@Phantasm_Lab – Telegram
@Phantasm_Lab
2.56K subscribers
712 photos
34 videos
671 files
2.71K links
- Red x Blue Security
- Bug Bounty 💷 💵
- Exploitable tools
- Programming Languages
- Malware Analysis

🇺🇸 🇧🇷 🇪🇸

since 2017 ©


Parceiros:
@TIdaDepressaoOficial @acervoprivado @ReneGadesx @G4t3w4y
Download Telegram
Alien Vault - The World’s First Truly Open Threat Intelligence Community

https://otx.alienvault.com/
What is Prometheus ?

Prometheus is an open-source systems monitoring and alerting toolkit originally built at SoundCloud. Since its inception in 2012, many companies and organizations have adopted Prometheus, and the project has a very active developer and user community

Prometheus collects and stores its metrics as time series data, i.e. metrics information is stored with the timestamp at which it was recorded, alongside optional key-value pairs called labels.

https://prometheus.io/docs/introduction/overview/
Vuln Research in VIDEO GAMES?!?!

Our adventure with FreeDroid RPG began when we were perusing the National Vulnerability Database (NVD) for video game-related bugs and discovered two CVEs from 2020 related to this game: CVE-2020-14938 and CVE-2020-14939. Both CVEs involved ways to maliciously manipulate the save game data—each fascinating in their own right. As we looked into the technical details of this original research from LogicalTrust, we noticed anomalies in the patches that were meant to address these vulnerabilities, sparking a deeper investigation

https://youtu.be/vHocemqpOuo?si=x7Et0MJdhwMdHTIv
🔎 Threat Intel Roundup: CrushFTP, CS2, Lazarus, Trigona
Week in Overview(5 Dec-12 Dec)
Forwarded from SHELL SHOCK
PiiScanner - Burp Suite Extension

A PiiScanner Extension é uma extensão para o Burp Suite desenvolvida para detectar informações de identificação pessoal (PII), especificamente CPFs do Brasil, em requisições e respostas HTTP. Esta extensão utiliza o Montoya API e implementa validações para garantir que CPFs válidos e inválidos sejam registrados, auxiliando na identificação de possíveis exposições de dados sensíveis.

https://github.com/vanguard-threat-seekers/vanguard-burp-pii-scanner
4👍2
The Greatest Video Game Pirate of All Time

EMPRESS is a renowned video game cracker known for their exceptional skills in bypassing digital rights management (DRM) protections. With a reputation for cracking the toughest security measures, EMPRESS has become a prominent figure in the gaming community, enabling players to access and play pirated versions of popular noscripts. Their contributions have sparked debates around piracy, copyright infringement, and the effectiveness of DRM in the gaming industry.

https://youtu.be/ZUioVa-wdDk?si=TKyx58h-k69KX60q
🔥8😱1
SpiderFoot - OSINT automation Tool

SpiderFoot is an open source intelligence (OSINT) automation tool. It integrates with just about every data source available and utilises a range of methods for data analysis, making that data easy to navigate.

SpiderFoot has an embedded web-server for providing a clean and intuitive web-based interface but can also be used completely via the command-line.

https://github.com/smicallef/spiderfoot
👍5
Bitbucket Monitoring Activity

Automation that sends alerts when new repositories are created. Bitbucket provides features to notify repository members about specific activities, such as code pushes, pull requests, and other events, but does not notify about new repositories created across the organization.


https://github.com/u37-Luth1er/bitbucket-monitoring-activity
👍1
Network Pivoting with Ligolo-NG

how you can use Ligolo-NG to setup simple network pivots for use in your OSCP prep and use Ligolo's handy listener functionality to transfer files and receive reverse shell connections from machines on internal networks!

https://youtu.be/DM1B8S80EvQ?si=dKB7Uc6MTFVOKItL
👍3
Hacking Security Cams & CCTV System's.
🔥9