g-laurent.blogspot.com
Laurent Gaffié blog: Apr 8, 2014
http://g-laurent.blogspot.com/2014_04_08_archive.html
This blog reflects my own opinions. Tuesday, April 8, 2014. PCredz was built to extract credentials from large pcap files or from a live interface. Stats on juicy pcap files:. 30 mo pcap file : 15s. 500mo pcap file: 1.5 minutes. 2 Go pcap file: 7 minutes. Extract from a pcap file or from a live interface:. NTLMv1/v2 (DCE-RPC,SMBv1/2,LDAP, MSSQL, HTTP, etc). Kerberos (AS-REQ Pre-Auth etype 2#) hashes. Log all credentials to a file (CredentialDump-Session.log). Os X and other distributions:. ADD / XOR / ROL.
g-laurent.blogspot.com
Laurent Gaffié blog: May 28, 2014
http://g-laurent.blogspot.com/2014_05_28_archive.html
This blog reflects my own opinions. Wednesday, May 28, 2014. Microsoft DHCP INFORM Configuration Overwrite. Title: Microsoft DHCP INFORM Configuration Overwrite. Issue type: Protocol Security Flaw. Discovered by: Laurent Gaffié. Advisory by: Laurent Gaffié. Issue status: Patch not available. A vulnerability in Windows DHCP ( http:/ www.ietf.org/rfc/. Was found on Windows OS versions. Ranging from Windows 2000 through to Windows server 2003. This vulnerability allows an attacker to remotely. Set a DWORD r...
g-laurent.blogspot.com
Laurent Gaffié blog: Jan 5, 2014
http://g-laurent.blogspot.com/2014_01_05_archive.html
This blog reflects my own opinions. Sunday, January 5, 2014. Thoughts on NSA and our future. NSA recent disclosures, makes the paranoid not so paranoid after all. We confirmed, that they will listen on your call, your internet session, etc, particularly if you're a foreigner; me and you. The whole current B.S is about "So what you're doing, is U.S constitutionally compliant? What will happens after restriction applies (if it does) :. Oaths of office are a statement of loyalty to a constitution. If you ex...
g-laurent.blogspot.com
Laurent Gaffié blog: Breaking MSFT Kerberos With Responder
http://g-laurent.blogspot.com/2014/04/breaking-msft-kerberos-with-responder.html
This blog reflects my own opinions. Wednesday, April 9, 2014. Breaking MSFT Kerberos With Responder. I've been working on a way to get MS Kerberos v5 hashes via the Browser protocol automatically with no user interaction on a given network. Click on the pics if they don't display correctly). Often you see these requests in wireshark on an internal penetration test:. So I came up with a tool that automates kerberos' connection for these:. Which shows up like this in Wireshark:. April 11, 2014 at 12:43 AM.
g-laurent.blogspot.com
Laurent Gaffié blog: Introducing PCredz
http://g-laurent.blogspot.com/2014/04/introducing-pcredz.html
This blog reflects my own opinions. Tuesday, April 8, 2014. PCredz was built to extract credentials from large pcap files or from a live interface. Stats on juicy pcap files:. 30 mo pcap file : 15s. 500mo pcap file: 1.5 minutes. 2 Go pcap file: 7 minutes. Extract from a pcap file or from a live interface:. NTLMv1/v2 (DCE-RPC,SMBv1/2,LDAP, MSSQL, HTTP, etc). Kerberos (AS-REQ Pre-Auth etype 2#) hashes. Log all credentials to a file (CredentialDump-Session.log). Os X and other distributions:. ADD / XOR / ROL.
g-laurent.blogspot.com
Laurent Gaffié blog: Jan 24, 2013
http://g-laurent.blogspot.com/2013_01_24_archive.html
This blog reflects my own opinions. Thursday, January 24, 2013. Owning Windows Networks with Responder 1.7. Full post and download link can be found here :. Http:/ blog.spiderlabs.com/2013/01/owning-windows-networks-with-responder-17.html. Posted by Laurent Gaffié blog. Subscribe to: Posts (Atom). Owning Windows Networks with Responder 1.7. Vulnerability Spotlight: Multiple Remote Code Execution Vulnerabilities Within Lexmark Perceptive Document Filters. ADD / XOR / ROL. An attempt at fixing Wassenaar.
g-laurent.blogspot.com
Laurent Gaffié blog: Microsoft DHCP INFORM Configuration Overwrite
http://g-laurent.blogspot.com/2014/05/microsoft-dhcp-inform-configuration.html
This blog reflects my own opinions. Wednesday, May 28, 2014. Microsoft DHCP INFORM Configuration Overwrite. Title: Microsoft DHCP INFORM Configuration Overwrite. Issue type: Protocol Security Flaw. Discovered by: Laurent Gaffié. Advisory by: Laurent Gaffié. Issue status: Patch not available. A vulnerability in Windows DHCP ( http:/ www.ietf.org/rfc/. Was found on Windows OS versions. Ranging from Windows 2000 through to Windows server 2003. This vulnerability allows an attacker to remotely. Set a DWORD r...
g-laurent.blogspot.com
Laurent Gaffié blog: Jun 7, 2014
http://g-laurent.blogspot.com/2014_06_07_archive.html
This blog reflects my own opinions. Saturday, June 7, 2014. Pcredz was designed to dump useful information on the fly, from a pcap file or from a pcap directory. Unlike tools like, for example Breachprobe, Pcredz is highly effective and fast just to meet your pentest needs. What Pcredz does right now from a live interface or pcap file:. Identify Card Holder Data (CHD) on any port. Dump NTLMv1/v2 (DCE-RPC,SMBv1/2,LDAP,MSSQL,. HTTP,etc) hashes on any protocol and port. Dump HTTP Basic (any port).
g-laurent.blogspot.com
Laurent Gaffié blog: More on PCredz..
http://g-laurent.blogspot.com/2014/06/more-on-pcredz.html
This blog reflects my own opinions. Saturday, June 7, 2014. Pcredz was designed to dump useful information on the fly, from a pcap file or from a pcap directory. Unlike tools like, for example Breachprobe, Pcredz is highly effective and fast just to meet your pentest needs. What Pcredz does right now from a live interface or pcap file:. Identify Card Holder Data (CHD) on any port. Dump NTLMv1/v2 (DCE-RPC,SMBv1/2,LDAP,MSSQL,. HTTP,etc) hashes on any protocol and port. Dump HTTP Basic (any port).
g-laurent.blogspot.com
Laurent Gaffié blog: Dec 30, 2013
http://g-laurent.blogspot.com/2013_12_30_archive.html
This blog reflects my own opinions. Monday, December 30, 2013. Responder 2.0 is out. A quick blog post to let you know that Responder 2.0 Beta is out:. This version includes several new rogue auth servers, SMB Relay and much much more. If you enjoy internal pentests, stay tuned on http:/ blog.spiderlabs.com, a complete blog post will be detailing all new functionalities and some actual Responder wushu. Happy new year all. Posted by Laurent Gaffié blog. Subscribe to: Posts (Atom). Responder 2.0 is out.