home.social

#hashpwn — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #hashpwn, aggregated by home.social.

  1. Copy Fail (CVE-2026-31431) is a Linux kernel LPE that gives root access on every major linux distro.

    All that is needed is local shell access and a few lines of python.

    forum.hashpwn.net/post/12727

    #cybersecurity #copyfail #linux #exploit #cve202631431 #hashpwn

  2. Copy Fail (CVE-2026-31431) is a Linux kernel LPE that gives root access on every major linux distro.

    All that is needed is local shell access and a few lines of python.

    forum.hashpwn.net/post/12727

    #cybersecurity #copyfail #linux #exploit #cve202631431 #hashpwn

  3. Copy Fail (CVE-2026-31431) is a Linux kernel LPE that gives root access on every major linux distro.

    All that is needed is local shell access and a few lines of python.

    forum.hashpwn.net/post/12727

    #cybersecurity #copyfail #linux #exploit #cve202631431 #hashpwn

  4. Copy Fail (CVE-2026-31431) is a Linux kernel LPE that gives root access on every major linux distro.

    All that is needed is local shell access and a few lines of python.

    forum.hashpwn.net/post/12727

    #cybersecurity #copyfail #linux #exploit #cve202631431 #hashpwn

  5. Copy Fail (CVE-2026-31431) is a Linux kernel LPE that gives root access on every major linux distro.

    All that is needed is local shell access and a few lines of python.

    forum.hashpwn.net/post/12727

    #cybersecurity #copyfail #linux #exploit #cve202631431 #hashpwn

  6. Released: hashgen v1.3.0

    New in this version:

    * HMAC modes
    * PBKDF2 modes
    * scrypt support
    * additional BLAKE2 modes
    * hashcat UTF-16LE modes
    * optimized salt RNG on salted hashes
    * 95+ supported hash modes

    forum.hashpwn.net/post/89

    #hashgen #hashgenerator #hashcracking #hashpwn #golang

  7. Released: hashgen v1.3.0

    New in this version:

    * HMAC modes
    * PBKDF2 modes
    * scrypt support
    * additional BLAKE2 modes
    * hashcat UTF-16LE modes
    * optimized salt RNG on salted hashes
    * 95+ supported hash modes

    forum.hashpwn.net/post/89

    #hashgen #hashgenerator #hashcracking #hashpwn #golang

  8. Released: hashgen v1.3.0

    New in this version:

    * HMAC modes
    * PBKDF2 modes
    * scrypt support
    * additional BLAKE2 modes
    * hashcat UTF-16LE modes
    * optimized salt RNG on salted hashes
    * 95+ supported hash modes

    forum.hashpwn.net/post/89

    #hashgen #hashgenerator #hashcracking #hashpwn #golang

  9. Released: hashgen v1.3.0

    New in this version:

    * HMAC modes
    * PBKDF2 modes
    * scrypt support
    * additional BLAKE2 modes
    * hashcat UTF-16LE modes
    * optimized salt RNG on salted hashes
    * 95+ supported hash modes

    forum.hashpwn.net/post/89

    #hashgen #hashgenerator #hashcracking #hashpwn #golang

  10. Released pcfg-go — a full Go rewrite of pcfg_cracker with ~3× faster training, ~40× faster guessing, $HEX[] and multi-byte support, improved trainer parsing...

    Full Details: forum.hashpwn.net/post/11277

    #pcfg #hashcracking #trainer #guesser #wordlist #generator #hashcat #hashpwn

  11. CsP’s @Waffle_Real just released a new tool called hashpipe, and it solves a problem many of us run into with large potfiles: messy, misidentified hash:password entries.

    hashpipe automatically validates founds by recomputing them, identifying the correct algorithm, and outputting verified results in an mdxfind format.

    If you maintain large cracking datasets or potfiles, this is a great way to verify and clean them up.

    Details:
    forum.hashpwn.net/post/11119

    GitHub repo:
    github.com/Cynosureprime/hashp

    #hashcracking #hashcat #jtr #hashpipe #CsP #cynosureprime #potfile #hashpwn

  12. CsP’s @Waffle_Real just released a new tool called hashpipe, and it solves a problem many of us run into with large potfiles: messy, misidentified hash:password entries.

    hashpipe automatically validates founds by recomputing them, identifying the correct algorithm, and outputting verified results in an mdxfind format.

    If you maintain large cracking datasets or potfiles, this is a great way to verify and clean them up.

    Details:
    forum.hashpwn.net/post/11119

    GitHub repo:
    github.com/Cynosureprime/hashp

    #hashcracking #hashcat #jtr #hashpipe #CsP #cynosureprime #potfile #hashpwn

  13. CsP’s @Waffle_Real just released a new tool called hashpipe, and it solves a problem many of us run into with large potfiles: messy, misidentified hash:password entries.

    hashpipe automatically validates founds by recomputing them, identifying the correct algorithm, and outputting verified results in an mdxfind format.

    If you maintain large cracking datasets or potfiles, this is a great way to verify and clean them up.

    Details:
    forum.hashpwn.net/post/11119

    GitHub repo:
    github.com/Cynosureprime/hashp

    #hashcracking #hashcat #jtr #hashpipe #CsP #cynosureprime #potfile #hashpwn

  14. CsP’s @Waffle_Real just released a new tool called hashpipe, and it solves a problem many of us run into with large potfiles: messy, misidentified hash:password entries.

    hashpipe automatically validates founds by recomputing them, identifying the correct algorithm, and outputting verified results in an mdxfind format.

    If you maintain large cracking datasets or potfiles, this is a great way to verify and clean them up.

    Details:
    forum.hashpwn.net/post/11119

    GitHub repo:
    github.com/Cynosureprime/hashp

    #hashcracking #hashcat #jtr #hashpipe #CsP #cynosureprime #potfile #hashpwn

  15. CsP’s @Waffle_Real just released a new tool called hashpipe, and it solves a problem many of us run into with large potfiles: messy, misidentified hash:password entries.

    hashpipe automatically validates founds by recomputing them, identifying the correct algorithm, and outputting verified results in an mdxfind format.

    If you maintain large cracking datasets or potfiles, this is a great way to verify and clean them up.

    Details:
    forum.hashpwn.net/post/11119

    GitHub repo:
    github.com/Cynosureprime/hashp

    #hashcracking #hashcat #jtr #hashpipe #CsP #cynosureprime #potfile #hashpwn

  16. Update: Solflare “xpass exploit" Details Released

    In Feb 2025, I reported an exploit vulnerability in the Solflare Chrome wallet which allowed the wallet vault (solflaredata) to be decrypted without the user's password.

    Turns out, this was a backdoor, not a bug.

    Today, I am releasing the full details of the xpass exploit, aka the "backdoor master key".

    forum.hashpwn.net/post/11116

    #solflare #crypto #wallet #vulnerability #exploit #backdoor #xpass #cyclone #hashpwn #news #infosec #cybersecurity

  17. Cisco Catalyst SD-WAN CVSS 10.0 zero-day (CVE-2026-20127) has been actively exploited, with attackers gaining admin access.

    Full technical breakdown: forum.hashpwn.net/post/10802

    #cisco #sdwan #cvss10 #cve202620127 #exploit #cybersecurity #infosec #news #hashpwn

  18. Chrome CSS Zero-Day (CVE-2026-2441)

    Google has patched a CVSS 8.8 high-severity use-after-free bug in Chrome’s CSS engine that is being exploited in the wild. This also affects all Chrome-based browsers such as Brave, Edge and Opera.

    forum.hashpwn.net/post/10273

    #google #chrome #brave #edge #opera #browser #cybersecurity #css #zeroday #cve20262441 #news #hashpwn

  19. Another successful MetaMask crypto wallet recovered. This one was on the Zen browser, so was a first for me.

    forum.hashpwn.net/post/10221

    #metamask #crypto #wallet #recovery #zen #browser #firefox #hashpwn

  20. For those who lost their Dogecoins due to the defunct Dough Wallet iPhone app, here's a tool to recover your Dogecoin address and private keys.

    forum.hashpwn.net/post/10034

    #doughwallet #recoverytool #crypto #hashpwn

  21. Windows Notepad RCE - CVE-2026-20841

    A crafted Markdown link could trigger command execution via protocol handler abuse on Windows 11 Notepad.

    forum.hashpwn.net/post/10031

    #notepad #rce #cve202620841 #cybersecurity #news #hashpwn

  22. Ivanti has disclosed two critical zero-day vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) which allow RCE, tracked as CVE-2026-1281 and CVE-2026-1340. Both flaws are unauthenticated code injection issues that allow remote attackers to achieve arbitrary code execution on affected EPMM appliances. Active exploitation has been confirmed.

    forum.hashpwn.net/post/9428

    #cybersecurity #zeroday #rce #news #ivanti #cve #epmm #hashpwn

  23. Atomic Wallet users recently noticed their Monero (XMR) balances missing or displaying incorrectly. Atomic Wallet says this is a Monero sync and display issue, not lost funds, and that all XMR remains safe on-chain while a fix is being worked on.

    Given Atomic Wallet’s past security incident in 2023, caution is understandable. No theft has been reported, but users are encouraged to verify independently and never share private keys or seed phrases.

    forum.hashpwn.net/post/8866

    #atomic #wallet #crypto #monero #xmr #hashpwn #news #cybersecurity

  24. Happy New Year!

    Hashpwn wrapped up our first full year in 2025 and had a lot of fun along the way.

    A big thank you to everyone who has been part of the community, and to our staff who helped turn an idea into a reality.

    Here's to 2026!

    forum.hashpwn.net/post/8234

    #hashpwn #hashcracking #forum

  25. hashpwn-2025 wordlist is available for download and now includes all founds submitted to forum.hashpwn.net from Oct 2024 - Dec 2025.

    forum.hashpwn.net/post/237

    #hashpwn #wordlist #dictionary #hashcracking

  26. The hashpwn 12 Days of Christmas Challenge Walkthrough and Submission Results have been posted!

    Walkthrough:
    forum.hashpwn.net/post/8042

    Challenge Submission Results:
    forum.hashpwn.net/post/8043

    Also, Grand Prize winner #_cin posted a summary of his experience:
    forum.hashpwn.net/post/8041

    #hashpwn #christmas #challenge #puzzle #results #walkthrough

  27. A special thanks to our sponsors this year which made the prizes possible. Participates won over $700 worth of prizes in 13 different puzzles!

    • Hashpwn.net
    Hashpwn is an ethical hash cracking forum that offers moderated discussion, shared research, custom tools, all in a friendly and professional community.
    Sponsored: Daily Prizes, Grand Prize

    • Lethologica.nl
    Lethologica specializes in ethical crypto wallet recovery using advanced password research, digital forensics, and high-performance compute.
    Sponsored: Daily Prizes, Grand Prize

    • Hashes.com
    Hashes.com is a site dedicated to hash recovery with hash lookups, an escrow service, and an API to tie it all together.
    Sponsored: Grand Prize

    • Hashmob.net
    HashMob is a collaborative password research platform focused on hash recovery, analysis, and statistics. It provides shared hashlists, wordlists, tools, optimized rules, and APIs that help researchers and penetration testers improve real-world password security.
    Sponsored: 3-month Diamond Patreon Vouchers to hashmob.net, Daily Prizes, Grand Prize

    • Hashcracky.com
    Hashcracky hosts gamified hash cracking events where participants crack hashes, earn loot, and compete on live leaderboards. It blends competitive fun with real cracking skills through themed, time-limited challenges.
    Sponsored: Vouchers for 35k Gold and loot at hashcracky.com

    #hashpwn #lethologica #hashescom #hashmob #hashcracky #hashcracking #challenge #puzzle #christmas

  28. 🎄 Merry Christmas Eve! 🎅

    The easy part of the Challenge is coming to an end, and everyone should find the upcoming Challenges a bit more complex to solve. Don't let that discourage you from continuing though as there's still more prizes to be won.

    forum.hashpwn.net/post/7931

    #challenge #puzzle #hashpwn #christmas

  29. Thanks to our sponsors, we have already given out $60 in cash prizes and multiple vouchers, with over $400 and many more vouchers still up for grabs!

    What are you waiting for? Come join the fun!

    forum.hashpwn.net/post/4844

    #hashpwn #christmas #challenge #puzzle

  30. Congrats to the 8 who have completed Challenge 01 so far! Buckle up, they get harder from here.

    The Challenge is open to everyone of all skill levels including visitors and hashpwn members.

    forum.hashpwn.net/post/4844

    #hashpwn #challenge