Pentester world 2.0
Ir al canal en Telegram
⚠️ DISCLAIMER :- 𝚃𝙷𝙸𝚂 𝙲𝙷𝙰𝙽𝙽𝙴𝙻 𝙳𝙾𝙴𝚂 𝙽𝙾𝚃 𝙿𝚁𝙾𝙼𝙾𝚃𝙴 𝙰𝙽𝚈 𝙸𝙻𝙻𝙴𝙶𝙰𝙻 𝙰𝙲𝚃𝙸𝚅𝙸𝚃𝙸𝙴𝚂 , 𝙸𝚃𝚂 𝙹𝚄𝚂𝚃 𝙵𝙾𝚁 𝙵𝚄𝙽 𝙰𝙽𝙳 𝙴𝙳𝚄𝙲𝙰𝚃𝙸𝙾𝙽𝙰𝙻 𝙿𝚄𝚁𝙿𝙾𝚂𝙴 😇 Welcome pentester world in this group you
Mostrar másEl país no está especificadoTecnologías y Aplicaciones75 932
596
Suscriptores
+724 horas
+407 días
+14430 días
Archivo de publicaciones
How a Cross-Site Scripting Vulnerability Led to Account Takeover
https://www.hackerone.com/vulnerability-management/xss-deep-dive
236 - Bypassing Chromecast Secure-Boot and Exploiting Factorio
https://dayzerosec.com/podcast/236.html
High Signal Detection and Exploitation of Ivanti's Pulse Connect Secure Auth Bypass & RCE
https://blog.assetnote.io/2024/01/19/ivanti-pulse-connect-secure-auth-bypass-rce/
Episode 54: White Box Formulas - Vulnerable Coding Patterns
https://rss.com/podcasts/ctbbpodcast/1304217
Repost from ᴋᴀᴛᴀɴᴀ ꜱᴇᴄᴜʀɪᴛʏ
Top disclosed report on hackerone:-
https://github.com/reddelexc/hackerone-reports/blob/master/tops_by_bug_type/TOPXSS.md
Join:- https://t.me/+5x4RA8x2O_UwMDg5
#report
How Hackers Move Through Networks (with Ligolo)
https://www.youtube.com/watch?v=qou7shRlX_s
Getting Started with iOS Penetration Testing — Part 1: The Setup
https://sahil-security-nerd07.medium.com/getting-started-with-ios-penetration-testing-part-1-the-setup-e322c73ab9a0
“MyFlaw” — Cross Platform 0-Day RCE Vulnerability Discovered in Opera’s Browsers
https://labs.guard.io/myflaw-cross-platform-0-day-rce-vulnerability-discovered-in-operas-browsers-099361a808ab
CVE-2023-43786 & CVE-2023-43787 Vulns in libX11: All You Need To Know
https://jfrog.com/blog/xorg-libx11-vulns-cve-2023-43786-cve-2023-43787-part-one/
The major bug bounty debate: Which department should pay for rewards?
https://blog.intigriti.com/2024/01/18/which-department-should-pay-for-bug-bounty-rewards/
Hacking into a Toyota/Eicher Motors insurance company by exploiting their premium calculator website
https://eaton-works.com/2024/01/17/ttibi-email-hack/
235 - A GitLab Account Takeover and a Coldfusion RCE
https://dayzerosec.com/podcast/235.html
Security Code Review: Finding XML vulnerabilities in Code [1/2]
https://www.muqsitbaig.com/blog/security-code-review-finding-xxes-in-code/
Report security vulnerabilities in any WordPress plugins and themes to earn monthly rewards and earn AXP on your researcher profile to unlock cash rewards as you level up!
Join Patchstack Alliance to learn more: https://discord.gg/FS6b9ghzU3l
If I Started Bug Bounty Hunting in 2024, I'd Do this
https://www.youtube.com/watch?v=z6O6McIDYhU
Deobfuscating Android ARM64 strings with Ghidra: Emulating, Patching, and Automating
https://blog.nviso.eu/2024/01/15/deobfuscating-android-arm64-strings-with-ghidra-emulating-patching-and-automating/
Xiaomi HyperOS BootLoader Bypass
A PoC that exploits a vulnerability to bypass the Xiaomi HyperOS community restrictions of BootLoader unlocked account bindings
https://github.com/MlgmXyysd/Xiaomi-HyperOS-BootLoader-Bypass#xiaomi-hyperos-bootloader-bypass
GrapheneOS: Frequent Android auto-reboots block firmware exploits
https://www.bleepingcomputer.com/news/security/grapheneos-frequent-android-auto-reboots-block-firmware-exploits/
Financial Fraud APK Campaign targeting Chinese users
https://unit42.paloaltonetworks.com/malicious-apks-steal-pii-from-chinese-users/
