359
مشترکین
اطلاعاتی وجود ندارد24 ساعت
اطلاعاتی وجود ندارد7 روز
اطلاعاتی وجود ندارد30 روز
در حال بارگیری داده...
کانالهای مشابه
هیچ دادهای
مشکلی وجود دارد؟ لطفاً صفحه را تازه کنید یا با مدیر پشتیبانی ما تماس بگیرید.
ابر برچسبها
هیچ دادهای
مشکلی وجود دارد؟ لطفاً صفحه را تازه کنید یا با مدیر پشتیبانی ما تماس بگیرید.
اشارات ورودی و خروجی
---
---
---
---
---
---
جذب مشترکین
مه '24
مه '24
+362
در 0 کانالها
| تاریخ | رشد مشترکین | اشارات | کانالها | |
| 30 مه | +2 | |||
| 29 مه | 0 | |||
| 28 مه | +1 |
پستهای کانال
Resources through which you can find information about your target by having an IP or MAC address:
1. Metrics.torproject.org
– checks whether the IP address was used as a node for transmitting traffic to Tor, you must specify the date;
2. HostHunter
– discovers and extracts host names from a set of target IP addresses;
3. Сyberhubarchive
– an archive intended only for research and security testing, it contains IP addresses of Skype accounts;
4. Recon.secapps.com
– automatic search and creation of relationship maps;
5. Check.torproject.org –
– will find a list of all Tor exit nodes in the last 16 hours that could contact the IP
#osint @infosecbd23
| 2 | https://youtu.be/fDACXq1mrzo?si=NYFW8qhFJvtDkCkc | 309 |
| 3 | Facebook is updating....
Don't panic. | 499 |
| 4 | https://youtu.be/ir8jlslUGA0 | 533 |
| 5 | https://youtu.be/lGdtOn6thc0?si=Z_Kwdg1usWQPWvti | 537 |
| 6 | Free labs to train your skills in pentesting/CTF and Computer Science Skills.
Best wishes for successful education!!
-> Try Hack Me https://tryhackme.com
-> Attack-Defense https://attackdefense.com
-> alert to win https://alf.nu/alert1
-> CMD Challenge https://cmdchallenge.com
-> Exploration Education https://exploit.education
-> Google CTF https://capturetheflag.withgoogle.com
-> HackTheBox https://www.hackthebox.com/
-> Defendtheweb https://defendtheweb.net/
-> Hacksplaining https://www.hacksplaining.com/lessons
-> Hacker101 https://ctf.hacker101.com
-> Hacker Security https://capturetheflag.com.br
-> Hacking-Lab https://www.hacking-lab.com/events/
-> HSTRIKE https://hstrike.com
-> ImmersiveLabs https://immersivelabs.com
-> NewbieContest https://www.newbiecontest.org/
-> OverTheWire http://overthewire.org
-> Practical Pentest Labs https://practicalpentestlabs.com
-> Pentestlab https://pentesterlab.com
-> Penetration Testing Practice Labs http://www.amanhardikar.com/mindmaps/Practice.html
-> PentestIT LAB https://lab.pentestit.ru
-> PicoCTF https://picoctf.com
-> PWNABLE https://pwnable.kr/play.php
-> Root-Me https://www.root-me.org
-> SANS Challenger https://www.holidayhackchallenge.com
-> SmashTheStack http://smashthestack.org/wargames.html
-> The Cryptopals Crypto Challenges https://cryptopals.com/
-> Vulnhub https://www.vulnhub.com
-> W3Challs https://w3challs.com
-> WeChall http://www.wechall.net
-> HackerRank https://www.hackerrank.com
-> kaggle https://www.kaggle.com/
-> Zenk-Security
https://www.zenk-security.com/ | 535 |
| 7 | https://youtu.be/FRF0f5v3tcE?si=AfsF5bqyzRl4pfm1 | 419 |
| 8 | 🧵 Complete Cybersecurity Professional Roadmap 🧵
1. Introduction to Ethical Hacking
- Definition
- Purpose
- Types of Hackers
- Legal and Ethical Considerations
2. Networking Basics
- TCP/IP
- OSI Model
- Subnetting
- DNS
- DHCP
3. Operating Systems
- Linux
- Windows
- macOS
- Command Line Basics
4. Cybersecurity Fundamentals
- Encryption
- Firewalls
- Antivirus
- IDS/IPS
5. Programming Languages
- Python
- Javascript
- Bash Scripting
- SQL
- C/ C++/ Java/ Ruby
6. Scanning and Enumeration
- Port Scanning
- Service Enumeration
- Vulnerability Scanning
7. Exploitation
- Common Vulnerabilities and Exploits
- Metasploit Framework
- Buffer Overflows
8. Web Application Security
- OWASP Top Ten
- SQL Injection
- Cross-Site Scripting (XSS)
9. Wireless Network Hacking
- Wi-Fi Security
- WEP, WPA, WPA2
- Wireless Attacks
10. Social Engineering
- Phishing
- Spear Phishing
- Social Engineering Toolkit (SET)
11. Sniffing and Spoofing
- Man-in-the-Middle Attacks
- ARP Spoofing
- DNS Spoofing
12. Malware Analysis
- Types of Malware
- Sandbox Analysis
- Signature-Based and Behavior-Based Detection
13. Incident Response and Handling
- Incident Response Process
- Digital Forensics
- Chain of Custody
14. Penetration Testing
- Types of Penetration Testing
- Methodology
- Reporting
15. Cryptography
- Symmetric and Asymmetric Encryption
- Hashing Algorithms
- Digital Signatures
16. Mobile Hacking
- Android and iOS Security
- Mobile Application Security
17. Cloud Security
- AWS, Azure, Google Cloud
- Security Best Practices
18. IoT Security
- Internet of Things Risks
- Securing IoT Devices
19. Legal and Compliance
- Computer Fraud and Abuse Act (CFAA)
- GDPR, HIPAA, PCI DSS
20. Cybersecurity Tools
- Nmap, Wireshark, Burp Suite
- Snort, Nessus, Aircrack-ng
21. Career Path and Certifications
- Certified Ethical Hacker (CEH)
- Offensive Security Certified Professional (OSCP)
- CISSP, CompTIA Security+ | 553 |
| 9 | 🔥Google Dorking🔥
Discovering hidden information online is a key aspect of staying ahead in #cybersecurity. 🌐✨ Here is some effective #GoogleDorking commands to help you up your game in #ethicalhacking and #ctf :
✨Cache Search: Find cached versions of websites with cache:example.com.
✨Site-specific Search: Narrow down results to a specific domain using site:example.com.
✨Filetype Filters: Locate specific file types, like PDFs, using filetype:pdf.
✨Date Range Filtering: Refine results within a specific date range with filetype:pdf & (before:2022-01-01 after:2023-01-01).
✨Related Sites: Discover websites related to a specific domain with related:www.google.com.
✨Text and Anchor Searches: Find pages with specific text or anchor text using intext:"Google Dork Query" and inanchor:"cyber attacks".
Combination Search: Combine queries for comprehensive results, like example1 | example2 - dork and example1 | example2.
✨Title and Directory Searches: Target specific titles or directories in search results with intitle:"Index of /", intitle:"Apache2 Debian Default Page", and intitle:"Index of /" or intitle:"Browse Directory".
✨Targeted Site and Filetype Searches: Identify specific file types on a particular site with site:target.com filetype:php, site:target.com filetype:aspx, and site:target.com filetype:swf (Shockwave Flash).
Always remember to use these commands responsibly and ethically.
#happyhunting
#infosecbd #infosec #infosec_bd #ethicalhacking #cybersecurityawareness #cybersecurityresouces #ctf #cybersecuritycommunity #cybersecuritycommunitybangladesh | 603 |
| 10 | you guys can follow our LinkedIn page for more resources and guidelines.😊
https://www.linkedin.com/company/infosec-bd23/?viewAsMember=true | 496 |
| 11 | بدون متن... | 549 |
| 12 | 🔍Search Engines for Hackers
1. Censys
🔗https://search.censys.io/
2. Shodan
🔗https://www.shodan.io/
3. Greynoise
🔗https://www.greynoise.io/
4. ZoomEye
🔗https://www.zoomeye.org/
5. Hunter
🔗https://hunter.io/
6. Onyphe
🔗https://www.onyphe.io/
🔖#infosec #cybersecurity #hacking #pentesting #security | 505 |
| 13 | بدون متن... | 540 |
| 14 | https://youtu.be/PEzZ2rtvRDk?si=zmzljn0dmyyV0ex3 | 513 |
| 15 | https://youtu.be/sfbxRO8D1QM?si=DgxyI94OTdMwu4Jc | 502 |
| 16 | 🔰List of terms used in the field of hacking.
🚩Adware − Adware is software designed to force pre-chosen ads to display on your system.
🚩Attack − An attack is an action that is done on a system to get its access and extract sensitive data.
🚩Back door − A back door, or trap door, is a hidden entry to a computing device or software that bypasses security measures, such as logins and password protections.
🚩Bot − A bot is a program that automates an action so that it can be done repeatedly at a much higher rate for a more sustained period than a human operator could do it. For example, sending HTTP, FTP or Telnet at a higher rate or calling script to create objects at a higher rate.
🚩Botnet − A botnet, also known as zombie army, is a group of computers controlled without their owners’ knowledge. Botnets are used to send spam or make denial of service attacks.
🚩Brute force attack − A brute force attack is an automated and the simplest kind of method to gain access to a system or website. It tries different combination of usernames and passwords, over and over again, until it gets in.
🚩Buffer Overflow − Buffer Overflow is a flaw that occurs when more data is written to a block of memory, or buffer, than the buffer is allocated to hold.
🚩Clone phishing − Clone phishing is the modification of an existing, legitimate email with a false link to trick the recipient into providing personal information.
🚩Cracker − A cracker is one who modifies the software to access the features which are considered undesirable by the person cracking the software, especially copy protection features.
🚩Denial of service attack (DoS) − A denial of service (DoS) attack is a malicious attempt to make a server or a network resource unavailable to users, usually by temporarily interrupting or suspending the services of a host connected to the Internet.
🚩DDoS − Distributed denial of service attack.
🚩Exploit Kit − An exploit kit is software system designed to run on web servers, with the purpose of identifying software vulnerabilities in client machines communicating with it and exploiting discovered vulnerabilities to upload and execute malicious code on the client.
🚩Exploit − Exploit is a piece of software, a chunk of data, or a sequence of commands that takes advantage of a bug or vulnerability to compromise the security of a computer or network system.
🚩Firewall − A firewall is a filter designed to keep unwanted intruders outside a computer system or network while allowing safe communication between systems and users on the inside of the firewall.
🚩Keystroke logging − Keystroke logging is the process of tracking the keys which are pressed on a computer (and which touchscreen points are used). It is simply the map of a computer/human interface. It is used by gray and black hat hackers to record login IDs and passwords. Keyloggers are usually secreted onto a device using a Trojan delivered by a phishing email.
🚩Logic bomb − A virus secreted into a system that triggers a malicious action when certain conditions are met. The most common version is the time bomb.
🚩Malware − Malware is an umbrella term used to refer to a variety of forms of hostile or intrusive software, including computer viruses, worms, Trojan horses, ransomware, spyware, adware, scareware, and other malicious programs.
🚩Master Program − A master program is the program a black hat hacker uses to remotely transmit commands to infected zombie drones, normally to carry out Denial of Service attacks or spam attacks.
🚩Phishing − Phishing is an e-mail fraud method in which the perpetrator sends out legitimate-looking emails, in an attempt to gather personal and financial information from recipients.
🚩Phreaker − Phreakers are considered the original computer hackers and they are those who break into the telephone network illegally, typically to make free long distance phone calls or to tap phone lines.
====================
Join Our Telegram Channel
❶ https://t.me/infosecbd23 | 505 |
| 17 | 🚨 100 web vulnerabilities, categorized into various types:
Injection Vulnerabilities:
1. SQL Injection (SQLi)
2. Cross-Site Scripting (XSS)
3. Cross-Site Request Forgery (CSRF)
4. Remote Code Execution (RCE)
5. Command Injection
6. XML Injection
7. LDAP Injection
8. XPath Injection
9. HTML Injection
10. Server-Side Includes (SSI) Injection
11. OS Command Injection
12. Blind SQL Injection
13. Server-Side Template Injection (SSTI)
Broken Authentication and Session Management:
14. Session Fixation
15. Brute Force Attack
16. Session Hijacking
17. Password Cracking
18. Weak Password Storage
19. Insecure Authentication
20. Cookie Theft
21. Credential Reuse
Sensitive Data Exposure:
22. Inadequate Encryption
23. Insecure Direct Object References (IDOR)
24. Data Leakage
25. Unencrypted Data Storage
26. Missing Security Headers
27. Insecure File Handling
Security Misconfiguration:
28. Default Passwords
29. Directory Listing
30. Unprotected API Endpoints
31. Open Ports and Services
32. Improper Access Controls
33. Information Disclosure
34. Unpatched Software
35. Misconfigured CORS
36. HTTP Security Headers Misconfiguration
XML-Related Vulnerabilities:
37. XML External Entity (XXE) Injection
38. XML Entity Expansion (XEE)
39. XML Bomb
Broken Access Control:
40. Inadequate Authorization
41. Privilege Escalation
42. Insecure Direct Object References
43. Forceful Browsing
44. Missing Function-Level Access Control
Insecure Deserialization:
45. Remote Code Execution via Deserialization
46. Data Tampering
47. Object Injection
API Security Issues:
48. Insecure API Endpoints
49. API Key Exposure
50. Lack of Rate Limiting
51. Inadequate Input Validation
Insecure Communication:
52. Man-in-the-Middle (MITM) Attack
53. Insufficient Transport Layer Security
54. Insecure SSL/TLS Configuration
55. Insecure Communication Protocols
Client-Side Vulnerabilities:
56. DOM-based XSS
57. Insecure Cross-Origin Communication
58. Browser Cache Poisoning
59. Clickjacking
60. HTML5 Security Issues
Denial of Service (DoS):
61. Distributed Denial of Service (DDoS)
62. Application Layer DoS
63. Resource Exhaustion
64. Slowloris Attack
65. XML Denial of Service
Other Web Vulnerabilities:
66. Server-Side Request Forgery (SSRF)
67. HTTP Parameter Pollution (HPP)
68. Insecure Redirects and Forwards
69. File Inclusion Vulnerabilities
70. Security Header Bypass
71. Clickjacking
72. Inadequate Session Timeout
73. Insufficient Logging and Monitoring
74. Business Logic Vulnerabilities
75. API Abuse
Mobile Web Vulnerabilities:
76. Insecure Data Storage on Mobile Devices
77. Insecure Data Transmission on Mobile Devices
78. Insecure Mobile API Endpoints
79. Mobile App Reverse Engineering
IoT Web Vulnerabilities:
80. Insecure IoT Device Management
81. Weak Authentication on IoT Devices
82. IoT Device Vulnerabilities
Web of Things (WoT) Vulnerabilities:
83. Unauthorized Access to Smart Homes
84. IoT Data Privacy Issues
Authentication Bypass:
85. Insecure "Remember Me" Functionality
86. CAPTCHA Bypass
Server-Side Request Forgery (SSRF):
87. Blind SSRF
88. Time-Based Blind SSRF
Content Spoofing:
89. MIME Sniffing
90. X-Content-Type-Options Bypass
91. Content Security Policy (CSP) Bypass
Business Logic Flaws:
92. Inconsistent Validation
93. Race Conditions
94. Order Processing Vulnerabilities
95. Price Manipulation
96. Account Enumeration
97. User-Based Flaws
Zero-Day Vulnerabilities:
98. Unknown Vulnerabilities
99. Unpatched Vulnerabilities
100. Day-Zero Exploits | 474 |
| 18 | https://vt.tiktok.com/ZSNrXDsTR/ | 345 |
| 19 | Ethical Hacking Freelancing using ChatGPT. ChatGPT ব্যবহার করে কীভাবে ফ্রীল্যান্সিং এর কাজগুলো করা যায় সে বিষয়ে বিস্তারিত জানতে পুরো ভিডিওটি দেখুন। এই ভিডিওটি Beginner🔰 দের জন্য আশা করি সহায়ক হবে।
~
#InfoSecBD #cybersecurity #onlinesecurity #technology #bugbounty #ethicalhacking
#freelancing #upwork #fiver
Subscribe Our YouTube Channel: https://youtube.com/@infosecbd
Join Our Telegram Channel:
https://t.me/infosecbd23
Like Our Facebook Page: https://www.facebook.com/infosecbd23/
Join Our Facebook Group: https://www.facebook.com/groups/infosecbd23
Follow us on Instagram: https://www.instagram.com/infosec.bd/
Follow us on Tiktok: https://www.tiktok.com/@infosec.bd
https://www.instagram.com/reel/CytRML_pOyT/?igshid=MTc4MmM1YmI2Ng== | 397 |
| 20 | 🔰Reccon Tool
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities
GitHub: https://github.com/six2dez/reconftw
====================
Join Our Telegram Channel
❶ https://t.me/infosecbd23 | 417 |
