ru
Feedback
Peneter Tools

Peneter Tools

Открыть в Telegram

https://blog.peneter.com @Peneter_News @Peneter_Media @Peneter_Tools https://www.youtube.com/channel/UCewDE8winhc8DSPFnpSksTA برای ارتباط با بنده به توییتر پیغام ارسال کنید https://twitter.com/soheilhashemii https://twitter.com/5tuxnet

Больше
Страна не указанаКатегория не указана
256
Подписчики
+124 часа
+127 дней
+4830 дней
Архив постов
The sources of the Linux kernel exploitation technique called DirtyCred are now on GitHub. The attack, which was presented at Black Hat 2022 security conference, is a kernel exploitation concept that swaps unprivileged kernel credentials with privileged ones to escalate privileges without overwriting any critical data on the kernel heap. https://github.com/Markakd/DirtyCred #LPE

Security researchers discovered 3 vulnerabilities in the Linux kernel that could allow a local attacker to elevate privileges and potentially execute malicious code. The proof-of-concept code is publicly available increasing the likelihood of exploitation in the wild. https://github.com/greek0x0/2022-LPE-UAF https://zplin.me/papers/DirtyCred-Zhenpeng.pdf #LPE

Zimbra RCE simple poc https://github.com/vnhacker1337/CVE-2022-27925-PoC #Zimbra #RCE

TOP All bugbounty pentesting CVE-2022- POC Exp RCE example payload Things https://github.com/hktalent/TOP #bugbounty

Sandman is a NTP based backdoor for red team engagements in hardened networks. https://github.com/Idov31/Sandman #NTP #backdoor

Parameter miner for zap https://github.com/zaproxy/zap-extensions #bugbounty

This repository contains de materials for the talk "Exploring the hidden attack surface of OEM IoT devices: pwning thousands of routers with a vulnerability in Realtek’s SDK for eCos OS.", which was presented at DEFCON30. https://github.com/infobyte/cve-2022-27255 #Realtek #eCos

An automatic unpacker and logger for DotNet Framework targeting files! This tool has been unveiled at Black Hat USA 2022. https://github.com/advanced-threat-research/DotDumper #unpacker #DotNet

A Python script to exploit CVE-2022-36446 Software Package Updates RCE (Authenticated) on Webmin < 1.997 for mitigation Update to Webmin >= 1.997 https://github.com/p0dalirius/CVE-2022-36446-Webmin-Software-Package-Updates-RCE #webmin #rce

JMX enumeration and attacking tool https://github.com/qtc-de/beanshooter

PersistAssist is a fully modular persistence framework written in C#. All persistence techniques contain a cleanup method which will server to remove the persistence aside from the persistence code. This is a WIP so there are many empty classes, the main object of this project initially was to build out a fully modular framework meant to make adding new features as simple as inheriting a class and adding the code. https://github.com/FortyNorthSecurity/PersistAssist

This script allows to find MySQLi vulnerabilities Based on Errors with nuclei https://github.com/HernanRodriguez1/ScanMySQLiErrorBased-Nuclei

Powershell script that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines. https://github.com/last-byte/PersistenceSniper/

Linux kernel through 5.18.9 LPE POC: https://github.com/veritas501/CVE-2022-34918 #Linux #Kernel #LPE