hacker_trick | Unsorted

Telegram-канал hacker_trick - Hacker tricks

3151

CVEs🔰 Tools🛠 RedTeam📕

Subscribe to a channel

Hacker tricks

Telegram Web app XSS/Session Hijacking 1-click
pedbap/telegram-web-app-xss-session-hijacking-1-click-95acccdc8d90" rel="nofollow">https://medium.com/@pedbap/telegram-web-app-xss-session-hijacking-1-click-95acccdc8d90

Читать полностью…

Hacker tricks

Google Recaptcha Bypass less than 5 seconds
https://github.com/sarperavci/GoogleRecaptchaBypass

Читать полностью…

Hacker tricks

Automating API Vulnerability Testing Using Postman Workflows
https://haymiz.dev/security/2024/04/27/automating-apis-with-postman-workflows

Читать полностью…

Hacker tricks

Disk Group Privilege Escalation
https://www.hackingarticles.in/disk-group-privilege-escalation

Читать полностью…

Hacker tricks

AutoAppDomainHijack: Tools to automate finding AppDomain hijacks and generating payloads from shellcode
https://github.com/nbaertsch/AutoAppDomainHijack

Читать полностью…

Hacker tricks

Exploiting the NT Kernel in 24H2: New Bugs in Old Code & Side Channels Against KASLR
https://exploits.forsale/24h2-nt-exploit

Читать полностью…

Hacker tricks

ThreadlessSpawn: A Simple PoC
https://github.com/BambiZombie/ThreadlessSpawn

Читать полностью…

Hacker tricks

AWS Cloud Security Config Review using Nuclei Templates
https://blog.projectdiscovery.io/aws-cloud-security-config-review-using-nuclei-templates

Читать полностью…

Hacker tricks

DLHell: Local & remote Windows DLL Proxying
https://github.com/synacktiv/DLHell

Читать полностью…

Hacker tricks

PrickSense: How Cactus Exploits Qlik Sense
https://northwave-cybersecurity.com/whitepapers-articles/pricksense-how-cactus-exploits-qlik-sense

Читать полностью…

Hacker tricks

Multiple Vulnerabilities in Open Devin
(Autonomous AI Software Engineer)
https://evren.ninja/multiple-vulnerabilities-in-opendevin

Читать полностью…

Hacker tricks

A Practical Guide to PrintNightmare in 2024
https://itm4n.github.io/printnightmare-exploitation

Читать полностью…

Hacker tricks

C# API for Nidhogg rootkit
https://github.com/Idov31/NidhoggCSharpApi

Читать полностью…

Hacker tricks

The Dark Side of EDR: Repurpose EDR as an Offensive Tool
https://www.safebreach.com/blog/dark-side-of-edr-offensive-tool

Читать полностью…

Hacker tricks

Grafana backend sql injection affected all version
https://fdlucifer.github.io/2024/04/22/grafana-sql-injection

Читать полностью…

Hacker tricks

Embed A Malicious Executable in a Normal PDF or EXE
sam.rothlisberger/embed-a-malicious-executable-in-a-normal-pdf-or-exe-81ee5339707e" rel="nofollow">https://medium.com/@sam.rothlisberger/embed-a-malicious-executable-in-a-normal-pdf-or-exe-81ee5339707e

Читать полностью…

Hacker tricks

LSASS rings KsecDD ext. 0
Overview of the recent KexecDD exploit
https://tierzerosecurity.co.nz/2024/04/29/kexecdd.html

Читать полностью…

Hacker tricks

OSCP Prep: Introducing My Runbooks —RCE on Linux
Fanicia/oscp-prep-introducing-my-runbooks-rce-on-linux-44099b36aa34" rel="nofollow">https://medium.com/@Fanicia/oscp-prep-introducing-my-runbooks-rce-on-linux-44099b36aa34

Читать полностью…

Hacker tricks

PoC for CVE-2024-21345 Windows Kernel EoP
https://github.com/exploits-forsale/CVE-2024-21345

Читать полностью…

Hacker tricks

iMessage with PQ3: How this new protocol works to defend your iPhone against Post-Quantum Attacks
https://medium.com/macoclock/imessage-with-pq3-how-it-works-and-why-it-matters-for-your-iphone-3120528ee109

Читать полностью…

Hacker tricks

Windows KASLR bypass using prefetch side-channel
https://github.com/exploits-forsale/prefetch-tool

Читать полностью…

Hacker tricks

CertifiedDCOM: The Privilege Escalation Journey to Domain Admin with DCOM
https://i.blackhat.com/Asia-24/Presentations/Asia-24-Ding-CertifiedDCOM-The-Privilege-Escalation-Journey-to-Domain-Admin.pdf

Читать полностью…

Hacker tricks

Deploy an Active Directory Lab Within Minutes
https://www.blackhillsinfosec.com/deploy-an-active-directory-lab-within-minutes

Читать полностью…

Hacker tricks

ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices
https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices

Читать полностью…

Hacker tricks

Exploiting embedded mitel phones for unauthenticated remote code
https://baldur.dk/blog/embedded-mitel-exploitation

Читать полностью…

Hacker tricks

CVE-2024-21111 – LPE in Oracle VirtualBox
https://www.mdsec.co.uk/2024/04/cve-2024-21111-local-privilege-escalation-in-oracle-virtualbox

Читать полностью…

Hacker tricks

CVE-2023-20198-RCE, support adding/deleting users and executing cli commands/system commands
https://github.com/W01fh4cker/CVE-2023-20198-RCE

Читать полностью…

Hacker tricks

Hello: I’m your Domain Admin and I want to authenticate against you
https://decoder.cloud/2024/04/24/hello-im-your-domain-admin-and-i-want-to-authenticate-against-you

Читать полностью…

Hacker tricks

18 vulnerabilities in Brocade SANnav
https://pierrekim.github.io/blog/2024-04-24-brocade-sannav-18-vulnerabilities

Читать полностью…

Hacker tricks

IOS Penetration Testing: Guide to Static Analysis
adityasawant00/ios-penetration-testing-guide-to-static-analysis-4a9dea5d672d" rel="nofollow">https://medium.com/@adityasawant00/ios-penetration-testing-guide-to-static-analysis-4a9dea5d672d

Читать полностью…
Subscribe to a channel