Hacking Articles
21.1K subscribers
1.13K photos
165 files
777 links
House of Pentester
Download Telegram
Path Traversal Attack

๐Ÿ”ฅ Telegram: https://t.me/hackinarticles

Today, in this article we will explore one of the most critical vulnerabilities, that arises when the developer does not validate the inclusion functions in the web-applications, which thus allows the attacker to read and access any sensitive file from the server.

๐Ÿ“ Basic Path Traversal
๐Ÿšซ Blocked Traversal Sequence
โœ… Validated Path Traversal
๐ŸŒ Path Disclosure in URL
๐Ÿงต Null Byte Bypass
ADCS ESC10 โ€“ Weak Certificate Mapping

๐Ÿ”ฅ Telegram: https://t.me/hackinarticles

ESC10 is a powerful post-exploitation technique in Active Directory Certificate Services (ADCS) that lets attackers authenticate as any user even Domain Admins without knowing their password.

๐Ÿ“˜ Overview of the ESC10 Attack
โš™๏ธ Working of ESC10
๐Ÿ”„ ESC10 as an Extension of ESC9
๐Ÿ“‹ Prerequisites
๐Ÿงช Lab Setup
๐Ÿ”Ž Enumeration & Exploitation
๐Ÿง  Post Exploitation
๐Ÿ›ก๏ธ Mitigation
๐Ÿšจ Start Your Bug Bounty Journey โ€” Find & Exploit Real-World Vulnerabilities.

๐Ÿง  Real-world web flaws. ๐Ÿ’ป Hands-on labs. ๐ŸŽฏ Career-ready skills.

๐Ÿ”— Register Now โ†’ https://forms.gle/bowpX9TGEs41GDG99
๐Ÿ“ฒ Chat on WhatsApp โ†’ https://wa.me/message/HIOPPNENLOX6F1
๐Ÿ’ฅ Only โ‚น41,000 / $495 โ€“ Limited Seats

Why Join?

โฆ Master web app hacking & OWASP Top 10 vulnerabilities
โฆ Learn real-world recon, exploitation & bug reporting
โฆ Hands-on labs with bug bounty hunting scenarios
โฆ Live sessions with experts + recordings access
โฆ Bonus: Responsible disclosure & professional reporting tips

๐ŸŽ“ Perfect For:
โœ”๏ธ Bug Bounty Hunters (beginner & intermediate)
โœ”๏ธ OSCP/OSEP aspirants
โœ”๏ธ Pentesters sharpening web app skills
โœ”๏ธ Ethical hackers aiming for paid bounties

๐Ÿ’ก Not just another course.
This is hands-on bug bounty training, built by real-world hunters.

๐Ÿ“ง info@ignitetechnologies.in
๐ŸŒ www.ignitetechnologies.in
โค1
Cryptocurrency Attack OSINT
Personnel security mind map
๐Ÿ‘1
Linux Command Line
Netcat cmd
๐Ÿ‘2
IPSec Modes of Operation
๐Ÿฅฐ2
๐Ÿšจ Learn Red Teaming Like a Pro โ€” From Initial Access to Exfiltration.

๐Ÿง  Adversary simulation. ๐Ÿ’ป Hands-on labs. ๐ŸŽฏ Career-ready red team skills.

๐Ÿ”— Register Now โ†’ https://forms.gle/bowpX9TGEs41GDG99
๐Ÿ“ฒ Chat on WhatsApp โ†’ https://wa.me/message/HIOPPNENLOX6F1
๐Ÿ“ง Email โ†’ info@ignitetechnologies.in
๐Ÿ’ฅ Only โ‚น41,000 / $495 โ€“ Limited Seats

Why Join?

โฆ Simulate full attack chains: delivery, weaponization, and privilege escalation
โฆ Learn C2 setup, lateral movement & Active Directory exploitation
โฆ Practice defense evasion, persistence & data exfiltration techniques
โฆ Live sessions led by red teamers + recording access
โฆ Bonus: Real-world reporting & OPSEC practices included

๐ŸŽ“ Perfect For:
โœ”๏ธ Red Teamers & Adversary Simulation Professionals
โœ”๏ธ OSCP / CRTP / CRTO aspirants
โœ”๏ธ Pentesters moving into full-scope attacks
โœ”๏ธ SOC Analysts learning offensive strategies

๐Ÿ’ก Not just another attack lab.
This is real-world Red Team training โ€” built by operators, for operators.

๐ŸŒ www.ignitetechnologies.in
๐Ÿ“ง info@ignitetechnologies.in
โค1
Cyber Attack
๐Ÿ‘1
5 Tools for AD Enumeration
๐Ÿ”ฅ2๐Ÿ‘1
9 Ways to gain Expersience in CYber Security
๐Ÿ‘1
Amazing SOC Analyst Skills
Comprehensive Guide on HTML Injection

๐Ÿ”ฅ Telegram: https://t.me/hackinarticles

Today, in this article, weโ€™ll learn how such misconfigured HTML codes, open the gates for the attackers to manipulate the designed webpages and grabs up the sensitive data from the users.

๐ŸŒ What is HTML?
๐Ÿ“˜ Introduction to HTML Injection
๐Ÿ’ฅ Impact of HTML Injection
โš”๏ธ HTML Injection vs XSS
๐Ÿงฌ Types of Injection
๐Ÿ’พ Stored HTML
๐Ÿ” Reflected HTML
๐Ÿ“ฅ Reflected GET
๐Ÿ“ค Reflected POST
๐Ÿ”— Reflected Current URL
MSSQL for Pentester: NetExec

๐Ÿ”ฅ Telegram: https://t.me/hackinarticles

MSSQL NetExec Pentesting is an essential technique for red teamers and penetration testers who want to automate attacks against Microsoft SQL Servers.

๐Ÿงช Lab Setup
๐ŸŽฏ Password Spray
๐Ÿ”‘ Password Spray Using Hashes
โœ… Check Authentication
๐Ÿ—„๏ธ DB Command Execution Using nxc
๐Ÿ’ป Command Execution Using nxc
๐Ÿ” Command Execution With Hashes
๐Ÿ“ค๐Ÿ“ฅ File Upload and Download
๐Ÿš€ Privilege Escalation
๐Ÿ“ก Enumeration on a Different Port Number
๐Ÿ“˜ Conclusion