en
Feedback
Pentester

Pentester

Open in Telegram

- Offensive Security (Red Teaming / PenTesting) - BlueTeam (OperationSec, TreatHunting, DFIR) - Reverse Engineering / Malware Analisys - Web Security

Show more
2 644
Subscribers
No data24 hours
+77 days
+3030 days
Posts Archive

#Mobile_Security Black Hat USA 2024: "The Way to Android Root: Exploiting Your GPU on Smartphone (CVE-2024-23380)".

CVE-2024-38856_Scanner: Apache OFBiz RCE Scanner & Exploit (CVE-2024-38856) https://github.com/securelayer7/CVE-2024-38856_Scanner

CVE-2024-38077: Windows Remote Desktop Licensing Service RCE https://github.com/CloudCrowSec001/CVE-2024-38077-POC

Leaked Wallpaper This is a privilege escalation tool (fixed with CVE-2024-38100 in KB5040434) that allows us to leak a user's NetNTLM hash from any session on the computer, even if we are working from a low-privileged user. https://github.com/MzHmO/LeakedWallpaper

Customizable Linux Persistence Tool for Security Research and Detection Engineering https://github.com/Aegrah/PANIX
Customizable Linux Persistence Tool for Security Research and Detection Engineering https://github.com/Aegrah/PANIX

Vulnerability in Telegram for Android: Use-after-free in Connection::onReceivedData https://bugs.chromium.org/p/project-zero/issues/detail?id=2547

A Pwn2Own #SpiderMonkey JIT Bug: From Integer Range Inconsistency to Bound Check Elimination then RCE CVE-2024-29943 https://github.com/bjrjk/CVE-2024-29943

Breaking Custom Encryption Using Frida (Mobile Application Pentesting) https://labs.cognisys.group/posts/Breaking-Custom-Ecryption-Using-Frida-Mobile-Application-pentesting/

CVE-2024-30088: Windows LPE PATCHED: June 11, 2024 https://github.com/tykawaii98/CVE-2024-30088

Progressive phishing: How PWAs can be used to steal passwords https://www.kaspersky.com/blog/phishing-with-progressive-web-apps/51496/

"Becoming a Vulnerability Researcher roadmap: my personal experience" https://gist.github.com/tin-z/a469e996f8107a5ca8d3c858a2a4b65f

CVE-2024-4577 - Yet Another PHP RCE: Make PHP-CGI Argument Injection Great Again! https://blog.orange.tw/2024/06/cve-2024-4577-yet-another-php-rce.html https://github.com/TAM-K592/CVE-2024-4577

A Frida-focused GPT to help reverse engineers in writing Frida scripts and using Frida Python bindings. https://chatgpt.com/g/g-KwZVA8dTp-fridagpt

CCTV Close-Circuit Telegram Vision revolutionizes location tracking with its open-source design and Telegram API integration. Offering precise tracking within 50-100 meters, users can monitor others in real-time for logistics or safety, redefining how we navigate our surroundings. https://github.com/IvanGlinkin/CCTV

CVE-2024-24919: Check Point arbitrary file read (as root) https://labs.watchtowr.com/check-point-wrong-check-point-cve-2024-24919/