reconcore
Статистика#vulnerability #research #cve #rce #lpe #poc #tools #pentest #redteam #blueteam #offensivesecurity #technique #methods Educational use only. Content from public sources. Admin holds no liability for misuse. Users are solely responsible for their actions.
- Последний пост
- 14 авг.
- Последнее чтение
- 12:14
- Постов за неделю
- 6
- Всего постов
- 1 123
- Тип
- открытый
- Язык
- английский
- Категория
- Новости и СМИ (по похожим)
- В каталоге с
- 12 авг.
- 1/24сутки в ленте
- 346
- 1/48двое суток
- 396
- 1/72трое суток
- 427
Оценка по просмотрам недавних постов: пост набирает почти всё за первые сутки.
Посты
VsockDrop Linux kernel LPE via an io_uring zerocopy page-refcount underflow over AF_VSOCK. (CVE-2026-53365) Bug affects Linux 6.7 -> 7.0.10, fixed in 7.0.11. Tested on unpatched Ubuntu 22.04 HWE/24.04/26.04, Debian 13, Arch, and openSUSE Leap/Tumbleweed. #cve #linux #lpe #kernel @reconcore
CDP-Enable-BOF After enabling CDP, you can use CDP-Toolkit to connect to the endpoint directly or through a SOCKS proxy. Its commands support enumerating open tabs, searching browser history, extracting cookies and saved passwords, capturing screenshots, listing bookmarks, managing extensions, and navigating the browser to specified websites via the Chrome DevTools Protocol APIs. CDP-Toolkit Commands: discover tabs list tabs screenshot cookies dump bookmarks list history search saved-passwords list saved-passwords dump extensions list extensions load page new page snapshot page close contexts list contexts dispose browser-takeover screencast browser-takeover proxy Return of the Cookie Monster This post explores enabling the Chrome DevTools Protocol (CDP) inside a running Chromium browser to perform post-ex activities such as browser enumeration, cookie theft, and browser takeover #bof #cdp @reconcore
CVE-2026-64638: Pre-auth reflected XSS in WordPress, 8.9 rating WordPress is vulnerable to a pre-auth reflected cross-site scripting (XSS) on the login screen, which can be escalated to RCE. https://app.netlas.io/responses/?q=tag.name%3A%22wordpress%22&page=1&indices= dork — tag.name:"wordpress" #wordpress #xss #rce @reconcore
ShieldBreak - Windows Defender 0day vulnerability Microsoft has failed to properly patch the RoguePlanet vulnerability CVE-2026-50656, this PoC demonstrates a full patch bypass. The PoC was tested in the latest version of windows 11 25h2 (+Canary channel) and windows server 2025, the PoC also have a 100% success rate. Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well. #vulnerability #poc #lpe #ad #zeroday @reconcore
Dumping NTLM Hashes from Windows Memory via forensics tools What can an attacker recover from a Windows memory image after gaining access to an endpoint? WinPmem → Volatility 3 → SYSTEM/SAM → NTLM #redteam #offensivesecurity @reconcore
DEF CON 34
Plug & Pwn: Weaponizing Windows PnP Every time a USB device is plugged into a Windows machine, the operating system may silently download a package from Microsoft and execute vendor code as NT AUTHORITY\SYSTEM. That can happen without administrator privileges, without a logged-on user, and in some environments even remotely through RDP USB redirection. #defcon #technique #methods #rdp #lpe #smb @reconcore
Vipere BOF exploiting the Visual Studio Installer Elevation Service for SYSTEM LPE and persistence via AppDomainManager hijacking, with native ETW evasion. For Cobalt Strike & Adaptix. Windows 11 25H2 Build 26200 (July 2026: fully patched) Visual Studio 2022 Build Tools 17.x Windows Defender (current definitions) #bof #coff #loader #etw #edr #bypass @reconcore
ResetNightmare Proof-of-concept (POC) tool for ResetNightmare (CVE-2026-27912). ResetNightmare is a validation flaw in the Kerberos Change Password protocol that allows for resetting the password of any target user/computer account, without knowing the current one. The attack requires an unpatched domain controller, and the ability to write a userPrincipalName (UPN) on any account you control. Alternatively, the vulnerability can also be abused by an attacker having the ability to create new users/computers in any OU, as creating a user/computer allows you to get GenericWrite permissions over it. Identity Crisis: Novel Vulnerabilities Leading to Kerberos Downgrade, DoS, and Full Domain Takeover #vulnerability #kerberos #poc
Unauthenticated Remote Code Execution in JetBrains TeamCity CVE-2026-63077 This is a proof-of-concept exploit script for CVE-2026-63077. Organizations can use this script to validate their detection and remediation posture. For a full technical analysis of CVE-2026-63077, please read our Rapid7 Analysis. #cve #poc #analysis @reconcore
Nocturne A CET-compatible Windows x64 loader that produces fully backed call stacks through runtime function table manipulation, code cave injection, and inverted function table collapse. #edr #evasion #bypass #payload #loader #redteam #sleep #obfuscation @reconcore
ClamAV 1.5.x Memory Corruption Vulnerabilities This is the minimized, three independently patchable ClamAV findings. Each package contains a concise advisory, a local Docker reproduction, the PoC source, a proposed source patch, and the minimum preserved evidence needed to validate. 100% Clanker generated with a touch of meatbag commentary to finish the report. #vulnerability #zeroday #av #poc @reconcore
MariaDB 13.0.1-rc RCE Lab Remote code execution on the unmodified, stock MariaDB 13.0.1-rc Docker image as uid 999 (mysql). #sql #rce #poc @reconcore
CVE-2026-57239 Foxit PDF Reader LPE Proof of concept exploit for CVE-2026-3775/CVE-2026-3780 and CVE-2026-57239 which lets you obtain NT AUTHORITY\SYSTEMrights via the Foxit PDF Reader updater service. Escalating All The Privileges With Foxit PDF Reader CVE-2026–57239 #poc #cve #lpe @reconcore
CVE-2026-60004 Gitea RCE (CVSS 9.8) Remote Code Execution via diffpatch Git Hook Installation #cve #rce #poc @reconcore
PoC for CVE-2026-66066 - Minimal stock Rails/libvips lab This repository reproduces the Rails Active Storage file-read-to-RCE chain described byGHSA-xr9x-r78c-5hrm against Rails 8.1.3, the newest affected Rails 8.1 release. Rails 8.1.3.1 is the patched control. Use it only in the disposable local lab described here. The HTTP driver refuses non-loopback targets (although trivial to modify the Python code for authorized testing against other targets). #cve #rce #ruby #rails #poc @reconcore
CVE-2026-57827 critical-severity (CVSS 9.8) unauthenticated arbitrary file upload vulnerability in RSFiles! (com_rsfiles), a widely used file-manager and download component for Joomla, versions < 1.17.12. The vulnerability exploits a split-controller design flaw: RSFiles! separates its upload into two frontend tasks — a pre-flight check (permission gate + extension allow-list) and a write method (saves file to disk). The write method can be called directly, bypassing the pre-flight check entirely. No authentication, no CSRF token required. #vulnerability #cve #joomla #csrf @reconcore
Red Team Engineering 2026 #redteam @reconcore
Check Point SmartConsole Authentication Bypass CVE-2026-16232 Authentication bypass via the SmartConsole login process using an application token. This affects Check Point Security Management Server and Multi-Domain Security Management Server (MDS). Blog: https://www.rapid7.com/blog/post/ra-check-point-smartconsole-authentication-bypass-technical-analysis-cve-2026-16232/
видео или голосовое, без подписи