CrackCodes 🇮🇳
15.9K subscribers
1.89K photos
386 videos
722 files
3.67K links
Official Websites: https://crackcodes.in | https://system32.in |
For Bug Hunters: https://system32.ink

Admin: @MynK0x00
Admin Math: prapattimynk.crackcodes.in


Be Secure~
जय श्री राम
Download Telegram
Forwarded from 卩ro 爪Cracker
Fuzzing ping(8)…and finding a 24 year old bug
https://ift.tt/z5ORFPV

Submitted December 11, 2022 at 09:57AM by Gallus
via reddit https://ift.tt/kyRpCqZ
#exploit
1. ThinkPHP latest RCE reproduction and analysis
https://xz.aliyun.com/t/11940

2. Folina, Shadow Credentials, and WSUS exploitation
https://0xdf.gitlab.io/2022/12/10/htb-outdated.html

3. CVE-2022-1361:
Improper Neutralization of Special Elements Used In a SQL Command: New Technique Discovered To Bypass WAF Of Several Vendors
https://gbhackers.com/bypass-web-application-firewalls/amp
PCI_Sec_Soft_Std_1_2.pdf
914.3 KB
#Infosec_Standards
"PCI Software Security Framework - Secure Software Requirements and Assessment Procedures", Version 1.2, Dec. 2022.
New_Class_Kernel_Exploit_Primitive.pdf
920.1 KB
#reversing
#Research
BlackHat Europe 2022:
"Exploring a New Class of Kernel Exploit Primitive".
#Infographics
#Infosec_Standards
Types of VPN

]-> RFC4026: "Provider Provisioned VPN Terminology", 2018.
https://datatracker.ietf.org/doc/rfc4026
Dirty_Vanity.pdf
2.3 MB
#Red_Team_Tactics
BlackHat Europe 2022:
"Dirty Vanity: A New Approach to Code injection & EDR bypass".

]-> A PoC for the new injection technique, abusing windows fork API to evade EDRs:
https://github.com/deepinstinct/Dirty-Vanity
Routing_security.pdf
3.3 MB
#Whitepaper
"Routing Security: BGP Incidents, Mitigation Techniques and Policy Actions", 2022.