Pentester world 2.0
Open in Telegram
β οΈ DISCLAIMER :- ππ·πΈπ π²π·π°π½π½π΄π» π³πΎπ΄π π½πΎπ πΏππΎπΌπΎππ΄ π°π½π πΈπ»π»π΄πΆπ°π» π°π²ππΈπ πΈππΈπ΄π , πΈππ πΉπππ π΅πΎπ π΅ππ½ π°π½π³ π΄π³ππ²π°ππΈπΎπ½π°π» πΏπππΏπΎππ΄ π Welcome pentester world in this group you
Show moreThe country is not specifiedTechnologies & Applications75 932
596
Subscribers
+724 hours
+407 days
+14430 days
Posts Archive
Encrypted Doesn't Mean Authenticated: ShareFile RCE (CVE-2023-24489)
https://blog.assetnote.io/2023/07/04/citrix-sharefile-rce/
CVE-2023-27997 Is Exploitable, and 69% of FortiGate Firewalls Are Vulnerable
https://bishopfox.com/blog/cve-2023-27997-exploitable-and-fortigate-firewalls-vulnerable
Critical Foswiki Vulnerablities: A Logic Error Turned Remote Code Execution
https://herolab.usd.de/en/critical-foswiki-vulnerablities-a-logic-error-turned-remote-code-execution/
Exploiting XSS in hidden inputs and meta tags
https://portswigger.net/research/exploiting-xss-in-hidden-inputs-and-meta-tags
Lessons Learned From HackerOne's Live Hacking Event (h1-4420)!
https://www.youtube.com/watch?v=R3lsiENY5v8
Exploit Google Pixel 7
In detail analysis of exploiting CVE-2023-21400 on Google Pixel 7 with Dirty Pagetable exploit that uses file UAF and pid UAF vulnerabilities
https://yanglingxi1993.github.io/dirty_pagetable/dirty_pagetable.html
Ghauri
An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws
https://github.com/r0oth3x49/ghauri
Advisory: ShareFile Pre-Auth RCE (CVE-2023-24489)
https://blog.assetnote.io/2023/07/04/citrix-sharefile-rce-advisory/
CVE-2023-36934 Analysis: MOVEit Transfer SQL Injection
https://blog.projectdiscovery.io/moveit-transfer-sql-injection/
Introducing NucleiFuzzer: A Powerful Automation Tool for Web Application Security
https://medium.com/@qaafqasim/introducing-nucleifuzzer-a-powerful-automation-tool-for-web-application-security-32f5b4fc8e2d
Cloning apk for bypassing code tampering detection, Google Safety Net and scanning vulnerable plugins
https://github.com/Anof-cyber/MobSecco
BUG BOUNTY: USING DEV TOOL TO FIND CLIENT SIDE VULNERABILITIES #1 | 2023
https://youtu.be/02aF7T_7_m0
Latest ReconFTW Release v2.7!
https://github.com/six2dez/reconftw/releases/tag/v2.7
Two XSS Vulnerabilities in Azure with Embedded postMessage IFrames
https://orca.security/resources/blog/examining-two-xss-vulnerabilities-in-azure-services/
chonked pt.2: exploiting cve-2023-33476 for remote code execution
https://blog.coffinsec.com/0day/2023/06/19/minidlna-cve-2023-33476-exploits.html
Bypassing Okta SSO=> HTTPS/HTTP
https://rashahacks.com/bypassing-okta-sso-https-http/
Genymotion β Proxying Android App Traffic Through Burp Suite in Windows
https://medium.com/@mzkamol/genymotion-proxying-android-app-traffic-through-burp-suite-in-windows-5754f742a06
If you're not writing custom Nuclei templates, you're missing out
https://blog.projectdiscovery.io/if-youre-not-writing-custom-nuclei-templates-youre-missing-out/
CVE-2023-27997 Vulnerability Scanner for FortiGate Firewalls
https://bishopfox.com/blog/cve-2023-27997-vulnerability-scanner-fortigate
A brief summary about a SSTI to RCE in Bagisto
https://siltonrenato02.medium.com/a-brief-summary-about-a-ssti-to-rce-in-bagisto-e900ac450490
