Pentester world 2.0
الذهاب إلى القناة على Telegram
⚠️ DISCLAIMER :- 𝚃𝙷𝙸𝚂 𝙲𝙷𝙰𝙽𝙽𝙴𝙻 𝙳𝙾𝙴𝚂 𝙽𝙾𝚃 𝙿𝚁𝙾𝙼𝙾𝚃𝙴 𝙰𝙽𝚈 𝙸𝙻𝙻𝙴𝙶𝙰𝙻 𝙰𝙲𝚃𝙸𝚅𝙸𝚃𝙸𝙴𝚂 , 𝙸𝚃𝚂 𝙹𝚄𝚂𝚃 𝙵𝙾𝚁 𝙵𝚄𝙽 𝙰𝙽𝙳 𝙴𝙳𝚄𝙲𝙰𝚃𝙸𝙾𝙽𝙰𝙻 𝙿𝚄𝚁𝙿𝙾𝚂𝙴 😇 Welcome pentester world in this group you
إظهار المزيدلم يتم تحديد البلدالتكنولوجيات والتطبيقات75 932
596
المشتركون
+724 ساعات
+407 أيام
+14430 أيام
أرشيف المشاركات
Encrypted Doesn't Mean Authenticated: ShareFile RCE (CVE-2023-24489)
https://blog.assetnote.io/2023/07/04/citrix-sharefile-rce/
CVE-2023-27997 Is Exploitable, and 69% of FortiGate Firewalls Are Vulnerable
https://bishopfox.com/blog/cve-2023-27997-exploitable-and-fortigate-firewalls-vulnerable
Critical Foswiki Vulnerablities: A Logic Error Turned Remote Code Execution
https://herolab.usd.de/en/critical-foswiki-vulnerablities-a-logic-error-turned-remote-code-execution/
Exploiting XSS in hidden inputs and meta tags
https://portswigger.net/research/exploiting-xss-in-hidden-inputs-and-meta-tags
Lessons Learned From HackerOne's Live Hacking Event (h1-4420)!
https://www.youtube.com/watch?v=R3lsiENY5v8
Exploit Google Pixel 7
In detail analysis of exploiting CVE-2023-21400 on Google Pixel 7 with Dirty Pagetable exploit that uses file UAF and pid UAF vulnerabilities
https://yanglingxi1993.github.io/dirty_pagetable/dirty_pagetable.html
Ghauri
An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws
https://github.com/r0oth3x49/ghauri
Advisory: ShareFile Pre-Auth RCE (CVE-2023-24489)
https://blog.assetnote.io/2023/07/04/citrix-sharefile-rce-advisory/
CVE-2023-36934 Analysis: MOVEit Transfer SQL Injection
https://blog.projectdiscovery.io/moveit-transfer-sql-injection/
Introducing NucleiFuzzer: A Powerful Automation Tool for Web Application Security
https://medium.com/@qaafqasim/introducing-nucleifuzzer-a-powerful-automation-tool-for-web-application-security-32f5b4fc8e2d
Cloning apk for bypassing code tampering detection, Google Safety Net and scanning vulnerable plugins
https://github.com/Anof-cyber/MobSecco
BUG BOUNTY: USING DEV TOOL TO FIND CLIENT SIDE VULNERABILITIES #1 | 2023
https://youtu.be/02aF7T_7_m0
Latest ReconFTW Release v2.7!
https://github.com/six2dez/reconftw/releases/tag/v2.7
Two XSS Vulnerabilities in Azure with Embedded postMessage IFrames
https://orca.security/resources/blog/examining-two-xss-vulnerabilities-in-azure-services/
chonked pt.2: exploiting cve-2023-33476 for remote code execution
https://blog.coffinsec.com/0day/2023/06/19/minidlna-cve-2023-33476-exploits.html
Bypassing Okta SSO=> HTTPS/HTTP
https://rashahacks.com/bypassing-okta-sso-https-http/
Genymotion — Proxying Android App Traffic Through Burp Suite in Windows
https://medium.com/@mzkamol/genymotion-proxying-android-app-traffic-through-burp-suite-in-windows-5754f742a06
If you're not writing custom Nuclei templates, you're missing out
https://blog.projectdiscovery.io/if-youre-not-writing-custom-nuclei-templates-youre-missing-out/
CVE-2023-27997 Vulnerability Scanner for FortiGate Firewalls
https://bishopfox.com/blog/cve-2023-27997-vulnerability-scanner-fortigate
A brief summary about a SSTI to RCE in Bagisto
https://siltonrenato02.medium.com/a-brief-summary-about-a-ssti-to-rce-in-bagisto-e900ac450490
