CrackCodes ๐Ÿ‡ฎ๐Ÿ‡ณ
15.9K subscribers
1.89K photos
386 videos
722 files
3.67K links
Official Websites: https://crackcodes.in |
For Bug Hunters: https://system32.ink

Admin: @MynK0x00
About Admin: prapattimynk.crackcodes.in


Be Secure~
เคœเคฏ เคถเฅเคฐเฅ€ เคฐเคพเคฎ
Download Telegram
๐Ÿ’ฅGeoServer SQL Injection Vulnerability Analysis (CVE-2023-25157)

SQL Injection Vulnerabilities have been found with:
๐Ÿ’พ PropertyIsLike filter, when used with a String field and any database DataStore, or with a PostGIS DataStore with encode functions enabled
๐Ÿ’พ strEndsWith function, when used with a PostGIS DataStore with encode functions enabled
๐Ÿ’พ strStartsWith function, when used with a PostGIS DataStore with encode functions enabled
๐Ÿ’พ FeatureId filter, when used with any database table having a String primary key column and when prepared statements are disabled
๐Ÿ’พ jsonArrayContains function, when used with a String or JSON field and with a PostGIS or Oracle DataStore (GeoServer 2.22.0+ only)
๐Ÿ’พ DWithin filter, when used with an Oracle DataStore


๐Ÿ”–CVE-2023-25157 - GeoServer SQL Injection - PoC

Usage:
python3 CVE-2023-25157.py <URL>
System32.ink on The maintenance

We will be start it after 6 days
๐Ÿ‘4
๐Ÿ’ฅRCE in GitLab's CLI tool

Attack scenario:
1๏ธโƒฃAttacker creates a repository. They create a branch named "@|calc".
2๏ธโƒฃTo make the attack more convincing, they set this branch as the default branch.
3๏ธโƒฃVictim clones the repository on their machine.
4๏ธโƒฃVictim tries to create an MR using glab mr create --web
5๏ธโƒฃThe following command is run: cmd.exe /c "start https://gitlab.com/test-user/test-repo/-/merge_requests/new?merge_request[title]=%s^&amp;merge_request[description]=%s^&amp;merge_request[source_branch]=%s^&amp;merge_request[target_branch]=@|calc^&amp;merge_request[source_project_id]=%d^&amp;merge_request[target_project_id]=%d".
6๏ธโƒฃThe pipe character allows to break out of the URL context and launch calc.
Forwarded from ๐˜พ.๐˜ฟ.๐™„ (๐™๐™€๐™Ž๐™Š๐™๐™๐˜พ๐™€๐™Ž) ๐Ÿšฉ
AAJ INTEHAAN HAI SABKA BADA SHIKAR HAI ISKO SAZA DILWANI HAI ISNE KYA KIYA WO KHUD JAKE TWEET PE DEKHLENA VIDEO HAI

JITNE RETWEETS HO SKE KRWA DO MUMBAI POLICE KO TAG KRK

LINK - RETWEET
๐Ÿ‘1
If you Need TryHackMe Voucher At a Cheapest Rate in the Market...โœ…

1 Month Voucher = 1.25$ & 100โ‚น

2 Month Voucher =  3$ & 250โ‚น

3 Month Voucher = 5$ & 415โ‚น

Payment Method ๐Ÿ‘‘

BTC๐Ÿ’ธ, USDt๐Ÿ’ธ, UPI ๐ŸŒ


Dm ๐Ÿ‘ผ@lexlegion๐Ÿ‘ผ

Limited 2 & 3 month Vouchers Remains...

Grab Your Oppertunity Fast๐Ÿ“
Please open Telegram to view this post
VIEW IN TELEGRAM
โคโ€๐Ÿ”ฅ2
Join our exclusive General Discussion on OSINT, where knowledge meets innovation! Unleash the power of open-source intelligence and dive into cutting-edge strategies with like-minded enthusiasts. Don't miss this opportunity to expand your horizons and stay ahead of the game. Join us now on Telegram and let's unlock the secrets of the digital world together!
โฑTiming: 9pm IST
๐Ÿ”ŽAt: https://t.me/osintambition
๐Ÿ•ต๐Ÿฟโ€โ™‚๏ธBy: @hacklathon
๐Ÿ—“Date: July 8, 2023 ( Saturday)
Media is too big
VIEW IN TELEGRAM
Kya hai bhai ye Matha chakra gaya ye dekhkar
๐Ÿคฃ11
Forwarded from ๅฝกแด…แด€ส€แด‹ ๊œฐษชส€แด‡ๅฝก
๐Ÿ‘‘DIGITAL OCEAN WINDOWS VPS AVAILABLE๐Ÿ‘‘

๐ŸŒONLY 8GB 4CORE VPS

๐Ÿ’ธPRICE :- 300/-RS

โœ…20DAYS WARRENTY AND 1MONTH VALIDITYโœ…

๐ŸฆVPS SERVER AND ANTIBAN SO YOU CAN DO CRACKING OR OTHER THINGS BUT NO MINNING .

๐ŸคฉIB :- @Darkweb_x1

โœ…PERFOMENCE AND SPEED BETTER THEN RDPโœ…

โœˆ๏ธINTERNET SPEED 1GBPS+
๐Ÿ˜Ž1
๐Ÿ’ฅKramer Enterprises Leak : https://system32.ink/kramer-enterprises-leak/

๐Ÿ’ฅFHR Electric Data Leak : https://system32.ink/fhr-electric-data-leak/

๐Ÿ’ฅManjaro LPE 0day root LPE Exploit : https://system32.ink/manjaro-lpe-0day-root-lpe-exploit/

๐Ÿ’ฅRhadamanthys Stealer : https://system32.ink/rhadamanthys-stealer/
๐Ÿ‘1
Forwarded from BlackDragonSec ๐Ÿ‡ฎ๐Ÿ‡ณ
Some Pedophile Activists claimed to hack Indian satalite database UwU. Here's the very sensitive database Link but public :'(

https://aerospaceweb.org/question/weapons/q0187.shtml

POV: what's this sir..
UwU ๐Ÿ˜‚
Good Job ICF ๐Ÿ‘
๐Ÿคฃ3๐Ÿ‘1
Forwarded from BlackDragonSec ๐Ÿ‡ฎ๐Ÿ‡ณ
When Pedophiles see something advance chapters for the first time and don't understand anything. Just seeing the rocket, aircraft images on chapters they named it they hacked the "INDIAN SATALITE" ๐Ÿ˜‚๐Ÿ˜‚๐Ÿ˜‚

This is not the first time. They claimed it earlier also but after I showed them the truth they deleted their messages LoL
๐Ÿคฃ3
Forwarded from Parth Narula
Anyone want bug hunting and owasp top 10 vulnerabilities tips so visit https://scriptjacker.in/owasp.php
You need to first get signup then login to visit this page. Very awesome content and I bet you that you can't find it at one place on entire internet. It's free.
Forwarded from ๐™Ž๐™ ๐™ช๐™ก๐™ก ๐™๐™š๐™–๐™ฅ๐™š๐™ง๐™จ ๐Ÿ’€ (๐™‚โšก๐™ง๐™ค ๐™‚๐™๐™ค๐™จ๐™ฉ)
Fake Hindu Spotted @MynK0x00 Hinduon ko gaali dera hai madarchod , Mulla hindu bnke ghumra

Maa chod do iski Dm mai @MynK0x00
๐Ÿ‘1๐Ÿ‘Œ1