Skip to content

Instantly share code, notes, and snippets.

@trash-rabbit
trash-rabbit / config.zsh
Created September 3, 2023 14:27 — forked from acamino/README.md
Shortcuts to Improve Your Bash & Zsh Productivity
bindkey -e
bindkey \^u backward-kill-line
@trash-rabbit
trash-rabbit / ws.harness.py
Created December 28, 2022 14:32 — forked from mfowl/ws.harness.py
Web Socket Harness
#!/usr/bin/python
import socket,ssl
from BaseHTTPServer import BaseHTTPRequestHandler,HTTPServer
from websocket import create_connection, WebSocket
from urlparse import parse_qs
import argparse
import os
LOOP_BACK_PORT_NUMBER = 8000
@trash-rabbit
trash-rabbit / certifried_with_krbrelayup.md
Created December 27, 2022 17:09 — forked from tothi/certifried_with_krbrelayup.md
Certifried combined with KrbRelayUp: non-privileged domain user to Domain Admin without adding/pre-owning computer accounts

Certifried combined with KrbRelayUp

Certifried (CVE-2022-26923) gives Domain Admin from non-privileged user with the requirement adding computer accounts or owning a computer account. Kerberos Relay targeting LDAP and Shadow Credentials gives a non-privileged domain user on a domain-joined machine local admin access on (aka owning) the machine. Combination of these two: non-privileged domain user escalating to Domain Admin without the requirement adding/owning computer accounts.

The attack below uses only Windows (no Linux tools interacting with the Domain), simulating a real-world attack scenario.

Prerequisites:

@trash-rabbit
trash-rabbit / pedantically_commented_playbook.yml
Created March 12, 2017 15:25 — forked from marktheunissen/pedantically_commented_playbook.yml
Insanely complete Ansible playbook, showing off all the options
---
# ^^^ YAML documents must begin with the document separator "---"
#
#### Example docblock, I like to put a descriptive comment at the top of my
#### playbooks.
#
# Overview: Playbook to bootstrap a new host for configuration management.
# Applies to: production
# Description:
# Ensures that a host is configured for management with Ansible.