MaxMnMl
banner
maxmnml.bsky.social
MaxMnMl
@maxmnml.bsky.social
[ - ] https://github.com/MaxMnMl [ - ] c12f97f864dff657f7294c6c9d03e18d
Google Cloud Account Takeover via URL Parsing Confusion 💣🔥👀

infosecwriteups.com/google-cloud...
Google Cloud Account Takeover via URL Parsing Confusion
TL;DR
infosecwriteups.com
May 3, 2025 at 5:25 PM
🔓 Just beat the "Dojo #40 - Hacker profile" challenge on @YesWeHack!
Think you can match my skills? 🌟

dojo-yeswehack.com/challenge/pl...

#YesWeHack #ChallengeAccepted
Dojo #40 - Hacker profile - YesWeHack Dojo
# Hacker profile - Dojo #40 Active until : **17th April - 2025** Authors: [Minilucker](https://x.com/0xidel) #### How to submit your report 1. Visit the Dojo program at [https://yeswehack.com/progr...
dojo-yeswehack.com
March 30, 2025 at 8:55 PM
Reposted by MaxMnMl
Paged Out! #6 has arrived! And it's jam-packed with content!
You can download it here:
pagedout.institute?page=issues....
March 29, 2025 at 12:17 PM
Exploring Dompurify Misc (2/2) by @mizu.re … What an Amazing Work 🫶

mizu.re/post/explori...
Exploring the DOMPurify library: Hunting for Misconfigurations (2/2). Tags:Article - Article - Web - mXSS
Exploring the DOMPurify library: Hunting for Misconfigurations (2/2)
mizu.re
March 1, 2025 at 8:01 AM
Amazing Work 👏 … The MIDI Shellcode 🎹👾
psi3.ru/blog/swl01u/
World's First MIDI Shellcode
Blog post about a reverse engineering project
psi3.ru
January 27, 2025 at 9:36 PM
Broken authentication: 7 Advanced ways of bypassing insecure 2-FA implementations 🪲

blog.intigriti.com/hacking-tool...
Broken authentication: 7 Advanced ways of bypassing insecure 2-FA implementations
Two-factor authentication (2FA) has become the go-to solution for strengthening account security. More and more companies are deploying 2FA implementations, and some even enforce them on their users t...
blog.intigriti.com
December 9, 2024 at 6:19 AM
Cross-Site POST Requests Without a Content-Type Header 🛰️

nastystereo.com/security/cro...
Cross-Site POST Requests Without a Content-Type Header / nastystereo.com
nastystereo.com
December 4, 2024 at 8:26 PM
Zero-Day in Active Directory Certificate Services: Researcher Exposes CVE-2024-49019 with PoC 🚀🪟

securityonline.info/zero-day-in-...
Zero-Day in Active Directory Certificate Services: Researcher Exposes CVE-2024-49019 with PoC
Discover the details of the critical zero-day vulnerability CVE-2024-49019 affecting Active Directory Certificate Services (AD CS).
securityonline.info
November 30, 2024 at 8:38 AM
Reposted by MaxMnMl
What is an API? What makes them special? And what kind of APIs are out there? #apisecurity #apis #bugbountytips #BugBounty
November 30, 2024 at 8:00 AM
💢 regreSSHion: RCE in OpenSSH's server, on glibc-based Linux systems
(CVE-2024-6387)

Qualys Paper : www.qualys.com/2024/07/01/c...
www.qualys.com
July 3, 2024 at 5:03 AM
The leader of GhostSec, Sebastian Dante Alexander, talks about the group's decision to abandon financial hacking and shift its focus to hacktivism.

podcasts.apple.com/fr/podcast/c...
‎Click Here : 139. Mic Drop: GhostSec’s quest for redemption: their leader claims their life of crime is over. sur Apple Podcasts
‎Afficher Click Here, ép 139. Mic Drop: GhostSec’s quest for redemption: their leader claims their life of crime is over. - 14 juin 2024
podcasts.apple.com
June 15, 2024 at 1:42 PM
Hacking Millions Of Modem 👀. An incredible work of samwcyo, a must read guys. 💢

samcurry.net/hacking-mill...
Hacking Millions of Modems (and Investigating Who Hacked My Modem)
Two years ago, something very strange happened to me while working from my home network. I was exploiting a blind XXE vulnerability that required an external HTTP server to smuggle out files, so I spu...
samcurry.net
June 8, 2024 at 1:53 PM
💢Le groupe de hacker pro russe Killnet annonce detenir la version originale de Pegasus (NSO Group). Mise en vente : 1 500 000 $.

« Nous avons actuellement entre nos mains la version originale. Nous avons le programme pour toujours ! NSO ne pourra pas restreindre l’accès. »
April 6, 2024 at 10:26 AM
The DGSI gets DDOSed by the GLORIAMIST hacker group 😅 We've seen it all !!
April 1, 2024 at 9:10 PM