Best-practice Linux Auditd rule set with 14,956 MITRE ATT&CK-mapped rules, Ansible deployment role, and lint/test tooling for security monitoring and compliance auditing.
Collects, checks and ranks public HTTP/SOCKS proxies against your own targets, then serves them via ranked exports, pools, a rotating gateway and a local API.
Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/
Web Cache Deception: Understanding the Attack and How to Prevent It
https://medium.com/@MazenElsayed_/web-cache-deception-understanding-the-attack-and-how-to-prevent-it-f9d617af56d3?source=rss------bug_bounty-5
https://medium.com/@MazenElsayed_/web-cache-deception-understanding-the-attack-and-how-to-prevent-it-f9d617af56d3?source=rss------bug_bounty-5
IntroductionContinue reading on Medium » (https://medium.com/@MazenElsayed_/web-cache-deception-understanding-the-attack-and-how-to-prevent-it-f9d617af56d3?source=rss------bug_bounty-5)
Recruit — SSRF → LFI → SQL Injection → Admin Takeover”THM”
https://medium.com/@ahmed240102345/recruit-ssrf-lfi-sql-injection-admin-takeover-thm-e31a0688b0bc?source=rss------bug_bounty-5
Difficulty: Easy/Medium Category: Web Application Pentesting Techniques: SSRF, Local File Inclusion, SQL Injection, Vulnerability ChainingContinue reading on Medium » (https://medium.com/@ahmed240102345/recruit-ssrf-lfi-sql-injection-admin-takeover-thm-e31a0688b0bc?source=rss------bug_bounty-5)
https://medium.com/@ahmed240102345/recruit-ssrf-lfi-sql-injection-admin-takeover-thm-e31a0688b0bc?source=rss------bug_bounty-5
Difficulty: Easy/Medium Category: Web Application Pentesting Techniques: SSRF, Local File Inclusion, SQL Injection, Vulnerability ChainingContinue reading on Medium » (https://medium.com/@ahmed240102345/recruit-ssrf-lfi-sql-injection-admin-takeover-thm-e31a0688b0bc?source=rss------bug_bounty-5)
Support — Cookie Tampering → IDOR → LFI → Command Injection (RCE) “THM”
https://medium.com/@ahmed240102345/support-cookie-tampering-idor-lfi-command-injection-rce-thm-d8bf93bcb5ce?source=rss------bug_bounty-5
Difficulty: Medium Category: Web Application Pentesting Techniques: Credential Brute-Forcing, Insecure Cookie Trust, Local File Inclusion…Continue reading on Medium » (https://medium.com/@ahmed240102345/support-cookie-tampering-idor-lfi-command-injection-rce-thm-d8bf93bcb5ce?source=rss------bug_bounty-5)
https://medium.com/@ahmed240102345/support-cookie-tampering-idor-lfi-command-injection-rce-thm-d8bf93bcb5ce?source=rss------bug_bounty-5
Difficulty: Medium Category: Web Application Pentesting Techniques: Credential Brute-Forcing, Insecure Cookie Trust, Local File Inclusion…Continue reading on Medium » (https://medium.com/@ahmed240102345/support-cookie-tampering-idor-lfi-command-injection-rce-thm-d8bf93bcb5ce?source=rss------bug_bounty-5)
It Returned 404… But the Data Was Still There
https://medium.com/@hamdyosama2995/it-returned-404-but-the-data-was-still-there-6e9bf4dd408d?source=rss------bug_bounty-5
https://medium.com/@hamdyosama2995/it-returned-404-but-the-data-was-still-there-6e9bf4dd408d?source=rss------bug_bounty-5
Hello Hacker👋Continue reading on Medium » (https://medium.com/@hamdyosama2995/it-returned-404-but-the-data-was-still-there-6e9bf4dd408d?source=rss------bug_bounty-5)
OnTheEdge - Extracting Edge plaintext credentials
https://www.reddit.com/r/redteamsec/comments/1wo3frp/ontheedge_extracting_edge_plaintext_credentials/
<!-- SC_OFF -->I've been working on a small C-based program that looks for credential-related data in running Microsoft Edge processes. The program simply enumerates msedge.exe processes, reads accessible memory regions and looks for specific patterns associated with credential data. The project includes both a standalone EXE and a BOF version for Sliver. Would be interested to know if others can reproduce it on different Edge/Windows versions. <!-- SC_ON --> submitted by /u/KeyDay4761 (https://www.reddit.com/user/KeyDay4761)
[link] (https://github.com/JssNGC/OnTheEdge) [comments] (https://www.reddit.com/r/redteamsec/comments/1wo3frp/ontheedge_extracting_edge_plaintext_credentials/)
https://www.reddit.com/r/redteamsec/comments/1wo3frp/ontheedge_extracting_edge_plaintext_credentials/
<!-- SC_OFF -->I've been working on a small C-based program that looks for credential-related data in running Microsoft Edge processes. The program simply enumerates msedge.exe processes, reads accessible memory regions and looks for specific patterns associated with credential data. The project includes both a standalone EXE and a BOF version for Sliver. Would be interested to know if others can reproduce it on different Edge/Windows versions. <!-- SC_ON --> submitted by /u/KeyDay4761 (https://www.reddit.com/user/KeyDay4761)
[link] (https://github.com/JssNGC/OnTheEdge) [comments] (https://www.reddit.com/r/redteamsec/comments/1wo3frp/ontheedge_extracting_edge_plaintext_credentials/)