Hacking Articles
21K subscribers
1.13K photos
165 files
777 links
House of Pentester
Download Telegram
2 Turbo Intruder.pdf
4.4 MB
Burp Suite for Pentester: Turbo Intruder

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Turbo Intruder is a powerful Burp Suite extension designed to send a massive number of HTTP requests at high speed for fuzzing and brute-force attacks. It uses HTTP pipelining and customizable Python scripts to perform advanced testing scenarios with low memory usage. ()

⚑️ Key Features of Turbo Intruder
πŸš€ Ultra-fast HTTP request fuzzing
🐍 Customizable Python attack scripts
πŸ“¦ Handles millions of payloads efficiently
πŸ”— Uses HTTP pipelining for reduced latency
βš™οΈ Supports multi-parameter fuzzing attacks

🎯 Common Security Testing Scenarios
πŸ” Password brute-force attacks
πŸ§ͺ Race condition testing
πŸ“‘ Parameter fuzzing
πŸ”Ž Authentication bypass testing
⚑️ High-volume request attacks

πŸ“– Article: https://www.hackingarticles.in/burp-suite-for-pentester-turbo-intruder/
SMB Enumeration.png
1.6 MB
🚨 A Little Guide to SMB Enumeration

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

SMB (Server Message Block) is widely used for file and resource sharing in Windows environments. During penetration testing, SMB enumeration helps identify shares, users, hostnames, and potential vulnerabilities that could lead to system compromise. ()

⚑️ Key Tools for SMB Enumeration

πŸ”Ž Nmap (nbstat / smb-os-discovery / smb-enum-shares)
🧠 Enum4linux
πŸ“‚ SMBMap
πŸ’» smbclient
🌐 nbtscan
πŸ–₯ nmblookup
🧾 rpcclient
βš”οΈ CrackMapExec
πŸ’£ Metasploit: smb_enumshares
🧬 Metasploit: smb_lookupsid
🐍 Impacket: lookupsid

These tools help security professionals enumerate SMB shares, users, SIDs, hostnames, and vulnerabilities during reconnaissance and penetration testing. ()

πŸ“– Article: https://www.hackingarticles.in/a-little-guide-to-smb-enumeration/
❀2
🚨 Best Alternative of Netcat Listener

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

During penetration testing, listeners are used to receive reverse shell connections from compromised systems. While Netcat is widely used, several powerful alternatives provide better stability, command history, and interactive shell capabilities. ()

⚑️ Popular Netcat Listener Alternatives

πŸ”§ Netcat (nc)
⌨️ Rlwrap
πŸ¦€ Rustcat
🐱 Pwncat
πŸͺŸ Windows ConPty Shell
🌐 Reverse Shell Generator

These tools help pentesters establish interactive reverse shells, improve command handling, and maintain stable sessions during exploitation and post-exploitation phases. ()

πŸ“– Article: https://www.hackingarticles.in/best-alternative-of-netcat-listener/
😈1
A Detailed Guide on Ligolo-Ng

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Ligolo-Ng is a modern tunneling and pivoting tool used by penetration testers to perform lateral movement and access internal network services through compromised machines. It enables secure communication channels between attacker and target systems. ()

πŸ“š What You’ll Learn in This Guide

βš™οΈ Introduction to Ligolo-Ng
🧰 Installation & Setup
πŸ–₯ Ligolo-Ng Server Configuration
πŸ’» Ligolo-Ng Agent Setup
🌐 Creating Tunnels
πŸ” Network Pivoting
πŸ“‘ Accessing Internal Services
πŸ§ͺ Scanning Internal Network through Tunnel

πŸ“– Article:
https://www.hackingarticles.in/a-detailed-guide-on-ligolo-ng/
❀3
πŸ”₯ OSCP+ / CTF Exam Practice Training (Online) – Enroll Now! πŸš€

Looking to strengthen your practical penetration testing skills and boost your confidence before the OSCP+ exam?

Join Ignite Technologies’ Exclusive Capture The Flag (CTF) Practice Program β€” designed to simulate real exam scenarios and real-world attack environments.

πŸ”— Register Here:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

πŸ“š What You’ll Cover:

🧠 Introduction to Exam Strategy & Methodology
🌐 Information Gathering & Enumeration
🧱 Vulnerability Scanning & Analysis
πŸ”“ Windows Privilege Escalation
🐧 Linux Privilege Escalation
πŸ›‘ Client-Side Attacks
🌐 Web Application Attacks
🧬 Password Attacks & Credential Exploitation
🧠 Tunneling & Pivoting Techniques
🏰 Active Directory Attacks
πŸ’£ Exploiting Public Exploits Effectively
πŸ“‹ Professional Report Writing

🎯 This training is ideal for:
β€’ OSCP+ aspirants
β€’ CTF players aiming to go professional
β€’ Pentesters wanting structured exam practice
β€’ Security professionals strengthening real-world attack skills

Limited seats available. Prepare smart. Hack ethically. πŸš€
Burp Suite for Pentester: Active Scan++

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Active Scan++ is a powerful extension that enhances vulnerability detection in Burp Suite by adding additional active and passive scanning checks. It helps penetration testers identify advanced web application vulnerabilities that may be missed by default scans.

⚑️ Key Features of Active Scan++
πŸ” Advanced active & passive scanning
🧩 Integration with Burp Suite BApp Store
βš™οΈ Supports Jython-based scanning modules
πŸ›‘ Detects complex web vulnerabilities
πŸ“‘ Improves automated testing coverage

🎯 Vulnerabilities Detected
πŸ’₯ Host Header Injection
πŸ§ͺ XML Injection
🧬 Template Injection
🌐 DNS Rebinding
⚑️ Cache Poisoning

πŸ“– Article: https://www.hackingarticles.in/burp-suite-for-pentester-active-scan/
❀3
Burp Suite for Pentester: Burp’s Project Management

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Burp Suite Project Management helps penetration testers organize, save, and resume web application testing projects efficiently. It allows storing scan data, requests, responses, and configurations so testing sessions can continue without losing progress. ()

πŸ“š Project Management Features Covered

πŸ“‚ Temporary Project
πŸ’Ύ Project on Disk
πŸ“ Open Existing Project
πŸ›  Manipulating Project Files
βš™οΈ Project Options
πŸ“€ Exporting Custom Configuration
πŸ“₯ Importing Project Options

πŸ“– Article:
https://www.hackingarticles.in/burp-suite-for-pentester-burps-project-management/
❀4
Burp Suite for Pentester: Logger++

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Logger++ is a powerful Burp Suite extension that captures and analyzes all HTTP requests and responses during web application testing. It helps pentesters filter, search, and analyze traffic efficiently to uncover hidden vulnerabilities.

⚑️ Key Features of Logger++
πŸ“‘ Capture complete HTTP traffic logs
πŸ”Ž Query-based filtering for precise analysis
🎨 Color-coded log highlighting
🧩 Regex-based search for sensitive data
πŸ“€ Export logs for reporting and analysis

🎯 Useful Detection Scenarios
πŸ” Sensitive parameters (passwords, tokens)
πŸ“‚ Exposed files or configuration leaks
🌐 Server information disclosure
πŸ”„ URL redirection parameters
⚠️ CORS misconfiguration

πŸ“– Article: https://www.hackingarticles.in/burpsuite-for-pentester-logger/
❀3
πŸš€ AI Penetration Testing Training (Live Online Program)

The future of cybersecurity is AI-driven β€” are you ready to test and secure it?

Ignite Technologies is launching an intensive AI Penetration Testing Training designed for security professionals, pentesters, red teamers, and researchers who want to understand how to attack and defend Large Language Models (LLMs) and AI systems.

πŸ”— Register Now: https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

⚠️ Limited seats available.

🧠 What You’ll Learn

πŸ”Ή LLM Architecture & Security Principles
πŸ”Ή Data Security in AI Systems
πŸ”Ή Model & Infrastructure Security
πŸ”Ή OWASP Top 10 for LLMs
πŸ”Ή LLM Installation & Secure Deployment
πŸ”Ή Model Context Protocol (MCP)
πŸ”Ή Publishing Models using Ollama
πŸ”Ή Retrieval-Augmented Generation (RAG) Security

πŸ”₯ Offensive AI Security Modules

βœ”οΈ Prompt Injection & Indirect Injection Attacks
βœ”οΈ Exploiting LLM APIs (Real-World Bug Scenarios)
βœ”οΈ Password & Sensitive Data Leakage via AI
βœ”οΈ Excessive Privilege Exploitation
βœ”οΈ LLM Misconfigurations
βœ”οΈ Data Extraction Attacks
βœ”οΈ Content Manipulation in LLM Outputs
βœ”οΈ AI-based Enumeration Techniques

πŸ›‘ Defensive & Automation Focus

βœ… Securing AI Systems
βœ… System Prompt Security Implications
βœ… Automated Penetration Testing with AI
βœ… Making AI Applications Secure & Public-Ready

If you're already into Pentesting, Red Teaming, Bug Bounty, OSCP prep, or Offensive Security, this program will give you a cutting-edge advantage in AI security.

Secure your seat before registrations close.
❀8πŸ‘1
Burp Suite for Pentester: Turbo Intruder

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Turbo Intruder is a powerful Burp Suite extension designed to send a massive number of HTTP requests at high speed for fuzzing and brute-force attacks. It uses HTTP pipelining and customizable Python scripts to perform advanced testing scenarios with low memory usage. ()

⚑️ Key Features of Turbo Intruder
πŸš€ Ultra-fast HTTP request fuzzing
🐍 Customizable Python attack scripts
πŸ“¦ Handles millions of payloads efficiently
πŸ”— Uses HTTP pipelining for reduced latency
βš™οΈ Supports multi-parameter fuzzing attacks

🎯 Common Security Testing Scenarios
πŸ” Password brute-force attacks
πŸ§ͺ Race condition testing
πŸ“‘ Parameter fuzzing
πŸ”Ž Authentication bypass testing
⚑️ High-volume request attacks

πŸ“– Article: https://www.hackingarticles.in/burp-suite-for-pentester-turbo-intruder/
Burp Suite for Pentester: Repeater

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Burp Repeater is a manual testing tool in Burp Suite that allows penetration testers to modify and resend HTTP requests to analyze server responses without affecting normal browser traffic. ()

πŸ“š Topics Covered in This Guide

πŸ”Ž Introduction to Burp Repeater
πŸ“ Renaming Repeater Tabs
πŸ” Changing HTTP Request Method
πŸ“œ Request History Navigation
🌐 Paste URL as Request
πŸ” URL Encoding
➑️ Following Redirections
πŸ” Searching within Requests & Responses
πŸ“‚ Reopening Closed Tabs
πŸ–₯ Request/Response View Modes
πŸ’Ύ Exporting Repeater History

πŸ“– Article:
https://hackingarticles.in/burp-suite-for-pentester-repeater/
Burp Suite for Pentester: Burp Sequencer

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Burp Sequencer is a Burp Suite tool used to analyze the randomness and predictability of tokens generated by web applications, such as session IDs, CSRF tokens, and password reset tokens. ()

πŸ“š Topics Covered in This Guide

πŸ”Ž Introduction to Burp Sequencer
🎯 Session ID Exploitation via Sequencer
πŸ“‘ Capturing Tokens from Requests
βš™οΈ Custom Token Location Configuration
πŸ“Š Live Capture & Token Collection
🧠 Statistical Randomness Analysis
πŸ“‚ Manual Token Analysis
βš–οΈ Comparing Tokens using Burp Comparer

πŸ“– Article:
https://hackingarticles.in/burp-suite-for-pentester-burp-sequencer/
Burp Suite for Pentester: HackBar

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

HackBar is a Burp Suite extension that speeds up manual penetration testing by providing ready-to-use payload dictionaries for common web vulnerabilities, allowing testers to quickly insert payloads while analyzing HTTP requests. ()

πŸ“š Vulnerability Testing with HackBar

πŸ’‰ SQL Injection
πŸ” SQLi Login Bypass
⚑️ Cross-Site Scripting (XSS)
πŸ“‚ Local File Inclusion (LFI)
πŸ“„ XML External Entity (XXE)
πŸ“€ Unrestricted File Upload
πŸ’» OS Command Injection

πŸ“– Article:
https://hackingarticles.in/burp-suite-for-pentester-hackbar/
❀3
πŸ”₯ Ethical Hacking Proactive Training – Live & Practical πŸ”₯

Ready to build real-world cybersecurity skills with hands-on experience?

πŸš€ Ignite Technologies brings you a comprehensive Ethical Hacking Proactive Training Program designed with live sessions and core practical exposure β€” at an affordable price.

πŸ”— Register Now:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

🎯 Book Your Demo Session Today!

πŸ“˜ What You’ll Learn:

βœ… Introduction to Ethical Hacking
βœ… Old School Learning Methodology
βœ… Networking Fundamentals
βœ… Reconnaissance (Footprinting, Scanning & Enumeration)
βœ… System Hacking
βœ… Post Exploitation & Persistence
βœ… Web Server Penetration Testing
βœ… Website Hacking Techniques
βœ… Malware Threats & Analysis
βœ… Wireless Network Security
βœ… Cryptography & Steganography
βœ… Sniffing Attacks
βœ… Denial of Service (DoS)
βœ… Evading IDS, Firewalls & Honeypots
βœ… Social Engineering Techniques
βœ… Mobile Platform Security

πŸ’‘ Whether you're a beginner or looking to strengthen your penetration testing skills, this training is structured to provide practical knowledge aligned with real-world attack scenarios.

Limited seats available. Secure yours now.
πŸ‘1
πŸ”₯ OSCP+ / CTF Exam Practice Training (Online) – Enroll Now! πŸš€

Looking to strengthen your practical penetration testing skills and boost your confidence before the OSCP+ exam?

Join Ignite Technologies’ Exclusive Capture The Flag (CTF) Practice Program β€” designed to simulate real exam scenarios and real-world attack environments.

πŸ”— Register Here:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

πŸ“š What You’ll Cover:

🧠 Introduction to Exam Strategy & Methodology
🌐 Information Gathering & Enumeration
🧱 Vulnerability Scanning & Analysis
πŸ”“ Windows Privilege Escalation
🐧 Linux Privilege Escalation
πŸ›‘ Client-Side Attacks
🌐 Web Application Attacks
🧬 Password Attacks & Credential Exploitation
🧠 Tunneling & Pivoting Techniques
🏰 Active Directory Attacks
πŸ’£ Exploiting Public Exploits Effectively
πŸ“‹ Professional Report Writing

🎯 This training is ideal for:
β€’ OSCP+ aspirants
β€’ CTF players aiming to go professional
β€’ Pentesters wanting structured exam practice
β€’ Security professionals strengthening real-world attack skills

Limited seats available. Prepare smart. Hack ethically. πŸš€
SSH Penetration Testing (Port 22)

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

SSH (Secure Shell) is a cryptographic protocol used for secure remote login and command execution over unsecured networks. During penetration testing, misconfigurations or weak credentials in SSH services can allow attackers to gain unauthorized access. ()

πŸ“š Techniques Covered in This Guide

πŸ”Ž Enumeration with Nmap
πŸ” Password Cracking using Hydra
⚑️ Authentication using Metasploit
πŸ’» Running Commands on Remote Machine
πŸ” SSH Port Redirection
πŸ§ͺ Nmap SSH Brute Force Script
πŸ” Enumerating SSH Authentication Methods
πŸ”‘ Key-Based Authentication
πŸ›  Key-Based Authentication using Metasploit
πŸ“¦ Post Exploitation using Metasploit
🌐 Local Port Forwarding (Password Based)
πŸ” Local Port Forwarding (Key Based)

πŸ“– Article:
https://www.hackingarticles.in/ssh-penetration-testing-port-22/
❀4
WinRM Penetration Testing

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

WinRM (Windows Remote Management) is a Microsoft protocol used for remote system management and command execution. If misconfigured or protected with weak credentials, attackers can abuse WinRM to gain remote shell access and move laterally across Windows environments. ()

πŸ“š Techniques Covered in This Guide

βš™οΈ Lab Setup
πŸ”Ž Testing WinRM Connection
πŸ’» Connecting with Enter-PSSession
πŸ–₯ Remote Command Execution using winrs
πŸ“‘ PowerShell Remote Execution (Invoke-Command)
πŸ” Scanning WinRM Service with Nmap
πŸ” Identifying Authentication Methods
πŸ’₯ WinRM Login Brute Force (Metasploit)
⚑️ Password Spray using NetExec (nxc)
🐚 Remote Shell using Evil-WinRM
🧰 Exploiting WinRM using Metasploit
🐳 Connecting Remote Shell using Docker
πŸ“œ Connecting Remote Shell using Ruby Script

πŸ“– Article:
https://www.hackingarticles.in/winrm-penetration-testing/
❀1
Tcpdump Cheat Sheet for Pentesters

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Tcpdump is a powerful command-line packet analyzer used to capture and inspect network traffic. It is widely used for network troubleshooting, packet analysis, and security monitoring on Linux systems. ()

⚑️ Useful Tcpdump Commands

πŸ“‘ tcpdump -i eth0
πŸ”Ž tcpdump host 192.168.1.1
🌐 tcpdump port 80
πŸ“‚ tcpdump -w capture.pcap
πŸ“– tcpdump -r capture.pcap
🧠 tcpdump -i eth0 tcp
πŸ“Š tcpdump -n -vv
πŸ” tcpdump icmp
πŸ“ tcpdump src 192.168.1.5
πŸ“ tcpdump dst 192.168.1.5

🧠 Mindmap:
https://github.com/Ignitetechnologies/Mindmap/tree/main/Tcpdump
❀1πŸ‘1
πŸ”₯ OSCP+ / CTF Exam Practice Training (Online) – Enroll Now! πŸš€

Looking to strengthen your practical penetration testing skills and boost your confidence before the OSCP+ exam?

Join Ignite Technologies’ Exclusive Capture The Flag (CTF) Practice Program β€” designed to simulate real exam scenarios and real-world attack environments.

πŸ”— Register Here:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

πŸ“š What You’ll Cover:

🧠 Introduction to Exam Strategy & Methodology
🌐 Information Gathering & Enumeration
🧱 Vulnerability Scanning & Analysis
πŸ”“ Windows Privilege Escalation
🐧 Linux Privilege Escalation
πŸ›‘ Client-Side Attacks
🌐 Web Application Attacks
🧬 Password Attacks & Credential Exploitation
🧠 Tunneling & Pivoting Techniques
🏰 Active Directory Attacks
πŸ’£ Exploiting Public Exploits Effectively
πŸ“‹ Professional Report Writing

🎯 This training is ideal for:
β€’ OSCP+ aspirants
β€’ CTF players aiming to go professional
β€’ Pentesters wanting structured exam practice
β€’ Security professionals strengthening real-world attack skills

Limited seats available. Prepare smart. Hack ethically. πŸš€
❀1
πŸ›‘ Penetration Testing on MySQL (Port 3306)

πŸ”— Twitter: https://lnkd.in/e7yRpDpY
πŸ“’ Telegram: https://t.me/hackinarticles

MySQL databases are widely used in web applications, but misconfigurations can expose critical data.

This guide covers:
πŸ”Ž MySQL Enumeration
πŸ”‘ Login testing & brute force
⚑️ Hydra attacks
🧰 Metasploit exploitation
πŸ“‚ Database extraction techniques

Read the full article πŸ‘‡
https://www.hackingarticles.in/penetration-testing-on-mysql-port-3306/
❀4
OSEP Exam Practice Training (Online) – Registration Open! πŸš€

Ready to level up your offensive security skills and prepare for advanced red team operations?

Join Ignite Technologies’ Exclusive β€œCapture The Flag” (CTF) Based OSEP Practice Program and train in a real-world, attack-driven environment designed for serious cybersecurity professionals.

πŸ”— Register Now:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

πŸ“š Training Modules Include:

πŸš€ Introduction
πŸ” Advanced Information Gathering
🎯 Initial Access & Client-Side Attacks
πŸ›‘ Bypassing Security Controls
πŸͺŸ Windows Privilege Escalation
🐧 Linux Privilege Escalation
🧭 Active Directory Enumeration
πŸ” Lateral Movement
🏰 Active Directory Attacks
🌐 Web Application Attacks
πŸ•³ Tunneling & Pivoting
🧬 Post-Exploitation & Persistence
πŸ₯· Defense Evasion & OPSEC
πŸ§ͺ Custom Malware & Tool Development
πŸ’₯ Advanced Exploitation
πŸ“ Reporting & Documentation

This program is ideal for professionals preparing for advanced offensive security certifications and those aiming to strengthen their red teaming capabilities.

Seats are limited. Secure yours today. πŸš€
❀1