CYBER TRICKS ZONE ๐Ÿ‡ฎ๐Ÿ‡ณ
3.71K subscribers
814 photos
252 videos
662 files
2.74K links
This channel/community aims to provide free courses related to programming,web development, cyber security, ethical hacking and many more tech related stuff and news #programming, #coding, #ethicalhacking #cybersecurity. About: @about_cybertrickszone
Download Telegram
Here is an updated list of free cybersecurity certifications you can get to kickstart your career in cybersecurity :

1. Introduction to Cybersecurity[https://lnkd.in/gS4ncPmX]
2. Cybersecurity Essentials[https://lnkd.in/gSQqNY9h]
3. Introduction to Dark Web, Anonymity, and Cryptocurrency[https://lnkd.in/g8FSgRtH]
4. Ethical Hacking Essentials (EHE)[https://lnkd.in/gG4RgHA9]
5. Networking Essentials[https://lnkd.in/g6JMDGGe]
6. Website Hacking Techniques[https://lnkd.in/gUdjnpRW]
7. Digital Forensics Essentials (DFE)[https://lnkd.in/gkMpN--B]
8. Network Defense Essentials (NDE)[https://lnkd.in/gnvw7Fiy]
9. Android Bug Bounty Hunting: Hunt Like a Rat[https://lnkd.in/g76Jnzmi]
10. Certified in Cybersecurityโ„  - CC[https://lnkd.in/gB2fGdfC]
11. 20+ Free AWS Certs Related to Cybersecurity[https://lnkd.in/gfsqsQKz]
12. Cyber crime:[https://lnkd.in/gdiS-pqK]
13. Cyber Forensics:[https://lnkd.in/g22nfYaN]
14. Network Security:[https://lnkd.in/gXB4nTx5]





#infosec #cybersecurity #pentesting #ethicalhacking #informationsecurity #learningeveryday #networksecurity
Social engineering is that branch of the Cybersecurity space that has always intrigued my interest and curiousity. I mean manipulating human emotions and luring them into getting hacked - Absolutely intriguing!!

And With the recent growing number of social engineering attacks, phising being one of the major one, Curiousity about social engineering has grown as well.

It really doesn't matters how smart we are, well planned social engineering attacks can trick us all. And yet there is no solution to install on the human brain that could warn and prevent them from those attacks.

so what's there that can be done apart from security awareness trainings? An approach to actively test the readiness of our people, processes and technology and awareness against those social engineering attacks can be helpful. And gain more knowledge on the nature and approach of various social engineering attacks.

Here's some great resources for social engineering I came across which lists various:
- Online Courses
- Capture the Flag
- Psychology Books
- Books
- Documentation
- Tools
- Miscellaneus
- OSINT

Awesome Social Engineering : https://lnkd.in/g485SKzj





#infosec #CyberSecurity #pentesting #ethicalhacking #learningeveryday #cybersec #skillsdevelopment #socialengineering
Activate t
Cybersecurity Resources: Blue Team, Red Team, CTF, and more!

A collection of cybersecurity-related resources to add skills development to our Free Time Activities list!

The resources are well organized in three different categories as follows:

โ€ข Cybersecurity & Hacking Documentaries
โ€ข Cybersecurity-YouTube Channels
โ€ข Cybersecurity-Labs [RED TEAM/BLUE TEAM and CTF Skills]

Kindly note that there are several labs in the list which are completely FREE to use; however, for some services, such as #hackthebox VIP access, we need to pay a fee to enjoy all the best features and benefits!

Cybersecurity-Resources: https://lnkd.in/gESByfuT

Happy learning All!





#infosec #CyberSecurity #pentesting #ethicalhacking #learningeveryday #cybersec #skillsdevelopment
Activate to view la
Here are some of the free websites to learn Linux from for free :
1. OverTheWire[https://lnkd.in/eFKK_85m]
2. Linux Journey[https://linuxjourney.com/]
3. Linux Handbook[https://linuxhandbook.com/]
4. Tecmint[https://www.tecmint.com/]
5. Linux Hint[https://linuxhint.com/]
6. LinuxOPsys[https://linuxopsys.com/]
7. Linuxize[https://linuxize.com/]
8. Eduonix Learn Linux From Scratch[https://lnkd.in/e7cHemyy]
9. Cyberciti Bash Shell Scripting Tutorial[https://lnkd.in/eNn5_9Gv]
10. Learn Enough Command Line To Be Dangerous[https://lnkd.in/eZimTYA4]
11. The Debian Administrator's Handbook[https://lnkd.in/exZzEwFS]
12. LabEx Linux For Noobs[https://lnkd.in/e_FPpdtz]
13. nixCraft[https://www.cyberciti.biz/]
14. Conquering the Command Line[https://lnkd.in/eHSc8Sza]
15. FOSS Linux[https://www.fosslinux.com/]
16. It's FOSS[https://itsfoss.com/]
17. Linux Survival[https://linuxsurvival.com/]
18. Ryan's Tutorials[https://lnkd.in/ePGx5PaC]
19. TLDP Advanced Bash Scripting Guide[https://lnkd.in/e4nzZmvV]
20. Guru99 Linux Tutorial Summary[https://lnkd.in/ebeJuzq8]





#pentesting #ethicalhacking #cybersecurity #learningeveryday #infosec #cybersec
๐‘๐ž๐ ๐“๐ž๐š๐ฆ ๐“๐จ๐จ๐ฅ๐ฌ ๐Ÿ”ฅ

๐Ÿ”ด RECONNAISSANCE:
- RustScan ==> https://lnkd.in/ebvRfBNy
- NmapAutomator ==> https://lnkd.in/gu5wxzf6
- AutoRecon ==> https://lnkd.in/g3DeG6YT
- Amass ==> https://lnkd.in/e7V569N5
- CloudEnum ==> https://lnkd.in/ePHDeGZv
- Recon-NG ==> https://lnkd.in/edwaXFjS
- AttackSurfaceMapper ==> https://lnkd.in/ebbcj6Rm
- DNSDumpster ==> https://dnsdumpster.com/

๐Ÿ”ด INITIAL ACCESS:
- SprayingToolKit ==> https://lnkd.in/eBSAPz5z
- o365Recon ==> https://lnkd.in/eJwCx-Ga
- Psudohash ==> https://lnkd.in/gcaxV6fR
- CredMaster ==> https://lnkd.in/gtMEDVuS
- DomainPasswordSpray ==> https://lnkd.in/guWj4TYv
- TheSprayer ==> https://lnkd.in/gZVuQYiv
- TREVORspray ==> https://lnkd.in/gHgcbjgV

๐Ÿ”ด DELIVERY:
- o365AttackToolKit ==> https://lnkd.in/etCCYi8y
- EvilGinx2 ==> https://lnkd.in/eRDPvwUg
- GoPhish ==> https://lnkd.in/ea26dfNg
- PwnAuth ==> https://lnkd.in/eqecM7de
- Modlishka ==> https://lnkd.in/eds-dR5C

๐Ÿ”ด COMMAND AND CONTROL:
- PoshC2 ==> https://lnkd.in/eqSJUDji
- Sliver ==> https://lnkd.in/ewN9Nday
- SILENTTRINITY ==> https://lnkd.in/eeZGbYMs
- Empire ==> https://lnkd.in/egAPa8gY
- AzureC2Relay ==> https://lnkd.in/efmh2t3g
- Havoc C2 ==> https://lnkd.in/gEFp2iym
- Mythic C2 ==> https://lnkd.in/gnCGwfWk

๐Ÿ”ด CREDENTIAL DUMPING:
- MimiKatz ==> https://lnkd.in/etEGfvJK
- HekaTomb ==> https://lnkd.in/eJx5Ugu5
- SharpLAPS ==> https://lnkd.in/eA28n9FT
- Net-GPPPassword ==> https://lnkd.in/e3CTez5A
- PyPyKatz ==> https://lnkd.in/eeb5b6Tz

๐Ÿ”ด PRIVILEGE ESCALATION:
- SharpUp ==> https://lnkd.in/etR2Pe_n
- MultiPotato ==> https://lnkd.in/eq53PXcJ
- PEASS ==> https://lnkd.in/eWA66akh
- Watson ==> https://lnkd.in/eZfYMSMX
- Bat-Potato ==> https://lnkd.in/gjziyG8q

๐Ÿ”ด DEFENSE EVASION:
- Villain ==> https://lnkd.in/gquyGFm5
- EDRSandBlast ==> https://lnkd.in/e8g8zYFT
- SPAWN - Cobalt Strike BOF ==> https://lnkd.in/e223PbqZ
- NetLoader ==> https://lnkd.in/ef5wCD4y
- KillDefenderBOF ==> https://lnkd.in/eVd54HUp
- ThreatCheck ==> https://lnkd.in/eHvSPakR
- Freeze ==> https://lnkd.in/eNUh3zCi
- GadgetToJScript ==> https://lnkd.in/egPQBBXJ

๐Ÿ”ด PERSISTENCE:
- SharPyShell ==> https://lnkd.in/eXm8h8Bj
- SharpStay ==> https://lnkd.in/erRbeFMj
- SharpEventPersist ==> https://lnkd.in/e_kJFNiB

๐Ÿ”ด LATERAL MOVEMENT:
- SCShell ==> https://lnkd.in/e256fC8B
- MoveKit ==> https://lnkd.in/eR-NUu_U
- ImPacket ==> https://lnkd.in/euG4hTTs

๐Ÿ”ด EXFILTRATION:
- SharpExfiltrate ==> https://lnkd.in/eGC4BKRN
- DNSExfiltrator ==> https://lnkd.in/epJ-s6gp
- Egress-Assess ==> https://lnkd.in/eXGFPQRJ

#redteam #cybersecurity #penetrationtesting #security #ethicalhacking #tools
This channel/community aims to provide free courses related to programming,web development, cyber security, ethical hacking and many more tech related stuff and news #programmming, #coding, #ethicalhacking #cybersecurity

Join our channel channel :- telegram.me/cybertrickzone

@cybertrickzone for more to learn hacking, programming, hacking tools, pdf , courses, tech news, database daily updates. Please join my channel
Bug bounty Cheatsheet:

For more like this, join us at:
t.me/cybertrickzone

XSS
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/xss.md
https://github.com/ismailtasdelen/xss-payload-list

SQLi
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/sqli.md

SSRF
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/ssrf.md
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Server%20Side%20Request%20Forgery

CRLF
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/crlf.md
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/CRLF%20Injection

CSV-Injection
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/csv-injection.md
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/CSV%20Injection

Command Injection
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Command%20Injection

Directory Traversal
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Directory%20Traversal

LFI
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/lfi.md
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/File%20Inclusion

XXE
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/xxe.md

Open-Redirect
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/open-redirect.md

RCE
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/rce.md

Crypto
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/crypto.md

Template Injection
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/template-injection.md
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Server%20Side%20Template%20Injection

XSLT
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/xslt.md

Content Injection
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/content-injection.md

LDAP Injection
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/LDAP%20Injection

NoSQL Injection
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/NoSQL%20Injection

CSRF Injection
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/CSRF%20Injection

GraphQL Injection
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/GraphQL%20Injection

IDOR
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Insecure%20Direct%20Object%20References

ISCM
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Insecure%20Source%20Code%20Management

LaTex Injection
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/LaTeX%20Injection

OAuth
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/OAuth

XPATH Injection
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/XPATH%20Injection

Bypass Upload Tricky
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Upload%20Insecure%20Files
Forwarded from Cybertix
๐—ง๐—ฟ๐˜†๐—›๐—ฎ๐—ฐ๐—ธ๐— ๐—ฒ ๐—–๐˜†๐—ฏ๐—ฒ๐—ฟ ๐—”๐—ฑ๐˜ƒ๐—ฒ๐—ป๐˜ ๐——๐—ฎ๐˜†- ๐Ÿฎ


๐—Ÿ๐—ฒ๐—ฎ๐—ฟ๐—ป ๐—ฃ๐˜†๐˜๐—ต๐—ผ๐—ป & ๐—๐˜‚๐—ฝ๐˜†๐˜๐—ฒ๐—ฟ ๐Ÿ˜


๐—ช๐—ฎ๐—น๐—ธ๐˜๐—ต๐—ฟ๐—ผ๐˜‚๐—ด๐—ต: https://youtu.be/MPjm-g0Uq5Q?si=C7-ZZsDlozN4syzQ


Please Like & Subscribe to our YouTube channel๐Ÿ˜„
Forwarded from Cybertix
๐—ง๐—ฟ๐˜†๐—›๐—ฎ๐—ฐ๐—ธ ๐— ๐—ฒ ๐—”๐—ฑ๐˜ƒ๐—ฒ๐—ป๐˜ ๐—ผ๐—ณ ๐—–๐˜†๐—ฏ๐—ฒ๐—ฟ ๐——๐—ฎ๐˜†-๐Ÿฏ

๐—•๐—ฟ๐˜‚๐˜๐—ฒ ๐—ณ๐—ผ๐—ฟ๐—ฐ๐—ถ๐—ป๐—ด ๐—ฃ๐—ฎ๐˜€๐˜€๐˜„๐—ผ๐—ฟ๐—ฑ๐Ÿ˜

๐—ช๐—ฎ๐—น๐—ธ๐˜๐—ต๐—ฟ๐—ผ๐˜‚๐—ด๐—ต: https://youtu.be/tbNuQH8vFMU

Please Like & Subscribe to our YouTube Channel๐Ÿ˜„
Forwarded from Cybertix
๐—™๐—ถ๐—ป๐—ฎ๐—น๐—น๐˜† ๐˜๐—ต๐—ฒ ๐—ฆ๐˜๐—ฟ๐—ถ๐—ธ๐—ฒ ๐—ต๐—ฎ๐˜€ ๐—ฏ๐—ฒ๐—ฒ๐—ป ๐—ฅ๐—ฒ๐—บ๐—ผ๐˜ƒ๐—ฒ๐—ฑ ๐Ÿฅณ

๐—ช๐—ฎ๐˜๐—ฐ๐—ต ๐—ง๐—ฟ๐˜†๐—›๐—ฎ๐—ฐ๐—ธ๐— ๐—ฒ ๐——๐—ฎ๐˜†-๐Ÿฐ

๐—ช๐—ฎ๐—น๐—ธ๐˜๐—ต๐—ฟ๐—ผ๐˜‚๐—ด๐—ต: https://youtu.be/qLusVF1owU0?si=kXfDTMpWTx60giSA
Forwarded from Hacking Vidhya (Dark Hacked)
๐Ÿž Bug Bounty Tip: ๐Ÿ•ต๏ธโ€โ™‚๏ธ

If you find Web frameworks like Symfony, add /app_dev.php/_profiler/open?file=app/config/parameters.yml to the wordlist, and you may get juicy data. Enjoy! ๐Ÿš€




Symfony has a built-in profiler that can be accessed during development to provide information about the application's performance and behavior. The URL /app_dev.php/_profiler/ is used to access this profiler.

In the tip, it suggests adding /app_dev.php/_profiler/open?file=app/config/parameters.yml to a wordlist. A wordlist is a list of words used for testing purposes, often in password cracking or in this case, for trying different URLs.

By adding this specific URL to the wordlist and attempting to access it on a Symfony application in development mode, an attacker might be able to access sensitive data stored in the parameters.yml file. This file often contains configuration settings, including database credentials and other sensitive information.

#bugbountytips #bugbountytip #cybersecurity #ethicalhacking