Hacking Articles
21.1K subscribers
1.13K photos
165 files
777 links
House of Pentester
Download Telegram
DFIR Mindmap
πŸš€ Active Directory Penetration Training (Online) – Register Now! πŸš€

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Limited slots available! Hurry up to secure your spot in this exclusive training program offered by Ignite Technologies.

βœ”οΈ Comprehensive Table of Contents:
πŸ” Initial Active Directory Exploitation
πŸ”Ž Active Directory Post-Enumeration
πŸ” Abusing Kerberos
🧰 Advanced Credential Dumping Attacks
πŸ“ˆ Privilege Escalation Techniques
πŸ”„ Persistence Methods
πŸ”€ Lateral Movement Strategies
πŸ›‘ DACL Abuse (New)
🏴 ADCS Attacks (New)
πŸ’Ž Saphire and Diamond Ticket Attacks (New)
🎁 Bonus Sessions
❀2
Linux Cheat Sheet
Linux Command Line
❀1
Git cheat sheet
git command
DevOPS Roadmap
Cybersecurity Conference
Anti Forensics
Infosec Dorks
API Penetration Testing Training (Online)

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Hurry up, get enrolled yourself with Ignite Technologies’ fully exclusive Training Program "API Penetration Testing Training."

βœ”οΈ Table of Content

πŸ“˜ Course Introduction
πŸ” How API works with Web application
βš–οΈ Types of APIs and their advantages/disadvantages
πŸ”Ž Analysing HTTP request and response headers
πŸ›‘ API Hacking methodologies
πŸ“„ Enumerate web pages and analyse functionalities
πŸ•΅οΈ API passive reconnaissance Strategies
πŸš€ API active reconnaissance (Kite runner)
πŸ”§ Introduction to POSTMAN
πŸ” Testing for Excessive data exposure
πŸ“‚ Directory indexing / brute force
πŸ”‘ Password mutation
🎯 Password spray attacks against web application
πŸ›‘ Introduction to JSON Web Token
πŸ•΅οΈ Hunting for JWT authentication vulnerabilities
πŸ’£ Exploiting JWT unverified signature
πŸ”“ Cracking JWT secret keys
🚫 Bypass JWT removing signature
Linux Privilege Escalation
🀯1
Antivirus vs EDR vs XDR
DORA Regulation: Cybersecurity Rules Explained Like a Bank Heist Movie
πŸ”— Twitter: Share this thread

Learn how the EU’s Digital Operational Resilience Act (DORA) protects financial systems like an elite security team:

πŸ” ICT Risk Management
"Bank vault with laser sensors, guard shifts, and backup keys."
β†’ Must identify, assess, and mitigate cyber risks.

🚨 Incident Reporting
"Alarm triggers β†’ SWAT team notified in 5 mins."
β†’ Major cyber incidents must be reported immediately.

πŸ’» Resilience Testing
"Annual bank robbery drills (even fake hackers try)."
β†’ Penetration tests & Threat-Led Testing every 3 years.

🀝 Third-Party Risk
"Security checks for every delivery guy entering the bank."
β†’ IT vendors must meet strict cybersecurity standards.

⚠ Penalties for Failure
"Get caught with weak locks? Huge fine + public shame."
β†’ Up to 1% global revenue fines for critical IT providers.
❀1
Path Traversal Attack

πŸ”₯ Telegram: https://t.me/hackinarticles

Today, in this article we will explore one of the most critical vulnerabilities, that arises when the developer does not validate the inclusion functions in the web-applications, which thus allows the attacker to read and access any sensitive file from the server.

πŸ“ Basic Path Traversal
🚫 Blocked Traversal Sequence
βœ… Validated Path Traversal
🌐 Path Disclosure in URL
🧡 Null Byte Bypass
ADCS ESC10 – Weak Certificate Mapping

πŸ”₯ Telegram: https://t.me/hackinarticles

ESC10 is a powerful post-exploitation technique in Active Directory Certificate Services (ADCS) that lets attackers authenticate as any user even Domain Admins without knowing their password.

πŸ“˜ Overview of the ESC10 Attack
βš™οΈ Working of ESC10
πŸ”„ ESC10 as an Extension of ESC9
πŸ“‹ Prerequisites
πŸ§ͺ Lab Setup
πŸ”Ž Enumeration & Exploitation
🧠 Post Exploitation
πŸ›‘οΈ Mitigation