Redforce Always Stay Ahead!

  • Home
  • Categories
    • Web Security
    • Mobile pentest
  • About us
    • About us
    • Our team
  • Our services

Get in!

Share stories that are meaningful to you
and connect with your audiences.

Click to sign in/sign up

Categories

  • Active directory
  • Mobile Penetration Testing
  • Red teaming
  • Web Security

Recent Posts

  • Windows authentication attacks part 2 – kerberos
  • Windows authentication attacks – part 1
  • Attacking HelpDesks Part 1: RCE Chain on DeskPro, with Bitdefender as a Case Study
  • Oh, My Kerberos! Do Not Get Kerberoasted!
  • Comma is forbidden! No worries!! Inject in insert/update queries without it

Archives

  • April 2020
  • March 2020
  • April 2019
  • March 2019
  • February 2019

Recent Comments

    Windows authentication attacks part 2 - kerberos

    Windows authentication attacks part 2 – kerberos

    Kerberos authentication is one of the cores of the AD, knowing how it works facilitates the deep understanding of many attacks.

    Active directory Red teaming   •   April 28, 2020   •   84 min read
    Windows authentication attacks - part 1

    Windows authentication attacks – part 1

    In order to understand attacks such as Pass the hash, relaying, Kerberos attacks, one should have pretty good knowledge about the windows Authentication / Authorization process.
    That’s what we’re going to achieve in this series.
    In this part we’re discussing the different types of windows hashes and focus on the NTLM authentication process.

    Red teaming   •   April 2, 2020   •   26 min read
    Attacking Helpdesks - Part 1: DeskPro

    Attacking HelpDesks Part 1: RCE Chain on DeskPro, with Bitdefender as a Case Study

    We decided to look at the most popular on-premise helpdesk solutions. In this article we explain how we managed to find and exploit multiple vulnerabilities that eventually lead to remote code execution (RCE) at DeskPro software utilized by thousands of organizations using Bitdefender and Freelancer Inc in a case study. No full exploit is currently available, but steps can be easily reproduced and used to build one.

    Web Security   •   March 28, 2020   •   15 min read
    Oh, My Kerberos! Do Not Get Kerberoasted!

    Oh, My Kerberos! Do Not Get Kerberoasted!

      Part of an upcoming series trying to shed the light on attacks targeting Microsoft Kerberos implementation in Active Directory …

    Active directory Red teaming   •   April 9, 2019   •   15 min read
    Comma is forbidden! No worries!! Inject in insert/update queries without it

    Comma is forbidden! No worries!! Inject in insert/update queries without it

    A writeup regarding exploiting SQL injection issue in an insert query while it wasn’t possible to use a comma at my payload at all.

    Web Security   •   March 31, 2019   •   13 min read
    DUMPit - The new SHAREit Vulnerability

    SHAREit Multiple Vulnerabilities Enable Unrestricted Access to Adjacent Devices’ Files

    Two recently discovered vulnerabilities affecting SHAREit Android application <= v 4.0.38. The first one allows attacker to bypass SHAREit device authentication mechanism, and the other one enables authenticated attacker to download arbitrary files from user's device. Both vulnerabilities were reported to the vendor and patches have been released.

    Mobile Penetration Testing   •   February 25, 2019   •   17 min read
    [SQLi] Extracting data without knowing columns names

    [SQLi] Extracting data without knowing columns names

    Extracting data without knowing columns names from MYSQL < 5 or in case of WAF blacklisting sending information_schema in the request

    Web Security   •   February 9, 2019   •   7 min read

    Who are we

    RedForce is an information security consultancy firm consists of a team of experts in the offensive security field. We are a service-oriented organization specialized in offensive consultancy services . . . more

    Contact us

    Address: 5th Floor, Golden Mall, 6th Of October, Giza, Egypt.

    Phone: +20 100 7842 224
    Email: [email protected]

    Redforce © Copyright 2025. All rights reserved.