en
Feedback
Pentester

Pentester

Open in Telegram

- Offensive Security (Red Teaming / PenTesting) - BlueTeam (OperationSec, TreatHunting, DFIR) - Reverse Engineering / Malware Analisys - Web Security

Show more
2 644
Subscribers
No data24 hours
+77 days
+3030 days
Posts Archive
HackBrowserData - CLI tool for decrypting/exporting browser data (passwords, history, cookies, bookmarks, credit cards, download records, localStorage and extension) from the browser https://github.com/moonD4rk/HackBrowserData

#OWASP Top 10 for Large Language Model Applications https://hadess.io/owasp-top-10-for-large-language-model-applications

Bad Spin: Android Binder Privilege Escalation Exploit (CVE-2022-20421) https://github.com/0xkol/badspin

Operation Triangulation: iOS devices targeted with previously unknown malware https://securelist.com/operation-triangulation/109842/

LightsOut - Generate an obfuscated DLL that will disable AMSI & ETW https://github.com/icyguider/LightsOut

Kali Linux 2023.2 Release (Hyper-V & PipeWire) https://www.kali.org/blog/kali-linux-2023-2-release/

DevSecOps_Fundamentals_Guidebook_DevSecOps_Tools_and_Activities.pdf1.04 MB

photo content

Dissecting GobRAT behaviors - Linux malware https://jstnk9.github.io/jstnk9/research/GobRAT-Malware/

Cymulate - framework to help red team construct fully customizable/automated APT attacks https://github.com/opabravo/cymulate-framework

Mini.WebVM: Your own Linux box from Dockerfile, virtualized in the browser via WebAssembly https://leaningtech.com/mini-webvm-your-linux-box-from-dockerfile-via-wasm/

Python for OSINT. 21 day course for beginners.pdf18.96 MB

In this repository you will find sample code files for each day of the course "Python for OSINT. A 21-day course for beginners". https://github.com/cipher387/python-for-OSINT-21-days

A simple tool to allows users to search for and analyze android apps for potential security threats and vulnerabilities https://github.com/teixeira0xfffff/KoodousFinder

Multiple Vulnerabilities in Kiddoware Kids Place Parental Control Android App (CVE-2023-28153, CVE-2023-29078, CVE-2023-29079) 1) Login and registration returns password as MD5 hash 2) Stored XSS via device name in parent Dashboard 3) Possible CSRF attacks in parent Dashboard 4) Arbitrary File Upload to AWS S3 bucket 5) Disable Child App Restriction without Parent's notice https://sec-consult.com/vulnerability-lab/advisory/multiple-vulnerabilities-in-kiddoware-kids-place-parental-control-android-app/

#Avast Anti-Virus privileged arbitrary file create on virus restore (CVE-2023-1586) https://the-deniss.github.io/posts/avast-privileged-arbitrary-file-create-on-restore/

Exploiting Windows’ vulnerabilities with Hyper-V: A Hacker’s swiss army knife https://reversing.info/posts/hyperdeceit/