ch
Feedback
BugLearn

BugLearn

前往频道在 Telegram
3 261
订阅者
+224 小时
-87 天
-2230 天
帖子存档
HOW TO MASTER FFUF FOR BUG BOUNTIES AND PEN TESTING.pdf8.74 MB

📚 خاموشی در لایه فیزیکی جمرها چطور ارتباطات بیسیم رو فلج می‌کنن ؟ 📝 توی این مقاله با یکی از مهم‌ ترین حملات دنیای ارتباطات
📚 خاموشی در لایه فیزیکی جمرها چطور ارتباطات بیسیم رو فلج می‌کنن ؟ 📝 توی این مقاله با یکی از مهم‌ ترین حملات دنیای ارتباطات رادیویی و جنگ الکترونیک یعنی جمینگ (Jamming) آشنا می‌شین؛ جایی که مهاجم با ارسال سیگنال‌های نویز پرقدرت، بدون نیاز به شکستن رمزنگاری، ارتباطات وای‌فای، بلوتوث، GPS و فرکانس‌های رادیویی رو مختل و از دسترس خارج می‌کنه 📖 توی این مقاله با این موارد آشنا می‌شین : 🔹 مفهوم جمر، رفتار امواج الکترومغناطیسی و نسبت سیگنال به نویز (SNR) 🔹 تاریخچه مسدودکننده‌های فرکانسی از جنگ‌های جهانی تا تراشه‌های امروزی 🔹 بررسی فنی اختلال در وای‌فای و بلوتوث و تفاوت اون با حملات Deauth 🔹 آشنایی با انواع جمرهای کاربردی مثل GPS، دیتای سلولار، ضد پهپاد و SDR 🔹 بررسی معماری سخت‌افزاری مدارهای مسدودکننده RF 🔹 روش‌های شناسایی، مقابله و مقاوم‌سازی شبکه‌های بیسیم در برابر پارازیت 🌐 مطالعه مقاله : کلیک کنید 🎓 @pentifyteam | pentify.ir

#tools #AIOps "Scanning the Harness: An Empirical Study of Supply-Chain Defects in AI Coding-Agent Configurations", Sep 2026. ]-> data and scripts ]-> tool // AI coding agents such as Claude Code, Cursor, GitHub Copilot, and OpenAI Codex are configured through artifacts developers write and share: instruction files, skills, hooks, MCP server declarations, subagents. This harness is a dependency layer installed from marketplaces and public repositories, running with the developer's privileges, with no lockfile, no install-time check, and no vocabulary for what a component may do

Search for all leaked keys/secrets using one regex! regex: https://gist.github.com/h4x0r-dz/be69c7533075ab0d3f0c9b97f7c93a59
Search for all leaked keys/secrets using one regex! regex: https://gist.github.com/h4x0r-dz/be69c7533075ab0d3f0c9b97f7c93a59 #BugBounty #bugbountytip

🛡 nexHarden | Linux Security Hardener یه ابزار سبک و متن‌باز برای بررسی امنیت سیستم‌های لینوکسی و پیدا کردن تنظیمات ناامن. با nexHarden می‌تونی بخش‌هایی مثل: 🔐 تنظیمات SSH 🔥 Firewall 👤 کاربران و سطح دسترسی‌ها ⚙️ تنظیمات سیستم 📦 سرویس‌های فعال رو بررسی کنی و پیشنهادهای Hardening بگیری و اعمال کنی. ساخته شده با Python برای اینکه بررسی‌های امنیتی سیستم Linux ساده‌تر و سریع‌تر انجام بشه. 🐧 ⭐️ اگه برات مفیده، یه Star کوچیک هم به پروژه بده. 🔗 GitHub: https://github.com/7hekasra/nexHarden #Linux #LinuxSecurity #Python #CyberSecurity #Hardening #OpenSource #nexHarden

#نصیحت از #جادی (سریع و به روز فکر کردن) روایت حال حاضر مسیر باگ بانتی @gitbook_s

CVE-2026-75650: Adobe Commerce and Magento Open Source RCE vulnerability (StyleSmuggler) exploited in the wild, 10.0 rating ‍
CVE-2026-75650: Adobe Commerce and Magento Open Source RCE vulnerability (StyleSmuggler) exploited in the wild, 10.0 rating ‍🔥 Recently disclosed vulnerability in Adobe Commerce and Magento Open Source allows an unauthenticated attacker to execute arbitrary code. This vulnerability is being actively exploited in the wild! Search at Netlas.io: 👉 Link: https://nt.ls/bX5dx 👉 Dork: tag.name:"magento" Read more : https://sansec.io/research/stylesmuggler-0day

مسابقه فتح پرچم بلو bluCTF جایزه‌ها: 🥇 ۱۳۳۳۷ میلی‌گرم طلا 🥈 ۷۷۷۰ میلی‌گرم طلا 🥉 ۴۴۴۰ میلی‌گرم طلا برای ثبت‌نام وارد شوید:
مسابقه فتح پرچم بلو bluCTF جایزه‌ها: 🥇 ۱۳۳۳۷ میلی‌گرم طلا 🥈 ۷۷۷۰ میلی‌گرم طلا 🥉 ۴۴۴۰ میلی‌گرم طلا برای ثبت‌نام وارد شوید: 🔗 https://ctf.blubank.com 🧠 City Of Learn

مجموعه‌ای از Use Caseهای امنیتی قابل پیاده‌سازی در Splunk @buglearn

.

.

CVE-2026-67276 MikroTrick lab PoC — CVE-2026-67276 (RouterOS SSH public-key auth bypass) @buglearn
CVE-2026-67276 MikroTrick lab PoC — CVE-2026-67276 (RouterOS SSH public-key auth bypass) @buglearn

Bug Bounty Tip – SQL Injection Hard-to-exploit SQL injection? This time-based payload worked when others failed:
''||(select 1 from (select pg_sleep(6))x)||'
Add it to your SQL wordlist. Download - https://github.com/orwagodfather/SQL-Wordlist/blob/main/sql.txt @buglearn

+1
All about JWT Hacking.pdf

🕵️‍♂️ هنوز برای پیدا کردن یه رایتاپ درست و حسابی، بین صدتا سایت و لینک گم میشی؟ تبلیغات، لینک‌های مرده، محتوای تکراری و رایتاپ‌های بی‌کیفیت رو بذار کنار. ⚡️ رایتاپ ماینر مثل یک ماینر داخل سطح وب می‌چرخه و رایتاپ‌های ارزشمند رو شکار می‌کنه؛ از CTF و Bug Bounty گرفته تا تحلیل‌های امنیتی و تکنیک‌های فنی. 🎯 ما می‌گردیم، فیلتر می‌کنیم و رایتاپ‌های مفید رو میاریم اینجا. Less Searching. More Hacking. 🧑‍💻 🔻 وارد معدن شو: @writeup_miner

🐛 Bug Bounty Writeup 300$ ETag Bounty: https://medium.com/@sari.mmusab/300-etag-bounty-9f6e9aecc12e The Bug Bounty Recon Cheat Sheet: A Practical Workflow From Domain to Attack Surface: https://infosecwriteups.com/the-bug-bounty-recon-cheat-sheet-a-practical-workflow-from-domain-to-attack-surface-6ff3b44a00d0 ️The Organization Had Users… But Nobody Could Own It: https://medium.com/@0xMo7areb/%EF%B8%8Fthe-organization-had-users-but-nobody-could-own-it-ae9e7513a969 PentestCode: The Multi-Agent AI That Automates Penetration Testing: https://medium.com/@pentesterclubpvtltd/pentestcode-the-multi-agent-ai-that-automates-penetration-testing-8223a8e73446 Belajar dari Celah RCE di NASA VDP: Dokumentasi dan Analisis Teknis: https://medium.com/@radith614/belajar-dari-celah-rce-di-nasa-vdp-dokumentasi-dan-analisis-teknis-0a61473cab43 Ten Years of SSTI Disclosures. $4,300 in Public Bounties.: https://rajnamdev.medium.com/ten-years-of-ssti-disclosures-4-300-in-public-bounties-8d93a8ddc2ff So You Want to Hunt on the Dark Web? A Practical Field Guide for Independent Researchers: https://medium.com/@paritoshblogs/so-you-want-to-hunt-on-the-dark-web-a-practical-field-guide-for-independent-researchers-3e39f4dc75fd How I Found an SQL Injection Vulnerability at Universitas Negeri Jakarta (UNJ): https://medium.com/@adtynll/how-i-found-an-sql-injection-vulnerability-at-universitas-negeri-jakarta-unj-f372203ffa71 Smali By bithowl: Chapter 9 Register Architecture: https://medium.com/@bithowl/smali-by-bithowl-chapter-9-register-architecture-d737d22e4f3d @buglearn

اگه یه باگ کریتیکال توی یه برنامه vdp پیدا کنی ، انگیزت برای گزارشش چیه ؟ @buglearn

Repost from N/a
تجربه خوبی بود مرسی از دوستایی که وقت گذاشتن و اومدن پیشمون.
تجربه خوبی بود مرسی از دوستایی که وقت گذاشتن و اومدن پیشمون.