Low Orbit Security's Avatar

Low Orbit Security

@loworbitsec.bsky.social

Tailored Security Solutions

14 Followers  |  2 Following  |  10 Posts  |  Joined: 27.12.2024  |  1.7416

Latest posts by loworbitsec.bsky.social on Bluesky

Post image

6. This could be you running gubble....

01.01.2025 18:53 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

5. With Gubble you can easily identify these threats (or opportunities if you're on the offensive security side of things)

01.01.2025 18:53 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

4. In this example, anyone in the organization can send messages from the security group. This can be used for internal phishing.

If a threat actor can post as security@<yourorganization>.com, they can send out extremely successful internal phishing emails

01.01.2025 18:53 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

3. Or how about finding a group called CLOUD_ADMINS that anyone in your organization can join?

Who knows what level of access being in this group would give an attacker.

01.01.2025 18:53 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

2. Gubble finds overly permissive group like this HR one that exposes highly sensitive information.

01.01.2025 18:53 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

1. Are you sure your your sensitive Groups are locked down?

In this example everyone in the domain can view the conversations of the HR Group.

01.01.2025 18:53 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
GitHub - LowOrbitSecurity/gubble: gubble is a tool designed to audit Google Workspace group settings. It analyzes settings such as who can join, view membership, post messages, view conversations, and... gubble is a tool designed to audit Google Workspace group settings. It analyzes settings such as who can join, view membership, post messages, view conversations, and more to help identify potentia...

Happy new year! Gubble is out now!

Gubble is a tool that queries the Workspace API to analyze Group permissions to identify potential security risks, allowing both offensive and defensive teams to programmatically identify risky permissions.

github.com/LowOrbitSecu...

01.01.2025 18:53 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 1
Post image

Gubble is coming out this week. Here is a sneak peek of some tools I created to help test it. What could this be for πŸ€”

29.12.2024 12:08 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 2
Post image

Soon.

27.12.2024 13:17 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

# ---- LOW ORBIT SECURITY ----
# <<INCOMING TRANSMISSION>>

# Objectives: Tailored Security Solutions,
# Research, Tooling
# Date: <Unknown>

# ---- :WQ ----

27.12.2024 13:17 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@loworbitsec is following 2 prominent accounts