HackTheBox Academy
Closed channel
🔴Learn About #Linux 🔴Learn About #Windows 🔴Learn About #CVE 🔴Learn About #EXPLOIT 🔴Learn About #Vulnerability ✅ADMIN : @NullByte0x1
Show more3 327
Subscribers
No data24 hours
-207 days
-9330 days
Posts Archive
3 327
↔️ CVE-2024-55591
❗️ The manipulation with an unknown input leads to a authentication bypass vulnerability.
🖥 Exploit - POC
Hunter:
product.name="Fortinet Firewall"FOFA:
product="FORTINET-Firewall"#Ethical_Hacker #Exploit # #CVE #Pentest #Vulnerability ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security
3 327
👩💻 Create an Account On HTB Academy Right Now And Get #FREE Cubes To Unlock Great Cybersecurity Courses!
https://referral.hackthebox.com/mz7TUT7
3 327
A neat trick for bypassing WAF/filters while testing for OS command injection vulnerabilities.
Use shell globbing / wildcard expansion. Here is an example 👇 `cat /e*c/p*s*d` is equivalent to `cat /etc/passwd`. But how? Before cat runs, the shell expands the glob pattern /e*c/p*s*d to match actual files and directories in the filesystem. `/e*c`: The shell interprets this as "any path starting with /e, followed by zero or more characters (*), ending with c." `/p*s*d`: This matches a path or file name starting with p, followed by zero or more characters (*), then s, then zero or more characters (*), then d#BugBountyTips #Hacking #Security ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security
3 327
🔠 WebCopilot
⭐️ An automation tool that enumerate subdomains then filters out xss, sqli, open redirect, lfi, ssrf and rce parameters and then scans for vulnerabilities.
💫 Features:
💜 Subdomain Enumeration.
💜 Extract titles and take screenshots of live subdomains.
💜 Crawl all the endpoints of the subdomains using waymore and filter out XSS, SQLi, SSRF, etc parameters using gf patterns.
🖥 GitHub
#Web #Tools #Injection #Scanner #RCE
#Pentest #Ethical_Hacker #XSS #SQLI
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security
3 327
🩸🩸🫵🩸🩸🩸 💥
🕷 Hackify BugBounty Pack.
1. Bug Bounty Hunting and Penetration Testing v1 2. Bug Bounty Hunting and Penetration Testing v2 3. CVE's for Bug Bounties & Penetration Testing 4. Recon For Bug Bounties & Penetration Testing 5. Top 5 Tools & Techniques for Penetration Testing#Course #Pentest #BugBounty #Hacking #Ethical_Hacker #Security ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security
3 327
↔️ CVE-2024-49138
❗️ Windows Common Log File System(CLFS.sys) Driver Elevation of Privilege Vulnerability.
🖥 Exploit - POC
#Ethical_Hacker #Exploit #Privilege_Escalation
#CVE #Pentest #Vulnerability #Windows
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security
3 327
Get the hash of favicon of website (by url or file) and search it in Shodan, Censys and Virustotal.
favihash.com
3 327
🔠 Injectra
⭐️ Injectra is a Python-based tool for injecting custom payloads into various file types using their magic numbers. It supports file types like zip, rar, docx, jpg, and more.
💫 Features:
💜 Magic Number-Based Payload Injection.
💜 Customizable Payloads.
💜 Broad File Type Support.
🖥 GitHub
#Web #Tools #Injection
#Pentest #Ethical_Hacker
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security
3 327
👩💻 Apache RCE Vulnerability.
🔎 SHODAN:
Apache 2.4.49🔎 Fofa:
server="Apache/2.4.49"#Tools #Vulnerability #REC #Hacking #Ethical_Hacker #Pentest ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security
3 327
⚔️ Find a Thousands Of Target IP from SHODAN Just By a Single Script Without Api.
🔠 Example Of Usage:
./shodanspider.sh -q "apache"
./shodanspider -q "apache" -o "results.txt"
#Tools #Pentest #Shodan
#Hacking #Ethical_Hacker #Security
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security