hacker_trick | Неотсортированное

Telegram-канал hacker_trick - Hacker tricks

-

CVEs🔰 Tools🛠 Security Research🔒

Подписаться на канал

Hacker tricks

Database Hacking with common SQL Injection commands
redfanatic7/database-hacking-with-common-sql-injection-commands-c33b049554fe" rel="nofollow">https://medium.com/@redfanatic7/database-hacking-with-common-sql-injection-commands-c33b049554fe

Читать полностью…

Hacker tricks

Deep Sea Phishing Pt. 1
https://posts.specterops.io/deep-sea-phishing-pt-1-092a0637e2fd

Читать полностью…

Hacker tricks

Helios: Automated XSS Testing
https://github.com/Stuub/Helios

Читать полностью…

Hacker tricks

Advanced SQL Injection Techniques
https://github.com/ifconfig-me/SQL_Injection-Techniques
List of Directory Traversal/LFI Payloads
https://github.com/ifconfig-me/Directory-Traversal-Payloads

Читать полностью…

Hacker tricks

SOC Home Lab
dyavanapellisujal7/soc-home-lab-part-1-6309b5b91118">Part 1     ○●     dyavanapellisujal7/soc-home-lab-part-2-2a0e1f3cdca6">Part 2     ○●     dyavanapellisujal7/soc-home-lab-part-3-8832e8325e80">Part 3

Читать полностью…

Hacker tricks

WhatsApp trick: Android malware can impersonate PDF file
https://www.mobile-hacker.com/2024/07/23/whatsapp-trick-android-malware-can-impersonate-pdf-file

Читать полностью…

Hacker tricks

Goffloader: A pure Go implementation of an in-memory COFFLoader (and PE loader)
https://github.com/praetorian-inc/goffloader

Читать полностью…

Hacker tricks

Cursed tapes: Exploiting the EvilVideo vulnerability on Telegram for Android
https://www.welivesecurity.com/en/eset-research/cursed-tapes-exploiting-evilvideo-vulnerability-telegram-android

Читать полностью…

Hacker tricks

3 ways to get Remote Code Execution in Kafka UI
https://github.blog/2024-07-22-3-ways-to-get-remote-code-execution-in-kafka-ui

Читать полностью…

Hacker tricks

The Security Principle Every Attacker Needs to Follow
https://posts.specterops.io/the-security-principle-every-attacker-needs-to-follow-905cc94ddfc6

Читать полностью…

Hacker tricks

Wyvern is a kernel driver designed to facilitate the transmission and reception of memory from any process via the computer's kernel
https://github.com/SnyakoCode/wyvernkernel

Читать полностью…

Hacker tricks

Lsass Dump using MiniDump Method and Direct Syscall Technique
https://github.com/CyberSecurityUP/LsassDumpSyscall

Читать полностью…

Hacker tricks

ZeroHVCI accomplishes arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin permissions or kernel drivers
https://github.com/zer0condition/ZeroHVCI

Читать полностью…

Hacker tricks

Electron JS ASAR Integrity Bypass
https://blog.souravkalal.tech/electron-js-asar-integrity-bypass-431ac4269ed5

Читать полностью…

Hacker tricks

HotPage: Story of a signed, vulnerable, ad-injecting driver
https://www.welivesecurity.com/en/eset-research/hotpage-story-signed-vulnerable-ad-injecting-driver

Читать полностью…

Hacker tricks

timebased blind sqli with 99% success rate
https://github.com/coffinxp/BSQLi

Читать полностью…

Hacker tricks

PoC for CVE-2024-40348 Bazaar v1.4.3 and prior
Will attempt to read /etc/passwd from target
https://github.com/bigb0x/CVE-2024-40348

Читать полностью…

Hacker tricks

JScripter: is a Python script designed to scrape and save unique JavaScript files from a list of URLs or a single URL
https://github.com/ifconfig-me/JScripter

Читать полностью…

Hacker tricks

Top 10 XSS Payloads
https://rodoassis.medium.com/top-10-xss-payloads-e4774a43e285

Читать полностью…

Hacker tricks

How Almost Sacrificing a University Group Project led to a Microsoft Bug Bounty
pyrus369/how-almost-sacrificing-a-university-group-project-led-to-a-microsoft-bug-bounty-9801e0f8f006" rel="nofollow">https://medium.com/@pyrus369/how-almost-sacrificing-a-university-group-project-led-to-a-microsoft-bug-bounty-9801e0f8f006

Читать полностью…

Hacker tricks

Blocks EDR Telemetry by performing Person-in-the-Middle attack where network filtering is applied using iptables
https://github.com/TierZeroSecurity/edr_blocker

Читать полностью…

Hacker tricks

SessionExec allows you to execute specified commands in other Sessions on Windows Systems, either targeting a specific session ID or All sessions, with the option to suppress command output
https://github.com/Leo4j/SessionExec

Читать полностью…

Hacker tricks

View State, The unpatchable IIS forever day being actively exploited
https://zeroed.tech/blog/viewstate-the-unpatchable-iis-forever-day-being-actively-exploited

Читать полностью…

Hacker tricks

Linux Shellcoding
https://sid4hack.medium.com/linux-shellcoding-9ce073353011

Читать полностью…

Hacker tricks

JNDI Injection Remote Code Execution via Path Manipulation in MemoryUserDatabaseFactory
https://srcincite.io/blog/2024/07/21/jndi-injection-rce-via-path-manipulation-in-memoryuserdatabasefactory

Читать полностью…

Hacker tricks

BenignHunter: is a simple tool to try and identify which native api's are deemed benign by EDRs and are therefore not hooked
https://github.com/Allevon412/BenignHunter

Читать полностью…

Hacker tricks

Forensic Investigation Operations — Windows Base I
brsdncr/forensic-investigation-operations-windows-base-i-ca28d9982729" rel="nofollow">https://medium.com/@brsdncr/forensic-investigation-operations-windows-base-i-ca28d9982729

Читать полностью…

Hacker tricks

CVE-2024-40725 and CVE-2024-40898, affecting Apache HTTP Server versions 2.4.0 through 2.4.61
https://github.com/TAM-K592/CVE-2024-40725-CVE-2024-40898

Читать полностью…

Hacker tricks

Announcing Pwn2Own Ireland – Bringing Pwn2Own (and WhatsApp) to the Emerald Isle
https://www.zerodayinitiative.com/blog/2024/7/16/announcing-pwn2own-ireland-2024

Читать полностью…

Hacker tricks

The Return of Ghost Emperor’s Demodex
https://www.sygnia.co/blog/ghost-emperor-demodex-rootkit

Читать полностью…
Подписаться на канал