996
Підписники
Немає даних24 години
Немає даних7 днів
Немає даних30 днів
Архів дописів
996
Repost from .....
🔸CVE-2023-27524 , CVE-2023-39265 , CVE-2023-37941 : Apache Superset - Remote Code Execution , Credential Harvesting & More (Disclosed)
✅Blog : https://www.horizon3.ai/apache-superset-part-ii-rce-credential-harvesting-and-more/
📱@APTIRAN
996
🙂CVE-2023-3959, CVE-2023-4249 - Multiple critical vulnerabilities in Zavio IP cameras
ℹ️Blog : https://bugprove.com/knowledge-hub/cve-2023-3959-cve-2023-4249-multiple-critical-vulnerabilities-in-zavio-ip-cameras/
⛔#Exploit , #POC , #Analysis , #Vulnerability , #CVE
❤@APTANALYSIS
996
📔IIS Range
⭐️Attacking Secondary Contexts in Web Applications
🗣️https://docs.google.com/presentation/d/1N9Ygrpg0Z-1GFDhLMiG3jJV6B_yGqBk8tuRWO1ZicV8/mobilepresent?slide=id.p
🥸Exploiting __VIEWSTATE knowing the secrets
🔤https://book.hacktricks.xyz/pentesting-web/deserialization/exploiting-__viewstate-knowing-the-secret
🔤https://soroush.me/blog/2019/04/exploiting-deserialisation-in-asp-net-via-viewstate/
📌shortscan : filename enumeration tool
🕹️https://github.com/bitquark/shortscan
⛔#Tools , #IIS , #Exploiting
❤@APTANALYSIS
996
1️⃣Mshikaki
Mshikaki is a shellcode injection tool designed to bypass AMSI (Antimalware Scan Interface). It leverages the QueueUserAPC() injection technique and offers support for XOR encryption, making it a powerful tool for security researchers and penetration testers.⭐️Link : https://github.com/trevorsaudi/Mshikaki 2️⃣PySQLRecon
Offensive MSSQL toolkit written in Python, based off SQLRecon⭐️Link : https://github.com/Tw1sm/PySQLRecon 3️⃣EDRSandblast-GodFault
EDRSandBlast is a tool written in C that weaponize a vulnerable signed driver to bypass EDR detections (Notify Routine callbacks, Object Callbacks and ETW TI provider) and LSASS protections. Multiple userland unhooking techniques are also implemented to evade userland monitoring.⭐️Link : https://github.com/gabriellandau/EDRSandblast-GodFault 4️⃣PPLBlade
Protected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk.
⭐️Link : https://github.com/tastypepperoni/PPLBlade
⛔#Tools , #Offensive ,#RedTeam
❤@APTANALYSIS996
🌟Make KSMA Great Again , The Art of Rooting Android
devices by GPU MMU features
🌎https://i.blackhat.com/BH-US-23/Presentations/US-23-WANG-The-Art-of-Rooting-Android-devices-by-GPU-MMU-features.pdf
⛔#Pdf ,#Blackhat
❤@APTANALYSIS
996
😠CVE-2023-39362 : Cacti v1.2.24 - Authenticated command injection
POC : https://github.com/m3ssap0/cacti-rce-snmp-options-vulnerable-application
Blog : https://m3ssap0.github.io/articles/cacti_authenticated_command_injection_snmp.html
⛔#Exploit , #POC , #Analysis , #rce , #cacti
❤@APTANALYSIS
996
Repost from .....
🔥CVE-2023-4634 : Wordpress Plugins Media-Library-Assistan < 3.10 - Unauthenticated LFI / Remote Code Execution
👩💻 POC : https://github.com/Patrowl/CVE-2023-4634
🐈⬛NIST : https://nvd.nist.gov/vuln/detail/CVE-2023-4634
✔️ Blog : https://patrowl.io/blog-wordpress-media-library-rce-cve-2023-4634/
📱@APTIRAN
996
😠Hiew External Module (HEM) to calculate CRC-32, MD5, SHA-1, and SHA-256 hashes of a given file/block
⭐️Repo : https://github.com/merces/hem-hashes
⛔#malware_analysis , #hem , #hexeditor , #hiew
❤@APTANALYSIS
996
⭐️Hot list
💎CVE-2023-26469 : Jorani 1.0.0 - Remote Code Execution
⭐️Yaml : https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-26469.yaml
⭐️POC : https://github.com/d0rb/CVE-2023-26469/blob/main/PoC.py
💎CVE-2023-4596 : WordPress plugin Forminator - unauthenticated Remote Command Execution
⭐️POC : https://github.com/E1A/CVE-2023-4596
⭐️Yaml : https://github.com/projectdiscovery/nuclei-templates/pull/8118/files
💎CVE-2023–28072: Local Privilege Escalation in Alienware Command Center
⭐️Blog : https://medium.com/@matterpreter/cve-2023-28072-local-privilege-escalation-in-alienware-command-center-a836607762ba
💎CVE-2023-36281 : langchain v.0.0.171 - Remote Code Execution
⭐️POC : https://github.com/tagomaru/CVE-2023-36281
💎CVE-2023-28229 : Windows CNG Key Isolation Service Elevation of Privilege
⭐️POC : https://github.com/Y3A/CVE-2023-28229
⭐️Blog : https://whereisk0shl.top/post/isolate-me-from-sandbox-explore-elevation-of-privilege-of-cng-key-isolation
⛔#Exploit , #POC , #Analysis , #Vulnerability , #CVE
❤@APTANALYSIS
996
😮Has the dark side of artificial intelligence been able to produce and broadcast p•rn videos with people's faces? It is strange!!!
⛓Related news: Link
⛔#News , #Strange
❤@APTANALYSIS
996
⭐️CVE-2023-37895: Apache Jackrabbit RMI RCE
➡️Blog : https://y4er.com/posts/cve-2023-37895-apache-jackrabbit-rmi-rce/
⭐️Original | A brief discussion on Apache and CVE-2023-20860
➡️Blog : https://mp.weixin.qq.com/s?__biz=MzAwMDQwNTE5MA==&mid=2650246963&idx=2&sn=c57210c9eb8fcb5551f595893daa8c78&chksm=82ea549ab59ddd8c76938a75fc2c8c6d7fa954674307ea96943276fb66bfb24e3a61d83b954c&scene=0&xtrack=1#rd
⛔#Apache , #RCE , #Analysis , #Vulnerability , #CVE
❤@APTANALYSIS
996
🤔CVE-2023-38831: WinRAR Bug Or Windows Feature? In-Depth Analysis of Winrar Vulnerability
🗣️https://aleeamini.com/cve-2023-38831-winrar-bug-or-windows-feature/
⛔#shell , #winrar , #Analysis
❤@APTANALYSIS
996
⭐️CVE-2023-4696 : Account Takeover at usememos
⭐️ Link : https://www.youtube.com/watch?v=wV1RPv-ezc4
⛔#Hunting
❤@APTANALYSIS
996
Repost from .....
🔥🔥🔥CVE-2023-34039 : VMWare Aria Operations for Networks (vRealize Network Insight) Static SSH key Remote Code Execution
🟢POC : https://github.com/sinsinology/CVE-2023-34039
📱@APTIRAN
996
⚠️Diving Deep into UNC4841 Operations Following Barracuda ESG Zero-Day Remediation (CVE-2023-2868)
⚠️CVE-2023-38831 Detection: UAC-0057 Group Exploits a WinRAR Zero-Day to Spread a PicassoLoader Variant and CobaltStrike Beacon via Rabbit Algorithm
⚠️Hackers Exploit Openfire Vulnerability To Deploy Kinsing Malware
⛔#ANALYSIS , #NEWS
❤@APTANALYSIS
996
☕️Redirect bypasses for Open Redirect & SSRF!
?u=example2\.com ➡️ ❎
?u=example\.com@example2\.com ➡️ ✅
⛔#Bugbounty
📱@APTANALYSIS
996
👩💻netfilter: nf_tables: prevent OOB access in nft_byteorder_eval(Exploited on Pwn2Own, CVE-2023-35001)
🟥Kernel : https://lore.kernel.org/netfilter-devel/20230705121515.747251-1-cascardo@canonical.com/T/
🫥Exp : https://github.com/synacktiv/CVE-2023-35001
⛔#Exp , #POC , #CVE , #Kernel , #Vulnerability
📱@APTANALYSIS
996
😊Converting Tokens to Session Cookies for Outlook Web Application
⭐️https://labs.lares.com/owa-cap-bypass
⛔#Outlook , #Bypass , #Token
📱@APTANALYSIS
996
👩💻NetNTLMv1 Downgrade to compromise
🐈Blog : https://www.r-tec.net/r-tec-blog-netntlmv1-downgrade-to-compromise.html
⛔#RedTeam , #Offensive , #Attacks
📱@APTANALYSIS
996
🔥Supernova (Shellcode Encryptor)
➡️Repo : https://github.com/nickvourd/Supernova
⛔#shellcode , #Encrypt
📱@APTANALYSIS
