Pentester world 2.0
Open in Telegram
β οΈ DISCLAIMER :- ππ·πΈπ π²π·π°π½π½π΄π» π³πΎπ΄π π½πΎπ πΏππΎπΌπΎππ΄ π°π½π πΈπ»π»π΄πΆπ°π» π°π²ππΈπ πΈππΈπ΄π , πΈππ πΉπππ π΅πΎπ π΅ππ½ π°π½π³ π΄π³ππ²π°ππΈπΎπ½π°π» πΏπππΏπΎππ΄ π Welcome pentester world in this group you
Show moreThe country is not specifiedTechnologies & Applications75 932
596
Subscribers
+724 hours
+407 days
+14430 days
Posts Archive
How a Cross-Site Scripting Vulnerability Led to Account Takeover
https://www.hackerone.com/vulnerability-management/xss-deep-dive
236 - Bypassing Chromecast Secure-Boot and Exploiting Factorio
https://dayzerosec.com/podcast/236.html
High Signal Detection and Exploitation of Ivanti's Pulse Connect Secure Auth Bypass & RCE
https://blog.assetnote.io/2024/01/19/ivanti-pulse-connect-secure-auth-bypass-rce/
Episode 54: White Box Formulas - Vulnerable Coding Patterns
https://rss.com/podcasts/ctbbpodcast/1304217
Repost from α΄α΄α΄α΄Ι΄α΄ κ±α΄α΄α΄ΚΙͺα΄Κ
Top disclosed report on hackerone:-
https://github.com/reddelexc/hackerone-reports/blob/master/tops_by_bug_type/TOPXSS.md
Join:- https://t.me/+5x4RA8x2O_UwMDg5
#report
How Hackers Move Through Networks (with Ligolo)
https://www.youtube.com/watch?v=qou7shRlX_s
Getting Started with iOS Penetration TestingβββPart 1: The Setup
https://sahil-security-nerd07.medium.com/getting-started-with-ios-penetration-testing-part-1-the-setup-e322c73ab9a0
βMyFlawββββCross Platform 0-Day RCE Vulnerability Discovered in Operaβs Browsers
https://labs.guard.io/myflaw-cross-platform-0-day-rce-vulnerability-discovered-in-operas-browsers-099361a808ab
CVE-2023-43786 & CVE-2023-43787 Vulns in libX11: All You Need To Know
https://jfrog.com/blog/xorg-libx11-vulns-cve-2023-43786-cve-2023-43787-part-one/
The major bug bounty debate: Which department should pay for rewards?
https://blog.intigriti.com/2024/01/18/which-department-should-pay-for-bug-bounty-rewards/
Hacking into a Toyota/Eicher Motors insurance company by exploiting their premium calculator website
https://eaton-works.com/2024/01/17/ttibi-email-hack/
235 - A GitLab Account Takeover and a Coldfusion RCE
https://dayzerosec.com/podcast/235.html
Security Code Review: Finding XML vulnerabilities in Codeβ [1/2]
https://www.muqsitbaig.com/blog/security-code-review-finding-xxes-in-code/
Report security vulnerabilities in any WordPress plugins and themes to earn monthly rewards and earn AXP on your researcher profile to unlock cash rewards as you level up!
Join Patchstack Alliance to learn more: https://discord.gg/FS6b9ghzU3l
If I Started Bug Bounty Hunting in 2024, I'd Do this
https://www.youtube.com/watch?v=z6O6McIDYhU
Deobfuscating Android ARM64 strings with Ghidra: Emulating, Patching, and Automating
https://blog.nviso.eu/2024/01/15/deobfuscating-android-arm64-strings-with-ghidra-emulating-patching-and-automating/
Xiaomi HyperOS BootLoader Bypass
A PoC that exploits a vulnerability to bypass the Xiaomi HyperOS community restrictions of BootLoader unlocked account bindings
https://github.com/MlgmXyysd/Xiaomi-HyperOS-BootLoader-Bypass#xiaomi-hyperos-bootloader-bypass
GrapheneOS: Frequent Android auto-reboots block firmware exploits
https://www.bleepingcomputer.com/news/security/grapheneos-frequent-android-auto-reboots-block-firmware-exploits/
Financial Fraud APK Campaign targeting Chinese users
https://unit42.paloaltonetworks.com/malicious-apks-steal-pii-from-chinese-users/
