Hacking Brasil
241 subscribers
74 photos
21 videos
20 files
219 links
Think correctly about hacking!
By: @hxcking
Download Telegram
CVE-2025-30208
*
Vitejs File read vulnerability
*
POC
LLM4Decompile: Reverse Engineering: Decompiling Binary Code with Large Language Models https://github.com/albertan017/LLM4Decompile
Mastering Burp Suite

Language : English

Download link

https://mega.nz/file/HhBTEBZB#qT3LAia71mf-ld-GjeIpHEzjafwlX19-3oEkSJrBSFs
CVE-2025-1094
*
RCE SQL Injection in PostgreSQL 14.15
*
exploit
PoC for CVE-2025-48799, an elevation of privilege vulnerability in Windows Update service

☢️ https://github.com/Wh04m1001/CVE-2025-48799
【Informação】Vulnerabilidade de imagem ImageIO encontrada no iOS 18.6.1🚨🚨🚨
Na madrugada do dia 21 de agosto, a Apple lançou urgentemente o sistema iOS 18.6.2, que corrige principalmente a vulnerabilidade de imagem ImageIO🧐
Link do Poc: https://github.com/b1n4r1b01/n-days/blob/main/CVE-2025-43300.md
O número CVE da vulnerabilidade é CVE-2025-43300, esta falha pode afetar o processamento de arquivos de imagem maliciosos, causando corrupção de memória e até possibilitando a execução remota de comandos
Para quem joga CS2, estou vendendo essa faca por R$ 1.000. Se tiver interesse pode me chamar no @hxcking
[ Cobalt Strike 4.12: Fix Up, Look Sharp! ]

Cobalt Strike 4.12 is LIVE, complete with a new look for the GUI! Additionally:
- A REST API
- User Defined Command and Control (UDC2)
- New process injection options
- New UAC bypasses
- and more!
Check out the release blog for details.


https://www.cobaltstrike.com/blog/cobalt-strike-412-fix-up-look-sharp
CVE-2025-6389
is a Critical (CVSS 9.8) vulnerability
in the Sneeit Framework WordPress plugin (≤ 8.3)
exploit
👍2
Microsoft Web Deploy RCE Exploit - CVE-2025-53772

https://github.com/sailay1996/CVE-2025-53772/tree/main
On the clock: Escaping VMware Workstation at Pwn2Own Berlin 2025

🔗 Link
Bypass Azure Admin Approval Mode for User Consent Workflow When Enumerating

https://pgj11.com/posts/Bypass-Azure-Admin-Approval-Mode-Enumeration/
This media is not supported in your browser
VIEW IN TELEGRAM
Evil-Cardputer - Wi-Fi Spycam detection and CCTV Toolkit

Ever wanted a pocket-size toolkit with Wi-Fi Spycam detection and CCTV Toolkit? 📸

A major update that brings CCTV Toolkit 🎥 directly on the device. You can now check for your badly configured camera and check for hidden one with direct stream view when found !!!

Key features (v1.4.3)
💎CCTV Toolkit: LAN/WAN IP-camera recon → port scan, brand fingerprint + CVE hints, login finder, default-creds test, stream discovery, reporting.
💎MJPEG Viewer: cycle through discovered MJPEG streams, adjust resolution/compression.
💎Spycam Detector: detect hidden Wi-Fi cameras via SSID/OUI heuristics that know for being SpyCamera.


GitHub
👍1
Windows Kernel Debugging Fundamentals @hackingbra.zip
739.3 MB
Windows Kernel Debugging Fundamentals

◽️ Introduction to Windows Crashes and Hangs
◽️ Getting Started With the Windows Debugger
◽️ Getting Help in the Windows Debugger
◽️ Configuring the Windows Debugger
◽️ Starting Your Crash Dump Analysis
◽️ Understanding Stack Traces
◽️ Debugging Processes and Threads
◽️ Understanding Processors and Disassembled Code
◽️ Investigating Locks and Spinlocks
◽️ Exploring Windows Virtual Memory
◽️ Windows Drivers and Interrupts
◽️ Forcing Windows Memory Dumps
VENOM 1.0.17 - metasploit Shellcode generator/compiller

https://github.com/r00t-3xp10it/venom