6 Aug 2026, 15:53 UTC33 views8 reactionsread 10 August 2026 Photo
XXE Injection 🚨📁
A critical XML External Entity (XXE) vulnerability was discovered in the Stock Check functionality. The application parses user-controlled XML using an insecure XML parser with external entity processing enabled. 🔧
As a result, an attacker can read arbitrary files from the server and potentially escalate the attack depending on the parser configuration. 🕵️♂️
Step 1: Identifying the XML endpoint 🎯…
⚡1❤🔥1💯1🔥1custom 52357476871139613591custom 52358499674651486131custom 52738654574414792321custom 52739685151817423681
3 Aug 2026, 17:50 UTC44 views15 reactionsread 10 August 2026 Photo
:)
I successfully passed the practical exam and received the TryHackMe PT1 certification.
In the process, I solidified key skills in ethical hacking, vulnerability analysis, and pentesting.
Moving on!
#turansecurity #tryhackme #pt1
🔥3⚡2custom 52738654574414792322❤🔥1👍1👏1💯1🤩1
29 Jul 2026, 14:59 UTC319 views10 reactionsread 10 August 2026 Photo
📧 SSTI
A Server-Side Template Injection vulnerability was discovered in the "Contact Us" form, caused by the user-supplied message field being rendered directly into a server-side template (e.g., the auto-reply/confirmation email) without proper sanitization or escaping. 🛠
Step 1: Identifying the vulnerable parameter 🔍
The Contact Us form on the /contact page accepts an email and a message field. The message field'…
⚡2🔥1🤩1😁1custom 52335670119586970781custom 52738654574414792321custom 52739685151817423681custom 53616813036682881341
24 Jul 2026, 15:39 UTC289 views14 reactionsread 10 August 2026 Photo
Arbitrary File Read Vulnerability 📁⚠️
An arbitrary file read vulnerability was discovered, caused by the lack of path validation in an endpoint that serves raw content via the ?raw?? parameter. The application does not restrict access to the project root directory, allowing system files on the server to be read directly through an HTTP request 🚫🔒.
Step 1: Identifying the vulnerable parameter 🔍
The endpoint accepts …
🔥4custom 52738654574414792322custom 52739685151817423682⚡1👏1😎1custom 52335670119586970781custom 52354781220815605351
22 Jul 2026, 02:58 UTC142 views15 reactionsread 10 August 2026 Photo
I discovered a Blind Remote Code Execution (RCE) vulnerability in Koha ILS caused by improper handling of the jobid parameter. By injecting shell metacharacters, it's possible to execute arbitrary operating system commands. 🕵️♂️💻 Since the application doesn't return command output, execution can be confirmed through DNS-based OAST interactions using Burp Collaborator. 🌐
📌 Step 1: Identify the vulnerable parameter
T…
⚡3🔥3❤1👀1👨💻1😍1🆒1custom 52335670119586970781
16 Jul 2026, 18:01 UTCviews —8 reactionsread 10 August 2026 Posted without readable text
❤1🎉1💯1🔥1custom 52335670119586970781custom 52738654574414792321custom 52739685151817423681custom 53641578977752773041
16 Jul 2026, 15:00 UTC430 views20 reactionsread 10 August 2026 File
🔥 Meet YUSCAN v1.0.0 — a console-based tool for network perimeter reconnaissance! 🛠🌐
github: https://github.com/Solihov-Y/yuscan
The tool automates all the routine work: a single target is input, and a ready-made three-column report.txt is generated as output.
• All-in-one: Combines port scanning, vulnerability/CVE scanning, and path enumeration into one fast pipeline. ⚙️
• Quiet mode: Only a neat live timer is d…
⚡5custom 53641578977752773043custom 52354781220815605352custom 52357476871139613592custom 53616813036682881342🍓1🔥1🆒1
11 Jul 2026, 05:26 UTC361 views25 reactionsread 10 August 2026 Photo
I sent a detailed report to the Koha developers, but they didn't acknowledge the issue and dismissed the vulnerability. However, the technical aspects clearly demonstrate a serious flaw in the access control logic 🛡.
Step 1: Data and login leak 🕵️♂️
A GET request to /api/v1/patrons/51—that's it, no verification whether it's your patron or someone else's 🤷♂️. The backend returns the victim's full JSON profile, wit…
🔥7⚡4🌚3❤2👨💻2🗿2👍1🤨1
7 Jul 2026, 10:21 UTC100 views19 reactionsread 10 August 2026 Forwarded from @CentiSecVideo
Not cybersecurity today...
Just respect. ❤️
Thank you, Cristiano Ronaldo.
The end of an era. The legacy lives forever. 🤍
😢8👍2🍾1🤔1🤯1😁1😎1custom 52335670119586970781
27 Jun 2026, 05:02 UTC101 views13 reactionsread 10 August 2026 Forwarded from @fr3nzy_h4ck3r5Photo
😎 Yangi darslar Turan Securityning YouTube kanalida!
Kiberxavfsizlik sohasini o‘rganishni xohlaysizmi? Endi buning uchun ajoyib imkoniyat! 💻
😎 Turan Security YouTube kanalida yangi darslar e'lon qilindi:
🛡 Information Security (InfoSec) – Axborot xavfsizligi asoslari, tahdidlar va himoyalanish usullari.
🌐 Web Pentesting – Veb-ilovalardagi zaifliklarni aniqlash, Burp Suite bilan ishlash va amaliy pentest jarayonlar…
🔥4⚡1❤🔥1🎉1👍1👨💻1custom 52335670119586970781custom 52354781220815605351
16 Jun 2026, 08:56 UTC117 views12 reactionsread 10 August 2026 Photo
🏴 Completed boroCTF 2026.
This time, I managed to place 17th in the HS Division and scored 9,400 personal points 🏆. I solved mainly problems in OSINT, Web, Forensics, Pwn, and Misc.
There were many interesting and innovative challenges 🧩, which allowed me to gain valuable practical experience. Thanks to the organizers for the competition! 🙌
🔥5⚡1🌚1🏆1👍1🤩1custom 52358065668206197551custom 52739685151817423681
8 Jun 2026, 11:12 UTC314 views17 reactionsread 10 August 2026 Photo
)
🔥5🤔2😁2❤1👍1👨💻1💯1🆒1
Showing the 12 most recent of 14 posts we hold for @solihov_blog. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked ≈ was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.