■■■□□ Profil3r: OSINT tool to find a person’s accounts and emails + breached emails.
https://github.com/Rog3rSm1th/Profil3r
https://github.com/Rog3rSm1th/Profil3r
■□□□□ BazarLoader Malware Abuses Slack, BaseCamp Clouds.
https://threatpost.com/bazarloader-malware-slack-basecamp/165455/
https://threatpost.com/bazarloader-malware-slack-basecamp/165455/
Threat Post
BazarLoader Malware Abuses Slack, BaseCamp Clouds
Two cyberattack campaigns are making the rounds using unique social-engineering techniques.
■■■■□ PwnLnX: advanced multi-threaded, multi-client python reverse shell for hacking linux systems.
https://github.com/spectertraww/PwnLnX
https://securityonline.info/pwnlnx/
https://github.com/spectertraww/PwnLnX
https://securityonline.info/pwnlnx/
GitHub
GitHub - thatstraw/PwnLnX: An advanced multi-threaded, multi-client python reverse shell for hacking linux systems. There's still…
An advanced multi-threaded, multi-client python reverse shell for hacking linux systems. There's still more work to do so feel free to help out with the development. Disclaimer: This revers...
■■■□□ How a WhatsApp status loophole is aiding cyberstalkers.
https://traced.app/2021/04/13/whatsapp-status-loophole-is-aiding-cyberstalkers/
https://traced.app/2021/04/13/whatsapp-status-loophole-is-aiding-cyberstalkers/
Trustd Mobile
How a WhatsApp status loophole is aiding cyberstalkers | Trustd Mobile
Cyberstalkers typically like to collect as much information about their target as possible. They want to know where they
■■■■□ #Exclusive | Zero-Day: Privilege Escalation in Nvidia Control Panel.
As per the researcher, the vulnerability was identified using alert 📢 mechanism based on an earlier UAC bypass (CVE-2019-1388).
https://twitter.com/_M_Shahnawaz/status/1383686714087010311
As per the researcher, the vulnerability was identified using alert 📢 mechanism based on an earlier UAC bypass (CVE-2019-1388).
https://twitter.com/_M_Shahnawaz/status/1383686714087010311
Twitter
Muhammed Shameem
In 2019 I had setup an EDR Alert for exploitation of privilege escalation on UAC vulnerability CVE-2019-1388 , 4 days ago it triggered and found that @nvidia Control panel upgrade gives away SYSTEM privilege to any user. Funniest finding ever
■■□□□ Privacy violation by app | Interesting thread: https://mobile.twitter.com/0dayCTF/status/1383494676141903877
Twitter
Ryan M. Montgomery
I was proxying traffic from a mobile crypto app called "Pi", I noticed that 3700 of my contacts were being uploaded to their server and are stored/searchable. - Any explanation @PiCoreTeam? - #cryptocurrency #picoin #cryptocurrencies #altcoin #minepi #cybersecurity…
■■■■■ The Code Testing Company CodeCov Suffers a Data Breach Which Went Undetected for Months.
U.S. federal authorities are investigating a safety violation at Codecov, which works on selling a tool that allows developers to calculate their codebase coverage and works for more than 29,000 clients worldwide. The organization acknowledged the violation and reported that for months it remained unnoticed.
https://www.ehackingnews.com/2021/04/the-code-testing-company-codecov.html
U.S. federal authorities are investigating a safety violation at Codecov, which works on selling a tool that allows developers to calculate their codebase coverage and works for more than 29,000 clients worldwide. The organization acknowledged the violation and reported that for months it remained unnoticed.
https://www.ehackingnews.com/2021/04/the-code-testing-company-codecov.html
■□□□□ Data-Leak | Russia 🇷🇺 : Database containing e-mail addresses of Navalny's supporters leaked onto the Internet.
https://www.ehackingnews.com/2021/04/database-containing-e-mail-addresses-of.html
https://www.ehackingnews.com/2021/04/database-containing-e-mail-addresses-of.html
■■□□□ Sish - HTTP(S)/WS(S)/TCP Tunnels To Localhost Using Only SSH.
https://github.com/antoniomika/sish
https://github.com/antoniomika/sish
GitHub
GitHub - antoniomika/sish: HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH.
HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH. - antoniomika/sish
■□□□□ India 🇮🇳: CERT-IN Issues "High" Severity Rating Advisory for WhatsApp Threats.
■■■■□ HttpDoom - A Tool For Response-Based Inspection Of Websites Across A Large Amount Of Hosts For Quickly Gaining An Overview Of HTTP-based Attack Surface.
https://github.com/filipi86/httpdoom
https://github.com/filipi86/httpdoom
GitHub
GitHub - filipi86/httpdoom: HttpDoom is a tool for response-based inspection of websites across a large amount of hosts for quickly…
HttpDoom is a tool for response-based inspection of websites across a large amount of hosts for quickly gaining an overview of HTTP-based attack surface. - filipi86/httpdoom
■■■■■ (POC) Remove any Facebook’s live video ($14,000 bounty) | by Ahmad Talahmeh | Apr, 2021.
https://infosecwriteups.com/poc-remove-any-facebooks-live-video-14-000-bounty-70c8135b7b4c
https://infosecwriteups.com/poc-remove-any-facebooks-live-video-14-000-bounty-70c8135b7b4c
Medium
(POC) Remove any Facebook’s live video ($14,000 bounty)
Description / Impact
■□□□□ Pakistan 🇵🇰 shut down several social networks within its borders last Friday but lifted the ban after around four hours.
https://mobile.twitter.com/PTAofficialpk/status/1382963881979482112
https://www.theregister.com/2021/04/19/pakistan_brief_social_media_ban/
https://mobile.twitter.com/PTAofficialpk/status/1382963881979482112
https://www.theregister.com/2021/04/19/pakistan_brief_social_media_ban/
Twitter
PTA
Press Release: In order to maintain public order and safety, access to certain social media applications has been restricted temporarily.
■■□□□ Interesting thread: https://mobile.twitter.com/sec_r0/status/1381645790263697411
Twitter
Rohit
🚨🥳😍#SecurityZine - Day 1/30 SQLi leads to Auth Bypass, info disclosure, tamper existing data and much more. Learn SQli through the Zine landing on 14th, and guess what it will be free and under pay as u wish. #SqlInjection #infosec #security #appsec #webdev…
■■□□□ Command to extract all endpoints from a JS File.
cat files.txt | grep -aoP "(?<=(\"|\'|`))\/[a-zA-Z0-9?&=\/-#.](?=(\"|\'|`))" | sort -u | tee output.txt
■□□□□ Almost all XSS Payloads / brute-force list for quick results.
https://github.com/irfan-knr/KNR-XSS-Payloads
https://github.com/irfan-knr/KNR-XSS-Payloads
■□□□□ Interesting Thread: https://mobile.twitter.com/Aamer_Sha/status/1384077678941073408
Twitter
Aamer Shah 🐦
Google Chrome Zeroday. Type: Escalation of Privilege Severity: Medium / Low Google chose not to fix. The bug exists in all chromium based browsers (including v92 Chrome) except 'Samsung Internet' that choose to patch it after my report in 2018 (SVE-2018-11602).