Monday, April 1, 2019

Commando VM - The First of Its Kind Windows Offensive Distribution



Welcome to CommandoVM - a fully customized, Windows-based security distribution for penetration testing and red teaming.

Using HTTP Pipelining to hide requests

Image result for http bad request

In this post I'm going to discuss using HTTP pipelining to hide malicious HTTP requests. This is not domain fronting but uses similar techniques to get the same result, an observer who is not able to perform TLS interception is only able to see the "good" request which conceals the "bad" request.

Osmedeus - Fully Automated Offensive Security Tool For Reconnaissance And Vulnerability Scanning

Osmedeus allow you automated run the collection of awesome tools to  reconnaissance  and  vulnerability scanning  against the target.