Pentester world 2.0
Kanalga Telegram’da o‘tish
⚠️ DISCLAIMER :- 𝚃𝙷𝙸𝚂 𝙲𝙷𝙰𝙽𝙽𝙴𝙻 𝙳𝙾𝙴𝚂 𝙽𝙾𝚃 𝙿𝚁𝙾𝙼𝙾𝚃𝙴 𝙰𝙽𝚈 𝙸𝙻𝙻𝙴𝙶𝙰𝙻 𝙰𝙲𝚃𝙸𝚅𝙸𝚃𝙸𝙴𝚂 , 𝙸𝚃𝚂 𝙹𝚄𝚂𝚃 𝙵𝙾𝚁 𝙵𝚄𝙽 𝙰𝙽𝙳 𝙴𝙳𝚄𝙲𝙰𝚃𝙸𝙾𝙽𝙰𝙻 𝙿𝚄𝚁𝙿𝙾𝚂𝙴 😇 Welcome pentester world in this group you
Ko'proq ko'rsatishMamlakat belgilanmaganTexnologiyalar & Aralashmalar75 932
596
Obunachilar
+724 soatlar
+407 kun
+14430 kun
Postlar arxiv
Analysis of CVE-2023-22518 Authentication Bypass in Confluence
https://blog.securelayer7.net/confluence-authentication-bypass/
Executing a Chromecast Exploit – Times Three
https://www.directdefense.com/executing-a-chromecast-exploit-times-three/
Finding that one weird endpoint, with Bambdas
https://portswigger.net/research/finding-that-one-weird-endpoint-with-bambdas
SSRF Via Exploiting Parse URL to Read Local Files (CVE-2022-2216)
https://www.youtube.com/watch?v=_avYi3_Lm9A
Learn to Hack AWS & Kubernetes Clusters (for free)
https://www.youtube.com/watch?v=kUYtY49XZfE
Dashboard for Nuclei Results ProjectDiscovery Cloud Platform Integration
https://blog.projectdiscovery.io/dashboard-for-nuclei-results-projectdiscovery-cloud-platform-integration/
Subdomain Takeover in Azure Trafficmanager for Fun & Profit
https://padsalatushal.medium.com/subdomain-takeover-in-azure-trafficmanager-for-fun-profit-09c858ca3d0e
How to reverse engineer #Xamarin iOS and Android apps
Xamarin is open-source platform that allows to create cross platform apps for iOS, Android, and Windows using C#
https://www.appknox.com/security/xamarin-reverse-engineering-a-guide-for-penetration-testers
Session Token Enumeration in RWS WorldServer
https://www.redteam-pentesting.de/de/advisories/rt-sa-2023-001/-session-token-enumeration-in-rws-worldserver
Why are you not an Elite Smart Contract Security Researcher?
https://www.gmhacker.com/why-are-you-not-an-elite-smart-contract-security-researcher/
Security Should Never Sleep: Adopting Continuous Testing for Evolving Threats
https://www.hackerone.com/vulnerability-management/adopting-continuous-testing-evolving-threats
Extending Burp Suite for fun and profit – The Montoya way – Part 3
https://security.humanativaspa.it/extending-burp-suite-for-fun-and-profit-the-montoya-way-part-3/
Bug Bytes #208 – Burp gets an update, Sharefile gets a CVE and JavaScript files get analysed
https://blog.intigriti.com/2023/07/19/bug-bytes-208-burp-gets-an-update-sharefile-gets-a-cve-and-javascript-files-get-analysed/
Using MiTMProxy as a scriptable pre-proxy for BurpSuite
https://zolder.io/using-mitmproxy-as-a-scriptable-pre-proxy-for-burpsuite
One LFI bypass to rule them all (using base64)
https://matan-h.com/one-lfi-bypass-to-rule-them-all-using-base64/
ChatGPT DAN MODE:
LINK : https://github.com/0xk1h0/ChatGPT_DAN
With the help of this Script you can ask Anything you want to ChatGPT without any problem
Streamlining Websocket Pentesting with wsrepl
https://blog.doyensec.com/2023/07/18/streamlining-websocket-pentesting-with-wsrepl.html
Uncovering SSRF Vulnerabilities Made Simple: Leveraging the Wayback Machine’s Saved Pages
https://xelkomy.medium.com/uncovering-ssrf-vulnerabilities-made-simple-leveraging-the-wayback-machines-saved-pages-e510c68c818
Forager: Browse Millions of Leaked API keys Found With TruffleHog
https://trufflesecurity.com/blog/introducing-forager/
