HHHHarshil

66 posts

HHHHarshil

HHHHarshil

@hhhharshil

Katılım Ekim 2020
277 Takip Edilen30 Takipçiler
HHHHarshil retweetledi
Sam Curry
Sam Curry@samwcyo·
New blog post with @infosec_au: We found a vulnerability in Subaru where an attacker, with just a license plate, could retrieve the full location history, unlock, and start vehicles remotely. The issue was reported and patched. Full post here: samcurry.net/hacking-subaru
English
47
312
1K
117.9K
HHHHarshil retweetledi
Sam Curry
Sam Curry@samwcyo·
New writeup from @_specters_ and I: we're finally allowed to disclose a vulnerability reported to Kia which would've allowed an attacker to remotely control almost all vehicles made after 2013 using only the license plate. Full disclosure: samcurry.net/hacking-kia
English
86
978
3.6K
343.9K
HHHHarshil retweetledi
ϻг_ϻε
ϻг_ϻε@steventseeley·
What you think, you become. What you feel, you attract. What you imagine, you create.
English
2
5
28
5.9K
d415k
d415k@d415k·
I have successfully passed the HTB Certified Web Exploitation Expert (HTB CWEE)! I am so happy to hear that I am the first person to pass the exam.
d415k tweet media
English
49
15
305
15.1K
Matt Biedronski
Matt Biedronski@Gonski47·
My template for identifying CVE-2023-5830 is now available within @pdnuclei's community template repository (github.com/projectdiscove…)! Update your nuclei templates and read more about the vuln via the pinned post on my profile.
English
2
5
27
3K
HHHHarshil retweetledi
Octoberfest7
Octoberfest7@Octoberfest73·
This field is too vast to know it all, let alone remember it all the time. So the question becomes what "baseline" knowledge is, and how deep it goes(e.g. Nmap? Probably baseline. Unconstrained delegation? Probably not.) Portfolios/proven work and practical certs > trivia IMO
English
2
3
12
1.8K
HHHHarshil retweetledi
John Hammond
John Hammond@_JohnHammond·
CVEs!!! 🤩 CVE-2024-1708 and CVE-2024-1709 assigned for the #ScreenConnect vulnerabilities. .... and ah, the words 'affected from version 0' are pretty brutal 😅😅
John Hammond tweet mediaJohn Hammond tweet mediaJohn Hammond tweet media
English
10
83
511
63.1K
HHHHarshil
HHHHarshil@hhhharshil·
A more refined query to find unpatched ScreenConnect instances would look like the following: Server: ScreenConnect -"ScreenConnect/23.9.8.8811" Direct link: shodan.io/search?query=S… #ScreenConnect
Hunter@HunterMapping

🚨Alert🚨Critical Flaws Found in ConnectWise ScreenConnect Software ⚠ConnectWise has released security updates to address critical RCE vulnerability in its ScreenConnect remote desktop and access software. 📊 17.3K+ Services are found on the Hunter.how 🔗Hunter:hunter.how/list?searchVal… Dorks 👇👇👇 Hunter: product.name="ConnectWise ScreenConnect software" FOFA: app="ScreenConnect-Remote-Support-Software" Shodan: http.title:"ConnectWise ScreenConnect" 📰Refer to thehackernews.com/2024/02/critic… #ConnectWise #hunterhow #infosec #infosecurity #Infosys #Vulnerability

English
2
2
5
1.1K
Justin Gardner
Justin Gardner@Rhynorater·
I'm cooking up a pretty sick episode of @ctbbpodcast outlining 15+ gadgets that are useful in web vuln chains. It's pretty awesome to see all of this written out - there are so many attack vectors out there and ways that developers can make mistakes. I love this industry.
English
6
5
148
9.3K
HHHHarshil retweetledi
Ru Campbell
Ru Campbell@rucam365·
Entra ID Protection (previously Identity Protection) could have stopped many incidents I’ve worked before they even started. But there are gotchas and misconceptions that can catch you out. Check out my five of these, and share any others you’ve got! campbell.scot/entra-id-prote…
English
7
59
210
20.4K
HHHHarshil retweetledi
s1zz
s1zz@s1zzzz·
Discovered and exploited an arbitrary file delete vulnerability that lead to SYSTEM level privileges. Thanks to the goat @filip_dragovic.
s1zz tweet media
English
7
29
157
21K
Roll4Combat
Roll4Combat@BadAt_Computers·
Got my first big submitted and accepted from the data.
Roll4Combat tweet media
JS0N Haddix@Jhaddix

As part of tbhmlive.com you get access to private discord channels on discord.gg/jhaddix Focus? Learning, hunting, and sharing. Today we released v1 of Janurary's HUNT target data! Cant wait to see what shakes out. Already 2 subs in under 5 hours. ✌️❤️🫶

English
2
1
21
3.3K
HHHHarshil
HHHHarshil@hhhharshil·
@bxmbn Great read! Love the use of wayback machine to hunt for endpoints.
English
0
0
1
473
🇪🇨🍫
🇪🇨🍫@bxmbn·
Wanna know How I prevented a Mass Data Breach? Go Read: @bxmbn/how-i-prevented-a-mass-data-breach-15-000-bounty-bxmbn-1096e6400e3d" target="_blank" rel="nofollow noopener">medium.com/@bxmbn/how-i-p… Wanna know How a Bank offer led to PII Leak? Go Read: @bxmbn/i-received-a-bank-offer-in-my-mailbox-and-discovered-an-idor-vulnerability-5-000-bounty-bxmbn-5209cab1fba8" target="_blank" rel="nofollow noopener">medium.com/@bxmbn/i-recei… More writeups coming soon 🖤
English
20
105
569
34.9K