Forwarded from 卩ro 爪Cracker
👍2
Forwarded from Biała Bł
Forwarded from 卩ro 爪Cracker
S3Viewer
s3viewer is a free tool for security researchers that lists the content of publicly open storages and helps to identify leaking data. The tool allows you to view all the files in a given storage and download selected files and directories. The goal is to identify the owner of the storage as quickly as possible in order to report that data is leaking from it.
Supported open storage:
▫️ Amazon S3 Buckets
▫️ Microsoft Azure Blobs
▫️ FTP servers with Anonymous access allowed
▫️ HTTP Index Of / Pages (Apache/nginx-style directory listing)
https://github.com/SharonBrizinov/s3viewer
s3viewer is a free tool for security researchers that lists the content of publicly open storages and helps to identify leaking data. The tool allows you to view all the files in a given storage and download selected files and directories. The goal is to identify the owner of the storage as quickly as possible in order to report that data is leaking from it.
Supported open storage:
▫️ Amazon S3 Buckets
▫️ Microsoft Azure Blobs
▫️ FTP servers with Anonymous access allowed
▫️ HTTP Index Of / Pages (Apache/nginx-style directory listing)
https://github.com/SharonBrizinov/s3viewer
Forwarded from 卩ro 爪Cracker
Shadow Workers
Shadow Workers is a free and open source C2 and proxy designed for penetration testers to help in the exploitation of XSS and malicious Service Workers (SW).
A successful exploitation allows you to browse on the targeted application as the victim(s), as long as the SW (agent) is active. A victim does not have to have a browser tab open in the application for the agent to be active.
https://github.com/shadow-workers/shadow-workers
Shadow Workers Site:
https://shadow-workers.github.io/
Shadow Workers is a free and open source C2 and proxy designed for penetration testers to help in the exploitation of XSS and malicious Service Workers (SW).
A successful exploitation allows you to browse on the targeted application as the victim(s), as long as the SW (agent) is active. A victim does not have to have a browser tab open in the application for the agent to be active.
https://github.com/shadow-workers/shadow-workers
Shadow Workers Site:
https://shadow-workers.github.io/
Forwarded from 卩ro 爪Cracker
Active Directory Pentest Mindmap.
https://orange-cyberdefense.github.io/ocd-mindmaps/img/pentest_ad_dark_2022_11.svg
#mindmap #ad #pentesting
https://orange-cyberdefense.github.io/ocd-mindmaps/img/pentest_ad_dark_2022_11.svg
#mindmap #ad #pentesting