
						
						
						HTB Rainbow 
						
						
					 | 
					
						2025-08-28 22:02:12 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							adb6272876
							
						
					 | 
					
						
						
							
							Merge pull request #1345 from HackTricks-wiki/update_From__Low-Impact__RXSS_to_Credential_Stealer__A_JS_20250827_063121
						
						
						
						
						
						
						
						From "Low-Impact" RXSS to Credential Stealer A JS-in-JS Walk... 
						
						
					 | 
					
						2025-08-28 20:02:18 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							daa8503656
							
						
					 | 
					
						
						
							
							Merge pull request #1350 from HackTricks-wiki/update_HTB_Zero___htaccess_ErrorDocument_LFI___credential_20250827_152245
						
						
						
						
						
						
						
						HTB Zero .htaccess ErrorDocument LFI → credential reuse → ro... 
						
						
					 | 
					
						2025-08-28 20:02:06 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							5b4eb853a1
							
						
					 | 
					
						
						
							
							Merge pull request #1346 from HackTricks-wiki/research_update_src_binary-exploitation_libc-heap_unsorted-bin-attack_20250827_082545
						
						
						
						
						
						
						
						Research Update Enhanced src/binary-exploitation/libc-heap/u... 
						
						
					 | 
					
						2025-08-28 18:02:31 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							89269d07ae
							
						
					 | 
					
						
						
							
							Merge pull request #1354 from HackTricks-wiki/update_HTB_Reaper__Format-string_leak___stack_BOF___Virtu_20250827_170453
						
						
						
						
						
						
						
						HTB Reaper Format-string leak + stack BOF → VirtualAlloc ROP... 
						
						
					 | 
					
						2025-08-28 18:02:10 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							dde1258022
							
						
					 | 
					
						
						
							
							Merge pull request #1347 from HackTricks-wiki/update_Start_hacking_Bluetooth_Low_Energy_today___part_2__20250827_124037
						
						
						
						
						
						
						
						Start hacking Bluetooth Low Energy today! (part 2) 
						
						
					 | 
					
						2025-08-28 16:02:31 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							acbc6203ee
							
						
					 | 
					
						
						
							
							Merge pull request #1360 from HackTricks-wiki/update_HTB_Nocturnal__IDOR___Command_Injection___Root_via_20250827_191622
						
						
						
						
						
						
						
						HTB Nocturnal IDOR → Command Injection → Root via ISPConfig ... 
						
						
					 | 
					
						2025-08-28 16:02:10 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								carlospolop
							
						 
					 | 
					
						
						
						
						
							
						
						
							4c7d69faac
							
						
					 | 
					
						
						
							
							Merge branch 'master' of github.com:HackTricks-wiki/hacktricks
						
						
						
						
						
						
					 | 
					
						2025-08-28 13:55:03 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								carlospolop
							
						 
					 | 
					
						
						
						
						
							
						
						
							ebfa5c6be1
							
						
					 | 
					
						
						
							
							Merge branch 'master' of github.com:HackTricks-wiki/hacktricks
						
						
						
						
						
						
					 | 
					
						2025-08-28 13:44:18 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							ff4d1db05b
							
						
					 | 
					
						
						
							
							Update command-injection.md
						
						
						
						
						
						
					 | 
					
						2025-08-28 12:05:50 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							596fcf3bc6
							
						
					 | 
					
						
						
							
							Merge pull request #1356 from HackTricks-wiki/update_HTB__Sweep___Abusing_Lansweeper_Scanning__AD_ACLs__20250827_180612
						
						
						
						
						
						
						
						HTB Sweep — Abusing Lansweeper Scanning, AD ACLs, and Secret... 
						
						
					 | 
					
						2025-08-28 12:02:13 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							f660c8dcb6
							
						
					 | 
					
						
						
							
							Merge pull request #1359 from HackTricks-wiki/update_University__HTB___Exploiting_ReportLab_CVE_2023_33_20250827_184924
						
						
						
						
						
						
						
						University (HTB) Exploiting ReportLab CVE‑2023‑33733 to gain... 
						
						
					 | 
					
						2025-08-28 12:02:06 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							08b6739e17
							
						
					 | 
					
						
						
							
							Update README.md
						
						
						
						
						
						
					 | 
					
						2025-08-28 11:50:29 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							ece2294b21
							
						
					 | 
					
						
						
							
							Update README.md
						
						
						
						
						
						
					 | 
					
						2025-08-28 11:49:38 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								carlospolop
							
						 
					 | 
					
						
						
						
						
							
						
						
							093bac3bad
							
						
					 | 
					
						
						
							
							f
						
						
						
						
						
						
					 | 
					
						2025-08-28 11:44:38 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							1ca12267e8
							
						
					 | 
					
						
						
							
							Update unsorted-bin-attack.md
						
						
						
						
						
						
					 | 
					
						2025-08-28 11:39:47 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							4992be72a2
							
						
					 | 
					
						
						
							
							Update roguepotato-and-printspoofer.md
						
						
						
						
						
						
					 | 
					
						2025-08-28 11:26:20 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							399a99eefa
							
						
					 | 
					
						
						
							
							Add content from: HTB Nocturnal: IDOR → Command Injection → Root via ISPConfig...
						
						
						
						
						
						
						
						- Remove searchindex.js (auto-generated file) 
						
						
					 | 
					
						2025-08-27 19:21:10 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							fdb533d0f7
							
						
					 | 
					
						
						
							
							Add content from: University (HTB): Exploiting ReportLab CVE‑2023‑33733 to gai...
						
						
						
						
						
						
						
						- Remove searchindex.js (auto-generated file) 
						
						
					 | 
					
						2025-08-27 18:54:18 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							b3dab58dcb
							
						
					 | 
					
						
						
							
							Add content from: HTB: Sweep — Abusing Lansweeper Scanning, AD ACLs, and Secre...
						
						
						
						
						
						
						
						- Remove searchindex.js (auto-generated file) 
						
						
					 | 
					
						2025-08-27 18:10:58 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							2e78574fc1
							
						
					 | 
					
						
						
							
							Add content from: HTB Reaper: Format-string leak + stack BOF → VirtualAlloc RO...
						
						
						
						
						
						
						
						- Remove searchindex.js (auto-generated file) 
						
						
					 | 
					
						2025-08-27 17:11:32 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							8a3275fb2b
							
						
					 | 
					
						
						
							
							Add content from: HTB Zero: .htaccess ErrorDocument LFI → credential reuse → r...
						
						
						
						
						
						
						
						- Remove searchindex.js (auto-generated file) 
						
						
					 | 
					
						2025-08-27 15:29:12 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							b3881abe2d
							
						
					 | 
					
						
						
							
							Add content from: HTB: Rainbow
						
						
						
						
						
						
						
						- Remove searchindex.js (auto-generated file) 
						
						
					 | 
					
						2025-08-27 15:12:01 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							4501b98594
							
						
					 | 
					
						
						
							
							Add content from: Start hacking Bluetooth Low Energy today! (part 2)
						
						
						
						
						
						
					 | 
					
						2025-08-27 12:43:40 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							3c0908f8eb
							
						
					 | 
					
						
						
							
							Add content from: Research Update: Enhanced src/binary-exploitation/libc-heap/...
						
						
						
						
						
						
					 | 
					
						2025-08-27 08:30:10 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							e43a1147c1
							
						
					 | 
					
						
						
							
							Add content from: From "Low-Impact" RXSS to Credential Stealer: A JS-in-JS Wal...
						
						
						
						
						
						
					 | 
					
						2025-08-27 06:35:05 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							7b609aef63
							
						
					 | 
					
						
						
							
							Merge pull request #1332 from HackTricks-wiki/research_update_src_mobile-pentesting_android-app-pentesting_insecure-in-app-update-rce_20250825_013931
						
						
						
						
						
						
						
						Research Update Enhanced src/mobile-pentesting/android-app-p... 
						
						
					 | 
					
						2025-08-27 06:02:03 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							3e51e24fbb
							
						
					 | 
					
						
						
							
							Merge pull request #1333 from HackTricks-wiki/research_update_src_binary-exploitation_stack-overflow_ret2win_ret2win-arm64_20250825_082821
						
						
						
						
						
						
						
						Research Update Enhanced src/binary-exploitation/stack-overf... 
						
						
					 | 
					
						2025-08-27 04:28:22 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							e3c5f26a1a
							
						
					 | 
					
						
						
							
							Add content from: Research Update: Enhanced src/windows-hardening/windows-loca...
						
						
						
						
						
						
					 | 
					
						2025-08-27 01:29:39 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							74a1ba247c
							
						
					 | 
					
						
						
							
							Add content from: GhostPack/Certify: Abusing Active Directory Certificate Serv...
						
						
						
						
						
						
					 | 
					
						2025-08-27 01:26:07 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							365e44e13e
							
						
					 | 
					
						
						
							
							Merge pull request #1334 from HackTricks-wiki/update_Countering_EDRs_With_The_Backing_Of_Protected_Proc_20250825_123951
						
						
						
						
						
						
						
						Countering EDRs With The Backing Of Protected Process Light ... 
						
						
					 | 
					
						2025-08-27 02:05:24 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							f28318eeaa
							
						
					 | 
					
						
						
							
							Merge pull request #1335 from HackTricks-wiki/update_CreateProcessAsPPL__launch_a_Windows_Protected_Pro_20250825_124827
						
						
						
						
						
						
						
						CreateProcessAsPPL launch a Windows Protected Process Light 
						
						
					 | 
					
						2025-08-27 00:01:53 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							93b11a0c65
							
						
					 | 
					
						
						
							
							Merge pull request #1336 from HackTricks-wiki/update_ELEGANTBOUNCER__When_You_Can_t_Get_the_Samples_but_20250825_125341
						
						
						
						
						
						
						
						ELEGANTBOUNCER When You Can't Get the Samples but Still Need... 
						
						
					 | 
					
						2025-08-26 22:02:01 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							d81ff58ade
							
						
					 | 
					
						
						
							
							Add content from: ZipLine Campaign: A Sophisticated Phishing Attack Targeting ...
						
						
						
						
						
						
					 | 
					
						2025-08-26 18:39:45 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							dd01833124
							
						
					 | 
					
						
						
							
							Merge pull request #1337 from HackTricks-wiki/update_SpearSpray___Pattern-driven__Kerberos-based_AD_pas_20250825_182847
						
						
						
						
						
						
						
						SpearSpray — Pattern-driven, Kerberos-based AD password spra... 
						
						
					 | 
					
						2025-08-26 20:02:10 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							7210f6a397
							
						
					 | 
					
						
						
							
							Merge pull request #1330 from HackTricks-wiki/research_update_src_macos-hardening_macos-security-and-privilege-escalation_macos-proces-abuse_macos-dirty-nib_20250824_082236
						
						
						
						
						
						
						
						Research Update Enhanced src/macos-hardening/macos-security-... 
						
						
					 | 
					
						2025-08-26 18:02:32 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							7eb24f3148
							
						
					 | 
					
						
						
							
							Merge pull request #1340 from HackTricks-wiki/update_VTENEXT_25_02___a_three-way_path_to_RCE_20250826_125221
						
						
						
						
						
						
						
						VTENEXT 25.02 – a three-way path to RCE 
						
						
					 | 
					
						2025-08-26 18:02:02 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							9a09f24243
							
						
					 | 
					
						
						
							
							Merge pull request #1328 from HackTricks-wiki/research_update_src_macos-hardening_macos-security-and-privilege-escalation_macos-apps-inspecting-debugging-and-fuzzing_objects-in-memory_20250823_082246
						
						
						
						
						
						
						
						Research Update Enhanced src/macos-hardening/macos-security-... 
						
						
					 | 
					
						2025-08-26 16:50:36 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							bc1ada9454
							
						
					 | 
					
						
						
							
							Merge pull request #1327 from HackTricks-wiki/research_update_src_network-services-pentesting_pentesting-web_ruby-tricks_20250823_012514
						
						
						
						
						
						
						
						Research Update Enhanced src/network-services-pentesting/pen... 
						
						
					 | 
					
						2025-08-26 16:49:16 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							7d05801e3f
							
						
					 | 
					
						
						
							
							Add content from: VTENEXT 25.02 – a three-way path to RCE
						
						
						
						
						
						
					 | 
					
						2025-08-26 12:57:50 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							9aab3fb444
							
						
					 | 
					
						
						
							
							Add content from: SpearSpray — Pattern-driven, Kerberos-based AD password spra...
						
						
						
						
						
						
					 | 
					
						2025-08-25 18:31:41 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							c01eee5608
							
						
					 | 
					
						
						
							
							Add content from: ELEGANTBOUNCER: When You Can't Get the Samples but Still Nee...
						
						
						
						
						
						
					 | 
					
						2025-08-25 12:57:14 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							6f51e788c2
							
						
					 | 
					
						
						
							
							Add content from: CreateProcessAsPPL: launch a Windows Protected Process Light
						
						
						
						
						
						
					 | 
					
						2025-08-25 12:53:05 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							a6041dcc93
							
						
					 | 
					
						
						
							
							Add content from: Countering EDRs With The Backing Of Protected Process Light ...
						
						
						
						
						
						
					 | 
					
						2025-08-25 12:48:06 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							214aabcdde
							
						
					 | 
					
						
						
							
							Add content from: Research Update: Enhanced src/binary-exploitation/stack-over...
						
						
						
						
						
						
					 | 
					
						2025-08-25 08:31:21 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							1679a66713
							
						
					 | 
					
						
						
							
							Add content from: Research Update: Enhanced src/mobile-pentesting/android-app-...
						
						
						
						
						
						
					 | 
					
						2025-08-25 01:42:18 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							2c09db2658
							
						
					 | 
					
						
						
							
							Merge pull request #1326 from HackTricks-wiki/update_Hosting_security_tested__87_8__of_vulnerability_ex_20250822_124121
						
						
						
						
						
						
						
						Hosting security tested 87.8% of vulnerability exploits bypa... 
						
						
					 | 
					
						2025-08-24 14:02:06 +02:00 | 
					
					
						
						
							
							
							
						
					 |