Looking at the burp history & analyzing | InfoSec | Hacker | An semi-active member at @Hacker0x01 | Securing IoMT Devices | BLR๐AMD | Views are my own
Conducted IoMT PT on one of the large manufacturers of different medical devices, critical flaw leads to access their azure!
Here is how:
TL;DR
Frontend application was running on kiosk mode, backend was win with restrictions such as application control, where you cant,
[1/n]
The Internet is falling down, falling down, falling down
Welcome back to another disaster - this time, an Auth Bypass in cPanel/WHM, tracked as CVE-2026-41940
Enjoy with us..
labs.watchtowr.com/the-interโฆ
What happens when you can tamper with patient data in transit?
Episode 2 of Bytez by @Hacker0x01 India West Club dives into red teaming healthcare systems.
From device-level access to manipulating results seen by doctors.
On the stage: @0_0eth0 ๐๏ธ
๐ discord.gg/nrXWWTF9JS
Introducing the new /crawl endpoint - one API call and an entire site crawled.
No scripts. No browser management. Just the content in HTML, Markdown, or JSON.
Reconftw v4.0 is almost ready. It will contain a ton of changes and a proper documentation page. The doc page is also almost ready at docs.reconftw.com
๐ฅ๐ฅ๐ฅ๐ฌ๐ฌ๐ฌ
We want to thank the hackerone community for an incredible collaboration over the weekend. They discovered a total of 15 unique issues, leading to an expected payout of $750K.
Our eng team has hardened the WAF as issues were discovered, and the last "flag capture" was 20 hours ago as of this writing. By no means is the work done, but we have have jointly achieved substantial protection against React2Shell for Vercel customers.
With that: The focus should remain on patching vulnerable deployments. If you have not patched the time is now! vercel.com/react2shell
reconFTW v3.2.0 released!
- New modules: GraphQL, gRPC reflection, param discovery, websockets, cloud enum & mail hygiene
- Faster --quick-rescan (skips heavy web steps)
- Optional Axiom in Docker, IPv6 support, more toggles
- All open issues fixed!
github.com/six2dez/reconftw
Ever seen two responses to one request? That's just pipelining... or is it? I've just published "Beware the false false-positive: how to distinguish HTTP pipelining from request smuggling" ๐
Little late to this, but you can follow these steps:
1. Create Rooted AVD with rootAVD & Magisk v27. Choose SDK API v33.
2. Add magisk modules: MagiskFrida, Always Trust User Certificates
3. Use the following script with Frida: github.com/hackcatml/frida-fโฆ
This worked for me.
Soโฆ
Weโre hosting something special๐
At @Hacker0x01 India West Club :-
๐ Goa
๐ Aug 23-24
๐ง H1 HackerHouse - 2 days of learning, hacking & vibing together. Weโll pick a target, hack, collab &
(find 0days?).
๐ฏ Focused Yet Fun!
Link - h1.community/e/m9gwzn/ OR
Send me a DM!
Attention @kalilinux users! In the coming day(s), apt update is going to fail for pretty much everyone.
The reason? We had to roll a new signing key for the Kali repository. You need to download and install the new key manually: offs.ec/4lUEtak
Just finished my writeup about CVE-2025-23369, an interesting SAML authentication bypass on GitHub Enterprise Server I reported last year. you can read about it here: repzret.blogspot.com/2025/02โฆ
๐จ Hey Hackers! ๐จ
Get ready for HackerOne Hacking Meetup โ Bangalore 3rd Edition! ๐
organized by @akshanshjaiswl
๐ฏ Hack live on a private program
๐ Earn bounties & rewards
๐ค Collaborate, learn, and network with top hackers
๐๏ธ Event Date: December 7th
Donโt miss out โ Apply now!
bit.ly/4imGXMH#BugBounty#meetup
Story Time: How I hacked back a crypto scammer!
Yesterday an NFT collector reached out to me showing interest in buying my NFTs. He/she messed up right there, no one would want to buy it!
He had a good profile, even had his @opensea in bio
#Crypto#NFTs#CyberSecurity
1/n
Just gained RCE on an AEM web server (real world) by exploiting GroovyConsole and an exceptional bounty!
In @intigriti !
If you too, want to do super cool hax0r things such as hacking real-world web apps, use my link and sign up today!
login.intigriti.com/account/โฆ
๐งต...(1/n)