en
Feedback
Pentester

Pentester

Open in Telegram

- Offensive Security (Red Teaming / PenTesting) - BlueTeam (OperationSec, TreatHunting, DFIR) - Reverse Engineering / Malware Analisys - Web Security

Show more
2 644
Subscribers
No data24 hours
+77 days
+3030 days
Posts Archive
#Fortinet FortiManager Unauthenticated RCE (CVE-2024-47575) The remote code execution vulnerability in FortiManager allows attackers to perform arbitrary operations by exploiting commands via the FGFM protocol, circumventing authentication. Referred to as FortiJump, this vulnerability provides unauthorized access to FortiManager, enabling control over FortiGate devices by taking advantage of insufficient security in command handling and device registration processes. Affected Versions: FortiManager 7.6.0 FortiManager 7.4.0 through 7.4.4 FortiManager 7.2.0 through 7.2.7 FortiManager 7.0.0 through 7.0.12 FortiManager 6.4.0 through 6.4.14 FortiManager 6.2.0 through 6.2.12 FortiManager Cloud 7.4.1 through 7.4.4 FortiManager Cloud 7.2.1 through 7.2.7 FortiManager Cloud 7.0.1 through 7.0.12 FortiManager Cloud 6.4 Research: https://labs.watchtowr.com/hop-skip-fortijump-fortijumphigher-cve-2024-23113-cve-2024-47575/ Source: https://github.com/watchtowrlabs/Fortijump-Exploit-CVE-2024-47575

Python implementation of GhostPack's Seatbelt situational awareness tool https://github.com/0xthirteen/Carseat

Frida Script Runner is a versatile web-based tool designed for Android and iOS penetration testing purposes. https://github.com/z3n70/Frida-Script-Runner

Python tool to interact with WMI StdRegProv https://github.com/0xthirteen/reg_snake

Frida Script Runner - Versatile web-based tool designed for Android and iOS penetration testing purposes https://github.com/z
Frida Script Runner - Versatile web-based tool designed for Android and iOS penetration testing purposes https://github.com/z3n70/Frida-Script-Runner

Analysis of CVE-2024-26926 A Linux kernel bug in the Binder component primarily affecting Android devices labeled as EoP https://github.com/MaherAzzouzi/LinuxKernel-nday/blob/main/CVE-2024-26926/CVE_2024_26926_Analysis.pdf

ChatGPT-4o Guardrail Jailbreak: Hex Encoding for Writing CVE Exploits https://0din.ai/blog/chatgpt-4o-guardrail-jailbreak-hex-encoding-for-writing-cve-exploits

#Offensive_security "Generative AI for pentesting: the good, the bad, the ugly", 2024. https://github.com/TheR1D/shell_gpt https://github.com/morpheuslord/GPT_Vuln-analyzer

Silently Install Chrome Extension For Persistence https://syntax-err0r.github.io/Silently_Install_Chrome_Extension.html

Finding #TeamViewer 0days Part 1 - The story begins https://pgj11.com/posts/Finding-TeamViewer-0days-Part-1 Part 2 - Reversing the Authentication Protocol https://pgj11.com/posts/Finding-TeamViewer-0days-Part-2 Part 3 - Putting it all together. PARTY TIME https://pgj11.com/posts/Finding-TeamViewer-0days-Part-3

SIMurai is software that emulates a SIM card, which helps in fuzzing modem firmware for vulnerabilities or testing SIM spyware Github: https://github.com/tomasz-lisowski/simurai Paper: https://www.usenix.org/system/files/usenixsecurity24-lisowski.pdf Presentation: https://www.usenix.org/system/files/usenixsecurity24_slides-lisowski.pdf

Bounty Security Releases GBounty: Our Web Scanning Tools Are Now Open Source https://bountysecurity.ai/blogs/news/bounty-security-releases-gbounty-our-web-scanning-tools-are-now-open-source

ChatGPT_Cybersecurity.pdf11.47 MB

photo content

CVE-2024-7479 & CVE-2024-7481: TeamViewer User to Kernel LPE PoC: https://youtu.be/lUkAMAK-TPI exploit: https://github.com/PeterGabaldon/CVE-2024-7479_CVE-2024-7481

CVE-2024-47176, CVE-2024-47076, CVE-2024-47175, CVE-2024-47177: Linux OpenPrinting CUPS RCE blog: https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/ PoC: https://github.com/RickdeJager/cupshax patch: sudo systemctl stop cups-browsed sudo systemctl disable cups-browsed