Windows Snipping Tool is vulnerable to sensitive data leakage after cropping -
Windows Snipping Tool is vulnerable to sensitive data leakage after cropping
If you had an arbitrary file read exploit, what would you do to try and escalate it to a remote shell? 🤔
The dark defaults of Microsoft Edge - TL:DR Full on keylogging and similar by default
Exploiting aCropalypse: Recovering cropped PNGs -
Exploiting aCropalypse: Recovering cropped PNGs -
Misc dump of a mechanical part seller including limited customer information. Credit to @savage_sales
Just a general public announcement, stop with the vaccine ramblings, thanks. Given how politically charged it can be and how I don't really feel like this is the appropriate place for politics, I'm sure you can understand my reasoning. P.s. In my humble opinion, the tracking stuff makes absolutely no sense. There is no need for such elaborate shit when everyone has phones that they can track you through. Sources:SCOTUS Says Domestic Spying Is Too Secret to Be Challenged in Court - FBI Just Admitted It Bought US Location Data
Fun fact:According to shodan, 0.311% of the IPV4 range are honeypots.
Google compiled a list of likely affected products:Samsung Galaxy phones including those in the S22, M33, M13, M12, A71, A53, A33, A21, A13, A12, and A04 seriesVivo phones including those in the S16, S15, S6, X70, X60, and X30 seriesGoogle Pixel 6 and 6 Pro, Pixel 6a, Pixel 7 and 7 ProAny wearables that use the Exynos W920 chipsetAny vehicles that use the Exynos Auto T5123 chipset
Google: Turn off VoLTE, Wi-Fi calling: severe Exynos modem vulnerabilities -
How can I debug chrome when chrome://crashes ... crashes?
How could an attacker exploit this vulnerability?An attacker could send a low-level protocol error containing a fragmented IP packet inside another ICMP packet in its header to the target machine. To trigger the vulnerable code path, an application on the target must be bound to a raw socket.
Internet Control Message Protocol (ICMP) Remote Code Execution Vulnerability -
I apologize for the lack of pixels, the government stole most of them
@FrankHambert is looking for some crowdfunding for a archival effort.
What's the coolest/best name for a penetration testing company you can think of? 🤔
Rather interesting cellibrite write-up I think you'd enjoy.
What's the best currency? Gold, Silver, Crypto or Cash?
Screw "good" code fixes. I spent hours trying to pass some data into a python library to realize that the fork I had to use was ignoring that data entirely. 🤓
It's not appropriate or necessary to threaten to replace someone with a few hundred lines of code, though technically feasible.Coworkers are not to be subject of psychological experiments, regardless of how benign they may be.Sniffing the SSH and Kerberos password of the chief security officer isn't funny.Sending inane messages to management when a user leaves their desktop unlocked doesn't effectively promote desktop security practicecs.Challenging a developer to a duel because he constantly fails to do bounds checking or input validation will not fix the problem.Calling desktop support to my desk to deliver a mouse because playing a first person shooter with trackpad only is not a valuable use of company resources.I'm not allowed to trade on of my coworkers to another team.Nor am I authorized to fire anyone."I'm still a little drunk" is not an approiate answer when asked how the late night server maintenance went.
Hiring PHP developers does not contribute to the quota of employees with disabilities.While its advisable to confer with the team before writing something in Ruby or Go which they don't know, Brainfuck is never an appropriate language.Comments in code are not only "for those of weak constitution and simple minds"Quoting Oscar Wilde's "The Soul of Man Under Socialism" during a charity function isn't helping."Project management may be compared to a primate attempting sexual congress with a football" is right outAn hourly crontab from 3am-6am stating the time via SMS to a coworker doesn't convey any useful information.Reverse engineering the encoding in a closed source messaging protocol an employee uses for non-business related communications and posting the study with the live data is in poor taste.Exploiting and shutting off compromised routers leveraged in a DoS attack directed at the company, while more effective than upstream filtering, is still a federal crime."Do you suffer from a learning disability?" is likely never a proper response to anything.
No jail time for women who raped a 13 year old - know this is generally off topic from our usual content but these kinds of double standards piss me off 😔
Remember friends, they don't care about your safety. Only about shareholders profit. That's the way the system works.
Leaked audio reveals US rail workers were told to skip inspections -
I would like to address an informal complaint about our channel not being learning focused enough. I share stuff I find interesting or amusing, I'm not smart. I'm literally a morbidly obese cat who eats lasagne.
Imagine having to beg Microsoft to fix their shit vs just fixing the code yourself
SCOTUS Says Domestic Spying Is Too Secret to Be Challenged in Court -
Can someone tell me what encoding these passwords are using?18beysvg2Q==18beysvg2YOdoag=lYeZnNrkzrbU0A==
Imagine making a database table specifically for logging 'idiots' 💀
2023-02-25 22:52:18 Old code had boiler plate to prevent vulnerability, new code removed boiler plate because bloat and everything went tits up
Thanks to all who joined us yesterday for our casual chat session
Surprise Q&A Live stream eta 5min
Congrats to (¯´•._.• 乇Ѷ𝐈ㄥ •._.•´¯) for cracking today's inspirational quote
Hint: The password is in rockyou 💀
You guys asked for harder 🤷‍♂ I did also make sure it was doable
I made a very special daily quote for you guys today, but unfortunately I forgot the archive's password. Maybe with enough determination you could break into it? 🤷‍♂️
I'm not telling you guys how to decode that. If you're not a skid, you'll instantly recognize it anyway ❤️
Imagine hosting a website and they shut down your website because it's being DDOSed 💀
2023-02-19 02:10:38
I'd like to vouch for @ziyaettin753 and got them to test the power against a personal vps to see how it'd react... it was so powerful my hosting provider temporarily shut down my VPS
Don't you fuckers hate on me, it makes me a lot of money okay?? 😤You just need to have flexible morals that's all
I may or may not have worked for them previously before the CIA recruited me to hack human rights activists
If anyone has programming skills and wants to make a bit of cash on the side 💰 ^
February 14th, United States Republican Congressman Clay Higgins tweeted that he is working on passing legislation that allows life imprisonment, without the possibility of parole, for cyber criminals.He also makes a snarky remark about ... weight?
‘I will show you how safe Telegram is’ -
The CIA's favorite beverage 😍
100 FREE Carwash coupons for ~60 different locations. Credit to
Classic case of, fuck around and find out
How accurate is this?
Breaking news: Ransomware is now targeting "smart washing machines"
Reddit was breached February 5th - the threat actors were able to exfiltrate internal documents and source code. Reddit confirmed the attack was conducted via a spear-phish.Reddit is currently doing an AMA regarding the incident:
The S in IOT stands for security.
if anyone is using nexo or advcash - cashout fast Crypto Savings are shutting down. Please withdraw all assets ASAP.Giovanni,Unfortunately, in the current regulatory climate the service provider behind our Crypto Savings wallets is no longer able to offer their products on outside platforms like ours.Crypto Savings wallets in Advcash are shutting down as a result.Withdraw all assets from your Crypto Savings wallets by February 11th, 2023.Make sure you do not have any assets in any of your Crypto Savings wallets by evening of Feb 10th, 2023.You can:1. Send assets to your own crypto wallet or to your account on a crypto exchange that you trust2. Withdraw assets with conversion to fiat by choosing ‘To ADV wallet’ during withdrawalSee the Withdrawal page in Crypto Savings for details.Important: for your convenience, the Withdraw button will now send max possible amount regardless of the amount entered.If your amount is below the withdrawal limit, you can deposit enough to reach the limit and then withdraw the total amount.Please get in touch with our operators if you need any help.Check all information carefully and make sure your details are correct including destination wallet address, coin type etc.We sincerely apologize for these complications. The stability of Advcash and the availability of other features are not affected.Advcash has a lot ahead in the roadmap, and we will keep working hard to give you industry’s best products and services.Thank you for understanding.Advcash customer
Episode n++ of don't be this person.
Bitcoin maxis have a secret love for Monero and that's a good thing. Bitcoin maxis and Monero extremists need to work together to eliminate all shitcoins. Atomic swap adoption with BTC <> XMR changes the game.
Episode n+=1 of don't be this person.
Stop with the hotdog emojis, thanks.
Episode ??? of don't be this person.
2023-02-06 22:35:45 GPL Violations with a Side of DRM - discord is as follows if you wish to make a legal complaint: with this kind of event, sharing this is always appreciated as it helps the little guys (open source developers) fight back
Hey friends, I want to keep this channel growing and enjoyable for you all. Feedback would be appreciated 🍻
I feel bad for whoever's government this is considering what they're likely gonna do with this access.Source: Redacted
Forward that post above to all of your channels, please. Continued backlash is the only way to stop stupid shit like this from being implemented. Once they implemented that, there is no going back.
Stop the proposal on mass surveillance of the EU -
Thanks for the help guys, I was trying to find a person running a telegram bot
Got this info
Can anyone get any information about this telegram chat id?
Financial opsec tutorial:- Do jobs for monero- Keep them in a secure wallet - Buy gift cards (prepaid visa) from cakewallet or coincards and use them for your irl payments and purchasesDoing this allows for true financial freedom and anonymity
Telegram unveiled a new feature that will automatically censor your password! Here's mine: ****Go ahead and try this cool trick in the comments!
Alright well I don't need these personally but I know some of yall will make use of them. | | NICK48
Fucking feds are trying to poison me
Though Gaggle’s software is generally limited to monitoring school-issued accounts, including those by Google and Microsoft, the company recently acknowledged it can scan through photos on students’ personal cell phones if they plug them into district laptops.
Just a tip for those tryna get ripped
TSA NOFLY List went public.
Friendly reminder:Never ever leave #satellite panels without authentications
Appliance makers sad that 50% of customers won’t connect smart appliances
2023-01-26 08:17:21
Update, Yandex done goofed. Multiple hardcoded passwords, and we are just scratching the surface.
Yandex GIT Source tree got leaked!magnet:?xt=urn:btih:7e0ac90b489baee8a823381792ec67d465488fef&dn=yandexarc&
IPinside: (South) Korea’s Mandatory Spyware -
Microsoft has announced it intends on modernizing Windows ExplorerThis is a preview image that has been released.
I'm a VIM user. Mainly because I haven't figured out how to exit yet.
Part 2 of, don't be this person.
UK proposal to criminalize “sophisticated encrypted communication devices” -
Lesson of the day, don't be this person.
Due to the absurd volume of people DMing me - we have re-opened the chatroom. We are in search of moderators who will actively monitor chatroom and nuke nerds who disobey the rules.Here, have your dumb chatroom back, please stop asking us about it:
I thought only my official account @The_Archivist_01 could do that 🤔
Credit to
If you bank with BoA check your balance this morning. Accounts are negative due to thousands of dollars in Zelle transfers suddenly vanishing overnight. Calling customer service goes nowhere, just dead air. Many other customers reporting the same problem:
Fuck y'all and here is your voice reveal.
The Archivist irl ^
Paying $100 xmr to whoever can crack the speedify app for android. Dm @The_Archivist_01
We are publishing phone forensics software and documentation from the Israeli company Cellebrite and from its Swedish competitor, MSAB. These companies sell their tools to police and governments around the world. Cellebrite and MSAB’s tools are typically…
Image leaving your password (hash?) exposed on your production site:
We are publishing phone forensics software and documentation from the Israeli company Cellebrite and from its Swedish competitor, MSAB.These companies sell their tools to police and governments around the world. Cellebrite and MSAB’s tools are typically used to collect information from smartphones.The leak includes actual software as well as documentation.The tools have been used against journalists, activists, & dissidents across the globe.Cellebrite magnet link: magnet:?xt=urn:btih:f881291ab69fff48393ede2e36a4f8fcb4b5bf7a&dn=cellebrite& download link:magnet:?xt=urn:btih:0e7d11a34f71887aca3a388795e0b019cca44858&dn=msab.tar.zst&
Archivist's OpSec Tip #536Pick out your autopsy doctor before you die so they can't be forced to rule it as a suicide.
Imagine being a talented actor but being canceled because you're white or a dude 🤓
2023-01-12 19:32:15
Viewership for the golden globe awards are down again 26% since their last show in 2021. They also had canceled their 2022 show due to a "lack of diversity" 🤡
Breaking news:Pedophile hackers sim swapped a TikTok'ers boyfriend to acquire her nudes. (She is like 15)
For example just set the sign_id to "example && sudo run_backdoor_cmd"
This IoT company basically had a hard coded backdoor in all of their devices shown above
Taking over a Dead IoT Company -
1.3k subs with 6 views in 12 hours. Legit?
Fun little thing for those football enthusiasts out there. This is actually a leak lol.
Fucked up minecraft server, feel free to blow it all up. (1.19.2)
do your magic 😜
2023-01-06 00:52:20 (1.19.3)
Which one of you fuckers made this
Their honest reaction
Thanks for the help
One of them LGBT guys
Guys troll these guys twitch. Theyre coping VERY hard.
They changed games...
Any publicly available exploits for nginx 1.22.0?
Just vouching for Ziyaettin as they have always been reliable and quick 🍻
2023-01-03 22:20:01 😔
How does one download a build from Jenkins? Can't find shit atm
Huh, there are some people at my front door for a welfare check. That's so kind of them 🥰
If yall don't like the schizoposting just leave a thumbs down and I'll cool it 😎
All the glowies in my Telegram dm's ^
148k git repo's on exposed gitlab instances
You know what to look for in these repo's
4.6K Valid gitlab url's with guaranteed repos.I was gonna process this myself but its too much to store and upload.
Shoutout to my brotha and his channel. Great content and deserves more members. @DontProprietaryReborn
2022-12-24 10:23:49
2022-12-24 10:23:24
Shoutout to my brotha and his channel. Great content and deserves more members.@DontProprietaryReborn
config = { # global configuration 'slack_token': 'xoxp-983593023204-1052550053683-1060113903860-7052e436602a50e35d477eb23a215866', # Slack API token 'workspace_id': 'TUXHF0P60' # Slack workspace id}
They dropped this in my bashrc echo You have been pwned by Nexus Inc.
2022-12-24 03:29:49
One of my vps's got hacked by someone called 'Nexus Inc'. Can someone give me intel on them please?
Consider this your 2k member reward 😉 ...oh and also, Merry Christmas in advance
2022-12-23 12:25:47
~22k Files - 400Mb - Qantas source code leakCollab with @savethekiddes
Master password for all OSINT_without_borders archives
This, but without the anime chick
I got the one with plaintext passwords and found that the target doesnt even make a decent pass
2022-12-20 23:19:57
I no-longer need the databases. Thanks to all who offered to assist
paying $10 xmr per
If anyone can get theirs hand on the 'Daily Quiz' leak please DM me
Consider all this, your collective Christmas present 🎁
2022-12-16 05:37:02 is a store that sells phones, good luck.
Guys I have another website, the catch is I need to find a login panel for the site. So can yall promise not to DDOS it if I share
If you can find a working admin panel where we can use that admin login, we can get all get dinner for everyone in Singapore
Random active supermarket checkout vnc:
Random industrial vnc:
Cutting that stuff out makes you feel like you have a lot more free time in your day to day life :)
2022-12-09 10:17:41
Focus on what really matters in life and ignore the things that give you those short dopamine hits like tiktok etc.
I may be occupied irl but stay safe out there yall
Where do you fit in?
NSA - The only government agency that really listens. 🥰
The Archivists Domain pinned «I apologize for the wait friends, I was trying to find a VPS that actually had enough storage to seed that big database collection torrent. Anyways without further ado, here you go. Leak of database dumps from seller website (13/11/22) 7,651 Deduplicated…»
This is their twitch FYI
Joins this discord server. The guys is in stream and vc, go help troll him please., do whatever :)
Torrent file uploaded to our Matrix!
I apologize for the wait friends, I was trying to find a VPS that actually had enough storage to seed that big database collection torrent. Anyways without further ado, here you go.Leak of database dumps from seller website (13/11/22) 7,651 Deduplicated Databases total 5.9Gb Compressed 17.6Gb Uncompressed ~The Archivist
2022-11-07 08:53:29 their MC server and troll em :)
Why do people buy things they don't need with money they don't have to impress people they don't like?
Okay imma need something to read out then
DDOS these mf's lmao
Also I'm feeling a bit nauseous so I might not be able to be very active today sorry
Since you guys were so interested I went back to the university and found this in the same dumpster contained within a really heavy container. Anyone know what it is?
Found this behind my university in a dumpster, anyone knows what it is?
To celebrate hitting 1.8k I will be uploading a compilation of 12 thousand different breaches bundled together.Remember, if you haven't already remember to join our matrix channel as it will be where all future uploads happen.
Cracked logins dumped on
