cKure
6.59K subscribers
1.35K photos
320 videos
270 files
12K links

This channel was created in 2018 and contains content from the information security domain.

This channel is primarily run by AI bots (n8n).

Archive: ckure.esy.es
Criticals: @ckuRED
linkedin.com/company/ckure

Support 📨 i@ckure.org
Download Telegram
Microsoft's Internet Explorer on phone 📱 now called Bing is really good in solving mathematical equations.

I had written a big formula with exponents and factorials to calculate something. It solved ot in 1 iteration without error. Very good for hand written stuff.
cKure
PoC of proxylogon chain SSRF(CVE-2021-26855).py
■□□□□ ProxyLogon PoC Exploit Released; Likely to Fuel More Disruptive Cyber Attacks.

https://thehackernews.com/2021/03/proxylogon-exchange-poc-exploit.html
■■■■■ Browser exploit via side channel attack: Researchers have discovered a new side-channel that they say can be reliably exploited to leak information from web browsers that could then be leveraged to track users even when JavaScript is completely disabled.
"This is a side-channel attack which doesn't require any JavaScript to run," the researchers said. "This means script blockers cannot stop it. The attacks work even if you strip out all of the fun parts of the web browsing experience. This makes it very difficult to prevent without modifying deep parts of the operating system."

https://arxiv.org/abs/2103.04952

https://thehackernews.com/2021/03/new-browser-attack-allows-tracking.html
■□□□□ 📢 Hackers Are Targeting Microsoft Exchange Servers With Ransomware.
■□□□□ Microsoft's GitHub under fire after disappearing proof-of-concept exploit for critical Microsoft Exchange vuln.

On Wednesday, shortly after security researcher Nguyen Jang posted a proof-of-concept exploit on GitHub that abuses a Microsoft Exchange vulnerability revealed earlier this month, GitHub, which is owned by Microsoft, removed code, to the alarm of security researchers.
■□□□□ 7-Zip developer releases the first official Linux version.

https://sourceforge.net/p/sevenzip/discussion/45797/thread/cec5e63147/
■■■■■ A decent way to bypass XSS filters, rather WAFs.

https://mobile.twitter.com/0dayCTF/status/1370187588385058819
● Yet another website: RevShells.com [Reverse Shell generator]
cKure
PoC of proxylogon chain SSRF(CVE-2021-26855).py
Currently, there are over 80,000 servers exposed to DearCry ransomware. And exploit code is public (t.me/cKure/7129).

I assume that every hacker (black / white) is busy in their own ways.
■□□□□ #DataLeak: Apple 🍎 is suing a former employee who it claims leaked company trade secrets to a media outlet for over a year for his own personal gain.

Former advanced materials lead and product design architect Simon Lancaster is accused of abusing his position to access information outside of his job scope. He allegedly exchanged the data he stole for payment and positive media coverage of a startup business.

https://www.infosecurity-magazine.com:443/news/apple-sues-employee-for-stealing/