AfroSec
788 subscribers
463 photos
33 videos
7 files
239 links
hello friend
am AfroSec | AASTU dropout | cybersecurity enthusiast | CRTO | CRTOM | CRTA | passionate about Red Teaming :)

portifolio : https://afrosec.et
blog: https://blog.afrosec.et
file : @Afr0Files
Download Telegram
hey fam
i got u something today especially If you're into blue teaming, this site is perfect for you!
It has incredible contentโ€”check it out and enjoy the journey ahead!

letsdefend.io

@AfroSec
๐Ÿ‘2
While learning about a vuln called insecure deserialization from PwnFunction, I noticed a Base64-encoded string in the comment section and decided to decode it.

I think it might be some kind of CTF rabbit hole! ๐Ÿ‡๐Ÿ”

mtsm ๐Ÿ˜ข๐Ÿ˜‚

@AfroSec
๐Ÿ˜4
#Advent_Of_Cyber
One down! ๐Ÿ’ช๐Ÿ˜๐Ÿ˜Š

it was pretty easy and straightforward. The downloaded ZIP file contained two files. One was a Windows shortcut file designed to download malicious malware from a remote serverโ€”in this case, GitHub. This malware was intended to harvest sensitive information. ๐Ÿ˜Š๐Ÿ˜Š

@AfroSec
๐Ÿ‘3๐Ÿ”ฅ1
Speaking of stealing someone's password ๐Ÿ‘จโ€๐Ÿ’ป๐Ÿ‘ฉโ€๐Ÿ’ป
Which method do you think is better: cookie hijacking, cracking, or social engineering? ๐Ÿค”๐Ÿง๐Ÿง

I'll leave the question to you ๐Ÿ˜Š Have a wonderful night! Byeee ๐Ÿซก๐Ÿ’ค

@AfroSec
Forwarded from BePractical
While i have shared a lot of my bug bounty success story with you all, let me share story of my failures!

You know, When i was starting bug bounty hunting, I was unable to report a valid vulnerability for 6 month straight! Every report that i submitted got marked as informative, not applicable and duplicate! At that time, i was very demotivated, stressed and depressed. I was thinking, "Maybe bug bounty is not my thing" but suddenly, I started questioning myself:
1. Didn't i wanted to learn cyber security because it is my passion?
2. Am i only focusing on reporting vulnerabilities instead of improving my skills?

By asking these questions, I understand one thing: I need to switch my focus on learning, improving and hacking instead of getting demotivated because i was not getting any rewards! And eventually, I was able to get that first vulnerability and now i can easily say that i am the better version of myself than before!
#Day_2

Finished Day 2 of the Advent of Cyber challenge! . It was about detecting a brute-force attack and investigating compromised systems using a SIEM tool. The attacker immediately ran a PowerShell command after gaining access.

Feels good to play detective, huh? ๐Ÿ˜
@AfroSec
๐Ÿ”ฅ4๐Ÿ‘1
Day 3 is done!
I was a bit busy, but it was easy and straight forward. The challenge was about log analysis, and the web app was vulnerable to RCE via file upload.

@AfroSec
๐Ÿ‘1๐Ÿ‘1
Forwarded from Programmer Jokes
๐Ÿคฃ5
Day 5 - Done! ๐Ÿ˜Š

it was all about the XXE vulnerability in web apps. It was super fun! If you want to dive deeper into this vuln, I recommend checking out the XXE room on TryHackMe, as well as resources like PortSwigger and PwnFunction's YouTube video [vid ].

I skipped Day 4 and Day 6 because my internet was like shit, but hopefully, Iโ€™ll catch up tomorrow!

@AfroSec
๐Ÿ‘1
Forwarded from แฏค CONTENT ZONE แฏค (ะ‘ะตะท ะฒะพะถะดั) (๐“๐ก๐ž ๐€๐ฅ๐ฉ๐ก๐š๐’๐ž๐œ)
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ4
You ever have one of those moments where you just stop and think, "Wow, how did I not know this?" ๐Ÿ˜‚

Well, today I realized something obvious: TOR isnโ€™t just nameโ€”itโ€™s actually an abbreviation for "The Onion Router!" ๐Ÿคฏ All this time, I thought it was just a catchy title. Silly me, right?

And to make things even better,i barely remember what WiFi stands for... ๐Ÿค” Guess I need to dig into that next.

@AfroSec
๐Ÿ˜4
Forwarded from Mira
Collection of resources to learn cyber-security, and pentest in general

https://github.com/Nickyie/Cybersecurity-Resources
End of Time
K-391 & Alan Walker & Ahrix
Back in high school, I was totally hooked on EDM. ๐ŸŽง๐Ÿ”ฅ I couldnโ€™t get enough of artists like Alan Walker, Martin Garrix, Marshmello, Avicii, and more.

I was that guy who spammed our Telegram group with songs from these legends. ๐Ÿ˜… My classmates had no escapeโ€”EDM vibes were everywhere.after two years, and guess what? I just stumbled upon that same group and all the songs I shared back then

Listening to them now, it feels so freshโ€” Itโ€™s such a vibe to remember about the good old days before AASTU ๐Ÿ˜‚. Nostalgia hits differently when it comes with beats, drops, and memories! ๐Ÿ•บ
and this song is one of'em .

Whatโ€™s your throwback from high school? wanna drop it in the comment section ?

@AfroSec
๐Ÿ”ฅ4
Oh, and btw, Iโ€™m still in love with EDM!๐Ÿ˜๐Ÿ˜

@AfroSec
โค1
goodnight Afro fam ๐Ÿ’ค๐Ÿ’ค๐Ÿ’ค๐Ÿ’ค๐Ÿ’ค

@AfroSec
๐Ÿ˜5
logs don't lie โ€“ ๐Ÿ˜the blue teamers' motto

@AfroSec
๐Ÿ˜2
Forwarded from Luna's pathway๐Ÿค— (Luna)
Hello,I need your attention for a second!
One of our own, Daniel Basazinew, a talented software engineer and an incredible human being, is facing a life-threatening challenge. Daniel has been diagnosed with End-Stage Renal Disease (ESRD), and both of his kidneys have failed. He urgently needs a kidney transplant, but the cost of the procedure abroad is $40,000.

Daniel has always been there for others, mentoring, helping, and inspiring those around him. Now, it's our turn to help him in his time of need.

Here's how you can support:
Donate via GoFundMe: https://www.gofundme.com/f/urgent-support-daniels-kidney-transplant


Local Donations (Ethiopia):

Commercial Bank of Ethiopia: 1000259462774 (Daniel Basazinew)

Telebirr: 0941219026 (Zinash)

Share the campaign with your networks to spread the word.
Let's rally together to save Danielโ€™s life. Every little bit countsโ€”thank you for your support!

content credit : Nahom Abera
โค2