Carlos Polop and Claude Opus 4.8
b055d05cef
Add Discord and Telegram links to footer/menu socials
...
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-07-08 20:03:43 +02:00
SirBroccoli and GitHub
8ed59d5760
Merge pull request #319 from HackTricks-wiki/update_Caught_in_the_Octopus_Trap_Unauthenticated_RCE_i_7e1b915b024944ba
...
Caught in the Octopus Trap Unauthenticated RCE in Argo CD wi...
2026-07-06 17:52:00 +02:00
HackTricks News Bot and Carlos Polop
aa550f3c3c
Add Argo CD security page
2026-07-06 17:32:36 +02:00
SirBroccoli and GitHub
6657d67454
Merge pull request #318 from HackTricks-wiki/update_Find_Comment_Get_Shell_Command_Injection_in_dbt__4f2a061f6bbf07ee
...
Find Comment, Get Shell Command Injection in dbt’s GitHub Ac...
2026-07-06 17:24:26 +02:00
SirBroccoli and GitHub
e405713d17
Merge pull request #317 from HackTricks-wiki/update_Charting_your_way_in_Helm_template_injection_c4c3d85e188cf37f
...
Charting your way in Helm template injection
2026-07-06 17:23:40 +02:00
SirBroccoli and GitHub
12c5862052
Merge branch 'master' into update_Charting_your_way_in_Helm_template_injection_c4c3d85e188cf37f
2026-07-06 17:23:33 +02:00
Carlos Polop
7c46190697
Add summer discount popup
2026-07-06 14:57:14 +02:00
Carlos Polop
30f0e6f3e3
Fix chapter navigation links
2026-07-05 16:55:32 +02:00
Carlos Polop
e1ed994783
Fix vertical sponsor ad overflow
2026-07-05 02:06:30 +02:00
Carlos Polop
58413bbe99
Update sponsor card styling
2026-07-04 20:53:44 +02:00
Carlos Polop
339eaf5aba
changes
2026-07-04 13:36:42 +02:00
Carlos Polop
c4d28b9207
Support absolute sponsor image URLs
2026-07-04 13:35:45 +02:00
Carlos Polop
fdd3d95668
Add local cloud Kubernetes updates
2026-07-04 00:45:00 +02:00
Carlos Polop
42c3a88de7
Improve sponsor ad hover layout
2026-07-03 23:05:07 +02:00
HackTricks News Bot
0d31686e87
Add content from: Find Comment, Get Shell: Command Injection in dbt’s GitHub A...
2026-07-01 20:03:49 +00:00
HackTricks News Bot
37e8c750e6
Add content from: Charting your way in: Helm template injection
2026-06-29 16:00:32 +00:00
SirBroccoli and GitHub
36c997b8f0
Merge pull request #316 from OffsecPierogi/master
...
azrte-MahonIsland
2026-06-26 10:15:37 +02:00
SirBroccoli and GitHub
5490c138ba
Merge pull request #312 from HackTricks-wiki/update_What_the_Miasma_Campaign_Reveals_About_the_New_S_9de20d9245b07fa3
...
What the Miasma Campaign Reveals About the New Supply Chain ...
2026-06-25 18:06:10 +02:00
Carlos Polop
1b27af5f46
Move Miasma npm abuse into dedicated page
2026-06-25 18:00:45 +02:00
SirBroccoli and GitHub
4bb7f5d2d7
Merge pull request #311 from HackTricks-wiki/update_The_Global_Namespace_Risk_Universal_Bucket_Hijac_541fed5c68a1451e
...
The Global Namespace Risk Universal Bucket Hijacking Techniq...
2026-06-25 17:56:15 +02:00
Carlos Polop
356e26a346
Move bucket hijacking technique to service pages
2026-06-25 17:54:40 +02:00
OffsecPierogi and GitHub
9153166a1d
Update az-automation-accounts-privesc.md
...
The 2 following techniques demonstrate how privilege escalation can be done with modules and python packages in Azure involving automation accounts. Original research with screenshots and evidence can be provided upon request.
2026-06-25 09:44:28 -04:00
SirBroccoli and GitHub
42e19b55ad
Merge pull request #315 from HackTricks-wiki/refine-hovered-sponsor-layout-20260624173941
...
Refine hovered sponsor layout
2026-06-24 17:57:50 +02:00
Carlos Polop
da81c92add
Adjust sponsor ad layout
2026-06-24 17:56:26 +02:00
Hermes
d529a9e36d
Refine hovered sponsor layout
2026-06-24 17:39:41 +02:00
SirBroccoli and GitHub
8e4b5d5693
Merge pull request #314 from HackTricks-wiki/fix-sponsor-title-visibility-20260624171228
...
Fix sponsor title visibility
2026-06-24 17:24:42 +02:00
Hermes
fbbe2cbad8
Improve sponsor title visibility
2026-06-24 17:12:28 +02:00
SirBroccoli and GitHub
221643d353
Merge pull request #313 from HackTricks-wiki/add-linux-course-sponsor-images-20260624163124
...
Add Linux course sponsor images
2026-06-24 16:33:57 +02:00
Hermes
6bec7f4e0a
Add Linux course sponsor images
2026-06-24 16:31:25 +02:00
HackTricks News Bot
b3aea588e8
Add content from: What the Miasma Campaign Reveals About the New Supply Chain ...
2026-06-23 14:54:34 +00:00
HackTricks News Bot
d10beb1886
Add content from: The Global Namespace Risk: Universal Bucket Hijacking Techni...
2026-06-23 03:02:47 +00:00
SirBroccoli and GitHub
901f745d5a
Merge pull request #309 from HackTricks-wiki/hermes/reduce-cloudfront-invalidation-paths
...
Reduce redundant CloudFront invalidation paths
2026-06-21 15:52:05 +02:00
SirBroccoli and GitHub
db20d27796
Merge pull request #310 from TheToddLuci0/azure_alert_phishing
...
azrte-TheToddLuci0
2026-06-21 15:51:41 +02:00
Hermes Agent
50de879350
Reduce redundant CloudFront invalidation paths
2026-06-19 08:37:23 +02:00
SirBroccoli and GitHub
6a99acfb6f
Merge pull request #306 from HackTricks-wiki/update_Hacking_Google_with_AI_AI-Assisted_Discovery-Doc_f250207268e52efb
...
Hacking Google with AI AI-Assisted Discovery-Document Fuzzin...
2026-06-16 15:37:49 +02:00
SirBroccoli and GitHub
a11e2ff62a
Merge pull request #304 from HackTricks-wiki/update_Ghost-Sender_-_Universal_Email_Spoofing_against__8fb2d618657690cb
...
Ghost-Sender - Universal Email Spoofing against Exchange Onl...
2026-06-16 15:26:37 +02:00
SirBroccoli and GitHub
7a707977b1
Merge pull request #308 from marcgoam/azrte-marcgoam
...
azrte-marcgoam
2026-06-16 15:20:23 +02:00
SirBroccoli and GitHub
d318847a36
Merge pull request #305 from Fudgedotdotdot/master
...
azrte-Fudgedotdotdot
2026-06-16 15:13:09 +02:00
Marc Gonzalez Amores and GitHub
f2f340de83
Add applications.myOrganization/allProperties/update privesc technique
...
## Summary
Adds a new privilege escalation technique to the EntraID privesc page, covering `microsoft.directory/applications.myOrganization/allProperties/update`.
This permission is not present in any built-in role but commonly appears in custom roles delegated to application teams under the assumption that the `.myOrganization` subtype scopes the action to internal-only apps. Since `allProperties` includes `passwordCredentials` and `keyCredentials`, the permission is functionally equivalent to credential-injection capability against every single-tenant app in the tenant.
## Why this matters
The existing page already documents `applications/credentials/update`. The new section complements it by surfacing the custom-role-scoped variant, which is underdocumented and easy to miss during privileged-role audits, admins filter on built-in privileged roles and miss custom roles carrying this single action.
## Testing
The full attack chain was reproduced end-to-end in an isolated Microsoft 365 Business Premium trial tenant:
1. Created a custom role with `applications.myOrganization/allProperties/update` as the only action.
2. Assigned it to a non-privileged victim user.
3. From the victim's session, ran the documented commands to inject a credential into a target single-tenant app and successfully authenticated as the application via `az login --service-principal`.
## References
- https://learn.microsoft.com/entra/identity/role-based-access-control/custom-available-permissions
- https://learn.microsoft.com/entra/identity/role-based-access-control/permissions-reference
- https://learn.microsoft.com/graph/api/application-addpassword
2026-06-12 11:02:33 +02:00
HackTricks News Bot
108413b913
Add content from: Hacking Google with AI: AI-Assisted Discovery-Document Fuzzi...
2026-06-11 16:13:40 +00:00
Fudgedotdotdot
7e4c12b7ff
Clarified Microsoft.Web/sites/publishxml/action , Microsoft.Web/sites/basicPublishingCredentialsPolicies/write for functionapps
2026-06-10 14:33:48 +02:00
HackTricks News Bot
94cb3da491
Add content from: Ghost-Sender - Universal Email Spoofing against Exchange Onl...
2026-06-10 03:40:02 +00:00
SirBroccoli and GitHub
b81257def6
Merge pull request #301 from HackTricks-wiki/update_Poisoning_Claude_Code__One_GitHub_Issue_to_Break_t_20260602_103342
...
Poisoning Claude Code One GitHub Issue to Break the Supply C...
2026-06-05 16:11:29 +02:00
SirBroccoli and GitHub
680428f929
Merge pull request #299 from HackTricks-wiki/update_Authenticated_RCE_via_Argument_Injection_in_Gogs_R_20260528_154851
...
Authenticated RCE via Argument Injection in Gogs Rebase Merg...
2026-06-05 15:52:53 +02:00
SirBroccoli and GitHub
ab22b74079
Merge pull request #298 from cblopez/patch-1
...
Added access entry abuse to pivot from AWS to Kubernetes
2026-06-05 15:51:47 +02:00
SirBroccoli and GitHub
45e53868a6
Merge pull request #297 from HackTricks-wiki/update_Investigating_Suspicious_AI_Workflows_in_Microsoft_20260527_153712
...
Investigating Suspicious AI Workflows in Microsoft Entra Age...
2026-06-05 11:23:54 +02:00
SirBroccoli and GitHub
f509732e5d
Merge pull request #296 from JaimePolop/master
...
Fix table
2026-06-05 11:22:07 +02:00
Carlos Polop
8867d2f8c0
f
2026-06-05 10:40:57 +02:00
SirBroccoli and GitHub
ec2bf385fe
Merge pull request #302 from HackTricks-wiki/fix/hermes-root-sitemap-invalidation
...
ci: skip unchanged root sitemap invalidations
2026-06-04 23:56:41 +02:00
Hermes
4c4632303a
ci: skip unchanged root sitemap invalidations
2026-06-04 08:23:45 +02:00