Последние посты

1N73LL1G3NC3
20 сент., 06:46
BigDiskBusterWindows Defender Update Denial of Service Vulnerability.


1N73LL1G3NC3
18 сент., 15:18
cups2root Linux LPEInteractive root shell from a local account in the lpadmin group.


1N73LL1G3NC3
16 сент., 16:42
Exploit module for N-able N-central unauthenticated RCE (CVE-2026-86218)Blog: https://www.rapid7.com/blog/post/ve-cve-2026-86206-cve-2026-86207-n-able-n-central-authentication-bypass-fixed/FOFA Query: app="N-Able-N-Central-Monitor-MGMT"


1N73LL1G3NC3
11 сент., 10:37
Хак тайм епта…Кто понял, тот понял😸


1N73LL1G3NC3
9 сент., 03:56
переслано из @ralfhackerchannel
Продолжаетсяhttps://github.com/MSNightmare/ShieldCrashWindows Defender 0day Vulnerability#ad #lpe #exploit #git


1N73LL1G3NC3
8 сент., 17:04изменён
🔗 NTLMRain web lookup 🔗 NTLMRain CLI tool on GitHubRecover NT hashes from NetNTLMv1 responses using local WebGPU computation and remote table lookup.Blog: NetNTLMv1 Is Dead. Long Live NetNTLMv1.Fitting lossless rainbow tables on a 4 TB disk and cracking NetNTLMv1 with WebGPU and ntlmrain.Google’s release of the NetNTLMv1 rainbow tables made it much more practical to recover an NT hash from a NetNTLMv1 response captured with the fixed challenge 1122334455667788, further reducing the needed compute power.NetNTLMv1 cracking is a problem I’ve kept returning to over the past several years. The recent table release prompted me to explore whether the process could be made cheaper, faster and easier to run. This post describes the result: a compact indexed table format, a WebGPU browser client and a native command-line tool.


1N73LL1G3NC3
8 сент., 08:45
CVE-2026-62735Windows HTTP.sys Elevation of Privilege.Blog: https://hackmd.io/@nhh/Hy6Oem7_Me


1N73LL1G3NC3
8 сент., 06:27изменён
SonicWall SMA1000 unauthenticated RCEExploit for last weeks SonicWall SMA1000 zero-day chain that has been exploited in-the-wild (CVE-2026-83548 + SMA1000-9427 + CVE-2026-83549). It a 3 bug chain; an SSRF to CouchDB read/write for low priv RCE, to root RCE via command injection in cmsSnmpTrap.


1N73LL1G3NC3
7 сент., 06:23изменён
CVE-2026-67276MikroTik lab PoC — RouterOS SSH public-key auth bypass


1N73LL1G3NC3
5 сент., 10:26
M0nCrushKernel-mode process terminator using a signed BYOVD driver (MonProcessEX.sys). Works on all Windows 10/11. No offsets, no PDB. Rust.
1N73LL1G3NC3
4 сент., 09:43
VMware threat emulation techniquesA reproducible catalogue of 86 atomic actions against vCenter, ESXi, SDDC Manager, and the wider VCF ecosystem — sourced from threat intelligence reporting, mapped to MITRE ATT&CK, and paired with the log sources where evidence is expected.


1N73LL1G3NC3
3 сент., 06:52
переслано из @ralfhackerchannel
Идем дальшеhttps://github.com/MSNightmare/FalconFlankCrowdstrike Falcon 0day LPE#lpe #ad #exploit #git


1N73LL1G3NC3
1 сент., 06:47
Exploit module for the recent PaperCut MF/NG 0day (CVE-2026-81578 + CVE-2026-82078)Module supports both MF and NG editions, and all supported product versions 26.x, 25.x, 24.x. Bypasses vendor emergency patch v1. Emergency patch v2 successfully remediates the chain. Module also has platform agnostic Java payload support (and that will be in-memory on 26.x targets), along with OS command based payloads.Blog: https://www.rapid7.com/blog/post/etr-papercut-ng-mf-critical-zero-day-exploited-in-the-wild/


1N73LL1G3NC3
31 авг., 04:07
PrettyPragueGenDigital Avast Antivirus ZeroDay Elevation of Privileges VulnerabilityAnother zeroday in an antimalware provider, I'm not sure but I believe this vulnerability affect other GenDigital products as well (such as AVG, Norton...)For now the PoC is compatible with any version of Avast Antivirus.The PoC will dump the SAM database by abusing a vulnerability in Avast Sandbox and spawn a full SYSTEM shell, at the time of writing this the PoC works with fully patched Avast Antivirus + Patched Windows 11 25H2


1N73LL1G3NC3
29 авг., 08:56
HardBreacherKaspersky Antivirus For Endpoint ZeroDay Elevation of Privileges Vulnerability


1N73LL1G3NC3
27 авг., 17:37
PRTremoteExtract Primary Refresh Tokens (PRT) Cookies Remotely with InteractiveToken Scheduled TasksBlog: https://www.armadin.com/blog-posts/prtremote-extract-prt-cookies-remotely-with-interactivetoken-scheduled-task


1N73LL1G3NC3
24 авг., 13:08
CrystalPotatoA Crystal port of GodPotato, a local privilege escalation tool that abuses the DCOM OXID Resolver and named pipe impersonation to escalate from service accounts with SeImpersonatePrivilege to NT AUTHORITY\SYSTEM.The main contribution of this port beyond the language change is a set of OPSEC improvements designed to reduce the binary’s signature surface.Blog: https://ricardojoserf.github.io/crystalpotato/• GodPotato - Original C# • RustPotato - Rust implementation • SigmaPotato - C# implementation



1N73LL1G3NC3
21 авг., 08:41
SSHDESKA full interactive remote desktop delivered entirely through SSH and displayed directly in your terminal. OpenSSH authenticates the user and launches SSHDESK as a forced command. The active graphical desktop then appears inside that same terminal. Keyboard, mouse, resize events, changed pixels, and session cleanup all travel through the one SSH PTY. There is no browser, custom SSH client, VNC/RDP listener, second password database, web server, or additional network port.
1N73LL1G3NC3
19 авг., 17:51
Synology-Inventory-DecryptorA post-exploitation tool that instantly decrypts all credentials stored in Synology Active Backup for Business (ABB) config.db, yielding plaintext passwords for ESXi, vCenter, Hyper-V, Windows/Linux servers, MSSQL, and Oracle databases. Tested only on a Synology DS920+ NAS.Blog: https://blog.offseclabs.tech/posts/synology-active-backup-decrypting-inventory-credentials/


1N73LL1G3NC3
19 авг., 17:40изменён
BOFScaleA collection of BOF-PE's that allow running tailscale from memory. A CDN-fronted tailnet from a BOF-PE. The entire Tailscale daemon runs inside the implant process with no driver, no service, no disk state, and no child processes. Traffic relays over standard RFC 6455 WebSockets, so both DERP relay servers and the control plane can sit behind CloudFront or Fastly without any special handling.Blog: https://www.netspi.com/blog/technical-blog/red-teaming/bofscale-a-cdn-fronted-tailnet-from-a-bof-pe/

