en
Feedback
Pentester

Pentester

Open in Telegram

- Offensive Security (Red Teaming / PenTesting) - BlueTeam (OperationSec, TreatHunting, DFIR) - Reverse Engineering / Malware Analisys - Web Security

Show more
2 644
Subscribers
No data24 hours
+77 days
+3030 days
Posts Archive
Zimbra - Remote Command Execution (CVE-2024-45519) https://blog.projectdiscovery.io/zimbra-remote-code-execution/

How hackers can exploit Wi-Fi Captive Portals to distribute Android malware all from a smartphone using WifiPumpkin on NetHunter https://www.mobile-hacker.com/2024/09/27/wifipumpkin3-integrated-into-nethunter-powerful-duo-allows-malware-distribution-via-captive-portal/

A step-by-step guide to writing an iOS kernel exploit https://alfiecg.uk/2024/09/24/Kernel-exploit.html

Bypass #LSA protection using the BYODLL technique https://github.com/itm4n/PPLrevenant

#AI has potential to automate threat detection, transform cybersecurity https://siliconangle.com/2024/09/20/red-teaming-google-mwise2024/

Splinter: New Post-Exploitation Red Team Tool https://unit42.paloaltonetworks.com/analysis-pentest-tool-splinter

Exploiting Android Client WebViews with Help from HSTS 1-click account takeover vulnerability discovered in a popular Indonesian Android Tokopedia app https://seanpesce.blogspot.com/2024/09/exploiting-android-client-webviews-with.html

Veeam Backup & Response — RCE (CVE-2024-40711) A critical deserialization vulnerability in .NET Remoting has been discovered in Veeam Backup & Replication, allowing unauthenticated remote code execution (RCE). The flaw affects versions 12.1.2.172 and earlier. Research: https://labs.watchtowr.com/veeam-backup-response-rce-with-auth-but-mostly-without-auth-cve-2024-40711-2/ Source: https://github.com/watchtowrlabs/CVE-2024-40711

Kali Linux 2024.3 Release (Multiple transitions) | Kali Linux Blog https://www.kali.org/blog/kali-linux-2024-3-release/

Web-Check - All-in-one #OSINT tool for analysing any website https://github.com/Lissy93/web-check

Veeam Backup & Response - RCE With Auth, But Mostly Without Auth (CVE-2024-40711) https://labs.watchtowr.com/veeam-backup-response-rce-with-auth-but-mostly-without-auth-cve-2024-40711-2/

How to intercepting #Android at runtime on non-rooted devices using frida-gadget https://dispatchersdotplayground.hashnode.dev/intercepting-android-at-runtime-on-non-rooted-devices

Infiltrax - post-exploitation tool to capture screenshots, retrieve clipboard contents, log keystrokes, and install AnyDesk for persistent remote access https://github.com/alexdhital/Infiltrax

Windows Wi-Fi Driver #RCE Vulnerability - CVE-2024-30078 - Crowdfense https://www.crowdfense.com/windows-wi-fi-driver-rce-vulnerability-cve-2024-30078/

Introducing Java fuzz harness synthesis using LLMs https://blog.oss-fuzz.com/posts/introducing-java-auto-harnessing/