hackerfantastic.crypto's Avatar

hackerfantastic.crypto

@hackerfantastic

Co-Founder https://hacker.house cyber security assurance & hacker training ~ ISBN9781119561453 ~ a book on professional hacking. Contact for competitive quotes on cyber security projects.

1,122
Followers
1
Following
41
Posts
08.06.2023
Joined
Posts Following

Latest posts by hackerfantastic.crypto @hackerfantastic

Multiple Unreal Engine (core.dll) URI Handler Arbitrary Command Injection Vulnerabilities github.com/hackerhouse-...

18.02.2026 17:28 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

Unreal Tournament (2004/1999) Multiple Vulnerabilities in Uri and Argument Handlers result in Arbitrary Code Execution [0day] - hacker.house/services - Patches are being made available. Advisory on HH github.

18.02.2026 15:32 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
GitHub - hackerhouse-opensource/MoneroMiner: A high-performance Monero (XMR) mining implementation in C++ using the RandomX algorithm. This miner is optimized for modern CPUs and provides efficient mi... A high-performance Monero (XMR) mining implementation in C++ using the RandomX algorithm. This miner is optimized for modern CPUs and provides efficient mining capabilities with a simple command-li...

MoneroMiner - A lightweight, high-performance Monero (XMR) CPU miner using the RandomX proof-of-work algorithm. Designed for maximum efficiency and cross-platform compatibility. github.com/hackerhouse-...

22.01.2026 21:50 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

bitchat-esp32: A minimal implementation of bitchat for use on ESP32-C6 based devices. github.com/hackerhouse-...

22.01.2026 21:49 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

Not enough focus was put on this malware, it has the potential to disrupt energy networks in every country except Africa.

08.01.2026 13:45 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
β€˜I Was a Weird Kid’: Jailhouse Confessions of a Teen Hacker Noah Urban’s role in the notorious Scattered Spider gang was talking people into unwittingly giving criminals access to sensitive computer systems.

For more than a year I’ve spoken with Scattered Spider β€œcaller” Noah Urban from a Florida jail. I wanted to know how they chose victims, their methods and how Noah became entangled in a virtually and physically violent world.

We’re publishing his story today: www.bloomberg.com/news/feature...

19.09.2025 11:46 πŸ‘ 36 πŸ” 17 πŸ’¬ 3 πŸ“Œ 3
Preview
US sanctions firm linked to cyber scams behind $200 million in losses The U.S. Treasury Department has sanctioned Funnull Technology, a Philippines-based company that supports hundreds of thousands of malicious websites behind cyber scams linked to over $200 million in losses for Americans.

The U.S. Treasury Department has sanctioned Funnull Technology, a Philippines-based company that supports hundreds of thousands of malicious websites behind cyber scams linked to over $200 million in losses for Americans.

29.05.2025 11:42 πŸ‘ 8 πŸ” 5 πŸ’¬ 0 πŸ“Œ 0

looks like an airplane banner that got loose.

29.05.2025 16:06 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Video thumbnail

Exploiting MS-TNAP, 1-click, no prompts.

05.05.2025 19:41 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Explore our detailed Telnet vulnerability research:

πŸ“Œ Guest Bypass: github.com/hackerhouse-...

πŸ“Œ Mutual Auth: github.com/hackerhouse-...

πŸ“Œ Telnet Client MS-TNAP PoC: github.com/hackerhouse-...

#HackerHouse

05.05.2025 16:51 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

We released three advisories on Microsoft Telnet Server & Client, targeting MS-TNAP vulnerabilities.

1️⃣ Guest Restriction Bypass (CVSS 7.5)

2️⃣ MS-TNAP Mutual Auth Protocol Issue: Non-exploitable config/protocol issue.

3️⃣ Telnet Client PoC: Exposes MS-TNAP risks e.g. phishing.

#Cybersecurity

05.05.2025 16:51 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Video thumbnail

Microsoft Telnet Client MS-TNAP Server-Side Authentication Token Exploit github.com/hackerhouse-...

05.05.2025 16:41 πŸ‘ 2 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0

Not every bug can be a vulnerability and not every vulnerability can be exploited, the MS-TNAP issue I describe exists within the protocol for Telnet authentication using NTLM and partially in the Telnet Server code, but was not fully implemented by Microsoft. PoC's are available for both issues.

30.04.2025 20:17 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Hacker House exposes flaws in Microsoft Telnet Server! Two advisories reveal a high-severity Guest Access Bypass (CVSS 7.5) in MS-TNAP, risking unauthorized access on Windows 2000 to Server 2008 R2, and an unexploitable NTLM mutual auth issue github.com/hackerhouse-... & github.com/hackerhouse-...

30.04.2025 20:17 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image
28.04.2025 22:40 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Interesting that the cyberbeat journalists wrote multiple news articles about a fake exploit of this recent bug. It's fine though, I almost fell for this AI generated crap too, just like the fake TaskScheduler UAC Bypass you all wrote about. ;-) cyberdom.blog/abusing-the-...

24.04.2025 15:06 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

have you tried turning it off and on again?

24.04.2025 15:02 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

"MSRC didn’t consider a single report as a vulnerability." - is something I agree with, you need the Administrator password to leverage this and whilst Task Scheduler is awesome and tons of fun - you need some kind of boundary violation for this to be an issue. "I have the password" is not one.

22.04.2025 15:47 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

It reads to me as a surface-level analysis of the Task Scheduler implementation with the remarkable realization that "Task Scheduler can run Tasks as other users!" 🫒 - I enjoyed the write up but this is a very misleading post.

22.04.2025 15:43 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
Task Scheduler– New Vulnerabilities for schtasks.exe UAC bypass, metadata poisoning, and log overflow vulnerabilities in Windows Task Scheduler reveal new tactics for defense evasion and privilege escalation

I found this article interesting, but it isn't technically a UAC bypass - if you have the Administrator username and password, you can authenticate to the host via TaskScheduler by design. The other vulnerabilities were also not really of any value to an attacker. cymulate.com/blog/task-sc...

22.04.2025 15:42 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
DHS Secretary Noem’s purse stolen at Easter dinner with family in D.C. The theft occurred as Homeland Security Secretary Kristi L. Noem dined with her extended family at the Capital Burger on Seventh Street NW, people familiar with the incident said.

Department of Homeland Security Secretary Kristi L. Noem’s purse was stolen from a downtown Washington restaurant Sunday night, with her passport, DHS badge and about $3,000 cash inside, the department confirmed Monday.

21.04.2025 23:58 πŸ‘ 713 πŸ” 122 πŸ’¬ 351 πŸ“Œ 73

I was conversing, you unthreaded my comment which is just sad to see.

22.04.2025 14:51 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I often discuss in my talks about how political bias influences and shapes the technology we build and use. The "underground" of computing technology has typically been right of center which is where many interesting protocols have come from. Internet is healing and people are free to speak again.

22.04.2025 14:46 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Political-bias on BlueSky is largely left-leaning, it's a comment that "verification" is just an extension of those political biases on display where those who ascribe to particularly agendas and ideologies leverage institutions and systems as power in the society.

22.04.2025 14:44 πŸ‘ 0 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0
Post image Post image

This morning Minnesota Republicans introduced a bill banning mRNA vaccines and labeling them "weapons of mass destruction." It would make manufacturing, possessing or administering them a crime punishable by up to 20 years in prison. www.revisor.mn.gov/bills/bill.p...

21.04.2025 20:01 πŸ‘ 981 πŸ” 453 πŸ’¬ 148 πŸ“Œ 298

Those who ascribe to extreme-left "woke" ideology.

22.04.2025 14:12 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

The woke do love assigning themselves perceived authority over others.

22.04.2025 14:04 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
facedancer/examples/camera.py at rawgadget2 Β· zhuowei/facedancer Fork of https://github.com/xairy/Facedancer/tree/rawgadget with patches for testing CVE-2024-53197 - zhuowei/facedancer

Zhuowei Zhang released POC code for CVE-2024-53104, a zero-day used by Cellebrite to unlock Android devices

-patched in February
-used by Serbian law enforcement to unlock the phones of anti-government protesters and journalists

github.com/zhuowei/face...

22.04.2025 11:20 πŸ‘ 10 πŸ” 6 πŸ’¬ 0 πŸ“Œ 0
Post image

Mikrotik "opensesame" SNMP backdoor. Tutorial on how to create a backdoor modelled on EXTRABACON that resets the admin password using a UDP packet (SNMPset) as a post-exploitation technique. github.com/hackerhouse-...

17.04.2025 19:55 πŸ‘ 3 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0