Hacking Vidhya
الذهاب إلى القناة على Telegram
We Talk about : Hacking , CTFs , Pentesting , Red & Blue Team etc. Not Allowed: Selling, Carding, Cracking Crypto.
إظهار المزيد385
المشتركون
-124 ساعات
+27 أيام
+2330 أيام
أرشيف المشاركات
🚨 CVE-2025-55177 & CVE-2025-43300: WhatsApp 0-Click Crash
CVE-2025-43300 GitHub: https://github.com/DarkNavySecurity/PoC/tree/main/CVE-2025-43300
‼️👉 OpenAI monitors ChatGPT chats – can report users to the police
OpenAI has quietly begun monitoring users' ChatGPT conversations and can report content to law enforcement agencies.
The revelation came after incidents in which AI chatbots were linked to self-harming behavior, delusions, hospitalizations, and suicide – what experts refer to as “AI psychosis.”
In a blog post, the company admits to systematically scanning users' messages. If the system detects users who want to harm others, the conversations are forwarded to a review team that can suspend accounts and notify the police.
“If human reviewers determine that a case poses an immediate risk of serious physical harm to others, we may refer it to law enforcement,” OpenAI writes. ..."
🚨 Vulnerable Parameter:
?dest=
Used for post-login redirects, dest can be dangerous if not properly validated. Example:
https://www.reddit.com/login/?dest=/protected/resourceLegit flow, right? But what if we replace the value with:
dest=javascript:alert(document.domain)Boom. The browser executes the JS instead of redirecting. No encoding, no obfuscation — just pure client-side execution via open redirect. 🎯 This can be used in phishing, bypassing login flows, or chaining with other bugs. Always validate redirect destinations on the server. 🧠 Simple bug. Big impact. https://t.me/Hacking_Vidhya
+2
👾 #Latrodectus C2 domains (active):
alfryudabikuta[.]com
faryshopkleyskipi[.]com
dorevilokpadjghs[.]com
fadoklismokley[.]com
gasrobariokley[.]com
jojikloertoys[.]com
sistoronykastadro[.]com
adsqwiolkuerkom[.]com
doskaevriakjoilo[.]com
ganstopliomalifas[.]com
laghuirtinosdek[.]com
lounfaslkijsdf[.]com
sisadfriolkdle[.]com
darklousdirupas[.]com
dlinofinopasster[.]com
basokilometrsdo[.]com
kutakdokliurio[.]com
blaksdioklery[.]com
sigdalokanolkas[.]com
lilikutliputsdf[.]com
hdflksgreklams[.]com
kwjfalvalkloun[.]com
fikysandroisder[.]com
kasldericoname[.]com
lalasisifuryglap[.]com
dasrilkosdirosado[.]com
kwestgidokudiojek[.]com
asakusubinitohas[.]com
signamoykloysd[.]com
djkloyfarelbister[.]com
↳ Bypassing Cloudflare's Turnstile CAPTCHA With thermoptic
• Github
• You can also use FlareSolverr too
#infosec #cybersecurity #bugbounty
➯ Share & Support Us
🙏 Thank You for Joining Our WiFi Pentesting Webinar! 🙏
We’d love to hear your thoughts 💡
👉 Share your feedback & topic suggestions in our WhatsApp group:
🔗 https://chat.whatsapp.com/ES6N2CXl4tkIvKNMUNAv4h
🎥 Recording Update:
The official webinar recording will be available within a week. We’ll upload it and share the link directly with you.
⚠️ Kindly do not upload raw/self-recorded versions of the session. Since our speakers provide valuable client PoCs & real-world knowledge, we request you to respect their work. Unauthorized uploads may lead to action.
Thank you for your support and cooperation 🙌
— Team Hacking Vidhya
🚨 WiFi Pentesting Webinar is LIVE! 🚨
We’re starting now — don’t miss it! 🎯
👉 Join here: https://meet.google.com/hmc-rbsm-fyr
🧩Cybersecurity Quiz
An event signaling an IDS to produce an alarm when no attack has taken place would be classified as which of the following?
A. False Positive
B. False Negative
C. True Negative
D. True Positive
AI-Powered OSINT: Email/Username Lookup + Face Matching
Watch how you can verify identities using just two inputs:
- Discover all linked accounts
- Cross-check information across profiles
- Match faces from extracted photos
- Generate an editable intelligence report
Cutting-edge investigations 👌
Google Dork - APIs Endpoints ⚙️
site:example[.]com inurl:api | site:*/rest | site:*/v1 | site:*/v2 | site:*/v3
Find hidden APIs, try techniques 👨💻
+1
Hey Hunter's,
just look at this one crazy boolean SQLi.
Tip: never forget to test boolean SQLi even it is a .json file parameterSometimes .json files load SQLi. So, it's not necessary that only php file parameters we hunt. #sqli #bugbountytips
