olá amigos virtuais!
passando pra avisar que a segunda edição da @tramoia_sh está disponível ein!
é uma zine brasileira e focada em hacking raiz. nosso intuito é justamente manter essa cultura sempre viva!
estamos sempre aceitando submissões, seja em ptbr ou outros idiomas
e caso seu artigo seja aceito, ganha uma camiseta lindona ♥️
rt pra alcançar mais hackudos 🙏🏻
🚨 CFP aberto — Bug Bounty Village @ H2HC 2025 🚨
Achou um bug insano, bypass criativo ou tem case real de pentest/bug bounty?
Manda sua talk!
👉 https://t.co/qiinfEVgtH
#H2HC#BugBounty#Call4Papers#HackerCulture
CHAMADA DE ARTIGOS 2025
Mais artigos, novos autores, pwnage e 0days. Com esses objetivos iniciamos a nova Chamada de Artigos 2025 para a segunda edição!
Envie seu artigo para : [email protected]
New Active Directory Mindmap v2025.03! 🚀
📖 Readable version: https://t.co/gQd6WsLnzG
🔧 Now fully generated from markdown files—way easier to update and maintain!
💡 Got improvements? PRs welcome! 👉 https://t.co/o52PAmek7b
very pleased to announce the release of my new article based on my research that led to CVE-2024-46982 titled:
Next.js, cache, and chains: the stale elixir
https://t.co/UFndJxNYLI
note: does not cover the latest findings shared in my recent posts
enjoy reading;
ADCS Attack Techniques Cheatsheet for all of you lazy folks who prefer colored tables over reading a bunch of articles just to find some specific information:
https://t.co/HyvnCrBKnP
New writeup from @_specters_ and I: we're finally allowed to disclose a vulnerability reported to Kia which would've allowed an attacker to remotely control almost all vehicles made after 2013 using only the license plate.
Full disclosure:
https://t.co/e2EwvUMgqw
In August, watchTowr Labs hijacked parts of the global .mobi TLD - and went on to discover the mayhem that we could cause.
Enjoy....
https://t.co/maUn3dHnee
PHP just fixed one of my RCE vulnerabilities, which affects XAMPP by default. Check to see if you are affected and update now! 🔥
https://t.co/EQdzNTihOm
“Rook to XSS: How I hacked chess[.]com with a rookie exploit”
https://t.co/Gnur3tc8M5
Really great read! If you’ve never looked, https://t.co/G45QH58TNi has a great off-platform bug bounty program via [email protected]
This is a very unknown technique. Tried googling it and found no results, so maybe even a novelty.
This allows you to dump all domains from a Cloudflare user by doing nameserver correlation. Great for finding base domains owned by the company.
https://t.co/wIa4r7mZVR
Sharing my experience with alias path traversals on nginx, and how we leaked sensitive data on Bitwarden and GCP with that. Along with that, we also released a tool called navgix to check for the presence of these vulnerabilities in an automated manner.
https://t.co/D2MTRb7EEM
I hacked into a @Bing CMS that allowed me to alter search results and take over millions of @Office365 accounts.
How did I do it? Well, it all started with a simple click in @Azure… 👀
This is the story of #BingBang 🧵⬇️
The team at @OpenAI just fixed a critical account takeover vulnerability I reported few hours ago affecting #ChatGPT.
It was possible to takeover someone's account, view their chat history, and access their billing information without them ever realizing it.
Breakdown below 👇