Infosec.Pub
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
digicatM to blueteamsecEnglish · 6 days ago

ClickExfil: My iteration on ClickFix and FileFix

catchingphish.com

external-link
message-square
0
link
fedilink
2
external-link

ClickExfil: My iteration on ClickFix and FileFix

catchingphish.com

digicatM to blueteamsecEnglish · 6 days ago
message-square
0
link
fedilink
*The concepts discussed in this blog are for Red Team purposes only* I remain in awe of ClickFix’s ingenuity. It has become a fruitful source for initial access and continues a broader trend of relying less on zero-days and focusing on the victim as the weakest point. FileFix was a unique iteration that got me thinking about utilising the file browser. I started thinking backwards: the end goal of most attacks is exfiltration of some kind, whether that’s credentials or intellectual property. Why convince users to download and execute malicious scripts when you can simply ask them to run a command?
alert-triangle
You must log in or # to comment.

blueteamsec

blueteamsec

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !blueteamsec@infosec.pub

For [Blue|Purple] Teams in Cyber Defence - covering discovery, detection, response, threat intelligence, malware, offensive tradecraft and tooling, deception, reverse engineering etc.

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 23 users / day
  • 114 users / week
  • 320 users / month
  • 1.03K users / 6 months
  • 252 local subscribers
  • 792 subscribers
  • 4.66K Posts
  • 350 Comments
  • Modlog
  • mods:
  • digicat
  • UI: 0.19.19
  • BE: 0.19.19-jemalloc
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org