Hacking Vidhya
الذهاب إلى القناة على Telegram
We Talk about : Hacking , CTFs , Pentesting , Red & Blue Team etc. Not Allowed: Selling, Carding, Cracking Crypto.
إظهار المزيد420
المشتركون
+124 ساعات
+67 أيام
+5230 أيام
أرشيف المشاركات
❗️CrazyRDP has been seized❗️
Dutch Police Seize Thousands of Cybercrime Servers
Dutch police have seized thousands of servers in The Hague and Zoetermeer that were used exclusively for cybercrime, including ransomware, botnets, phishing, and child sexual abuse material. The hosting company involved—linked to 80 investigations since 2022—marketed itself as a “bulletproof” provider offering anonymity to criminals.
About 250 physical servers were taken on Wednesday, shutting down thousands of virtual machines. Police say the operation immediately disrupts ongoing crimes and enables further investigation of the seized data.
The action follows an international Europol-led effort, during which Dutch authorities also took down 83 servers and 20 domains tied to services like CrazyRDP. No arrests have been made.
Report Here
➡News
CACHE POISONING QUICK WIN:
Most apps validate X-Forwarded-Host as a single value.
But try this:
X-Forwarded-Host: http://legit.com, http://evil.com
• CDN: Reads first → Allows ✅
• App: Reads last → Injects
🚨Multi-target unauthenticated RCE scanner for CVE-2025-34085 affecting WordPress Simple File List plugin. Uploads, renames, and triggers PHP webshells across large target sets.
✅https://github.com/ill-deed/CVE-2025-34085-Multi-target
🔥 Free Course Alert! 🔥
Red Team Leaders ka ek dhamakedaar exam absolutely FREE me claim karo!
Bas niche wala code use karo 👇
🎟 Coupon: CCEP100OFF
🎯 Link: https://redteamleaders.coursestack.com/exams/b442ad36-44fe-4b6f-99f5-fd6f7ddbb4b4
⚡ Limited-time offer — pehle claim karo, baad me padhai shuru!
🚨 Big News, Hackers! 🚨
We’re thrilled to announce that Hacking Vidhya is now an Official Community Partner of BSides Agra 2025! 💥
BSides is one of India’s most respected cybersecurity conferences — bringing together hackers, researchers, and infosec enthusiasts from across the nation. 🇮🇳
🔗 Check out the event: https://bsidesagra.com
Stay tuned — we’ll soon share exclusive community updates, volunteer opportunities, and event highlights!
💻 Together for a Secure Future 🛡
WAF bypass for XSS can be that simple, change the request method from GET to POST.
The WAF was blocking the single quote we needed for an XSS payload, We managed to bypass by simply changing the request method from GET to POST which bypassed the WAF
New bug bounty resource 🚀
The Cache Poisoning Bible - Part 1: Advanced Fundamentals
Everything I wish I knew when I started:
• Cache key architectures
• CDN comparison guide
• Advanced detection methods
• Real-world patterns
https://medium.com/@Aacle/the-cache-poisoning-bible-part-1-advanced-fundamentals-2c8e9d7be2e9
🌐CloudRip - A tool that helps you find the real IP addresses hiding behind Cloudflare by checking subdomains. For penetration testing, security research, and learning how Cloudflare protection works.
👉https://github.com/staxsum/CloudRip
🔥 Join Our Official WhatsApp Community! 💬
Be part of the most active cybersecurity & programming group — where learners and experts share:
📘 Premium courses & materials
🧠 Daily learning resources
💻 Real bug hunting discussions
🚀 Don’t miss out — join now 👇
👉 https://chat.whatsapp.com/GmQEHhFkeEa4QjsMg2haYr?mode=wwt
