⚠️ CVE-2025-32463
- Local privilege escalation: sudo versions 1.9.14 – 1.9.17
- CVSS: 9.3 (critical)
- reason :
- exploit :
https://github.com/kh4sh3i/CVE-2025-32463
@reverseengineer101
- Local privilege escalation: sudo versions 1.9.14 – 1.9.17
- CVSS: 9.3 (critical)
- reason :
/etc/nsswitch.conf from a user-controlled directory is used with the --chroot option
- exploit :
https://github.com/kh4sh3i/CVE-2025-32463
@reverseengineer101
🤯10❤5
Very happy to share these certificates I got recently
It was great to the labs there, I got more knowledge and new skills
It was great to the labs there, I got more knowledge and new skills
❤19👏5🥰1
Forwarded from Fly Dragon Fly
REVERSE ENGINEERING
Learn the art and science of reverse engineering through hands-on tutorials, practical examples, and real-world scenarios.
Master binary analysis, understand malware behavior, and develop the skills to deconstruct and analyze software systems.
https://reverseengineering.vercel.app/
Please open Telegram to view this post
VIEW IN TELEGRAM
reverseengineering.vercel.app
Reverse Engineering Academy
Learn the fundamentals of reverse engineering, binary analysis, and software security
❤16🔥4
For Egyptians
If you are looking for a place that you can find free professional courses in different fields as well as certificates then, Maharatech (ITI) is the place you are searching for
Visit https://maharatech.gov.eg
If you are looking for a place that you can find free professional courses in different fields as well as certificates then, Maharatech (ITI) is the place you are searching for
Visit https://maharatech.gov.eg
maharatech.gov.eg
Home | Mahara-Tech
maharatech is an online learning platform, offering high-quality courses authored by Information Technology Institute ITI, All Videos in maharatech Produced in ITI e-Learning Studio to serve Arab Youth in Information Technology Fields and avail Content for…
❤2
I'm not the person who is usually post about politics, but today is a very special day
Egypt is hosting today -in sharm el sheikh- a lot of world leaders
UK, USA, Italy, France, Qatar, turkey, Iraq, Saudi Arabia, Jordan, ...
We are missing Russia for the compelet package 😅
#peace_2025
Egypt is hosting today -in sharm el sheikh- a lot of world leaders
UK, USA, Italy, France, Qatar, turkey, Iraq, Saudi Arabia, Jordan, ...
We are missing Russia for the compelet package 😅
#peace_2025
❤8🔥1🫡1
reverse engineering
Unfortunately, today Oct 14 is the death day of Windows 10
After this,
The number of windows 7 increased (which is insane 😅)
But Linux still a great choice to try many people recommend Linux mint or Zorin OS, I personally recommend Pop! OS or Ubuntu to use
If you have fears about windows applications you can try Winboat, which is a free and open source project allows to run windows applications on Linux
https://github.com/TibixDev/winboat
The number of windows 7 increased (which is insane 😅)
But Linux still a great choice to try many people recommend Linux mint or Zorin OS, I personally recommend Pop! OS or Ubuntu to use
If you have fears about windows applications you can try Winboat, which is a free and open source project allows to run windows applications on Linux
https://github.com/TibixDev/winboat
❤3👍3
If you are looking for privilege escalation on a
https://swisskyrepo.github.io/PayloadsAllTheThings/Methodology%20and%20Resources/Linux%20-%20Privilege%20Escalation/
https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html
If you have some binaries like SUID bins and you don't know what to do, then search in GTFOBins
https://gtfobins.github.io/
Linux machine, then this is your guidehttps://swisskyrepo.github.io/PayloadsAllTheThings/Methodology%20and%20Resources/Linux%20-%20Privilege%20Escalation/
https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html
If you have some binaries like SUID bins and you don't know what to do, then search in GTFOBins
https://gtfobins.github.io/
swisskyrepo.github.io
Linux - Privilege Escalation - Payloads All The Things
Payloads All The Things, a list of useful payloads and bypasses for Web Application Security
❤5👍1
NSO Group has been acquired by U.S. investors, ending Israeli control
NSO Group is the company that develops every smart phone's nightmare Pegasus, the know Spyware
In my opinion it will still be used by Americans and Israelis for the same reasons they used before or the Israelis are developing something new
You can read the article: https://techcrunch.com/2025/10/10/spyware-maker-nso-group-confirms-acquisition-by-us-investors/
NSO Group is the company that develops every smart phone's nightmare Pegasus, the know Spyware
In my opinion it will still be used by Americans and Israelis for the same reasons they used before or the Israelis are developing something new
You can read the article: https://techcrunch.com/2025/10/10/spyware-maker-nso-group-confirms-acquisition-by-us-investors/
TechCrunch
Spyware maker NSO Group confirms acquisition by US investors | TechCrunch
NSO Group confirmed to TechCrunch that an unnamed group of American investors has taken “controlling ownership” of the surveillance tech maker.
❤5👀2🤬1
AWS is suffering from a huge technical problem that makes it almost down
Google services are affected as well as Preplexity AI also Chatgpt is affected
Really hard time for huge tech companies and other companies that use their services like hosting, this news is enough to make companies think twice before fully relying on a third-party or think about self hosting
Google services are affected as well as Preplexity AI also Chatgpt is affected
Really hard time for huge tech companies and other companies that use their services like hosting, this news is enough to make companies think twice before fully relying on a third-party or think about self hosting
❤8🤪2🥰1
reverse engineering
AWS is suffering from a huge technical problem that makes it almost down Google services are affected as well as Preplexity AI also Chatgpt is affected Really hard time for huge tech companies and other companies that use their services like hosting, this…
Docker and postman are down
There are some news says it's because of Russian cyber attacks
https://www.euronews.com/next/2025/10/20/huge-internet-outage-hits-mobile-apps-and-websites-such-as-amazon-heres-what-we-know
There are some news says it's because of Russian cyber attacks
https://www.euronews.com/next/2025/10/20/huge-internet-outage-hits-mobile-apps-and-websites-such-as-amazon-heres-what-we-know
😁4❤2
Hetty is an open-source and free HTTP toolkit designed for security research, useful to be a powerful alternative to commercial tools like Burp Suite Pro. It offers features specifically tailored for the needs of the infosec community
▲ For Linux:
https://github.com/dstotijn/hetty
▲ For Linux:
sudo snap install hetty
https://github.com/dstotijn/hetty
GitHub
GitHub - dstotijn/hetty: An HTTP toolkit for security research.
An HTTP toolkit for security research. Contribute to dstotijn/hetty development by creating an account on GitHub.
❤8👍2
Swift Announcing the Swift SDK for Android !
Swift now is available for android and can be used on windows, Linux and MacOS. really big news that might change the world of android development
https://www.swift.org/blog/nightly-swift-sdk-for-android/
Swift now is available for android and can be used on windows, Linux and MacOS. really big news that might change the world of android development
https://www.swift.org/blog/nightly-swift-sdk-for-android/
Swift.org
Announcing the Swift SDK for Android
Swift has matured significantly over the past decade — extending from cloud services to Windows applications, browser apps, and microcontrollers. Swift powers apps and services of all kinds, and thanks to its great interoperability, you can share code across…
🔥4
Next.js pentesting guide by Mr. Daoud Youssef
Really a very good and advanced article
https://deepstrike.io/blog/nextjs-security-testing-bug-bounty-guide
Really a very good and advanced article
https://deepstrike.io/blog/nextjs-security-testing-bug-bounty-guide
DeepStrike
Next.js Security Testing Guide for Bug Hunters and Pentesters
Learn how to assess Next.js apps for SSRF, XSS, CSTI, SSTI, CSRF, cache issues, and data leaks. Practical tips, checks, and tools for bug bounty and pentesting.
❤2
CVE-2025-59287
⚠️🚨CVSS: Critical 9.8
ဗ Affected: Windows Server Update Service (WSUS)
▲Description: Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
https://nvd.nist.gov/vuln/detail/CVE-2025-59287
⚠️🚨CVSS: Critical 9.8
ဗ Affected: Windows Server Update Service (WSUS)
▲Description: Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
https://nvd.nist.gov/vuln/detail/CVE-2025-59287
❤3🥰1🤣1