Hey All, just wanted to drop by and say thank you for everything you do! I've been watching your streams, VODs, and videos for the past year, soaking in your advice and recommendations. As a result, I landed my first job offer and joined a great company! Wishing you all the best, and once again, thank you!
I’ve only tested it for kernel mode imports but it should be possible either way. The only hard thing is finding the base address of the DLL you’re looking for (because of ASLR). Most should be automatically loaded so you should be able to get it by iterating the loaded modules list from the PEB. (gs:60 iirc)
@@alh4zr3d3 I am absolutely loving OSEP, the course structure and teaching materials are light years ahead of the random mess of topics Offsec teach at OSCP.
no, throwing a meterpreter instead of calc will not work as well, especially with C# and an EDR on board. it will probably get flagged before you get to launch it
This calc shellcode would also get flagged. As I say in the video, I kept the code as boilerplate as possible to make it simple and to focus on the technique. How would you fix it? Make it so the shellcode doesn't pop AV.