{"generator":"GNU social 2.0.2-dev","title":"Conversation","totalItems":2,"items":[{"actor":{"id":"https:\/\/infosec.exchange\/users\/wdormann","displayName":"Will Dormann","status_net":{"avatarLinks":[{"url":"https:\/\/gnusocial.jp\/avatar\/232810-original-tmp20240116185707.webp","rel":"avatar","type":"image\/webp","width":400,"height":400},{"url":"https:\/\/gnusocial.jp\/avatar\/232810-96-20240116185707.webp","rel":"avatar","type":"image\/webp","width":96,"height":96},{"url":"https:\/\/gnusocial.jp\/avatar\/232810-48-20240116185707.webp","rel":"avatar","type":"image\/webp","width":48,"height":48},{"url":"https:\/\/gnusocial.jp\/avatar\/232810-24-20240116185707.webp","rel":"avatar","type":"image\/webp","width":24,"height":24}],"profile_info":{"local_id":"232810"}},"image":{"url":"https:\/\/gnusocial.jp\/avatar\/232810-96-20240116185707.webp","rel":"avatar","type":"image\/webp","width":96,"height":96},"objectType":"person","summary":"I play with vulnerabilities and exploits. I used to be https:\/\/twitter.com\/wdormann but Twitter has become unbearable, so here I am.","url":"https:\/\/infosec.exchange\/@wdormann","portablecontacts_net":{"preferredUsername":"wdormann","displayName":"Will Dormann","note":"I play with vulnerabilities and exploits. I used to be https:\/\/twitter.com\/wdormann but Twitter has become unbearable, so here I am."}},"content":"<p>Someone on the Bad Site pointed out that the exploit only triggers upon entry to a Defender Offline scan. To which the author replied:<\/p><p>Exactly why I kept repeating the victim machine needed to have at least one offline scan initiated before the attack can be done without authentication.<\/p><p>So at the end of the day, I think GreatXML is a thing you can do do someone's computer that results in the comouter's administrator themselves getting an unexpected privileged command prompt.<\/p><p>So what?  \ud83e\udd37\u2642\ufe0f<\/p>","generator":{"id":"tag:gnusocial.jp,2026-08-23:notice-source:ActivityPub","objectType":"application","status_net":{"source_code":"ActivityPub"}},"id":"https:\/\/infosec.exchange\/users\/wdormann\/statuses\/116739334274781447","object":{"id":"https:\/\/infosec.exchange\/users\/wdormann\/statuses\/116739334274781447","objectType":"note","content":"<p>Someone on the Bad Site pointed out that the exploit only triggers upon entry to a Defender Offline scan. To which the author replied:<\/p><p>Exactly why I kept repeating the victim machine needed to have at least one offline scan initiated before the attack can be done without authentication.<\/p><p>So at the end of the day, I think GreatXML is a thing you can do do someone's computer that results in the comouter's administrator themselves getting an unexpected privileged command prompt.<\/p><p>So what?  \ud83e\udd37\u2642\ufe0f<\/p>","url":"https:\/\/infosec.exchange\/@wdormann\/116739334274781447","status_net":{"notice_id":null},"inReplyTo":{"objectType":"note","id":"https:\/\/infosec.exchange\/users\/wdormann\/statuses\/116729310091855591","url":"https:\/\/infosec.exchange\/@wdormann\/116729310091855591"}},"to":[{"objectType":"http:\/\/activitystrea.ms\/schema\/1.0\/collection","id":"http:\/\/activityschema.org\/collection\/public"}],"status_net":{"conversation":"tag:gnusocial.jp,2026-06-11:objectType=thread:nonce=6aaed76d365b77e4","notice_info":{"local_id":"12743587","source":"ActivityPub"}},"published":"2026-06-12T21:52:20+00:00","provider":{"objectType":"service","displayName":"GNU social JP","url":"https:\/\/gnusocial.jp\/"},"verb":"post","url":"https:\/\/infosec.exchange\/@wdormann\/116739334274781447"},{"actor":{"id":"https:\/\/infosec.exchange\/users\/wdormann","displayName":"Will Dormann","status_net":{"avatarLinks":[{"url":"https:\/\/gnusocial.jp\/avatar\/232810-original-tmp20240116185707.webp","rel":"avatar","type":"image\/webp","width":400,"height":400},{"url":"https:\/\/gnusocial.jp\/avatar\/232810-96-20240116185707.webp","rel":"avatar","type":"image\/webp","width":96,"height":96},{"url":"https:\/\/gnusocial.jp\/avatar\/232810-48-20240116185707.webp","rel":"avatar","type":"image\/webp","width":48,"height":48},{"url":"https:\/\/gnusocial.jp\/avatar\/232810-24-20240116185707.webp","rel":"avatar","type":"image\/webp","width":24,"height":24}],"profile_info":{"local_id":"232810"}},"image":{"url":"https:\/\/gnusocial.jp\/avatar\/232810-96-20240116185707.webp","rel":"avatar","type":"image\/webp","width":96,"height":96},"objectType":"person","summary":"I play with vulnerabilities and exploits. I used to be https:\/\/twitter.com\/wdormann but Twitter has become unbearable, so here I am.","url":"https:\/\/infosec.exchange\/@wdormann","portablecontacts_net":{"preferredUsername":"wdormann","displayName":"Will Dormann","note":"I play with vulnerabilities and exploits. I used to be https:\/\/twitter.com\/wdormann but Twitter has become unbearable, so here I am."}},"content":"<p>Nightmare Eclipse has posted another purported bitlocker bypass: <a href=\"https:\/\/github.com\/MSNightmare\/GreatXML\" rel=\"nofollow\">GreatXML<\/a><\/p><p>This exploit claims to be able to bypass bitlocker on systems that have executed <a href=\"https:\/\/learn.microsoft.com\/en-us\/defender-endpoint\/microsoft-defender-offline\" rel=\"nofollow\">Microsoft Defender Offline<\/a> at some point in the past.  This is done by replacing Recovery\\WindowsRE\\ReAgent.xml and placing unattend.xml in the WinRE partition.<\/p><p>I think the writeup is flawed in that the spawned CMD.EXE happens on the NEXT time that a Microsoft Defender Offline scan is triggered.  And in order to trigger a Microsoft Defender Offline scan, you both need to be logged in to Windows, and also have admin credentials.  And if you've already got that level of access, you can just turn off bitlocker.<\/p><p>The writeup for GreatXML suggests that the prerequisite is that Windows Defender Offline has been executed at some point in the past.  And that after planting two files in WinRE, all you need to do is [Shift]-reboot into WinRE, and Windows will automatically go into Microsoft Defender Offline scan mode.  But this is not the case in any of the 3 lineages of Win11 that I have handy.<\/p><p>If you only [Shift]-reboot into WinRE, you get the normal WinRE menu.  Not anything related to Microsoft Defender Offline.  Even after the placement of the specified files.<\/p>","generator":{"id":"tag:gnusocial.jp,2026-08-23:notice-source:ActivityPub","objectType":"application","status_net":{"source_code":"ActivityPub"}},"id":"https:\/\/infosec.exchange\/users\/wdormann\/statuses\/116729310091855591","object":{"id":"https:\/\/infosec.exchange\/users\/wdormann\/statuses\/116729310091855591","objectType":"note","content":"<p>Nightmare Eclipse has posted another purported bitlocker bypass: <a href=\"https:\/\/github.com\/MSNightmare\/GreatXML\" rel=\"nofollow\">GreatXML<\/a><\/p><p>This exploit claims to be able to bypass bitlocker on systems that have executed <a href=\"https:\/\/learn.microsoft.com\/en-us\/defender-endpoint\/microsoft-defender-offline\" rel=\"nofollow\">Microsoft Defender Offline<\/a> at some point in the past.  This is done by replacing Recovery\\WindowsRE\\ReAgent.xml and placing unattend.xml in the WinRE partition.<\/p><p>I think the writeup is flawed in that the spawned CMD.EXE happens on the NEXT time that a Microsoft Defender Offline scan is triggered.  And in order to trigger a Microsoft Defender Offline scan, you both need to be logged in to Windows, and also have admin credentials.  And if you've already got that level of access, you can just turn off bitlocker.<\/p><p>The writeup for GreatXML suggests that the prerequisite is that Windows Defender Offline has been executed at some point in the past.  And that after planting two files in WinRE, all you need to do is [Shift]-reboot into WinRE, and Windows will automatically go into Microsoft Defender Offline scan mode.  But this is not the case in any of the 3 lineages of Win11 that I have handy.<\/p><p>If you only [Shift]-reboot into WinRE, you get the normal WinRE menu.  Not anything related to Microsoft Defender Offline.  Even after the placement of the specified files.<\/p>","url":"https:\/\/infosec.exchange\/@wdormann\/116729310091855591","status_net":{"notice_id":null}},"to":[{"objectType":"http:\/\/activitystrea.ms\/schema\/1.0\/collection","id":"http:\/\/activityschema.org\/collection\/public"}],"status_net":{"conversation":"tag:gnusocial.jp,2026-06-11:objectType=thread:nonce=6aaed76d365b77e4","notice_info":{"local_id":"12737130","source":"ActivityPub"}},"published":"2026-06-11T18:37:59+00:00","provider":{"objectType":"service","displayName":"GNU social JP","url":"https:\/\/gnusocial.jp\/"},"verb":"post","url":"https:\/\/infosec.exchange\/@wdormann\/116729310091855591"}],"links":[{"url":"https:\/\/gnusocial.jp\/conversation\/6470277","rel":"alternate","type":"text\/html"}]}