News

Comprendiendo ADCS 101

Understanding ADCS 101

Celia Catalán

In this publication we will be discussing the basic aspects of ADCS, as well as the ESC1 exploitation technique. Introduction to ADCS Active Directory Certificate Services (ADCS) is a role...

Understanding ADCS 101

Celia Catalán

In this publication we will be discussing the basic aspects of ADCS, as well as the ESC1 exploitation technique. Introduction to ADCS Active Directory Certificate Services (ADCS) is a role...

CVE-2024-28995 – SolarWinds Serv-U Path Traversal

CVE-2024-28995 – SolarWinds Serv-U Path Traversal

Celia Catalán

Continuing with the saga of the CVEs of this 2024, today we have CVE-2024-28995.  The SolarWinds IT management platform reported a vulnerability in its server on June 5...

CVE-2024-28995 – SolarWinds Serv-U Path Traversal

Celia Catalán

Continuing with the saga of the CVEs of this 2024, today we have CVE-2024-28995.  The SolarWinds IT management platform reported a vulnerability in its server on June 5...

Alternativas a BurpSuite - Caido Web Proxy

Alternatives to BurpSuite - Caido Web Proxy

Celia Catalán

When carrying out web audits we always tend to think of BurpSuite, which is the tool par excellence, but have you ever thought about other alternatives?  We know that if...

Alternatives to BurpSuite - Caido Web Proxy

Celia Catalán

When carrying out web audits we always tend to think of BurpSuite, which is the tool par excellence, but have you ever thought about other alternatives?  We know that if...

Las Autoridades Europeas de Supervisión (AES) acaban de lanzar el segundo paquete RTS bajo DORA.

The European Supervisory Authorities (ESA) have...

Celia Catalán

On December 27, 2022, two different, but closely linked, regulations related to cybersecurity were published in the Official Journal of the European Union. They came into force 20 days...

The European Supervisory Authorities (ESA) have...

Celia Catalán

On December 27, 2022, two different, but closely linked, regulations related to cybersecurity were published in the Official Journal of the European Union. They came into force 20 days...

NTLMv1 Downgrade attack

NTLMv1 Downgrade attack

Celia Catalán

NetNTLMv1 downgrade  As we have commented in previous posts, after forcing authentication and obtaining the NetNTLM hash of the password of the victim's machine user, we are mainly presented with...

NTLMv1 Downgrade attack

Celia Catalán

NetNTLMv1 downgrade  As we have commented in previous posts, after forcing authentication and obtaining the NetNTLM hash of the password of the victim's machine user, we are mainly presented with...

¿Por qué se han caído los servicios de medio mundo tras un fallo de Crowdstrike?

Why have half the world's services fallen after...

Juan Antonio Calles

Today, July 19, 2024, many companies globally have encountered the well-known "Blue Screen of Death" (BSOD) in their systems. This failure has forced many companies to discontinue their...

Why have half the world's services fallen after...

Juan Antonio Calles

Today, July 19, 2024, many companies globally have encountered the well-known "Blue Screen of Death" (BSOD) in their systems. This failure has forced many companies to discontinue their...