Pentester world 2.0
الذهاب إلى القناة على Telegram
⚠️ DISCLAIMER :- 𝚃𝙷𝙸𝚂 𝙲𝙷𝙰𝙽𝙽𝙴𝙻 𝙳𝙾𝙴𝚂 𝙽𝙾𝚃 𝙿𝚁𝙾𝙼𝙾𝚃𝙴 𝙰𝙽𝚈 𝙸𝙻𝙻𝙴𝙶𝙰𝙻 𝙰𝙲𝚃𝙸𝚅𝙸𝚃𝙸𝙴𝚂 , 𝙸𝚃𝚂 𝙹𝚄𝚂𝚃 𝙵𝙾𝚁 𝙵𝚄𝙽 𝙰𝙽𝙳 𝙴𝙳𝚄𝙲𝙰𝚃𝙸𝙾𝙽𝙰𝙻 𝙿𝚄𝚁𝙿𝙾𝚂𝙴 😇 Welcome pentester world in this group you
إظهار المزيدلم يتم تحديد البلدالتكنولوجيات والتطبيقات75 932
596
المشتركون
+724 ساعات
+407 أيام
+14430 أيام
أرشيف المشاركات
🌟BugBounty Methodology by Jason Haddix🌟
https://gowthams.gitbook.io/bughunter-handbook/presentations
How To Pick Your Targets // How To Bug Bounty
https://www.youtube.com/watch?v=vbXpRHcKIr0
Unleashing the power of CSS injection: The access key to an internal API
https://sanderwind.medium.com/unleashing-the-power-of-css-injection-the-access-key-to-an-internal-api-789b166d0527
Detecting Server-Side Prototype Pollution
https://www.intruder.io/research/server-side-prototype-pollution
🧑💻💥[Malware Analysis Home-Lab v1.0]💥👩💻
🟢 Platform and OS Setup
📌 Setup Virtual-box https://lnkd.in/d8Shs5VE
📌 Download Windows 7
🟢 Malware Analysis Tool [Static]
📌 HashCalc https://lnkd.in/dz2_wNpB
📌 UPX https://lnkd.in/d_pQHBpy
📌 PE Studio https://lnkd.in/dSMQBm-w
📌 Trid https://lnkd.in/dbFf9JAt
📌 Exeinfo PE https://lnkd.in/dAyQZRBN?
📌 DETECT-IT-EASY https://lnkd.in/dNsjTJBT
📌 BinText https://lnkd.in/d9bqnkFh
📌 FakeNet https://lnkd.in/dy_86n6T 📌 ProcDot https://lnkd.in/d-_jSxUt
🟢 Ready-to-Use Malware Lab
📌 Flare VM by Fireeye
https://github.com/mandiant/flare-vm
🟢 Some Important Hands-on Exercise
📌 Calculate Hash of the File https://lnkd.in/dUyHYVct
📌 Learn to Unpack binaries https://lnkd.in/dfBe3ZRY
📌 Extracting Strings using BinText https://lnkd.in/dTHzcyEK
📌 Indicators of Malicious Activities in Exe’s and PDF’s https://lnkd.in/dTXjX7fV
Awesome ADB
Probably the most detailed ADB documentation with examples I have ever seen
https://github.com/mzlogin/awesome-adb/blob/master/README.en.md
Resource for Android static analysis and vulnerability assessment
Tutorials, tools, and resources for identifying and mitigating security vulnerabilities in Android applications
https://github.com/krizzsk/HackersCave4StaticAndroidSec
𝙊𝙎𝙄𝙉𝙏 𝙁𝙧𝙤𝙢 𝙖 𝙎𝙞𝙣𝙜𝙡𝙚 𝙒𝙚𝙗𝙥𝙖𝙜𝙚 𝙍𝙚𝙦𝙪𝙚𝙨𝙩
Blog link 🔗:-
https://intel471.com/blog/all-the-osint-you-can-get-from-a-single-webpage-request
𝙊𝙎𝙄𝙉𝙏 𝙩𝙤 𝙀𝙡𝙚𝙫𝙖𝙩𝙚 𝘿𝙁𝙄𝙍
Blog link 🔗:-
https://intel471.com/blog/how-osint-can-be-used-to-elevate-dfir
Favirecon
Use favicon.ico to improve your target recon phase. Quickly detect technologies, WAF, exposed panels, known services.
https://github.com/edoardottt/favirecon
of-CORS
Bypass firewalls with of-CORs and typo-squatting
https://github.com/trufflesecurity/of-cors
#Bypass
extracting NTLMv2 hashes from a network traffic dump
https://github.com/mlgualtieri/NTLMRawUnHide
#ntlm #pcap
Favirecon
Use favicon.ico to improve your target recon phase. Quickly detect technologies, WAF, exposed panels, known services.
https://github.com/edoardottt/favirecon
SQL injection vulnerabilities in Owncloud Android app - CVE-2023-24804, CVE-2023-23948
The Owncloud Android app uses content providers to manage its data. The provider FileContentProvider has SQL injection vulnerabilities that allow malicious applications or users in the same device to obtain internal information of the app
https://securitylab.github.com/advisories/GHSL-2022-059_GHSL-2022-060_Owncloud_Android_app/
Bug Bytes #192 – Post-recon blues, a lesson in Rust and fuzzing open source
https://blog.intigriti.com/2023/02/15/bug-bytes-192-post-recon-blues-a-lesson-in-rust-and-fuzzing-open-source/
Hello exploiterz,
Today, I wrote a blog about uncontrolled format string vulnerability which is well-known a security hole in the binary world. But, it is well worth to read this blog to have to have a better understanding to exploiting/bypassing other security mitigation.
Thank you
https://link.medium.com/xUZMiLpdtxb
