Hacking Articles
21.2K subscribers
1.13K photos
165 files
777 links
House of Pentester
Download Telegram
John the Ripper Cheat Sheet

πŸ”΄βš«οΈFull HD Image: https://github.com/Ignitetechnologies/Mindmap/blob/main/John/John%20HD.png
πŸ”₯ OSCP+/CTF Exam Practice Training (Online) πŸ”₯ – Register Now! πŸš€

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Join IGNITE TECHNOLOGIES’ exclusive "Capture the Flag" Training Program and enhance your skills with the following modules:

🧠 Introduction
🌐 Information Gathering
🧱 Vulnerability Scanning
πŸ”“ Windows Privilege Escalation
🐧 Linux Privilege Escalation
πŸ›‘οΈ Client-Side Attacks
🌐 Web Application Attacks
🧬 Password Attacks
🧠 Tunneling & Pivoting
🏰 Active Directory Attacks
πŸ’£ Exploiting Public Exploits
πŸ“‹ Report Writing
Comprehensive Guide on SSH Tunneling

✴ Twitter: https://lnkd.in/e7yRpDpY

SSH Tunnel: Tunneling is the concept to encapsulate the network protocol to another protocol here we put into SSH, so all network communication is encrypted. Because tunneling involves repackaging the traffic data into a different form, perhaps with encryption as standard, a third use is to hide the nature of the traffic that is run through the tunnels

➑ Dynamic SSH tunneling
➑ Local SSH tunneling
➑ Remote SSH tunneling
A Detailed Guide on OS Command Injection

πŸ”₯ Telegram: https://t.me/hackinarticles

In this article, we’ll learn about OS Command Injection, in which an attacker is able to trigger some arbitrary system shell commands on the hosted operating system via a vulnerable web-application.

πŸ“˜ Introduction to Command Injection
❓ How Command Injection Occurs?
πŸ”£ Metacharacters
πŸ“‚ Types of Command Injection
πŸ’₯ Impact of OS Command Injection
🧭 Steps to Exploit – OS Command Injection
πŸ› οΈ Manual Exploitation
πŸ“Ÿ Basic OS Command Injection
🚫 Bypass a Blacklist Implemented
πŸ€– Exploitation through Automated Tools
πŸ§ͺ Burp Suite
✍️ Manual
πŸŒͺ️ Fuzzing
🧬 Commix
🎯 Metasploit
πŸ‘οΈ Blind OS Command Injection
πŸ” Detection
πŸ’£ Exploitation
Bug Bounty Training Program (Online)

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Hurry up, get enrolled yourself with IGNITE TECHNOLOGIES’ fully exclusive Training Program β€œBug Bounty.”

βœ”οΈ Table of Content
πŸš€ Introduction to WAPT & OWASP Top 10
πŸ› οΈ Pentest Lab Setup
πŸ” Information Gathering & Reconnaissance
πŸ’» Netcat for Pentester
βš™οΈ Configuration Management Testing
πŸ” Cryptography
πŸ”‘ Authentication
πŸ•’ Session Management
πŸ“‚ Local File Inclusion
🌐 Remote File Inclusion
πŸ“ Path Traversal
πŸ’£ OS Command Injection
πŸ”€ Open Redirect
πŸ“€ Unrestricted File Upload
🐚 PHP Web Shells
πŸ“ HTML Injection
🌟 Cross-Site Scripting (XSS)
πŸ”„ Client-Side Request Forgery
πŸ›‘ SQL Injection
πŸ“œ XXE Injection
🎁 Bonus Section
❀2
Multiple Ways to Crack WordPress login

πŸ”₯ Telegram: https://t.me/hackinarticles

In this article, you will be learning how to compromise a WordPress website’s credentials using different brute-force techniques.

πŸ“š Pre-requisites
πŸ›°οΈ WPScan
πŸ’₯ Metasploit
πŸ§ͺ Burp Suite
πŸ›‘οΈ How to avoid a Brute Force Attack?
❀1
Burp Suite for Pentester: Web Scanner & Crawler

✴ Twitter: https://lnkd.in/e7yRpDpY
πŸ”₯Telegram: https://t.me/hackinarticles

In this article, we’ll discuss how you can identify hidden web pages or determine the existing vulnerabilities in a web application. To do this, we will use one of the best intercepting tools – β€œBurp Suite”.

πŸ•·οΈ The Burp’s Crawler
 ❓ What is Crawler?
β€ƒβš™οΈ Crawl with Default Configurations
β€ƒπŸ› οΈ Customizing the Crawler

πŸ›‘οΈ Vulnerability Scanning over Burp Suite
β€ƒπŸ” Auditing with Default Configurations
β€ƒπŸŽ›οΈ Defining Audit Options

πŸ”„ Crawling & Scanning with an Advanced Scenario
πŸ—‘οΈ Deleting the Defined Tasks
Mitre Collection