Hacking Articles
21.1K subscribers
1.13K photos
165 files
777 links
House of Pentester
Download Telegram
9 Ways to gain Expersience in CYber Security
πŸ‘1
Amazing SOC Analyst Skills
Comprehensive Guide on HTML Injection

πŸ”₯ Telegram: https://t.me/hackinarticles

Today, in this article, we’ll learn how such misconfigured HTML codes, open the gates for the attackers to manipulate the designed webpages and grabs up the sensitive data from the users.

🌐 What is HTML?
πŸ“˜ Introduction to HTML Injection
πŸ’₯ Impact of HTML Injection
βš”οΈ HTML Injection vs XSS
🧬 Types of Injection
πŸ’Ύ Stored HTML
πŸ” Reflected HTML
πŸ“₯ Reflected GET
πŸ“€ Reflected POST
πŸ”— Reflected Current URL
MSSQL for Pentester: NetExec

πŸ”₯ Telegram: https://t.me/hackinarticles

MSSQL NetExec Pentesting is an essential technique for red teamers and penetration testers who want to automate attacks against Microsoft SQL Servers.

πŸ§ͺ Lab Setup
🎯 Password Spray
πŸ”‘ Password Spray Using Hashes
βœ… Check Authentication
πŸ—„οΈ DB Command Execution Using nxc
πŸ’» Command Execution Using nxc
πŸ” Command Execution With Hashes
πŸ“€πŸ“₯ File Upload and Download
πŸš€ Privilege Escalation
πŸ“‘ Enumeration on a Different Port Number
πŸ“˜ Conclusion
Virtual Patching: Security Fixes Explained Like a Band-Aid for Software
πŸ”— Twitter: Share this thread

Learn how virtual patching acts as an emergency shield for apps, blocking hackers without touching the code:

πŸ›‘οΈ SQL Injection Patch
"Like a bouncer checking IDs for suspicious SQL commands."
β†’ Blocks UNION SELECT, DROP TABLE, etc.

πŸ’‰ Command Injection Fix
"Filters out hacker β€˜ingredients’ like ; rm -rf /."
β†’ Stops malicious system commands.

πŸ“‚ Insecure File Upload Defense
"Only allows .jpg/.pdfβ€”rejects .exe like a strict club dress code."
β†’ Whitelists safe file types.

πŸ” Broken Access Control
"Locks VIP sections (admin pages) from regular users."
β†’ Blocks IDOR attacks.

πŸ”„ CSRF/SSRF Protection
"Validates requests like a secret handshakeβ€”no forgery allowed."
β†’ Checks tokens and blocks internal IP abuse.

⚑ XSS Defense
"Scrubs <script> tags like a sanitizer for HTML."
β†’ Neutralizes malicious scripts.

πŸ”§ Tools: FortiWeb, AWS WAF, Cloudflare, OpenRASP.
❀1
🚨 Master API Penetration Testing β€” From Recon to Real-World Exploits.

🧠 Real-world API attacks. πŸ’» Hands-on labs. 🎯 Career-ready skills.

πŸ”— Register Now β†’ https://forms.gle/bowpX9TGEs41GDG99
πŸ“² Chat on WhatsApp β†’ https://wa.me/message/HIOPPNENLOX6F1
πŸ’₯ Only β‚Ή41,000 / $495 – Limited Seats

Why Join?

⦁ Master API hacking from recon to exploitation (OWASP API Top 10)
⦁ Exploit JWT flaws, OAuth 2.0 misconfigurations & SSRF bugs
⦁ Hands-on API labs: HTTP analysis, fuzzing, brute force, injections
⦁ Learn with industry tools β€” Postman, Kite Runner, Burp Suite
⦁ Live sessions with experts + lifetime recordings access
⦁ Bonus: Secure coding tips & practical remediation strategies

🎯 Key Topics You'll Master:
βœ”οΈ Passive & active reconnaissance of APIs
βœ”οΈ JWT attacks: unverified signatures, key cracking & bypasses
βœ”οΈ OAuth 2.0 exploitation & insecure token handling
βœ”οΈ SQLi, NoSQLi, SSRF (in-band & out-of-band), ReDoS, RFI, and XXE
βœ”οΈ Function-level access control bypasses & business logic flaws
βœ”οΈ Exploiting serialization, OS command injection & asset mismanagement

πŸŽ“ Perfect For:
βœ”οΈ Bug Bounty Hunters targeting modern web & mobile APIs
βœ”οΈ Pentesters expanding into cloud & microservices APIs
βœ”οΈ Red Teamers and OSCP / OSEP aspirants
βœ”οΈ Developers & SOC teams securing their API landscape

πŸ’‘ Not just another theory course.
This is practical API hacking, taught by real-world offensive security professionals.

πŸ“§ info@ignitetechnologies.in
🌐 www.ignitetechnologies.in
❀4
Filesystem Hierarchy
Home Network Security Tips
❀1
How NAT works
❀1
HTTP headers
❀1πŸ‘1πŸ”₯1
πŸš€ Active Directory Penetration Training (Online) – Register Now! πŸš€

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Limited slots available! Hurry up to secure your spot in this exclusive training program offered by Ignite Technologies.

βœ”οΈ Comprehensive Table of Contents:
πŸ” Initial Active Directory Exploitation
πŸ”Ž Active Directory Post-Enumeration
πŸ” Abusing Kerberos
🧰 Advanced Credential Dumping Attacks
πŸ“ˆ Privilege Escalation Techniques
πŸ”„ Persistence Methods
πŸ”€ Lateral Movement Strategies
πŸ›‘ DACL Abuse (New)
🏴 ADCS Attacks (New)
πŸ’Ž Saphire and Diamond Ticket Attacks (New)
🎁 Bonus Sessions
❀2
Encryption vs Cryptography
πŸ’―1
Computer Networking
πŸ‘1πŸ”₯1
Cyber Crime Forum
πŸ’―1
Red Team vs Blue Team
⚑1
Industrial Pentester Career Path
πŸ‘3