Hacking Articles
21.1K subscribers
1.13K photos
165 files
777 links
House of Pentester
Download Telegram
ADCS ESC10 – Weak Certificate Mapping

πŸ”₯ Telegram: https://t.me/hackinarticles

ESC10 is a powerful post-exploitation technique in Active Directory Certificate Services (ADCS) that lets attackers authenticate as any user even Domain Admins without knowing their password.

πŸ“˜ Overview of the ESC10 Attack
βš™οΈ Working of ESC10
πŸ”„ ESC10 as an Extension of ESC9
πŸ“‹ Prerequisites
πŸ§ͺ Lab Setup
πŸ”Ž Enumeration & Exploitation
🧠 Post Exploitation
πŸ›‘οΈ Mitigation
🚨 Start Your Bug Bounty Journey β€” Find & Exploit Real-World Vulnerabilities.

🧠 Real-world web flaws. πŸ’» Hands-on labs. 🎯 Career-ready skills.

πŸ”— Register Now β†’ https://forms.gle/bowpX9TGEs41GDG99
πŸ“² Chat on WhatsApp β†’ https://wa.me/message/HIOPPNENLOX6F1
πŸ’₯ Only β‚Ή41,000 / $495 – Limited Seats

Why Join?

⦁ Master web app hacking & OWASP Top 10 vulnerabilities
⦁ Learn real-world recon, exploitation & bug reporting
⦁ Hands-on labs with bug bounty hunting scenarios
⦁ Live sessions with experts + recordings access
⦁ Bonus: Responsible disclosure & professional reporting tips

πŸŽ“ Perfect For:
βœ”οΈ Bug Bounty Hunters (beginner & intermediate)
βœ”οΈ OSCP/OSEP aspirants
βœ”οΈ Pentesters sharpening web app skills
βœ”οΈ Ethical hackers aiming for paid bounties

πŸ’‘ Not just another course.
This is hands-on bug bounty training, built by real-world hunters.

πŸ“§ info@ignitetechnologies.in
🌐 www.ignitetechnologies.in
❀1
Cryptocurrency Attack OSINT
Personnel security mind map
πŸ‘1
Linux Command Line
Netcat cmd
πŸ‘2
IPSec Modes of Operation
πŸ₯°2
🚨 Learn Red Teaming Like a Pro β€” From Initial Access to Exfiltration.

🧠 Adversary simulation. πŸ’» Hands-on labs. 🎯 Career-ready red team skills.

πŸ”— Register Now β†’ https://forms.gle/bowpX9TGEs41GDG99
πŸ“² Chat on WhatsApp β†’ https://wa.me/message/HIOPPNENLOX6F1
πŸ“§ Email β†’ info@ignitetechnologies.in
πŸ’₯ Only β‚Ή41,000 / $495 – Limited Seats

Why Join?

⦁ Simulate full attack chains: delivery, weaponization, and privilege escalation
⦁ Learn C2 setup, lateral movement & Active Directory exploitation
⦁ Practice defense evasion, persistence & data exfiltration techniques
⦁ Live sessions led by red teamers + recording access
⦁ Bonus: Real-world reporting & OPSEC practices included

πŸŽ“ Perfect For:
βœ”οΈ Red Teamers & Adversary Simulation Professionals
βœ”οΈ OSCP / CRTP / CRTO aspirants
βœ”οΈ Pentesters moving into full-scope attacks
βœ”οΈ SOC Analysts learning offensive strategies

πŸ’‘ Not just another attack lab.
This is real-world Red Team training β€” built by operators, for operators.

🌐 www.ignitetechnologies.in
πŸ“§ info@ignitetechnologies.in
❀1
Cyber Attack
πŸ‘1
5 Tools for AD Enumeration
πŸ”₯2πŸ‘1
9 Ways to gain Expersience in CYber Security
πŸ‘1
Amazing SOC Analyst Skills
Comprehensive Guide on HTML Injection

πŸ”₯ Telegram: https://t.me/hackinarticles

Today, in this article, we’ll learn how such misconfigured HTML codes, open the gates for the attackers to manipulate the designed webpages and grabs up the sensitive data from the users.

🌐 What is HTML?
πŸ“˜ Introduction to HTML Injection
πŸ’₯ Impact of HTML Injection
βš”οΈ HTML Injection vs XSS
🧬 Types of Injection
πŸ’Ύ Stored HTML
πŸ” Reflected HTML
πŸ“₯ Reflected GET
πŸ“€ Reflected POST
πŸ”— Reflected Current URL
MSSQL for Pentester: NetExec

πŸ”₯ Telegram: https://t.me/hackinarticles

MSSQL NetExec Pentesting is an essential technique for red teamers and penetration testers who want to automate attacks against Microsoft SQL Servers.

πŸ§ͺ Lab Setup
🎯 Password Spray
πŸ”‘ Password Spray Using Hashes
βœ… Check Authentication
πŸ—„οΈ DB Command Execution Using nxc
πŸ’» Command Execution Using nxc
πŸ” Command Execution With Hashes
πŸ“€πŸ“₯ File Upload and Download
πŸš€ Privilege Escalation
πŸ“‘ Enumeration on a Different Port Number
πŸ“˜ Conclusion
Virtual Patching: Security Fixes Explained Like a Band-Aid for Software
πŸ”— Twitter: Share this thread

Learn how virtual patching acts as an emergency shield for apps, blocking hackers without touching the code:

πŸ›‘οΈ SQL Injection Patch
"Like a bouncer checking IDs for suspicious SQL commands."
β†’ Blocks UNION SELECT, DROP TABLE, etc.

πŸ’‰ Command Injection Fix
"Filters out hacker β€˜ingredients’ like ; rm -rf /."
β†’ Stops malicious system commands.

πŸ“‚ Insecure File Upload Defense
"Only allows .jpg/.pdfβ€”rejects .exe like a strict club dress code."
β†’ Whitelists safe file types.

πŸ” Broken Access Control
"Locks VIP sections (admin pages) from regular users."
β†’ Blocks IDOR attacks.

πŸ”„ CSRF/SSRF Protection
"Validates requests like a secret handshakeβ€”no forgery allowed."
β†’ Checks tokens and blocks internal IP abuse.

⚑ XSS Defense
"Scrubs <script> tags like a sanitizer for HTML."
β†’ Neutralizes malicious scripts.

πŸ”§ Tools: FortiWeb, AWS WAF, Cloudflare, OpenRASP.
❀1