Pentester world 2.0
Open in Telegram
⚠️ DISCLAIMER :- 𝚃𝙷𝙸𝚂 𝙲𝙷𝙰𝙽𝙽𝙴𝙻 𝙳𝙾𝙴𝚂 𝙽𝙾𝚃 𝙿𝚁𝙾𝙼𝙾𝚃𝙴 𝙰𝙽𝚈 𝙸𝙻𝙻𝙴𝙶𝙰𝙻 𝙰𝙲𝚃𝙸𝚅𝙸𝚃𝙸𝙴𝚂 , 𝙸𝚃𝚂 𝙹𝚄𝚂𝚃 𝙵𝙾𝚁 𝙵𝚄𝙽 𝙰𝙽𝙳 𝙴𝙳𝚄𝙲𝙰𝚃𝙸𝙾𝙽𝙰𝙻 𝙿𝚄𝚁𝙿𝙾𝚂𝙴 😇 Welcome pentester world in this group you
Show moreThe country is not specifiedTechnologies & Applications75 932
596
Subscribers
+724 hours
+407 days
+14430 days
Posts Archive
assetfinder
Find domains and subdomains potentially related to a given domain.
https://github.com/tomnomnom/assetfinder
Research:
https://securitytrails.com/blog/assetfinder
#pentest #bugbounty
Firestore Security Testing Guide: Everything a Pinterester, Developer, and Architect Needs to Know
https://michael-yer.medium.com/firestore-security-testing-guide-go-beyond-firebaseio-com-json-69715891a51d
github.com/pr0xh4ck/web-recon
Large list of tools for:
- dns bruteforce;
- ip check;
- subdomain/cms/cloud enumeration;
- working with data breaches and wayback (archive org)
- port scanning
and much more
#recon
Jawbreaker
A Python obfuscator written in Python3, using double encoding in base16, base32, base64, HTTP requests and the Hastebin API.
https://github.com/billythegoat356/Jawbreaker
#python
XSS Exploitation Tool
A penetration testing tool that focuses on the exploit of Cross-Site Scripting vulnerabilities.
▫️ Exfiltrate input field data
▫️ Exfiltrate cookies
▫️ Keylogging
▫️ Display alert box
▫️ Redirect user
https://github.com/Sharpforce/XSS-Exploitation-Tool
#tools
Testing MEDUSA Android dynamic instrumentation Tool for Android pentesting & malware analysis
https://youtu.be/4hpjRuNJNDw
A three day video course on Android Malware Analysis:
Day 1: http://youtube.com/watch?v=CwCOGf4Uunk
Day 2: http://youtube.com/watch?v=yZe8tGzm8nA
Day 3: http://youtube.com/watch?v=JdBu9yEu8g4
Discovering a weakness leading to a partial bypass of the login rate limiting in the AWS Console
https://securitylabs.datadoghq.com/articles/aws-console-rate-limit-bypass/
Installing Gxss both methods
https://medium.com/@sherlock297/install-gxss-on-kali-linux-b598e30e8be5
SSRF vulnerabilities caused by SNI proxy misconfigurations
https://www.invicti.com/blog/web-security/ssrf-vulnerabilities-caused-by-sni-proxy-misconfigurations/
ChatGPT — Bug Bounty Recon Automation
https://medium.com/@nkrohitkumar2002/chatgpt-bug-bounty-recon-automation-bd18291953cb
S3cret Scanner: Hunting For Secrets Uploaded To Public S3 Buckets
https://github.com/Eilonh/s3crets_scanner
Top 10 web hacking techniques of 2022 - nominations open
https://portswigger.net/research/top-10-web-hacking-techniques-of-2022-nominations-open
Web-Cache Poisoning $$$? Worth it?
https://yaseenzubair.medium.com/web-cache-poisoning-worth-it-e7c6d88797b1
Finding Uncommon Vulnerabilities with Manual Testing - [A Pentester's Perspective]
https://youtu.be/Ho2G4fjwBQ0
Centos Web Panel 7 Unauthenticated Remote Code Execution - CVE-2022-44877
https://github.com/numanturle/CVE-2022-44877
