3 261
Підписники
+224 години
-87 днів
-2230 днів
Архів дописів
3 261
Repost from آموزش امنیت سایبری | پنتیفای
📚 خاموشی در لایه فیزیکی جمرها چطور ارتباطات بیسیم رو فلج میکنن ؟
📝 توی این مقاله با یکی از مهم ترین حملات دنیای ارتباطات رادیویی و جنگ الکترونیک یعنی جمینگ (Jamming) آشنا میشین؛ جایی که مهاجم با ارسال سیگنالهای نویز پرقدرت، بدون نیاز به شکستن رمزنگاری، ارتباطات وایفای، بلوتوث، GPS و فرکانسهای رادیویی رو مختل و از دسترس خارج میکنه
📖 توی این مقاله با این موارد آشنا میشین :
🔹 مفهوم جمر، رفتار امواج الکترومغناطیسی و نسبت سیگنال به نویز (SNR)
🔹 تاریخچه مسدودکنندههای فرکانسی از جنگهای جهانی تا تراشههای امروزی
🔹 بررسی فنی اختلال در وایفای و بلوتوث و تفاوت اون با حملات Deauth
🔹 آشنایی با انواع جمرهای کاربردی مثل GPS، دیتای سلولار، ضد پهپاد و SDR
🔹 بررسی معماری سختافزاری مدارهای مسدودکننده RF
🔹 روشهای شناسایی، مقابله و مقاومسازی شبکههای بیسیم در برابر پارازیت
🌐 مطالعه مقاله :
کلیک کنید 🎓
@pentifyteam | pentify.ir
3 261
#tools
#AIOps
"Scanning the Harness: An Empirical Study of Supply-Chain Defects in AI Coding-Agent Configurations", Sep 2026.
]-> data and scripts
]-> tool
// AI coding agents such as Claude Code, Cursor, GitHub Copilot, and OpenAI Codex are configured through artifacts developers write and share: instruction files, skills, hooks, MCP server declarations, subagents. This harness is a dependency layer installed from marketplaces and public repositories, running with the developer's privileges, with no lockfile, no install-time check, and no vocabulary for what a component may do
3 261
Search for all leaked keys/secrets using one regex!
regex: https://gist.github.com/h4x0r-dz/be69c7533075ab0d3f0c9b97f7c93a59
#BugBounty #bugbountytip
3 261
Repost from Linuxfarci | لینوکس فارسی
🛡 nexHarden | Linux Security Hardener
یه ابزار سبک و متنباز برای بررسی امنیت سیستمهای لینوکسی و پیدا کردن تنظیمات ناامن.
با nexHarden میتونی بخشهایی مثل:
🔐 تنظیمات SSH
🔥 Firewall
👤 کاربران و سطح دسترسیها
⚙️ تنظیمات سیستم
📦 سرویسهای فعال
رو بررسی کنی و پیشنهادهای Hardening بگیری و اعمال کنی.
ساخته شده با Python برای اینکه بررسیهای امنیتی سیستم Linux سادهتر و سریعتر انجام بشه. 🐧
⭐️ اگه برات مفیده، یه Star کوچیک هم به پروژه بده.
🔗 GitHub:
https://github.com/7hekasra/nexHarden
#Linux #LinuxSecurity #Python #CyberSecurity #Hardening #OpenSource #nexHarden
3 261
CVE-2026-75650: Adobe Commerce and Magento Open Source RCE vulnerability (StyleSmuggler) exploited in the wild, 10.0 rating 🔥
Recently disclosed vulnerability in Adobe Commerce and Magento Open Source allows an unauthenticated attacker to execute arbitrary code. This vulnerability is being actively exploited in the wild!
Search at Netlas.io:
👉 Link: https://nt.ls/bX5dx
👉 Dork: tag.name:"magento"
Read more :
https://sansec.io/research/stylesmuggler-0day
3 261
Repost from City of learn📚 | شهر یادگیری
مسابقه فتح پرچم بلو bluCTF
جایزهها:
🥇 ۱۳۳۳۷ میلیگرم طلا
🥈 ۷۷۷۰ میلیگرم طلا
🥉 ۴۴۴۰ میلیگرم طلا
برای ثبتنام وارد شوید:
🔗 https://ctf.blubank.com
🧠 City Of Learn
3 261
CVE-2026-67276
MikroTrick lab PoC — CVE-2026-67276 (RouterOS SSH public-key auth bypass)
@buglearn
3 261
Bug Bounty Tip – SQL Injection
Hard-to-exploit SQL injection?
This time-based payload worked when others failed:
''||(select 1 from (select pg_sleep(6))x)||'
Add it to your SQL wordlist.
Download - https://github.com/orwagodfather/SQL-Wordlist/blob/main/sql.txt
@buglearn3 261
🕵️♂️ هنوز برای پیدا کردن یه رایتاپ درست و حسابی، بین صدتا سایت و لینک گم میشی؟
تبلیغات، لینکهای مرده، محتوای تکراری و رایتاپهای بیکیفیت رو بذار کنار. ⚡️
رایتاپ ماینر مثل یک ماینر داخل
سطح وب میچرخه و رایتاپهای
ارزشمند رو شکار میکنه؛
از CTF و Bug Bounty گرفته تا تحلیلهای امنیتی و تکنیکهای فنی.
🎯 ما میگردیم، فیلتر میکنیم و رایتاپهای مفید رو میاریم اینجا.
Less Searching. More Hacking. 🧑💻
🔻 وارد معدن شو:
@writeup_miner
3 261
🐛 Bug Bounty Writeup
300$ ETag Bounty: https://medium.com/@sari.mmusab/300-etag-bounty-9f6e9aecc12e
The Bug Bounty Recon Cheat Sheet: A Practical Workflow From Domain to Attack Surface: https://infosecwriteups.com/the-bug-bounty-recon-cheat-sheet-a-practical-workflow-from-domain-to-attack-surface-6ff3b44a00d0
️The Organization Had Users… But Nobody Could Own It: https://medium.com/@0xMo7areb/%EF%B8%8Fthe-organization-had-users-but-nobody-could-own-it-ae9e7513a969
PentestCode: The Multi-Agent AI That Automates Penetration Testing: https://medium.com/@pentesterclubpvtltd/pentestcode-the-multi-agent-ai-that-automates-penetration-testing-8223a8e73446
Belajar dari Celah RCE di NASA VDP: Dokumentasi dan Analisis Teknis: https://medium.com/@radith614/belajar-dari-celah-rce-di-nasa-vdp-dokumentasi-dan-analisis-teknis-0a61473cab43
Ten Years of SSTI Disclosures. $4,300 in Public Bounties.: https://rajnamdev.medium.com/ten-years-of-ssti-disclosures-4-300-in-public-bounties-8d93a8ddc2ff
So You Want to Hunt on the Dark Web? A Practical Field Guide for Independent Researchers: https://medium.com/@paritoshblogs/so-you-want-to-hunt-on-the-dark-web-a-practical-field-guide-for-independent-researchers-3e39f4dc75fd
How I Found an SQL Injection Vulnerability at Universitas Negeri Jakarta (UNJ): https://medium.com/@adtynll/how-i-found-an-sql-injection-vulnerability-at-universitas-negeri-jakarta-unj-f372203ffa71
Smali By bithowl: Chapter 9 Register Architecture: https://medium.com/@bithowl/smali-by-bithowl-chapter-9-register-architecture-d737d22e4f3d
@buglearn
