@mf0cuz Profile picture

Maxim Tyukov

@mf0cuz

aka mfocuz . Security research, Bug bounty, CTF, Programming.

Joined July 2013
Similar User
Aleksei Tiurin photo

@antyurin

Dmitriy Evdokimov photo

@evdokimovds

H̷͙̰͕̼̫̥͔̮͓͈͉̩͇̯̍̄̍́͊̋̓͜_̸̭̤̻̫͚̗͒̀́̊͆͜D̷̛̈́̏̓̈̒̈͂̚͝ photo

@hd_421

Alexander Zaytsev photo

@arbitrarycode

Zabbix 7.0 has introduced a new feature that allows manual user input for scripts: lnkd.in/e5GfJmqw So now user roles may control script input. Be very careful when setting the "Input validation rule," as it is now the first place hackers will check.

Tweet Image 1
Tweet Image 2
Tweet Image 3

3000$ bug and my second CVE in collection support.zabbix.com/browse/ZBX-245…


Maxim Tyukov Reposted

Common Vulnerabilities in #SmartContracts

Tweet Image 1

Just got my first CVE! Request smuggling in spring: tanzu.vmware.com/security/cve-2…


Found Netflix Registry service exposed to internet? That is how you can exploit it: “Hacking Netflix Eureka!” by Maxim link.medium.com/v0iXQwWa8jb


Maxim Tyukov Reposted

The new version is almost ready. In the meantime - meet the online password generator. Suitable for generation wordlist based on specific words, names, and so on with hashcat rules. Happy cracking! #passwords github.com/zzzteph/weakpa… Online generator: zzzteph.github.io/weakpass/


Maxim Tyukov Reposted

💥Easy RCE Ports (part 2) IBM WebSphere: 8880 Apache Hadoop: 8088 Redis: 6379 Docker: 2375 Apache Solr: 8983 Zoho Manageengine Desktop: 8383 Atlassian Crowd: 4990 Portainer: 9000 Hashicorp Consul: 8500 Apache Spark: 6066 #ptswarmTechniques

Tweet Image 1

Maxim Tyukov Reposted

Active Directory Cheat Sheet - A cheat sheet that contains common enumeration and attack methods for Windows Active Directory github.com/Integration-IT…


Maxim Tyukov Reposted

I promise, I'll have the rest of the videos uploaded to YouTube soon. For now enjoy @Jhaddix's "The Bug Hunter's Methodology v4.0" from #NahamCon2020 youtu.be/p4JgIu1mceI

Tweet Image 1

My friends released hacking educational portal hacktory.ai, check it out!


Maxim Tyukov Reposted
Tweet Image 1

Maxim Tyukov Reposted

ParamSpider : Parameter miner for humans Got a nice SSRF last week using this : - paramspider found a url with parameter ?file_url= - The parameter was deprecated long back from the production - luckily the parameter was vulnerable to SSRF Github : github.com/devanshbatham/…

Tweet Image 1

Maxim Tyukov Reposted

CRYPTOHACK : A fun platform for learning modern cryptography : cryptohack.org


Maxim Tyukov Reposted

A deep dive into disable_functions bypasses and PHP exploitation (long post with internals, fuzzing & examples) blackarrow.net/disable-functi…


Maxim Tyukov Reposted

Whoever wrote this... I love you gitexplorer.com this will make anyone who is starting to use git (or just wants a quick answer) life that much easier!


If you are interested in hacking, you definitely want to become a patron of zzzteph for weakpass.com and Pavel Zhovner for flipperzero.one on patreon! I'm in!


Maxim Tyukov Reposted

Good whitepaper about windows 10 secure kernel: "Live forensics on the Windows 10 securekernel (2017)" ntnuopen.ntnu.no/ntnu-xmlui/bit…


Maxim Tyukov Reposted

Reversing Windows Internals (Part 1) – Digging Into Handles, Callbacks & ObjectTypes rayanfam.com/topics/reversi…


United States Trends
Loading...

Something went wrong.


Something went wrong.