AGENTZ SECURITY!
Open in Telegram
481
Subscribers
No data24 hours
+27 days
+1430 days
Posts Archive
API FUZZING LISTS
Out of turn post, a very tasty collection of fuzzing wordlists for the API
Description of this list from the author:
744,000+ endpoints
357,000+ object properties
211,000+ object names
127,000+ query parameters
74,000+ parameter values
35,000+ path parameters
8,300+ headers
5,300+ paths
880+ common ports
XST (Cross-Site Tracing) Injection itu salah satu teknik hacking yang maininnya lewat metode HTTP TRACE. Intinya, kalau server nge-izinin metode TRACE, kita bisa nyoba buat nyedot balik request yang kita kirim.
Contohnya:
curl -X TRACE http://target.com -H "Test: Fck"
Nah, kalau server respons balik request kita, artinya dia nge-echo header yang kita kirim. Ini bahaya banget, terutama kalau barengan sama XSS (Cross-Site Scripting). Soalnya attacker bisa inject skrip buat nyedot data sensitif kayak cookie atau token.
Kalau server bales semua header request, bisa jadi celah buat maling session pengguna. Makanya, TRACE method sebaiknya dimatiin di server buat ngehindarin serangan ini.
simpelnya, TRACE = ngintip balik request kita sendiri, dan kalau dipake buat hal jahat, bisa nyolong informasi sensitif.
#Exclusive 🔥
Zero Point Security: Red Team Ops [CRTO] 2025
Info : https://training.zeropointsecurity.co.uk/courses/red-team-ops#pricing
Linux nc-ph-3575.boss.gov.ss 5.14.0-503.23.2.el9_5.x86_64 #1 SMP PREEMPT_DYNAMIC Wed Feb 12 05:52:18 EST 2025 x86_64 x86_64 x86_64 GNU/Linux
www.jtiuganda.go.ug | Goverment Uganda Got Hacked!
Server security information
Server software: Apache
Loaded Apache modules: mod_rewrite, mod_mime, mod_headers, mod_expires, mod_auth_basic
Disabled PHP Functions: none
cURL support: enabled
Readable /etc/passwd: yes [view]
Readable /etc/shadow: no
OS version: Linux version 6.10.2-x86_64-linode165 (maker@build.linode.com) (gcc (Ubuntu 9.4.0-1ubuntu1~20.04.2) 9.4.0, GNU ld (GNU Binutils for Ubuntu) 2.34) #1 SMP PREEMPT_DYNAMIC Tue Jul 30 15:03:21 EDT 2024
Distr name:
\S
Kernel \r on an \m
Userful: gcc, lcc, cc, ld, make, php, perl, python, ruby, tar, gzip, bzip, bzip2, nc, locate, suidperl
Danger: kav, nod32, bdcored, uvscan, sav, drwebd, clamd, rkhunter, chkrootkit, iptables, ipfw, tripwire, shieldcc, portsentry, snort, ossec, lidsadm, tcplodg, sxid, logcheck, logwatch, sysmask, zmbscap, sawmill, wormscan, ninja
Downloaders: wget, fetch, lynx, links, curl, get, lwp-mirror
HDD space:
Filesystem Size Used Avail Use% Mounted on
/dev/root 315G 285G 15G 96% /
devtmpfs 7.8G 0 7.8G 0% /dev
tmpfs 7.9G 0 7.9G 0% /dev/shm
tmpfs 7.9G 674M 7.2G 9% /run
tmpfs 7.9G 0 7.9G 0% /sys/fs/cgroup
/dev/loop0 3.9G 316K 3.7G 1% /tmp
Hosts:
127.0.0.1 localhost localhost.localdomain localhost4 localhost4.localdomain4
::1 localhost localhost.localdomain localhost6 localhost6.localdomain6
172.105.72.236 node2937 template.myfcloud.com template li2033-236.members.linode.com li2033-236
139.162.152.130 node1811 node1811.myfcloud.com node2937
139.162.187.227 node1811.danskictmanagement.com node1811 node2937.myfcloud.com node2937
https://lnx.studiocimolino.eu/README.txt
Linux hlpi1ws-c316s08.ad.aruba.it 5.15.0-130-generic #140-Ubuntu SMP Wed Dec 18 17:59:53 UTC 2024 x86_64 x86_64 x86_64 GNU/Linux
Shell Access : https://testing.jeffreytest.inception-example.com/ALFA_DATA/alfacgiapi/old-index.php
PHP : 8.1.31
IP Server : 172.31.25.216
HDD Total : 484.4 GB
Free : 443.02 GB [41.38 GB]
Doamin Web : testing.jeffreytest.inception-example.com
MySQL : OFF
CURL : ON
Sistem Operasi : Linux 35-175-194-72.cprapid.com 6.8.0-1015-aws #16~22.04.1-Ubuntu SMP Mon Aug 19 19:38:17 UTC 2024 x86_64
uid=1005(jeffreytest) gid=1007(jeffreytest) groups=1007(jeffreytest)
uid=1005(jeffreytest) gid=1007(jeffreytest) groups=1007(jeffreytest)
