ar
Feedback
Hacking Vidhya

Hacking Vidhya

الذهاب إلى القناة على Telegram

We Talk about : Hacking , CTFs , Pentesting , Red & Blue Team etc. Not Allowed: Selling, Carding, Cracking Crypto.

إظهار المزيد
385
المشتركون
-124 ساعات
+27 أيام
+2330 أيام
أرشيف المشاركات
🚨 CVE-2025-55177 & CVE-2025-43300: WhatsApp 0-Click Crash CVE-2025-43300 GitHub: https://github.com/DarkNavySecurity/PoC/tree/main/CVE-2025-43300

‼️👉 OpenAI monitors ChatGPT chats – can report users to the police OpenAI has quietly begun monitoring users' ChatGPT conversations and can report content to law enforcement agencies. The revelation came after incidents in which AI chatbots were linked to self-harming behavior, delusions, hospitalizations, and suicide – what experts refer to as “AI psychosis.” In a blog post, the company admits to systematically scanning users' messages. If the system detects users who want to harm others, the conversations are forwarded to a review team that can suspend accounts and notify the police. “If human reviewers determine that a case poses an immediate risk of serious physical harm to others, we may refer it to law enforcement,” OpenAI writes. ..."

🚨 Vulnerable Parameter: ?dest= Used for post-login redirects, dest can be dangerous if not properly validated. Example: http
🚨 Vulnerable Parameter: ?dest= Used for post-login redirects, dest can be dangerous if not properly validated. Example:
https://www.reddit.com/login/?dest=/protected/resource
Legit flow, right? But what if we replace the value with:
dest=javascript:alert(document.domain)
Boom. The browser executes the JS instead of redirecting. No encoding, no obfuscation — just pure client-side execution via open redirect. 🎯 This can be used in phishing, bypassing login flows, or chaining with other bugs. Always validate redirect destinations on the server. 🧠 Simple bug. Big impact. https://t.me/Hacking_Vidhya

👾 #Latrodectus C2 domains (active): alfryudabikuta[.]com faryshopkleyskipi[.]com dorevilokpadjghs[.]com fadoklismokley[.]com
+2
👾 #Latrodectus C2 domains (active): alfryudabikuta[.]com faryshopkleyskipi[.]com dorevilokpadjghs[.]com fadoklismokley[.]com gasrobariokley[.]com jojikloertoys[.]com sistoronykastadro[.]com adsqwiolkuerkom[.]com doskaevriakjoilo[.]com ganstopliomalifas[.]com laghuirtinosdek[.]com lounfaslkijsdf[.]com sisadfriolkdle[.]com darklousdirupas[.]com dlinofinopasster[.]com basokilometrsdo[.]com kutakdokliurio[.]com blaksdioklery[.]com sigdalokanolkas[.]com lilikutliputsdf[.]com hdflksgreklams[.]com kwjfalvalkloun[.]com fikysandroisder[.]com kasldericoname[.]com lalasisifuryglap[.]com dasrilkosdirosado[.]com kwestgidokudiojek[.]com asakusubinitohas[.]com signamoykloysd[.]com djkloyfarelbister[.]com

☄️Photon - Fast web crawler for osint and recon 🚀https://github.com/s0md3v/Photon
☄️Photon - Fast web crawler for osint and recon 🚀https://github.com/s0md3v/Photon

Bypassing Cloudflare's Turnstile CAPTCHA With thermoptic Github You can also use FlareSolverr too #infosec #cybersecurity #bugbounty ➯ Share & Support Us

🙏 Thank You for Joining Our WiFi Pentesting Webinar! 🙏 We’d love to hear your thoughts 💡 👉 Share your feedback & topic suggestions in our WhatsApp group: 🔗 https://chat.whatsapp.com/ES6N2CXl4tkIvKNMUNAv4h 🎥 Recording Update: The official webinar recording will be available within a week. We’ll upload it and share the link directly with you. ⚠️ Kindly do not upload raw/self-recorded versions of the session. Since our speakers provide valuable client PoCs & real-world knowledge, we request you to respect their work. Unauthorized uploads may lead to action. Thank you for your support and cooperation 🙌 — Team Hacking Vidhya

🚨 WiFi Pentesting Webinar is LIVE! 🚨 We’re starting now — don’t miss it! 🎯 👉 Join here: https://meet.google.com/hmc-rbsm-fyr

blind RCE payload + sleep ;if [  $( whoami | cut -c 1) = "d" ]; then sleep 10; fi

🧩Cybersecurity Quiz An event signaling an IDS to produce an alarm when no attack has taken place would be classified as which of the following? A. False Positive B. False Negative C. True Negative D. True Positive

AI-Powered OSINT: Email/Username Lookup + Face Matching Watch how you can verify identities using just two inputs: - Discover all linked accounts - Cross-check information across profiles - Match faces from extracted photos - Generate an editable intelligence report Cutting-edge investigations 👌

Google Dork - APIs Endpoints ⚙️ site:example[.]com inurl:api | site:*/rest | site:*/v1 | site:*/v2 | site:*/v3 Find hidden AP
Google Dork - APIs Endpoints ⚙️ site:example[.]com inurl:api | site:*/rest | site:*/v1 | site:*/v2 | site:*/v3 Find hidden APIs, try techniques 👨‍💻

140 #CRUNCHYROLL.txt0.05 KB

Hey Hunter's, just look at this one crazy boolean SQLi. Tip: never forget to test boolean SQLi even it is a .json file parame
+1
Hey Hunter's, just look at this one crazy boolean SQLi.
Tip: never forget to test boolean SQLi even it is a .json file parameter
Sometimes .json files load SQLi. So, it's not necessary that only php file parameters we hunt. #sqli #bugbountytips