2 682
订阅者
+724 小时
+1637 天
+8230 天
数据加载中...
吸引订阅者
九月 '269月 '26
九月 '26
+288
在7个频道中
八月 '26
+232
在6个频道中
Get PRO
七月 '26
+107
在2个频道中
Get PRO
六月 '26
+35
在2个频道中
Get PRO
五月 '26
+91
在6个频道中
Get PRO
四月 '26
+2 600
在5个频道中
| 日期 | 订阅者增长 | 提及 | 频道 | |
| 25 九月 | +8 | |||
| 24 九月 | +9 | |||
| 23 九月 | +7 | |||
| 22 九月 | +6 | |||
| 21 九月 | +120 | |||
| 20 九月 | +22 | |||
| 19 九月 | +42 | |||
| 18 九月 | 0 | |||
| 17 九月 | 0 | |||
| 16 九月 | +32 | |||
| 15 九月 | +2 | |||
| 14 九月 | 0 | |||
| 13 九月 | +4 | |||
| 12 九月 | +2 | |||
| 11 九月 | +2 | |||
| 10 九月 | 0 | |||
| 09 九月 | 0 | |||
| 08 九月 | +7 | |||
| 07 九月 | 0 | |||
| 06 九月 | +2 | |||
| 05 九月 | +6 | |||
| 04 九月 | +11 | |||
| 03 九月 | 0 | |||
| 02 九月 | +6 | |||
| 01 九月 | 0 |
频道帖子
Repost from RΞDOPS NINJA 🧑🏻💻
+1
🔴 KaliGPT + AI for Red Team on Kali Linux 🐉🤖
Main functionalities :
🌟Recognition: discovery of hosts, services, domains, and attack surface.
🌟Enumeration: identification of ports, versions, technologies and configurations.
🌟Vulnerability analysis: search and validation of known vulnerabilities.
🌟Web security: testing of web applications, APIs, authentication, sessions and configurations.
🌟Controlled exploitation: validation of vulnerabilities within an authorized environment.
🌟Post-exploitation: analysis of privileges, persistence and lateral movement in a laboratory.
🌟Active Directory: Enumeration of users, groups, trusted relationships, and insecure configurations.
🌟Wireless: audit of own or authorized Wi-Fi networks.
🌟Password auditing: evaluation of password robustness using legitimately obtained hashes.
🌟Forensic and analysis: inspection of evidence, traffic and artifacts.
Reporting: documentation of findings, evidence, impact and recommendations.
The idea is not to replace the security professional, but to use AI as a co-pilot to analyze information, automate repetitive tasks and speed up documentation.
Official repository:
👉https://github.com/SudoHopeX/KaliGPT
The project supports vendors such as Gemini, Ollama, OpenRouter, and OpenAI models, as well as including agent roles for cybersecurity assistance
☕️Don't forget to follow me
👉https://x.com/r0psx_ninja
| 2 | 💠 Burp Suite + Claude AI: Connect Using MCP Server (2025 Setup)
🔗 https://hacklido.com/blog/1051-burp-suite-claude-ai-connect-using-mcp-server-2025-setup | 622 |
| 3 | 🚨 CVE-2026-18963 - Keycloak < 26.7.2 - Unauthenticated Account Takeover via Reset-Credentials Bypass
Nuclei Template - https://github.com/projectdiscovery/nuclei-templates/pull/16995/changes
Reference: https://github.com/keycloak/keycloak/issues/51833
#hackwithautomation #bugbounty #keycloak | 764 |
| 4 | 没有文字... | 711 |
| 5 | 🔔 Bug Bounty Tip 🕵️
Did you know some exposed Google Maps API keys may also have access to Gemini models? 👀
Try geminiHunter to hunt for exposed Gemini API keys across:
* JS/source maps
* Wayback snapshots
* Android APKs
* Web assets
It also deduplicates and validates keys, helping you identify which exposed keys are actually usable.
🔗 https://github.com/devploit/geminiHunter | 1 048 |
| 6 | 🚨All about bug bounty
🔥https://github.com/daffainfo/AllAboutBugBounty | 1 080 |
| 7 | 🔥HackTools - The all-in-one RedTeam extension for Web Pentester.
✅https://github.com/LasCC/Hack-Tools | 841 |
| 8 | 11 new vulnerabilities in WordPress, no CVE assigned yet ❗️
WordPress 7.1.1 security release patches 11 vulnerabilities including stored XSS, path traversal, and other security flaws.
Search at Netlas.io:
👉 Link: https://nt.ls/s3kOE
👉 Dork: tag.name:"wordpress" | 509 |
| 9 | 🔥 ⛓️ Click2Shell is a one-click unauthenticated remote command execution chain (Preauth RCE) affecting every WordPress website. Wordpress rolled out a fix yesterday! The story about how one preview link made WordPress click Install, load an inactive theme's PHP, and hand us RCE is below.
⚠️https://pwn.ai/blog/click2shell | 771 |
| 10 | 🚨Search for all leaked keys/secrets using one regex!
✅regex: https://gist.github.com/h4x0r-dz/be69c7533075ab0d3f0c9b97f7c93a59
#BugBounty #bugbountytip | 461 |
| 11 | FOUNDATIONAL & ESSENTIAL COURSES
Introduction to Cybersecurity – Cisco Networking Academy
🔗 netacad.com/courses/cybersecurity
Cybersecurity Basics – edX
🔗 edx.org/course/cybersecurity-basics
Cybersecurity Essentials – Cisco Networking Academy
🔗 netacad.com/courses/cybersecurity-essentials
Introduction to Information Security – Great Learning
🔗 mygreatlearning.com/academy
CERTIFICATIONS & SPECIALIZED PATHS
5. Certified in Cybersecurity (CC) – ISC2
🔗 isc2.org/Certifications/CC
Fortinet Network Security Expert (NSE 1, 2, & 3) – Fortinet Training Institute
🔗 training.fortinet.com
Ethical Hacking Essentials (EHE) – EC-Council CodeRed
🔗 codered.eccouncil.org
Digital Forensics Essentials (DFE) – EC-Council CodeRed
🔗 codered.eccouncil.org
Network Defense Essentials (NDE) – EC-Council CodeRed
🔗 codered.eccouncil.org
ETHICAL HACKING & PENETRATION TESTING
10. Introduction to Ethical Hacking – Great Learning
🔗 mygreatlearning.com/academy
Penetration Testing: Discovering Vulnerabilities – edX
🔗 edx.org/course/penetration-testing
DIGITAL FORENSICS & INVESTIGATION
12. Computer Forensics – edX
🔗 edx.org/course/computer-forensics
Cyber Forensics – edX
🔗 edx.org/course/cyber-forensics
Introduction to Cybercrime – Simplilearn
🔗 simplilearn.com/free-cybercrime-courses
Cybercrime Concepts – Great Learning
🔗 olympus.mygreatlearning.com
NETWORK & ENTERPRISE SECURITY
16. Network Security – Great Learning
🔗 olympus.mygreatlearning.com
Network Security Foundations – OpenLearn
🔗 open.edu/openlearn
Enterprise and Infrastructure Security – Coursera
🔗 coursera.org/learn/enterprise-infrastructure-security
Real-Time Cyber Threat Detection and Mitigation – Coursera
🔗 coursera.org/learn/real-time-cyber-threat-detection
ADVANCED CONCEPTS
20. Introduction to Dark Web, Anonymity, and Cryptocurrency – EC-Council CodeRed
🔗 codered.eccouncil.org | 497 |
| 12 | ⛧ PRACTICAL PHISHING COURSE ⛧
Break the Light. Enter the Grid.
👾 Construct a Stealth Phishing Framework
💉 Inject & Execute High‑Impact Campaigns
🔐 Slip Through MFA Barriers
🕳 Ghost Past Spam Filters
🎯 Precision Credential Extraction
🧨 Post‑Breach Exploit Operations
🛡 Blue‑Team Countermeasure Mapping
⚔️ Insights from Real Offensive Scenarios | 157 |
| 13 | 📂 PENETRATION TESTING
┃
┣ 📂 Reconnaissance & Discovery
┃ ┣ 📂 OSINT & Asset Discovery
┃ ┣ 📂 Subdomain Enumeration
┃ ┣ 📂 Port & Service Scanning
┃ ┣ 📂 Tech Stack Fingerprinting
┃ ┣ 📂 Directory & File Fuzzing
┃ ┗ 📂 Cloud Storage Bucket Hunting
┃
┣ 📂 Authentication & Sessions
┃ ┣ 📂 Brute Force & Credential Stuffing
┃ ┣ 📂 MFA / 2FA Bypass
┃ ┣ 📂 JWT Misconfigurations
┃ ┣ 📂 OAuth & SAML Flaws
┃ ┗ 📂 Session Fixation & Hijacking
┃
┣ 📂 Access Control
┃ ┣ 📂 BOLA / IDOR
┃ ┣ 📂 Horizontal Privilege Escalation
┃ ┣ 📂 Vertical Privilege Escalation
┃ ┣ 📂 Forced Browsing
┃ ┗ 📂 Parameter Tampering
┃
┣ 📂 Information Disclosure
┃ ┣ 📂 Sensitive Data Exposure
┃ ┣ 📂 Debug Information & Stack Traces
┃ ┣ 📂 Backup Files (.bak, .old)
┃ ┣ 📂 Source Code Exposure (.git, .env)
┃ ┗ 📂 Configuration Exposure
┃
┣ 📂 File Upload
┃ ┣ 📂 Extension Bypass
┃ ┣ 📂 MIME / Magic Byte Validation
┃ ┣ 📂 Content-Type Manipulation
┃ ┣ 📂 Zip Slip / Archive Extraction
┃ ┗ 📂 Upload → RCE
┃
┣ 📂 File Inclusion & Traversal
┃ ┣ 📂 Local File Inclusion (LFI)
┃ ┣ 📂 Remote File Inclusion (RFI)
┃ ┣ 📂 Path Traversal
┃ ┣ 📂 Log Poisoning → RCE
┃ ┗ 📂 Filter Bypass & Wrappers
┃
┣ 📂 XSS (Cross-Site Scripting)
┃ ┣ 📂 Reflected XSS
┃ ┣ 📂 Stored XSS
┃ ┣ 📂 DOM XSS
┃ ┣ 📂 Blind XSS
┃ ┣ 📂 Mutation XSS (mXSS)
┃ ┗ 📂 WAF / Filter Bypass
┃
┣ 📂 Injection Attacks
┃ ┣ 📂 SQL Injection (Error, Boolean, Time, Union, Blind)
┃ ┣ 📂 OS Command Injection (Blind, Argument)
┃ ┣ 📂 LDAP Injection
┃ ┣ 📂 NoSQL Injection
┃ ┗ 📂 XPath / XML Injection
┃
┣ 📂 Template Injection (SSTI)
┃ ┣ 📂 Python (Jinja2, Mako)
┃ ┣ 📂 PHP (Twig, Smarty)
┃ ┣ 📂 Java (FreeMarker, Velocity)
┃ ┗ 📂 Filter Bypass → RCE
┃
┣ 📂 XML External Entity (XXE)
┃ ┣ 📂 In-Band XXE
┃ ┣ 📂 Error-Based XXE
┃ ┣ 📂 Blind / Out-of-Band (OOB) XXE
┃ ┗ 📂 Billion Laughs Attack (DoS)
┃
┣ 📂 CSRF (Cross-Site Request Forgery)
┃ ┣ 📂 Token Validation Flaws
┃ ┣ 📂 SameSite Cookie Bypass
┃ ┣ 📂 Origin / Referer Validation
┃ ┗ 📂 CSRF to Account Takeover
┃
┣ 📂 SSRF (Server-Side Request Forgery)
┃ ┣ 📂 Basic SSRF
┃ ┣ 📂 Blind SSRF
┃ ┣ 📂 Cloud Metadata Extraction
┃ ┣ 📂 Allowlist/Blocklist Bypass
┃ ┗ 📂 SSRF Chains (e.g., SSRF → RCE)
┃
┣ 📂 HTTP Routing & Desync
┃ ┣ 📂 HTTP Request Smuggling (CL.TE, TE.CL, TE.TE)
┃ ┣ 📂 Host Header Injection
┃ ┣ 📂 Cache Poisoning
┃ ┣ 📂 Cache Deception
┃ ┗ 📂 Open Redirects
┃
┣ 📂 Business Logic Flaws
┃ ┣ 📂 Race Conditions (TOCTOU)
┃ ┣ 📂 Price / Currency Manipulation
┃ ┣ 📂 Workflow Bypass
┃ ┗ 📂 Trust Boundary Violation
┃
┣ 📂 API & GraphQL Security
┃ ┣ 📂 Introspection Queries
┃ ┣ 📂 Mass Assignment / Auto-binding
┃ ┣ 📂 Query Complexity (DoS)
┃ ┣ 📂 Unauthenticated Endpoints
┃ ┗ 📂 Rate Limiting & Pagination Flaws
┃
┣ 📂 CORS Misconfigurations
┃ ┣ 📂 Origin Validation Flaws
┃ ┣ 📂 Null Origin Trust
┃ ┣ 📂 Credentials Leakage
┃ ┗ 📂 Wildcard Origins
┃
┣ 📂 Known Vulnerabilities & CVEs
┃ ┣ 📂 N-Day Exploitation
┃ ┣ 📂 Version Detection
┃ ┣ 📂 Component Analysis (SBOM)
┃ ┗ 📂 Patch Validation
┃
┣ 📂 Study & Reference
┃ ┣ 📂 Cheat Sheets
┃ ┣ 📂 Payload Dictionaries (SecLists)
┃ ┣ 📂 Writeups & Bug Bounty Reports
┃ ┗ 📂 Custom Mindmaps
┃
┗ 📂 Tooling & Scripts
┣ 📂 Recon Automation
┣ 📂 Custom Fuzzers
┣ 📂 Exploit PoCs
┣ 📂 Payload Generators
┗ 📂 Reporting Templates
SCOPE → RECON → ENUMERATE → VULN ANALYSIS → EXPLOIT → ESCALATE → CHAIN → REPORT → REMEDIATE | 493 |
| 14 | +4 5.HackAcademy_OSCP AD_Chain5 - Walkthrough.ops.pdf | 235 |
| 15 | +6 4.HackAcademy_OSCP AD Chain 4 - Walkthrough.sn.pdf | 238 |
| 16 | +1 HTB_OSCP_Ranked.xlsx | 235 |
| 17 | oscp+.pdf | 239 |
| 18 | OSCP+ machine walkthrough | 243 |
| 19 | 🔥 OffSec Certified Professional (OSCP) (PEN-200) - Notes
🚀 My OSCP Preparation Journey: How I Cracked the Exam
https://blog.rootkid.in/exam-prep-notes/offsec-certified-professional-oscp-pen-200-notes/my-oscp-preparation-journey-how-i-cracked-the-exam
⚡️ My OSCP Exam Day Experience
https://blog.rootkid.in/exam-prep-notes/offsec-certified-professional-oscp-pen-200-notes/my-oscp-exam-day-experience
📚 Best Resources I Found During My OSCP Journey
https://blog.rootkid.in/exam-prep-notes/offsec-certified-professional-oscp-pen-200-notes/best-resources-i-found-during-my-oscp-journey | 1 487 |
| 20 | 没有文字... | 39 |
