![Pierre Milioni Profile](https://pbs.twimg.com/profile_images/1064217922481082368/NFqOTJam_x96.jpg)
Pierre Milioni
@b1two_
Followers
263
Following
604
Statuses
68
Joined November 2018
RT @Synacktiv: In our latest article, @croco_byte proposes an implementation of a trick discovered by James Forshaw in his research. Discov…
0
100
0
RT @Synacktiv: A few months ago, Microsoft released a critical patch for CVE-2024-43468, an unauthenticated SQL injection vulnerability in…
0
63
0
RT @Synacktiv: We really love relaying authentication: you can now also perform NTLM relaying on SCCM Management and Distribution points th…
0
39
0
Thrilled to see it merged! Note: some tools may not integrate well (without tweaks) with ntlmrelayx due to, for instance, concurrent LDAP connections, SMB queries before LDAP communications, or starttls. Check this PR comment for details and workarounds:
You can now use LDAP/LDAPs protocols with the SOCKS proxy of ntlmrelayx thanks to the PR from @b1two_ (now merged upstream). Here is an example with ldeep using relayed authentication from HTTP to LDAPs :
1
10
39
RT @Synacktiv: GitLab recently released a patch for the Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409). Our ninjas @alexisdaniza…
0
34
0
RT @Synacktiv: We just rewrote the AsOutsider part of #AADInternals in Python to enhance compatibility and ease of use in Linux environment…
0
42
0
RT @Synacktiv: Want to know how we prevented some CI/CD supply chain attacks against Microsoft, FreeRDP, AutoGPT, Ant-Design, Cypress, Exca…
0
28
0
RT @hugow_vincent: I've converted my @sstic talk on #GitHub action exploitation to a series of blogspots with additional details, here is t…
0
7
0
RT @Synacktiv: In his latest blogpost, @yaumn_ analyzes MDI's detection of PKINIT authentication, explains how to bypass it and releases In…
0
48
0
RT @GrehackConf: Hey folks, We're back, with a great new logo that's right up there with the weather ❄️🥶 And save the date: this year #G…
0
18
0
RT @Synacktiv: Bored of managing multiple proxychains configurations? @hugoclout developed bbs, a swiss army knife proxy manager for red te…
0
41
0
RT @Synacktiv: Our ninjas, @myr463 and @b1two_, have uncovered various vulnerabilities in Peplink Balance Two devices, including command in…
0
13
0
RT @mariuszbit: ☢️ClickOnce + AppDomain Manager Injection (aka signed EXE + DLL sideloading) is the new Initial Access Hotness❤️ Check out…
0
126
0
RT @hexacon_fr: Last sponsor we want to introduce is a special one: it's @Synacktiv, the company organizing #HEXACON2023. Leader in offen…
0
55
0