@gkpacker@0xVasconcelos A preocupação do cara é tão grande de não ter o “nome dele atrelada essa parada” que ele publica no X e ainda cria uma caralhada de grupo para falar sobre o tal feito incrível dele
Testing for postMessage vulnerabilities? 🤠
Your web console includes this useful breakpoint feature that allows you to intercept postMessage calls! Here's how:
1. Navigate to your target that uses postMessages
2. Open the Sources tab in your web console
3. Check the message property under Event Listener Breakpoints
4. Whenever a new postMessage call is received, you'll be able to fully inspect it, including the code!
More in next post! 👇
My 2 new CVES!!
https://t.co/uHCraWAffE
https://t.co/9lPt2z61I7
The first one allows RCE using SSTI and the second one is a html injection storage! Both on TacticalRMM
Thanks for my teammates: m0unt ( Ntgabriel) and 0xL1zard
CVE-2025-69516 A Server-Side Template Injection (SSTI) vulnerability in the /reporting/templates/preview/ endpoint of Amidaware Tactical RMM, affecting versions equal to or earlier … https://t.co/TPbkUJCH7h
CVE-2025-45160 A HTML injection vulnerability exists in the file upload functionality of Cacti <= 1.2.29. When a file with an invalid format is uploaded, the application reflects th… https://t.co/AmfuGs3Vb0