Pentester world 2.0
الذهاب إلى القناة على Telegram
⚠️ DISCLAIMER :- 𝚃𝙷𝙸𝚂 𝙲𝙷𝙰𝙽𝙽𝙴𝙻 𝙳𝙾𝙴𝚂 𝙽𝙾𝚃 𝙿𝚁𝙾𝙼𝙾𝚃𝙴 𝙰𝙽𝚈 𝙸𝙻𝙻𝙴𝙶𝙰𝙻 𝙰𝙲𝚃𝙸𝚅𝙸𝚃𝙸𝙴𝚂 , 𝙸𝚃𝚂 𝙹𝚄𝚂𝚃 𝙵𝙾𝚁 𝙵𝚄𝙽 𝙰𝙽𝙳 𝙴𝙳𝚄𝙲𝙰𝚃𝙸𝙾𝙽𝙰𝙻 𝙿𝚄𝚁𝙿𝙾𝚂𝙴 😇 Welcome pentester world in this group you
إظهار المزيدلم يتم تحديد البلدالتكنولوجيات والتطبيقات75 932
596
المشتركون
+724 ساعات
+407 أيام
+14430 أيام
أرشيف المشاركات
FREE LABS RED TEAM/BLUE TEAM and CTF SKILLS - 2023 (REPOST)
Share with your network and friends.
· Attack-Defense - https://attackdefense.com
· Alert to win - https://alf.nu/alert1
· Bancocn - https://bancocn.com
· Buffer Overflow Labs - https://lnkd.in/eNbEWYh
· CTF Komodo Security - https://ctf.komodosec.com
· CryptoHack - https://cryptohack.org/
· CMD Challenge - https://cmdchallenge.com
· Explotation Education - https://exploit.education
· Google CTF - https://lnkd.in/e46drbz8
· HackTheBox - https://www.hackthebox.com
· Hackthis - https://www.hackthis.co.uk
· Hacksplaining - https://lnkd.in/eAB5CSTA
· Hacker101 - https://ctf.hacker101.com
· Capture The Flag - Hacker Security - https://lnkd.in/ex7R-C-e
· Hacking-Lab - https://hacking-lab.com/
· ImmersiveLabs - https://immersivelabs.com
· NewbieContest - https://lnkd.in/ewBk6fU5
· OverTheWire - http://overthewire.org
· Practical Pentest Labs - https://lnkd.in/esq9Yuv5
· Pentestlab - https://pentesterlab.com
· Penetration Testing Practice Labs - https://lnkd.in/e6wVANYd
· PentestIT LAB - https://lab.pentestit.ru
· PicoCTF - https://picoctf.com
· PWNABLE - https://lnkd.in/eMEwBJzn
· Root-Me - https://www.root-me.org
· Root in Jail - http://rootinjail.com
· SANS Challenger - https://lnkd.in/e5TAMawK
· SmashTheStack - https://lnkd.in/eVn9rP9p
· The Cryptopals Crypto Challenges - https://cryptopals.com
· Try Hack Me - https://tryhackme.com
· Vulnhub - https://www.vulnhub.com
· Vulnmachine - https://lnkd.in/eJ2e_kD
· W3Challs - https://w3challs.com
· WeChall - http://www.wechall.net
· Websploit - https://websploit.org/
· Zenk-Security - https://lnkd.in/ewJ5rNx2
· Cyberdefenders - https://lnkd.in/dVcmjEw8
· LetsDefend- https://letsdefend.io/
Five Takeaways from Ohio Secretary of State's VDP Success Story
https://www.hackerone.com/vulnerability-disclosure/five-takeaways-ohio-secretary-states-vdp-success-story
Bypassing advance root detections using Frida
Techniques learned from video:
-presence of SU binary
-SELinux policies
-mountinfo
-attr/prev
-looking for SU bin paths using Supervisor calls
Video: https://youtu.be/7KqPwxlA-00
Scripts and POCs: https://github.com/fatalSec/in-app-protections
How We Found Another GitHub Actions Environment Injection Vulnerability in a Google Project
https://www.legitsecurity.com/blog/-how-we-found-another-github-action-environment-injection-vulnerability-in-a-google-project
Improve your API Security Testing with Burp BCheck Scripts.
https://danaepp.com/improve-your-api-security-testing-with-burp-bcheck-scripts
BurpGPT
A Burp Suite extension that integrates OpenAI's GPT to perform an additional passive scan for discovering highly bespoke vulnerabilities, and enables running traffic-based analysis of any type.
https://github.com/aress31/burpgpt
Burp VPS Proxy: Easy Cloud Proxies for Burp Suite
This Burp Suite extension allows for the automatic creation and deletion of an upstream SOCKS5 proxy on popular cloud services.
https://github.com/d3mondev/burp-vps-proxy
Evolution of the original getAllParams extension for Burp
https://github.com/xnl-h4ck3r/GAP-Burp-Extension
#NahamCon2023: How to Properly Own API’s for Your First Valid Submission | @InsiderPhD
https://www.youtube.com/watch?v=1lVuWqsqESU
List of resources that can be helpful while preparing for CISSP exam:
• Kelly Handerhan's Why will you pass the CISSP https://lnkd.in/g8nPXzx3
• The Official (ISC)2 CISSP CBK Reference, 6th Edition https://amzn.eu/d/8NYHvKz
• Official (ISC)2 CISSP Study Guide, 9th Edition and Practice Tests, 3rd Edition Bundle https://amzn.eu/d/8TR206n
• CISSP For Dummies, 7th Edition https://amzn.eu/d/hLQmtkK
• Official (ISC)2 CISSP Flash Cards https://lnkd.in/gTj5jqw6
• Eleventh Hour CISSP®: Study Guide, 3rd Edition by Eric Conrad, Seth Misenar and Joshua Feldman https://amzn.eu/d/1ZsACly
• Prashant Mohan, CISSP-ISSAP, CCSP's The Memory Palace - A Quick Refresher For Your CISSP Exam! https://lnkd.in/gdAdzmmr
• Luke Ahmed 🚀's How To Think Like A Manager for the CISSP Exam https://amzn.eu/d/1H10Smj
• Thor Pedersen - Lead trainer at ThorTeaches's Complete CISSP Bundle (all CISSP videos and all questions) https://lnkd.in/gEVqxUdJ
• Prabh Nair's CISSP Coffee Shots https://lnkd.in/gmgyUMX9
• Rob Witcher's MindMap Videos https://lnkd.in/g3m47EwQ
• Destination Certification Inc.'s Domain Summaries https://lnkd.in/gKPnsQSQ
• Mike Chapple's Practice Test https://lnkd.in/gG37c73x
• Adam Gordon's Question of the Day https://lnkd.in/gjwScvmk
• Wentz Wu's CISSP Practice Questions https://lnkd.in/gk23HdC5
• CertMike's CISSP Last Minute Review Guide https://lnkd.in/gGxB4Wen
Malware Analysis Course and Certification
1) Ultimate Malware Analysis by Zero2Automated
https://lnkd.in/dN7v2zNj
2) Practical Junior Malware Research by TCM Security
https://lnkd.in/dR6mTmQ8
3) Giac Reverse Engineering and Malware by SANS
https://lnkd.in/d6UvAbun
4) Certified Malware Analyst by Ethical Hackers Academy
https://lnkd.in/dt3xQFQT
5) Malware Analysis by Red Team Academy
https://lnkd.in/duBMbZV8
6) Malware Analysis Course by Black Storm Security
https://lnkd.in/dwhn_uuH
7) Practical Malware Analysis: The Hands-On Guide to Dissecting Malicious Software
https://lnkd.in/dmyhKDBV
8) Malware Analysis Fundamentals by Let's Defend
https://lnkd.in/dSDUeyP7
9) Malware Analysis Detection Engineering
https://lnkd.in/dSEA37wQ
10) Malware Analysis Master by Mandiant
https://lnkd.in/dNM54d2C
11) CS6038/CS5138 Malware Analysis
https://class.malware.re/
12) Malware Analysis CSCI 4976 by RPISEC
https://lnkd.in/dC7kZkAK
13) Reverse Engineering 101 by Malware Unicorn
https://lnkd.in/dwGu22if
14) Purple Team Analyst by CyberwarfareLabs
https://lnkd.in/dBAqYG3j
#NahamCon2023: The Power of Shodan: Leveraging Shodan for Critical Vulnerabilities | @GodFatherOrwa
https://www.youtube.com/watch?v=WgMGLlpznao
How I got Two RCE at EPAM-Bounty Program
https://0xbartita.medium.com/how-i-got-two-rce-at-epam-bounty-program-389eb9fc7938
Bug Bytes #207 -IIS, LLMs and iOS
https://blog.intigriti.com/2023/07/12/bug-bytes-207-iis-llms-and-ios/
Analysis CVE-2023-29300: Adobe ColdFusion Pre-Auth RCE
https://blog.projectdiscovery.io/adobe-coldfusion-rce/
Finding the Entrypoint of iOS Apps in Ghidra
In video tutorial we extract the components of an iOS application and learn how to find the entrypoint using Ghidra to start reverse engineering
https://youtu.be/mLDsIMXafP4
CoWitness is a powerful web application testing tool that enhances the accuracy and efficiency of your testing efforts. It allows you to mimic an HTTP server and a DNS server, providing complete responses and valuable insights during your testing process.
https://github.com/stolenusername/cowitness
