@Vx_main

🗡️, 🛡️, 🦠, 🕷️, 🕸️

Joined February 2025
So fast?
FalconFlank : Crowdstrike Falcon 0day LPE is now public github.com/MSNightmare/Falco…
59
FalconFlank : Crowdstrike Falcon 0day LPE is now public github.com/MSNightmare/Falco…
91
503
78
2,915
365,641
😏😏
I absolutely LOVE cookie tossing! 🍪 It's one of my favorite attacks. Just found another one: 1️⃣ You upload an SVG file to this site and it stores it at files[.]target[.]com. 👉 This is XSS, but quite useless on this domain 2️⃣ You use the XSS to set a cookie on the parent domain target[.]com for a specific path? 🤔 But why do you want to set a cookie on the parent domain Well because now when the victim uses the site, they will be using their own account ... BUT ... when they link their Github account to the site, that request will actually use MY cookie that I set via the cookie tossing. What cookie did I set? Well, my own session token! So when the user links their Github account, it will actually link it to MY ACCOUNT on target[.]com and just like that, I can access all their private Github repositories. I love cookie tossing 🍪
42
what the f....🤣🤣
1
43
Sent a SALARY REVIEW phishing mail to all staff this morning. Data protection officer clicked 😭😭😭
1,284
8,117
2,097
122,910
7,192,516
😅😅😅😅
2
66