uz
Feedback
Pentester

Pentester

Kanalga Telegram’da o‘tish

- Offensive Security (Red Teaming / PenTesting) - BlueTeam (OperationSec, TreatHunting, DFIR) - Reverse Engineering / Malware Analisys - Web Security

Ko'proq ko'rsatish
2 644
Obunachilar
Ma'lumot yo'q24 soatlar
+77 kunlar
+3030 kunlar
Postlar arxiv

SANS-OO-Pen-Testing-0725.pdf2.28 MB

photo content
+1

CVE-2025-32433-Erlang-OTP-SSH-RCE-PoC The vulnerability allows an attacker with network access to an Erlang/OTP SSH server to execute arbitrary code without prior authentication.

CVE-2025-53770: SharePoint RCE (ToolShell) Exploit: https://github.com/soltanali0/CVE-2025-53770-Exploit Patched: July 20, 2025 #rce #pentest #redteam #ad #sharepoint #cve

CVE-2025-53770: SharePoint RCE (ToolShell) Exploit: https://github.com/soltanali0/CVE-2025-53770-Exploit Patched: July 20, 2025 #rce #pentest #redteam #ad #sharepoint #cve

CVE-2025-25257: Pre-Auth SQLi to RCE - Fortinet FortiWeb PoC: https://github.com/watchtowrlabs/watchTowr-vs-FortiWeb-CVE-2025-25257 Blog: https://labs.watchtowr.com/pre-auth-sql-injection-to-rce-fortinet-fortiweb-fabric-connector-cve-2025-25257/
Affected: 7.6.0 through 7.6.3 7.4.0 through 7.4.7 7.2.0 through 7.2.10 7.0.0 through 7.0.10

CVE-2025-48799: Windows Update Service #LPE PoC: https://github.com/Wh04m1001/CVE-2025-48799 Patched: July 8, 2025 This vulnability affects windows clients (win11/win10) with at least 2 hard drives.

CitrixBleed 2 — Citrix NetScaler Memory Leak (CVE-2025-5777) Critical memory leak vulnerability in Citrix NetScaler ADC/Gateway. Sending malformed POST request with login parameter without value causes server to return ~127 bytes of uninitialized stack memory, including session tokens, enabling MFA bypass and active session hijacking. Research: https://doublepulsar.com/citrixbleed-2-electric-boogaloo-cve-2025-5777-c7f5e349d206 Source: https://github.com/win3zz/CVE-2025-5777

CVE-2025-32463: sudo 1.9.14-1.9.17 LPE Blog + exploit: https://www.stratascale.com/vulnerability-alert-CVE-2025-32463-sudo-ch
CVE-2025-32463: sudo 1.9.14-1.9.17 LPE Blog + exploit: https://www.stratascale.com/vulnerability-alert-CVE-2025-32463-sudo-chroot Patched: June 28, 2025

CVE-2025-32756: Fortinet UnAuth RCE PoC: https://github.com/kn0x0x/CVE-2025-32756-POC
Affected Products: FortiVoice, FortiMail, FortiNDR, FortiRecorder, FortiCamera

AdaptixC2 v0.2 Adaptix is an extensible post-exploitation and adversarial emulation framework made for penetration testers. The Adaptix server is written in Golang and to allow operator flexibility. The GUI Client is written in C++ QT, allowing it to be used on Linux, Windows, and MacOS operating systems. https://github.com/Adaptix-Framework/AdaptixC2

A cross-platform tool for handling Active Directory Shadow Credentials/msDS-KeyCredentialLink. It supports UnPAC-the-Hash/PKINIT, Pass-the-Cert, Channel Binding and more. https://github.com/RedTeamPentesting/keycred

Nuclei AI Prompts Nuclei v3.3.9 has -ai option to generate and run nuclei templates on the fly in natural language. This is a
Nuclei AI Prompts Nuclei v3.3.9 has -ai option to generate and run nuclei templates on the fly in natural language. This is a list of prompts for this option: - sensitive data exposure - SQLi - XSS - SSRF and more https://github.com/reewardius/Nuclei-AI-Prompts

#GitHub Entreprise Server SAML authentication bypass (CVE-2025-23369) exploit https://github.com/hakivvi/cve-2025-23369