moltenbit https://moltenbit.net/ Recent content on moltenbit Hugo -- 0.147.2 en-us Tue, 17 Mar 2026 12:00:00 +0100 Bypassing Wazuh's UNC Mitigation in Windows OSQuery via \\?\UNC\ (CVE-2025-30201 / GHSA-x697-jf34-gp5x) https://moltenbit.net/posts/wazuh-unc-mitigation-bypass-cve-2025-30201/ Tue, 17 Mar 2026 12:00:00 +0100 https://moltenbit.net/posts/wazuh-unc-mitigation-bypass-cve-2025-30201/ <p>Wazuh mitigated a NetNTLMv2 hash leakage (<a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30201">CVE-2025-30201</a> / <a href="https://github.com/wazuh/wazuh/security/advisories/GHSA-x697-jf34-gp5x">GHSA-x697-jf34-gp5x</a>) issue caused by allowing classic UNC paths (e.g., <code>\\server\share</code>) in centrally managed Windows agent configuration. The core risk is that when a attacker controlled domain-joined Windows agent accesses a remote SMB path, Windows may perform NTLM authentication to that server, allowing an attacker to capture the machine account&rsquo;s NetNTLMv2 hash.</p> <p>In follow-up testing on <strong>Wazuh 4.14.1</strong>, <a href="https://github.com/wazuh/wazuh/security/advisories/GHSA-5g2v-99vr-3hgw">I found</a> that the mitigation could still be bypassed in the <strong>OSQuery</strong> configuration: classic UNC paths were blocked, but <strong>extended-length UNC paths</strong> using the <code>\\?\UNC\</code> prefix were accepted for OSQuery&rsquo;s <code>log_path</code> and <code>config_path</code>.</p> <p>The CVE has seen bince been extended to cover the bypass.</p> Privacy https://moltenbit.net/privacy/ Sat, 07 Feb 2026 00:00:00 +0000 https://moltenbit.net/privacy/ <p>This site does not use cookies, tracking scripts, or third-party resources. No data is shared with third parties.</p> <p>The web server automatically collects access logs (IP address, timestamp, requested URL, referrer, user agent) for security and operational purposes. Logs are automatically deleted after 14 days.</p> Detecting the Notepad++ Supply Chain Attack: A PowerShell Triage Script https://moltenbit.net/posts/notepad-supply-chain-attack-triage-script/ Wed, 04 Feb 2026 12:00:00 +0100 https://moltenbit.net/posts/notepad-supply-chain-attack-triage-script/ A PowerShell-based triage script to check systems for indicators of compromise related to the Notepad++ supply chain attack attributed to Lotus Blossom APT. Contact https://moltenbit.net/contact/ Wed, 10 Dec 2025 19:05:55 +0200 https://moltenbit.net/contact/ <p>You can communicate with me via PGP encrypted mail.</p> <ul> <li>Email: moltenbit [AT] protonmail.com</li> <li>PGP fingerprint: <code>3FE5 6A85 DF1B C97C C570 276B B02E 49E4 AE1D EB00</code></li> <li><a href="https://moltenbit.net/pgp/moltenbit.asc">Download PGP key</a></li> </ul> <p>You can also find me on these platforms:</p> <ul> <li><a href="https://bsky.app/profile/moltenbit.bsky.social">Blue Sky</a></li> <li><a href="https://infosec.exchange/@moltenbit">Mastodon</a></li> <li><a href="https://github.com/moltenbit">GitHub</a></li> </ul> Combating Misinformation Through Geolocation: Colombian Trucker vs. Wind Energy https://moltenbit.net/posts/combating-misinformation-through-geolocation/ Mon, 26 May 2025 20:47:17 +0200 https://moltenbit.net/posts/combating-misinformation-through-geolocation/ <p>Recently colombian journalist Alexander Campos submitted a request on the Bellingcat Discord server to identify the location of a convoy of trucks carrying wind turbine blades shown in a Facebook video, which can be seen here:<br> <a href="https://web.archive.org/web/20250526164607/https://www.facebook.com/100064060326287/videos/1227863822389050/">https://web.archive.org/web/20250526164607/https://www.facebook.com/100064060326287/videos/1227863822389050/</a><br> The person recording stated the convoy is driving to &ldquo;Alta Guajira&rdquo;, the northest point in Colombian geography. Rightfully so there were doubts about this statement.</p> Custom Admin Notifications for New Intune Enrollments https://moltenbit.net/posts/custom-admin-notifications-for-new-intune-enrollments/ Sun, 25 May 2025 10:05:55 +0200 https://moltenbit.net/posts/custom-admin-notifications-for-new-intune-enrollments/ Intune lacks native admin alerts for new enrollments. This script fixes that – using Entra, Microsoft Graph API, and a simple Linux setup. Gralhix OSINT exercise 005 walkthrough https://moltenbit.net/posts/gralhix-osint-exercise-005-walkthrough/ Wed, 21 May 2025 19:23:09 +0200 https://moltenbit.net/posts/gralhix-osint-exercise-005-walkthrough/ <p>This is a walkthrough of the OSINT exercise 005 by <a href="https://gralhix.com/list-of-osint-exercises/osint-exercise-005/">Gralhix</a>.</p> <p>Starting off this OSINT challenge I did a reverse image search which led to nothing, unsurprisingly, since the image is taken from a livestream.</p> moltenbit.net https://moltenbit.net/homepage/ Mon, 01 Jan 0001 00:00:00 +0000 https://moltenbit.net/homepage/ moltenbit.net