ch
Feedback
road to OSCP

road to OSCP

前往频道在 Telegram

🇺🇦 тестуємо 🇺🇦

显示更多
1 660
订阅者
无数据24 小时
-47 天
+130 天

数据加载中...

相似频道
无数据
有任何问题?请刷新页面或联系我们的客服
标签云
无数据
有任何问题?请刷新页面或联系我们的客服
进出提及
---
---
---
---
---
---
吸引订阅者
九月 '25
九月 '250
在0个频道中
八月 '25
+21
在0个频道中
Get PRO
七月 '25
+13
在0个频道中
Get PRO
六月 '25
+24
在0个频道中
Get PRO
五月 '25
+17
在0个频道中
Get PRO
四月 '25
+16
在0个频道中
Get PRO
三月 '25
+74
在0个频道中
Get PRO
二月 '25
+82
在0个频道中
Get PRO
一月 '25
+64
在0个频道中
Get PRO
十二月 '24
+85
在0个频道中
Get PRO
十一月 '24
+92
在0个频道中
Get PRO
十月 '24
+53
在0个频道中
Get PRO
九月 '24
+48
在0个频道中
Get PRO
八月 '24
+58
在0个频道中
Get PRO
七月 '24
+70
在0个频道中
Get PRO
六月 '24
+100
在2个频道中
Get PRO
五月 '24
+87
在0个频道中
Get PRO
四月 '24
+125
在3个频道中
Get PRO
三月 '24
+82
在3个频道中
Get PRO
二月 '24
+162
在3个频道中
Get PRO
一月 '24
+124
在3个频道中
Get PRO
十二月 '23
+107
在2个频道中
Get PRO
十一月 '23
+82
在2个频道中
Get PRO
十月 '23
+494
在4个频道中
日期
订阅者增长
提及
频道
07 九月0
06 九月0
05 九月0
04 九月0
03 九月0
02 九月0
01 九月0
频道帖子
GODAP A complete TUI for LDAP Features: • Supports authentication with password, NTLM hash, Kerberos ticket or PEM/PKCS#12 certificate • Formats date/time, boolean and other categorical attributes into readable text • Pretty colors & cool emojis • LDAPS & StartTLS support • Fast explorer that loads objects on demand • Recursive object search bundled with useful saved searches • Flexible group members & user groups lookups • Supports creation, editing and removal of objects and attributes • Supports moving and renaming objects • Supports searching deleted & recycled objects • Supports exporting specific subtrees of the directory into JSON files • Interactive userAccountControl editor • Interactive DACL viewer + editor • Interactive ADIDNS viewer + editor (basic) • GPO Viewer • SOCKS support https://github.com/Macmod/godap Thanks to: @hybgl

2
#ldap #enum #shell #go [ godap ] TUI for LDAP written in Golang Features: - Formats date/time, boolean and other categorical
#ldap #enum #shell #go [ godap ] TUI for LDAP written in Golang Features: - Formats date/time, boolean and other categorical attributes into readable text - Supports changing the search filter & base DN for the query - LDAPS & StartTLS support - Pretty colors & cool emojis - Quick explorer that loads objects on demand - Recursive object search bundled with useful saved searches - Group members & user groups lookup - Supports basic attribute editing - Basic DACL viewer Thanks to: @zimnyaatishina https://github.com/Macmod/godap
1
3
https://github.com/Macmod/godap
1
4
A script that exploits the SeTcbPrivilege to achieve local privilege escalation on Windows. Note: The privilege must be enabl
A script that exploits the SeTcbPrivilege to achieve local privilege escalation on Windows. Note: The privilege must be enabled before running the script. https://gist.github.com/antonioCoco/19563adef860614b56d010d92e67d178
613
5
LLC (Linux Log Cleaner) A convenient tool for modifying or deleting information in Linux log files, includes: - /var/log/last
LLC (Linux Log Cleaner) A convenient tool for modifying or deleting information in Linux log files, includes: - /var/log/lastlog: Contains the last login of each user. Command to view: lastlog - /var/run/utmp: Contains information about currently active login sessions. Command to view: who, w - /var/log/wtmp: Stores the history of logins and logouts. Command to view: last - /var/log/btmp: Records failed login attempts. Command to view: lastb https://github.com/Macr0phag3/LLC
607
6
Tool to extract Kerberos tickets from Linux kernel keys. https://github.com/TarlogicSecurity/tickey
Tool to extract Kerberos tickets from Linux kernel keys. https://github.com/TarlogicSecurity/tickey
832
7
A platform that provides intentionally vulnerable applications for learning source code review. Currently, 25 challenges are
A platform that provides intentionally vulnerable applications for learning source code review. Currently, 25 challenges are available. It looks very interesting and promising https://vulnerable.codes/ Thanks to: "Руслан 😎😎😎😎😎"
999
8
ScriptSentry is a powerful tool for automating the detection of unsafe configurations in logon scripts. It can identify issue
ScriptSentry is a powerful tool for automating the detection of unsafe configurations in logon scripts. It can identify issues such as: - Unsafe UNC Folder Permissions - Unsafe UNC File Permissions - Unsafe Logon Script Permissions - Unsafe GPO Logon Script Permissions - Unsafe NETLOGON/SYSVOL Permissions - Plaintext Credentials This tool is described in detail in the blog post Hidde Menace: How to Identify Misconfigured and Dangerous Logon Scriptsn https://github.com/techspence/ScriptSentry
1 095
9
https://github.com/CICADA8-Research/Spyndicapped/tree/main
19
10
З новим роком, далі - більше! Happy New Year! The best is yet to come!
1 191
11
https://x.com/anyrun_app/status/1861024182210900357 Креативно!
1 008
12
Introduction to the Exploitation of Xamarin Apps TL;DR: This article covers methods of analyzing Xamarin applications for beg
Introduction to the Exploitation of Xamarin Apps TL;DR: This article covers methods of analyzing Xamarin applications for beginners. It explains the differences between Xamarin and native applications, provides a step-by-step guide for static analysis, and demonstrates app modification techniques. https://www.justmobilesec.com/en/blog/introduction-to-the-exploitation-of-xamarin-apps
1 211
13
Ways to use templates in SQL-map to bypass WAFs from vendors like FortiWAF, F5, Barracuda, Akamai, Cloudflare, and Imperva ht
Ways to use templates in SQL-map to bypass WAFs from vendors like FortiWAF, F5, Barracuda, Akamai, Cloudflare, and Imperva https://redteamrecipe.com/awesome-sqlmap-tampers
1 095
14
Gotta cache 'em all: bending the rules of web cache exploitation This article examines the behavior of different HTTP servers
Gotta cache 'em all: bending the rules of web cache exploitation This article examines the behavior of different HTTP servers and proxies when parsing specially crafted URLs. It also introduces techniques that exploit parser discrepancies, enabling arbitrary web cache poisoning and deception across numerous websites and CDN providers. https://portswigger.net/research/gotta-cache-em-all
796
15
Listen to the whispers: web timing attacks that actually work The article considers ways of conducting web timing attacks in
Listen to the whispers: web timing attacks that actually work The article considers ways of conducting web timing attacks in real conditions by reducing network and server noise This method of detecting hidden parameters and headers is already implemented in Param Miner. https://portswigger.net/research/listen-to-the-whispers-web-timing-attacks-that-actually-work
897
16
Source Code Review Bug Patterns This repository contains Regex patterns to look for while performing manual application sourc
Source Code Review Bug Patterns This repository contains Regex patterns to look for while performing manual application source code analysis. https://github.com/va1da5/manual-source-code-review
1 000
17
JJS to find endpoints on a site in HTML code, in the developer console, execute: javascript:(function(){var scripts=document.getElementsByTagName("script"),regex=/(?<=(\"|\'|\`))\/[a-zA-Z0-9_?&=\/\-\#\.]*(?=(\"|\'|\`))/g;const results=new Set;for(var i=0;i<scripts.length;i++){var t=scripts[i].src;""!=t&&fetch(t).then(function(t){return t.text()}).then(function(t){var e=t.matchAll(regex);for(let r of e)results.add(r[0])}).catch(function(t){console.log("An error occurred: ",t)})}var pageContent=document.documentElement.outerHTML,matches=pageContent.matchAll(regex);for(const match of matches)results.add(match[0]);function writeResults(){results.forEach(function(t){document.write(t+"<br>")})}setTimeout(writeResults,3e3);})(); from: https://www.youtube.com/@criticalthinkingpodcast
1 268
18
Реквізити Охматдит. Думаю, не треба пояснювати, чому вони тут з'явились. Можливо, скоро буде збір від DC8044. Тачка, яку ми купували спільнотою - приїхала на то, і рамі повна пизда... https://www.ohmatdytfund.org/donate?fbclid=PAZXh0bgNhZW0CMTEAAaYWu24k4BrghTfey5q64dBXnLk9Wd25oUVdh7jIY9HgYn4ybXthXVIkz-8_aem_kbb-zZtAqdqfp5A_2OYpFQ
946
19
WiFi Exploitation Framework Nothing new. Just a pretty shell for convenient work Supported attacks: - Deauthentication attack
WiFi Exploitation Framework Nothing new. Just a pretty shell for convenient work Supported attacks: - Deauthentication attack - WIDS Confusion attack - Authentication attack - Beacon Flood attack - TKIP attack (Michael Shutdown Exploitation) - Pixie Dust attack - Null Pin attack - PIN Bruteforce attack - ARP Replay attack - HIRTE attack - Caffe Latte attack - Fake Authentication attack - WPA/WPA2 handshake capture attack - PMKID attack - EvilTwin attack https://github.com/D3Ext/WEF
1 010
20
[ Bypassing SSRF Filters Using r3dir ] r3dir: redirection service designed to help bypass SSRF filters that do not validate t
[ Bypassing SSRF Filters Using r3dir ] r3dir: redirection service designed to help bypass SSRF filters that do not validate the redirect location. It allows you to: - Set the redirection target via URL parameters or subdomains; - Control HTTP response codes; - Obfuscate the target URL with Base32 encoding; - Bypass some allowlist filters. Author: Senior Security Consultant Vladyslav H. Blog: https://www.leviathansecurity.com/blog/bypassing-ssrf-filters-using-r3dir Tool itself: https://github.com/Horlad/r3dir
846