For Pentesters and CTF players, here’s a list of useful payloads and bypasses, covering various WebApp attacks.

There are a lot of similar GitHub repos out there. What’s your personal favorite?


Windows Event ID 4624 displays a numerical value for the type of login that was attempted. These numbers are important from a forensic standpoint but also for understanding credential exposure and mitigating risks. Descriptions in replies.

~=8 Character Passwords Are Dead=~

New benchmark means that the entire keyspace, or every possible combination of:
- Upper
- Lower
- Number
- Symbol

...of an 8 character password can be guessed in:

~2.5 hours

(8x 2080 GPUs against NTLM Windows hash)

"Pwning WPA/WPA2 Networks With Bettercap and the PMKID Client-Less Attack "

Solid writeup for his tool (bettercap) @evilsocket@twitter.com.
Still need a big cracking ring to be interesting.


New release: a Python script to catch careless intruders on your machines by "booby-trapping" binaries. github.com/JusticeRage/freedom

Synacktiv is hiring! We are looking for a sysadmin, a commercial as well as pentesters, reversers and developers. We also have internship positions (documents in French): synacktiv.com/en/company.html#

Hello tout le monde, on se retrouve pour le prochain meet le 22 Février à partir de 18h30 (Paris intra-muros).

Comme d'habitude, le lieu sera communiqué sous peu, merci de vous inscrire pour prendre en compte le nombre de personnes 😀


Wondering about Android and Apple phone security? Here's an objective chart to help you decide:

Privilege escalation on UFED touch, auxiliary is Admin and using a shared password. Shows how Operator can escalate privilege to Administrator and interfere with the unit.

