home.social

#hashpwn — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #hashpwn, aggregated by home.social.

fetched live
  1. hashgen v1.3.2 is out!

    v1.3.2 brings 37 new modes since the last published release.

    These include KoreLogic’s CMIYC 2026 $cmiyc$2026$ algo, gost-yescrypt, Streebog, LDAP SHA/SSHA, nested modes, multiple bcrypt modes, sm3crypt, the entire MD6 family, plus more.

    More info:
    forum.hashpwn.net/post/89

    #hashgen #cmicy #korelogic #gostyescrypt #streebog #ldap #ssha #bcrypt #sm3crypt #md6 #hashpwn #hash #algo

  2. pcfg-go v0.5.3 has been released.

    This release focuses heavily on pcfg_guesser performance and memory efficiency:

    • half the memory usage of v0.5.2
    • 2x faster than v0.5.2
    • 2,578% faster than the original Python3 pcfg_guesser.py

    Twice the speed with half the memory usage? Nice.

    forum.hashpwn.net/post/11277

    #pcfg #wordlist #generator #hashcracking #golang #hashpwn

  3. FortiBleed: The ongoing Fortinet / FortiGate compromise campaign

    Fortinet edge devices are being targeted in a large-scale compromise campaign involving exposed management interfaces, FortiCloud SSO abuse, credential theft, brute forcing, config exports, and suspicious admin account creation.

    This should be treated as a compromise-assessment event, not just a normal patch cycle.

    Admins should patch FortiOS, review all local admin accounts, rotate credentials and shared secrets, check for config exports, enforce MFA, and restrict management access to trusted IPs or VPN-only access.

    Full details:
    forum.hashpwn.net/post/14105

    #fortinet #fortigate #fortibleed #fortios #forticloud #cybersecurity #vpn #hashpwn

  4. NOCIX is currently experiencing an ongoing service-impacting outage affecting customer-hosted servers, with some users also reporting issues accessing the customer portal.

    No official root cause has been confirmed by NOCIX, but Reddit users are stating this is a power outage. This should be treated as unverified until NOCIX publishes an incident notice.

    More info:
    forum.hashpwn.net/post/13533

    #NOCIX #Hosting #DataCenter #Outage #SysAdmin #InfoSec #hashpwn

  5. YellowKey: BitLocker Bypass or Backdoor

    YellowKey, tracked as CVE-2026-45585, is a public BitLocker bypass that abuses WinRE/recovery-path behavior to expose a protected volume without the Windows password, recovery key, or AES cracking.

    At the time of this post, the author’s GitHub and original YellowKey repo appear to be down.

    Read more: forum.hashpwn.net/post/13339

    #BitLocker #YellowKey #CVE202645585 #CyberSecurity #InfoSec #WindowsSecurity #TPM #FullDiskEncryption #hack #exploit #news #hashpwn

  6. Spider v1.0.0 released.

    Spider is not just another web crawler -- it is a purpose-built wordlist and ngram processor for hash cracking workflows.

    URL Mode:
    Point it at a URL and Spider crawls the target, extracts words, and generates frequency-sorted wordlists and/or ngrams.

    But, Spider does not stop at web crawling...

    File Mode:
    Feed it local files and it brings the same word-processing engine to your own datasets, scraped content, notes, dumps, configs, or any other plaintext source you want to turn into a targeted wordlist or ngram set.

    More info:
    forum.hashpwn.net/post/52

    #spider #webcrawler #wordlist #generator #sort #ngram #cyclone #hashpwn #hashcracking

  7. Copy Fail (CVE-2026-31431) is a Linux kernel LPE that gives root access on every major linux distro.

    All that is needed is local shell access and a few lines of python.

    forum.hashpwn.net/post/12727

    #cybersecurity #copyfail #linux #exploit #cve202631431 #hashpwn

  8. Released: hashgen v1.3.0

    New in this version:

    * HMAC modes
    * PBKDF2 modes
    * scrypt support
    * additional BLAKE2 modes
    * hashcat UTF-16LE modes
    * optimized salt RNG on salted hashes
    * 95+ supported hash modes

    forum.hashpwn.net/post/89

    #hashgen #hashgenerator #hashcracking #hashpwn #golang

  9. Released pcfg-go — a full Go rewrite of pcfg_cracker with ~3× faster training, ~40× faster guessing, $HEX[] and multi-byte support, improved trainer parsing...

    Full Details: forum.hashpwn.net/post/11277

    #pcfg #hashcracking #trainer #guesser #wordlist #generator #hashcat #hashpwn

  10. CsP’s @Waffle_Real just released a new tool called hashpipe, and it solves a problem many of us run into with large potfiles: messy, misidentified hash:password entries.

    hashpipe automatically validates founds by recomputing them, identifying the correct algorithm, and outputting verified results in an mdxfind format.

    If you maintain large cracking datasets or potfiles, this is a great way to verify and clean them up.

    Details:
    forum.hashpwn.net/post/11119

    GitHub repo:
    github.com/Cynosureprime/hashp

    #hashcracking #hashcat #jtr #hashpipe #CsP #cynosureprime #potfile #hashpwn

  11. Update: Solflare “xpass exploit" Details Released

    In Feb 2025, I reported an exploit vulnerability in the Solflare Chrome wallet which allowed the wallet vault (solflaredata) to be decrypted without the user's password.

    Turns out, this was a backdoor, not a bug.

    Today, I am releasing the full details of the xpass exploit, aka the "backdoor master key".

    forum.hashpwn.net/post/11116

    #solflare #crypto #wallet #vulnerability #exploit #backdoor #xpass #cyclone #hashpwn #news #infosec #cybersecurity

  12. Cisco Catalyst SD-WAN CVSS 10.0 zero-day (CVE-2026-20127) has been actively exploited, with attackers gaining admin access.

    Full technical breakdown: forum.hashpwn.net/post/10802

    #cisco #sdwan #cvss10 #cve202620127 #exploit #cybersecurity #infosec #news #hashpwn

  13. Chrome CSS Zero-Day (CVE-2026-2441)

    Google has patched a CVSS 8.8 high-severity use-after-free bug in Chrome’s CSS engine that is being exploited in the wild. This also affects all Chrome-based browsers such as Brave, Edge and Opera.

    forum.hashpwn.net/post/10273

    #google #chrome #brave #edge #opera #browser #cybersecurity #css #zeroday #cve20262441 #news #hashpwn

  14. Another successful MetaMask crypto wallet recovered. This one was on the Zen browser, so was a first for me.

    forum.hashpwn.net/post/10221

    #metamask #crypto #wallet #recovery #zen #browser #firefox #hashpwn

  15. For those who lost their Dogecoins due to the defunct Dough Wallet iPhone app, here's a tool to recover your Dogecoin address and private keys.

    forum.hashpwn.net/post/10034

    #doughwallet #recoverytool #crypto #hashpwn

  16. Windows Notepad RCE - CVE-2026-20841

    A crafted Markdown link could trigger command execution via protocol handler abuse on Windows 11 Notepad.

    forum.hashpwn.net/post/10031

    #notepad #rce #cve202620841 #cybersecurity #news #hashpwn

  17. Ivanti has disclosed two critical zero-day vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) which allow RCE, tracked as CVE-2026-1281 and CVE-2026-1340. Both flaws are unauthenticated code injection issues that allow remote attackers to achieve arbitrary code execution on affected EPMM appliances. Active exploitation has been confirmed.

    forum.hashpwn.net/post/9428

    #cybersecurity #zeroday #rce #news #ivanti #cve #epmm #hashpwn

  18. Atomic Wallet users recently noticed their Monero (XMR) balances missing or displaying incorrectly. Atomic Wallet says this is a Monero sync and display issue, not lost funds, and that all XMR remains safe on-chain while a fix is being worked on.

    Given Atomic Wallet’s past security incident in 2023, caution is understandable. No theft has been reported, but users are encouraged to verify independently and never share private keys or seed phrases.

    forum.hashpwn.net/post/8866

    #atomic #wallet #crypto #monero #xmr #hashpwn #news #cybersecurity

  19. Happy New Year!

    Hashpwn wrapped up our first full year in 2025 and had a lot of fun along the way.

    A big thank you to everyone who has been part of the community, and to our staff who helped turn an idea into a reality.

    Here's to 2026!

    forum.hashpwn.net/post/8234

    #hashpwn #hashcracking #forum

  20. hashpwn-2025 wordlist is available for download and now includes all founds submitted to forum.hashpwn.net from Oct 2024 - Dec 2025.

    forum.hashpwn.net/post/237

    #hashpwn #wordlist #dictionary #hashcracking

  21. The hashpwn 12 Days of Christmas Challenge Walkthrough and Submission Results have been posted!

    Walkthrough:
    forum.hashpwn.net/post/8042

    Challenge Submission Results:
    forum.hashpwn.net/post/8043

    Also, Grand Prize winner #_cin posted a summary of his experience:
    forum.hashpwn.net/post/8041

    #hashpwn #christmas #challenge #puzzle #results #walkthrough