2024 topics

  • EvilGinx 3.3
    • adversary in the middle, proxy/reverse proxy, steals username/password/MFA token
    • now uses goPhish to send and track phishing campaigns
  • Basic External Pentest Methodology - on THM box
    • scan for open ports
    • scan open ports for services and their versions
    • search for exploits for those versions
  • XZ Hack