Pinaki ❄️

742 posts

Pinaki ❄️ banner
Pinaki ❄️

Pinaki ❄️

@0xInfection

I am just an Infected Geek. \o/

/dev/null Katılım Şubat 2018
148 Takip Edilen6.9K Takipçiler
Pinaki ❄️ retweetledi
Philo Groves
Philo Groves@PhiloGroves·
Mythos' Firefox exploitation didn't actually have sandbox enabled and built on top of research from Opus. Shocker.
Philo Groves tweet media
English
17
83
946
201.7K
Pinaki ❄️ retweetledi
blasty
blasty@bl4sty·
mere moments after the mythos announcement:
blasty tweet media
English
10
19
265
23.8K
Pinaki ❄️
Pinaki ❄️@0xInfection·
Published something that has been sitting in my drafts for quite sometime. This one is all about the cool bypasses that I stumbled upon during 1337UP0522 live hacking event where we tried to bypass ModSecurity CRS. 0xinfection.xyz/posts/breaking…
Pinaki ❄️ tweet media
English
1
2
6
940
Pinaki ❄️ retweetledi
watchTowr
watchTowr@watchtowrcyber·
8 million requests, $400 later - we’re back. 🚀 We have demonstrated supply chain attacks that could have allowed us to trivially compromise critical infra. networks, including .gov, .mil, and more. This is real Attack Surface Management. labs.watchtowr.com/8-million-requ…
English
11
90
272
56K
Pinaki ❄️
Pinaki ❄️@0xInfection·
@ETHICALEXO Its been quite some time I've written the tool, I think changes at the backend of canarytokens.org is why the generation of new tokens don't work anymore. However you can still go to canarytokens.org/generate and grab a new DNS token and supply via the -token argument.
English
0
0
0
20
EXOSITES
EXOSITES@ETHICALEXO·
@0xInfection I keep trying to run it but I can't figure out the canary token for the life of me. It keeps saying this: 2023/10/11 00:54:04 Trying to generate a new Canary Token... 2023/10/11 00:54:04 invalid character 'I' looking for beginning of value any help would be greatly appreciated
English
1
0
1
29
Pinaki ❄️
Pinaki ❄️@0xInfection·
Since the final fix for the #log4j RCE vulnerability is out — I'm finally open-sourcing a scanning toolkit for CVE-2021-44228 that I developed over the weekend. Features include automatic Canary Tokens generation, request customization and many others. :) github.com/0xInfection/Lo…
English
4
94
295
0
Kody
Kody@KodyKinzie·
ChatGPT launched plugins! There aren't many to choose from, but it was already able to list 3 star hotels in LA by room price for specific dates. I see this saving me time.
Kody tweet mediaKody tweet mediaKody tweet media
English
2
2
14
2K
Pinaki ❄️
Pinaki ❄️@0xInfection·
Back in 2022, I found a (stupid) local privilege escalation vulnerability in QuickHeal's @Seqrite Endpoint Security (EPS) AV product. Today I'm dropping some vulnerability details and a PoC exploit for the LPE. CVE and blogpost soon! 😄 Exploit: github.com/0xInfection/EP…
English
1
16
77
17.6K
Pinaki ❄️
Pinaki ❄️@0xInfection·
Can't believe its been over 2 months the event happened. Hacking cool targets, meeting hackers from around the world, what more could you ask for? 😄 Once again, cheers to @intigriti and @TheParanoids for organizing such a fun-filled event timeline! youtu.be/XeICEz81zuw
YouTube video
YouTube
English
0
1
10
0
John Hammond
John Hammond@_JohnHammond·
There looks to be multiple of these, another one with a different SatoshiDisk link and "only selling FIVE copies".... scam methinks. Multiple files to look more legitimate? I've reported the account & repository to GitHub. https[:]//github[.]com/TimWallbey/CVE-2022-41082-RCE
John Hammond tweet mediaJohn Hammond tweet media
English
4
8
99
0
Pinaki ❄️
Pinaki ❄️@0xInfection·
This is not how anyone should use OSINT. This "challenge" is meaningless platitude. This thread post lays out a playbook for others to abuse OSINT. Please take a step back and consider what you’ve posted and all the different ways it could be misused.
English
2
2
6
0
Pinaki ❄️
Pinaki ❄️@0xInfection·
Really enjoyed the F1 Qualifiers at Spa Francorchamps. What a remarkable way to end a live hacking event! ✨ Heartiest gratitude to @intigriti and @TheParanoids for making this happen and having me in this! ♥️
English
1
2
26
0