Proxy Bar
21.2K subscribers
1.71K photos
104 videos
669 files
1.76K links
Exploits, Hacking and Leaks

Чат группы - https://xn--r1a.website/

Связь с администрацией и реклама:
@NULL_vm

Поддержать проект:
BTC bc1qmrt229eghjyj9wqa7nmr9j8zuq6khz6km2pker
Download Telegram
SakDriver: Reversing a Windows Kernel Driver Rootkit

Original text: “SakDriver: Reversing a Kernel Driver Rootkit” — 0xSec, 0xsec.gitbook.io. Disassembly screenshots, the command-ID table, indicators of compromise and the YARA figure below are reproduced with attribution captions.

Executive Summary

What began as a routine look at a “Cobalt Strike Beacon” sample turned out to be something far more dangerous: a full Windows kernel-mode…

https://core-jmp.org/2026/07/sakdriver-reversing-kernel-driver-rootkit/
👍7🔥3
CVE-2026-57827 — Joomla
*
Component Unauthenticated File Upload RCE
Split-Controller Upload Bypass → Direct Write Task → /downloads/shell.php → RCE

Exploit
👍8🔥6
CVE-2026-66066 in Ruby on Rails
*
Storage file-read-to-RCE chain

*
PoC
👍6🔥4😱3
Longinus: Two Security Boundaries in One Bug — Piercing Chrome’s Renderer and the V8 Sandbox with CVE-2026-6307

Original text: “Longinus: 2 Boundaries in One Bug, Piercing Chrome’s Renderer and V8 Sandbox with a Single Vulnerability, CVE-2026-6307” — Nebula Security, NebuSec (June 29, 2026). Code, tables and figures below are reproduced verbatim with attribution captions.

Executive Summary

CVE-2026-6307 is a single V8 vulnerability that crosses two security boundaries at once. The root cause…

https://core-jmp.org/2026/07/cve-2026-6307-v8-framestate-type-confusion/
🔥5
CVE-2026-60004 Gitea RCE
(CVSS 9.8)
*
PoC
👍23🔥6😱2
CVE-2026-58025 MediaWiki
*
The deserialization flaw could lead to RCE via malicious log imports.
*
PoC
👍8🔥5
🔥12👍3😱3
Основные функции допилил, в cli все доступно, накидал gui для коробки
а вы как лето проводите ? 🏴‍☠️

#deadbox
🔥25
IDA pro 9.4
*
Linux + Windows + Mac + ARM
download
*
tree "/home/data/0x01/IDA/IDA pro 9.4/"
/home/reeves/data/soft/IDA/IDA pro 9.4/
├── ida-pro_94_armlinux.run
├── ida-pro_94_armmac.app.zip
├── ida-pro_94_armwin.exe
├── ida-pro_94_x64linux.run
├── ida-pro_94_x64mac.app.zip
├── ida-pro_94_x64win.exe
├── kg_patch
│   ├── idapro.hexlic
│   ├── keygen.js
│   ├── README
│   ├── x64linux
│   │   ├── libida32.so
│   │   └── libida.so
│   └── x64win
│   ├── ida32.dll
│   └── ida.dll
└── misc
├── hexlicsrv94_x64linux.run
├── hexvault94_x64linux.run
├── idapin94.zip
└── lumina94_x64linux.run

5 directories, 17 files
🔥36👍19😱12
defcon 34
*
media server
🔥10👍7
🔥18👍7
Продолжаем делиться интересным
*
DEFCON: New Red Team Tactic - EvilFontTool
👍15🔥11
This media is not supported in your browser
VIEW IN TELEGRAM
skitter-creek-bath-salts
*
exploit: “xor dword [0xf80c2094], 1<<22”

Unlocks CPU microcode, the platform security processor, system management mode, and every internal processor register, all at once, on 100 million AMD CPUs. As far as I can tell can’t be fixed.

get
👍11🔥2
This media is not supported in your browser
VIEW IN TELEGRAM
CVE-2026-68138
Linux qdisc rate-table race to local root

PoC
👍9🔥4
CVE-2026-41452 Krayin CRM
*
Auth Bypass → Admin Takeover

PoC
👍4🔥3😱2
CVE-2026-20217 File Drop to RCE
*
full WriteUP

+ PoC
👍8🔥4
Забавнейшая штука ! SSHDESK
пиксели и input идут внутри SSH PTY
Я так подумал, концептуально его можно превратить в HVNC под *nix, большая часть архитектуры то готова:
screen capture
mouse injection
keyboard injection
remote GUI
encrypted transport
управляющий канал !!!
*** осталось сдлеать отдельный desktop в параллель (desk 0 to desk X), user hide, ну и какую никакую persistence модель бы воткнуть

god bless SSH
👍14🔥12😱2
👍17😱4🔥2