Reposted by Cristian CantosCristian Cantos @kriware.bsky.social · 06/12/2024Are you still not part of the EXCLUSIVE hacker community that receives a DAILY TECHNICAL article about hacking? Every day, practical and advanced knowledge delivered straight to you. Join now! 👇 021
Cristian Cantos @kriware.bsky.social · 20/07/2025Chaining Directory Traversal & CSV Parser Abuse for RCE in Django Combines unsanitized username path traversal with pandas CSV to_csv() quirks to overwrite wsgi.py and gain RCE. jineeshak.github.io/posts/Chaining-… #django 000
Cristian Cantos @kriware.bsky.social · 19/07/2025Solo: A Pixel 6 Pro Story Researcher adapts a Mali GPU integer overflow (CVE‑2023‑48409) to root Pixel 6 Pro by adding memory-spraying and SELinux bypasses—all from a single bug. starlabs.sg/blog/2025/06-solo-a-pix… #Android 000
Cristian Cantos @kriware.bsky.social · 18/07/2025TapTrap: Invisible Animation‑Driven Tapjacking on Android A malicious app with zero permissions uses transparent animations to hide real system prompts (e.g., camera, location, admin) and trick users into tapping them unknowingly. taptrap.click #Tapjacking #AndroidAttack 000
Cristian Cantos @kriware.bsky.social · 17/07/2025GPUHammer: Rowhammer Attack on NVIDIA GDDR6 GPUs GPUHammer is the first practical Rowhammer attack on GDDR6 VRAM (e.g., RTX A6000), flipping bits via CUDA and silently corrupting AI models, plummeting accuracy from ~80% to under 1%. gpuhammer.com #Rowhammer #GPUAttacks 000
Cristian Cantos @kriware.bsky.social · 16/07/2025DreamWalkers: Reflective Shellcode Loader with Clean Call Stacks A loader that achieves believable call stacks in reflectively loaded modules by parsing PE and registering unwind data via RtlAddFunctionTable. maxdcb.github.io/DreamWalkers #ShellcodeLoader #CallStackSpoofing 000
Cristian Cantos @kriware.bsky.social · 15/07/2025Windows Kernel Pool Internals Explains kernel pool allocation, PoolTags, segment heap (kLFH, VS, Large), and building a no‑admin tool to enumerate tags. r0keb.github.io/posts/Windows-Kerne… #Kernel #Heap #windows 011
Cristian Cantos @kriware.bsky.social · 14/07/2025Exploiting WRMSR in Vulnerable Drivers Detailed guide on abusing unsecured WRMSR IOCTLs to overwrite LSTAR MSR, build ROP chains bypassing SMEP/SMAP/KPTI, and gain kernel execution. idafchev.github.io/blog/wrmsr #Kernel #windows 000
Cristian Cantos @kriware.bsky.social · 13/07/2025Hexagon Fuzz: Full-System Emulated Fuzzing of Qualcomm Basebands SRLabs released the first open-source emulator-based fuzzing toolchain for Qualcomm Hexagon baseband firmware www.srlabs.de/blog-post/hexagon-fuz… #Baseband #Fuzzing 000
Cristian Cantos @kriware.bsky.social · 12/07/2025Rediscovered an 11‑Year‑Old libpng Vulnerability A beginner in secure code review reintroduced CVE‑2014‑9495 by fuzzing width * bit-depth overflow blog.himanshuanand.com/posts/discov… #libpng #IntegerOverflow 000
Cristian Cantos @kriware.bsky.social · 11/07/2025Resurrecting a Dead Torrent Tracker and Finding 3M Peers Revived an expired .si tracker domain, launched Opentracker on VPS, and attracted ~1.7M torrents with 3.1M unique peers in just one hour. kianbradley.com/2025/06/15/resurrec… #TorrentTracker 000
Cristian Cantos @kriware.bsky.social · 10/07/2025Reliable System Call Interception Highlights using seccomp_user_notify with BPF for low‑overhead syscall interception, replacing slow ptrace—demoed via “copycat” tool for per‑syscall file redirection. blog.mggross.com/intercepting-sysca… #Seccomp #SyscallInterceptor 000
Cristian Cantos @kriware.bsky.social · 09/07/2025VNC Honeypot Setup by James Woolley Details setting up a VNC honeypot on Ubuntu that logs sessions, records attacker interactions, and captures payloads for monitoring. ja.meswoolley.co.uk/vnc-honeypot #VNC #Honeypot 000
Cristian Cantos @kriware.bsky.social · 08/07/2025The Hidden JTAG in Your Qualcomm/Snapdragon Device’s USB Port A built-in Embedded USB Debug (EUD) interface since ~2018 allows SWD/JTAG access via USB, enabling kernel/U-Boot debugging without external tools. www.linaro.org/blog/hidden-jtag-qua… #Snapdragon 000
Cristian Cantos @kriware.bsky.social · 07/07/2025Implementing Fast TCP Fingerprinting with eBPF A Golang webserver uses eBPF (XDP + kernel hashmap) to capture TCP SYN options at kernel-level and fingerprint clients efficiently. halb.it/posts/ebpf-fingerprinting-1 #eBPF #TCPFingerprinting 020
Cristian Cantos @kriware.bsky.social · 06/07/2025How I Scanned all of GitHub’s “Oops Commits” for Leaked Secrets Using GH Archive & GitHub Event API, Truffle’s tool scans zero‑commit force-pushes since 2020 to find leaked secrets. trufflesecurity.com/blog/guest-post… #git 000
Cristian Cantos @kriware.bsky.social · 05/07/2025Alice’s Adventures in a Differentiable Wonderland A friendly primer on differentiable programming and neural nets—covering autodiff, CNNs, RNNs, transformers in PyTorch & JAX. arxiv.org/abs/2404.17625 #NeuralNetwork 000
Cristian Cantos @kriware.bsky.social · 01/07/2025Essential C – Stanford CS Education Library Concise 45‑page guide covering C fundamentals: types, control flow, arrays, pointers, memory, struct, functions, and compilation. cslibrary.stanford.edu/101 #c #programming 000
Cristian Cantos @kriware.bsky.social · 30/06/2025TPU Deep Dive Google’s TPUs use large systolic arrays, scratchpad memory, XLA AoT compilation, and 3D-torus interconnects to deliver exascale AI compute with efficiency. henryhmko.github.io/posts/tpu/tpu.h… #tpu #firmware 000
Cristian Cantos @kriware.bsky.social · 29/06/2025Root Shell on Yomani Credit‑Card Terminal Reverse‑engineered Worldline Yomani XR: found exposed serial console with root shell, bypassed tamper protections via hardware debug port. stefan-gloor.ch/yomani-hack #terminal 000
Cristian Cantos @kriware.bsky.social · 28/06/2025FileFix – A ClickFix Alternative Browser trick uses file upload to open File Explorer, copy malicious PowerShell path disguised as a doc, and auto-execute via address bar. mrd0x.com/filefix-clickfix-alternat… #Phishing 000
Cristian Cantos @kriware.bsky.social · 27/06/2025Primitive Injection – Breaking the Status Quo Project creates reliable read/write/allocate primitives to evade telemetry by enabling custom injection flows and changing process IOCs. trickster0.github.io/posts/Primitiv… #injection #evasion 000
Cristian Cantos @kriware.bsky.social · 26/06/2025PicoEMP – Low-Cost DIY EMFI Tool PicoEMP is a budget Electromagnetic Fault Injection (EMFI) device using Raspberry Pi Pico, ideal for hobbyist security research. github.com/newaetech/chipshouter-pi… #HardwareHacking 000
Cristian Cantos @kriware.bsky.social · 24/06/2025Intercepting Traffic on Android with Mainline and Conscrypt NVISO explains how Conscrypt updates impacted HTTPS interception and how their AlwaysTrustUserCerts Magisk module now supports A7–A16. blog.nviso.eu/2025/06/05/intercepti… #android 000
Cristian Cantos @kriware.bsky.social · 23/06/2025Fault Injection – Follow the White Rabbit Demonstrates EMFI and voltage glitching on ESP32‑V3 to modify flash CRC32 and combine glitch for Secure Boot bypass via complex fault‑injection chain. security.humanativaspa.it/fault-inj… #EMFI #SecureBootBypass 000
Cristian Cantos @kriware.bsky.social · 22/06/2025Make Self‑XSS Great Again Transforms stored self‑XSS into actual stored XSS using modern credentialless iframes plus CSRF to hijack victim sessions. blog.slonser.info/posts/make-self-x… #web #xss 000
Cristian Cantos @kriware.bsky.social · 21/06/2025Funky Chunks: Abusing Chunk Line Terminators for Request Smuggling Investigates ambiguous chunk-line terminators enabling HTTP request smuggling via non-standard chunk parsing. w4ke.info/2025/06/18/funky-chunks.h… #RequestSmuggling #HTTPParsing 000
Cristian Cantos @kriware.bsky.social · 20/06/2025MCP Security Tips – 5 Risks & Safeguards NCC Group highlights five MCP security risks: supply-chain, local/remote vulnerabilities, prompt injection, excessive capabilities, and offers practical mitigations. www.nccgroup.com/us/research-blog/5… #MCP #AI 000
Cristian Cantos @kriware.bsky.social · 19/06/2025Emulating a Bike Sensor with ESP32 BLE Builds an ESP32-based BLE Cycling Speed & Cadence sensor using a single reed switch to emulate speed and cadence, leveraging the standard CSC BLE profile. eybisi.run/Emulating-a-Bike-Sensor #BLE #HardwareHacking 000
Cristian Cantos @kriware.bsky.social · 18/06/2025PatchGuard Internals – Deep Kernel Protection Dive Explains PatchGuard’s initialization phases, secure-hypervisor activation paths, and context setup, revealing potential bypass points. r0keb.github.io/posts/PatchGuard-In… #PatchGuard #WindowsKernel 000
Cristian Cantos @kriware.bsky.social · 17/06/2025Fuzzing WebSockets for Server‑Side Vulnerabilities Research reveals a technique using the Backslash Powered Scanner extension to fuzz WebSocket endpoints and find server‑side bugs. arete06.com/posts/fuzzing-ws #WebSocket #Fuzzing 000
Cristian Cantos @kriware.bsky.social · 16/06/2025Brokering File System January 2025 Patch Analysis Microsoft patched two use‑after‑free bugs in bfs.sys via KB5050009 and KB5049984, fixing race‑condition flaws in PipeMappingTable and PolicyTable. ht3labs.com/Brokering-File-System-J… #WindowsKernel 000
Cristian Cantos @kriware.bsky.social · 15/06/2025Reverse Camera Firmware Decryption Researchers figured out encrypted Hanwha firmware uses AES‑256‑CFB8 with key derived from “zeppelin” hash and model-based passphrases to decrypt .img files. brownfinesecurity.com/blog/hanwha-f… #IoT #Firmware 000
Cristian Cantos @kriware.bsky.social · 14/06/2025Brute‑forcing Any Google User’s Phone Number IPv6 address rotation across no‑JS account recovery forms enables bruteforcing phone+display name combinations to discover full user numbers. brutecat.com/articles/leaking-googl… #AccountAbuse #PrivacyExploit 000
Cristian Cantos @kriware.bsky.social · 13/06/2025Covert Web-to-App Tracking via Localhost on Android JavaScript via Meta Pixel and Yandex Metrica transmits browser cookies to native Android apps via localhost sockets, linking web sessions to user IDs—bypassing incognito, permissions, and clearing cookies. localmess.github.io #privacy 000
Cristian Cantos @kriware.bsky.social · 12/06/2025Camera & Microphone Spying via Chromium Flags Chromium’s --auto-accept-camera-and-microphone-capture flag lets attackers silently record webcam audio/video without user consent. mrd0x.com/spying-with-chromium-brow… #Chromium #PrivacyThreat 000
Cristian Cantos @kriware.bsky.social · 11/06/2025High-Performance Network Fuzzing with LibAFL and libdesock Custom fuzzer using LibAFL and libdesock achieves 42x speedup over AFLNet via tokenized inputs and shared memory, uncovering new bugs. lolcads.github.io/posts/2025/05/hig… #Fuzzing #Network 000
Cristian Cantos @kriware.bsky.social · 10/06/2025The Ultimate Guide to Windows Coercion Techniques in 2025 RedTeam Pentesting details modern Windows coercion methods, analyzing their effectiveness and bypasses for recent mitigations. blog.redteam-pentesting.de/2025/win… #Windows 000
Cristian Cantos @kriware.bsky.social · 09/06/2025Tokenization Confusion Reseacher examines how simple prompt obfuscations, like hyphenation, can bypass LLM safety models due to tokenization quirks. blog.xpnsec.com/tokenization-confus… #LLM #PromptInjection 000
Cristian Cantos @kriware.bsky.social · 08/06/2025Poison Everywhere: No Output from Your MCP Server Is Safe Attackers can manipulate outputs from Anthropic's MCP servers, complicating detection and response. www.cyberark.com/resources/threat-r… #MCP 110
Cristian Cantos @kriware.bsky.social · 04/06/2025Offensive CTI Explores offensive cyber threat intelligence (CTI) techniques, focusing on leveraging adversary tactics for proactive defense strategies. blog.zsec.uk/offensive-cti #CTI #ThreatIntel 000
Cristian Cantos @kriware.bsky.social · 03/06/2025Understanding Integer Overflow in Windows Kernel White Knight Labs explores how unchecked arithmetic in kernel drivers can cause heap corruption via integer overflows. whiteknightlabs.com/2025/05/27/unde… #Exploiting 000
Cristian Cantos @kriware.bsky.social · 02/06/2025Red Team Gold: Extracting Credentials from MDT Shares TrustedSec reveals how misconfigured Microsoft Deployment Toolkit shares can expose plaintext domain credentials, aiding lateral movement. trustedsec.com/blog/red-team-gold-e… #MDT #RedTeam 000
Cristian Cantos @kriware.bsky.social · 01/06/2025Abusing dMSA to Escalate Privileges in Active Directory Akamai reveals a flaw in Windows Server 2025's dMSA, allowing attackers with minimal permissions to escalate privileges in AD. www.akamai.com/blog/security-resear… #AD 000
Cristian Cantos @kriware.bsky.social · 31/05/2025Decoding TCP SYN for Stronger Network Security Analysis unsolicited TCP SYN packets from honeypots, revealing patterns in TTL and header lengths without evidence of IP spoofing. www.netscout.com/blog/asert/decodin… #TCP #DDoS 000
Cristian Cantos @kriware.bsky.social · 30/05/2025From Reverse Engineering to Cheat Development Step-by-step guide to building an external ESP and aimbot for AssaultCube adminions.ca/books/articles/page/pa… #GameHacking #RE 000
Cristian Cantos @kriware.bsky.social · 29/05/2025How to use o3 to Find CVE-2025-37899 Researcher used OpenAI’s o3 model to discover CVE-2025-37899, a use-after-free bug in Linux. sean.heelan.io/2025/05/22/how-i-use… #Linux #SMB 000
Cristian Cantos @kriware.bsky.social · 28/05/2025Attacking EDRs: Intro & Security Analysis of EDR Drivers InfoGuard examines EDR driver attack surfaces, focusing on low-privileged user access and potential vulnerabilities in Windows agents. labs.infoguard.ch/posts/edr_part1_i… #EDR #DriverAnalysis 000
Cristian Cantos @kriware.bsky.social · 27/05/2025Bypassing kASLR via Cache Timing Explores a prefetch side-channel attack to bypass kASLR on Windows 11 by measuring cache access times to locate the kernel base address. r0keb.github.io/posts/Bypassing-kAS… #kASLR #SideChannel 000