Hacking Articles
21.2K subscribers
1.13K photos
165 files
777 links
House of Pentester
Download Telegram
Bug Bounty Training Program (Online)

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Hurry up, get enrolled yourself with IGNITE TECHNOLOGIES’ fully exclusive Training Program β€œBug Bounty.”

βœ”οΈ Table of Content
πŸš€ Introduction to WAPT & OWASP Top 10
πŸ› οΈ Pentest Lab Setup
πŸ” Information Gathering & Reconnaissance
πŸ’» Netcat for Pentester
βš™οΈ Configuration Management Testing
πŸ” Cryptography
πŸ”‘ Authentication
πŸ•’ Session Management
πŸ“‚ Local File Inclusion
🌐 Remote File Inclusion
πŸ“ Path Traversal
πŸ’£ OS Command Injection
πŸ”€ Open Redirect
πŸ“€ Unrestricted File Upload
🐚 PHP Web Shells
πŸ“ HTML Injection
🌟 Cross-Site Scripting (XSS)
πŸ”„ Client-Side Request Forgery
πŸ›‘ SQL Injection
πŸ“œ XXE Injection
🎁 Bonus Section
❀1πŸ”₯1
πŸ”₯ CISSP Training Program (Online) πŸ”₯ – Register Now! πŸš€

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Join Ignite Technologies CISSP live sessions with core practicals at Lowest Price.
BOOK YOUR Seat NOW ………….


πŸ” Security and Risk Management
πŸ“¦ Asset Security
πŸ— Security Architecture and Engineering
🌐 Communication and Network Security
πŸ§‘β€πŸ’» Identity and Access Management (IAM)
πŸ§ͺ Security Assessment and Testing
βš™οΈ Security Operations
πŸ’» Software Development Security
A Detailed Guide on Log4J Penetration Testing

✴ Twitter: https://lnkd.in/e7yRpDpY

In this article, we are going to discuss and demonstrate in our lab setup, the exploitation of the new vulnerability identified as CVE-2021-44228 affecting the java logging package, Log4J.

☒ Log4jShell
☒What is log4j
☒What is LDAP and JNDI
☒LDAP and JNDI Chemistry
☒Log4j JNDI lookup
☒Normal Log4j scenario
☒Exploit Log4j scenario
☒Pentest Lab Setup
☒Exploiting Log4j (CVE-2021-44228)
☒Mitigation
πŸ‘1
A Detailed Guide on Data Exfiltration Using DNSSteal

✴ Twitter: Link

In this article, we demonstrate how attackers stealthily exfiltrate data using DNS queries, bypassing traditional security controls.

☒ What is DNS Exfiltration?
☒ How DNSSteal Works
☒ Lab Setup for DNS Tunneling
☒ Configuring Attacker Server
☒ Sending Data via DNS Queries
☒ Capturing Exfiltrated Data
☒ Detection & Mitigation Strategies
A Detailed Guide on ICS/OT Cyber Security Lab Manual

✴ Twitter: Link

Master industrial control system security with this hands-on lab manual covering:

☒ ICS/OT Fundamentals – Key differences from IT, critical controls
☒ Protocol Analysis – Modbus, Wireshark captures, TCP/IP inspection
☒ Secure Architecture – Purdue Model, IT/OT DMZ, ACL reviews
☒ Threat Hunting – Asset registers, vulnerability scanning (Nmap/Nessus)
☒ OSINT Techniques – Shodan, Google dorks, LinkedIn recon
☒ Incident Response – Backdoors & Breaches (ICS OT Core Deck)
πŸš€ Join Ignite Technologies' Red Team Operation Course Online! πŸš€

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Enroll now in our exclusive "Red Teaming" Training Program and explore the following modules:

βœ… Introduction to Red Team
πŸ“© Initial Access & Delivery
βš™οΈ Weaponization
🌐 Command and Control (C2)
πŸ”Ό Escalate Privileges
πŸ” Credential Dumping
πŸ–§ Active Directory Exploitation
πŸ”€ Lateral Movement
πŸ”„ Persistence
πŸ“€ Data Exfiltration
πŸ›‘οΈ Defense Evasion
πŸ“ Reporting


Join us for a comprehensive learning experience! πŸ”’πŸ’»πŸ”
Tomcat Penetration Testing

✴ Twitter: https://lnkd.in/e7yRpDpY

In this article, we are going to setup the Tomcat server on the ubuntu machine and exploit the file upload vulnerability. Following are the machines:

πŸ€ Lab Setup
πŸ€Installation
πŸ€Configuration
πŸ€Enumeration
πŸ€Exploitation using Metasploit Framework
πŸ€Exploiting Manually (Reverse shell)
πŸ€Exploiting Manually (Web shell)
πŸ€Conclusion