Build Custom multimodal agents in minutes.
You can now fine-tune Qwen3.5 2B🫠
Run locally on a potato GPU
5GB train Qwen3.5-2B LoRA,1.5x faster with 50% less memory. By @UnslothAI Vis text
0 dollars in Qwen3.5-4B Colab: https://t.co/9c9VfvNuYi
Github : https://t.co/pihhisnPWR
Fancy DLL sideloading? Add built-in licensingdiag.exe to your toolbox. It will load everything listed under Windows NT\CurrentVersion\LicensingDiag and then call exported InitializeCollector() function.
BTW have they heard about REG_EXPAND_SZ?
My new blog post! Dissecting and Exploiting TCP/IP RCE Vulnerability “EvilESP”. Reverse engineering CVE-2022-34718 + write a remote Denial of Service exploit. Covers IPsec and IPv6 fragmentation in the Windows kernel, bin-diffing, and making weird packets https://t.co/XR8qhoq1ub
PoC Exploit Released for 0-day Windows Kernel
of Privilege Vulnerability (CVE-2024-21338) : https://t.co/vBcaCQ9MSi
https://t.co/vHofGL819e
Details : https://t.co/ngV9GWaYDU
I just released the exploit and technical analysis of my CVE-2023-36424 - Windows Kernel Pool (clfs.sys) Corruption Privilege Escalation.
Happy Reading.
https://t.co/Z0He4FCgtR
#exploit#cybersecurity#news
Introduction to Windows Kernel Exploitation for Beginners
Part 1: https://t.co/iytco8khA0
Part 2: https://t.co/Kr5z56e0pV
Part 3: https://t.co/sdI2uEndk6
Part 4: https://t.co/6DmUNO3iQU
Part 5: https://t.co/CW1ulPqGqq
#windows#infosec#kernal#exploit#100xSecurity
The Complete Malware Development Guide
Part 1:
https://t.co/BFjBaO4PCV
Part 2:
https://t.co/v5Zc8qydnH
Part 3:
https://t.co/bf1tj6lbKC
Part 4:
https://t.co/qSOfOvObp1
Part 5: DLL injection into the process
https://t.co/qIsHp4kN6W
Part 6: DLL hijacking
https://t.co/2fdRlxdYH1
Part 7: Advanced Code Injection
https://t.co/vTSjy1iZ7B
Part 8: Reverse Shell Via Dll Hijacking
https://t.co/QPd69K83bl
#malware #infosec #100xSecurity #dll
Cool finding from my colleague @cj_berlin detailed here: https://t.co/zzDlXDxXZv. PS remoting and SSH ignores "Deny Logon restrictions". So if you enable SSHd on a Domain Controller, every domain user can log in... and, for example, perform a #RemotePotato0 attack 😲
Wrote an Custom DLL Libraries and Injector using Rust with explanation.
Code+Explanation:https://t.co/Hsj9AGeUfa
POC : Executing exe's files from custom dll's and impl function linkages among dll's in Rust.
#maldev#rustlang#offensiverust#dll#redteam
CVE-2024-25600: Unauth. RCE vulnerability caused by PHP code injection in Bricks Builder, a WordPress site builder with over 25,000+ active installations.
Severity: Critical (CVSS 9.8)
Root cause analysis: https://t.co/E5K0sIZQn9
PoC: https://t.co/8DflZk7QIW
Mitigation: Upgrade
Got a working POC for CVE-2024-23208 UaF in one app. It uses the keyboard extension for the receiver.
Instructions to crash your phone:
Press go
Open the keyboard
Clear the app
Github: https://t.co/LXA6yW5Ul5
Reproduced the CVE-2023-46747 F5 Big-IP RCE via AJP smuggling. Props to @praetorianlabs for identifying this cool bug. @pdnuclei template dropping soon. Time to sleep😴 #f5-rce #CVE-2023-46747
¡Agradecemos a todos los equipos participantes de este año en las clasificatorias y final! Fue otro año exitoso gracias a ustedes ¡Nos vemos en 2024! #Hackmex24