And here we go, first CVE-2025-53770 exploit hitting the honeypots I deployed. I guess there is a public exploit now somewhere?
POST /_layouts/15/ToolPane.aspx?DisplayMode=Edit&a=/ToolPane.aspx HTTP/1.1 Host: xxxx User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64;…
And here we go, first CVE-2025-53770 exploit hitting the honeypots I deployed. I guess there is a public exploit now somewhere?
POST /_layouts/15/ToolPane.aspx?DisplayMode=Edit&a=/ToolPane.aspx HTTP/1.1 Host: xxxx User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64;… https://t.co/bw5EJTNshJ
That is actually the real exploit.
I went through all the decoding and stuff.
It finally is the payload that creates spinstall0.aspx which then gets you the machine keys that allow you to craft your own Viewstates.
That is actually the real exploit.
I went through all the decoding and stuff.
It finally is the payload that creates spinstall0.aspx which then gets you the machine keys that allow you to craft your own Viewstates. https://t.co/9SjaPAlurx
3 Followers 192 FollowingI’m a 17-year-old cybersecurity enthusiast on a mission to document my journey into the world of hacking, red teaming, and security research.
294 Followers 693 Followingsecurity researcher, aficionado of theoretical CS and program analysis, player of 🎹 and 🎸. connoisseur of class 4 scrambling & technical hikes⛰️
7K Followers 788 FollowingSecurity engineer at https://t.co/027VXUlgOx. Focusing on the Linux kernel. Maintaining @linkersec. Trainings at https://t.co/D5MrxmYimS.
18K Followers 835 FollowingRansomware, Online Security, and Malware. Owner, Editor in Chief of @bleepincomputer.
DM on Signal: LawrenceA.11 * https://t.co/LXVRoICs8Z
48K Followers 2K FollowingSpecializing in pen testing, red teaming, and Active SOC. We share our knowledge through blogs, webcasts, open-source tools, and Backdoors & Breaches game.
77K Followers 765 FollowingEnd-to-end Cybersecurity consulting team leading the industry, supporting organizations, and giving back. #Hacktheplanet
Blogs, news, webinars, and tools!
11K Followers 1K FollowingCensys is the source for real-time Internet intelligence and actionable threat insights for governments, F500 companies, and leading threat intel providers