FBI Watchdog 3.0.0: A multi-layered domain monitoring tool that detects law enforcement seizures, DNS changes, HTTP fingerprint shifts, WHOIS record mutations, and IP address changes across clearnet domains and Tor onion sites.
https://t.co/3Q6SKLei3v
This is HUGE! 🪝🐟
Make sure to check out what @NathanMcNulty has cooked up!
You can use webhooks with Evilginx Pro to send out the ESTSAUTH cookie, captured through phishing, and use Nathan's script to register a passkey for persistence automatically. 🔥
Nathan took a quick trip to the dark side... for science! 😂
🔍 Bug Bounty Tip: WAF Bypass
Evade WAF’s URL normalization with double encoding (%252f) or unusual paths.
Example: /api/v1/%2e%2e/%2e%2e/config?id=1%252bUNION%252bSELECT%252bsecrets--
Test only on authorized systems!
#Cybersecurity#BugBounty
🔐 WhatsApp Crypt Tool to Encrypt and Decrypt WhatsApp Backups
Source: https://t.co/pWtX5idOxz
An open-source solution for handling encrypted WhatsApp backups. The wa-crypt-tools suite, hosted on GitHub, decrypts and encrypts .crypt12, .crypt14, and .crypt15 files from WhatsApp and WhatsApp Business, provided users supply the required key file or 64-character key.
wa-crypt-tools simplifies access to WhatsApp's end-to-end encrypted backups, which store chat histories, media, and metadata in SQLite databases or ZIP archives.
#cybersecuritynews
🚨 Critical RCE (CVSS 10) vulnerability affecting n8n instances: CVE-2025-68613
I've created a vulnerability detection script here:
https://t.co/WVGrr4SUSM
No signs of active exploitation, yet.
Patches are available and users are strongly advised to upgrade to version 1.122.0 or later, which introduces additional safeguards to restrict expression evaluation.
Workarounds are available as mentioned here:
https://t.co/bRpVVPMBfY
WAF Bypass Discovered - Akamai & Cloudflare
A fresh technique has been spotted that successfully bypasses WAFs like Akamai and Cloudflare.
#infosec#Cybersecurity#bugbountytip
Always thoroughly examine your targets' .js and .js.map files; these files can always provide you with great information about your target. 🥳👍
My tool: https://t.co/0cYQPyZMtW
#DevTools#JsMap#bugbountytip#bugbountytips#InfoSec#recon
@IndianTechGuide Not worth it🙏🏻
Same thing happened with the Perplexity and Airtel
Even free version was working better than the premium version for free they offered
@ide9x In cloud fair, there is one setting
Inside security, there is option called TLS SSL
There you will find one option called config in which unit to change from fix to flexible
That should solve the issue