UNDERCODE SECURITY
226 subscribers
295 photos
1.03K files
1.73K links
πŸ¦‘WELCOME IN UNDERCODE TESTING FOR LEARN HACKING | PROGRAMMING | SECURITY & more..

THIS CHANNEL BY :

@UndercodeTesting
UndercodeTesting.com (official)

@iUndercode
iUndercode.com (iOs)

@Dailycve
DailyCve.com


@UndercodeNews
UndercodeNews.com
Download Telegram
▁ β–‚ β–„ Uπ•Ÿπ”»β’Ίπ«Δ†π”¬π““β“” β–„ β–‚ ▁

πŸ¦‘WEB HACKING TIPS BY UNDERCODE :
#fastTips

1. Use website filtering to bypass the background verification directly, add admin/session.asp or admin/left.asp behind the website

2. When some websites enter the background, a script prompt box will appear, enter: administrator to break! admin means to enter as an administrator.

3. Some websites have opened 3389. Before hacking, connect to 3389 first, try a weak password or blast, and then press the shift key 5 times to see if anyone has installed the back door, and then the social work password.

4. Sometimes a prompt box "Please log in" will pop up when entering the background, copy the address out (you can't copy it), and then put it in the webpage source code analyzer, select the browser-intercept jump check-check to enter the background!

5. Break through the anti-theft chain to access webshell, code:



Copy codecode show as below:

javascript:document.write("<a href='http://www.example.com/uploadfile/1.asp'>fuck</a>")

After pressing enter, click GO to enter the webshell

6. Break through the first-class information monitoring interception system access. When the pony can access but uploading to Malaysia is not possible, you can use Malaysia to merge with a picture first, upload the merged picture, and then access after the database is backed up!

7. When taking the editor's shell, sometimes adding asp|asa|cer|php|aspx and other extensions are filtered when uploading, in fact, as long as adding aaspsp and uploading asp will break through.

8. Sometimes D has guessed the table segment, but when you can’t guess the field, you can go to the background to view the source file, search for ID or type, you can usually find it, and then add a field to D to guess the content to break through .

9. This technique can be used for the social work background password. If the website domain name is: exehack.Net and the administrator name is admin, you can try the passwords "exehack" and "exehack.net" to log in.

10. If the website filters and 1=1 and 1=2 during manual injection, you can use xor 1=1 xor 1=2 to judge.

11. The local structure uploads a one-sentence Trojan. If it prompts "Please select the file you want to upload! [Re-upload]", the file is too small. Open it with Notepad and copy a few more sentences to enlarge the file size before uploading OK.

12. Use ah d to stop the watch, run the field name name and pass can not come out, the display length exceeds 50 or something, if you can't figure it out, you can usually run out of pangolins at this time!

13. Guess the administrator background tips, admin/left.asp, admin/main.asp, admin/top.asp, admin/admin.asp will show the menu navigation, and then Thunder download all links.

14. Know the table name, field, use SQL statement to add a user name and password statement in the ACCESS database:

Insert into admin(user,pwd) values('test','test')

15. When you get the administrator's password, but you can't get the administrator's account, go to the front desk to open a news item and look for words such as "submitter" and "publisher". Generally, the "submitter" is the administrator's Account now.

16. The absolute web path of the website set up by blasting ASP+IIS, assuming that the home page of the website is: http://www.xxxxx/index.asp/ Submit http://www.xxxxx.cn/fkbhvv.aspx/, fkbhvv.aspx is nonexistent.

17. Utilization of source code, many websites use source code downloaded from the Internet. Some webmasters are lazy and don’t change anything, and then upload and open the website. We can download a set, which contains a lot of default information worthy of use.

enjoyβ€οΈπŸ‘πŸ»
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
▁ β–‚ β–„ Uπ•Ÿπ”»β’Ίπ«Δ†π”¬π““β“” β–„ β–‚ ▁
▁ β–‚ β–„ Uπ•Ÿπ”»β’Ίπ«Δ†π”¬π““β“” β–„ β–‚ ▁

πŸ¦‘All Port Numbers :

1 TCP Port Service Multiplexer (TCPMUX)
5 Remote Job Entry (RJE)
7 ECHO
18 Message Send Protocol (MSP)
20 FTP -- Data
21 FTP -- Control
22 SSH Remote Login Protocol
23 Telnet
25 Simple Mail Transfer Protocol (SMTP)
29 MSG ICP
37 Time
42 Host Name Server (Nameserv)
43 WhoIs
49 Login Host Protocol (Login)
53 Domain Name System (DNS)
69 Trivial File Transfer Protocol (TFTP)
70 Gopher Services
79 Finger
80 HTTP
103 X.400 Standard
108 SNA Gateway Access Server
109 POP2
110 POP3
115 Simple File Transfer Protocol (SFTP)
118 SQL Services
119 Newsgroup (NNTP)
137 NetBIOS Name Service
139 NetBIOS Datagram Service
143 Interim Mail Access Protocol (IMAP)
150 NetBIOS Session Service
156 SQL Server
161 SNMP
179 Border Gateway Protocol (BGP)
190 Gateway Access Control Protocol (GACP)
194 Internet Relay Chat (IRC)
197 Directory Location Service (DLS)
389 Lightweight Directory Access Protocol (LDAP)
396 Novell Netware over IP
443 HTTPS
444 Simple Network Paging Protocol (SNPP)
445 Microsoft-DS
458 Apple QuickTime
546 DHCP Client
547 DHCP Server
563 SNEWS
569 MSN
1080 Socks

enjoyβ€οΈπŸ‘πŸ»
powered by wiki
▁ β–‚ β–„ Uπ•Ÿπ”»β’Ίπ«Δ†π”¬π““β“” β–„ β–‚ ▁
Forwarded from WEB UNDERCODE - PRIVATE
TCPDUMP_ a simple cheatsheet.pdf
383.1 KB
TCPDUMP_tutorial
Forwarded from WEB UNDERCODE - PRIVATE
Passive Data Collecting_ Shodan.pdf
1.7 MB
Forwarded from WEB UNDERCODE - PRIVATE
Polyglots_ The Ultimate XSS Payloads..pdf
291.5 KB
Forwarded from WEB UNDERCODE - PRIVATE
RANDOM 2020 HACKING TUTORIALS
Forwarded from Backup Legal Mega
πŸ¦‘ ANOTHER UDEMY 2019-2020 PACK :


1️⃣Code with Mosh - Angular 4 - Beginner to Pro

> https://mega.nz/folder/QZpXSaya#-3jLvY6VRQrRMpCVTA7Xbw

2️⃣Jeff Smith - Instant Email Profits

> https://mega.nz/folder/tV40GA6a#1yrej8OWFuIAUoFYWq_seg

3️⃣Linux Academy - Linux Foundation Certified Engineer (2019)

> https://mega.nz/folder/IIpXmJDT#6ddbNZXgZC7wJEqkOoc16A

4️⃣Lynda - Advertising on Facebook

> https://mega.nz/folder/4IglgAqD#IUlKpdoVJHkqCvSHYX5CEA

5️⃣Lynda - Data Acquisition with LabVIEW

> https://mega.nz/folder/oNYCRYjD#9hWG1OFO2gb4kjhvmVFrRA

6️⃣Lynda - Learning DaVinci Resolve 16

> https://mega.nz/folder/lZhVETKJ#kWG17bGqECh1kjm_GgP-1w

7️⃣Packt - TypeScript for JavaScript Developers

> https://mega.nz/folder/UYxFgByB#aeAhAGEOJVLQnuS8zygsxQ

8️⃣Pluralsight - Securing React Apps with Auth0

> https://mega.nz/folder/FJQHwCBB#A7zmoXg3WCGhIZr4VZGw3Q

9️⃣Pluralsight - Troubleshooting Slow Networks with Wireshark

> https://mega.nz/folder/dRxxFB4a#qTq9iRMUlaPcU7lgt7dyOg

πŸ”ŸSkillshare - Natural Light Portrait Retouching in Photoshop Start to Finish

> https://mega.nz/folder/YFw1GBza#c6nNbrT9AoDYzu6R1l5Ueg

1️⃣1️⃣Stone River eLearning - Common PHP Errors You Will Encounter

> https://mega.nz/folder/tY5yhYjL#UTK35kOS7O4lHiavDQJVxQ

1️⃣2️⃣The Great Courses - Understanding Complexity

> https://mega.nz/folder/MFY0iKTT#iBTtPfd7P5Z_qehHX_o_WA

1️⃣3️⃣Top Secert

> https://mega.nz/folder/hJoxSbwD#oJXfTaxuPk4QCB6owh_Daw

1️⃣4️⃣Udemy - AWS Certified Cloud Practitioner 2019 – In Depth & Hands On!

> https://mega.nz/folder/oYwn2KLA#YDWBHeCtWkGgBMG4SpPklg

1️⃣5️⃣Udemy - Build your first Microservices application using Go and gRPC

> https://mega.nz/folder/oVoXAY4A#2cow0MfEHx5IeIyhNgBs3g

1️⃣6️⃣Udemy - Learn Figma - UIUX Design Essential Training


> https://mega.nz/folder/RNJEQYSL#FtZnp3LM-3ol0eP7FPOEbg

e n j o yβ€οΈπŸ‘πŸ»
LINUX COMMANDS & TOOLS FULL.pdf
198.3 KB
All Popular Linux commands & tools
TERMUX TOOLS .pdf
1.3 MB
All Popular Termux commands & Tools
#requested
Have a good Sunday β€οΈπŸ‘πŸΌ