home.social

#hashpwn — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #hashpwn, aggregated by home.social.

fetched live
  1. pcfg-go v0.5.3 has been released.

    This release focuses heavily on pcfg_guesser performance and memory efficiency:

    • half the memory usage of v0.5.2
    • 2x faster than v0.5.2
    • 2,578% faster than the original Python3 pcfg_guesser.py

    Twice the speed with half the memory usage? Nice.

    forum.hashpwn.net/post/11277

    #pcfg #wordlist #generator #hashcracking #golang #hashpwn

  2. pcfg-go v0.5.3 has been released.

    This release focuses heavily on pcfg_guesser performance and memory efficiency:

    • half the memory usage of v0.5.2
    • 2x faster than v0.5.2
    • 2,578% faster than the original Python3 pcfg_guesser.py

    Twice the speed with half the memory usage? Nice.

    forum.hashpwn.net/post/11277

    #pcfg #wordlist #generator #hashcracking #golang #hashpwn

  3. pcfg-go v0.5.3 has been released.

    This release focuses heavily on pcfg_guesser performance and memory efficiency:

    • half the memory usage of v0.5.2
    • 2x faster than v0.5.2
    • 2,578% faster than the original Python3 pcfg_guesser.py

    Twice the speed with half the memory usage? Nice.

    forum.hashpwn.net/post/11277

    #pcfg #wordlist #generator #hashcracking #golang #hashpwn

  4. pcfg-go v0.5.3 has been released.

    This release focuses heavily on pcfg_guesser performance and memory efficiency:

    • half the memory usage of v0.5.2
    • 2x faster than v0.5.2
    • 2,578% faster than the original Python3 pcfg_guesser.py

    Twice the speed with half the memory usage? Nice.

    forum.hashpwn.net/post/14910

    #pcfg #wordlist #generator #hashcracking #golang #hashpwn

  5. pcfg-go v0.5.3 has been released.

    This release focuses heavily on pcfg_guesser performance and memory efficiency:

    • half the memory usage of v0.5.2
    • 2x faster than v0.5.2
    • 2,578% faster than the original Python3 pcfg_guesser.py

    Twice the speed with half the memory usage? Nice.

    forum.hashpwn.net/post/11277

    #pcfg #wordlist #generator #hashcracking #golang #hashpwn

  6. FortiBleed: The ongoing Fortinet / FortiGate compromise campaign

    Fortinet edge devices are being targeted in a large-scale compromise campaign involving exposed management interfaces, FortiCloud SSO abuse, credential theft, brute forcing, config exports, and suspicious admin account creation.

    This should be treated as a compromise-assessment event, not just a normal patch cycle.

    Admins should patch FortiOS, review all local admin accounts, rotate credentials and shared secrets, check for config exports, enforce MFA, and restrict management access to trusted IPs or VPN-only access.

    Full details:
    forum.hashpwn.net/post/14105

    #fortinet #fortigate #fortibleed #fortios #forticloud #cybersecurity #vpn #hashpwn

  7. FortiBleed: The ongoing Fortinet / FortiGate compromise campaign

    Fortinet edge devices are being targeted in a large-scale compromise campaign involving exposed management interfaces, FortiCloud SSO abuse, credential theft, brute forcing, config exports, and suspicious admin account creation.

    This should be treated as a compromise-assessment event, not just a normal patch cycle.

    Admins should patch FortiOS, review all local admin accounts, rotate credentials and shared secrets, check for config exports, enforce MFA, and restrict management access to trusted IPs or VPN-only access.

    Full details:
    forum.hashpwn.net/post/14105

    #fortinet #fortigate #fortibleed #fortios #forticloud #cybersecurity #vpn #hashpwn

  8. FortiBleed: The ongoing Fortinet / FortiGate compromise campaign

    Fortinet edge devices are being targeted in a large-scale compromise campaign involving exposed management interfaces, FortiCloud SSO abuse, credential theft, brute forcing, config exports, and suspicious admin account creation.

    This should be treated as a compromise-assessment event, not just a normal patch cycle.

    Admins should patch FortiOS, review all local admin accounts, rotate credentials and shared secrets, check for config exports, enforce MFA, and restrict management access to trusted IPs or VPN-only access.

    Full details:
    forum.hashpwn.net/post/14105

    #fortinet #fortigate #fortibleed #fortios #forticloud #cybersecurity #vpn #hashpwn

  9. FortiBleed: The ongoing Fortinet / FortiGate compromise campaign

    Fortinet edge devices are being targeted in a large-scale compromise campaign involving exposed management interfaces, FortiCloud SSO abuse, credential theft, brute forcing, config exports, and suspicious admin account creation.

    This should be treated as a compromise-assessment event, not just a normal patch cycle.

    Admins should patch FortiOS, review all local admin accounts, rotate credentials and shared secrets, check for config exports, enforce MFA, and restrict management access to trusted IPs or VPN-only access.

    Full details:
    forum.hashpwn.net/post/14105

    #fortinet #fortigate #fortibleed #fortios #forticloud #cybersecurity #vpn #hashpwn

  10. NOCIX is currently experiencing an ongoing service-impacting outage affecting customer-hosted servers, with some users also reporting issues accessing the customer portal.

    No official root cause has been confirmed by NOCIX, but Reddit users are stating this is a power outage. This should be treated as unverified until NOCIX publishes an incident notice.

    More info:
    forum.hashpwn.net/post/13533

    #NOCIX #Hosting #DataCenter #Outage #SysAdmin #InfoSec #hashpwn

  11. NOCIX is currently experiencing an ongoing service-impacting outage affecting customer-hosted servers, with some users also reporting issues accessing the customer portal.

    No official root cause has been confirmed by NOCIX, but Reddit users are stating this is a power outage. This should be treated as unverified until NOCIX publishes an incident notice.

    More info:
    forum.hashpwn.net/post/13533

    #NOCIX #Hosting #DataCenter #Outage #SysAdmin #InfoSec #hashpwn

  12. NOCIX is currently experiencing an ongoing service-impacting outage affecting customer-hosted servers, with some users also reporting issues accessing the customer portal.

    No official root cause has been confirmed by NOCIX, but Reddit users are stating this is a power outage. This should be treated as unverified until NOCIX publishes an incident notice.

    More info:
    forum.hashpwn.net/post/13533

    #NOCIX #Hosting #DataCenter #Outage #SysAdmin #InfoSec #hashpwn

  13. NOCIX is currently experiencing an ongoing service-impacting outage affecting customer-hosted servers, with some users also reporting issues accessing the customer portal.

    No official root cause has been confirmed by NOCIX, but Reddit users are stating this is a power outage. This should be treated as unverified until NOCIX publishes an incident notice.

    More info:
    forum.hashpwn.net/post/13533

    #NOCIX #Hosting #DataCenter #Outage #SysAdmin #InfoSec #hashpwn

  14. YellowKey: BitLocker Bypass or Backdoor

    YellowKey, tracked as CVE-2026-45585, is a public BitLocker bypass that abuses WinRE/recovery-path behavior to expose a protected volume without the Windows password, recovery key, or AES cracking.

    At the time of this post, the author’s GitHub and original YellowKey repo appear to be down.

    Read more: forum.hashpwn.net/post/13339

    #BitLocker #YellowKey #CVE202645585 #CyberSecurity #InfoSec #WindowsSecurity #TPM #FullDiskEncryption #hack #exploit #news #hashpwn

  15. YellowKey: BitLocker Bypass or Backdoor

    YellowKey, tracked as CVE-2026-45585, is a public BitLocker bypass that abuses WinRE/recovery-path behavior to expose a protected volume without the Windows password, recovery key, or AES cracking.

    At the time of this post, the author’s GitHub and original YellowKey repo appear to be down.

    Read more: forum.hashpwn.net/post/13339

    #BitLocker #YellowKey #CVE202645585 #CyberSecurity #InfoSec #WindowsSecurity #TPM #FullDiskEncryption #hack #exploit #news #hashpwn

  16. YellowKey: BitLocker Bypass or Backdoor

    YellowKey, tracked as CVE-2026-45585, is a public BitLocker bypass that abuses WinRE/recovery-path behavior to expose a protected volume without the Windows password, recovery key, or AES cracking.

    At the time of this post, the author’s GitHub and original YellowKey repo appear to be down.

    Read more: forum.hashpwn.net/post/13339

    #BitLocker #YellowKey #CVE202645585 #CyberSecurity #InfoSec #WindowsSecurity #TPM #FullDiskEncryption #hack #exploit #news #hashpwn

  17. YellowKey: BitLocker Bypass or Backdoor

    YellowKey, tracked as CVE-2026-45585, is a public BitLocker bypass that abuses WinRE/recovery-path behavior to expose a protected volume without the Windows password, recovery key, or AES cracking.

    At the time of this post, the author’s GitHub and original YellowKey repo appear to be down.

    Read more: forum.hashpwn.net/post/13339

    #BitLocker #YellowKey #CVE202645585 #CyberSecurity #InfoSec #WindowsSecurity #TPM #FullDiskEncryption #hack #exploit #news #hashpwn

  18. Spider v1.0.0 released.

    Spider is not just another web crawler -- it is a purpose-built wordlist and ngram processor for hash cracking workflows.

    URL Mode:
    Point it at a URL and Spider crawls the target, extracts words, and generates frequency-sorted wordlists and/or ngrams.

    But, Spider does not stop at web crawling...

    File Mode:
    Feed it local files and it brings the same word-processing engine to your own datasets, scraped content, notes, dumps, configs, or any other plaintext source you want to turn into a targeted wordlist or ngram set.

    More info:
    forum.hashpwn.net/post/52

    #spider #webcrawler #wordlist #generator #sort #ngram #cyclone #hashpwn #hashcracking

  19. Spider v1.0.0 released.

    Spider is not just another web crawler -- it is a purpose-built wordlist and ngram processor for hash cracking workflows.

    URL Mode:
    Point it at a URL and Spider crawls the target, extracts words, and generates frequency-sorted wordlists and/or ngrams.

    But, Spider does not stop at web crawling...

    File Mode:
    Feed it local files and it brings the same word-processing engine to your own datasets, scraped content, notes, dumps, configs, or any other plaintext source you want to turn into a targeted wordlist or ngram set.

    More info:
    forum.hashpwn.net/post/52

    #spider #webcrawler #wordlist #generator #sort #ngram #cyclone #hashpwn #hashcracking

  20. Spider v1.0.0 released.

    Spider is not just another web crawler -- it is a purpose-built wordlist and ngram processor for hash cracking workflows.

    URL Mode:
    Point it at a URL and Spider crawls the target, extracts words, and generates frequency-sorted wordlists and/or ngrams.

    But, Spider does not stop at web crawling...

    File Mode:
    Feed it local files and it brings the same word-processing engine to your own datasets, scraped content, notes, dumps, configs, or any other plaintext source you want to turn into a targeted wordlist or ngram set.

    More info:
    forum.hashpwn.net/post/52

    #spider #webcrawler #wordlist #generator #sort #ngram #cyclone #hashpwn #hashcracking

  21. Spider v1.0.0 released.

    Spider is not just another web crawler -- it is a purpose-built wordlist and ngram processor for hash cracking workflows.

    URL Mode:
    Point it at a URL and Spider crawls the target, extracts words, and generates frequency-sorted wordlists and/or ngrams.

    But, Spider does not stop at web crawling...

    File Mode:
    Feed it local files and it brings the same word-processing engine to your own datasets, scraped content, notes, dumps, configs, or any other plaintext source you want to turn into a targeted wordlist or ngram set.

    More info:
    forum.hashpwn.net/post/52

    #spider #webcrawler #wordlist #generator #sort #ngram #cyclone #hashpwn #hashcracking

  22. Spider v1.0.0 released.

    Spider is not just another web crawler -- it is a purpose-built wordlist and ngram processor for hash cracking workflows.

    URL Mode:
    Point it at a URL and Spider crawls the target, extracts words, and generates frequency-sorted wordlists and/or ngrams.

    But, Spider does not stop at web crawling...

    File Mode:
    Feed it local files and it brings the same word-processing engine to your own datasets, scraped content, notes, dumps, configs, or any other plaintext source you want to turn into a targeted wordlist or ngram set.

    More info:
    forum.hashpwn.net/post/52

    #spider #webcrawler #wordlist #generator #sort #ngram #cyclone #hashpwn #hashcracking

  23. Copy Fail (CVE-2026-31431) is a Linux kernel LPE that gives root access on every major linux distro.

    All that is needed is local shell access and a few lines of python.

    forum.hashpwn.net/post/12727

    #cybersecurity #copyfail #linux #exploit #cve202631431 #hashpwn

  24. Copy Fail (CVE-2026-31431) is a Linux kernel LPE that gives root access on every major linux distro.

    All that is needed is local shell access and a few lines of python.

    forum.hashpwn.net/post/12727

    #cybersecurity #copyfail #linux #exploit #cve202631431 #hashpwn

  25. Copy Fail (CVE-2026-31431) is a Linux kernel LPE that gives root access on every major linux distro.

    All that is needed is local shell access and a few lines of python.

    forum.hashpwn.net/post/12727

    #cybersecurity #copyfail #linux #exploit #cve202631431 #hashpwn

  26. Copy Fail (CVE-2026-31431) is a Linux kernel LPE that gives root access on every major linux distro.

    All that is needed is local shell access and a few lines of python.

    forum.hashpwn.net/post/12727

    #cybersecurity #copyfail #linux #exploit #cve202631431 #hashpwn

  27. Copy Fail (CVE-2026-31431) is a Linux kernel LPE that gives root access on every major linux distro.

    All that is needed is local shell access and a few lines of python.

    forum.hashpwn.net/post/12727

    #cybersecurity #copyfail #linux #exploit #cve202631431 #hashpwn

  28. Released: hashgen v1.3.0

    New in this version:

    * HMAC modes
    * PBKDF2 modes
    * scrypt support
    * additional BLAKE2 modes
    * hashcat UTF-16LE modes
    * optimized salt RNG on salted hashes
    * 95+ supported hash modes

    forum.hashpwn.net/post/89

    #hashgen #hashgenerator #hashcracking #hashpwn #golang

  29. Released: hashgen v1.3.0

    New in this version:

    * HMAC modes
    * PBKDF2 modes
    * scrypt support
    * additional BLAKE2 modes
    * hashcat UTF-16LE modes
    * optimized salt RNG on salted hashes
    * 95+ supported hash modes

    forum.hashpwn.net/post/89

    #hashgen #hashgenerator #hashcracking #hashpwn #golang

  30. Released: hashgen v1.3.0

    New in this version:

    * HMAC modes
    * PBKDF2 modes
    * scrypt support
    * additional BLAKE2 modes
    * hashcat UTF-16LE modes
    * optimized salt RNG on salted hashes
    * 95+ supported hash modes

    forum.hashpwn.net/post/89

    #hashgen #hashgenerator #hashcracking #hashpwn #golang

  31. Released: hashgen v1.3.0

    New in this version:

    * HMAC modes
    * PBKDF2 modes
    * scrypt support
    * additional BLAKE2 modes
    * hashcat UTF-16LE modes
    * optimized salt RNG on salted hashes
    * 95+ supported hash modes

    forum.hashpwn.net/post/89

    #hashgen #hashgenerator #hashcracking #hashpwn #golang

  32. Released pcfg-go — a full Go rewrite of pcfg_cracker with ~3× faster training, ~40× faster guessing, $HEX[] and multi-byte support, improved trainer parsing...

    Full Details: forum.hashpwn.net/post/11277

    #pcfg #hashcracking #trainer #guesser #wordlist #generator #hashcat #hashpwn

  33. Released pcfg-go — a full Go rewrite of pcfg_cracker with ~3× faster training, ~40× faster guessing, $HEX[] and multi-byte support, improved trainer parsing...

    Full Details: forum.hashpwn.net/post/11277

    #pcfg #hashcracking #trainer #guesser #wordlist #generator #hashcat #hashpwn

  34. Released pcfg-go — a full Go rewrite of pcfg_cracker with ~3× faster training, ~40× faster guessing, $HEX[] and multi-byte support, improved trainer parsing...

    Full Details: forum.hashpwn.net/post/11277

    #pcfg #hashcracking #trainer #guesser #wordlist #generator #hashcat #hashpwn

  35. Released pcfg-go — a full Go rewrite of pcfg_cracker with ~3× faster training, ~40× faster guessing, $HEX[] and multi-byte support, improved trainer parsing...

    Full Details: forum.hashpwn.net/post/11277

    #pcfg #hashcracking #trainer #guesser #wordlist #generator #hashcat #hashpwn

  36. Released pcfg-go — a full Go rewrite of pcfg_cracker with ~3× faster training, ~40× faster guessing, $HEX[] and multi-byte support, improved trainer parsing...

    Full Details: forum.hashpwn.net/post/11277

    #pcfg #hashcracking #trainer #guesser #wordlist #generator #hashcat #hashpwn

  37. CsP’s @Waffle_Real just released a new tool called hashpipe, and it solves a problem many of us run into with large potfiles: messy, misidentified hash:password entries.

    hashpipe automatically validates founds by recomputing them, identifying the correct algorithm, and outputting verified results in an mdxfind format.

    If you maintain large cracking datasets or potfiles, this is a great way to verify and clean them up.

    Details:
    forum.hashpwn.net/post/11119

    GitHub repo:
    github.com/Cynosureprime/hashp

    #hashcracking #hashcat #jtr #hashpipe #CsP #cynosureprime #potfile #hashpwn

  38. CsP’s @Waffle_Real just released a new tool called hashpipe, and it solves a problem many of us run into with large potfiles: messy, misidentified hash:password entries.

    hashpipe automatically validates founds by recomputing them, identifying the correct algorithm, and outputting verified results in an mdxfind format.

    If you maintain large cracking datasets or potfiles, this is a great way to verify and clean them up.

    Details:
    forum.hashpwn.net/post/11119

    GitHub repo:
    github.com/Cynosureprime/hashp

    #hashcracking #hashcat #jtr #hashpipe #CsP #cynosureprime #potfile #hashpwn

  39. CsP’s @Waffle_Real just released a new tool called hashpipe, and it solves a problem many of us run into with large potfiles: messy, misidentified hash:password entries.

    hashpipe automatically validates founds by recomputing them, identifying the correct algorithm, and outputting verified results in an mdxfind format.

    If you maintain large cracking datasets or potfiles, this is a great way to verify and clean them up.

    Details:
    forum.hashpwn.net/post/11119

    GitHub repo:
    github.com/Cynosureprime/hashp

    #hashcracking #hashcat #jtr #hashpipe #CsP #cynosureprime #potfile #hashpwn

  40. CsP’s @Waffle_Real just released a new tool called hashpipe, and it solves a problem many of us run into with large potfiles: messy, misidentified hash:password entries.

    hashpipe automatically validates founds by recomputing them, identifying the correct algorithm, and outputting verified results in an mdxfind format.

    If you maintain large cracking datasets or potfiles, this is a great way to verify and clean them up.

    Details:
    forum.hashpwn.net/post/11119

    GitHub repo:
    github.com/Cynosureprime/hashp

    #hashcracking #hashcat #jtr #hashpipe #CsP #cynosureprime #potfile #hashpwn

  41. CsP’s @Waffle_Real just released a new tool called hashpipe, and it solves a problem many of us run into with large potfiles: messy, misidentified hash:password entries.

    hashpipe automatically validates founds by recomputing them, identifying the correct algorithm, and outputting verified results in an mdxfind format.

    If you maintain large cracking datasets or potfiles, this is a great way to verify and clean them up.

    Details:
    forum.hashpwn.net/post/11119

    GitHub repo:
    github.com/Cynosureprime/hashp

    #hashcracking #hashcat #jtr #hashpipe #CsP #cynosureprime #potfile #hashpwn

  42. Update: Solflare “xpass exploit" Details Released

    In Feb 2025, I reported an exploit vulnerability in the Solflare Chrome wallet which allowed the wallet vault (solflaredata) to be decrypted without the user's password.

    Turns out, this was a backdoor, not a bug.

    Today, I am releasing the full details of the xpass exploit, aka the "backdoor master key".

    forum.hashpwn.net/post/11116

    #solflare #crypto #wallet #vulnerability #exploit #backdoor #xpass #cyclone #hashpwn #news #infosec #cybersecurity