Proxy Bar
21.2K subscribers
1.72K photos
104 videos
669 files
1.76K links
Exploits, Hacking and Leaks

Чат группы - https://xn--r1a.website/

Связь с администрацией и реклама:
@NULL_vm

Поддержать проект:
BTC bc1qmrt229eghjyj9wqa7nmr9j8zuq6khz6km2pker
Download Telegram
Malware Development Essentials for Operators: From PEB Walking to Kernel-Mode DKOM

Original English rewrite with full credit. This article is an independent English-language rewrite of “Malware Development Essentials for Operators”, published on f00crew.org (page /0x33). Author not clearly listed on the source page — site handle 0x00, no byline.

All technical content, code samples, ASCII diagrams, and VirusTotal screenshots are the work of the original author.…

https://core-jmp.org/2026/05/malware-development-essentials-for-operators-rewrite/
🔥9
educational project
Пфф, ну разумеется, о чем речь то

#rootkits #bootkits
🔥20👍4😱3
V2X2MAP: A $10 ESP32-C5 Board Plus an Android App Turns Live 802.11p V2X Traffic Into a Map

Original English rewrite with full credit. This article is an independent English-language rewrite of “Monitor live traffic from V2X signals with V2X2MAP open-source Android app and an ESP32-C5 development board”, by Jean-Luc Aufranc (CNXSoft), published on CNX Software on May 25, 2026.

All hardware photos, app screenshots, the legal disclaimer text and the underlying reporting…

https://core-jmp.org/2026/05/v2x2map-esp32-c5-android-v2x-traffic-monitor/
🔥9
Microphones Leak EM Signals Carrying Audio: A 93%-Accurate Side-Channel Attack on MEMS Mics

Original English rewrite with full credit. This article is an independent English-language rewrite of “Microphones leak EM signals carrying audio: new side-channel attack achieves 93% accuracy” by Denis Laskov, published in the Eye on Cyber Substack newsletter on May 24, 2026.

The Substack post itself is a short pointer to underlying academic work; the underlying…

https://core-jmp.org/2026/05/mems-microphone-em-side-channel-attack-rewrite/
😱7🔥5👍2
z386: An Open-Source FPGA 80386 Driven by the Original Intel Microcode

Original: This article is an independent of “z386: An Open-Source 80386 Built Around Original Microcode” by nand2mario, published on Small Things Retro on May 23, 2026.

All hardware research, RTL design decisions, performance measurements, block diagrams, die-shot annotations and benchmarks belong to the original author. Three of the original images (Doom II screenshot, 80386 block…

https://core-jmp.org/2026/05/z386-open-source-80386-fpga-microcode-rewrite/
🔥7
CVE-2026-5426: Mandiant Catches ViewState RCE Against KnowledgeDeliver LMS in Japan

Original: This article is an independent of “Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability” by Takahiro Sugiyama, Peter Revelant, and Mathew Potaczek, published on the Google Cloud Threat Intelligence (Mandiant) blog on May 25, 2026.

All incident-response work, IOCs, BLUEBEAM analysis, hunting queries, and the underlying disclosure (MNDT-2026-0009) are the work of the original authors…

https://core-jmp.org/2026/05/knowledgedeliver-viewstate-deserialization-cve-2026-5426/
🔥2👍1
OpenTrafficMap’s €20 ESP32-C5 Board Turns 802.11p V2X Into a Public Map of Traffic Lights and Buses

Original: This article is an independent of “OpenTrafficMap ESP32-C5 C-ITS receiver board can help improve traffic efficiency using 802.11p V2X communication” by Jean-Luc Aufranc (CNXSoft), published on CNX Software on May 24, 2026.

All hardware photos, deployment screenshots, the Graz Linux Days talk, and the underlying reporting are the work of the original author and…

https://core-jmp.org/2026/05/opentrafficmap-esp32-c5-cits-receiver-rewrite/
🔥8
CVE-2026-41873: Apache Pony Mail OAuth SSRF + Lua CRLF Smuggling = Unauthenticated Account Takeover

Original: This article is an independent of “(CVE-2026-41873) Apache Pony Mail CRLF Injection and SSRF Leading to Full Account Takeover”, by Li Jiantao and Tevel Sho, published on STAR Labs SG on 28 April 2026.

All vulnerability research, the PoC scripts, the Elasticsearch SQL exfiltration chain, the CRLF / HTTP-request-smuggling payload analysis, and the patch-diff…

https://core-jmp.org/2026/05/cve-2026-41873-apache-pony-mail-ssrf-crlf-rewrite/
🔥6👍4
Gargoyle, A Decade Later: Josh Lospinoso’s Memory-Scanning Evasion Idea, Refreshed for 2026

Original: This article is an independent of “Gargoyle, a decade later” by Josh Lospinoso, published on lospino.so on May 13, 2026.

All research, framing, the 2017 original Gargoyle proof of concept, the 2026 refresh, and the discussion of the broader sleep-obfuscation / temporal-memory-state family belong to the original author. The post contains no published code…

https://core-jmp.org/2026/05/gargoyle-decade-later-josh-lospinoso-rewrite/
🔥4
The epoll UAF: A Same-CPU Preemption Race in fs/eventpoll.c on Linux 6.6+

Original: This article is an independent of “The epoll uaf”, published on the personal blog at guysrd.github.io. Author not clearly listed on the source page — the site handle is guysrd, with no byline.

All vulnerability research, reverse engineering, the struct-offset table, the C excerpts from fs/eventpoll.c and the exploit-feasibility analysis are the work of…

https://core-jmp.org/2026/05/epoll-uaf-eventpoll-rcu-race-rewrite/
🔥3👍2
This media is not supported in your browser
VIEW IN TELEGRAM
GHSL-2026-140: Heap Buffer Write Overflow in 7-Zip

python3 gen_ntfs_sparse.py
👍11😱8🔥4
CVE-2021-21735: From Unauthenticated Information Leak to Full Admin Compromise on ZTE ZXHN H168N

Source & attribution. This is an original English rewrite of the writeup “Unauthenticated Information Leak to Full Admin Compromise on ZTE ZXHN H168N (CVE-2021-21735)” by Mina Zekry, published at minanagehsalalma.github.io. The accompanying public PoC repository is at github.com/minanagehsalalma/cve-2021-21735-zte-zxhn-h168n-admin-compromise. All technical observations, evidence images, code excerpts and the disclosure timeline are credited to the original author;…

https://core-jmp.org/2026/05/zte-zxhn-h168n-cve-2021-21735-admin-compromise/
👍5🔥4
Ghidra Basics: Reverse-Engineering Cobalt Strike Shellcode and Extracting the C2 Server

Source & attribution. This post is an original English rewrite of “How to Use Ghidra to Analyse Shellcode and Extract Cobalt Strike Command & Control Servers” by Matthew, published on Dec 08, 2023 at Embee Research (embeeresearch.io). All original screenshots are reproduced with attribution; the prose is paraphrased for core-jmp.org readers. For the canonical walkthrough,…

https://core-jmp.org/2026/05/ghidra-basics-shellcode-analysis-cobalt-strike/
🔥16👍2
CVE-2026-40369: Arbitrary Kernel Address Increment via NtQuerySystemInformation

Source & attribution. This post is an original English rewrite of “Arbitrary Kernel Address Increment via NtQuerySystemInformation (CVE-2026-40369)” by Ori Nimron (@orinimron123), published at pwn2nimron.com. The full exploit source lives at github.com/orinimron123/CVE-2026-40369-EXPLOIT. A shorter news-style coverage was also published by Daily CyberSecurity (securityonline.info). All IDA decompilations, the PoC source, the crash dump, the affected-versions table…

https://core-jmp.org/2026/05/cve-2026-40369-arbitrary-kernel-address-increment/
👍10🔥4😱2
Вчера на Linux тусе (Security of the linux kernel) мы как раз коллективно обсуждали нечто похожее, от hardware backdoors до дыр в sim-card
Ну так вот:
Сайты научились следить за юзерами через задержки в работе SSD
—PDF—
👍15🔥11😱6
Уютный 31 Мир ololo
🔥10👍3
CVE-2026-20182: Unauthenticated vHub Bypass in the Cisco Catalyst SD-WAN Controller

Original text: “CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)” — Jonah Burgess & Stephen Fewer, Rapid7 (May 14, 2026). Vendor advisory: cisco-sa-sdwan-rpa2-v69WY2SW. Code, tables and figures below are reproduced verbatim with attribution captions.

Executive Summary

CVE-2026-20182 is a critical (CVSS 10.0, CWE-287) authentication bypass in the Cisco Catalyst SD-WAN Controller — historically…

https://core-jmp.org/2026/05/cve-2026-20182-cisco-catalyst-sd-wan-vhub-auth-bypass/
👍4🔥2😱1
Reverse Engineering for Beginners: Defeating an XOR Crackme on Windows x64

Original text: “Reverse Engineering For Beginners – XOR encryption – Windows x64” — Chetan Nayak, Network Intelligence (July 29, 2025). The original tutorial was first published at scriptdotsh.com in May 2018 and the source code lives at paranoidninja/ScriptDotSh-Reverse-Engineering. Code, screenshots, register/value tables and worked XOR examples below are reproduced verbatim with attribution captions.

Executive Summary…

https://core-jmp.org/2026/05/reverse-engineering-xor-encryption-windows-x64-beginners/
👍5🔥3😱1
Visual Studio Extensions Revisited: Building, Publishing, and Hunting Malicious VSIXs

Original text: “Visual Studio Extensions Revisited” — MDSec Research (research by Dominic Chell), MDSec (28/05/2026). Code, tables and figures below are reproduced verbatim with attribution captions.

Executive Summary

Three years after their original work on VS Code extensions for red-team initial access, MDSec revisits the larger sibling — Visual Studio proper — and finds the…

https://core-jmp.org/2026/05/visual-studio-extensions-revisited-malicious-vsix/
👍5🔥4😱1
CVE-2025-61622: PyFory Insecure Pickle Deserialization to Remote Code Execution

Original text: “CVE-2025-61622: PyFory – Insecure Pickle Deserialization to Remote Code Execution” — SecureLayer7 Blog (May 28, 2026). Code blocks, screenshots and patch diff below are reproduced verbatim with attribution captions.

Executive Summary

CVE-2025-61622 is an unauthenticated remote code execution in PyFory (formerly PyFury / Apache Fory), an open-source high-performance Python serialization framework marketed as…

https://core-jmp.org/2026/05/cve-2025-61622-pyfory-pickle-deserialization-rce/
😱3🔥1