samael0x𝟜 ☠

135 posts

samael0x𝟜 ☠ banner
samael0x𝟜 ☠

samael0x𝟜 ☠

@nerdByt

0x4 | Bug Hunter Credited by Oracle People are the weakest link.

127.0.0.1 Se unió Temmuz 2022
294 Siguiendo41 Seguidores
samael0x𝟜 ☠
samael0x𝟜 ☠@nerdByt·
🚨 URGENCY + VIRAL New Critical CVE 🚨 CVE-2026-21643 — Unauthenticated SQL Injection (9.1) Demo + PoC 👇 youtu.be/dpCi0EW3N-s
YouTube video
YouTube
English
0
0
0
72
samael0x𝟜 ☠
samael0x𝟜 ☠@nerdByt·
Quick check: npm list axios If vulnerable → assume full compromise. Fix: • Downgrade immediately • Rotate ALL credentials • Rebuild system from clean image
English
0
0
0
25
samael0x𝟜 ☠
samael0x𝟜 ☠@nerdByt·
The real weapon = postinstall script Runs automatically when you do: → npm install No user interaction needed. Payload behavior: • Downloads cross-platform RAT • Executes in ~1.1 sec • Works on Windows / Linux / macOS
English
1
0
0
24
samael0x𝟜 ☠
samael0x𝟜 ☠@nerdByt·
🚨 Axios supply chain attack (2026) — this should scare every developer. 100M+ weekly downloads. No exploit. No click. Just npm install… and you're owned. 💀 Attacker took over the maintainer’s npm account. No code vuln. No zero-day. Just account compromise → full access.
English
1
0
0
64
samael0x𝟜 ☠ retuiteado
KNOXSS
KNOXSS@KN0X55·
🚨 KNOXSS GIVEAWAY March 2026 ✅ Follow us ✅ Like and share this 🎁 Prize: KNOXSS Pro for 1 Month 🏆 Results: March 6th (3 winners) Want to find some vulns? Get one of our plans and test for #XSS consistently. Sign up now! 😀 knoxss.pro #BugBounty #PenTesting
KNOXSS tweet media
English
13
34
51
5.1K
KNOXSS
KNOXSS@KN0X55·
Prepare for the 1st GIVEAWAY of 2026! 🤩 Despite the service issues, the lack of true (or fake) testimonials and unprofitable usage of the majority (which is expected)... KNOXSS remains the most smart and comprehensive tool for #XSS with a loyal user base. Stay tuned! 😉
KNOXSS tweet media
English
3
1
16
1.6K
samael0x𝟜 ☠
samael0x𝟜 ☠@nerdByt·
#الحمدالله Successfully worked with a major Enterprise vendor on a Responsible Disclosure. 🐞🔥 Issue resolved. Credit coming in next advisory. Patience is part of the process. 🛡️
English
1
0
2
27
samael0x𝟜 ☠
samael0x𝟜 ☠@nerdByt·
Reflected XSS identified via unsanitized error parameter — mapped to CVE-2020-19282. User input is reflected back without proper sanitization, allowing script execution in the browser. Minimal PoC used. Reported responsibly. Now waiting for Response 🕶️ #RXSS #BugBounty
samael0x𝟜 ☠ tweet media
English
0
0
0
208
samael0x𝟜 ☠ retuiteado
Coffin
Coffin@lostsec_·
We have only one life, if we can't achieve what we desire, then what's the point of living it?
English
13
15
173
9.5K
samael0x𝟜 ☠ retuiteado
Nana Sei Anyemedu
Nana Sei Anyemedu@RedHatPentester·
WhatsApp End-to-End Encryption vs. Forensic Extraction Although WhatsApp uses end-to-end encryption to protect messages, calls, and shared media during transmission, this protection only applies while the data is moving between devices. Once the content reaches the device, it is stored unencrypted within WhatsApp’s local databases and media folders. Out of the volumes of content, such as 733,543 WhatsApp messages, along with videos, audios, images, and documents. I was able to get a conversation between my kid sister @ama_Anyemedu in November 11, 2020. The chat preview shows a typical WhatsApp conversation recovered from a mobile forensic extraction. At the top of the chat, WhatsApp displays the standard banner “Messages are now secured with end-to-end encryption.” This banner simply means that when messages are being transmitted between two devices, WhatsApp’s servers cannot read them because they are protected by encryption keys stored only on the users’ devices. However, end-to-end encryption does NOT protect data stored on the device itself. Mobile forensics work by accessing the phone’s internal storage, not by intercepting messages from WhatsApp servers. Once a device is unlocked or decrypted by the lawful extraction process, the tool can read the local WhatsApp databases stored on the device (usually the `msgstore.db` and related SQLite databases). This is why, despite the presence of the "end-to-end encryption" banner, the forensic tool is still able to extract: * Full chat history * Timestamps * Participants * Message contents * Attachments * Deleted messages (if still recoverable in the database) End-to-end encryption protects data in transit, not data *at rest* on the device. Forensic tools exploit lawful access to the device’s decrypted file system, enabling them to parse and display the stored WhatsApp database, which is why you can see the complete message timeline, content, and timestamps on the right side.
Nana Sei Anyemedu tweet mediaNana Sei Anyemedu tweet media
English
103
612
2.6K
302K