      1. Past hour
      2. An Android RAT that written in completely C# by me (qH0sT a.k.a Sagopa K) I am AFK while 4 months.... Don't open issue. Minumum Android Version: 4.1 Tested on some systems: Android 4.4.2 - OK Android 5.1.1 - OK Android 7.1.2 - OK Android 6.0.1 - OK Android 9.0 - OK AndroSpy Project aims to most powerful-stable-useful open source Android RAT. Version 3 +Added live Camera stream (with resolution,zoom,flash,quality controls and scene,focus,white balance mode) +Fixed loss data transfer +Some excess codes have been removed +Performance has been increased [hide][Hidden Content]]
      3. Today
      4. 1337day-Exploits

        ExploitsCloudMe 1.11.2 Buffer Overflow

        CloudMe version 1.11.2 exploit that uses MSVCRT.System to create a new user (boku:0v3R9000!) and add the new user to the Administrators group. A requirement of successful exploitation is the CloudMe.exe process must be running as administrator. View the full article
      5. itsMe

        HTML Compiler 2021.7

        With DecSoft HTML Compiler you can easily compile your modern HTML apps (Single Page Apps, for example) into standalone executables for both Microsoft Windows® 32 and 64 bits. Your app' files are never extracted into the user's computer and run in a modern browser environment based in Chromium. [Hidden Content] [hide][Hidden Content]]
      6. HackBrowserData hack-browser-data is an open-source tool that could help you decrypt data[passwords|bookmarks|cookies|history] from the browser. It supports the most popular browsers on the market and runs on Windows, macOS, and Linux. Supported Browser Windows Browser Password Cookie Bookmark History Google Chrome (Full Version) Firefox Microsoft Edge 360 Speed Browser QQ Browser Internet Explorer [hide][Hidden Content]]
      7. Threadtear is a multifunctional deobfuscation tool for java. Android application support is coming soon (Currently working on a Dalvik to java converter). Suitable for easier code analysis without worrying too much about obfuscation. Even the most expensive obfuscators like ZKM or Stringer are included. For easier debugging, there are also other tools included. Insert debug line numbers to better understand where exceptions originate or add .printStackTrace() to try-catch blocks without recompiling your code. Reverse compatibility is not a problem anymore if no version-specific methods are used. Executions An “execution” is a task that is executed and modifies all loaded class files. There are multiple types of executions, varying from bytecode cleanup to string deobfuscation. Make sure to have them in the right order. Cleanup executions, for example, should be executed at last, but also can help other executions if executed first. If you are ready, click on the “Run” button and they will be executed in order. Warning Use this tool at your own risk. Some executions use implemented ClassLoaders to run code from the jar file. An attacker could tweak the bytecode so that malicious code could be executed. Affected executions use the class me.nov.threadtear.asm.vm.VM. These are mostly used for decrypting string or resource/access obfuscation, as it is much easier to execute the decryption methods remotely. Changelog v3.0 quick search in decompiler panel [hide][Hidden Content]]
      8. Yesterday
      9. Mida eFramework version 2.8.9 suffers from a remote code execution vulnerability. View the full article
      10. Joplin version 1.0.245 suffers from a cross site scripting vulnerability that can lead to allowing for remote code execution. View the full article
      11. MSI Ambient Link Driver version suffers from a local privilege escalation vulnerability. View the full article
      12. c0ol

        I'm back :)

        I returned after years of absence to share new cyber security methods with you
      13. This Metasploit module exploit uses access to the UniversalOrchestrator ScheduleWork API call which does not verify the caller's token before scheduling a job to be run as SYSTEM. You cannot schedule something in a given time, so the payload will execute as system sometime in the next 24 hours. View the full article
      14. This Metasploit module exploits an arbitrary file upload vulnerability in MaraCMS versions 7.5 and below in order to execute arbitrary commands. The module first attempts to authenticate to MaraCMS. It then tries to upload a malicious PHP file to the web root via an HTTP POST request to codebase/handler.php. If the php target is selected, the payload is embedded in the uploaded file and the module attempts to execute the payload via an HTTP GET request to this file. For the linux and windows targets, the module uploads a simple PHP web shell. Subsequently, it leverages the CmdStager mixin to deliver the final payload via a series of HTTP GET requests to the PHP web shell. Valid credentials for a MaraCMS admin or manager account are required. This module has been successfully tested against MaraCMS 7.5 running on Windows Server 2012 (XAMPP server). View the full article
      15. itsMe

        ILSpy 6.2

        Features Decompilation to C# Whole-project decompilation (csproj, not sln!) Search for types/methods/properties (substring) Hyperlink-based type/method/property navigation Base/Derived types navigation, history BAML to XAML decompiler Extensible via plugins (MEF) Check out the language support status New Language Features C# 7.0: Deconstruction C# 8.0: await foreach C# 8.0: Disposable ref structs C# 8.0: Enhanced using statements C# 8.0: switch expressions C# 9.0: init accessors C# 9.0: function pointers (see #2150) C# 9.0: foreach with GetEnumerator extension methods C# 9.0: Lambda parameter discards General Add an option to enable aggressive inlining of expressions Add option for string.Concat decompilation Add an option to always qualify member references (by @Pathoschild, see #2114) ReadyToRun: Variable tracking in output (by @edkazcarlson, see #2067) ReadyToRun: Optimized debug info output (by @cshung, see #2113) Work on unifying the code formatting (see #2128) Tests upgraded to Roslyn 3.8.0-3.final UI Improvements Improve performance of Metadata DataGridCell (see #2151) Fix #2107: Add ScrollViewer around DisplaySettingsPanel Metadata: Improvements/fixes by @srutzky, see #2134, #2135, #2145, #2147 and #2153 Updated Chinese translation Bug fixes Fix #2129: be more flexible about the initialization order for the async state machine Fix #2140: ILSpy 6.2p1 no longer respects "use discards" setting Fix #2139: ArgumentOutOfRangeException for some xmldoc Fix #2039: Code generated by VB's On Error Resume Next causes "unassigned variable" compile errors Fix #2156: range syntax not being detected correctly in some cases BAML decompiler: #2109 and #2106 Fix #2086: Check that window belongs to ILSpy before sending it a WM_COPYDATA message. Fix #2090: ignore mscorlib references without public key token, when trying to resolve mscorlib. This will automatically fallback to .NET 4.0's mscorlib.dll. #1292: Fix some more problems with pinned locals. Fix #1555: Eliminate value-type temporaries emitted by mcs on field reads. Fix #2056: "remove branch into body" must be executed before the clone cleanup Fix #2101: reset removeExtraLoad flag if keepAssignmentBefore is set; implement simple case-de-duplication: abort if there are any duplicate cases. Fix #2100: 'value'-named auto property could not be recognized correctly. Fix #1441: Decompose flags enum values starting from the value with the highest Hamming Weight (popcount). [hide][Hidden Content]]
      16. itsMe


        A deobfuscation tool for Eazfuscator. Description EazFixer is a deobfuscation tool for Eazfuscator, a commercial .NET obfuscator. For a list of features, see the list below. Implemented fixes: String encryption Resource encryption Assembly embedding Not implemented, may be added in the future: Entrypoint obfuscation Data virtualization [hide][Hidden Content]]
      17. itsMe


        Simple PPTP & L2TP Protocol VPN Client written in C# using DOTras [hide][Hidden Content]]
      18. itsMe


        Proxy Grabber using ProxyScrape API. [hide][Hidden Content]]
      19. Gitjacker downloads git repositories and extracts their contents from sites where the .git directory has been mistakenly uploaded. It will still manage to recover a significant portion of a repository even where directory listings are disabled. For educational/penetration testing use only. [hide][Hidden Content]]
      20. Improve your traffic now! Simple, fast and powerful SEO plugin for WordPress. [Hidden Content] [hide][Hidden Content]]
      21. IPS Community Suite 4.5.3 Released 09/22/2020 [Hidden Content] [hide][Hidden Content]]
      22. itsMe


        Programming language: C# Name of the product: Zenon Clipper Functional: - Replacing crypto wallets: Bitcoin, Etherum, Monero, Doge Coin, Lite Coin, Dash, Zcash. - Replacing wallets: Qiwi, Payeer, Yandex Money, Ripple, WMR, WMZ, WMU. [hide][Hidden Content]]
      23. itsMe

        Good Public RAT

        @c0ol [Hidden Content]
      24. c0ol

        Good Public RAT

        Hi, I'm looking for a great recent public rat that has good persistence. some idea ? thank you
      25. IObit Malware Fighter 8 PRO La protección completa en tiempo real de tu PC, para tus datos personales y navegación en línea El motor Anti-virus de Bitdefender Evita que más de 200 millones de amenazas de seguridad infecten y dañen tu computadora. Protección Inteligente Utiliza detección avanzada del comportamiento e inteligencia artificial para detectar actividades maliciosas de cualquier programa para prevenir que los ciber-criminales obtengan control de tu ordenador. Defensa de Ransomware Reforzada Combina el motor exclusive anti-ransomware de IObit con la protección por contraseña de la Caja Fuerte para garantizar que todos tus archivos importantes estén seguros de ataques y accesos no autorizados. [Hidden Content] [hide][Hidden Content]]
