rehackxyz

2K posts

rehackxyz banner
rehackxyz

rehackxyz

@rehackxyz

RE:HACK official Twitter account

Malaysia شامل ہوئے Eylül 2021
108 فالونگ1.4K فالوورز
rehackxyz ری ٹویٹ کیا
Calif
Calif@calif_io·
Inspired by master @kinugawamasato, here's a DOMPurify bypass, found by Codex: ```html
``` SAFE_FOR_TEMPLATES is a DOMPurify option that strips template syntax like {{...}} so sanitized HTML can't smuggle expressions into a framework like Vue. This bypasses it. How it works: DOMPurify's job is to delete dangerous code like {{...}} before it reaches Vue. Normally it checks twice, but the RETURN_DOM option skips the second check. So we sneak the payload past the first check by chopping {{...}} into harmless looking pieces, with junk tags between them. DOMPurify strips away the junk tags, the pieces fall back together into {{...}}, and Vue runs the code. Fixed in 3.4.0. Detailed breakdown: github.com/cure53/DOMPuri…
English
0
4
62
3.7K
rehackxyz ری ٹویٹ کیا
OtterSec
OtterSec@osec_io·
New research: We were able to access camera permissions and obtain user GPS coordinates across 20+ major mobile wallets by exploiting WebView misconfigurations. Here's how ↓
OtterSec tweet media
English
2
23
105
13.8K
rehackxyz ری ٹویٹ کیا
sofyank96
sofyank96@sofyank96·
Alhamdulillah diberi peluang untuk hasilkan video travel Malaysia bersama @mshaffuan07
Indonesia
45
2.1K
5.3K
136K
rehackxyz ری ٹویٹ کیا
payloadartist
payloadartist@payloadartist·
There are very few people in the #bugbounty community that share their stellar research in this day and age. Massive respect. @brutecat made half a million hacking Google with AI, and he also shared his prrompts and techniques! brutecat.com/articles/hacki…
payloadartist tweet media
English
3
51
321
12.5K
rehackxyz ری ٹویٹ کیا
Calif
Calif@calif_io·
We sent Claude Mythos Preview spelunking through Squid’s guts, and it surfaced clutching a 29-year-old bug. Meet Squidbleed: a Heartbleed-style vulnerability that leaks internal memory from every version of Squid Proxy, in its default configuration. Full story: blog.calif.io/p/squidbleed-c…
Calif tweet media
English
5
91
337
58.8K
rehackxyz ری ٹویٹ کیا
rehackxyz ری ٹویٹ کیا
avtokyo
avtokyo@avtokyo·
今年も AVTOKYO2026 ! 📅 2026年11月21日(土)※今年は土曜日に戻ります 📅 November 21, 2026 (Sat) — back to Saturday! 📍 TK NIGHTCLUB, Shibuya, Tokyo CFP/CFX will open soon. no drink, no hack. avtokyo.org/avtokyo2026 #avtokyo
avtokyo tweet media
日本語
0
34
64
6K
rehackxyz ری ٹویٹ کیا
vx-underground
vx-underground@vxunderground·
> be pakistan government > develop custom malware > used to target high profile targets > used against indian military and political ppl > named SHEETCREEP > send indian ppl file > UAE-India Strategic Partnership Week > malicious .lnk file > .lnk executes malicious c sharp code > does a bunch of stuff for persistence > exfiltrates data to Google Sheets > Google Sheets can be used to control victim pcs > pakistan gov hardcodes google c2 sheet > PAKISTAN GOV HARDCODES GOOGLE C2 SHEET > embed access key in payload > EMBED ACCESS KEY IN PAYLOAD > malware nerds find it > look inside > find all targets from pakistan gov > monitoring 91 ppl they think important THEY STARTED SO STRONG. WHY DID YOU HARDCODE EVERYTHING. YOU BURNED YOUR OPERATION securonix.com/blog/sheetcree…
English
51
314
2.7K
121.2K
rehackxyz ری ٹویٹ کیا
ABX
ABX@vx_antibi0tic·
My first attempt Exploit Developer (OSED) EXP-301 exam just passed! I enjoyed especially content that pushed down from exp-401. x64 vm-escape & dev shellcode. It's also fun to be able to read assembly in depth, heap/stack, reverse, and bypass aslr/dep. Thank you @offsectraining.
ABX tweet media
English
10
5
64
6.6K
rehackxyz ری ٹویٹ کیا
Alexander Popov
Alexander Popov@a13xp0p0v·
The video of the Kernel-Hack-Drill Masterclass that I gave in Kuala Lumpur🌴 A lot of live demos of Linux kernel attacks and defenses🛠 youtube.com/watch?v=zXVqGa…
YouTube video
YouTube
English
1
36
136
9.7K
rehackxyz ری ٹویٹ کیا
Aretiq.AI
Aretiq.AI@AretiqAI·
SharePoint Server RCE via webshell upload — CVE-2026-45454. A user with basic Contribute perms can upload an ASPX webshell to the Master Page Gallery and get code execution as the app pool identity. One HTTP request, no admin needed. Patch now. aretiq.ai/research/12/
English
0
47
157
17.5K
rehackxyz ری ٹویٹ کیا
nknwn
nknwn@nknwn_eth·
meanwhile in Kuala Lumpur.. am i going to jail?
nknwn tweet media
English
46
137
1K
140.4K
rehackxyz ری ٹویٹ کیا
Dark Web Intelligence
Dark Web Intelligence@DailyDarkWeb·
🇲🇾 Malaysia: Municipal Government VPN Access Advertised for Sale * Threat actor is advertising alleged VPN access to a Malaysian municipal government organization * The listing claims: * OpenVPN access * Domain Administrator privileges * Approximately 50 hosts within the environment * Revenue estimated between $50M–$100M * Cylance EDR reportedly deployed in the network * The access is being offered for sale on a cybercrime marketplace for approximately $978 USD * No specific government entity was identified in the visible portion of the listing * At the time of reporting, the claims remain unverified and should be treated as allegations until independently confirmed Analyst Note: Initial access listings remain one of the most reliable early indicators of potential ransomware activity. Government environments are frequently targeted because attackers can monetize privileged access through ransomware operators, data theft groups, and espionage actors. Even if the advertised access is exaggerated, the presence of claimed domain administrator privileges significantly increases the potential impact should the access prove legitimate. #DDW #Intelligence #Malaysia #DarkWeb
Dark Web Intelligence tweet media
English
0
21
56
9.7K
rehackxyz ری ٹویٹ کیا
Calif
Calif@calif_io·
Introducing HTTP/2 Bomb: a remote DoS in nginx, Apache httpd, Microsoft IIS, Envoy, and Cloudflare Pingora. A single client pins 32GB of server memory in 10s. Found by Codex. Blog post: blog.calif.io/p/codex-discov… PoCs: github.com/califio/public…
English
25
435
2K
185.9K
rehackxyz ری ٹویٹ کیا
RyotaK
RyotaK@ryotkak·
Claude Codeに対してサプライチェーン攻撃を行うことが可能だった脆弱性についての記事を公開しました!
GMO Flatt Security株式会社@flatt_security

セキュリティリサーチャー RyotaK @ryotkak の技術ブログを公開しました。 今回、Claude Code GitHub Actions の権限制御を外部の GitHub Issue 経由でバイパスし、ワークフロー権限を悪用できる脆弱性、並びにそれに付随する設定ミスを発見・報告しました。 当該の脆弱性は v1.0.94 で修正済みですが、設定ミスについては各リポジトリにて対応が必要であるため、当該製品を利用されている場合は設定の見直しと実行ログの確認を推奨します。 flatt.tech/research/posts…

日本語
10
26
237
35.6K