user avatar
Andrea P
@decoder_it
Security Consultant @semperistech . Independent Security Researcher. Cyclist & Scubadiver. MSRC MVR 2022. "So di non sapere"
Joined May 2009
Posts
  • user avatar
    We did it again with #LocalPotato! A not-so-common NTLM reflection attack allowing for arbitrary read/write. Basically EoP from user to SYSTEM. Tracked as #CVE-2023-21746 - Windows NTLM EoP Soon more details --> localpotato.com cc @splinter_code
  • user avatar
    When (NTLM) relaying potatoes lead you to domain admin... A "permanent" 0day Privilege Escalation Vulnerability in Windows RPC Protocol ;-) cc @splinter_code Our writeup here: labs.sentinelone.com/relaying-potat…
  • user avatar
    Just uploaded the pdf slides of my talk "whoami /priv" @hackinparis #HIP19
  • user avatar
    #remotepotato0 xsession is finally out! @splinter_code and me released it: github.com/antonioCoco/Re… Coerce and relay NTLM auth from any user in any session w/o session 0! Enjoy responsibly ;)
  • user avatar
  • user avatar
    Hello: I'm your ADCS server and I want to authenticate against you. My latest Post and PoC are out. You can read it here: decoder.cloud/2024/02/26/hel… Enjoy :)
  • user avatar
    M'm glad to release the tool I have been working hard on the last month: #KrbRelayEx A Kerberos relay & forwarder for MiTM attacks! >Relays Kerberos AP-REQ tickets >Manages multiple SMB consoles >Works on Win& Linux with .NET 8.0 >... GitHub: github.com/decoder-it/Krb…
  • user avatar
    We have just released a new version of our #JuicyPotatoNG tool to help red teamers/pentesters. Now you can bruteforce clsid's, find open ports and get interactive console. Check it out here: github.com/antonioCoco/Ju… cc @splinter_code
  • user avatar
    "Hello: I'm your Domain Administrator and I want to authenticate against you". My #SilverPotato is out, check the blog post: decoder.cloud/2024/04/24/hel… 😃
  • user avatar
    Cool finding from my colleague @cj_berlin detailed here: it-pro-berlin.de/2024/07/use-ss…. PS remoting and SSH ignores "Deny Logon restrictions". So if you enable SSHd on a Domain Controller, every domain user can log in... and, for example, perform a #RemotePotato0 attack 😲
  • user avatar
    I have just published this funny post: From iPhone to NT AUTHORITY\SYSTEM :-) decoder.cloud/2019/12/12/fro… cc @padovah4ck
  • user avatar
    From dropbox(updater) to NT AUTHORITY\SYSTEM decoder.cloud/2019/12/18/fro…
  • user avatar
    Is Kerberos relaying so limited? I'd say no, thanks to @tiraniddo CredMarshalTargetInfo trick. In this case, I'm relaying SMB to HTTP (ADCS) with a modified version of @cube0x0 krbrelay using DFSCoerce and PetitPotam - classic ESC8 attack with Kerberos, no DCOM involved ;)
  • user avatar
    Abusing Group Policy Caching