Hacking Articles
21.2K subscribers
1.13K photos
165 files
777 links
House of Pentester
Download Telegram
Bug Bounty Training Program (Online)

๐Ÿ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
๐Ÿ’ฌ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

๐Ÿ“ง Email: info@ignitetechnologies.in

Hurry up, get enrolled yourself with IGNITE TECHNOLOGIESโ€™ fully exclusive Training Program โ€œBug Bounty.โ€

โœ”๏ธ Table of Content
๐Ÿš€ Introduction to WAPT & OWASP Top 10
๐Ÿ› ๏ธ Pentest Lab Setup
๐Ÿ” Information Gathering & Reconnaissance
๐Ÿ’ป Netcat for Pentester
โš™๏ธ Configuration Management Testing
๐Ÿ” Cryptography
๐Ÿ”‘ Authentication
๐Ÿ•’ Session Management
๐Ÿ“‚ Local File Inclusion
๐ŸŒ Remote File Inclusion
๐Ÿ“ Path Traversal
๐Ÿ’ฃ OS Command Injection
๐Ÿ”€ Open Redirect
๐Ÿ“ค Unrestricted File Upload
๐Ÿš PHP Web Shells
๐Ÿ“ HTML Injection
๐ŸŒŸ Cross-Site Scripting (XSS)
๐Ÿ”„ Client-Side Request Forgery
๐Ÿ›‘ SQL Injection
๐Ÿ“œ XXE Injection
๐ŸŽ Bonus Section
โค3
๐Ÿ“ก Wireless Penetration Testing Using Aircrack-ng

Master wireless security assessments with this comprehensive guide to Aircrack-ng, the essential WiFi hacking toolkit:

โ€ข Captures WiFi handshakes (monitor mode)
โ€ข Cracks WPA/WPA2 passwords (dictionary attacks)
โ€ข Analyzes network traffic (packet injection)
โ€ข Supports all major wireless adapters

๐Ÿ” Key Attacks Covered:

WEP cracking

WPA/WPA2-PSK brute force

Deauthentication attacks

๐Ÿ“– Full Tutorial: Read Here
โค2๐Ÿ†’2
docker.png
1.3 MB
๐Ÿณ Docker Privilege Escalation Techniques

Escalate privileges in containerized environments using critical misconfigurations:

โ€ข Breakout Methods:
Abusing --privileged flag
Exploiting writable cgroups
Docker socket exposure (/var/run/docker.sock)
Capability abuse (e.g., CAP_SYS_ADMIN)

โ€ข Post-Exploitation:
Host filesystem access
Container-to-host process injection
Stealing secrets from mounted volumes

๐Ÿ” Mitigation:
Principle of Least Privilege
Read-only containers
Regular vulnerability scanning

๐Ÿ“– Full Guide: Docker Privilege Escalation
โค3
๐Ÿ” Learn SIEM with He-Man โ€“ The Defender of Eterniaโ€™s Cybersecurity!

This fun yet powerful guide explains Security Information & Event Management (SIEM) using He-Manโ€™s world:
โœ… Log Collection: Like Castle Grayskullโ€™s magic, SIEM gathers logs from servers, firewalls, and even Skeletorโ€™s lair!
โœ… Threat Detection: Correlates events (e.g., five login failures in 2 minutes = attack!).
โœ… Dashboards & Alerts: Real-time threat visualizationโ€”no magic, just data!
โœ… False Positives: "Royal teapot accessed at midnight?" Not every alert is evil.
โœ… Compliance: Generates reports for audits (ISO, SOC 2).
โค3
The Accenture Global Cybersecurity Outlook for 2025
Cybersecurity Handbook 2025
โค2
Comprehensive Guide on Unrestricted File Upload

Today, in this article, weโ€™ll learn how such invalidations to the user-input and server mismanagement, opens up the gates for the attackers to host malicious content, over from the Unrestricted File Upload functionality in order to drop down the web-applications..


๐Ÿ“ Basic File Upload
๐Ÿ“ฆ Content-Type Restriction
๐Ÿงพ Double Extension File Upload
๐Ÿ–ผ๏ธ Image Size Validation Bypass
๐Ÿšซ Blacklisted Extension File Upload
โค3๐Ÿ”ฅ1