Pentester world 2.0
Kanalga Telegramβda oβtish
β οΈ DISCLAIMER :- ππ·πΈπ π²π·π°π½π½π΄π» π³πΎπ΄π π½πΎπ πΏππΎπΌπΎππ΄ π°π½π πΈπ»π»π΄πΆπ°π» π°π²ππΈπ πΈππΈπ΄π , πΈππ πΉπππ π΅πΎπ π΅ππ½ π°π½π³ π΄π³ππ²π°ππΈπΎπ½π°π» πΏπππΏπΎππ΄ π Welcome pentester world in this group you
Ko'proq ko'rsatishMamlakat belgilanmaganTexnologiyalar & Aralashmalar75 932
596
Obunachilar
+724 soatlar
+407 kun
+14430 kun
Postlar arxiv
Pentration Testing, Beginners To Expert
Massive Web Application Penetration Testing Bug Bounty Notes:
https://github.com/xalgord/Massive-Web-Application-Penetration-Testing-Bug-Bounty-Notes
Join :- https://t.me/pentesterworld578
Repost from α΄α΄α΄α΄Ι΄α΄ κ±α΄α΄α΄ΚΙͺα΄Κ
Open Redirect Oneliner:-
cat waybackurls_result.txt|grep -a -i \=http|qsreplace 'http://evil.com'|while read host do;do curl -s -L $host -I|grep "evil.com" && echo "$host \033[0;31m[+]VULNERABLE-TO-OPEN-REDIRECT-ATTACK\n";doneHardware Hacking to Bypass BIOS Passwords
https://cybercx.co.nz/blog/bypassing-bios-password/
Join :- https://t.me/pentesterworld578
Collection of Bash scripts designed for comprehensive security audits and network mapping of Active Directory (AD) environments. The scripts automate various tasks including LDAP querying, Kerberos ticket analysis, SMB enumeration, and exploitation of known vulnerabilities like Zerologon and PetitPotam
https://github.com/emrekybs/AD-AssessmentKit
Join:-https://t.me/pentesterworld578
Repost from α΄α΄α΄α΄Ι΄α΄ κ±α΄α΄α΄ΚΙͺα΄Κ
Vmware Workstation Keys
Vmware Workstation 15 Pro:
ZG51K-25FE1-H81ZP-95XGT-WV2C0VMware Workstation-16.x.x-15.x.x FU512-2DG1H-M85QZ-U7Z5T-PY8ZD CU3MA-2LG1N-48EGQ-9GNGZ-QG0UD GV7N2-DQZ00-4897Y-27ZNX-NV0TD YZ718-4REEQ-08DHQ-JNYQC-ZQRD0 GZ3N0-6CX0L-H80UP-FPM59-NKAD4 YY31H-6EYEJ-480VZ-VXXZC-QF2E0 ZG51K-25FE1-H81ZP-95XGT-WV2C0 VG30H-2AX11-H88FQ-CQXGZ-M6AY4 CU7J2-4KG8J-489TY-X6XGX-MAUX2 FY780-64E90-0845Z-1DWQ9-XPRC0 UF312-07W82-H89XZ-7FPGE-XUH80 AA3DH-0PYD1-0803P-X4Z7V-PGHR4 VMWare Workstation 16: YF390-0HF8P-M81RQ-2DXQE-M2UT6 Vmware Workstation 16 Pro: 6JZPU-P8NYG-11Q12-ZZZ5R-ZQEGZ ZF3R0-FHED2-M80TY-8QYGC-NPKYF YF390-0HF8P-M81RQ-2DXQE-M2UT6 ZF71R-DMX85-08DQY-8YMNC-PPHV8 AZ3E8-DCD8J-0842Z-N6NZE-XPKYF FC11K-00DE0-0800Z-04Z5E-MC8T6 VMware Workstation 17 Pro MC60H-DWHD5-H80U9-6V85M-8280D 4A4RR-813DK-M81A9-4U35H-06KND NZ4RR-FTK5H-H81C1-Q30QH-1V2LA 4C21U-2KK9Q-M8130-4V2QH-CF810 4Y09U-AJK97-089Z0-A3054-83KLA Join:- https://t.me/+5x4RA8x2O_UwMDg5 #vmware
π Awesome GPTs (Agents) for Cybersecurity
The "Awesome GPTs (Agents) Repo" represents an initial effort to compile a comprehensive list of GPT agents focused on cybersecurity (offensive and defensive), created by the community.
πhttps://github.com/fr0gger/Awesome-GPT-Agents
Join :- https://t.me/pentesterworld578
#gpt
Livestream Hangout with NetworkChuck
https://www.youtube.com/watch?v=eP3iS_DmR4A
Repost from α΄α΄α΄α΄Ι΄α΄ κ±α΄α΄α΄ΚΙͺα΄Κ
Tools collection:-
Subdomain enum tools we can use!
1. bbot
2. amass
3. crt.sh
4. source codes
5. knockpy
6. subfinder
7. aquatone
8. subdomainzer
9. altDNS
10. Security Trails api
Bruteforcing tools we can use !
1. Go-buster
2. dirsearch
3. ssb - ssh brute
4. Callow -custom tools for logins
5. Ncrack - network
Spidering tools we can use !
1. Spider in Burp
2. Paramspider
3. Scarpy
4. Go_spider
5. aspider
6. ParamPAMPAM
Dir Enum tools we can use !
1. Dirb
2. Gobuster
3. Dirsearch
Wordlists we can use !
1. seclists
2. Assetnote
Join:- https://t.me/+5x4RA8x2O_UwMDg5
#tools
Dangling CNAME/Orphaned CNAME leads P2 on Google VRP
https://medium.com/@jerryhackgather/dangling-cname-orphaned-cname-leads-p2-on-google-vrp-fca8964d983c
Join :- https://t.me/pentesterworld578
Getting Started with iOS Penetration Testing ββPart 1: The Setup
https://sahil-security-nerd07.medium.com/getting-started-with-ios-penetration-testing-part-1-the-setup-e322c73ab9a0
Join:- https://t.me/pentesterworld578
Repost from α΄α΄α΄α΄Ι΄α΄ κ±α΄α΄α΄ΚΙͺα΄Κ
Nmap Oneliners :-
# Pull Resolved Hosts From .gnmap Files
grep "Host: " *.gnmap|sed 's/\t/ /g'|tr -s '[:space:]'|cut -d" " -f3|awk '!/\(\)/'|sort -u|sed 's/(//g;s/)//g'
# Pull Alive Host IPs Based on Open Port From .gnmap Files
grep "Host:.*Ports:.*/open/" *.gnmap|cut -d" " -f2
# Pull Alive Host IPs Based on Status Form .gnmap Files (Varying Results Based On Scan Flags [i.e.: -Pn])
grep "Host:.*Status: Up" *.gnmap|cut -d" " -f2
# Common Discovery Scan String (Known RTT)
nmap -Pn -R -sS -p 21-23,25,53,111,137,139,445,80,443,3389,5900,8080,8443 --min-rtt-timeout <Lowest RTT Time + 25ms> \
--max-rtt-timeout <Highest RTT Time + 100ms> --max-retries 1 --max-scan-delay 0 -oA <Output Filename> -vvv \
--open -iL <Host List>
# Common Discovery Scan String (Unknown RTT)
nmap -Pn -R -sS -p 21-23,25,53,111,137,139,445,80,443,3389,5900,8080,8443 --max-retries 1 \
--max-scan-delay 0 -oA <Output Filename> -vvv --open -iL <Host List>
Reference:- https://gist.github.com/sente/eb52bfceafe2abec4011
Join:- https://t.me/+5x4RA8x2O_UwMDg5
#onelinerMavenGate: a supply chain attack method for Java and Android applications
https://blog.oversecured.com/Introducing-MavenGate-a-supply-chain-attack-method-for-Java-and-Android-applications/
Bigpanzi botnet infects 170,000 Android TV boxes with malware
https://blog.xlab.qianxin.com/bigpanzi-exposed-hidden-cyber-threat-behind-your-stb/
Repost from α΄α΄α΄α΄Ι΄α΄ κ±α΄α΄α΄ΚΙͺα΄Κ
Where to find LFI
Endpoints/Parameter examples:
-> ?dir={payload}
-> ?cat={payload}
-> ?path={payload}
-> ?file={payload}
-> ?document={payload}
-> ?view={payload}
-> ?action={payload}
Join:- https://t.me/+5x4RA8x2O_UwMDg5
#lfi
