Hacking Articles
24.5K subscribers
1.47K photos
165 files
1.08K links
House of Pentester
Download Telegram
πŸ”₯ Types of Privileged Accounts You Should Know

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

πŸ” Not all accounts are created equal β€” privileged accounts can become high-value targets.

Here are 8 types every cybersecurity professional should understand:

πŸ‘‘ Root / Superuser Accounts
β†’ Highest level of access

πŸ›‘ Admin Accounts
β†’ Manage systems, users & configurations

πŸ—„ Database Admin Accounts
β†’ Control databases & sensitive data

βš™οΈ Service Accounts
β†’ Used by applications and services

πŸ’» Application Accounts
β†’ Run applications with defined permissions

🀝 Vendor / Third-Party Accounts
β†’ External access for support & services

πŸ”‘ Privileged User Accounts
β†’ Elevated access for specific tasks

🚨 Emergency / Break-Glass Accounts
β†’ Emergency access when normal accounts aren't available

🎯 Security tip:
The more privileged an account is, the more important it becomes to apply MFA, least privilege, strong credential management, monitoring and regular access reviews.

πŸ“Œ Save this cheat sheet.
πŸ” Repost to help another cybersecurity professional.
❀4πŸ‘1πŸ”₯1
πŸ”₯ Top 25 RCE Parameters Every Bug Hunter Should Know

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Looking for potential Remote Code Execution (RCE) entry points during an authorized web security assessment? πŸ‘€

🎯 Common parameters to investigate:

cmd β€’ exec β€’ command β€’ execute β€’ ping
query β€’ jump β€’ code β€’ reg β€’ do
func β€’ arg β€’ option β€’ load β€’ process
step β€’ read β€’ function β€’ req β€’ feature
exe β€’ module β€’ payload β€’ run β€’ print

🧠 Bug Hunting Workflow

πŸ”Ž Discover input parameters
➑️ Identify where the input is processed
➑️ Understand the application's intended functionality
➑️ Test safely within the authorized scope
➑️ Validate impact before reporting

⚠️ Important: A parameter name alone does not indicate an RCE vulnerability. Always verify the application's behavior and test only systems you are authorized to assess.

πŸ“Œ Save this cheat sheet for your next pentest.
πŸ” Repost to help fellow security researchers.
❀3
πŸ”₯ Top 25 SQL Injection Parameters Every Bug Hunter Should Know

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Looking for potential SQL injection entry points? πŸ‘€
Start by understanding the application's input parameters.

🎯 Common parameters to investigate:

id β€’ page β€’ region β€’ nav β€’ main
dir β€’ search β€’ category β€’ url β€’ class
file β€’ news β€’ item β€’ menu β€’ lang
name β€’ ref β€’ title β€’ view β€’ topic
form β€’ data β€’ type β€’ join β€’ date

🧠 Bug Hunting Workflow

πŸ”Ž Discover parameters
➑️ Identify where user input reaches the application
➑️ Review how the backend processes the input
➑️ Test safely in an authorized environment
➑️ Confirm the behavior before reporting

⚠️ Important: A parameter name alone does not mean SQL injection exists. Always validate the application's actual behavior and authorization scope.

πŸ“Œ Save this cheat sheet.
πŸ” Repost for fellow bug hunters.
❀4
πŸ”₯ Top 25 XSS Parameters Every Bug Hunter Should Know

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Finding XSS isn't always about the payload.
Sometimes, finding the right parameter is the first step. πŸ‘€

🎯 Common parameters worth checking:

q β€’ s β€’ search β€’ id β€’ lang
keyword β€’ query β€’ page β€’ keywords β€’ year
view β€’ email β€’ type β€’ name β€’ p
month β€’ url β€’ terms β€’ key β€’ l
begindate β€’ enddate β€’ and more…

🧠 Bug Hunting Workflow:

πŸ”Ž Discover parameters
➑️ Understand their purpose
➑️ Trace where input is reflected
➑️ Check the application’s output encoding
➑️ Validate safely in an authorized environment

⚑️ Remember: A parameter isn't automatically vulnerable just because its name appears on a list. Always verify the application's actual behavior.

πŸ“Œ Save this cheat sheet for your next web security assessment.

πŸ” Repost to help another bug hunter!
πŸ”₯ OSCP isn’t about knowing more tools.

πŸ“… LIMITED SEATS β€” ADMISSIONS CLOSING SOON

πŸ”— Register: https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

It’s about knowing what to do next when nothing works.

Nmap. Burp. Metasploit. PrivEsc.

Tools are easy to learn.
Methodology is what gets you through the exam.

πŸš€ OSCP Training Program

βœ… Hands-on Labs
βœ… Linux & Windows PrivEsc
βœ… Web Pentesting
βœ… Active Directory
βœ… Pivoting & Tunneling
βœ… Exam-Style Practice
βœ… Reporting & Methodology

🎯 Want to know the complete curriculum, batch details & training fees?

πŸ‘‰ Fill out the form and our team will contact you:
https://forms.gle/bowpX9TGEs41GDG99

⚑️ Limited seats for the upcoming batch.
❀1
Become Job-Ready in Cyber Security with Practical Labs

Ready to build real-world cybersecurity skills with hands-on experience?

πŸš€ Ignite Technologies brings you a comprehensive Ethical Hacking Proactive Training Program designed with live sessions and core practical exposure β€” at an affordable price.

πŸ”— Register Now:
https://forms.gle/bowpX9TGEs41GDG99

πŸ’¬ WhatsApp:
https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email:
info@ignitetechnologies.in

🎯 Book Your Demo Session Today!

πŸ“˜ What You’ll Learn:

βœ… Introduction to Ethical Hacking
βœ… Old School Learning Methodology
βœ… Networking Fundamentals
βœ… Reconnaissance (Footprinting, Scanning & Enumeration)
βœ… System Hacking
βœ… Post Exploitation & Persistence
βœ… Web Server Penetration Testing
βœ… Website Hacking Techniques
βœ… Malware Threats & Analysis
βœ… Wireless Network Security
βœ… Cryptography & Steganography
βœ… Sniffing Attacks
βœ… Denial of Service (DoS)
βœ… Evading IDS, Firewalls & Honeypots
βœ… Social Engineering Techniques
βœ… Mobile Platform Security

πŸ’‘ Whether you're a beginner or looking to strengthen your penetration testing skills, this training is structured to provide practical knowledge aligned with real-world attack scenarios.

Limited seats available. Secure yours now.
❀2
πŸ”₯ 28 Transfer Protocols You Should Know in Cybersecurity

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

One cheat sheet. 28 protocols. πŸš€

From everyday web traffic to secure file transfers and messaging:

🌐 Web & Application
HTTP β€’ HTTPS β€’ WebSocket β€’ Gopher β€’ RTSP β€’ RTMP

πŸ“ File Transfer
FTP β€’ FTPS β€’ SFTP β€’ SCP β€’ TFTP β€’ SMB β€’ SFTP

πŸ“§ Email
SMTP β€’ SMTPS β€’ IMAP β€’ IMAPS β€’ POP3 β€’ POP3S

πŸ” Secure Communication
SSH β€’ TLS β€’ QUIC β€’ LDAPS

πŸ“‘ Other Protocols
Telnet β€’ LDAP β€’ MQTT β€’ DNS/DIG β€’ WSS β€’ SMB

🧠 Why should security professionals care?

Every protocol creates a different communication pattern, attack surface, and troubleshooting path.

Understanding protocols helps with:

πŸ”Ž Network reconnaissance
πŸ›‘ SOC investigations
πŸ“‘ Traffic analysis
🐞 Web & API testing
πŸ” Secure configuration
🎯 Penetration testing

πŸ“Œ Save this cheat sheet for your networking & cybersecurity journey.

πŸ” Repost to help another security professional.
❀5
πŸ”₯ Cryptocurrency Attack Surface for OSINT Investigations

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Crypto investigations are not just about wallet addresses. 🧠

A single transaction can lead investigators through an entire ecosystem:

β‚Ώ Cryptocurrency
β†’ Blockchain
β†’ Transactions
β†’ Wallets
β†’ Exchanges
β†’ Mining activity
β†’ Contracts
β†’ Blocks

πŸ”Ž Key OSINT pivots:

πŸ’° Wallet balances & transactions
πŸ• Transaction timestamps
πŸ”— Transaction hashes
πŸ’΅ Amounts & fees
🏦 Intermediary wallets
πŸ”„ Cryptocurrency exchanges
πŸŒ€ Tumbling/mixing services
⛏️ Mining pools & payouts
πŸ“œ Smart contracts
πŸ–Ό NFTs & tokens
🚨 Scam reports
πŸ“ˆ Historical & current prices

🎯 Investigation mindset:

One wallet β†’ multiple transactions β†’ connected wallets β†’ services β†’ infrastructure β†’ broader intelligence.

The real value comes from connecting the relationships between these data points, rather than examining a single blockchain record in isolation.

πŸ“Œ Save this OSINT cheat sheet.
πŸ” Repost it for investigators & cybersecurity professionals.
❀1πŸ‘Ž1
πŸ”₯ Google Dorks for Bug Bounty β€” Recon Cheat Sheet

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Want to improve your web recon workflow? πŸ”Ž

Google operators can help security researchers discover publicly indexed information about an authorized target.

🎯 Useful recon patterns:

🌐 Domain Discovery
site:example.com

πŸ“„ Find PHP pages & parameters
site:example.com ext:php inurl:?

🐞 XSS-Prone Parameters
inurl:q | inurl:s | inurl:search | inurl:query | inurl:keyword

πŸ”€ Open Redirect Candidates
inurl:url= | inurl:return= | inurl:next= | inurl:redirect=

πŸ“ Potentially Interesting Files
site:example.com ext:log | ext:txt | ext:conf | ext:ini | ext:env

πŸ“Š Negative Search
site:example.com -www -shop -share

🧠 Recon mindset:

Discover β†’ Filter β†’ Validate β†’ Document β†’ Report

⚠️ Important: Search-engine indexing does not mean a resource is vulnerable. Use these techniques only against systems you are authorized to test, and avoid accessing sensitive data you don't need.

πŸ“Œ Save this cheat sheet for your next bug bounty recon.
πŸ” Repost to help another security researcher.
❀4πŸ‘2
πŸ” Reach 900,000+ Cybersecurity Professionals & Enthusiasts

Are you a Cybersecurity Vendor, SaaS Company, Security Product, Training Provider, Recruitment Platform, or Technology Brand looking to reach a highly targeted cybersecurity audience?

Hacking Articles offers advertising and strategic media partnership opportunities across our growing cybersecurity community.

πŸ“Š Our Audience Reach

πŸ’Ό LinkedIn: 600,000+ followers
🐦 X / Twitter: 300,000+ followers
πŸ“² Telegram: 23,000+ members

🌐 Our Community

πŸ”— LinkedIn: Hacking Articles LinkedIn
πŸ”— X / Twitter: Hacking Articles on X
πŸ”— Telegram: Hacking Articles Telegram

πŸš€ Partnership Opportunities

We work with brands looking to promote:

β€’ Cybersecurity Products & Solutions
β€’ Security Tools & Platforms
β€’ SaaS & Developer Security Products
β€’ Cybersecurity Training & Certifications
β€’ CTFs, Conferences & Security Events
β€’ Webinars & Technical Events
β€’ Cybersecurity Jobs & Recruitment Campaigns
β€’ Product Launches
β€’ Brand Awareness Campaigns
β€’ Sponsored Technical Content
β€’ Long-Term Media Partnerships

🎯 Why Hacking Articles?

Our community includes:

Penetration Testers β€’ Ethical Hackers β€’ Red Teamers β€’ Security Researchers β€’ SOC Professionals β€’ Developers β€’ IT Professionals β€’ Cybersecurity Students β€’ Security Enthusiasts

This makes our platforms an ideal channel for brands looking to reach a focused cybersecurity and technology audience.

πŸ“© Interested in advertising or partnering with us?

For advertising rates, campaign proposals, sponsored content, and partnership opportunities, contact:

πŸ“§ raj@hackingarticles.in

Let's create a cybersecurity campaign that puts your brand in front of the right audience. πŸš€πŸ”
❀2
🐧 GNU/Linux Command Reference β€” Essential Cheatsheet πŸ”₯

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

A quick reference for the Linux commands you actually use every day. ⚑️

πŸ“‚ File Commands
ls β€’ cd β€’ rm β€’ cp β€’ mv β€’ cat β€’ less β€’ du

πŸ” Permissions
chmod β€’ chown β€’ sudo β€’ su

πŸ“¦ Archives & Encryption
tar β€’ gpg β€’ zip

✍️ Text Editing
nano + essential shortcuts

βš™οΈ Resource Management
ps β€’ top β€’ free β€’ df β€’ mount β€’ kill

⌨️ Terminal Shortcuts
Ctrl+C β€’ Ctrl+Z β€’ Ctrl+D β€’ Ctrl+R β€’ Tab

πŸ’‘ Perfect for:
Linux Admins β€’ DevOps β€’ Cybersecurity β€’ Pentesters β€’ Students

πŸ“Œ SAVE this cheatsheet.
πŸ” Repost it for your Linux community.
πŸ‘1
🐧 Useful CLI Tools for Linux Admins πŸ”₯

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Your Linux terminal toolkit β€” in ONE cheatsheet. ⚑️

🌐 Networking
ss β€’ ip β€’ tcpdump β€’ nmap β€’ dig β€’ ping β€’ traceroute β€’ netcat β€’ iftop β€’ ethtool

πŸ” Security
iptables β€’ ufw β€’ ssh β€’ openssl β€’ gpg β€’ fail2ban β€’ nmap β€’ rkhunter

πŸ“‹ Logging
journalctl β€’ logrotate β€’ lnav β€’ multitail β€’ awk β€’ sed

βš™οΈ System
top β€’ ps β€’ htop β€’ lsof β€’ lsusb β€’ rsync β€’ tmux β€’ lspci

πŸ’Ύ Storage
df β€’ du β€’ fdisk β€’ lsblk β€’ mount β€’ lvm β€’ iostat β€’ smartctl

πŸ“Œ Save this cheatsheet for your next Linux administration task.

πŸ” Repost for Linux admins, DevOps & cybersecurity professionals.
πŸ‘2
πŸš€ Git Cheatsheet for Developers & DevOps Engineers

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles

Stop searching for Git commands every time you get stuck. 😎

πŸ“Œ Quick Git Reference Covers:

πŸ”Ή Git Configuration
πŸ”Ή git init & git clone
πŸ”Ή Git Log & History
πŸ”Ή git add / commit / rm / mv
πŸ”Ή Branching & Switching
πŸ”Ή Merge & Rebase
πŸ”Ή Fetch / Pull / Push
πŸ”Ή Remote Repositories
πŸ”Ή Git Diff & Commit Inspection
πŸ”Ή Rewriting Git History
πŸ”Ή Reset / Revert / Clean
πŸ”Ή Undoing Changes

πŸ’» Perfect for:
Developers β€’ DevOps Engineers β€’ Cloud Engineers β€’ SREs β€’ Students

πŸ”– Bookmark this cheatsheet.
πŸ” Repost it for your developer network.

Official Git documentation also provides a quick reference for these core workflows.
πŸ”₯ OSCP isn’t just a certification. It’s a practical skill test.

Stop only learning. Start practicing. 🎯

πŸ’» Real CTFs
🧠 Practical Pentesting
⚑️ OSCP-focused Training
πŸ† Build confidence before the exam

πŸŽ“ Ready to level up your pentesting skills?

πŸ”— Course: https://www.ignitetechnologies.in/ctf-advanced.php
πŸ“ Register: https://forms.gle/bowpX9TGEs41GDG99
πŸ‘1
One tool. Multiple authentication methods. Remote Windows access. πŸ‘€

πŸ”₯ Impacket for Pentester: TSCTool

TSCTool gives pentesters a way to interact with Windows Terminal Services / Remote Desktop sessions remotely β€” a useful capability during authorized post-exploitation and lateral-movement assessments. ⚠️

πŸ“š In This Guide

πŸ–₯ Understand Windows Terminal Services
πŸ” Enumerate Remote Desktop Sessions
πŸ‘₯ Identify Active User Sessions
βš™οΈ Explore TSCTool Capabilities
πŸ”‘ Authenticate with Windows Credentials
🎫 Understand Kerberos-Based Authentication
🌐 Interact with Remote Sessions
🎯 Assess RDP Session Security
🧠 Analyze Session Management Risks
πŸ›‘ Monitor Terminal Services Activity
⚠️ Detection & Mitigation Strategies

πŸ’‘ RDP isn't just about connecting to a desktop.

Active sessions, session IDs, authentication mechanisms, and Terminal Services configuration can reveal valuable information during an authorized Windows security assessment.

πŸ“– Read the Full Guide:
https://www.hackingarticles.in/impacket-for-pentester-tstool/

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles
❀2
One Windows misconfiguration. One MSI file. SYSTEM access. πŸ‘€

πŸ”₯ AlwaysInstallElevated β€” Windows Privilege Escalation

What if a standard user could install an MSI package with administrative privileges?

That's exactly where AlwaysInstallElevated becomes dangerous. ⚠️

πŸ“š In This Guide

πŸ” Understand AlwaysInstallElevated
πŸ“‹ Enumerate HKCU & HKLM Registry Keys
βš™οΈ Identify the Misconfiguration
πŸ•΅οΈ Detect It with WinPEAS
πŸ“¦ Understand Malicious MSI Abuse
πŸš€ Explore Manual Privilege Escalation
πŸ’€ Understand SYSTEM-Level Execution
πŸ›  Exploit the Misconfiguration with Metasploit
🧠 Analyze the Attack Chain
πŸ›‘ Hardening Windows Installer Policies
⚠️ Detection & Mitigation Strategies

πŸ’‘ The scary part?

You don't always need a kernel exploit or a zero-day.

A dangerous Windows Installer policy can allow a low-privileged user to execute an MSI with elevated privileges and reach NT AUTHORITY\SYSTEM. πŸ‘€

πŸ“– Read the Full Guide:
https://www.hackingarticles.in/windows-privilege-escalation-alwaysinstallelevated/

πŸ”₯ Telegram: https://t.me/hackinarticles
✴️ Twitter: https://x.com/hackinarticles
❀2