Uploaded December 2023 | Updated September 2026, 2 weeks ago
00:00 - Introduction
01:00 - Start of nmap
03:30 - Exploring the file share
07:15 - Finding Encrypter.exe, which is a dotnet encrypter. Discovering the seed is based upon time, modifying it to decrypt using metadata from the encrypted file to get the seed.
15:30 - The encrypted file was a Keepass Database, looking into it and seeing credentials and a uthenticator backup
19:45 - Installing the "Authenticator" app and seeing the backup format is the same
21:30 - Explaining why we want to just bruteforce AES vs Argon2id
25:50 - Creating a program in javascript to bruteforce the AES by decrypting and examining the contents of what was decrypted
40:40 - Cracking program done, then logging into TeamCity
45:45 - We can't modify the files on TeamCity but we can use the personal build, supply a dif and get it to execute code that way
49:50 - Defender blocked nishang reverse shell, doing some quick obfuscation to bypass defender and get a shell
55:50 - Discovering Teamcity keeps track of personal builds, looking at old ones and discovering powershell credentials. Decrypting the Secure String to get e.black's password
1:08:00 - Running the bloodhound python collector in a Docker
1:17:40 - Writing a bloodhound query to show Organization Units in active directory, then using Get-ACL to see unique privileges to each OU
1:24:15 - Explaining the attack path, e.blake can manipulate ADCS, s.blade can add machines to a specific OU. We can create a vulnerable ADCS Template and exploit this with Certifried
1:31:30 - Creating and publishing the Vulnerable Certificate. Cloning computer, then modifying msPKI-Enrollment-Flag
1:53:30 - Doing an easier vulnerable template, to make this box vulnerable to ESC1. Set msPKI-Enrollment-Flag, msPKI-Certificate-Name-Flag,
00:00 - Introduction
01:00 - Start of nmap
03:30 - Exploring the file share
07:15 - Finding Encrypter.exe, which is a dotnet encrypter. Discovering the seed is based upon time, modifying it to decrypt using metadata from the encrypted file to get the seed.
15:30 - The encrypted file was a Keepass Database, looking into it and seeing credentials and a uthenticator backup
19:45 - Installing the "Authenticator" app and seeing the backup format is the same
21:30 - Explaining why we want to just bruteforce AES vs Argon2id
25:50 - Creating a program in javascript to bruteforce the AES by decrypting and examining the contents of what was decrypted
40:40 - Cracking program done, then logging into TeamCity
45:45 - We can't modify the files on TeamCity but we can use the personal build, supply a dif and get it to execute code that way
49:50 - Defender blocked nishang reverse shell, doing some quick obfuscation to bypass defender and get a shell
55:50 - Discovering Teamcity keeps track of personal builds, looking at old ones and discovering powershell credentials. Decrypting the Secure String to get e.black's password
1:08:00 - Running the bloodhound python collector in a Docker
1:17:40 - Writing a bloodhound query to show Organization Units in active directory, then using Get-ACL to see unique privileges to each OU
1:24:15 - Explaining the attack path, e.blake can manipulate ADCS, s.blade can add machines to a specific OU. We can create a vulnerable ADCS Template and exploit this with Certifried
1:31:30 - Creating and publishing the Vulnerable Certificate. Cloning computer, then modifying msPKI-Enrollment-Flag
1:53:30 - Doing an easier vulnerable template, to make this box vulnerable to ESC1. Set msPKI-Enrollment-Flag, msPKI-Certificate-Name-Flag,










![Intercepting Android App Traffic with BurpSuite
00:00 - Introduction, talking about RouterSpace and why we cant just do what we did in that video
01:25 - Installing Genymotion, Virtual Box, and ADB; while talking about why I dont use Android Studio/AVD. Simply because genymotion just works.
02:05 - Make sure you upgrade your memory, processors, and enable Virtualization in your VM Settings!
02:30 - Running Genymotion and starting a Pixel 3 XL
03:37 - Converting BurpSuites Certificate to PEM Format with openssl x509 -inform der -in [name of cert] -out burp.pem
04:20 - Renaming the certificate to 9a5ba575.0, and showing how we got that name
06:00 - Starting the device and showing the certificate authorities
07:00 - Copying the certificate to /system/etc/security/cacerts/, and showing how to remount to rw
08:10 - Showing how to set the proxy through both the GUI and via ADB
09:50 - Installing GAPPS
10:30 - Showing how to unset the proxy from ADB
11:00 - Creating an alias to set and unset the proxy via adb
12:00 - Opening the google play store and logging in and install Wayzn to see if we can intercept traffic
15:20 - Showing we intercepted traffic from Wayzn, then installing Instagram
16:50 - Attempting to login to instagram and getting an error message
17:20 - Setting up Frida both on our computer and android device
19:20 - Showing Frida is working, getting ps output from the android device
19:55 - Downloading the instragram ssl pinning bypass script
21:20 - Using frida to start instagram and loading the script to bypass the SSL Checking
22:15 - Setting the proxy and showing us intercept instagram traffic Intercepting Android App Traffic with BurpSuite](https://i.ytimg.com/vi/xp8ufidc514/mqdefault.jpg)