ӉѦСҠіИԌ ҬЄѦӍ СѦИѦL ѺҒіСіѦL DіҒԱՏіóИ
Закритий канал
1 781
Підписники
Немає даних24 години
Немає даних7 днів
Немає даних30 днів
Архів дописів
Old but very interesting book and paper :
https://fricking.ninja/DIY/index/1001%20Tutorials/
Towards_a_Sandbox_for_the_Deobfuscation_and_Dissection_of_PHP_Malware.pdf1.49 MB
#Offensive_security
1. Vulnerable WordPress plugins
https://github.com/onhexgroup/Vulnerable-WordPress
2. C/C++ snippets for specific offensive scenarios
https://github.com/lsecqt/OffensiveCpp
#Red_Team_Tactics
1. Meterpreter vs Modern EDR(s)
https://redops.at/en/blog/meterpreter-vs-modern-edrs-in-2023
2. Abusing Reddit API To Host The C2 Traffic
https://github.com/kleiton0x00/RedditC2
#exploit
1. CVE-2022-46697:
Out-of-bounds access in IOMobileFrameBuffer
https://github.com/antoniozekic/Proof-of-concepts/tree/main/CVE-2022-46697
2. CVE-2022-38053, CVE-2023-21742, CVE-2023-21717:
SharePoint Webpart Property Traversal
https://testbnull.medium.com/ph%C3%A2n-t%C3%ADch-l%E1%BB%97-h%E1%BB%95ng-sharepoint-webpart-property-traversal-cve-2022-38053-cve-2023-21742-bc6931698a5f
3. CVE-2023-23398:
Microsoft Excel Spoofing
https://packetstormsecurity.com/files/171752/Microsoft-Excel-Spoofing.html
#Threat_Research
MERCURY/DEV-1084: Destructive attack on hybrid environment
https://www.microsoft.com/en-us/security/blog/2023/04/07/mercury-and-dev-1084-destructive-attack-on-hybrid-environment
#tools
1. Awesome Bug Bounty Tools
https://github.com/vavkamil/awesome-bugbounty-tools
2. Bug Bounty Beginner's Roadmap
https://github.com/bittentech/Bug-Bounty-Beginner-Roadmap
Android Penetration Testing Cheat Sheet
https://github.com/ivan-sincek/android-penetration-testing-cheat-sheet
iOS Penetration Testing Cheat Sheet
https://github.com/ivan-sincek/ios-penetration-testing-cheat-sheet
Python parser for #Cobalt_Strike stagers
Use parse_stager_config.py to search a file for Cobalt Strike stager shellcode. If shellcode is found, it will be extracted in JSON format.
https://github.com/stairwell-inc/cobalt-strike-stager-parser
#Cobalt_Strike
It's just un implementation of in-house CoffLoader supporting #CobaltStrike standard BOF and BSS initialized variables.
Look at the main.c file to change the BOF and its parameters. CobalStrike handles the BOF parameter in a special way, the Arg structure is here to pass parameters easier.
https://github.com/OtterHacker/CoffLoader
📧 BULK PHP Mailer (NON SMTP) 📧
✔️Custom From Email Address
✔️Custom From Name
✔️Reply-To Address Support
✔️Email Subject
✔️Bulk Emails Sendout
✔️Email Body (You can build your letters in it - like adding headings, blocks, aligns)
✔️Custom HTML
❗️Sender can be uploaded on C-Panels and you can send out.
