🚨🇺🇸A Threat actor is claiming to have leaked, for 0 credits, 2.8 billion Twitter/X users merged with a 2023 200M Twitter breach
The amount of rows in the csv file is 201,186,755. To be fair, I did a search for my data based on the fields in the file and none of my data came up; Username, Name, Email (Disposable).
The file is 9GB and is 34.1GB uncompressed. The name is: twitter_200M_AppendedWith_2.8B.7z.
Fields: ID,screen_name,name,name 2021,location,description,url,Email,time zone,language,followers_count 2021,followers_count,friends_count,listed_count,favourites_count,statuses_count,protected,verified,default_profile,default_profile_image,last_status_created_at,last_status_source,created_at
🚨🚨CVE-2024-46538: PfSense Stored XSS lead to RCE
⚠️A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $pconfig variable at interfaces_groups_edit.php.
ZoomEye Dork👉app:"pfSense Firewall httpd"
612k+ results are found on https://t.co/jfhKNZYvyg.
ZoomEye Link: https://t.co/ne2ufIl6S7
Refer: https://t.co/HQsSPhb4IS
If you want to know more cybersecurity information, please join
Telegram: https://t.co/AUq5jNpKkl
Discord: https://t.co/gkuYBJpBwY
#RCE #Cyberspacemapping #cybersecurity #ZoomEye #infosec2024
GitHub - loxy0dev/RedTiger-Tools: RedTiger-Tools is a free multi-tool with many features in the areas of Cybersecurity, Pentesting, OSINT, Network Scanning, Discord and Hacking. https://t.co/6oaMp1MHNL
🛡️ The U.S. government has released new guidance on the Traffic Light Protocol (TLP) to enhance controlled sharing of threat intelligence, enabling organizations to protect sensitive data while responding to cyber threats.
Learn more: https://t.co/uRBWPZZDeT
#cybersecurity
Offensive Security Tool: SQLMutant
SQLMutant is written by Chris Abou-Chabké from Black Hat Ethical Hacking and its a comprehensive SQL injection tool. It uses a variety of techniques to detect vulnerabilities, including pattern matching, error analysis, and timing attacks, ensuring that no stone is left unturned. In addition to its powerful features, SQLMutant also integrates with Waybackurls and Arjun, enabling it to find even more parameters and merge all results together. This integration is highly beneficial as it provides automated subdomain enumeration and SQL injection testing capabilities.
Requirements:
To use SQLMutant, you need to have the following tools installed:
figlet & lolcat: pip install lolcat & apt-get install figlet
Waybackurls : go install https://t.co/41JLMQHApH
Arjun: pip install arjun
SQLMap: git clone --depth 1 https://t.co/aRBCav1rLn sqlmap-dev
Installation
git clone https://t.co/hVnYwtUvwi
cd SQLMutant
chmod +x https://t.co/TwVnfjW0DR
./SQLMutant.sh
Read the full post: https://t.co/6j2PGyIEMo
#sqli #sqlinjection #hacking #bugbounty #pentesting #infosec #informationsecurity #offensivesecurity #redteam
Flipper Zero Unleashed Firmware : https://t.co/cz1yxvVzRO
awesome-flipperzero : A collection of awesome resources for the Flipper Zero device : https://t.co/uty3s3QjdV
Flipper : Playground (and dump) of stuff I make or modify for the Flipper Zero : https://t.co/tgSEo99okI
Try : https://t.co/dcKYdlF7Df
🔥 A new tool to uncover website ownership and investigate information campaigns using various technical indicators and searching for similar content.
👉 https://t.co/4B3Ws1POqa
Read more about the need for detecting copied content in OSINT in SOWEL: https://t.co/dnevf05ARI
After publishing Nuclei templates for AWS security checks, our template team is now working on publishing Nuclei templates for Kubernetes cluster security.
See ongoing progress at https://t.co/E63tkL4g7Z and share any feedback.
#cloudsecurity#k8s#CyberSecurity
INTRODUCING: Agentic Security - LLM Security Scanner! 🔍
🔑 Features:
Scans for prompt injections, jailbreaking & more.
Provides detailed reports & options to customize attack rules.
🔗access the GitHub Link ↓
You can still find SQL injections in User-Agent/ or other request-headers; you just need a keen eye to find it.
Make sure to include SQLi testing on headers in your methodology. Developers often tend to ignore headers. #BugBounty#SQLi#SQLInjection
Leaked passwords database search tool
Search by 3,2 billions leaked credentials by:
- email
- nickname
- password
(you can also try searching by mobile number, as some people use it as a password)
https://t.co/b6LXZAVpBR
Tip by @SaltinDeadsec