Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
A Deep Dive into the High-Risk SSRF Vulnerability Affecting Ivanti UsersContinue reading on System Weakness » (https://systemweakness.com/zero-day-navigating-the-storm-of-cve-2024-21893-in-ivanti-products-3b27078377e2?source=rss------bug_bounty-5)
Zero-Day: Navigating the Storm of CVE-2024–21893 in Ivanti Products

A Deep Dive into the High-Risk SSRF Vulnerability Affecting Ivanti UsersContinue reading on System Weakness »
Read more...
Collect Active Directory data with Adalanche
https://www.reddit.com/r/redteamsec/comments/1ahqnjp/collect_active_directory_data_with_adalanche/

<!-- SC_OFF -->I recently discovered the Adalanche tool (https://youtu.be/PG2J0uILL1Q?si=9aNcoAMca4OTHCW5) and was quite amazed on how easy it is to get it running. I know it's not Bloodhound but still can present real attack paths. I blogged my experience and review on Adalanche and hope you will find this useful (https://lsecqt.github.io/Red-Teaming-Army/active-directory/enumeration/visualizing-acls-with-adalanche/) <!-- SC_ON --> submitted by /u/lsecqt (https://www.reddit.com/user/lsecqt)
[link] (https://lsecqt.github.io/Red-Teaming-Army/) [comments] (https://www.reddit.com/r/redteamsec/comments/1ahqnjp/collect_active_directory_data_with_adalanche/)
Nemesis is an offensive data enrichment (https://www.kitploit.com/search/label/Enrichment) pipeline (https://www.kitploit.com/search/label/Pipeline) and operator support system. Built on Kubernetes (https://www.kitploit.com/search/label/Kubernetes) with scale in mind, our goal with Nemesis was to create a centralized data processing platform that ingests data produced during offensive security assessments. Nemesis aims to automate a number of repetitive tasks operators encounter on engagements, empower operators’ analytic capabilities and collective knowledge, and create structured and unstructured data stores of as much operational data as possible to help guide future research (https://www.kitploit.com/search/label/Research) and facilitate offensive data analysis.
Setup / Installation See the setup instructions (https://github.com/SpecterOps/Nemesis/blob/main/docs/setup.md). Contributing / Development Environment Setup See development.md (https://github.com/SpecterOps/Nemesis/blob/main/docs/development.md) Further Reading Post Name Publication Date Link Hacking With Your Nemesis Aug 9, 2023 https://posts.specterops.io/hacking-with-your-nemesis-7861f75fcab4 Challenges In Post-Exploitation (https://www.kitploit.com/search/label/Post-Exploitation) Workflows Aug 2, 2023 https://posts.specterops.io/challenges-in-post-exploitation-workflows-2b3469810fe9 On (Structured) Data Jul 26, 2023 https://posts.specterops.io/on-structured-data-707b7d9876c6 Acknowledgments Nemesis is built on large chunk of other people's work. Throughout the codebase we've provided citations, references, and applicable licenses for anything used or adapted from public sources. If we're forgotten proper credit anywhere, please let us know or submit a pull request! We also want to acknowledge Evan McBroom, Hope Walker, and Carlo Alcantara from SpecterOps for their help with the initial Nemesis concept and amazing feedback throughout the development process.

Download Nemesis (https://github.com/SpecterOps/Nemesis)
A Story of an IDOR bug I found on a SaaS application

IDORs. If you’re reading this, it’s probably too late! Haha.. I’m just messing with you. If you’re reading this, you probably know a thing…Continue reading on Medium »
Read more...
IDORs. If you’re reading this, it’s probably too late! Haha.. I’m just messing with you. If you’re reading this, you probably know a thing…Continue reading on Medium » (https://medium.com/@duncanochieng682/a-story-of-an-idor-bug-i-found-on-a-saas-application-28fa65907bfd?source=rss------bug_bounty-5)
Version Control History and Information Disclosure Vulnerabilities | 2024

Virtually all websites are developed using some form of version control system, such as Git. Let’s Explore that | Karthikeyan NagarajContinue reading on Medium »
Read more...
Virtually all websites are developed using some form of version control system, such as Git. Let’s Explore that | Karthikeyan NagarajContinue reading on Medium » (https://cyberw1ng.medium.com/version-control-history-and-information-disclosure-vulnerabilities-2024-3649060333bb?source=rss------bug_bounty-5)
This will change the way you hunt for bugs forever.

Common mistake that people make when they just learn about few web vulnerabilities is the actual approach to the target. There are a lot…Continue reading on Medium »
Read more...