Hacking Brasil
240 subscribers
74 photos
21 videos
20 files
219 links
Think correctly about hacking!
By: @hxcking
Download Telegram
CVE-2024-26229: Windows LPE

PATCHADO: 9 de abril de 2024

https://github.com/RalfHacker/CVE-2024-26229-exploit

P.S. Corrigida ligeiramente a exploração original
Assembly for Hackers

"Assembly Unleashed: A Hacker's Handbook" is a definitive resource tailored specifically for hackers and security researchers seeking to master the art of assembly programming language. Authored by seasoned practitioners in the field, this book offers a comprehensive journey into the depths of assembly, unraveling its complexities and exposing its potential for exploitation and defense.

Source:
https://redteamrecipe.com/assembly-for-hackers
CVE-2024-30103: Critical Microsoft Outlook Zero-Click RCE Flaw Executes as Email is Opened.

https://cybersecuritynews.com/microsoft-outlook-zero-click-rce-flaw/
CVE-2024-28995: High-Severity Directory Traversal Vulnerability affecting SolarWinds Serv-U.

SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.

POC: https://github.com/rapid7/metasploit-framework/pull/19255

Query:
Hunter: protocol.banner="Serv-U FTP"
FOFA: app="SolarWinds-Serv-U-FTP"
SHODAN: product:"Serv-U ftpd"
[OSEP-PEN300]-[2022]-offenseive_security_expert_penetration_tester

https://teraboxapp.com/s/1ukPQmfhzBxj6VnH5JwdXHg
Ec-Council | Drone Hacking Workshop

Download :
https://teraboxapp.com/s/1GV6U9bknGFhxGF5s2wGD9Q
CVE-2024-36401
*
RCE GeoServer
*
exploit
INE | eCPPT Penetration Testing Professional (NEW - 2024)

Download : https://1024terabox.com/s/1cVvLsmUf-Jb81Rawna24LQ

More info :https://security.ine.com/certifications/ecppt-certification/
pcap-did-what: Analyze pcaps with Zeek and a Grafana Dashboard https://github.com/hackertarget/pcap-did-what
duck.ai

Uma ferramenta de comunicação com chatbots feita pela DuckDuckGo. Gratuito, não requer cadastro (posiciona-se como anônimo e não coleta esses usuários) e muito rápido:

Turbo GPT-3.5
Claude 4 Haiku
Liama ​​​​3 70B
Mixtral 8x78
Fascinating C code: TCP sockets & HTTP file downloads using only ntdll exports (NtCreateFile & NtDeviceIoControlFile syscalls). Bypasses Winsock for low-level Windows networking.


https://www.x86matthew.com/view_post?id=ntsockets
👍1
A Universal Windows Bootkit
An analysis of the MBR bootkit referred to as “HDRoot”



https://williamshowalter.com/a-universal-windows-bootkit/
𝗢𝗪𝗔𝗦𝗣 𝗧𝗢𝗣 𝟭𝟬 - 𝗩𝘂𝗹𝗻𝗲𝗿𝗮𝗯𝗹𝗲 𝗟𝗟𝗠 𝗔𝗽𝗽𝗹𝗶𝗰𝗮𝘁𝗶𝗼𝗻𝘀

The OWASP Top 10 for LLMs is a list of the most critical vulnerabilities found in applications utilizing LLMs. It was created to provide developers, data scientists, and security experts with practical, actionable, and concise security guidance to navigate the complex and evolving terrain of LLM security.

Link 🔗:-
https://github.com/OWASP/www-project-top-10-for-large-language-model-applications/wiki/Vulnerable-LLM-Applications