Source Byte
前往频道在 Telegram
هشیار کسی باید کز عشق بپرهیزد وین طبع که من دارم با عقل نیامیزد Saadi Shirazi 187
显示更多8 336
订阅者
-124 小时
-127 天
-1330 天
帖子存档
8 337
DOM-based Extension Clickjacking: Your Password Manager Data at Risk
https://marektoth.com/blog/dom-based-extension-clickjacking/
8 337
Repost from Infosec Fortress
CVE-2025-52915: A BYOVD Evolution Story
🔗 Link
#exploitation
#av
#cve
———
🆔 @Infosec_Fortress
8 337
Repost from ARVIN
بر اساس این تحقیق بر اساس فایل لاگ مربوط به کارمند نوبیتکس با سطح دسترسی بالا و سرچ هیستوری های آن مشخص شده این کارمند تعداد زیادی اپ های کرک شده را از منابعی مثل soft98 و p30download دانلود کرده بوده
8 337
Repost from ARVIN
NEW RESEARCH: How $81M vanished from Iran's largest crypto exchange
https://akatsukilegion.netlify.app/nobitex_breach-2025
8 337
An Undocumented 64-bit Keylogger Targeting Windows Systems
https://github.com/ShadowOpCode/RustMe_Keylogger/blob/main/RustMe%20Keylogger.pdf
8 337
Repost from CyberSecurity Shield
یک روز تعطیل که ۶:۳۰ بیدار میشی منجر به تولید #مقاله میشه! یک بار برای همیشه تکلیف epp و edr و xdr رو با هم معلوم کنیم
8 337
Repost from 1N73LL1G3NC3
🧩 When too much access is not enough: a story about Confluence and tokens
During a Red Team engagement, we compromised an AWS account containing a Confluence instance hosted on an EC2 virtual machine. Although we fully compromised the machine hosting the Confluence instance, we did not have valid credentials to log in but were able to interact with the underlying database. This led us to study the structure of the Confluence database and the mechanism for generating API tokens.
P.S. Еще несколько полезных ссылок со старого канала:📜 Creating a Malicious Atlassian Plugin 🔗 Malfluence A PoC for a malicious Confluence plugin, which can access all content inside a Confluence instance, access the database directly, and execute arbitrary commands on the underlying Linux server. 📜 Stealing All of the Confluence Things 🔗 Conf-Thief A Red Team tool for exfiltrating sensitive data from Confluence pages. 🔗 AtlasReaper A command-line tool for reconnaissance and targeted write operations on Confluence and Jira instances. 🔗 Jecretz Jira Secret Hunter - Helps you find credentials and sensitive contents in Jira tickets.
8 337
Repost from Infosec Fortress
From Chrome renderer code exec to kernel with MSG_OOB
🔗 Link
#browser
#exploitation
#kernel
#linux
———
🆔 @Infosec_Fortress
8 337
Repost from APT
🛡CreateProcessAsPPL
This is a utility for running processes with Protected Process Light (PPL) protection, enabling bypass of EDR/AV solution defensive mechanisms. It leverages legitimate Windows clipup.exe functionality from System32 to create protected processes that can overwrite antivirus service executable files.
🔗 Source:
https://github.com/2x7EQ13/CreateProcessAsPPL
#av #edr #bypass #ppl
8 337
Repost from Caster
Релиз моей статьи об атаках на IPv6
Caster - Legless (БезногNM)
Genre: Offensive
Label: exploit.org
Release Date: 20 July 2025
Language: English
Performed by: Caster
Written by: Magama Bazarov
Mastered by: Magama Bazarov
Cover Edit: Magama Bazarov
https://blog.exploit.org/caster-legless
8 337
Repost from N/a
UAC Bypass Chain Leading To Silent Elevation
👾 The Presentation Video
My Blog:
https://binary-win.github.io/2025/08/22/UAC-Bypass.html
8 337
64-bit Intel Assembly Language Programming for Hackers
Lecture Notes for the DEF CON 33 Workshop
LINK
8 337
Repost from N/a
Friday, Aug 22 • 10:00 AM – 12:00 PM Google Meet joining info Video call link: https://meet.google.com/ubg-uwrt-mhg
