en
Feedback
Hacking Vidhya

Hacking Vidhya

Open in Telegram

We Talk about : Hacking , CTFs , Pentesting , Red & Blue Team etc. Not Allowed: Selling, Carding, Cracking Crypto.

Show more
385
Subscribers
+224 hours
+47 days
+2430 days
Posts Archive
BSides Prishtina 2026 slides. Full PoC code will be published in my blog soon. Enjoy! #conference #hacking #malware #math #physics #programming #threatintel #cybersecurity #research

This video contains the main methodologies attackers use to hack Wordpress websites

lab 1

photo content

πŸ”” A PoC/exploit has been discovered for vulnerability CVE-2026-35616 PT ID: PT-2026-30288 Vendor: Fortinet Product: FortiClientEMS Description: A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. Link: https://github.com/Alaatk/CVE-2026-35616

βž– TUTORIAL βž– How to Scan System Files, Check and Fix Problems Scan and repair system files: sfc /scannow How to Get Help When You Only Know Half a Command Let's say you remember half of a command but forgot the rest. To get help, add /? after what you know: net /? dir /? How to Select a Folder Inside a Drive Automatically Suppose you are in C: drive. Your prompt looks like C:\> Type cd followed by a space, then press the TAB key repeatedly to cycle through available folders. For example: C:\>cd user (user is one folder inside C: drive) Keep pressing TAB to choose different folders.

Switch from NordVPN to Mullvad. Mullvad requires no email or personal information to sign up. Only a randomly generated accou
Switch from NordVPN to Mullvad. Mullvad requires no email or personal information to sign up. Only a randomly generated account number. Switch from X to Mastodon. Mastodon is decentralized and community owned, meaning there are no central algorithms or advertisers tracking your behavior. Switch from Brave to Helium. Helium is a fully de Googled fork of Chrome that comes with uBlock Origin pre installed. Switch from Discord to Matrix. Matrix is an open source, end to end encrypted protocol. Unlike Discord, it’s decentralized, meaning you own your data and your conversations remain private.

The Astra OSINT tool has been updated and is now available free of charge to all users. For any inquiries, please contact @nexaq Start - @Osint_astra_bot use freely

AD in GOAD For OSCP.pdf8.17 MB

192. Metasploit 193. Responder (NTLM hash capture) 194. impacket (MSSQL, Kerberoast) 195. evil-winrm (WinRM shell) 196. kerbrute (Kerberos spraying) 197. netexec (AD enumeration) 198. ysoserial (Java deserialization) 199. PHPGGC (PHP gadget chains) 200. dnstool (ADIDNS manipulation) ⚑ PASSWORD CRACKING 201. John the Ripper 202. Hashcat 203. Hydra 204. Cewl (wordlist generator) 205. changeme (default creds) πŸ“ REPORTING & NOTES 206. Obsidian 207. Markmap 208. asciinema ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 🎯 TOTAL: 200+ tools ready for action! ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ πŸ’‘ Quick Pipeline Example: β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ subfinder | httpx | gau | gf xss | dalfox β”‚ β”‚ amass | naabu | nuclei -t cves/ -severity high β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

0x: ⚑ FULL TOOLS LIST FOR BUG BOUNTY HUNTERS (190+ tools) ⚑ Credit: CH355 INJ3CT0R & Security Community πŸ” RECON & SUBDOMAIN ENUM 1. Amass 2. Subfinder 3. Assetfinder 4. Sublist3r 5. Knockpy 6. Findomain 7. Chaos (ProjectDiscovery) 8. github-subdomains 9. CloudEnum 10. dnscan 11. HostileSubBruteforcer 12. SubzzZ 13. KARMA (Shodan integration) 14. Chaos Reader (Bash script) 15. Subvenkon 🌐 DNS RESOLUTION 16. MassDNS 17. dnsx 18. Shuffledns πŸ“‘ PORT SCANNING 19. Nmap 20. Masscan 21. Naabu 22. RustScan 23. afrog 24. netexec (ex-CrackMapExec) πŸ“‘ HTTP PROBING 25. httpx 26. Aquatone 27. HTTPx 28. pyhttpx 29. EyeWitness 30. XRay πŸ•·οΈ CRAWLING & URL DISCOVERY 31. Katana 32. GoSpider 33. Hakrawler 34. gau 35. waybackurls 36. crt.sh 37. urlfinder 38. waymore 39. gospider 40. Wayback Machine 41. GoogD0rker πŸ”¬ VULNERABILITY SCANNING 42. Nuclei 43. Nikto 44. afrog 45. Kiterunner 46. wpscan 47. CMSmap 48. Sn1per 49. Retire.js 50. LFISuite 51. XSStrike (XSS) 52. tplmap (SSTI) 53. Bibi-Bird (SQLi Auto) 54. Bounty Hunter Pro πŸ”„ PROXIES & INTERCEPTION 55. Burp Suite 56. Caido 57. mitmproxy 58. ZAP (Zed Attack Proxy) 59. Stoat Interceptor 60. RequestBin 61. Webhook.site 62. Beeceptor 63. ngrok 64. Postman Mock Servers πŸ’₯ FUZZING & CONTENT DISCOVERY 65. ffuf 66. feroxbuster 67. Dirsearch 68. Gobuster 69. wfuzz 70. DirBuster 71. bfac 72. patator 73. Race the Web πŸ”‘ PARAMETER DISCOVERY 74. Arjun 75. ParamSpider 76. x8 77. qsreplace 78. eaparam πŸ“œ JS ANALYSIS & SECRETS 79. LinkFinder 80. SecretFinder 81. TruffleHog 82. Gitleaks 83. GitHub Dorks 84. git-secrets 85. GitTools 86. mantra 87. xnLinkFinder 88. JSParser 89. doomxss 90. eefjsf 91. Gitrob 92. sandcastle 93. retire-js ⚠️ XSS (CROSS-SITE SCRIPTING) 94. Dalfox 95. XSStrike 96. kxss 97. crlfuzz 98. knoxssme 99. Magic Header Blind XSS πŸ’‰ SQL INJECTION 100. SQLMap 101. Ghauri 102. NoSQLMap 103. SQLiScanner 104. sqliv 105. SleuthQL 106. mssqli-duet 107. Blinder 108. andor 109. Bibi-Bird 110. waybackSqliScanner 111. ESC (Evil SQL Client) 112. burp-to-sqlmap 113. BurpSQLTruncSanner 114. mssqlproxy 115. sqli-hunter πŸ“€ OOB & TAKEOVERS 116. Interactsh 117. Subzy 118. tko-subs 119. subtake 120. HostileSubBruteforcer 121. Expired Domain Checker (Assetnote) 122. Subdomain Takeover Tool (Assetnote) 123. pingb.in 124. RequestCatcher 125. Hookbin ☁️ CLOUD & MISCONFIGURATION 126. AWSBucketDump 127. S3Scanner 128. GCPBucketBrute 129. bucketfinder 130. CloudEnum 131. Ground Control (SSRF) 132. ssrfDetector πŸ”Œ API & GRAPHQL HUNTING 133. GraphQLmap 134. InQL (Burp ext) 135. Kiterunner 136. Postman 137. Insomnia 138. NoSQLMap πŸ” AUTHENTICATION & TOKEN TESTING 139. jwt_tool 140. AuthMatrix (Burp ext) 141. Autorize (Burp ext) 142. Turbo Intruder (Burp ext) 143. JWT Tool 144. changeme πŸ€– AUTOMATION & FRAMEWORKS 145. bbot 146. reconFTW 147. Sn1per 148. All-in-one-recon 149. Strix (AI-powered) 150. datasploit 151. 3klector 152. Subvenkon 153. getsploit 154. Findsploit 🧩 BURP SUITE EXTENSIONS 155. Logger++ 156. Param Miner 157. JS Miner 158. Turbo Intruder 159. Autorize 160. AuthMatrix 161. InQL 162. BurpSQLTruncSanner 163. burp-to-sqlmap πŸ“š WORDLISTS & RESOURCES 164. SecLists 165. Assetnote Wordlists 166. Domain Search (Assetnote) 167. chaos wordlist generator πŸ“± MOBILE SECURITY 168. Frida 169. MobSF (Mobile Security Framework) 170. Apktool 171. dex2jar 172. objection (runtime exploration) πŸ›‘οΈ SSRF & WAF BYPASS 173. Surf (Assetnote) 174. Nowafpls (Assetnote) 175. Newtowner (Assetnote) 176. CORStest 177. Ground Control 178. ssrfDetector 179. OOB testing tools suite πŸ› οΈ MISC / CLI UTILITIES 180. anew 181. interlace 182. tmux 183. jq 184. unfurl 185. qsreplace (duplicate, keep as note) 186. curl 187. wget 188. grep / sed / awk 189. diff 190. strings 191. tcpdump πŸ”₯ EXPLOITATION & POST-EXPLOITATION

🎯If you want to survive in AI era, you must complete these 5 Free AI Courses by google before the 2026 ends πŸ‘‡ 1️⃣/ Introduction to Generative AI: https://www.skills.google/course_templates/536 2️⃣/ Introduction to LLM: https://www.skills.google/course_templates/539 3️⃣/ Introduction to Responsible AI: https://www.skills.google/course_templates/554 4️⃣/ GenAI Bootcamp: https://cloudonair.withgoogle.com/gen-ai-bootcamp 5️⃣/ Google AI Essentials: https://www.skills.google/paths/2336

How to make PC Hand βœ‹ Gesture Controller (No External device needed) ~ Ready to use Code ~ Simple Steps with Live Demo ~ Control your PC or Laptop with Hand βœ‹ just like Tony Stark 🫠 Repo Link πŸ”— https://github.com/Scripter7899/Control-PC-using-Hand-Gesture

πŸ”₯ Ultimate Bug Bounty Goldmine β€” 1000+ Real Writeups XSS, CSRF, SSRF, IDOR, SQLi, RCE… everything in one place. Real reports from Google, Facebook, PayPal, Microsoft & more. Perfect for learning real-world exploitation, not just theory. GitHub: https://github.com/devanshbatham/Awesome-Bugbounty-Writeups