Aggregator
CVE-2025-25292 | SAML-Toolkits ruby-saml up to 1.12.3/1.17.x ReXML/Nokogiri signature verification (GHSA-754f-8gm6-c4r2)
psudohash: Generates millions of keyword-based password mutations in seconds
psudohash Psudohash is a password list generator for orchestrating brute force attacks and cracking hashes. It imitates certain password creation patterns commonly used by humans, like substituting a word’s letters with symbols or numbers...
The post psudohash: Generates millions of keyword-based password mutations in seconds appeared first on Penetration Testing Tools.
web-check: All-in-one OSINT tool for analysing any website
web-check Get an insight into the inner workings of a given website: uncover potential attack vectors, analyse server architecture, view security configurations, and learn what technologies a site is using. Currently, the dashboard will...
The post web-check: All-in-one OSINT tool for analysing any website appeared first on Penetration Testing Tools.
紧急:微软修复57个安全漏洞,其中6个零日漏洞已被积极利用
CVE-2025-25291 | SAML-Toolkits ruby-saml up to 1.12.3/1.17.x ReXML/Nokogiri signature verification (GHSA-4vc4-m8qh-g8jm)
CVE-2025-25293 | SAML-Toolkits ruby-saml up to 1.12.3/1.17.x Message Size resource consumption (GHSA-92rq-c8cf-prrq)
CVE-2025-0116 | Palo Alto PAN-OS/Cloud NGFW/Prisma Access LLDP Frame unusual condition
CVE-2025-0115 | Palo Alto PAN-OS/Cloud NGFW/Prisma Access CLI resolution of path
CVE-2025-0114 | Palo Alto PAN-OS/Cloud NGFW/Prisma Access GlobalProtect resource consumption
CVE-2025-27407 | rmosolgo graphql-ruby up to 2.3.20 Loader.load code injection (GHSA-q92j-grw3-h492)
Callisto: An Intelligent Binary Vulnerability Analysis Tool
Callisto An Intelligent Automated Binary Vulnerability Analysis Tool Callisto is an intelligent automated binary vulnerability analysis tool. Its purpose is to autonomously decompile a provided binary and iterate through the pseudo code output looking...
The post Callisto: An Intelligent Binary Vulnerability Analysis Tool appeared first on Penetration Testing Tools.
SMShell: PoC for a SMS-based shell
SMShell PoC for an SMS-based shell. Send commands and receive responses over SMS from mobile broadband-capable computers. This tool came as an inspiration during research on eSIM security implications led by Markus Vervier, presented...
The post SMShell: PoC for a SMS-based shell appeared first on Penetration Testing Tools.