TGViewer
Channel Public Channel
MahadSec

MahadSec

@mahadsec

Subscribers
176
Photos
5
Videos
0
Links
9
Recent Posts 11 shown
Post #21 112

Forwarded from Bobur Abdugafforov

🇺🇿 O'zbekistondagi startuplar uchun taklif.

👨‍💻Hamma loyihasini qurish, investor topish, yangi funksiyalar chiqarish bilan band. Bu to'g'ri. Muammo chiqqunicha hech kim xavfsizlik haqida o'ylamaydi.

💧 Foydalanuvchilar ma'lumotlari oshkor bo'ladi, obro'ga putur yetadi, investor ishonchi yo'qoladi. Va bularning hammasi bittagina zaiflikdan boshlanadi.

🛡 @mahadsec jamoasi sifatida O'zbekistondagi startuplar uchun loyihangiz xavfsizligini bir marta bepul tekshirib beramiz.

Shunchaki scan qilib bermaymiz. Hammasi qo'lda, real hujumchi kabi sinab ko'riladi.

📄 Topilgan zaifliklar va tuzatish yo'llarini hisobot qilib beramiz.

Joylar cheklangan. Quyidagi link orqali ma'lumotlaringizni qoldiring, sizga bog'lanamiz.
🛡 mahadsec.com/startups
  • 🔥 7
  • ❤ 1
Post #20 1.13K
🏁 Mahadsec CTF is also live now!

Is solving machines too challenging right now? Start with easier CTFs to level up.

Start now:
🛡 https://my.mahadsec.com/ctf
  • 🔥 1
Post #19 1.43K
🐞 CVE-2025-24813 — Apache Tomcat (CVSS 9.8)

A path equivalence bug in Tomcat’s Default Servlet.

If writes are enabled and partial PUT is allowed, an attacker can abuse filenames like file.Name to plant content where they shouldn’t and in the right setup, that leads to remote code execution.

RCE needs a few things lined up:
• Default Servlet writable (readonly=false)
• Partial PUT enabled
• File-based session persistence
• A deserialization gadget on the classpath

Default installs are usually fine. Misconfigured ones are not.

Fix: upgrade to Tomcat 11.0.3 / 10.1.35 / 9.0.99, keep the Default Servlet read-only, and avoid file-based session stores unless you need them.


❓ Want to practice it hands-on?

Solve Bucket on MahadSec:
🛡 https://my.mahadsec.com/standalone-labs/machine/bucket
  • 🔥 1
Post #18 952
CVE-2025-55182 — React2Shell

🔴 CVSS 10.0. Unauthenticated RCE in React Server Components.

One crafted HTTP request to a Server Function endpoint → code execution on the server. No login. Default configs. Actively exploited in the wild.

If you’re running React 19 RSC / Next.js App Router and haven’t patched — do that first.

🗃 Affected packages: react-server-dom-webpack, -parcel, -turbopack (19.0 / 19.1.0–19.1.1 / 19.2.0).

Reading the advisory isn’t enough though.

Want to actually understand the attack path - enum the surface, craft the payload, get a shell, and see why this class of bug is
so dangerous?

Practice it on KickStore, an Easy Linux machine on MahadSec built around this vulnerability class.

🛡 https://my.mahadsec.com/standalone-labs/machine/kickstore

📁 Patch your apps. Then break the lab version so you recognize it next time it shows up in a real engagement.
  • 👍 2
Post #16 392
Your company's next breach isn't a zero-day.
It's the misconfiguration nobody checked.


At MahadSec, we find what scanners miss.

Here's what we offer:

🔴 Web App Pentesting — OWASP Top 10, API & business logic flaws, manual deep-dive testing
🔴 Network Pentesting — Internal/external, AD attacks, lateral movement, misconfig hunting
🔴 Cloud Security — AWS, Azure, GCP — IAM escalation, storage audits, CIS benchmarks
🔴 Red Team Operations — Full adversary simulation: phishing, C2, physical, post-exploitation
🔴 Mobile App Pentesting — iOS & Android reverse engineering, OWASP Mobile Top 10
🔴 Vulnerability Assessments — Attack surface mapping, CVSS scoring, compliance-ready reports

Every engagement includes:
✅ Manual-first testing (no scanner dumps)
✅ Developer-friendly reports with step-by-step remediation
✅ Free retest to confirm your fixes
✅ Direct communication with testers — no middlemen

We break it. We explain it. You fix it.

mahadsec.com/services
  • 🔥 4
  • ❤ 1
  • 🏆 1
Post #4 1.5K
🛡 Introducing MahadSec

🟣At MahadSec, we believe that a secure digital future begins with empowered, well-informed defenders. Our mission is to Innovate. Educate. Protect.

What Is MahadSec?
🟣A cybersecurity platform designed to challenge and grow your skills through hands-on “Capture The Flag” (CTF) competitions and interactive labs. Whether you’re just starting out or you’re an experienced pentester,

MahadSec offers:
🟣Real-world scenarios crafted by seasoned security professionals
🟣Diverse challenge categories: Networking, Web Exploitation, Forensics, Cryptography, Binary Exploitation, and more
🟣Hands-on learning via detailed write-ups and walkthroughs
🟣Dynamic leaderboards and community forums for collaboration and friendly competition

Why MahadSec?
🟣Cutting-edge challenges that mirror today’s threat landscape
🟣Continuous innovation in platform features, with weekly “CTF Drops” to keep content fresh
🟣A supportive community where knowledge is shared freely and inclusively
🟣Practical experience you can leverage in academic, professional, or personal cybersecurity pursuits

🔗 Stay Connected
Follow us for sneak peeks, challenge previews, and the official countdown:
🐦 X
🖥 Linkedin
📱 Instagram
🖥 YouTube

🌐 Learn more about us in our website:
https://mahadsec.com/
X (formerly Twitter) MahadSec (@mahadsec) on X Your Security. Our Mission.
  • 🎉 4
  • ❤ 3
  • 🔥 1
Post #1
Channel created

About this channel

How can I read @mahadsec without a Telegram account?
TGViewer shows the public web preview Telegram publishes for MahadSec: recent posts, photos, videos and the subscriber count, with no app, login or account.
How many subscribers does MahadSec have?
MahadSec (@mahadsec) has 176 subscribers on Telegram, refreshed roughly every 30 minutes.
Does MahadSec know I viewed it here?
No. Public channel previews carry no viewer identity, and TGViewer has no accounts or tracking of what you look up.
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →