SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							89503b1c9d
							
						
					 | 
					
						
						
							
							Merge pull request #1119 from HackTricks-wiki/update_SugarCRM___14_0_0__css_preview__LESS_Code_Injectio_20250714_123930
						
						
						
						
						
						
						
						SugarCRM ≤ 14.0.0 (css/preview) LESS Code Injection Vulnerab... 
						
						
					 | 
					
						2025-07-15 12:38:08 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							431f25c0fc
							
						
					 | 
					
						
						
							
							Add content from: Research Update: Enhanced src/windows-hardening/active-direc...
						
						
						
						
						
						
					 | 
					
						2025-07-15 08:28:01 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							afa72557d9
							
						
					 | 
					
						
						
							
							Add content from: Research Update: Enhanced src/network-services-pentesting/51...
						
						
						
						
						
						
					 | 
					
						2025-07-15 01:44:52 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							bb656a41ed
							
						
					 | 
					
						
						
							
							Add content from: Research Update: Enhanced src/macos-hardening/macos-security...
						
						
						
						
						
						
					 | 
					
						2025-07-14 16:29:36 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							2c5590c448
							
						
					 | 
					
						
						
							
							Add content from: Fix the Click: Preventing the ClickFix Attack Vector
						
						
						
						
						
						
					 | 
					
						2025-07-14 12:51:11 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							10b6790c7a
							
						
					 | 
					
						
						
							
							Add content from: Shizuku: Unlocking Advanced Android Capabilities Without Roo...
						
						
						
						
						
						
					 | 
					
						2025-07-14 12:49:08 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							c3f4c8eaf6
							
						
					 | 
					
						
						
							
							Add content from: SugarCRM ≤ 14.0.0 (css/preview) LESS Code Injection Vulnerab...
						
						
						
						
						
						
					 | 
					
						2025-07-14 12:40:51 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								carlospolop
							
						 
					 | 
					
						
						
						
						
							
						
						
							cec78bcdf8
							
						
					 | 
					
						
						
							
							f
						
						
						
						
						
						
					 | 
					
						2025-07-14 10:37:16 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							5de2f07668
							
						
					 | 
					
						
						
							
							Merge pull request #1100 from HackTricks-wiki/update_Pre-auth_SQL_Injection_to_RCE_in_Fortinet_FortiWeb_20250711_182725
						
						
						
						
						
						
						
						Pre-auth SQL Injection to RCE in Fortinet FortiWeb Fabric Co... 
						
						
					 | 
					
						2025-07-14 10:34:17 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							4b6147f85a
							
						
					 | 
					
						
						
							
							Merge pull request #1096 from HackTricks-wiki/research_update_src_network-services-pentesting_pentesting-telnet_20250711_082533
						
						
						
						
						
						
						
						Research Update Enhanced src/network-services-pentesting/pen... 
						
						
					 | 
					
						2025-07-13 23:18:21 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							56a15d52b9
							
						
					 | 
					
						
						
							
							Merge pull request #1097 from HackTricks-wiki/update_Hijacker_on_the_Samsung_Galaxy_S10_with_wireless_i_20250711_123906
						
						
						
						
						
						
						
						Hijacker on the Samsung Galaxy S10 with wireless injection 
						
						
					 | 
					
						2025-07-13 20:01:48 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							50413dd66a
							
						
					 | 
					
						
						
							
							Merge branch 'master' into update_Hijacker_on_the_Samsung_Galaxy_S10_with_wireless_i_20250711_123906
						
						
						
						
						
						
					 | 
					
						2025-07-13 19:02:28 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							194b113125
							
						
					 | 
					
						
						
							
							Merge branch 'master' into research_update_src_network-services-pentesting_pentesting-telnet_20250711_082533
						
						
						
						
						
						
					 | 
					
						2025-07-13 19:02:12 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							ec810eb93d
							
						
					 | 
					
						
						
							
							Merge pull request #1098 from HackTricks-wiki/update_Evolving_Tactics_of_SLOW_TEMPEST__A_Deep_Dive_Into_20250711_124156
						
						
						
						
						
						
						
						Evolving Tactics of SLOW#TEMPEST A Deep Dive Into Advanced M... 
						
						
					 | 
					
						2025-07-13 04:42:46 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							da3d1d6f49
							
						
					 | 
					
						
						
							
							Merge pull request #1099 from HackTricks-wiki/research_update_src_pentesting-web_http-connection-request-smuggling_20250711_162342
						
						
						
						
						
						
						
						Research Update Enhanced src/pentesting-web/http-connection-... 
						
						
					 | 
					
						2025-07-13 00:01:32 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							63cc164d9e
							
						
					 | 
					
						
						
							
							Merge pull request #1104 from HackTricks-wiki/research_update_src_pentesting-web_http-request-smuggling_request-smuggling-in-http-2-downgrades_20250712_013912
						
						
						
						
						
						
						
						Research Update Enhanced src/pentesting-web/http-request-smu... 
						
						
					 | 
					
						2025-07-12 20:01:36 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							08be34a8cf
							
						
					 | 
					
						
						
							
							Merge pull request #1110 from HackTricks-wiki/research_update_src_linux-hardening_privilege-escalation_docker-security_docker-breakout-privilege-escalation_docker-release_agent-cgroups-escape_20250712_110342
						
						
						
						
						
						
						
						Research Update Enhanced src/linux-hardening/privilege-escal... 
						
						
					 | 
					
						2025-07-12 17:18:23 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							9cd3de8711
							
						
					 | 
					
						
						
							
							Update README.md
						
						
						
						
						
						
					 | 
					
						2025-07-12 17:18:04 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							9311653d7a
							
						
					 | 
					
						
						
							
							Update 2375-pentesting-docker.md
						
						
						
						
						
						
					 | 
					
						2025-07-12 17:15:03 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							b82c3738a1
							
						
					 | 
					
						
						
							
							Merge branch 'master' into research_update_src_pentesting-web_http-request-smuggling_request-smuggling-in-http-2-downgrades_20250712_013912
						
						
						
						
						
						
					 | 
					
						2025-07-12 17:12:40 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							8e2325171c
							
						
					 | 
					
						
						
							
							Merge branch 'master' into update_Pre-auth_SQL_Injection_to_RCE_in_Fortinet_FortiWeb_20250711_182725
						
						
						
						
						
						
					 | 
					
						2025-07-12 17:12:25 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							e65a6bb268
							
						
					 | 
					
						
						
							
							Merge branch 'master' into research_update_src_pentesting-web_http-connection-request-smuggling_20250711_162342
						
						
						
						
						
						
					 | 
					
						2025-07-12 17:12:10 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							8c59d4a67c
							
						
					 | 
					
						
						
							
							Merge branch 'master' into update_Evolving_Tactics_of_SLOW_TEMPEST__A_Deep_Dive_Into_20250711_124156
						
						
						
						
						
						
					 | 
					
						2025-07-12 17:11:53 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							8cf1f42121
							
						
					 | 
					
						
						
							
							Merge branch 'master' into update_Hijacker_on_the_Samsung_Galaxy_S10_with_wireless_i_20250711_123906
						
						
						
						
						
						
					 | 
					
						2025-07-12 17:11:35 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							777109375e
							
						
					 | 
					
						
						
							
							Merge branch 'master' into research_update_src_network-services-pentesting_pentesting-telnet_20250711_082533
						
						
						
						
						
						
					 | 
					
						2025-07-12 17:11:02 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							ad720976e8
							
						
					 | 
					
						
						
							
							Merge pull request #1095 from HackTricks-wiki/research_update_src_pentesting-web_rate-limit-bypass_20250711_012858
						
						
						
						
						
						
						
						Research Update Enhanced src/pentesting-web/rate-limit-bypas... 
						
						
					 | 
					
						2025-07-12 16:01:31 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							9e75f98936
							
						
					 | 
					
						
						
							
							Add content from: Research Update: Enhanced src/linux-hardening/privilege-esca...
						
						
						
						
						
						
					 | 
					
						2025-07-12 11:05:14 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							200ef798df
							
						
					 | 
					
						
						
							
							Merge pull request #1109 from HackTricks-wiki/research_update_src_todo_radio-hacking_low-power-wide-area-network_20250712_104905
						
						
						
						
						
						
						
						Research Update Enhanced src/todo/radio-hacking/low-power-wi... 
						
						
					 | 
					
						2025-07-12 12:59:35 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							92a9bc7b12
							
						
					 | 
					
						
						
							
							Add content from: Research Update: Enhanced src/todo/radio-hacking/low-power-w...
						
						
						
						
						
						
					 | 
					
						2025-07-12 10:50:06 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								carlospolop
							
						 
					 | 
					
						
						
						
						
							
						
						
							3ad9a55c92
							
						
					 | 
					
						
						
							
							f
						
						
						
						
						
						
					 | 
					
						2025-07-12 11:50:55 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							1d1354c07d
							
						
					 | 
					
						
						
							
							Merge pull request #1101 from HackTricks-wiki/update_Dojo_CTF_Challenge__42__Hex_Color_Palette_XXE_File_20250711_183320
						
						
						
						
						
						
						
						Dojo CTF Challenge #42 Hex Color Palette XXE File Disclosure... 
						
						
					 | 
					
						2025-07-12 11:40:31 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							24d32ecb5a
							
						
					 | 
					
						
						
							
							Merge pull request #1105 from HackTricks-wiki/research_update_src_windows-hardening_active-directory-methodology_printnightmare_20250712_082222
						
						
						
						
						
						
						
						Research Update Enhanced src/windows-hardening/active-direct... 
						
						
					 | 
					
						2025-07-12 11:39:59 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							f53c11416a
							
						
					 | 
					
						
						
							
							Merge pull request #1102 from LetMeBeBee/nginx_try_files
						
						
						
						
						
						
						
						nginx try_files directive with variables 
						
						
					 | 
					
						2025-07-12 11:33:31 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								carlospolop
							
						 
					 | 
					
						
						
						
						
							
						
						
							e028317c2b
							
						
					 | 
					
						
						
							
							Merge branch 'master' of github.com:HackTricks-wiki/hacktricks
						
						
						
						
						
						
					 | 
					
						2025-07-12 10:48:51 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								carlospolop
							
						 
					 | 
					
						
						
						
						
							
						
						
							23d3f5017d
							
						
					 | 
					
						
						
							
							a
						
						
						
						
						
						
					 | 
					
						2025-07-12 10:48:33 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							e3705cacd5
							
						
					 | 
					
						
						
							
							Add content from: Research Update: Enhanced src/windows-hardening/active-direc...
						
						
						
						
						
						
					 | 
					
						2025-07-12 08:24:17 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							d0cc46ce8b
							
						
					 | 
					
						
						
							
							Add content from: Research Update: Enhanced src/pentesting-web/http-request-sm...
						
						
						
						
						
						
					 | 
					
						2025-07-12 01:40:49 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								n0ll
							
						 
					 | 
					
						
						
						
						
							
						
						
							cee232eead
							
						
					 | 
					
						
						
							
							nginx try_files directive with variables
						
						
						
						
						
						
					 | 
					
						2025-07-11 18:07:01 -04:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							fd1ef02762
							
						
					 | 
					
						
						
							
							Add content from: Dojo CTF Challenge #42: Hex Color Palette XXE File Disclosur...
						
						
						
						
						
						
					 | 
					
						2025-07-11 18:37:22 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							f5fdc6ec50
							
						
					 | 
					
						
						
							
							Add content from: Pre-auth SQL Injection to RCE in Fortinet FortiWeb Fabric Co...
						
						
						
						
						
						
					 | 
					
						2025-07-11 18:33:07 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							c65bce5f6d
							
						
					 | 
					
						
						
							
							Add content from: Research Update: Enhanced src/pentesting-web/http-connection...
						
						
						
						
						
						
					 | 
					
						2025-07-11 16:25:39 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							5dc7c0dc1a
							
						
					 | 
					
						
						
							
							Add content from: Evolving Tactics of SLOW#TEMPEST: A Deep Dive Into Advanced ...
						
						
						
						
						
						
					 | 
					
						2025-07-11 12:44:12 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							280be33c0e
							
						
					 | 
					
						
						
							
							Add content from: Hijacker on the Samsung Galaxy S10 with wireless injection
						
						
						
						
						
						
					 | 
					
						2025-07-11 12:41:44 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							b5fa7686cd
							
						
					 | 
					
						
						
							
							Merge pull request #1087 from HackTricks-wiki/research_update_src_pentesting-web_sql-injection_ms-access-sql-injection_20250710_082628
						
						
						
						
						
						
						
						Add content: Research Update Enhanced src/pentesting-web/sql-injection/ms... 
						
						
					 | 
					
						2025-07-11 12:01:48 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							8ab6aee5a1
							
						
					 | 
					
						
						
							
							Add content from: Research Update: Enhanced src/network-services-pentesting/pe...
						
						
						
						
						
						
					 | 
					
						2025-07-11 08:27:18 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							5c44912c76
							
						
					 | 
					
						
						
							
							Merge pull request #1089 from HackTricks-wiki/research_update_src_mobile-pentesting_ios-pentesting_ios-pentesting-without-jailbreak_20250710_083503
						
						
						
						
						
						
						
						Add content: Research Update Enhanced src/mobile-pentesting/ios-pentestin... 
						
						
					 | 
					
						2025-07-11 08:01:55 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							716cf3771a
							
						
					 | 
					
						
						
							
							Merge pull request #1092 from HackTricks-wiki/research_update_src_linux-hardening_privilege-escalation_docker-security_docker-breakout-privilege-escalation_sensitive-mounts_20250710_162429
						
						
						
						
						
						
						
						Research Update Enhanced src/linux-hardening/privilege-escal... 
						
						
					 | 
					
						2025-07-11 04:36:52 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								HackTricks News Bot
							
						 
					 | 
					
						
						
						
						
							
						
						
							a53839b788
							
						
					 | 
					
						
						
							
							Add content from: Research Update: Enhanced src/pentesting-web/rate-limit-bypa...
						
						
						
						
						
						
					 | 
					
						2025-07-11 01:30:33 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							8afdfa9956
							
						
					 | 
					
						
						
							
							Merge pull request #1093 from HackTricks-wiki/update_CVE-2025-27636___Remote_Code_Execution_in_Apache_C_20250710_182732
						
						
						
						
						
						
						
						CVE-2025-27636 – Remote Code Execution in Apache Camel via C... 
						
						
					 | 
					
						2025-07-11 00:01:39 +02:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								SirBroccoli
							
						 
					 | 
					
						
						
						
						
							
						
						
							c6ee4707ee
							
						
					 | 
					
						
						
							
							Merge pull request #1086 from HackTricks-wiki/research_update_src_mobile-pentesting_android-app-pentesting_reversing-native-libraries_20250710_013259
						
						
						
						
						
						
						
						Add content: Research Update Enhanced src/mobile-pentesting/android-app-p... 
						
						
					 | 
					
						2025-07-10 23:28:51 +02:00 | 
					
					
						
						
							
							
							
						
					 |