POC for CVE-2024-6387 Remote Code Execution | Bug bounty poc

Поделиться
HTML-код
  • Опубликовано: 26 окт 2024

Комментарии • 41

  • @haxshadow7
    @haxshadow7  Месяц назад

    join my Telegram channel-: t.me/mr0rh

  • @davidtancredi5658
    @davidtancredi5658 3 месяца назад +9

    Next time you use a template from another researcher (me..), at least have the decency to give credit where it is due. Funny you did not even bother changing the template name but straight out copied "cve-2024-6387-new.yaml" without knowing that the "new" tag I added was because I messed up the regex during testing. Sad.

    • @flowback6481
      @flowback6481 3 месяца назад +1

      活捉大佬 your video is so cool , I am your Fans~ 😀

    • @haxshadow7
      @haxshadow7  Месяц назад

      tnx bro

    • @anonp2958
      @anonp2958 25 дней назад

      @@haxshadow7 A bit late now! 😕

  • @hometrailer4865
    @hometrailer4865 3 месяца назад +11

    Wtf where is the POC skid

    • @Warning_Zone
      @Warning_Zone 3 месяца назад +1

      If you got them also tell me

    • @bugbounty9508
      @bugbounty9508 Месяц назад

      @@Warning_Zone share with me too

    • @kil_l_y
      @kil_l_y Месяц назад

      I have one lol. l-urk is my github

    • @haxshadow7
      @haxshadow7  Месяц назад

      ok

  • @3jee387
    @3jee387 3 месяца назад +6

    this only scans... show an actual rce next time

  •  Месяц назад

    There is nothing on your telegram (about CVE-2024-6387 exploit) Also you can do it on your local and you can share on youtube)

    • @haxshadow7
      @haxshadow7  Месяц назад

      you have to google how to do it expertly..

    •  Месяц назад

      @rajibhassen3 You telling us about an exploit in your telegram account. But there is nothing. I am talking about truth. Of course, I found an exploit and I created a shell and tested it locally, not work for me.

  • @darkmix4192
    @darkmix4192 3 месяца назад

    Brother this is only scanning process...next do manual, do you know manual test? I know and I reported lot in openssh server but doesn't respond that organisation. Now I leave the cve.

    • @haxshadow7
      @haxshadow7  3 месяца назад

      bro, i cna give the complete process on youtube if i want. due to some youtube rules and regulations I can't show as an expert. you can google it if you wnat

    • @Warning_Zone
      @Warning_Zone 3 месяца назад

      ​@@haxshadow7please provide any link or make any cheap course on it

  • @heyiamuday
    @heyiamuday 3 месяца назад +2

    Bro I didn't find nuclei template

    • @haxshadow7
      @haxshadow7  3 месяца назад

      This is private template bro

    • @kemeliaafrinkethi6606
      @kemeliaafrinkethi6606 3 месяца назад +1

      ​@@haxshadow7 no it is open source

    • @davidtancredi5658
      @davidtancredi5658 3 месяца назад

      As a matter of fact, my private template, which is in fact open source and available in my git repo 😂​@@kemeliaafrinkethi6606

    • @davidtancredi5658
      @davidtancredi5658 3 месяца назад

      Enjoy

  • @kemeliaafrinkethi6606
    @kemeliaafrinkethi6606 3 месяца назад +1

    This template is open source

  • @shingareom
    @shingareom 3 месяца назад

    Bro give the full credit to the song owner.

    • @haxshadow7
      @haxshadow7  3 месяца назад

      who owns the song?

    • @shingareom
      @shingareom 3 месяца назад +1

      @@haxshadow7 lostsec bro.

  • @100SHEMKUMARP
    @100SHEMKUMARP 3 месяца назад

    how exploit that server

  • @tempermail5735
    @tempermail5735 3 месяца назад

    script kiddie

  • @abhinabshrestha5175
    @abhinabshrestha5175 3 месяца назад

    Lostsec fanboy

  • @JoshTWO-ml5mo
    @JoshTWO-ml5mo 3 месяца назад

    How to Exploit?

    • @haxshadow7
      @haxshadow7  3 месяца назад

      Given in my Telegram channel

    • @valentinodentesano4182
      @valentinodentesano4182 3 месяца назад +1

      @@haxshadow7 you didnt

    • @RonaldoPiedade-zl1gv
      @RonaldoPiedade-zl1gv 3 месяца назад

      ​@@haxshadow7what is ur telegram channel bro?

    • @darkmix4192
      @darkmix4192 3 месяца назад

      Hi brother I'm intermidiat researcher and coffinxp student, I know this concept cve​....next process try ssh command to exploit then some commands to monitoring the race condition attack. Then you'll take rce attack.@@valentinodentesano4182