Pentester world 2.0
Open in Telegram
β οΈ DISCLAIMER :- ππ·πΈπ π²π·π°π½π½π΄π» π³πΎπ΄π π½πΎπ πΏππΎπΌπΎππ΄ π°π½π πΈπ»π»π΄πΆπ°π» π°π²ππΈπ πΈππΈπ΄π , πΈππ πΉπππ π΅πΎπ π΅ππ½ π°π½π³ π΄π³ππ²π°ππΈπΎπ½π°π» πΏπππΏπΎππ΄ π Welcome pentester world in this group you
Show moreThe country is not specifiedTechnologies & Applications75 932
596
Subscribers
+724 hours
+407 days
+14430 days
Posts Archive
πBugBounty Methodology by Jason Haddixπ
https://gowthams.gitbook.io/bughunter-handbook/presentations
How To Pick Your Targets // How To Bug Bounty
https://www.youtube.com/watch?v=vbXpRHcKIr0
Unleashing the power of CSS injection: The access key to an internal API
https://sanderwind.medium.com/unleashing-the-power-of-css-injection-the-access-key-to-an-internal-api-789b166d0527
Detecting Server-Side Prototype Pollution
https://www.intruder.io/research/server-side-prototype-pollution
π§βπ»π₯[Malware Analysis Home-Lab v1.0]π₯π©βπ»
π’ Platform and OS Setup
π Setup Virtual-box https://lnkd.in/d8Shs5VE
π Download Windows 7
π’ Malware Analysis Tool [Static]
π HashCalc https://lnkd.in/dz2_wNpB
π UPX https://lnkd.in/d_pQHBpy
π PE Studio https://lnkd.in/dSMQBm-w
π Trid https://lnkd.in/dbFf9JAt
π Exeinfo PE https://lnkd.in/dAyQZRBN?
π DETECT-IT-EASY https://lnkd.in/dNsjTJBT
π BinText https://lnkd.in/d9bqnkFh
π FakeNet https://lnkd.in/dy_86n6T π ProcDot https://lnkd.in/d-_jSxUt
π’ Ready-to-Use Malware Lab
π Flare VM by Fireeye
https://github.com/mandiant/flare-vm
π’ Some Important Hands-on Exercise
π Calculate Hash of the File https://lnkd.in/dUyHYVct
π Learn to Unpack binaries https://lnkd.in/dfBe3ZRY
π Extracting Strings using BinText https://lnkd.in/dTHzcyEK
π Indicators of Malicious Activities in Exeβs and PDFβs https://lnkd.in/dTXjX7fV
ποΈPentest-Cheat-Sheetsπ¨π»βπ»
https://github.com/Kitsun3Sec/Pentest-Cheat-Sheets
Awesome ADB
Probably the most detailed ADB documentation with examples I have ever seen
https://github.com/mzlogin/awesome-adb/blob/master/README.en.md
Resource for Android static analysis and vulnerability assessment
Tutorials, tools, and resources for identifying and mitigating security vulnerabilities in Android applications
https://github.com/krizzsk/HackersCave4StaticAndroidSec
π¨π»βπ»Malware π¨π»βπ»
https://github.com/rivitna/Malware/tree/main/DarkBit
πππππ ππ§π€π’ π πππ£ππ‘π ππππ₯πππ πππ¦πͺππ¨π©
Blog link π:-
https://intel471.com/blog/all-the-osint-you-can-get-from-a-single-webpage-request
πππππ π©π€ ππ‘ππ«ππ©π πΏπππ
Blog link π:-
https://intel471.com/blog/how-osint-can-be-used-to-elevate-dfir
Favirecon
Use favicon.ico to improve your target recon phase. Quickly detect technologies, WAF, exposed panels, known services.
https://github.com/edoardottt/favirecon
ββof-CORS
Bypass firewalls with of-CORs and typo-squatting
https://github.com/trufflesecurity/of-cors
#Bypass
extracting NTLMv2 hashes from a network traffic dump
https://github.com/mlgualtieri/NTLMRawUnHide
#ntlm #pcap
Favirecon
Use favicon.ico to improve your target recon phase. Quickly detect technologies, WAF, exposed panels, known services.
https://github.com/edoardottt/favirecon
SQL injection vulnerabilities in Owncloud Android app - CVE-2023-24804, CVE-2023-23948
The Owncloud Android app uses content providers to manage its data. The provider FileContentProvider has SQL injection vulnerabilities that allow malicious applications or users in the same device to obtain internal information of the app
https://securitylab.github.com/advisories/GHSL-2022-059_GHSL-2022-060_Owncloud_Android_app/
Bug Bytes #192 β Post-recon blues, a lesson in Rust and fuzzing open source
https://blog.intigriti.com/2023/02/15/bug-bytes-192-post-recon-blues-a-lesson-in-rust-and-fuzzing-open-source/
Hello exploiterz,
Today, I wrote a blog about uncontrolled format string vulnerability which is well-known a security hole in the binary world. But, it is well worth to read this blog to have to have a better understanding to exploiting/bypassing other security mitigation.
Thank you
https://link.medium.com/xUZMiLpdtxb
