Forwarded from DailyCVE
🔴 Uptime Kuma: Improper URL Handling Vulnerability (#CVE-TBD) - Critical
https://dailycve.com/uptime-kuma-improper-url-handling-vulnerability-cve-tbd-critical/
@Daily_CVE
https://dailycve.com/uptime-kuma-improper-url-handling-vulnerability-cve-tbd-critical/
@Daily_CVE
DailyCVE
Uptime Kuma: Improper URL Handling Vulnerability (CVE-TBD) - Critical - DailyCVE
2024-12-20 Form: Platform: Uptime Kuma Version: (unknown) Vulnerability: Improper URL Handling (LFI) Severity: Critical Date: (unknown) What Undercode Says: Uptime […]
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
⚡️ Aadhaar #Update Deadline Extended Until June 14, 2025: Ensure Your Information Stays Accurate!
https://undercodenews.com/aadhaar-update-deadline-extended-until-june-14-2025-ensure-your-information-stays-accurate/
@Undercode_News
https://undercodenews.com/aadhaar-update-deadline-extended-until-june-14-2025-ensure-your-information-stays-accurate/
@Undercode_News
UNDERCODE NEWS
Aadhaar Update Deadline Extended Until June 14, 2025: Ensure Your Information Stays Accurate! - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information and…
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
Earth's Secrets: The NISAR Mission Set for March 2025 Launch
https://undercodenews.com/earths-secrets-the-nisar-mission-set-for-march-2025-launch/
@Undercode_News
https://undercodenews.com/earths-secrets-the-nisar-mission-set-for-march-2025-launch/
@Undercode_News
UNDERCODE NEWS
Earth's Secrets: The NISAR Mission Set for March 2025 Launch - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information and…
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
🎮 #Google's #Android XR Headsets to Support Find My Device
https://undercodenews.com/googles-android-xr-headsets-to-support-find-my-device/
@Undercode_News
https://undercodenews.com/googles-android-xr-headsets-to-support-find-my-device/
@Undercode_News
UNDERCODE NEWS
Google's Android XR Headsets to Support Find My Device - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information and…
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
📡 Earth's Secrets: #NASA and ISRO Gear Up to Launch Revolutionary NISAR Satellite
https://undercodenews.com/earths-secrets-nasa-and-isro-gear-up-to-launch-revolutionary-nisar-satellite/
@Undercode_News
https://undercodenews.com/earths-secrets-nasa-and-isro-gear-up-to-launch-revolutionary-nisar-satellite/
@Undercode_News
UNDERCODE NEWS
Earth's Secrets: NASA and ISRO Gear Up to Launch Revolutionary NISAR Satellite - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information and…
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
⚠️ NodeStealer #Malware Evolves: Targeting Facebook Ads and Expanding its Reach
https://undercodenews.com/nodestealer-malware-evolves-targeting-facebook-ads-and-expanding-its-reach/
@Undercode_News
https://undercodenews.com/nodestealer-malware-evolves-targeting-facebook-ads-and-expanding-its-reach/
@Undercode_News
UNDERCODE NEWS
NodeStealer Malware Evolves: Targeting Facebook Ads and Expanding its Reach - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information and…
Forwarded from UNDERCODE TESTING
🦑XSS payload generated using JSfuck, for bypass attribute filters 🛡️
https://pastebin.ubuntu.com/p/5sVVKjqXxx
https://pastebin.ubuntu.com/p/5sVVKjqXxx
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
⚡️ #Software to the Rescue: NHTSA Recognizes Over-the-Air Updates for Vehicle Recalls
https://undercodenews.com/software-to-the-rescue-nhtsa-recognizes-over-the-air-updates-for-vehicle-recalls/
@Undercode_News
https://undercodenews.com/software-to-the-rescue-nhtsa-recognizes-over-the-air-updates-for-vehicle-recalls/
@Undercode_News
UNDERCODE NEWS
Software to the Rescue: NHTSA Recognizes Over-the-Air Updates for Vehicle Recalls - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information and…
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
🛡️ #ChatGPT Faces €15m Fine from Italian Data Protection Authority
https://undercodenews.com/chatgpt-faces-eur15m-fine-from-italian-data-protection-authority/
@Undercode_News
https://undercodenews.com/chatgpt-faces-eur15m-fine-from-italian-data-protection-authority/
@Undercode_News
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
⚠️ Lenovo's Rollable #Laptop: A Risky Innovation or the Future of Computing?
https://undercodenews.com/lenovos-rollable-laptop-a-risky-innovation-or-the-future-of-computing/
@Undercode_News
https://undercodenews.com/lenovos-rollable-laptop-a-risky-innovation-or-the-future-of-computing/
@Undercode_News
UNDERCODE NEWS
Lenovo's Rollable Laptop: A Risky Innovation or the Future of Computing? - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information and…
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
🚨 Emerging #Ransomware Threat: Funksec Targets Mongolian Energy Provider
https://undercodenews.com/emerging-ransomware-threat-funksec-targets-mongolian-energy-provider/
@Undercode_News
https://undercodenews.com/emerging-ransomware-threat-funksec-targets-mongolian-energy-provider/
@Undercode_News
UNDERCODE NEWS
Emerging Ransomware Threat: Funksec Targets Mongolian Energy Provider - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information and…
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
🔋 Breaking Down Language Barriers: Gemma's Power of Inclusion
https://undercodenews.com/breaking-down-language-barriers-gemmas-power-of-inclusion/
@Undercode_News
https://undercodenews.com/breaking-down-language-barriers-gemmas-power-of-inclusion/
@Undercode_News
UNDERCODE NEWS
Breaking Down Language Barriers: Gemma's Power of Inclusion - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information and…
Forwarded from Exploiting Crew (Pr1vAt3)
This media is not supported in your browser
VIEW IN TELEGRAM
Forwarded from Exploiting Crew (Pr1vAt3)
🦑🧪 Interactive Labs for Microsoft Certified: Security Operations Analyst Associate
🔹 Apply Microsoft Defender for Office 365 preset security policies
🧪 https://lnkd.in/d6BqZJtv
🔹 Deploy Microsoft Defender for Endpoint
🧪 https://lnkd.in/dd_Vj9VT
🔹 Mitigate Attacks with Microsoft Defender for Endpoint
🧪 https://lnkd.in/d273kEnd
🔹 Enable Microsoft Defender for Cloud
🧪 https://lnkd.in/d_nGMapG
🔹 Mitigate threats using Microsoft Defender for Cloud
🧪 https://lnkd.in/drJmedgr
🔹 Create queries for Microsoft Sentinel using Kusto Query Language (KQL)
🧪 https://lnkd.in/dQnQ_iEZ
🔹 Configure your Microsoft Sentinel environment
🧪 https://lnkd.in/dr4akkUX
🔹 Connect data to Microsoft Sentinel using data connectors
🧪 https://lnkd.in/dtRmAwFa
🔹 Connect Windows devices to Microsoft Sentinel using data connectors
🧪 https://lnkd.in/dpxmvabA
🔹 Connect Linux hosts to Microsoft Sentinel using data connectors
🧪 https://lnkd.in/dua8fHNm
🔹 Create workbooks
🧪 https://lnkd.in/dnawKhcP
🔹 Use Repositories in Microsoft Sentinel
🧪 https://lnkd.in/daQkDy9N
Ref: Dimitris Chatzidimitris
@UndercodeCommunity
▁ ▂ ▄ U𝕟𝔻Ⓔ𝐫Ć𝔬𝓓ⓔ ▄ ▂ ▁
🔹 Apply Microsoft Defender for Office 365 preset security policies
🧪 https://lnkd.in/d6BqZJtv
🔹 Deploy Microsoft Defender for Endpoint
🧪 https://lnkd.in/dd_Vj9VT
🔹 Mitigate Attacks with Microsoft Defender for Endpoint
🧪 https://lnkd.in/d273kEnd
🔹 Enable Microsoft Defender for Cloud
🧪 https://lnkd.in/d_nGMapG
🔹 Mitigate threats using Microsoft Defender for Cloud
🧪 https://lnkd.in/drJmedgr
🔹 Create queries for Microsoft Sentinel using Kusto Query Language (KQL)
🧪 https://lnkd.in/dQnQ_iEZ
🔹 Configure your Microsoft Sentinel environment
🧪 https://lnkd.in/dr4akkUX
🔹 Connect data to Microsoft Sentinel using data connectors
🧪 https://lnkd.in/dtRmAwFa
🔹 Connect Windows devices to Microsoft Sentinel using data connectors
🧪 https://lnkd.in/dpxmvabA
🔹 Connect Linux hosts to Microsoft Sentinel using data connectors
🧪 https://lnkd.in/dua8fHNm
🔹 Create workbooks
🧪 https://lnkd.in/dnawKhcP
🔹 Use Repositories in Microsoft Sentinel
🧪 https://lnkd.in/daQkDy9N
Ref: Dimitris Chatzidimitris
@UndercodeCommunity
▁ ▂ ▄ U𝕟𝔻Ⓔ𝐫Ć𝔬𝓓ⓔ ▄ ▂ ▁
lnkd.in
LinkedIn
This link will take you to a page that’s not on LinkedIn
Forwarded from Exploiting Crew (Pr1vAt3)
🦑 LFIer Tool :
>>>>LFIer>>>> is a powerful tool for detecting >>>>Local File Inclusion (LFI)>>>> vulnerabilities in web applications. By injecting payloads into URL parameters and analyzing responses, it efficiently identifies potential security issues. The tool is designed for flexibility, efficiency, and accuracy, even when scanning sites protected by WAFs or cloud-based defenses.
🌟 >>>>Key Features>>>>
1. >>>>⚡️ High Performance>>>>: Async programming ensures rapid, non-blocking requests for large-scale scanning.
2. >>>>🔍 Advanced Detection>>>>: Custom payloads and indicators accurately detect vulnerabilities.
3. >>>>🛡 WAF/Cloud Bypass>>>>: Simulates real browser requests to bypass security measures.
4. >>>>💉 Custom Payloads>>>>: Allows user-defined payload injection for flexibility.
5. >>>>🌐 Custom Headers>>>>: Mimics client requests or bypasses filters with custom headers.
6. >>>>⏱️ Rate Limiting>>>>: Prevents server overload by controlling request frequency and batching.
7. >>>>📝 Flexible Output>>>>: Results in JSON or plain text for seamless integration into pipelines.
8. >>>>🔧 Configurability>>>>: Adjustable settings for rate, timeouts, and workers.
9. >>>>📂 Organized Scans>>>>: Groups results by domain or URL list.
10. >>>>🔄 Easy Updates>>>>: One-click update mechanism ensures the latest features.
📥 >>>>Installation>>>>
# >>>>For Kali Linux (2024.4+)>>>>
# >>>>Using Virtual Environment (Recommended for Non-Kali Users)>>>>
1. >>>>Create and activate virtual environment:>>>>
2. >>>>Upgrade pip:>>>>
3. >>>>Clone the repository and install dependencies:>>>>
---
📄 >>>>Payloads & Indicators>>>>
# >>>>Linux Example>>>>
- >>>>Payloads>>>>:
- >>>>Indicators>>>>:
# >>>>Windows Example>>>>
- >>>>Payloads>>>>:
- >>>>Indicators>>>>:
---
🧩 >>>>Parameterized URLs>>>>
To find URLs with parameters:
---
🚀 >>>>Usage Examples>>>>
# >>>>Single Domain Scan>>>>
# >>>>Multiple URLs with Custom Rate>>>>
# >>>>Advanced Usage>>>>
- Custom headers:
- JSON output:
---
❗️ >>>>Important Notes>>>>
- Always activate the virtual environment before using LFIer:
- Regularly update LFIer to keep it effective against new protections:
This tool is a must-have for cybersecurity professionals looking to identify and remediate LFI vulnerabilities efficiently. Happy hunting!
@UndercodeCommunity
▁ ▂ ▄ U𝕟𝔻Ⓔ𝐫Ć𝔬𝓓ⓔ ▄ ▂ ▁
>>>>LFIer>>>> is a powerful tool for detecting >>>>Local File Inclusion (LFI)>>>> vulnerabilities in web applications. By injecting payloads into URL parameters and analyzing responses, it efficiently identifies potential security issues. The tool is designed for flexibility, efficiency, and accuracy, even when scanning sites protected by WAFs or cloud-based defenses.
🌟 >>>>Key Features>>>>
1. >>>>⚡️ High Performance>>>>: Async programming ensures rapid, non-blocking requests for large-scale scanning.
2. >>>>🔍 Advanced Detection>>>>: Custom payloads and indicators accurately detect vulnerabilities.
3. >>>>🛡 WAF/Cloud Bypass>>>>: Simulates real browser requests to bypass security measures.
4. >>>>💉 Custom Payloads>>>>: Allows user-defined payload injection for flexibility.
5. >>>>🌐 Custom Headers>>>>: Mimics client requests or bypasses filters with custom headers.
6. >>>>⏱️ Rate Limiting>>>>: Prevents server overload by controlling request frequency and batching.
7. >>>>📝 Flexible Output>>>>: Results in JSON or plain text for seamless integration into pipelines.
8. >>>>🔧 Configurability>>>>: Adjustable settings for rate, timeouts, and workers.
9. >>>>📂 Organized Scans>>>>: Groups results by domain or URL list.
10. >>>>🔄 Easy Updates>>>>: One-click update mechanism ensures the latest features.
📥 >>>>Installation>>>>
# >>>>For Kali Linux (2024.4+)>>>>
git clone https://github.com/Cybersecurity-Ethical-Hacker/lfier.git
cd lfier
pipx install aiohttp
pipx install colorama
pipx install tqdm
# >>>>Using Virtual Environment (Recommended for Non-Kali Users)>>>>
1. >>>>Create and activate virtual environment:>>>>
python3 -m venv venv
source venv/bin/activate
2. >>>>Upgrade pip:>>>>
pip install --upgrade pip
3. >>>>Clone the repository and install dependencies:>>>>
git clone https://github.com/Cybersecurity-Ethical-Hacker/lfier.git
cd lfier
pip install -r requirements.txt
---
📄 >>>>Payloads & Indicators>>>>
# >>>>Linux Example>>>>
- >>>>Payloads>>>>:
/..\\../..\\../etc/passwd
../../../../../etc/passwd
- >>>>Indicators>>>>:
root:x:0:0:
nobody:x:65534:
# >>>>Windows Example>>>>
- >>>>Payloads>>>>:
C:/boot.ini
- >>>>Indicators>>>>:
[boot loader]
timeout=30
---
🧩 >>>>Parameterized URLs>>>>
To find URLs with parameters:
paramspider -d domain.com -s 2>&1 | grep -Ei "https?://" | sort -u | httpx -silent -status-code -mc 200,201,204,401,403 > live_urls.txt
---
🚀 >>>>Usage Examples>>>>
# >>>>Single Domain Scan>>>>
python lfier.py -d "https://domain.com/file.php?parameter=1234"
# >>>>Multiple URLs with Custom Rate>>>>
python lfier.py -l urls.txt -r 5
# >>>>Advanced Usage>>>>
- Custom headers:
python lfier.py -d "https://example.com" -H "User-Agent: CustomAgent"
- JSON output:
python lfier.py -l urls.txt -j -o results.json
---
❗️ >>>>Important Notes>>>>
- Always activate the virtual environment before using LFIer:
source venv/bin/activate
- Regularly update LFIer to keep it effective against new protections:
python lfier.py -u
This tool is a must-have for cybersecurity professionals looking to identify and remediate LFI vulnerabilities efficiently. Happy hunting!
@UndercodeCommunity
▁ ▂ ▄ U𝕟𝔻Ⓔ𝐫Ć𝔬𝓓ⓔ ▄ ▂ ▁
Forwarded from UNDERCODE TESTING
WEB APPLICATION PENETRATION TESTING.pdf
13.1 MB
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
⚡️ #OpenAI's New Reasoning Model: o3
https://undercodenews.com/openais-new-reasoning-model-o3/
@Undercode_News
https://undercodenews.com/openais-new-reasoning-model-o3/
@Undercode_News
UNDERCODE NEWS
OpenAI's New Reasoning Model: o3 - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information and…
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
Elon Musk vs Sam Altman: A Feud Fueled by #AI Ambitions
https://undercodenews.com/elon-musk-vs-sam-altman-a-feud-fueled-by-ai-ambitions/
@Undercode_News
https://undercodenews.com/elon-musk-vs-sam-altman-a-feud-fueled-by-ai-ambitions/
@Undercode_News
UNDERCODE NEWS
Elon Musk vs Sam Altman: A Feud Fueled by AI Ambitions - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information and…