Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Cherry Blossom is a fun, multi-stage room that keeps you on your toes.Continue reading on Medium » (https://medium.com/@5um1t0x/cherry-blossom-tryhackme-walkthrough-f403496e1ff3?source=rss------bug_bounty-5)
Artificial intelligence is rapidly changing the way security professionals approach reconnaissance, vulnerability research, penetration…Continue reading on Medium » (https://medium.com/@pentesterclubpvtltd/agent-zero-ai-the-autonomous-ai-framework-for-cybersecurity-pentesting-ab1e6cacb544?source=rss------bug_bounty-5)
PortSwigger Lab Walkthrough — User ID Controlled by Request Parameter with Data Leakage in Redirect

Difficulty: Apprentice Category: Access Control Vulnerabilities Lab: User ID controlled by request parameter with data leakage in redirectContinue reading on Medium »
Read more...
Difficulty: Apprentice Category: Access Control Vulnerabilities Lab: User ID controlled by request parameter with data leakage in redirectContinue reading on Medium » (https://vivek0x.medium.com/portswigger-lab-walkthrough-user-id-controlled-by-request-parameter-with-data-leakage-in-redirect-21680c6506b1?source=rss------bug_bounty-5)
Red-Team-Infrastructure-Wiki
https://kitploit.com/en/tools/github/bluscreenofjeff/red-team-infrastructure-wiki

Wiki to collect Red Team infrastructure hardening resources
vegadns — Updated!
https://kitploit.com/en/posts/gitlab-wattocyber-vegadns-98175e161febf6e04d7c4b61b68bc9608c60f9fa9e5abdb057fa68608fda59b3

Rust-based DNS enumeration and subdomain discovery tool for reconnaissance and penetration testing security assessments.
sliver v1.7.6

Adversary Emulation Framework
Read more...
Httpx Explained with Practical Examples

How I use httpx to identify live hosts, collect valuable HTTP information, and streamline my bug bounty reconnaissance with practical…Continue reading on MeetCyber »
Read more...
I built a cross-platform Snaffler replacement for filesystem, network and cloud credential discovery
https://www.reddit.com/r/Pentesting/comments/1vzhuzu/i_built_a_crossplatform_snaffler_replacement_for/
How often should you run security control validation?
https://www.reddit.com/r/Pentesting/comments/1vzse1x/how_often_should_you_run_security_control/

<!-- SC_OFF -->We are building out a validation pipeline and I'm trying to decide on the cadence. We have 500+ controls mapped to CIS/NIST. A new platform we are evaluating promises to automate the "control plane" where validation results trigger updates to the controls themselves. If the validation layer tests a control, like whether our EDR blocks a specific LOLBin command, and it fails, the system triggers an automated workflow to update the EDR policy. My engineering team wants to run the full automated suite once a week to catch drift, but the SOC is pushing back because of the alert fatigue it causes. Is monthly "full sweep" with daily "spot checks" the industry standard? Or are you running continuous validation triggered by changes, such as whenever a new build is deployed? I'm trying to balance coverage with stability. <!-- SC_ON --> submitted by /u/Lowrypgztfer-Fig8398 (https://www.reddit.com/user/Lowrypgztfer-Fig8398)
[link] (https://www.reddit.com/r/Pentesting/comments/1vzse1x/how_often_should_you_run_security_control/) [comments] (https://www.reddit.com/r/Pentesting/comments/1vzse1x/how_often_should_you_run_security_control/)
Automated penetration testing vs manual pentesting: which finds more real risk?
https://www.reddit.com/r/Pentesting/comments/1vzskpn/automated_penetration_testing_vs_manual/

<!-- SC_OFF -->I'm a manual pentester, and I'm watching platforms automate the validation of misconfigurations and missing patches. They are even using AI to chain exploits and tailor attacks to specific environments. The difference from old-school vulnerability scanners is that these platforms actually execute the exploit path to confirm it works. I'm not worried about web app logic. That is still clearly a human domain. But for internal infrastructure and AD, is the writing on the wall? If AI-driven validation can test 80% of the attack surface daily and update controls, does that leave manual testers only with the complex 20%? The platforms also claim to help with detection engineering by validating SIEM rules against actual TTPs. That feels like it is eating into the blue team's territory too. Where does automation end and human expertise begin? Or do you still find things the automation misses because of contextual business logic? if anyone has seen an AI actually find a complex privilege escalation chain that a manual tester would have found, or if it is still just "low-hanging fruit" at scale. <!-- SC_ON --> submitted by /u/Any_Yesterday_6617 (https://www.reddit.com/user/Any_Yesterday_6617)
[link] (https://www.reddit.com/r/Pentesting/comments/1vzskpn/automated_penetration_testing_vs_manual/) [comments] (https://www.reddit.com/r/Pentesting/comments/1vzskpn/automated_penetration_testing_vs_manual/)
Anyone willing to pentest an extremely barebones ARG page?
https://www.reddit.com/r/Pentesting/comments/1vzv7yq/anyone_willing_to_pentest_an_extremely_barebones/

<!-- SC_OFF -->I'm working on a small Alternate Reality Game, mainly for friends.
The landing page consists of 3 fields. Email, Referral Code, and a user generate PIN. All data is stored in SQL, I have a very basic understanding of databases. I'm worried a simple SQL injection could ruin the whole thing. Although this is only for friends. I'd like it be somewhat airtight. Unfortunately I'm a broke college student, so I cant offer a bounty. If anyone is interested in having a go for fun, please let me know. I'm curious to see if the database is unsecured. If anything can be dumped, or if the two unclaimed referral codes can be leaked or any other form of attack. If anyone interested, shoot me a message. If proof of ownership is needed I can write something on the homepage. Apologizes is this is not the right place. I'll delete Thanks. <!-- SC_ON --> submitted by /u/ConsiderationEast229 (https://www.reddit.com/user/ConsiderationEast229)
[link] (https://www.reddit.com/r/Pentesting/comments/1vzv7yq/anyone_willing_to_pentest_an_extremely_barebones/) [comments] (https://www.reddit.com/r/Pentesting/comments/1vzv7yq/anyone_willing_to_pentest_an_extremely_barebones/)
Looking For a partner for CPTS Path on HTB
https://www.reddit.com/r/Pentesting/comments/1vzx7yp/looking_for_a_partner_for_cpts_path_on_htb/

<!-- SC_OFF -->Hello guys! I’m looking for a partner to work through the HTB CPTS path on Hack The Box. I’m honestly quite inconsistent with my learning, so I think having a partner to keep each other accountable and track our progress would be beneficial for both of us. We can also share our learnings, findings, and help each other out along the way. If anyone is interested, drop a comment or DM me. <!-- SC_ON --> submitted by /u/AdSubstantial7284 (https://www.reddit.com/user/AdSubstantial7284)
[link] (https://www.reddit.com/r/Pentesting/comments/1vzx7yp/looking_for_a_partner_for_cpts_path_on_htb/) [comments] (https://www.reddit.com/r/Pentesting/comments/1vzx7yp/looking_for_a_partner_for_cpts_path_on_htb/)