Elektrine
EN
Log in Register
Paige Chat Timeline Gallery Friends Lists Email Drive DNS Resolver Domains VPN Kairo Nerve
Remote

payloadforge

@payloadforge@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange
10 Followers
419 Following
5 Posts
Joined February 23, 2026
Open post
payloadforge @payloadforge@infosec.exchange
· 1mo ago
Replying to @payloadforge@infosec.exchange
Patched forks if you want to test the fix before the PRs merge. CertiGhost https://github.com/GregDurys/CVE-2026-54121 Impacket https://github.com/GregDurys/impacket #ADCS #ActiveDirectory #RedTeam
0
0
0
0
Open post
payloadforge @payloadforge@infosec.exchange
· 1mo ago
Replying to @payloadforge@infosec.exchange
One-bit fix in two places: ParameterControl 0x800 | 0x20. K preserves normal callbacks; E allows DC callbacks. Credential checks remain unchanged. The CA then issued the certificate. Three PRs: Impacket https://github.com/fortra/impacket/pull/2239 CertiGhost fix https://github.com/aniqfakhrul/CVE-2026-54121/pull/2 Debug https://github.com/aniqfakhrul/CVE-2026-54121/pull/3 A failing PoC often means your topology differs from the author's.
0
1
0
0
Open post
payloadforge @payloadforge@infosec.exchange
· 1mo ago
Replying to @payloadforge@infosec.exchange
Every run died in the same place. My Ludus lab runs AD CS on the Domain Controller, so the CA callback authenticated as the DC's machine account: a server trust account rather than an ordinary workstation trust account. Impacket's rogue SMB NetLogon path and CertiGhost's LDAP validation both set ParameterControl to K (0x800), but not E (0x20), the bit Microsoft defines for a Domain Controller. STATUS_NOLOGON_SERVER_TRUST_ACCOUNT, every time.
0
1
0
0
Open post
payloadforge @payloadforge@infosec.exchange
· 2mo ago
I wrote up CVE-2026-56877, a Skillable SCORM launch issue where the browser supplied userId drove lab allocation while the token was the only trusted value. Skillable's answer was migration, no SCORM path fix, and a private customer advisory. That is why the public record matters for anyone doing vendor due diligence. https://payloadforge.io/beyond-crto-skillable #SCORM #Disclosure #ThirdPartyRisk
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)
  • Source code

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 14:55:15 UTC