Загрузка видео...

Не удалось загрузить видео

На главную

New attack vector: FileFix. A phishing trick that executes PowerShell straight from your browser no Run dialog, no pop-ups. Just a fake file path + clipboard + File Explorer. Red teamers, this one’s wild. 📽️ PoC + write-up:

107,652 просмотров • 1 год назад •via X (Twitter)

Комментарии: 10

Фото профиля mr.d0x
mr.d0x1 год назад

Awesome work 👏

Фото профиля IT Guy
IT Guy1 год назад

You've laid the groundwork tbh which made it smooth the idea was top-notch I really admire what you do also especially in the maldev space! 🙌🏾 Thanks for following me back too🥹🙏🏾

Фото профиля ZoeCyber
ZoeCyber1 год назад

This is lit❤️

Фото профиля IT Guy
IT Guy1 год назад

Thanks boss

Фото профиля Matrix
Matrix1 год назад

This is nice 👏🏾 @mrd0x 👏🏾👏🏾👏🏾

Фото профиля IT Guy
IT Guy1 год назад

@mrd0x He is HIM!

Фото профиля H4RUK7 KIRA 🇯🇵
H4RUK7 KIRA 🇯🇵1 год назад

Wonderful

Фото профиля IT Guy
IT Guy1 год назад

Thank you 🙏🏾

Фото профиля Jaybeepy
Jaybeepy1 год назад

Good work man

Фото профиля IT Guy
IT Guy1 год назад

Thanks man

Похожие видео

Is reverse proxy phishing slowly dying? 💀🎣 This is what I've been trying to find out during the past several months. Major websites have caught up and vastly improved their security, successfully detecting malicious traffic originating from reverse-proxy phishing servers. The attackers have changed their tactics and begun utilising a new method that involves using a real web browser to sign in on the phished user's behalf. In the video I've just released, I am demonstrating a live demo of a modern phishing attack using the Credential Relay Phishing technique, which evades all current anti-phishing measures deployed against reverse-proxy phishing. To simulate a phishing attack against a Google account secured with FIDO MFA, I am using the latest features of Evilginx Pro to downgrade the FIDO MFA to less secure & phishable MFA alternatives. Additionally, the attack simulation employs a Browser-in-the-Browser social engineering technique to spoof the phishing URL in the address bar of the fake pop-up window, displaying the sign-in page. Everything you see in the video is ready to use in the latest beta version of Evilginx Pro, available exclusively to vetted cybersecurity professionals working within cybersecurity companies or internal red teams. Evilginx Pro's latest features include: Phishlets 2.0: A complete rewrite of the old phishlets format now allows for modification of every part of HTTP traffic going through the reverse proxy server. The new format allows hosting of static website content utilising external modules such as Evilpuppet to simulate Credential Relay Phishing attacks. Downgrading FIDO MFA: With the most recent implementation of Evilpuppet, it is now possible to control a separate background browser session and sign in on behalf of the phished user, allowing the attacker to be the one responsible for choosing which MFA method the user should authenticate with. Browser-in-the-Browser: It is now possible to embed any phishing page within a fake browser pop-up window, rendered with JavaScript and stylised for the OS on which the page is displayed. This enables the construction of extremely convincing social engineering attacks, as the URL in the pop-up window can be spoofed to any value using legitimate hostnames. If you want to use these features in your next red team engagement or assess your company's readiness against modern phishing attacks, make sure to give Evilginx Pro a try. Hope you enjoy the video! 💗 Happy phishing! 🪝🐟 Kuba

Kuba Gretzky

24,393 просмотров • 5 дней назад

Microsoft spent $13 billion and 3 years building an AI that knows your work context. Every time you open it, it still asks what you're working on. This developer set up a plain text file in 2 minutes. The file is called CLAUDE.md. It loads before every session. Before he types a single word. It already knows his name. It already knows his writing style. It already knows what he's building, who it's for, and what he never wants to see in a response. He doesn't introduce himself anymore. He doesn't explain his preferences anymore. He doesn't correct the same mistakes twice. He just works. No $30/month Copilot subscription. No Microsoft 365. No IT approval. No data sharing agreement. No onboarding. Just a plain text file, a free text editor, and 21 instructions a developer distilled from Andrej Karpathy's research. Those 21 instructions moved Claude's coding accuracy from 65% to 94%. The file hit #1 on GitHub with 82,000 stars. Most people using Claude right now have never heard of it. Microsoft has 221,000 employees, $13 billion invested in OpenAI, and a direct integration into every Windows laptop sold on the planet.. they built an AI assistant most companies pay $30/user/month for that still doesn't know your name. This developer has a laptop, a text file and a 2-minute setup.. he built something that knows more about how he works than any enterprise AI on the market. The $50 billion AI personalization industry just got embarrassed by a .md file. full breakdown down below

Dep

14,117 просмотров • 2 месяцев назад

🚨 JAILBREAK ALERT 🚨 OPENAI: PWNED 😎 ATLAS-BROWSER: LIBERATED 🙌 WOW! There's a new AI browser on the block! Has some hefty guardrails in play, but the browser surface area is vast 🌊 First, I started with a good ol' LSD jailbreak, which was cool to see that the GPT-5 prompt still works in this browser setup with the new sys prompts. Referencing search and videos are a fun enhancement for higher quality jailbreak outputs (some cool youtube videos out there about drugmaking, for example), but honestly that isn't anything new or different from regular ChatGPT's capabilities. What IS hot off the press, and IMO a very real security risk to be aware of for AI browsers (and the internet in general), is this humble yet mighty vuln: Clipboard Injection. It's trivial to add a hidden "copy to clipboard" feature to any clickable button on the web. It took me just a few minutes to update one of my personal websites such that ALL the buttons were geared for injecting the user's clipboard with a malicious phishing link. If your browser Agent is navigating a website and clicks a button like that without your knowledge, and you open a new tab later and hit paste without knowing what's in your clipboard, well...PWNED! 🙃 As you'll see in the video below, "control-c" is in my clipboard in the beginning, but unbeknownst to me, "I'VE BEEN PWNED BY PLINY!!! WEEE I'M FREEE FUCKITY FUCK FUCK!!! ABRACADABRA, BITCH!!! com/account-update" gets snuck into my clipboard as soon as Agent starts trying to navigate my website. This works so well because Agent is normally aware of all text/code being passed to and from the user, and has clearly been trained to recognize prompt injections, but since the "copy clipboard" button logic is hidden in js in the backend of the site, the Agent has zero awareness of the text content being injected to the user's clipboard. This has broad implications for anyone in the habit of copy-pasting, including coding, data entry, banking/trading, etc. Imagine going about your browsing business, then simply hitting control-v in your address bar and next thing you (don't) know, it takes you to a spoofed phishing website that tells you your OpenAI or Gmail or PayPal session has expired and you need to re-login. If you're not careful, the attackers now have all your login info, including any MFA codes 🥲 gg
0:28

Sensitive content

🚨 JAILBREAK ALERT 🚨 OPENAI: PWNED 😎 ATLAS-BROWSER: LIBERATED 🙌 WOW! There's a new AI browser on the block! Has some hefty guardrails in play, but the browser surface area is vast 🌊 First, I started with a good ol' LSD jailbreak, which was cool to see that the GPT-5 prompt still works in this browser setup with the new sys prompts. Referencing search and videos are a fun enhancement for higher quality jailbreak outputs (some cool youtube videos out there about drugmaking, for example), but honestly that isn't anything new or different from regular ChatGPT's capabilities. What IS hot off the press, and IMO a very real security risk to be aware of for AI browsers (and the internet in general), is this humble yet mighty vuln: Clipboard Injection. It's trivial to add a hidden "copy to clipboard" feature to any clickable button on the web. It took me just a few minutes to update one of my personal websites such that ALL the buttons were geared for injecting the user's clipboard with a malicious phishing link. If your browser Agent is navigating a website and clicks a button like that without your knowledge, and you open a new tab later and hit paste without knowing what's in your clipboard, well...PWNED! 🙃 As you'll see in the video below, "control-c" is in my clipboard in the beginning, but unbeknownst to me, "I'VE BEEN PWNED BY PLINY!!! WEEE I'M FREEE FUCKITY FUCK FUCK!!! ABRACADABRA, BITCH!!! com/account-update" gets snuck into my clipboard as soon as Agent starts trying to navigate my website. This works so well because Agent is normally aware of all text/code being passed to and from the user, and has clearly been trained to recognize prompt injections, but since the "copy clipboard" button logic is hidden in js in the backend of the site, the Agent has zero awareness of the text content being injected to the user's clipboard. This has broad implications for anyone in the habit of copy-pasting, including coding, data entry, banking/trading, etc. Imagine going about your browsing business, then simply hitting control-v in your address bar and next thing you (don't) know, it takes you to a spoofed phishing website that tells you your OpenAI or Gmail or PayPal session has expired and you need to re-login. If you're not careful, the attackers now have all your login info, including any MFA codes 🥲 gg

Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭

418,840 просмотров • 9 месяцев назад

Obsidian 1.8.3 is now available to all for desktop and mobile! - Web viewer. New core plugin lets you open external links within Obsidian on desktop. This makes it easier to read linked content without leaving the app and improves multitasking for web research. The plugin can be enabled manually in settings. - Improved iCloud sync. Obsidian no longer waits to confirm that configuration files have synced. - New mobile onboarding. This guided flow helps new mobile users create and sync a vault. - New "Download attachments for current file" command. Downloads all externally embedded images and replaces the external links with internal embeds. A few notable improvements: - When modifying a numbered list, the numbers are now updated automatically. - Pressing Enter in a multi-line list item now continues the list properly. - New "Insert footnote" command. Footnote autocomplete now provides a fallback to create a new footnote if no match is found. - Tags view now includes search. - File Explorer now includes an option to automatically reveal the active file. - Outline now has an "Auto-scroll to current section" option. - Sync now has a new view option, "Hide my changes," which hides your own file changes in a shared Obsidian sync vault. - Recently used commands now appear at the top of the command palette. - "Search current file" search bar now displays the total number of results. - "Insert template" command now sorts templates by file path and displays folder names. - , , and tags with relative src paths are now rendered in Live Preview and Reading mode. - Graph view no longer considers Canvas files as attachments. See the changelog for dozens more improvements and bug fixes.

Obsidian

118,704 просмотров • 1 год назад