Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

payloadforge

@payloadforge@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange
9 Followers
418 Following
5 Posts
Joined February 23, 2026
Open post
payloadforge @payloadforge@infosec.exchange
· 2mo ago
Replying to
Patched forks if you want to test the fix before the PRs merge. CertiGhost https://github.com/GregDurys/CVE-2026-54121 Impacket https://github.com/GregDurys/impacket #ADCS #ActiveDirectory #RedTeam
GitHub

GitHub - GregDurys/CVE-2026-54121: Certighost POC

Certighost POC. Contribute to GregDurys/CVE-2026-54121 development by creating an account on GitHub.

0
0
0
0
Open post
payloadforge @payloadforge@infosec.exchange
· 2mo ago
Replying to
One-bit fix in two places: ParameterControl 0x800 | 0x20. K preserves normal callbacks; E allows DC callbacks. Credential checks remain unchanged. The CA then issued the certificate. Three PRs: Impacket https://github.com/fortra/impacket/pull/2239 CertiGhost fix https://github.com/aniqfakhrul/CVE-2026-54121/pull/2 Debug https://github.com/aniqfakhrul/CVE-2026-54121/pull/3 A failing PoC often means your topology differs from the author's.
GitHub

smbserver.py: allow server-trust accounts in NetLogon validation by GregDurys · Pull Request #2239 · fortra/impacket

While playing with the CertiGhost PoC for CVE-2026-54121 in a lab with a Windows Server 2022 Domain Controller, a Windows Server 2016 domain functional level and an AD CS Enterprise CA installed on...

0
1
0
0
Open post
payloadforge @payloadforge@infosec.exchange
· 2mo ago
Replying to
Every run died in the same place. My Ludus lab runs AD CS on the Domain Controller, so the CA callback authenticated as the DC's machine account: a server trust account rather than an ordinary workstation trust account. Impacket's rogue SMB NetLogon path and CertiGhost's LDAP validation both set ParameterControl to K (0x800), but not E (0x20), the bit Microsoft defines for a Domain Controller. STATUS_NOLOGON_SERVER_TRUST_ACCOUNT, every time.
0
2
0
0
Open post
payloadforge @payloadforge@infosec.exchange
· 2mo ago
I wrote up CVE-2026-56877, a Skillable SCORM launch issue where the browser supplied userId drove lab allocation while the token was the only trusted value. Skillable's answer was migration, no SCORM path fix, and a private customer advisory. That is why the public record matters for anyone doing vendor due diligence. https://payloadforge.io/beyond-crto-skillable #SCORM #Disclosure #ThirdPartyRisk
payloadforge.io
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 05:35:33 UTC