AfroSec
620 subscribers
324 photos
23 videos
6 files
162 links
hello friend
am AfroSec | AASTU dropout | cybersecurity enthusiast | CRTOM | CRTA | passionate abt Red Teaming :)))

portifolio : soon....
file : @Afr0Files
Download Telegram
#insta

who can relate to this πŸ˜‚?
@AfroSec
😁9🀝5
😊our new dormmate

@AfroSec
πŸ₯°7😁1
am into cats but this one...... i cant resist him πŸ˜„πŸ˜Š

@AfroSec
😁5πŸ‘€2❀1
Advent of Cyber 2024Cyber is right around the corner! Have you all registered ???

@AfroSec
hey fam
i got u something today especially If you're into blue teaming, this site is perfect for you!
It has incredible contentβ€”check it out and enjoy the journey ahead!

letsdefend.io

@AfroSec
πŸ‘2
While learning about a vuln called insecure deserialization from PwnFunction, I noticed a Base64-encoded string in the comment section and decided to decode it.

I think it might be some kind of CTF rabbit hole! πŸ‡πŸ”

mtsm πŸ˜’πŸ˜‚

@AfroSec
😁4
#Advent_Of_Cyber
One down! πŸ’ͺ😁😊

it was pretty easy and straightforward. The downloaded ZIP file contained two files. One was a Windows shortcut file designed to download malicious malware from a remote serverβ€”in this case, GitHub. This malware was intended to harvest sensitive information. 😊😊

@AfroSec
πŸ‘3πŸ”₯1
Speaking of stealing someone's password πŸ‘¨β€πŸ’»πŸ‘©β€πŸ’»
Which method do you think is better: cookie hijacking, cracking, or social engineering? πŸ€”πŸ§πŸ§

I'll leave the question to you 😊 Have a wonderful night! Byeee πŸ«‘πŸ’€

@AfroSec
Forwarded from BePractical
While i have shared a lot of my bug bounty success story with you all, let me share story of my failures!

You know, When i was starting bug bounty hunting, I was unable to report a valid vulnerability for 6 month straight! Every report that i submitted got marked as informative, not applicable and duplicate! At that time, i was very demotivated, stressed and depressed. I was thinking, "Maybe bug bounty is not my thing" but suddenly, I started questioning myself:
1. Didn't i wanted to learn cyber security because it is my passion?
2. Am i only focusing on reporting vulnerabilities instead of improving my skills?

By asking these questions, I understand one thing: I need to switch my focus on learning, improving and hacking instead of getting demotivated because i was not getting any rewards! And eventually, I was able to get that first vulnerability and now i can easily say that i am the better version of myself than before!
#Day_2

Finished Day 2 of the Advent of Cyber challenge! . It was about detecting a brute-force attack and investigating compromised systems using a SIEM tool. The attacker immediately ran a PowerShell command after gaining access.

Feels good to play detective, huh? 😁
@AfroSec
πŸ”₯4πŸ‘1
Day 3 is done!
I was a bit busy, but it was easy and straight forward. The challenge was about log analysis, and the web app was vulnerable to RCE via file upload.

@AfroSec
πŸ‘1πŸ‘1
Forwarded from Programmer Jokes
🀣5
Day 5 - Done! 😊

it was all about the XXE vulnerability in web apps. It was super fun! If you want to dive deeper into this vuln, I recommend checking out the XXE room on TryHackMe, as well as resources like PortSwigger and PwnFunction's YouTube video [vid ].

I skipped Day 4 and Day 6 because my internet was like shit, but hopefully, I’ll catch up tomorrow!

@AfroSec
πŸ‘1
Forwarded from α―€ CONTENT ZONE α―€ (Π‘Π΅Π· воТдя) (π“π‘πž 𝐀π₯π©π‘πšπ’πžπœ)
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯4
You ever have one of those moments where you just stop and think, "Wow, how did I not know this?" πŸ˜‚

Well, today I realized something obvious: TOR isn’t just nameβ€”it’s actually an abbreviation for "The Onion Router!" 🀯 All this time, I thought it was just a catchy title. Silly me, right?

And to make things even better,i barely remember what WiFi stands for... πŸ€” Guess I need to dig into that next.

@AfroSec
😁4
Forwarded from Mira
Collection of resources to learn cyber-security, and pentest in general

https://github.com/Nickyie/Cybersecurity-Resources