Hacking Articles
21.2K subscribers
1.13K photos
165 files
777 links
House of Pentester
Download Telegram
πŸ” Firewall Audit Checklist: The Ultimate Security Review

Ensure your firewall is battle-ready with this comprehensive audit guide:

βœ” Pre-Audit Prep – Docs, diagrams & version checks
βœ” Access Control – Admin roles, password policies, VPN checks
βœ” Config Review – Rule order, DMZ setup, encryption status
βœ” Monitoring – Logging, IDS, incident response
βœ” Physical & Backup – Access logs, DR plans, patch management

πŸ”§ Critical Checks:
β€’ Test from trusted/untrusted networks
β€’ Verify "deny all except permitted" enforcement
β€’ Hunt for default credentials and stale accounts
❀1
❀1
Bug Bounty Training Program (Online)

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Hurry up, get enrolled yourself with IGNITE TECHNOLOGIES’ fully exclusive Training Program β€œBug Bounty.”

βœ”οΈ Table of Content
πŸš€ Introduction to WAPT & OWASP Top 10
πŸ› οΈ Pentest Lab Setup
πŸ” Information Gathering & Reconnaissance
πŸ’» Netcat for Pentester
βš™οΈ Configuration Management Testing
πŸ” Cryptography
πŸ”‘ Authentication
πŸ•’ Session Management
πŸ“‚ Local File Inclusion
🌐 Remote File Inclusion
πŸ“ Path Traversal
πŸ’£ OS Command Injection
πŸ”€ Open Redirect
πŸ“€ Unrestricted File Upload
🐚 PHP Web Shells
πŸ“ HTML Injection
🌟 Cross-Site Scripting (XSS)
πŸ”„ Client-Side Request Forgery
πŸ›‘ SQL Injection
πŸ“œ XXE Injection
🎁 Bonus Section
❀1πŸ”₯1
πŸ”₯ CISSP Training Program (Online) πŸ”₯ – Register Now! πŸš€

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Join Ignite Technologies CISSP live sessions with core practicals at Lowest Price.
BOOK YOUR Seat NOW ………….


πŸ” Security and Risk Management
πŸ“¦ Asset Security
πŸ— Security Architecture and Engineering
🌐 Communication and Network Security
πŸ§‘β€πŸ’» Identity and Access Management (IAM)
πŸ§ͺ Security Assessment and Testing
βš™οΈ Security Operations
πŸ’» Software Development Security
A Detailed Guide on Log4J Penetration Testing

✴ Twitter: https://lnkd.in/e7yRpDpY

In this article, we are going to discuss and demonstrate in our lab setup, the exploitation of the new vulnerability identified as CVE-2021-44228 affecting the java logging package, Log4J.

☒ Log4jShell
☒What is log4j
☒What is LDAP and JNDI
☒LDAP and JNDI Chemistry
☒Log4j JNDI lookup
☒Normal Log4j scenario
☒Exploit Log4j scenario
☒Pentest Lab Setup
☒Exploiting Log4j (CVE-2021-44228)
☒Mitigation
πŸ‘1
A Detailed Guide on Data Exfiltration Using DNSSteal

✴ Twitter: Link

In this article, we demonstrate how attackers stealthily exfiltrate data using DNS queries, bypassing traditional security controls.

☒ What is DNS Exfiltration?
☒ How DNSSteal Works
☒ Lab Setup for DNS Tunneling
☒ Configuring Attacker Server
☒ Sending Data via DNS Queries
☒ Capturing Exfiltrated Data
☒ Detection & Mitigation Strategies
A Detailed Guide on ICS/OT Cyber Security Lab Manual

✴ Twitter: Link

Master industrial control system security with this hands-on lab manual covering:

☒ ICS/OT Fundamentals – Key differences from IT, critical controls
☒ Protocol Analysis – Modbus, Wireshark captures, TCP/IP inspection
☒ Secure Architecture – Purdue Model, IT/OT DMZ, ACL reviews
☒ Threat Hunting – Asset registers, vulnerability scanning (Nmap/Nessus)
☒ OSINT Techniques – Shodan, Google dorks, LinkedIn recon
☒ Incident Response – Backdoors & Breaches (ICS OT Core Deck)