Pentester world 2.0
Открыть в Telegram
⚠️ DISCLAIMER :- 𝚃𝙷𝙸𝚂 𝙲𝙷𝙰𝙽𝙽𝙴𝙻 𝙳𝙾𝙴𝚂 𝙽𝙾𝚃 𝙿𝚁𝙾𝙼𝙾𝚃𝙴 𝙰𝙽𝚈 𝙸𝙻𝙻𝙴𝙶𝙰𝙻 𝙰𝙲𝚃𝙸𝚅𝙸𝚃𝙸𝙴𝚂 , 𝙸𝚃𝚂 𝙹𝚄𝚂𝚃 𝙵𝙾𝚁 𝙵𝚄𝙽 𝙰𝙽𝙳 𝙴𝙳𝚄𝙲𝙰𝚃𝙸𝙾𝙽𝙰𝙻 𝙿𝚄𝚁𝙿𝙾𝚂𝙴 😇 Welcome pentester world in this group you
БольшеСтрана не указанаТехнологии и приложения75 932
596
Подписчики
+724 часа
+407 дней
+14430 дней
Архив постов
Red teaming tools and techniques
https://github.com/Christbowel/Red-Teamer
Blues teaming tools and techniques
https://github.com/Christbowel/Blue-Teamer
Embedding Frida in iOS TestFlight Apps
https://naehrdine.blogspot.com/2023/02/embedding-frida-in-ios-testflight-apps.html
Android Banker Deep Dive (Part 1)
Fully reverse engineering of a Android Banker trojan from start to finish
https://youtu.be/Vs9Z3NDnVT8
𝘿𝙖𝙧𝙠𝙬𝙚𝙗 𝙈𝙤𝙣𝙞𝙩𝙤𝙧𝙞𝙣𝙜 & 𝙊𝙎𝙄𝙉𝙏 𝙄𝙣𝙫𝙚𝙨𝙩𝙞𝙜𝙖𝙩𝙞𝙤𝙣𝙨 🔍
Link :-
https://softwaretrailers.medium.com/dark-web-monitoring-and-osint-investigations-for-online-protection-a021c541c9a4
Safe harbor legal framework for ethical hacker officially launches in Belgium
https://blog.intigriti.com/2023/02/15/eu-whistleblower-directive-officially-launches-in-belgium/
❤️RedTeam-Tools❤️
This github repository contains a collection of 120+ tools and resources that can be useful for red teaming activities
https://github.com/A-poc/RedTeam-Tools
🌟18 Threat Hunting and OSINT Tools🌟
A good list of threat hunting and OSINT tools !
1. https://www.shodan.io/ - Search for devices connected to the internet and their vulnerabilities
2. https://prowl.lupovis.io/ - Free IP search & identifications of IoC and IoA
3. https://intelx.io/ - Search engine for data archives.
4. https://netlas.io/ - Search and monitor devices connected to the internet
5. https://urlscan.io/ - Scan a website incoming and outgoing links and assets
6. https://fullhunt.io/ - Identify an attack surface
7. https://www.zoomeye.org/ - Cyberspace search engine, users can search for network devices
8. https://leakix.net/ - Identify public data leaks
9. https://www.greynoise.io/ - Search for devices connected to the internet.
10. https://search.censys.io/ - Get information about devices connected to the internet
11. https://hunter.io/ - Search for email addresses
12. https://www.criminalip.io/ - Search for devices connected to the internet. Monitor potential attack vectors.
13. https://www.wigle.net/ - Map wireless access points around the world
14. https://grep.app/ - Grep across a half million github repos
15. https://www.onyphe.io/ - Search for devices connected to the internet and monitor attack vector
16. https://vulners.com/ - A vulnerability database .
17. https://pulsedive.com/ - Search for devices connected to the internet
18. grayhatwarfare.com - Search for S3 buckets that are public
❤️100 Red Team Projects for Pentesters and Network Managers❤️
https://github.com/kurogai/100-redteam-projects
🔮Kali-Purple🔮
💜The ultimate SOC in a box💜
https://gitlab.com/kalilinux/documentation/kali-purple
MediaTek Android information disclosure | CVE-2023-20606
By executing a specially-crafted application, an attacker could exploit this vulnerability to obtain sensitive information.
Affected Software Versions: Android 12.0, 12.1
https://www.redpacketsecurity.com/mediatek-android-information-disclosure-cve-2023-20606/
SQL injection vulnerabilities in Owncloud Android app - CVE-2023-24804, CVE-2023-23948
The Owncloud Android app uses content providers to manage its data. The provider FileContentProvider has SQL injection vulnerabilities that allow malicious applications or users in the same device to obtain internal information of the app
https://securitylab.github.com/advisories/GHSL-2022-059_GHSL-2022-060_Owncloud_Android_app/
Top-Tier Bug Bounty Hunter Mindset - Yassine Aboukir KEYNOTE at BSides Ahmedabad 2022
https://www.youtube.com/watch?v=QhpqBnu5MXo
OffensivePipeline allows to download, compile (without Visual Studio) and obfuscate C# tools for Red Team exercises.
https://github.com/Aetsu/OffensivePipeline
HubSpot Full Account Takeover in Bug Bounty
https://omar0x01.medium.com/hubspot-full-account-takeover-in-bug-bounty-4e2047914ab5
#webshell
A python based webshell discovery and decoder for static packet captures. Designed to be extended for easy identification and decoding of many webshell families.
https://github.com/fredflinch/mothra
Demonstrating the value of entropy as a detection mechanism for obfuscated webshells.
https://github.com/mttaggart/webshell-entropy
ExploitLeakedHandle: Identify and exploit leaked handles for local privilege escalation
https://github.com/0x00Check/ExploitLeakedHandle
CVE-2023-0669
GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object.
https://github.com/0xf4n9x/CVE-2023-0669
#cve
ConfFuzz
Fuzzing for Interface Vulnerabilities
ConfFuzz is an in-memory fuzzer aimed at detecting interface vulnerabilities in compartmentalized contexts. ConfFuzz is a cooperation between the University of Manchester, University Politehnica of Bucharest, Rice University, and Unikraft.io. It has been accepted to appear in NDSS'23.
https://github.com/conffuzz/conffuzz
http://w3snoop.com
Getting detailed information about website:
- general domain info;
- valuation ($);
- popularity;
- traffic;
- revenue;
- security (WOT rating, McAfee WebAdvisor Rating etc)
and more.
#osint
