Hacking Articles
21.2K subscribers
1.13K photos
165 files
777 links
House of Pentester
Download Telegram
πŸ”₯ OSCP+/CTF Exam Practice Training (Online) πŸ”₯ – Register Now! πŸš€

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Join IGNITE TECHNOLOGIES’ exclusive "Capture the Flag" Training Program and enhance your skills with the following modules:

🧠 Introduction
🌐 Information Gathering
🧱 Vulnerability Scanning
πŸ”“ Windows Privilege Escalation
🐧 Linux Privilege Escalation
πŸ›‘οΈ Client-Side Attacks
🌐 Web Application Attacks
🧬 Password Attacks
🧠 Tunneling & Pivoting
🏰 Active Directory Attacks
πŸ’£ Exploiting Public Exploits
πŸ“‹ Report Writing

#infosec #cybersecurity #cybersecuritytips #microsoft #AI #informationsecurity #CyberSec #microsoft #offensivesecurity #infosecurity #cyberattacks #security #oscp #cybersecurityawareness #bugbounty #bugbountytips
❀1
A Detailed Guide on Feroxbuster

✴ Twitter: https://lnkd.in/e7yRpDpY

Feroxbuster is a robust tool designed to identify directories and files on web servers using brute-force techniques. It is frequently utilized in penetration testing and security evaluations to detect concealed paths and resources.

☒ Lab setup
☒Installation
☒Default mode
☒Redirects
☒Extensions
☒Result output
☒User agent
☒Filter status code
☒Quiet mode
☒Controlling threads
☒Custom wordlist
☒Disable recursion
☒Limit recursion depth
☒Force Recursion
☒Filter by character size
☒Filter by number of words
☒Filter by number of lines
☒Filter by status code using deny list
☒Filter by status code using allow list
☒Generating random User-Agent
☒HTTP methods
❀1
A Detailed Guide on Tshark

✴ Twitter: https://lnkd.in/e7yRpDpY

In this article, we will learn about TShark which is a well-known network protocol analyzer. It lets us capture the data packets, from the live network. It also allows us, to read or analyze the previously captured data packets of a saved file.

⏺ Network traffic
⏺ Introduction to TShark
⏺ List interfaces
⏺ Capture traffic
⏺ Capture the interface in promiscuous mode
⏺ Capture the packet count
⏺ Read and Write in a file
⏺ Verbose mode
⏺ Output Formats
⏺ Difference between decoded packets and encoded packets
⏺ Converting PDML file HTML page
⏺ Capturing packets of a particular port
⏺ Display filter
❀2
πŸ” Firewall Audit Checklist: The Ultimate Security Review

Ensure your firewall is battle-ready with this comprehensive audit guide:

βœ” Pre-Audit Prep – Docs, diagrams & version checks
βœ” Access Control – Admin roles, password policies, VPN checks
βœ” Config Review – Rule order, DMZ setup, encryption status
βœ” Monitoring – Logging, IDS, incident response
βœ” Physical & Backup – Access logs, DR plans, patch management

πŸ”§ Critical Checks:
β€’ Test from trusted/untrusted networks
β€’ Verify "deny all except permitted" enforcement
β€’ Hunt for default credentials and stale accounts
❀1
❀1
Bug Bounty Training Program (Online)

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Hurry up, get enrolled yourself with IGNITE TECHNOLOGIES’ fully exclusive Training Program β€œBug Bounty.”

βœ”οΈ Table of Content
πŸš€ Introduction to WAPT & OWASP Top 10
πŸ› οΈ Pentest Lab Setup
πŸ” Information Gathering & Reconnaissance
πŸ’» Netcat for Pentester
βš™οΈ Configuration Management Testing
πŸ” Cryptography
πŸ”‘ Authentication
πŸ•’ Session Management
πŸ“‚ Local File Inclusion
🌐 Remote File Inclusion
πŸ“ Path Traversal
πŸ’£ OS Command Injection
πŸ”€ Open Redirect
πŸ“€ Unrestricted File Upload
🐚 PHP Web Shells
πŸ“ HTML Injection
🌟 Cross-Site Scripting (XSS)
πŸ”„ Client-Side Request Forgery
πŸ›‘ SQL Injection
πŸ“œ XXE Injection
🎁 Bonus Section
❀1πŸ”₯1
πŸ”₯ CISSP Training Program (Online) πŸ”₯ – Register Now! πŸš€

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Join Ignite Technologies CISSP live sessions with core practicals at Lowest Price.
BOOK YOUR Seat NOW ………….


πŸ” Security and Risk Management
πŸ“¦ Asset Security
πŸ— Security Architecture and Engineering
🌐 Communication and Network Security
πŸ§‘β€πŸ’» Identity and Access Management (IAM)
πŸ§ͺ Security Assessment and Testing
βš™οΈ Security Operations
πŸ’» Software Development Security
A Detailed Guide on Log4J Penetration Testing

✴ Twitter: https://lnkd.in/e7yRpDpY

In this article, we are going to discuss and demonstrate in our lab setup, the exploitation of the new vulnerability identified as CVE-2021-44228 affecting the java logging package, Log4J.

☒ Log4jShell
☒What is log4j
☒What is LDAP and JNDI
☒LDAP and JNDI Chemistry
☒Log4j JNDI lookup
☒Normal Log4j scenario
☒Exploit Log4j scenario
☒Pentest Lab Setup
☒Exploiting Log4j (CVE-2021-44228)
☒Mitigation
πŸ‘1