Pentester
الذهاب إلى القناة على Telegram
- Offensive Security (Red Teaming / PenTesting) - BlueTeam (OperationSec, TreatHunting, DFIR) - Reverse Engineering / Malware Analisys - Web Security
إظهار المزيد2 644
المشتركون
لا توجد بيانات24 ساعات
+77 أيام
+3030 أيام
أرشيف المشاركات
2 644
CVE-2025-32433-Erlang-OTP-SSH-RCE-PoC
The vulnerability allows an attacker with network access to an Erlang/OTP SSH server to execute arbitrary code without prior authentication.
2 644
CVE-2025-53770: SharePoint RCE (ToolShell)
Exploit: https://github.com/soltanali0/CVE-2025-53770-Exploit
Patched: July 20, 2025
#rce #pentest #redteam #ad #sharepoint #cve
2 644
CVE-2025-53770: SharePoint RCE (ToolShell)
Exploit: https://github.com/soltanali0/CVE-2025-53770-Exploit
Patched: July 20, 2025
#rce #pentest #redteam #ad #sharepoint #cve
2 644
CVE-2025-25257: Pre-Auth SQLi to RCE - Fortinet FortiWeb
PoC: https://github.com/watchtowrlabs/watchTowr-vs-FortiWeb-CVE-2025-25257
Blog: https://labs.watchtowr.com/pre-auth-sql-injection-to-rce-fortinet-fortiweb-fabric-connector-cve-2025-25257/
Affected: 7.6.0 through 7.6.3 7.4.0 through 7.4.7 7.2.0 through 7.2.10 7.0.0 through 7.0.10
2 644
CVE-2025-48799: Windows Update Service #LPE
PoC: https://github.com/Wh04m1001/CVE-2025-48799
Patched: July 8, 2025
This vulnability affects windows clients (win11/win10) with at least 2 hard drives.
2 644
CitrixBleed 2 — Citrix NetScaler Memory Leak (CVE-2025-5777)
Critical memory leak vulnerability in Citrix NetScaler ADC/Gateway. Sending malformed POST request with login parameter without value causes server to return ~127 bytes of uninitialized stack memory, including session tokens, enabling MFA bypass and active session hijacking.
Research:
https://doublepulsar.com/citrixbleed-2-electric-boogaloo-cve-2025-5777-c7f5e349d206
Source:
https://github.com/win3zz/CVE-2025-5777
2 644
CVE-2025-32463: sudo 1.9.14-1.9.17 LPE
Blog + exploit: https://www.stratascale.com/vulnerability-alert-CVE-2025-32463-sudo-chroot
Patched: June 28, 2025
2 644
CVE-2025-33073: Reflective Kerberos Relay (LPE)
Blog: https://blog.redteam-pentesting.de/2025/reflective-kerberos-relay-attack/
Auth RCE
https://www.synacktiv.com/publications/ntlm-reflection-is-dead-long-live-ntlm-reflection-an-in-depth-analysis-of-cve-2025
2 644
CVE-2025-32756: Fortinet UnAuth RCE
PoC: https://github.com/kn0x0x/CVE-2025-32756-POC
Affected Products: FortiVoice, FortiMail, FortiNDR, FortiRecorder, FortiCamera
2 644
CVE-2025-49113: Roundcube (1.6.10) Auth RCE
blog: https://fearsoff.org/research/roundcube
PoC: https://github.com/fearsoff-org/CVE-2025-49113
2 644
A library of tools for vibe coding
https://github.com/x1xhlol/system-prompts-and-models-of-ai-tools
2 644
AdaptixC2 v0.2
Adaptix is an extensible post-exploitation and adversarial emulation framework made for penetration testers. The Adaptix server is written in Golang and to allow operator flexibility. The GUI Client is written in C++ QT, allowing it to be used on Linux, Windows, and MacOS operating systems.
https://github.com/Adaptix-Framework/AdaptixC2
2 644
Regsecrets
Blog: https://www.synacktiv.com/publications/lsa-secrets-revisiting-secretsdump
Script: https://github.com/fortra/impacket/pull/1898/commits/e8f437200248b641b3baa3ce48505232287150e3
#pentest #redteam #ad #creds
2 644
A cross-platform tool for handling Active Directory Shadow Credentials/msDS-KeyCredentialLink. It supports UnPAC-the-Hash/PKINIT, Pass-the-Cert, Channel Binding and more.
https://github.com/RedTeamPentesting/keycred
2 644
Nuclei AI Prompts
Nuclei v3.3.9 has -ai option to generate and run nuclei templates on the fly in natural language.
This is a list of prompts for this option:
- sensitive data exposure
- SQLi
- XSS
- SSRF
and more
https://github.com/reewardius/Nuclei-AI-Prompts
2 644
#GitHub Entreprise Server SAML authentication bypass (CVE-2025-23369) exploit
https://github.com/hakivvi/cve-2025-23369
