es
Feedback
HackTheBox Academy

HackTheBox Academy

Canal cerrado

🔴Learn About #Linux 🔴Learn About #Windows 🔴Learn About #CVE 🔴Learn About #EXPLOIT 🔴Learn About #Vulnerability ✅ADMIN : @NullByte0x1

Mostrar más
3 327
Suscriptores
Sin datos24 horas
-207 días
-9330 días
Archivo de publicaciones
⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️ 💠 تست نفوذ را رایگان یاد بگیر . ⭕️ @TryHackBox 📖 کتاب ها و منابع Cyber Security 📚 @LibrarySecOfficial 💠 رودمپ های مختلف از جمله ردتیم بلوتیم تست نفوذ و ... ⭕️ @TryHackBoxOfficial 💠 منابع BlueTeam : ⭕️ @BlueTeamKit 💠 ابزارها و دوره های OSINT ⭕️ @OsintGit 💠 دوره ها و منابع Cyber Security ⭕ @BackupLSO 💠 تمامی منابع Red Team اینجاست! 💠 آموزش توسعه بدافزار (رایگان) ⭕ @RedTeamVillageRTV 💠 منابع CTF و رایت آپ ها و دوره های HackTheBox  : ⭕ @PfkCTF 💠 تمامی پکیج های برنامه نویسی و تست نفوذ در اینجا : ⭕ @cypack 💠 دوره های آموزشی - CVE-Exploit ⭕️ @HackTheBox_Academy 💠 برای اضافه شدن در لیست پیام دهید : 🤖 @Unique_exploitbot ⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️

↔️ CVE-2025-2005 ❗️ WordPress Front End Users Plugin <= 3.2.32 is vulnerable to Arbitrary File Upload 🖥 Exploit - POC 🔎
↔️ CVE-2025-2005 ❗️ WordPress Front End Users Plugin <= 3.2.32 is vulnerable to Arbitrary File Upload 🖥 Exploit - POC 🔎 FOFA:
body="/wp-content/plugins/front-end-only-users/"
#Ethical_Hacker #Exploit #Microsoft #CVE #Pentest #Vulnerability ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

↔️ CVE-2025-24071 ❗️ Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthoriz
↔️ CVE-2025-24071 ❗️ Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network. 🖥 Exploit - POC Hunter:
product.name="Windows Server"
FOFA:
product="Microsoft-Windows"
Shodan:
os:"Windows""
#Ethical_Hacker #Exploit #Microsoft #CVE #Pentest #Vulnerability ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

wstg-v4.2.pdf9.70 MB

📌 WSTG Web Security Testing Guide #BOOK #Pentest #Ethical_Hacker #Hacking #Owasp #WSTG ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @
📌  WSTG
Web Security Testing Guide
#BOOK #Pentest #Ethical_Hacker #Hacking #Owasp #WSTG ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

🔎 Some Google-Dorking To Find Private #BugBounty Programs.
-site:hackerone.com "hackerone.com" "private" ext:txt
"private, invite-only bug bounty program," -site:bugcrowd.com -site:hackerone.com
"may still submit a security bug" "private"
"private" "partnered with HackerOne" "submit" -site:hackerone.com
-site:bugcrowd.com "bugcrowd" "private" ext:txt -site:github.com -site:githubusercontent.com -site:crawler.ninja
"Help us get an idea of what this vulnerability is about"  "vulnerability disclosure" -site:bugcrowd.com -site:hackerone.com -site:intigriti.com -site:yeswehack.com
"Help us get an idea of what this vulnerability is about" "bounty" -site:bugcrowd.com -site:hackerone.com -site:intigriti.com -site:yeswehack.com

🎆🎆🎆🎆🎆🎆🎆🎆🎆🎆🎆🎆 سال جدید بر تمام ایرانیان دنیا مبارک باد با آرزوی آزادی از چنگال رژیم جمهوری تروریست اسلامی Happy Ne
🎆🎆🎆🎆🎆🎆🎆🎆🎆🎆🎆🎆 سال جدید بر تمام ایرانیان دنیا مبارک باد با آرزوی آزادی از چنگال رژیم جمهوری تروریست اسلامی Happy New Year to all Iranians around the world With wishes for freedom from the clutches of the terrorist Islamic Republic regime

سال جدید بر تمام ایرانیان دنیا مبارک باد با آرزوی آزادی از چنگال رژیم جمهوری تروریست اسلامی Happy New Year to all Iranians ar
سال جدید بر تمام ایرانیان دنیا مبارک باد با آرزوی آزادی از چنگال رژیم جمهوری تروریست اسلامی Happy New Year to all Iranians around the world With wishes for freedom from the clutches of the terrorist Islamic Republic regime

⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️ 💠 تست نفوذ را رایگان یاد بگیر . ⭕️ @TryHackBox 📖 کتاب ها و منابع Cyber Security 📚 @LibrarySecOfficial 💠 رودمپ های مختلف از جمله ردتیم بلوتیم تست نفوذ و ... ⭕️ @TryHackBoxOfficial 💠 منابع BlueTeam : ⭕️ @BlueTeamKit 💠 ابزارها و دوره های OSINT ⭕️ @OsintGit 💠 برگزاری دوره های امنیت سایبری ⭕️ @kasraone_com 💠 تمامی منابع Red Team اینجاست! 💠 آموزش توسعه بدافزار (رایگان) ⭕️ @RedTeamVillageRTV 💠 منابع CTF و رایت آپ ها و دوره های HackTheBox  : ⭕️ @PfkCTF 🐍 مینی آموزش های امنیت   : 🪽 @qp_learn 💠 دوره های آموزشی - CVE-Exploit ⭕️ @HackTheBox_Academy 💠 تست نفوذ وب ⭕️ @GitBook_s 💠 برای اضافه شدن در لیست پیام دهید : 🤖 @Delaram_Najafii ⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️

🔠 Jsmon ⭐️ JavaScript Change Monitoring Tool for BugBounty 💫 Features: 💜 Keep Track of endpoints - check them in a configu
🔠 Jsmon ⭐️ JavaScript Change Monitoring Tool for BugBounty 💫 Features: 💜 Keep Track of endpoints - check them in a configurable interval 💜 when endpoints change - send a notification via Telegram 🖥 GitHub #Web #Tools #BugBounty #Pentest #Ethical_Hacker ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

⭐️BYPASS File Extension Whitelists.
⭐️BYPASS File Extension Whitelists.

I Need 1 Person To Purches 1$ For Me For AWS Registration During My Country Is Under U.S.A Sanction And i Cant Do It My Self
I Need 1 Person To Purches 1$ For Me For AWS Registration During My Country Is Under U.S.A Sanction And i Cant Do It My Self Just 1$ Instead, I Iill Give Him My Personal BugBounty Method To Easily Find XSS , Include My Private python Script And my private nuclei template. With This Method You Can Easiliy Find XSS On Any Website If Vulnerability Exist. If You Are Okey,, Send Message To Me TNX @NullByte0x1

⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️ 💠 تست نفوذ را رایگان یاد بگیر . ⭕️ @TryHackBox 📖 کتاب ها و منابع Cyber Security 📚 @LibrarySecOfficial 💠 رودمپ های مختلف از جمله ردتیم بلوتیم تست نفوذ و ... ⭕️ @TryHackBoxOfficial 💠 منابع BlueTeam : ⭕️ @BlueTeamKit 💠 ابزارها و دوره های OSINT ⭕️ @OsintGit 💠 برگزاری دوره های امنیت سایبری ⭕️ @kasraone_com 💠 تمامی منابع Red Team اینجاست! 💠 آموزش توسعه بدافزار (رایگان) ⭕️ @RedTeamVillageRTV 💠 منابع CTF و رایت آپ ها و دوره های HackTheBox : ⭕️ @PfkCTF 💠 دوره های آموزشی - CVE-Exploit ⭕️ @HackTheBox_Academy 💠 آموزش و علم کامپیوتر و هک وب ⭕️ @qp_learn 💠 برای اضافه شدن در لیست پیام دهید : 🤖 @Unique_exploitbot

🖥 XSS BYPASS Think You Want To Execute This: javascript:alert(origin) But In The Server Side, "javascript:" Is Filtered, What We Can Do now? FUZZ: 1. Open Your Browser Console, In This Code You Are Fuzzing This javascript[FUZZ]: 2. Run This Command
log = [];
let anchor = document.createElement('a');
for (let i = 0; i <= 0x10ffff; i++) {
    anchor.href = `javascript${String.fromCodePoint(i)}:`;
    if (anchor.protocol === 'javascript:') {
        log.push(i);
    }
}
3. now call log, Response Will Be This Array(4) [ 9, 10, 13, 58 ] 4. It Will Give You Some Decimal Number 5. Turn This Decimal To HEX and Turn Your HEX To Url_Encode, In Our Case It Will Turn To This: Dec ==> HEX ==> Url_Encode 9 ==> 09 ==> %09 10 ==> 0A ==> %0A 13 ==> 0D ==> %0D 10. Now Put You Results On The Your JavaScript Code: javascript%09:alert(origin) javascript%0A :alert(origin) javascript%0D:alert(origin) *. By Luck, You Can Bypass Filtering, !! You Can Also Fuzz Like This By Changing The Code That I gave You, You Have More Chance [FUZZ]javascript: javas[FUZZ]cript:

🟢 𝗣𝗮𝘆𝗹𝗼𝗮𝗱 𝗪𝗶𝘇𝗮𝗿𝗱 An advanced AI assistant utilizing GPT language models to interpret and generate cybersecurity
🟢 𝗣𝗮𝘆𝗹𝗼𝗮𝗱 𝗪𝗶𝘇𝗮𝗿𝗱 An advanced AI assistant utilizing GPT language models to interpret and generate cybersecurity payloads 🔗 payload-wizard.vercel.app

↔️ CVE-2025-1302 ❗️ Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to
↔️ CVE-2025-1302 ❗️ Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of eval='safe' mode 🖥 Exploit - POC #Ethical_Hacker #Exploit #RCE #CVE #Pentest #Vulnerability ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

🔎 Search for Default Passwords ! pip3 install defaultcreds-cheat-sheet
🔎 Search for Default Passwords !
pip3 install defaultcreds-cheat-sheet

Add This Path To Your WordList For Directory Fuzzing. By Luck, You Will Find Interesting Stuff templates/processed/syslog-tcp
+1
Add This Path To Your WordList For Directory Fuzzing. By Luck, You Will Find Interesting Stuff
templates/processed/syslog-tcp-forward.conf
templates/processed/config.ini
#BugBounty #Fuzz #Ethical_Hacker #Recon #Osint #Tricks #Linux ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️ 💠 تست نفوذ را رایگان یاد بگیر . ⭕️ @TryHackBox 📖 کتاب ها و منابع Cyber Security 📚 @LibrarySecOfficial 💠 رودمپ های مختلف از جمله ردتیم بلوتیم تست نفوذ و ... ⭕️ @TryHackBoxOfficial 💠 منابع BlueTeam : ⭕️ @BlueTeamKit 💠 ابزارها و دوره های OSINT ⭕️ @OsintGit 🪽آموزش  امنیت وب 🪽@qp_learn 💠 برگزاری دوره های امنیت سایبری ⭕ @kasraone_com 💠 تمامی منابع Red Team اینجاست! 💠 آموزش توسعه بدافزار (رایگان) ⭕ @RedTeamVillageRTV 💠 منابع CTF و رایت آپ ها و دوره های HackTheBox  : ⭕ @PfkCTF 💠 تست نفوذ وب ⭕ @GitBook 💠 دوره های آموزشی - CVE-Exploit ⭕️ @HackTheBox_Academy 💠 برای اضافه شدن در لیست پیام دهید : 🤖 @Unique_exploitbot ⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️