Hacking Articles
21.2K subscribers
1.13K photos
165 files
777 links
House of Pentester
Download Telegram
Windows Persistence using WinLogon

πŸ”₯ Telegram: https://t.me/hackinarticles

In this article, we are going to describe the ability of the WinLogon process to provide persistent access to the Target Machine.

πŸ“˜ Introduction
βš™οΈ Configurations Used in Practical
πŸ—οΈ Default Registry Key Values
πŸ“Œ Persistence Using WinLogon
πŸ”‘ Using Userinit Key
πŸ’» Using the Shell Key
πŸ•΅οΈ Detection
πŸ›‘οΈ Mitigation
❀1
Comprehensive Guide on XXE Injection

πŸ”₯ Telegram: https://t.me/hackinarticles

today in this article, we will learn how an attacker can use this vulnerability to gain information and try to defame web-application.

πŸ“˜ Introduction to XML
πŸ’‰ Introduction to XXE Injection
⚠️ Impacts
🌐 XXE for SSRF
πŸ“‚ Local File
🌍 Remote File
πŸ’£ XXE Billion Laugh Attack
πŸ“€ XXE using File Upload
πŸ–₯️ Remote Code Execution
πŸ§ͺ XSS via XXE
πŸ”§ JSON and Content Manipulation
πŸ‘οΈβ€πŸ—¨οΈ Blind XXE
πŸ›‘οΈ Mitigation Steps
❀1
GenAI Red Teaming Guide

✴ Twitter: Link
Key focus areas:

πŸ” Model Risks

Prompt injection, data leaks, hallucinations

πŸ›  System Weaknesses

API abuse, RAG poisoning, jailbreaks

☒ Runtime Threats

Social engineering, agent hijacking

πŸ”§ Top Tools

PyRIT, Garak, Promptfoo
❀3πŸ”₯1
API Penetration Testing Training (Online)

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Hurry up, get enrolled yourself with Ignite Technologies’ fully exclusive Training Program "API Penetration Testing Training."

βœ”οΈ Table of Content

πŸ“˜ Course Introduction
πŸ” How API works with Web application
βš–οΈ Types of APIs and their advantages/disadvantages
πŸ”Ž Analysing HTTP request and response headers
πŸ›‘οΈ API Hacking methodologies
πŸ“„ Enumerate web pages and analyse functionalities
πŸ•΅οΈ API passive reconnaissance Strategies
πŸš€ API active reconnaissance (Kite runner)
πŸ”§ Introduction to POSTMAN
πŸ” Testing for Excessive data exposure
πŸ“‚ Directory indexing / brute force
πŸ”‘ Password mutation
🎯 Password spray attacks against web application
πŸ›‘οΈ Introduction to JSON Web Token
πŸ•΅οΈ Hunting for JWT authentication vulnerabilities
πŸ’£ Exploiting JWT unverified signature
πŸ”“ Cracking JWT secret keys
🚫 Bypass JWT removing signature
πŸ’‰ Exploit jku header injection
πŸ”§ Exploit KID in JSON web tokens
πŸ” Attacking 0Auth 2.0
πŸ“Š Introduction to OWASP TOP 10 API
βš”οΈ Hunting and exploiting XXS in API
πŸ•΅οΈ Testing for the ReDOS attack in the API web application
πŸ’₯ Exploiting XML vulnerabilities
πŸ”§ WordPress XML-RPC attack
🌐 Exploiting WSDL/SOAP to RFI
πŸ€– API Automated Vulnerability scanning
πŸ’‰ Testing SQL/NoSQL Injection in an API
πŸ”“ Exploiting object-level access control
πŸ”§ Exploiting Function level access control
πŸ“‘ Testing in-band SSRF vulnerabilities in an API
🌍 Testing out-band SSRF vulnerabilities in an API
βš™οΈ Testing OS Command Injection
β˜• Exploiting Java deserialization vulnerabilities
πŸ—‚οΈ Testing for improper assets management
πŸ“¦ Testing for Mass assignment vulnerabilities
🚧 Bypass filter, space, and blacklisted characters
πŸ” Bypass Captcha and MFA
πŸ“‹ Remediations and Reporting
❀1
Windows PowerShell Networking Guide
❀1
Top Cloud Threats Coverage
😐1
🚨 Upcoming Webinar Alert – Advance Your Cybersecurity Career! πŸ›‘

Are you ready to take the next step in your cybersecurity journey?

Join us for an exclusive CISSP Webinar where industry experts will guide you through:

βœ… What it takes to become CISSP certified
βœ… Key domains of the (ISC)Β² Common Body of Knowledge (CBK)
βœ… Proven strategies to pass the CISSP exam
βœ… Career opportunities unlocked by CISSP certification

πŸ“… Date: 21 June 2025
πŸ•’ Time: 06:00 PM - 07:30 PM IST
⏳ Duration: 90 Mins (60 min walkthrough + 30 min Q&A)
πŸ“ Location: Online

Whether you're preparing for the CISSP exam or simply exploring the certification, this session will provide valuable insights and practical advice.

πŸ’‘ Don’t miss the chance to ask your questions live!

πŸ”— Join Us on WhatsApp to get the webinar link: https://chat.whatsapp.com/Da2fPnvXrGt5SvC6rpEtwm
πŸš€ Active Directory Exploitation Training (Online) – Register Now! πŸš€

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Limited slots available! Hurry up to secure your spot in this exclusive training program offered by Ignite Technologies.

βœ”οΈ Comprehensive Table of Contents:
πŸ” Initial Active Directory Exploitation
πŸ”Ž Active Directory Post-Enumeration
πŸ” Abusing Kerberos
🧰 Advanced Credential Dumping Attacks
πŸ“ˆ Privilege Escalation Techniques
πŸ”„ Persistence Methods
πŸ”€ Lateral Movement Strategies
πŸ›‘ DACL Abuse (New)
🏴 ADCS Attacks (New)
πŸ’Ž Saphire and Diamond Ticket Attacks (New)
🎁 Bonus Sessions
❀2