Schlix CMS 2.2.7-2 Arbitrary File Upload - POC ---> https://news.1rj.ru/str/brutsecurity_poc/41
❤3👍1
Please open Telegram to view this post
VIEW IN TELEGRAM
🤣40🔥1
Nuclei v3.3.9 (@pdiscoveryio) has -ai option to generate and run nuclei templates on the fly in natural language.
This is a list of prompts for this option:
- sensitive data exposure
- SQLi
- XSS
- SSRF
https://github.com/reewardius/Nuclei-AI-Prompts
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥34👍6🗿2
Please open Telegram to view this post
VIEW IN TELEGRAM
🤣46👍6😢1🤨1
This media is not supported in your browser
VIEW IN TELEGRAM
Writeup- https://blog.chebuya.com/posts/server-side-request-forgery-on-sliver-c2/
POC- https://github.com/chebuya/exploits/tree/main/CVE-2025-27090%3A%20Sliver%20C2%20SSRF
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥43👍7❤2🤣1
CVE-2025-26465, -26466: Two vulnerabilities in OpenSSH, 6.8 rating❗️
MitM and DoS in OpenSSH. The severity level is medium, but the vulnerabilities cover many versions: from 2013 for -26465 and from 2023 for -26466.
Search at Netlas.io:
👉 Link: https://nt.ls/1TTrj
👉 Dork: ssh.server_key_exchange.client_to_server_compression:"zlib@openssh.com"
Read more: https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-discovers-two-vulnerabilities-in-openssh-cve-2025-26465-cve-2025-26466
MitM and DoS in OpenSSH. The severity level is medium, but the vulnerabilities cover many versions: from 2013 for -26465 and from 2023 for -26466.
Search at Netlas.io:
👉 Link: https://nt.ls/1TTrj
👉 Dork: ssh.server_key_exchange.client_to_server_compression:"zlib@openssh.com"
Read more: https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-discovers-two-vulnerabilities-in-openssh-cve-2025-26465-cve-2025-26466
👍10🔥5❤2😱1🤣1
Please open Telegram to view this post
VIEW IN TELEGRAM
10😱12👍7🔥7
CVE-2025-23209: Code Injection in CraftCMS, 8.1 rating❗️
Craft CMS contains a code injection vulnerability that allows for remote code execution as vulnerable versions have compromised user security keys.
Search at Netlas.io:
👉 Link: https://nt.ls/brxoj
👉 Dork: http.headers.x_powered_by:"Craft CMS"
Vendor's advisory: https://github.com/craftcms/cms/security/advisories/GHSA-x684-96hh-833x
Craft CMS contains a code injection vulnerability that allows for remote code execution as vulnerable versions have compromised user security keys.
Search at Netlas.io:
👉 Link: https://nt.ls/brxoj
👉 Dork: http.headers.x_powered_by:"Craft CMS"
Vendor's advisory: https://github.com/craftcms/cms/security/advisories/GHSA-x684-96hh-833x
🔥4👍2😱1
javanoscript:(function(){var noscripts=document.getElementsByTagName("noscript"),regex=/(?<=(\"|\'|\`))\/[a-zA-Z0–9_?&=\/\-\#\.]*(?=(\"|\'|\`))/g;const results=new Set;for(var i=0;i<noscripts.length;i++){var t=noscripts[i].src;""!=t&&fetch(t).then(function(t){return t.text()}).then(function(t){var e=t.matchAll(regex);for(let r of e)results.add(r[0])}).catch(function(t){console.log("An error occurred: ",t)})}var pageContent=document.documentElement.outerHTML,matches=pageContent.matchAll(regex);for(const match of matches)results.add(match[0]);function writeResults(){results.forEach(function(t){document.write(t+"<br>")})}setTimeout(writeResults,3e3);})();Please open Telegram to view this post
VIEW IN TELEGRAM
10👍7❤6🔥5🤝2
grep-backURLs - Automated way to extract juicy info with subfinder and waybackurls
https://github.com/gigachad80/grep-backURLs
https://github.com/gigachad80/grep-backURLs
1🔥12👍4
templates/processed/syslog-tcp-forward.conf
templates/processed/config.ini
Credit- Suyash Sharma
Please open Telegram to view this post
VIEW IN TELEGRAM
👍18🔥9❤2
https://github.com/iamunixtz/Lazy-Hunter
Please open Telegram to view this post
VIEW IN TELEGRAM
👍17🔥8❤3🗿1
Need an extensive SQL injection cheat sheet for bug bounty hunting and pentesting in general? 🧐
Check out @0xTib3rius' SQL Injection cheat sheet, it provides payloads for the 5 most popular databases such as MySQL, PostgreSQL, Oracle, etc.! 😎
🔗 buff.ly/3WeSO5X
Check out @0xTib3rius' SQL Injection cheat sheet, it provides payloads for the 5 most popular databases such as MySQL, PostgreSQL, Oracle, etc.! 😎
🔗 buff.ly/3WeSO5X
👏13👍6
🤝6
This media is not supported in your browser
VIEW IN TELEGRAM
urlhunter: A recon tool that allows searching on URLs that are exposed via shortener services
Link: https://github.com/utkusen/urlhunter
Link: https://github.com/utkusen/urlhunter
🔥18👍3❤2🤝2