W01fh4cker

351 posts

W01fh4cker banner
W01fh4cker

W01fh4cker

@W01fh4cker

Coder | Poet | Idealist

Katılım Ocak 2022
1.2K Takip Edilen2.1K Takipçiler
Sabitlenmiş Tweet
W01fh4cker
W01fh4cker@W01fh4cker·
昨天文章发出后访问量太大,导致阿里云oss不断告警欠费,因此干脆关了博客,文章开源至github:github.com/W01fh4cker/Lea…
中文
7
59
212
30.5K
W01fh4cker retweetledi
Tao Yan
Tao Yan@ga1ois·
[2]After our failed competition, we headed to Apple Store and bought the mbp m5 and spent less than half an hour to set it up and found a fixed offset is changed 1 bit on it, so we just change 1 bit on our exp and it worked with a 100% success rate. Yes just 1 bit change, 1 to 2.
Tao Yan tweet media
TrendAI Zero Day Initiative@thezdi

Unfortunately, Tao Yan & Edouard Bochin of Palo Alto Networks could not get their exploit of Apple Safari – Renderer Only working within the time allotted. #Pwn2Own #P2OBerlin

English
14
39
568
103.2K
W01fh4cker retweetledi
ggwhyp
ggwhyp@ggwhyp·
I was hoping to compete in Pwn2Own with a Firefox full-chain entry, but unfortunately it was rejected. I’ve reported the vulnerability to the Mozilla team.
English
31
95
717
110.6K
W01fh4cker
W01fh4cker@W01fh4cker·
@bestswngs @Y4tacker 尝试用evil-opencode+gpt5.2分析coldfusion,把diff丢给它让它写poc,直接拒绝了🌚有没有好的解决办法哇
中文
1
0
0
465
W01fh4cker
W01fh4cker@W01fh4cker·
@SimoKohonen Your computer allows authorized users to execute commands.👏
English
1
0
6
1.1K
Simo
Simo@SimoKohonen·
CVE-2026-21877, a CVSS 10 vuln allowing authenticated attackers to run commands on N8N.. which is a platform allowing users to run various commands 😂
English
9
14
224
31.6K
W01fh4cker retweetledi
Piotr Bazydło
Piotr Bazydło@chudyPB·
My research regarding .NET Framework HTTP client proxies and WSDL imports just dropped. Long story short: those proxies can be forced to write HTTP body to the local files, instead of sending them over HTTP. Leads to shells 😅
watchTowr@watchtowrcyber

Today, we’re releasing watchTowr Labs’ @chudyPB’s BlackHat .NET research, owning Barracuda, Ivanti and more solutions. Enjoy the read as Piotr explains a new .NET Framework primitive, used to achieve pre- and post-auth RCE on numerous enterprise appliances. labs.watchtowr.com/soapwn-pwning-…

English
3
31
183
22.6K
曾哥
曾哥@AabyssZG·
终于看到了一个非AI生成CVE-2025-55182的PoC,感兴趣的大家可以去试试🧐 Github地址:github.com/msanft/CVE-202… 真实场景下,利用应该是不带回显的,带命令执行结果的应该都是AI生成的测试😂
Moritz Sanft@stdoutput

Full RCE PoC is now live @ github.com/msanft/CVE-202… Credit goes to @maple3142. Great job! Brilliant idea for the root reference. Felt like a CTF challenge indeed. Writing the full breakdown now.

中文
3
9
69
19K
W01fh4cker retweetledi
SinSinology
SinSinology@SinSinology·
This was hella fun, together with my colleague Jake (@inkmoro) we worked on this target, chaining pre-auth XXE(s) that allowed for limited file read to leak the plain-text admin password! After that, a post-auth command injection for RCE as NT SYSTEM (^_^)
SinSinology tweet media
watchTowr@watchtowrcyber

Back in December, we disclosed numerous vulnerabilities to SysAid (who struggle to use email, it seems..) - eventually building a full pre-auth RCE chain. Join us on yet another journey..... labs.watchtowr.com/sysowned-your-…

English
8
21
193
17.7K
Themo
Themo@Th3m00·
@CS2News_EN DRILLAS, I want to see them play against NAVI lol
English
5
1
151
8.3K
CS2 NEWS
CS2 NEWS@CS2News_EN·
Only one of them can play in the Major and who do you want it to be? 🧐
CS2 NEWS tweet media
English
137
53
1.7K
137.9K
HLTV.org
HLTV.org@HLTVorg·
FlyQuest eliminate DRILLAS from the RMR after triple OT 😤
HLTV.org tweet media
English
505
83
5K
526.5K
Fancyyy
Fancyyy@ItzFancyyy·
@HLTVorg 我们的大马之光 kaze 🇲🇾🔥
中文
4
0
21
1.9K
W01fh4cker
W01fh4cker@W01fh4cker·
@HLTVorg Sick kaze, sick Summer, sick somebody, sick ChildKing, sick L1haNg, lets fucking go! Send them home!
English
0
0
5
762