Hacking Articles
21.2K subscribers
1.13K photos
165 files
777 links
House of Pentester
Download Telegram
WPScan: WordPress Pentesting Framework

πŸ”₯ Telegram: https://t.me/hackinarticles

In this article, we’ll show how to deface WordPress sites using WPScan, as most websites run on CMS platforms like WordPress.

πŸ“˜ Introduction
πŸ”Ž Enumerating the WordPress Web Application
πŸ“¦ Version Scanning
🎨 WordPress Themes
πŸ”Œ WordPress Plugins
πŸ‘€ WordPress Usernames
🧾 All in a Single Command
πŸ’₯ WordPress Exploitation
🎯 Brute Force Attack Using WPScan
🐚 Shell Upload Using Metasploit
🧨 Vulnerable Plugin Exploitation
πŸ•΅οΈβ€β™‚οΈ Scanning Over a Proxy Server
πŸ” Scanning With an HTTP Authentication Enabled
πŸ”₯1
❀1
Impacket Library Cheat Sheet

πŸ”΄βš«οΈFull HD Image: https://github.com/Ignitetechnologies/Mindmap/blob/main/Impacket/impacket%20HD.png
John the Ripper Cheat Sheet

πŸ”΄βš«οΈFull HD Image: https://github.com/Ignitetechnologies/Mindmap/blob/main/John/John%20HD.png
πŸ”₯ OSCP+/CTF Exam Practice Training (Online) πŸ”₯ – Register Now! πŸš€

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Join IGNITE TECHNOLOGIES’ exclusive "Capture the Flag" Training Program and enhance your skills with the following modules:

🧠 Introduction
🌐 Information Gathering
🧱 Vulnerability Scanning
πŸ”“ Windows Privilege Escalation
🐧 Linux Privilege Escalation
πŸ›‘οΈ Client-Side Attacks
🌐 Web Application Attacks
🧬 Password Attacks
🧠 Tunneling & Pivoting
🏰 Active Directory Attacks
πŸ’£ Exploiting Public Exploits
πŸ“‹ Report Writing
Comprehensive Guide on SSH Tunneling

✴ Twitter: https://lnkd.in/e7yRpDpY

SSH Tunnel: Tunneling is the concept to encapsulate the network protocol to another protocol here we put into SSH, so all network communication is encrypted. Because tunneling involves repackaging the traffic data into a different form, perhaps with encryption as standard, a third use is to hide the nature of the traffic that is run through the tunnels

➑ Dynamic SSH tunneling
➑ Local SSH tunneling
➑ Remote SSH tunneling
A Detailed Guide on OS Command Injection

πŸ”₯ Telegram: https://t.me/hackinarticles

In this article, we’ll learn about OS Command Injection, in which an attacker is able to trigger some arbitrary system shell commands on the hosted operating system via a vulnerable web-application.

πŸ“˜ Introduction to Command Injection
❓ How Command Injection Occurs?
πŸ”£ Metacharacters
πŸ“‚ Types of Command Injection
πŸ’₯ Impact of OS Command Injection
🧭 Steps to Exploit – OS Command Injection
πŸ› οΈ Manual Exploitation
πŸ“Ÿ Basic OS Command Injection
🚫 Bypass a Blacklist Implemented
πŸ€– Exploitation through Automated Tools
πŸ§ͺ Burp Suite
✍️ Manual
πŸŒͺ️ Fuzzing
🧬 Commix
🎯 Metasploit
πŸ‘οΈ Blind OS Command Injection
πŸ” Detection
πŸ’£ Exploitation
Bug Bounty Training Program (Online)

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Hurry up, get enrolled yourself with IGNITE TECHNOLOGIES’ fully exclusive Training Program β€œBug Bounty.”

βœ”οΈ Table of Content
πŸš€ Introduction to WAPT & OWASP Top 10
πŸ› οΈ Pentest Lab Setup
πŸ” Information Gathering & Reconnaissance
πŸ’» Netcat for Pentester
βš™οΈ Configuration Management Testing
πŸ” Cryptography
πŸ”‘ Authentication
πŸ•’ Session Management
πŸ“‚ Local File Inclusion
🌐 Remote File Inclusion
πŸ“ Path Traversal
πŸ’£ OS Command Injection
πŸ”€ Open Redirect
πŸ“€ Unrestricted File Upload
🐚 PHP Web Shells
πŸ“ HTML Injection
🌟 Cross-Site Scripting (XSS)
πŸ”„ Client-Side Request Forgery
πŸ›‘ SQL Injection
πŸ“œ XXE Injection
🎁 Bonus Section
❀2
Multiple Ways to Crack WordPress login

πŸ”₯ Telegram: https://t.me/hackinarticles

In this article, you will be learning how to compromise a WordPress website’s credentials using different brute-force techniques.

πŸ“š Pre-requisites
πŸ›°οΈ WPScan
πŸ’₯ Metasploit
πŸ§ͺ Burp Suite
πŸ›‘οΈ How to avoid a Brute Force Attack?
❀1