Pentester world 2.0
Ir al canal en Telegram
⚠️ DISCLAIMER :- 𝚃𝙷𝙸𝚂 𝙲𝙷𝙰𝙽𝙽𝙴𝙻 𝙳𝙾𝙴𝚂 𝙽𝙾𝚃 𝙿𝚁𝙾𝙼𝙾𝚃𝙴 𝙰𝙽𝚈 𝙸𝙻𝙻𝙴𝙶𝙰𝙻 𝙰𝙲𝚃𝙸𝚅𝙸𝚃𝙸𝙴𝚂 , 𝙸𝚃𝚂 𝙹𝚄𝚂𝚃 𝙵𝙾𝚁 𝙵𝚄𝙽 𝙰𝙽𝙳 𝙴𝙳𝚄𝙲𝙰𝚃𝙸𝙾𝙽𝙰𝙻 𝙿𝚄𝚁𝙿𝙾𝚂𝙴 😇 Welcome pentester world in this group you
Mostrar másEl país no está especificadoTecnologías y Aplicaciones75 932
596
Suscriptores
+724 horas
+407 días
+14430 días
Archivo de publicaciones
IDOR and API-keys🔑Token Hardcode Exposed
https://medium.com/@querylab/idor-and-api-keys-token-hardcode-exposed-201c73d2d667
Setting up your bug bounty scripts with Python and Bash — The subdomain monitoring bot
https://www.codelivly.com/setting-up-your-bug-bounty-scripts-with-python-and-bash/
mx-takeover focuses DNS MX records and detects misconfigured MX records.
https://github.com/musana/mx-takeover
I scanned every package on PyPi and found 57 live AWS keys
https://tomforb.es/i-scanned-every-package-on-pypi-and-found-57-live-aws-keys/
Malicious File Upload Checklist
https://aacle.notion.site/Malicious-File-Upload-Checklist-3cd2b85ff7494efdac47d646b98cdce4
How to automate your initial recon and extend ASM using Sub-Scout
https://medium.com/@akashtesla/how-to-automate-your-initial-recon-and-extend-asm-using-sub-scout-a52de14a2b6a
Disclosing a New Vulnerability in JWT Secret Poisoning (CVE-2022-23529)
https://unit42.paloaltonetworks.com/jsonwebtoken-vulnerability-cve-2022-23529/
Get Started with WiFi Hacking
https://www.cyberick.com/post/get-started-with-wifi-hacking
Cybersecurity events 2023: Your guide to the best bug bounty and hacker meetups
https://blog.intigriti.com/2023/01/12/cybersecurity-events-2023/
ChatGPT hacking tools for bug bounty, pentesting, blue teams, and more
https://medium.com/@david.azad.merian/chatgpt-hacking-tools-for-bug-bounty-pentesting-blue-teams-and-more-c445698d23f
UXSS to Account Takeover in Rushbet
https://fluidattacks.com/blog/uxss-to-account-takeover-rushbet/
All about: Business Logic Bugs
https://sl4x0.medium.com/all-about-business-logic-bugs-803fa0df9eb4
Testing the Performance of User Authentication Flow
https://ddosify.com/blog/testing-the-performance-of-user-authentication-flow
DLL Hijacking using Spartacus, outside of DllMain
https://www.pavel.gr/blog/dll-hijacking-using-spartacus-outside-of-dllmain
#NahamCon2022EU: Attacking Wide Scopes by @Hussein98d
https://www.youtube.com/watch?v=q84ldkGGXeY
Manipulating the WebSocket handshake to exploit vulnerabilities
https://cyberw1ng.medium.com/manipulating-the-websocket-handshake-to-exploit-vulnerabilities-7f8dc3504e9c
Account Take Over Due To AWS Cognito Misconfiguration
https://medium.com/@_deshine_/account-take-over-due-to-aws-cognito-misconfiguration-7b092c667ee3
csprecon
Discover new target domains using Content Security Policy
https://github.com/edoardottt/csprecon
Bug Bytes #190 – BBTips, Attacking Wide Scopes, AWS and Containers
https://blog.intigriti.com/2023/01/18/bug-bytes-190-bbtips-attacking-wide-scopes-aws-and-containers/
