Cyber0жff666 λ
115 subscribers
167 photos
209 files
522 links
Cyber intelligence corporation.

C, C++, Assembly, UNIX, Malwares, Ransomwares, Information Security, Networks and Anonymity

new group link in: @intell666
Download Telegram
https://github.com/Jasawn/python-instagram-story-visualiser

Instagram Instagram Story Visualizer – Extract location data on Instagram.
The tool reads stories and displays the location data of selected users on an interactive map with a user-friendly interface.
Millions of GitHub Repositories Are Vulnerable To RepoJacking

An attack called RepoJacking may potentially affect millions of GitHub repositories. If abused, this vulnerability might result in code execution on the internal networks of organizations or on the networks of their customers.  This includes the repositories of companies like Google, Lyft, and many others. It has many high-quality targets that are vulnerable to attack. […]
The post Millions of GitHub Repositories Are Vulnerable To RepoJacking appeared first on GBHackers - Latest Cyber Security News | Hacker News....

Continue reading at GBHackers – Latest Cyber Security News | Hacker News
Discord is spyware because it collects all information that passes through its communication platform. As Discord is a centralized communication platform, all communications have to go through Discord's official servers, where all of that information can potentially be recorded. The vast majority of said information has been confirmed to be recorded, such as all communications between users. Discord has also been confirmed to use other spyware features such as various forms of telemetry. Discord's main source of income is from investment, from which it has received over $279.3 million dollars. Discord cannot be built from source and the source code for Discord is unavailable.

https://spyware.neocities.org/articles/discord
2
Исследователь продемонстрировал деанонимизацию Tor-серверов через ETag

https://xakep.ru/2023/06/19/tor-etag/
👍1
CVE-2023-35086 POC - ASUS routers format string vulnerability

July 25 2023, Altin (tin-z), github.com/tin-zBrief descriptionASUS RT-AX56U V2 & RT-AC86U router firmwares below or equal to version 3.0.0.4.386_50460 and 3.0.0.4_386_51529 respectively have a format string vulnerability in the detwan.cgi function of the httpd service that can cause code execution when an attacker constructs malicious data.
The vulnerability affects also other ASUS devices using httpd service.
Read here for more details.
references:PocThe vulnerability permits achieving RCE, meanwhile the PoC only achieves DoS, mainly because the firmware was emulated with QEMU and so the stack is different from the real case device.
Prerequisites:The value of 'Referer' header should contain the target's addresspoc_crash.pyvirtualenv --python=python3 .venv source .venv/bin/activate pip install hexdump python poc_crash.py --HOST ...

Continue reading at github.com (from /r/netsec)
👍1