exploit.org @exploitorg Channel on Telegram

exploit.org

@exploitorg


FinTech & Cybersecurity.
[email protected]

exploitorg (English)

Are you interested in staying updated on the latest trends in FinTech and Cybersecurity? Look no further than the exploitorg Telegram channel! This channel is dedicated to providing valuable insights, news, and tips on how to navigate the ever-evolving world of financial technology and cybersecurity. Who is exploitorg? exploitorg is a leading authority in the FinTech and cybersecurity space, delivering quality content to an engaged audience of professionals, enthusiasts, and experts alike. With a focus on innovation, security, and best practices, exploitorg offers a unique perspective on the industry. What is exploitorg? exploitorg is more than just a Telegram channel – it's a community of like-minded individuals who are passionate about all things FinTech and cybersecurity. From discussing the latest advancements in digital banking to sharing tips on protecting your online data, exploitorg covers a wide range of topics to keep you informed and empowered in today's digital landscape. Whether you're a seasoned professional looking to stay ahead of the curve or a newcomer interested in learning more about FinTech and cybersecurity, exploitorg has something for everyone. Join us today and be part of a community that is shaping the future of technology and security. Contact us at [email protected] for more information. Stay informed, stay secure, and stay connected with exploitorg!

exploit.org

15 Nov, 07:13


TailScale is a popular solution for building virtual networks, but in the hands of a pentester, it can be a pivoting tool.

Magama Bazarov, known under his alter ego “Caster” returns to exploit.org with his exotic release “Bipolar Disorder” about pivoting using TailScale.

https://blog.exploit.org/caster-bipolar-disorder

exploit.org

28 Sep, 19:41


A researcher under the nickname Caster returns with his "Against" release to our blog.
This is an extremely specific article about attacks on MikroTik routers.

Release Date: 09/27/2024

https://blog.exploit.org/caster-against/

exploit.org

25 Aug, 14:52


Currently we are witnessing arrest of creator of main digital privacy respecting messenger Pavel Durov.

WHY THIS MATTERS:
With over 950 million users, Telegram is one of the last products with respect to digital privacy. Holding Durov accountable for content shared by users or for protecting user data from authorities sets a dangerous precedent moving on for everyone that wants to create a privacy first solutions. This is not just about one person. It’s about safeguarding the right to privacy for all of us as a collective.

This action is a serious threat to the fundamental right to privacy in the digital age. Telegram has been a vital tool for millions around the world, ensuring freedom of speech and protecting our personal data, as well as providing the outlet to freely share opinions and information from unwarranted intrusion.

WHAT CAN YOU DO:
We need to raise our voices and demand justice. Write to Amnesty International at [email protected] and urge them to support Pavel Durov and advocate for his release. Amnesty has a powerful voice on global platform and has been instrumental in defending human rights across the world. If we unite and work together by sending our concerns to them with requests, we will get justice to work.

Let’s stand together for our fundamental digital rights and make sure this doesn’t go unnoticed. 🛡️

#Repost to other places and channels in order to reach broader masses and communities, so we can get more gravitas in order to protect human right to digital privacy

We as humans are stronger and louder in unity and mass.

Line for Enquiries: [email protected]
Mail template: https://telegra.ph/Amnesty-Mail-Template-08-25

#FreeDurov #PrivacyMatters #DigitalRights #AmnestyInternational

exploit.org

24 Aug, 21:23


#FREEDUROV

exploit.org

22 Jun, 15:38


🚀 OWASP Netryx Release 🚀
https://github.com/OWASP/www-project-netryx

We have our official release of Netryx under OWASP Foundation - advanced Java security framework designed to protect your data and save you from cyber attacks. Here are the key features:

JA3, JA4+, and HTTP/2 Fingerprinting:
identification of users based on TLS and HTTP connection establishment, which helps to avoid bots and bad actors.

Intrusion Detection System (IDS):
Collect and analyze data to detect and block malicious activities.

HTTP/2 0day Protection:
Block attacks exploiting vulnerabilities in the HTTP/2 protocol, preventing you from RST Stream vulnerability

Path Traversal Protection:
Prevent unauthorized access to files outside the web root directory, ensuring your data remains secure.

Protection Against Various Injection Attacks:
HTML, JS, LDAP, and CMD encoders ensuring safety against different types of injection attacks.

Secure Memory Management:
Ensure sensitive information like keys and tokens are safely handled in memory, protecting from Data in Use attacks.

And much more! All these features are implemented in Java, making OWASP Netryx a big addition to your security toolkit.

Don't forget to star the repository 😉

#OWASP #Netryx #CyberSecurity #Java #WebSecurity

exploit.org

01 Jun, 06:21


I think network traffic analysis in pentest scenarios is vastly underrated. In this article, I will demonstrate a technique to silently analyze the security of network equipment based on traffic analysis alone.

Caster - Funeral

https://blog.exploit.org/caster-funeral

exploit.org

27 May, 10:19


Active Directory is used in many networks and is often the target of attacks. In this article, Caster will demonstrate the capabilities of Suricata signatures to detect attacks against Active Directory.

Caster - If You Hadn't

https://blog.exploit.org/caster-ifyouhadnt

exploit.org

26 May, 16:20


Tomorrow

exploit.org

19 May, 19:22


UPDATE: Telegram has fixed this bug.

🙂 Telegram started banning bots that send messages, where service number "t.me/+42777" is included in its content as a link.
Some of popular bots (like @fabrika) got already banned.

If you own a bot, turn off sending messages whose content depends on user input (e.g. greeting with user's firstname, etc.).

P.S Telegram started slowly rollbacking the bans.

exploit.org

19 May, 11:28


Kerberos, while more secure than NTLM, also has some security nuances. In this article, researcher Caster will demonstrate techniques for detecting Kerberos attacks using Suricata.

Caster - Kerbhammer

https://blog.exploit.org/caster-kerbhammer

exploit.org

12 May, 12:21


Poisoning attacks against Windows machines have become well known among pentesters. In this article, Caster will demonstrate how to detect poisoning attacks using Suricata.

Caster - Neurotransmitter

https://blog.exploit.org/caster-neurotransmitter

exploit.org

24 Apr, 08:19


Cisco equipment is widespread in production networks. In this article, Caster will demonstrate methods to protect Cisco IOS from network attacks.

Caster - Disciple

https://blog.exploit.org/caster-disciple

exploit.org

19 Apr, 22:01


10 winners of the giveaway were randomly selected by Telegram and received their gift links in private messages.

exploit.org

19 Apr, 09:02


MikroTik equipment is widely distributed all over the world and its security is an acute issue. In this paper, Caster covered many aspects related to the network security of MikroTik equipment.

Caster - Lockdown

https://blog.exploit.org/caster-routeros-lockdown

exploit.org

16 Apr, 16:10


⚠️PuTTY CVE-2024-31497 ⚠️

📰Brief: attacker can gain access to private key with public key and some signed messages on hand via forged identification signature of legitimate user. Signed messages may be publicly visible due to storage in public Git.

🚩Possibilities: login into any servers key was used in, supply chain attacks software maintained git, etc.

📗Affected versions: 0.80 and prior.

📚Full description: https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-p521-bias.html

exploit.org

15 Apr, 20:43


Alert for iOS users
Trust Wallet has just alerted about zero-day exploit in iMessage.

To disable iMessage go to Settings > Messages and toggle iMessage button.

The days are getting harder and harder 🤷

exploit.org

11 Apr, 19:11


Hi to all of those with superior taste and knowledge of true mastery.
Today we are giving away 10 Telegram Premiums amongst our subscribers.

Enjoy and hope the stakes play in your favour, while we do our job 😉

exploit.org

06 Apr, 22:40


Everything Lit: Ways to achieve UEFI persistence.

Just one view of "extreme" techniques. Imagination and knowledge is all you need!

https://blog.exploit.org/everything-lit/