Real profit
2.87K subscribers
107 photos
4 videos
155 files
3.37K links
Just invest your time
Download Telegram
curated list of services and alternatives that respect your privacy
https://github.com/pluja/awesome-privacy

single place for all useful android and iOS security related stuff
https://github.com/vaib25vicky/awesome-mobile-security
collection of awesome one-liner scripts
especially for bug bounty tips
https://github.com/dwisiswant0/awesome-oneliner-bugbounty

curated list of awesome links, resources
and tools on infosec related topics
https://github.com/pe3zx/my-infosec-awesome

RAT And C&C Resources. 250+ Open Source Projects, 1200+ RAT/C&C blog/video
https://github.com/alphaSeclab/awesome-rat
awesome list of browser exploitation tutorials
https://github.com/Escapingbug/awesome-browser-exploit

collection of awesome web crawler, spider
in different languages
https://github.com/BruceDone/awesome-crawler

List of libraries, tools and APIs
for web scraping and data processing
https://github.com/lorien/awesome-web-scraping

Everything about web-application firewalls (WAF)
https://github.com/0xInfection/Awesome-WAF
Pegasus Spyware Samples Decompiled
Operating System: AndroidOS
https://github.com/jonathandata1/pegasus_spyware
latest network security #vulnerability detection or #exploit code
https://github.com/aetkrad/goby_poc
Remote Desktop entirely coded in PowerShell
https://github.com/DarkCoderSc/PowerRemoteDesktop

fast terminal-ui for git written in rust
https://github.com/extrawurst/gitui
2201.01649.pdf
1.2 MB
WebSpec Machine-Checked Analysis of Browser Security Mechanisms, new cookie attack
https://arxiv.org/abs/2201.01649
CVE-2021-45608 | NetUSB RCE
Flaw in Millions of End User Routers
https://www.sentinelone.com/labs/cve-2021-45608-netusb-rce-flaw-in-millions-of-end-user-routers

CVE-2021-42278 Domain Escalation - sAMAccountName Spoofing
https://pentestlab.blog/2022/01/10/domain-escalation-samaccountname-spoofing

New macOS vulnerability, “powerdir,” could lead to unauthorized user data access
https://www.microsoft.com/security/blog/2022/01/10/new-macos-vulnerability-powerdir-could-lead-to-unauthorized-user-data-access
CVE-2021-41277 can be extended to an SSRF
https://github.com/sasukeourad/CVE-2021-41277_SSRF

SonicWall SMA-100 Unauth RCE
Exploit CVE-2021-20038
https://github.com/jbaines-r7/badblood
C# version of MDSec's ParallelSyscalls
https://github.com/cube0x0/ParallelSyscalls

A Linux program that replies to ping but modifies the payload of the ICMP package to get lower ping times
https://github.com/m-ou-se/pong

Bash script to check if a domain or list of domains can be spoofed based in DMARC records
https://github.com/v4d1/SpoofThatMail

Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory
https://github.com/optiv/Ivy
A lightweight, stable and high-performance reverse proxy for NAT traversal, written in Rust, An alternative to frp and ngrok
https://github.com/rapiz1/rathole

frp0.33 modified version, over-traffic detection, free from killing, support for loading remote configuration files, plug-ins that can be used directly by cs
https://github.com/mstxq17/FrpProPlugin
A curated list for getting up to speed on #crypto and decentralized networks
https://github.com/JumpCrypto/crypto-reading-list

A comprehensive, up-to-date collection of information about several thousands of #crypto tokens
https://github.com/trustwallet/assets
Nanocore, Netwire and AsyncRAT spreading campaign uses public cloud infrastructure. latest example of threat actors abusing cloud services like Microsoft Azure and Amazon Web Services
Cisco Talos
https://blog.talosintelligence.com/2022/01/nanocore-netwire-and-asyncrat-spreading.html?m=1
CVE-2022-21907 Wormable Windows HTTP hole. what you need to know
https://nakedsecurity.sophos.com/2022/01/12/wormable-windows-http-hole-what-you-need-to-know

ESET researchers look at malware that abuses vulnerabilities in kernel drivers and outline mitigation techniques against this type of exploitation
https://www.welivesecurity.com/2022/01/11/signed-kernel-drivers-unguarded-gateway-windows-core

New SysJoker Backdoor Targets Windows, Linux, macOS
https://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker

SysJoker analyzing the first (macOS) malware of 2022
https://objective-see.com/blog/blog_0x6C.html
Vulnerability Intelligence Center / Exploits
https://github.com/Patrowl/PatrowlHears

Open-Source Vulnerability Intelligence Center Unified source of vulnerability, exploit and threat Intelligence feeds
https://github.com/Patrowl/PatrowlHearsData