Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
My First Bug Report in Microsoft Windows Task Manager

Bug: Unclickable Right-Click Option for Microsoft Teams in Task Manager but clickable button in aboveContinue reading on Medium »
Read more...
A Comprehensive Guide to Identifying and Exploiting GraphQL Injection Vulnerabilities ResponsiblyContinue reading on Infosec Matrix » (https://medium.com/infosecmatrix/detecting-graphql-injection-tools-and-techniques-for-security-testers-f3742d0388aa?source=rss------bug_bounty-5)
Find XSS Vulnerabilities in Minutes
https://medium.com/@phirojshah20/find-xss-vulnerabilities-in-minutes-912d02d2b848?source=rss------bug_bounty-5

Cross-Site Scripting (XSS) remains one of the most prevalent vulnerabilities in web applications. As a red teamer or a bug bounty hunter…Continue reading on Medium » (https://medium.com/@phirojshah20/find-xss-vulnerabilities-in-minutes-912d02d2b848?source=rss------bug_bounty-5)
Why Does Windows Defender Detect Sliver C2 Implants While SentinelOne Does Not?
https://www.reddit.com/r/Pentesting/comments/1htxnps/why_does_windows_defender_detect_sliver_c2/

<!-- SC_OFF -->I recently discovered something surprising: SentinelOne was unable to detect an EXE implant generated using Sliver C2, while Windows Defender flagged it without issue. I'm trying to understand why this might be the case. Could it be related to differences in detection methodologies between the two? Perhaps Windows Defender has certain signatures or behavioral analysis techniques that SentinelOne doesn't employ? I'm looking for insights or recommendations, especially since I'm preparing to advise a client on endpoint security solutions and want to ensure I'm considering all the nuances. Any thoughts or similar experiences with SentinelOne or other tools in detecting Sliver C2 implants? <!-- SC_ON --> submitted by /u/Survival9421 (https://www.reddit.com/user/Survival9421)
[link] (https://www.reddit.com/r/Pentesting/comments/1htxnps/why_does_windows_defender_detect_sliver_c2/) [comments] (https://www.reddit.com/r/Pentesting/comments/1htxnps/why_does_windows_defender_detect_sliver_c2/)
Is it possible to man in the middle a pppoe connection?
https://www.reddit.com/r/Pentesting/comments/1hu1ew1/is_it_possible_to_man_in_the_middle_a_pppoe/

<!-- SC_OFF -->Im trying to monitor a pppoe connection between my router and the wall with a bridged device running ettercap, but it fails after the pado packet. I see a packet padt with: generic-error: Bye-bye Did it detect that im listening and is mocking me? 😂 <!-- SC_ON --> submitted by /u/Zakiyo (https://www.reddit.com/user/Zakiyo)
[link] (https://www.reddit.com/r/Pentesting/comments/1hu1ew1/is_it_possible_to_man_in_the_middle_a_pppoe/) [comments] (https://www.reddit.com/r/Pentesting/comments/1hu1ew1/is_it_possible_to_man_in_the_middle_a_pppoe/)
From Recon to Exploitation: 100 Linux Commands Every Pentester Must Know

Hey there, fellow pentesters! Ever felt like you’re juggling a million tools, trying to find just the right command for the job? Don’t…Continue reading on Medium »
Read more...
Reflected XSS on Gaming Blog Website

I found a reflected XSS vulnerability on a website I used to frequent when playing a text-based MUD (multi user dungeon).Continue reading on InfoSec Write-ups »
Read more...
P4 Bugs and PoC | Part 4

Hi everyone! 👋 I’m Abhijeet Kumawat — a passionate bug bounty hunter and security researcher. I enjoy sharing my knowledge and…Continue reading on InfoSec Write-ups »
Read more...
Mastering the Art of Bug Bounty Hunting: A Step-by-Step Guide

Welcome to the electrifying world of bug bounty hunting — a realm where cybersecurity enthusiasts turn digital detectives, solving…Continue reading on InfoSec Write-ups »
Read more...
How I Discovered an Email Disclosure Vulnerability

FREE ARTICLEContinue reading on InfoSec Write-ups »
Read more...