uz
Feedback
Pentester world 2.0

Pentester world 2.0

Kanalga Telegram’da oβ€˜tish

⚠️ DISCLAIMER :- πšƒπ™·π™Έπš‚ 𝙲𝙷𝙰𝙽𝙽𝙴𝙻 π™³π™Ύπ™΄πš‚ π™½π™Ύπšƒ π™Ώπšπ™Ύπ™Όπ™Ύπšƒπ™΄ π™°π™½πšˆ 𝙸𝙻𝙻𝙴𝙢𝙰𝙻 π™°π™²πšƒπ™Έπš…π™Έπšƒπ™Έπ™΄πš‚ , π™Έπšƒπš‚ π™Ήπš„πš‚πšƒ π™΅π™Ύπš π™΅πš„π™½ 𝙰𝙽𝙳 π™΄π™³πš„π™²π™°πšƒπ™Έπ™Ύπ™½π™°π™» π™Ώπš„πšπ™Ώπ™Ύπš‚π™΄ πŸ˜‡ Welcome pentester world in this group you

Ko'proq ko'rsatish
596
Obunachilar
+724 soatlar
+407 kun
+14430 kun
Postlar arxiv
Android DeviceVersionFragment.java Privilege Escalation Exploit for Pixel Watch (CVE-2023-48418) https://0day.today/exploit/description/39237

Analysis of iOS Info Stealer malware distributed via phishing website https://medium.com/@icebre4ker/analysis-of-an-info-stealer-chapter-2-the-ios-app-0529e7b45405

Portable Flipper Zero detector Now you can detect any Flipper Zeros and BLE advertisement spam attacks in vicinity using Android Bluetooth LE Spam app https://www.mobile-hacker.com/2024/01/09/how-to-detect-flipper-zero-and-bluetooth-advertisement-attacks/

MyEstatePoint Property Search app leaked data on nearly half a million of its users, exposing their names and plain-text passwords https://cybernews.com/security/myestatepoint-property-search-app-data-leak/

A PoC for the CVE-2023-32530, for iOS/MacOS from Operation Triangulation discovered by Kaspersky - Tested on: iOS 16.3, 16.3.1, 16.4 and 16.5 (iPhone 14 Pro Max) and macOS 13.1 and 13.4 (MacBook Air M2 2022) - Fixed in iOS 16.5.1 and macOS 13.4.1 https://github.com/felix-pb/kfd/blob/main/writeups/smith.md

Path traversal to RCE in Android β€” Mobile Hacking Lab β€˜Document Viewer’ write-up https://ajmal-moochingal.medium.com/path-traversal-to-rce-in-android-mobile-hacking-lab-document-viewer-write-up-ef9226aea1ac

Frida Android Helper: Several handy commands to facilitate common Android pentesting tasks https://github.com/Hamz-a/frida-android-helper

πŸ”Hunting & Detecting Remcos RAT with Splunk & Sysmon πŸ”—https://sakshamtushar.notion.site/Hunting-Detecting-Remcos-RAT-with-Splunk-Sysmon-947cd3c1988b4aba983bcaa6ce7d8897 #splunk #sysmon #detection

Automatic privilege escalation for misconfigured capabilities, sudo and suid binaries using #GTFOBins. https://github.com/Frissi0n/GTFONow

A collection of real world AI/ML exploits for responsibly disclosed vulnerabilities https://github.com/protectai/ai-exploits #AI #exploit

/ Active Directory Advanced Threat Hunting - Identify vulnerabilities before others do https://github.com/tomwechsler/Active_Directory_Advanced_Threat_Hunting

Pavel Yosifovich - Native Powers: leveraging the native API for power and flexibility πŸ”—https://www.youtube.com/watch?v=gewNYKjYybA&t=973s

CloakQuest3r is a powerful Python tool meticulously crafted to uncover the true IP address of websites safeguarded by Cloudflare and other alternatives, a widely adopted web security and performance enhancement service. πŸ”—https://github.com/spyboy-productions/CloakQuest3r #cloudflare

πŸ‘©β€πŸ’»Rapidly Search and Hunt through Windows Forensic Artefacts Chainsaw provides a powerful β€˜first-response’ capability to quickly identify threats within Windows forensic artefacts such as Event Logs and the MFT file. Chainsaw offers a generic and fast method of searching through event logs for keywords, and by identifying threats using built-in support for Sigma detection rules, and via custom Chainsaw detection rules. πŸ”—https://github.com/WithSecureLabs/chainsaw #windows #forensics

🧩 A list of Python books in English that are FREE 🧩 https://github.com/pamoroso/free-python-books

πŸ’ AI Exploits This repository, ai-exploits, is a collection of exploits and scanning templates for responsibly disclosed vulnerabilities affecting machine learning tools..: https://github.com/protectai/ai-exploits

CVE-2023-42325, -42326, -42327: XSS and RCE in pfSense Security, 5.4 - 8.8 rating πŸ”₯ By combining vulnerabilities, an attacker can force a user to activate XSS payload and thereby achieve RCE. pfSense CE 2.7.0 and below, pfSense Plus 23.05.1 and below are vulnerable. Search at Netlas.io: πŸ‘‰ Link (tag, more results): https://nt.ls/BRDDo πŸ‘‰ Link (no tag): https://nt.ls/Mr8WD πŸ‘‰ Dork: http.favicon.hash_sha256:b2dd935235013a51fde0a2afc12ba965952e384b7ab43fe1746cc21c7eafc38c Vendor's advisory: https://docs.netgate.com/downloads/pfSense-SA-23_08.webgui.asc

πŸ“•A Red-Teamer diariesπŸ“• Publicly accessible notes about my pentesting/red teaming experiments tested on several controlled environments/infrastructures that involve playing with various tools and techniques used by penetration testers and redteamers during a security assessment. https://github.com/ihebski/A-Red-Teamer-diaries