Pentester world 2.0
Відкрити в Telegram
⚠️ DISCLAIMER :- 𝚃𝙷𝙸𝚂 𝙲𝙷𝙰𝙽𝙽𝙴𝙻 𝙳𝙾𝙴𝚂 𝙽𝙾𝚃 𝙿𝚁𝙾𝙼𝙾𝚃𝙴 𝙰𝙽𝚈 𝙸𝙻𝙻𝙴𝙶𝙰𝙻 𝙰𝙲𝚃𝙸𝚅𝙸𝚃𝙸𝙴𝚂 , 𝙸𝚃𝚂 𝙹𝚄𝚂𝚃 𝙵𝙾𝚁 𝙵𝚄𝙽 𝙰𝙽𝙳 𝙴𝙳𝚄𝙲𝙰𝚃𝙸𝙾𝙽𝙰𝙻 𝙿𝚄𝚁𝙿𝙾𝚂𝙴 😇 Welcome pentester world in this group you
Показати більшеКраїна не вказанаТехнології та додатки75 932
596
Підписники
+724 години
+407 днів
+14430 днів
Архів дописів
Android DeviceVersionFragment.java Privilege Escalation Exploit for Pixel Watch (CVE-2023-48418)
https://0day.today/exploit/description/39237
Analysis of iOS Info Stealer malware distributed via phishing website
https://medium.com/@icebre4ker/analysis-of-an-info-stealer-chapter-2-the-ios-app-0529e7b45405
Portable Flipper Zero detector
Now you can detect any Flipper Zeros and BLE advertisement spam attacks in vicinity using Android Bluetooth LE Spam app
https://www.mobile-hacker.com/2024/01/09/how-to-detect-flipper-zero-and-bluetooth-advertisement-attacks/
MyEstatePoint Property Search app leaked data on nearly half a million of its users, exposing their names and plain-text passwords
https://cybernews.com/security/myestatepoint-property-search-app-data-leak/
A PoC for the CVE-2023-32530, for iOS/MacOS from Operation Triangulation discovered by Kaspersky
- Tested on: iOS 16.3, 16.3.1, 16.4 and 16.5 (iPhone 14 Pro Max) and macOS 13.1 and 13.4 (MacBook Air M2 2022)
- Fixed in iOS 16.5.1 and macOS 13.4.1
https://github.com/felix-pb/kfd/blob/main/writeups/smith.md
Path traversal to RCE in Android — Mobile Hacking Lab ‘Document Viewer’ write-up
https://ajmal-moochingal.medium.com/path-traversal-to-rce-in-android-mobile-hacking-lab-document-viewer-write-up-ef9226aea1ac
Frida Android Helper: Several handy commands to facilitate common Android pentesting tasks
https://github.com/Hamz-a/frida-android-helper
🔏Hunting & Detecting Remcos RAT with Splunk & Sysmon
🔗https://sakshamtushar.notion.site/Hunting-Detecting-Remcos-RAT-with-Splunk-Sysmon-947cd3c1988b4aba983bcaa6ce7d8897
#splunk #sysmon #detection
Automatic privilege escalation for misconfigured capabilities, sudo and suid binaries using #GTFOBins.
https://github.com/Frissi0n/GTFONow
A collection of real world AI/ML exploits for responsibly disclosed vulnerabilities
https://github.com/protectai/ai-exploits
#AI #exploit
/ Active Directory Advanced Threat Hunting - Identify vulnerabilities before others do
https://github.com/tomwechsler/Active_Directory_Advanced_Threat_Hunting
Pavel Yosifovich - Native Powers: leveraging the native API for power and flexibility
🔗https://www.youtube.com/watch?v=gewNYKjYybA&t=973s
CloakQuest3r is a powerful Python tool meticulously crafted to uncover the true IP address of websites safeguarded by Cloudflare and other alternatives, a widely adopted web security and performance enhancement service.
🔗https://github.com/spyboy-productions/CloakQuest3r
#cloudflare
👩💻Rapidly Search and Hunt through Windows Forensic Artefacts
Chainsaw provides a powerful ‘first-response’ capability to quickly identify threats within Windows forensic artefacts such as Event Logs and the MFT file. Chainsaw offers a generic and fast method of searching through event logs for keywords, and by identifying threats using built-in support for Sigma detection rules, and via custom Chainsaw detection rules.
🔗https://github.com/WithSecureLabs/chainsaw
#windows #forensics
🧩 A list of Python books in English that are FREE 🧩
https://github.com/pamoroso/free-python-books
💠AI Exploits
This repository, ai-exploits, is a collection of exploits and scanning templates for responsibly disclosed vulnerabilities affecting machine learning tools..:
https://github.com/protectai/ai-exploits
CVE-2023-42325, -42326, -42327: XSS and RCE in pfSense Security, 5.4 - 8.8 rating 🔥
By combining vulnerabilities, an attacker can force a user to activate XSS payload and thereby achieve RCE. pfSense CE 2.7.0 and below, pfSense Plus 23.05.1 and below are vulnerable.
Search at Netlas.io:
👉 Link (tag, more results): https://nt.ls/BRDDo
👉 Link (no tag): https://nt.ls/Mr8WD
👉 Dork: http.favicon.hash_sha256:b2dd935235013a51fde0a2afc12ba965952e384b7ab43fe1746cc21c7eafc38c
Vendor's advisory: https://docs.netgate.com/downloads/pfSense-SA-23_08.webgui.asc
📕A Red-Teamer diaries📕
Publicly accessible notes about my pentesting/red teaming experiments tested on several controlled environments/infrastructures that involve playing with various tools and techniques used by penetration testers and redteamers during a security assessment.
https://github.com/ihebski/A-Red-Teamer-diaries
BiBi Wiper: A Malware Analysis Amidst the Israel-Hamas-ISIS Conflict
https://medium.com/@idan_malihi/bibi-wiper-a-malware-analysis-amidst-the-israel-hamas-isis-conflict-42a589f86cda
👁🗨OSINT Tools for Analyzing Suspicious Emails👁🗨
https://www.thunderbird.net/en-US/
https://www.browserling.com/
https://mxtoolbox.com/
https://phishtank.org/
https://www.phishtool.com/
https://centralops.net/co/
https://www.virustotal.com/gui/
https://www.talosintelligence.com/
https://www.abuseipdb.com/
https://urlscan.io/
https://any.run/
https://www.hybrid-analysis.com/
