#esc16
Oh kijk! Een Joodse (!) zanger en Douwe Bob toen ze in Stockholm waren voor het Songfestival in 2016.

De originele versie van Michel Fugain blijft natuurlijk het allermooist, maar ik word hier wel blij van hoor.

#TeamDouweBob
Amir and Douwe Bob - Une Belle Histoire | The Bar | ESC16
YouTube video by AVROTROS
www.youtube.com
June 30, 2025 at 10:09 PM
#esc2025 #Deutschland #esc16 dafür mit einem Ballermann-Song... Ohne das Ballalalalalala wäre es ja vielleicht erträglich. Da fällt mir nicht mal was zur Kulisse ein...
May 17, 2025 at 8:34 PM
The Future of Certipy and the Release of v5 & ESC16 https://github.com/ly4k/Certipy/discussions/270
May 15, 2025 at 11:35 AM
Nog meer moois:
Douwe Bob & Eurovision Friends - Hey Jude | The Bar | ESC16
YouTube video by AVROTROS
www.youtube.com
June 30, 2025 at 10:20 PM
Hier opent Douwe Bob de bar: youtu.be/NNc78cS8bqo?...
Opening The Bar | Douwe Bob | TeamDouwe | ESC16
YouTube video by AVROTROS
youtu.be
December 2, 2025 at 10:06 PM
The Eurovision history of Netherlands #tehoNL, part 57
2016
Slow down
by Douwe Bob (1992-)
Music: 🌕🌕🌕🌕🌗
Lyrics: 🌕🌕🌕🌑🌑
Artist: 🌕🌕🌕🌕🌗
Staging: 🌕🌕🌕🌕🌑
Thoughts: A cozy little timeless entry, performed in a very cozy, professional way. A 'going home from work' song
Overall: 🌕🌕🌕🌕🌗
youtu.be/ffVDyQbUstY?...
Douwe Bob - Slow Down | First Semi-Final | ESC16
YouTube video by AVROTROS
youtu.be
July 3, 2025 at 5:47 AM
Bedankt voor deze tip. Het gaat over de opening van een tijdelijke bar in Stockholm door Douwe Bob in 2016. Daar is nog veel meer moois gezongen, zoals Hey Jude. youtu.be/DaNFe-J_SIg?...
Douwe Bob & Eurovision Friends - Hey Jude | The Bar | ESC16
YouTube video by AVROTROS
youtu.be
December 2, 2025 at 10:03 PM
Fries from HackTheBox is a Windows box fronting a mess of Linux containers. It features a pgAdmin eval RCE, Docker cert forging for root, PWM config decryption, a readable gMSA, and an ADCS ESC7 -> ESC6 + ESC16 chain to Administrator.
HTB: Fries
Fries is an assume breach Windows box that hides a sprawl of Linux services behind the domain controller. I’ll start with a set of credentials that don’t work anywhere obvious and use them to log into a Gitea instance, recovering database and pgAdmin access along the way. An outdated pgAdmin is vulnerable to a Python eval remote code execution bug that lands a shell in a container. From environment variables and the pgAdmin database I’ll collect more credentials and spray them to get a shell on the Docker host, which is itself a Hyper-V guest. There I’ll abuse a network file share by recreating a domain user locally to read the Docker daemon’s certificates, forge a client certificate, and use the Docker API to mount the host filesystem and become root. Root on that host holds a PWM configuration with an encrypted service account password, which I’ll recover to move into the domain. That account can read a group managed service account password, and from there I’ll abuse control over the certificate authority, chaining three ADCS misconfigurations to forge a certificate for the administrator and take over the domain.
0xdf.gitlab.io
July 26, 2026 at 5:52 PM
Just hanging out with educelebs here in Canyon!
Natalia Heckman's session was phenomenal & she presents again today. And, POPstar @learningleech.bsky.social
will be presenting today, too! If you are at WTAMU, check out these dedicated literacy leaders.
July 16, 2025 at 11:00 AM
Fluffy from HackTheBox is a nice AD / ADCS box with CVE-2025-24071/CVE-2025-24054 to get a NetNTLMv2, and then pivot using BloodHound to get access to a user who can exploit ESC16 in the ADCS environment.
HTB: Fluffy
Fluffy is an assume-breach Windows Active Directory challenge. I’ll start by exploiting CVE-2025-24071 / CVE-2025-24055, a vulnerability in how Windows handles library-ms files in zip archives, leading to authentication attempts to the attacker. I’ll get a NetNTLMv2 and crack it. From there, BloodHound data shows that this user has GenericWrite over some service accounts. I’ll abuse that to get a WinRM shell with one. From this user, I’ll exploit ESC16 in the ADCS environment to get a shell as Administrator.
0xdf.gitlab.io
September 20, 2025 at 3:00 PM
Madonna, bist du's? #esc16 #esp
January 23, 2025 at 6:36 AM
Toolkit for AD CS with support for all known ESC1-ESC16 attack paths
October 30, 2025 at 4:17 AM
As a Presidential AI Challenge mentor, you can shape the next generation of American innovators. Mentors provide invaluable support to teams in the Challenge. Interested? Contact Robert O’Connor of ESC Region 16 at robert.oconnor@esc16.net.

Learn more: www.ai.gov
October 1, 2025 at 1:31 PM
ADCSのESC1〜ESC16を完全攻略する〜Active Directory証明書サービスの全脆弱性クラスを理解する〜

#Security #ActiveDirectory #ADCS #Certip
ADCSのESC1〜ESC16を完全攻略する〜Active Directory証明書サービスの全脆弱性クラスを理解する〜 - Qiita
要旨 2021年、SpecterOpsのWill SchroederとLee Christensenが発表した論文「Certified Pre-Owned」は、Active Directory Certificate Services(ADCS)における攻撃クラスを「ES...
qiita.com
June 27, 2026 at 8:20 PM
Metasploit Pro 500 Unleashed: Mastering Active Directory Exploitation & Defense with New AD CS Modules + Video

Introduction The release of Metasploit Pro 5.0.0 marks a significant leap in red‑teaming capabilities, introducing an intuitive workflow and powerful modules that target Active Directory…
Metasploit Pro 500 Unleashed: Mastering Active Directory Exploitation & Defense with New AD CS Modules + Video
Introduction The release of Metasploit Pro 5.0.0 marks a significant leap in red‑teaming capabilities, introducing an intuitive workflow and powerful modules that target Active Directory Certificate Services (AD CS). With cybercriminals increasingly weaponizing certificate‑based attack vectors such as ESC9, ESC10, and ESC16, security teams must now understand both the offensive mechanics and the defensive countermeasures to protect their environments. This article dissects the new AD CS metamodules, provides step‑by‑step exploitation guides, and delivers actionable commands to audit and harden your PKI infrastructure.
undercodetesting.com
March 16, 2026 at 9:27 PM
Unlocking Fluffy: A Deep Dive into CVE-2025-24071, ACL Abuse, and ESC16 Privilege Escalation

Introduction: The Hack The Box machine "Fluffy" presents a realistic assumed breach scenario, challenging penetration testers to move from initial low-privileged access to full domain compromise. This…
Unlocking Fluffy: A Deep Dive into CVE-2025-24071, ACL Abuse, and ESC16 Privilege Escalation
Introduction: The Hack The Box machine "Fluffy" presents a realistic assumed breach scenario, challenging penetration testers to move from initial low-privileged access to full domain compromise. This walkthrough demonstrates a critical attack path involving a novel vulnerability, improper Access Control List (ACL) configurations, and the exploitation of Active Directory Certificate Services, highlighting common misconfigurations in enterprise environments. Learning Objectives: Understand the exploitation process for CVE-2025-24071 to perform lateral movement.
undercodetesting.com
September 29, 2025 at 4:19 AM
Unlocking Fluffy: A Deep Dive into ADCS Exploitation and CVE-2025-24071

Introduction: Active Directory Certificate Services (ADCS) presents a complex attack surface for penetration testers and a critical hardening area for defenders. The recent HackTheBox machine, Fluffy, showcases the real-world…
Unlocking Fluffy: A Deep Dive into ADCS Exploitation and CVE-2025-24071
Introduction: Active Directory Certificate Services (ADCS) presents a complex attack surface for penetration testers and a critical hardening area for defenders. The recent HackTheBox machine, Fluffy, showcases the real-world impact of combining NTLM relay techniques with ADCS misconfigurations, specifically leveraging CVE-2025-24071 and ESC16 to achieve full domain compromise. Learning Objectives: Understand the attack chain from initial NetNTLMv2 capture to domain administrator.
undercodetesting.com
September 20, 2025 at 5:07 PM
Breaking ADCS: ESC1 to ESC16 Attack Techniques

Active Directory Certificate Services (ADCS) is a prime target for attackers due to misconfigurations and misunderstood certificate templates. This article covers exploitation techniques from ESC1 to ESC16, including real-world penetration testing…
Breaking ADCS: ESC1 to ESC16 Attack Techniques
Active Directory Certificate Services (ADCS) is a prime target for attackers due to misconfigurations and misunderstood certificate templates. This article covers exploitation techniques from ESC1 to ESC16, including real-world penetration testing examples and GOAD lab scenarios. Read the full article here: Breaking ADCS: ESC1 to ESC16 Attack Techniques You Should Know: ESC1 Exploitation (Misconfigured Certificate Templates) Attackers can request a certificate with arbitrary SAN (Subject Alternative Name) for domain escalation.
undercodetesting.com
June 5, 2025 at 7:12 PM
Detecting ESC7 and ESC16 Misconfigurations in Active Directory Certificate Services with Locksmith

Source: GitHub - jakehildreth/Locksmith Active Directory Certificate Services (AD CS) is a critical component in enterprise environments, but misconfigurations can lead to severe security risks like…
Detecting ESC7 and ESC16 Misconfigurations in Active Directory Certificate Services with Locksmith
Source: GitHub - jakehildreth/Locksmith Active Directory Certificate Services (AD CS) is a critical component in enterprise environments, but misconfigurations can lead to severe security risks like ESC7 (Enterprise SubCA Certificate Template Abuse) and the newly discovered ESC16 (AD CS Relay Attack). Jake Hildreth’s Locksmith tool now includes detections for these vulnerabilities. You Should Know: 1. Understanding ESC7 & ESC16 Risks…
undercodetesting.com
May 18, 2025 at 1:20 AM
Polen singt einen schlechten Verschnitt von "i will survive" #esc16
November 13, 2024 at 9:00 AM
#esc16 oder Cover songs in a shitty way
November 13, 2024 at 9:00 AM
Zypern singt "somebody told me you have a boyfriend" gemixt mit bon jovi #esc16
November 13, 2024 at 9:00 AM