■■■■■ DuckDuckC2: A proof-of-concept C2 channel through DuckDuckGo’s image proxy service. The provided example can be extended multiple ways to achieve different deployments. https://github.com/nopcorn/DuckDuckC2 https://nopcorn.github.io/2023/09/25/duckduckgo-as-c2 https://t.me/cKure/13201
All posts in Uncategorized
November 8, 2023 at 05:30PM
■■■■□ Remote Code Execution in Tutanota Desktop due to Code Flaw. https://www.sonarsource.com/blog/remote-code-execution-in-tutanota-desktop-due-to-code-flaw/ https://t.me/cKure/13200
November 8, 2023 at 05:26PM
■■■■□ CVE-2023-22518: Improper Authorization Vulnerability in Confluence Data Center and Server. A critical vulnerability in Atlassian Confluence Data Center and Server. The vulnerability could potentially allow unauthenticated attackers with network access to the Confluence Instance to restore the database of the Confluence instance and eventually execute arbitrary system commands. https://github.com/ForceFledgling/CVE-2023-22518 https://t.me/cKure/13199
November 8, 2023 at 05:19PM
■□□□□ Cyber-Attack on Qatari Ecommerce Government by a group calling themselves ‘Indian Cyber Force’. It was a DoS attack. Target – https://ecommerce.gov.qa/ Check Host – https://check-host.net/check-report/130d6715kb0d Duration: 2 hours (as per the group). https://t.me/cKure/13198
November 7, 2023 at 06:10AM
■□□□□ CVE-2023-30190 (Folina) demo on windows office. https://www.facebook.com/share/r/1sTsufbUiqV8Arvc/ https://t.me/cKure/13197
November 7, 2023 at 02:35AM
■■■□□ Google Warns How Hackers Could Abuse Calendar Service as a Covert C2 Channel. https://thehackernews.com/2023/11/google-warns-of-hackers-absing-calendar.html https://t.me/cKure/13196
November 7, 2023 at 02:35AM
GCR – Google Calendar RAT Google Calendar RAT is a PoC of Command&Control (C2) over Google Calendar Events, This tool has been developed for those circumstances where it is difficult to create an entire red teaming infrastructure. To use GRC, only a Gmail account is required. The script creates a ‘Covert Channel’ by exploiting the…
November 7, 2023 at 02:08AM
■■□□□ LdrLibraryEx: A small x64 library to load dll’s into memory. https://github.com/Cracked5pider/LdrLibraryEx https://t.me/cKure/13193
November 7, 2023 at 02:08AM
■■■□□ CVE-2022-0847 eBPF: An eBPF program to detect and defense attacks on CVE-2022-0847 (DirtyPipe). https://github.com/h4ckm310n/CVE-2022-0847-eBPF https://t.me/cKure/13192
November 7, 2023 at 02:08AM
■■□□□ PrivFu: Kernel mode WinDbg extension and PoCs for token privilege investigation. https://github.com/daem0nc0re/PrivFu https://t.me/cKure/13191
