1019 Commits

Author SHA1 Message Date
SirBroccoli b81257def6 Merge pull request #301 from HackTricks-wiki/update_Poisoning_Claude_Code__One_GitHub_Issue_to_Break_t_20260602_103342
Poisoning Claude Code One GitHub Issue to Break the Supply C...
2026-06-05 16:11:29 +02:00
SirBroccoli 680428f929 Merge pull request #299 from HackTricks-wiki/update_Authenticated_RCE_via_Argument_Injection_in_Gogs_R_20260528_154851
Authenticated RCE via Argument Injection in Gogs Rebase Merg...
2026-06-05 15:52:53 +02:00
SirBroccoli ab22b74079 Merge pull request #298 from cblopez/patch-1
Added access entry abuse to pivot from AWS to Kubernetes
2026-06-05 15:51:47 +02:00
SirBroccoli 45e53868a6 Merge pull request #297 from HackTricks-wiki/update_Investigating_Suspicious_AI_Workflows_in_Microsoft_20260527_153712
Investigating Suspicious AI Workflows in Microsoft Entra Age...
2026-06-05 11:23:54 +02:00
SirBroccoli f509732e5d Merge pull request #296 from JaimePolop/master
Fix table
2026-06-05 11:22:07 +02:00
Carlos Polop 8867d2f8c0 f 2026-06-05 10:40:57 +02:00
SirBroccoli ec2bf385fe Merge pull request #302 from HackTricks-wiki/fix/hermes-root-sitemap-invalidation
ci: skip unchanged root sitemap invalidations
2026-06-04 23:56:41 +02:00
Hermes 4c4632303a ci: skip unchanged root sitemap invalidations 2026-06-04 08:23:45 +02:00
HackTricks News Bot 667a8b921e Add content from: Poisoning Claude Code: One GitHub Issue to Break the Supply ... 2026-06-02 10:37:40 +00:00
HackTricks News Bot 4317b90953 Add content from: Authenticated RCE via Argument Injection in Gogs Rebase Merg... 2026-05-28 15:52:25 +00:00
Christian Barral 97af0f5005 Added access entry abuse info
Added sections on abusing configmap (existing) and access entries (new) for AWS EKS, including commands for creating access entries and associating access policies.
2026-05-28 09:06:51 +02:00
HackTricks News Bot f6523f3643 Add content from: Investigating Suspicious AI Workflows in Microsoft Entra Age... 2026-05-27 15:41:56 +00:00
Jimmy 769ae53c76 Fix table 2026-05-27 00:26:48 +02:00
SirBroccoli 2aea30dad8 Merge pull request #295 from HackTricks-wiki/teamcity-security-section
Add TeamCity CI/CD pentesting section
2026-05-26 21:32:53 +02:00
Carlos Polop e9b5f23f8a Add TeamCity CI/CD pentesting section 2026-05-26 21:31:37 +02:00
SirBroccoli 23530050c5 Merge pull request #293 from HackTricks-wiki/update_Navigating_Lax_Load_Balancers__When_an_Intersectio_20260525_145126
Navigating Lax Load Balancers When an Intersection Gets You ...
2026-05-26 21:11:31 +02:00
SirBroccoli af48369ba7 Merge pull request #292 from HackTricks-wiki/update_Paved_With_Intent__ROADtools_and_Nation-State_Tact_20260522_143732
Paved With Intent ROADtools and Nation-State Tactics in the ...
2026-05-26 21:09:38 +02:00
SirBroccoli ae1056fe51 Merge pull request #290 from HackTricks-wiki/update_Mini_Shai-Hulud__FAQ_on_the_TeamPCP_npm_and_PyPI_s_20260521_195353
Mini Shai-Hulud FAQ on the TeamPCP npm and PyPI supply-chain...
2026-05-26 21:04:47 +02:00
SirBroccoli b4424204e9 Update README.md 2026-05-26 21:04:31 +02:00
SirBroccoli 5400f7c96a Merge pull request #288 from HackTricks-wiki/chore/drop-redundant-robots-invalidation-20260519
Avoid redundant robots CloudFront invalidations
2026-05-26 21:00:53 +02:00
SirBroccoli 2439b0354b Merge pull request #294 from Jacob-Ham/aws-fix-iam-mfa
Fixed some IAM MFA device priv esc issues.
2026-05-26 20:06:25 +02:00
Jacob-Ham 3963a1ef8a Fixed virtual mfa device creation command, add example TOTP tool, add command for getting mfa backed session 2026-05-26 12:54:52 -05:00
Carlos Polop 06a089227c f 2026-05-26 17:55:54 +02:00
HackTricks News Bot aa93024621 Add content from: Navigating Lax Load Balancers: When an Intersection Gets You... 2026-05-25 14:55:45 +00:00
HackTricks News Bot 28650f17b4 Add content from: Paved With Intent: ROADtools and Nation-State Tactics in the... 2026-05-22 14:43:02 +00:00
HackTricks News Bot 5704b992d8 Add content from: Red-Teaming Cloud Infrastructure with Neo 2026-05-22 09:06:12 +00:00
HackTricks News Bot 1484d713ec Add content from: Mini Shai-Hulud: FAQ on the TeamPCP npm and PyPI supply-chai... 2026-05-21 19:57:44 +00:00
Hermes 4ae4b59345 Avoid redundant robots CloudFront invalidations 2026-05-19 08:16:18 +02:00
Carlos Polop 8cb43f6b52 Keep sponsor title visible on hover 2026-05-18 21:36:03 +02:00
Carlos Polop 4345b0e6bb Refine sponsor hover and update CTA styling 2026-05-18 21:10:45 +02:00
Carlos Polop c1bd048854 Add page update request nav link 2026-05-18 21:03:00 +02:00
Carlos Polop caf7c4bcfd Improve sponsor ad hover layout 2026-05-18 20:51:59 +02:00
SirBroccoli 72f0f71ef5 Merge pull request #287 from JaimePolop/master
a
2026-05-18 17:32:37 +02:00
Jimmy 51f602b871 a 2026-05-18 17:10:42 +02:00
Carlos Polop e839fdd130 f 2026-05-11 16:51:50 +02:00
Carlos Polop b7832d4f82 Increase sponsor hover CTA text size 2026-05-09 21:49:49 +02:00
Carlos Polop 4244ebd156 Increase sponsor hover CTA prominence 2026-05-09 21:26:35 +02:00
Carlos Polop a80a62503c Tune sponsor hover text and CTA size 2026-05-09 21:01:46 +02:00
Carlos Polop 2afd0745f7 Prevent sponsor text CTA overlap 2026-05-09 20:36:22 +02:00
Carlos Polop 4efde9fabe Fix sponsor hover text placement 2026-05-09 19:02:23 +02:00
Carlos Polop 7759eb35db Improve sponsor hover layout 2026-05-09 18:50:44 +02:00
Carlos Polop 39db3878cf Improve SEO metadata and translation discovery 2026-05-09 17:34:28 +02:00
SirBroccoli d13c270d7f Merge pull request #286 from JaimePolop/master
Add WireServer & GoalState
2026-05-05 18:18:44 +02:00
Carlos Polop 2fe01e873a Mention WireServer MI selector fallback 2026-05-05 17:50:24 +02:00
Carlos Polop 2a4cc7c428 Document Azure MI token discovery limits 2026-05-05 17:45:43 +02:00
Carlos Polop 406b2549aa Replace brittle managed identity enumeration examples 2026-05-05 16:27:01 +02:00
Carlos Polop 393c6997b1 Clarify Azure WireServer access contexts 2026-05-05 16:16:00 +02:00
SirBroccoli 2f2df45366 Update README.md 2026-05-05 15:31:53 +02:00
SirBroccoli 28a5f23cd9 Merge pull request #279 from HackTricks-wiki/update_IAM_the_Captain_Now___Hijacking_Azure_Identity_Acc_20260409_132358
IAM the Captain Now – Hijacking Azure Identity Access
2026-05-05 15:17:16 +02:00
Jimmy 6f461640c2 Add WireServer & GoalState 2026-05-05 14:33:29 +02:00