Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe: Phishing Analysis Tools
https://cdn-images-1.medium.com/max/1267/1*xq0pZ8NRkW5SWuIQ_6QS3Q.jpeg
Please note: I am not going to post any flags from the TryHackMe (THM) platform on my walkthroughs. I feel I would be violating the…
Continue reading on Medium »
TryHackMe: Phishing Analysis Tools
https://cdn-images-1.medium.com/max/1267/1*xq0pZ8NRkW5SWuIQ_6QS3Q.jpeg
Please note: I am not going to post any flags from the TryHackMe (THM) platform on my walkthroughs. I feel I would be violating the…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The popping history of XSS
https://cdn-images-1.medium.com/max/2600/1*3coUI8c54rvDSfiRtW3d0Q.png
Cross-Site Scripting (XSS) is a type of security vulnerability that has been around since the early days of the World Wide Web. XSS allows…
Continue reading on Medium »
The popping history of XSS
https://cdn-images-1.medium.com/max/2600/1*3coUI8c54rvDSfiRtW3d0Q.png
Cross-Site Scripting (XSS) is a type of security vulnerability that has been around since the early days of the World Wide Web. XSS allows…
Continue reading on Medium »
Reflected XSS on Target with tough WAF ( WAF Bypass )
I was doing web pentesting on a private program. The program had a very tough WAF even typing alert as a payload would block be blocked by…Continue reading on Medium »
Read more...
I was doing web pentesting on a private program. The program had a very tough WAF even typing alert as a payload would block be blocked by…Continue reading on Medium »
Read more...
How could I exploit OpenID "request object" with none algorithm ?
https://www.reddit.com/r/Pentesting/comments/10wsa12/how_could_i_exploit_openid_request_object_with/
https://www.reddit.com/r/Pentesting/comments/10wsa12/how_could_i_exploit_openid_request_object_with/
submitted by /u/tomatediabolik (https://www.reddit.com/user/tomatediabolik)
[link] (https://i.redd.it/k55ufv37nxga1.png) [comments] (https://www.reddit.com/r/Pentesting/comments/10wsa12/how_could_i_exploit_openid_request_object_with/)
[link] (https://i.redd.it/k55ufv37nxga1.png) [comments] (https://www.reddit.com/r/Pentesting/comments/10wsa12/how_could_i_exploit_openid_request_object_with/)
Prospective Employer sent me a Project
https://www.reddit.com/r/Pentesting/comments/10wsqm7/prospective_employer_sent_me_a_project/
<!-- SC_OFF -->Hey guys, I recently interviewed for a junior PT position and was given a project to do at home to test my self-learning capabilities. I am completely out of my comfort zone as this project is beyond my skills at the moment, but I'm doing my best. If y'all don't mind, what steps should I take in testing a website once I have done basic reconnaissance? I did some vulnerability scanning and tinkered around with Burp but I'm coming up blank. Thank you! <!-- SC_ON --> submitted by /u/Yrsal (https://www.reddit.com/user/Yrsal)
[link] (https://www.reddit.com/r/Pentesting/comments/10wsqm7/prospective_employer_sent_me_a_project/) [comments] (https://www.reddit.com/r/Pentesting/comments/10wsqm7/prospective_employer_sent_me_a_project/)
https://www.reddit.com/r/Pentesting/comments/10wsqm7/prospective_employer_sent_me_a_project/
<!-- SC_OFF -->Hey guys, I recently interviewed for a junior PT position and was given a project to do at home to test my self-learning capabilities. I am completely out of my comfort zone as this project is beyond my skills at the moment, but I'm doing my best. If y'all don't mind, what steps should I take in testing a website once I have done basic reconnaissance? I did some vulnerability scanning and tinkered around with Burp but I'm coming up blank. Thank you! <!-- SC_ON --> submitted by /u/Yrsal (https://www.reddit.com/user/Yrsal)
[link] (https://www.reddit.com/r/Pentesting/comments/10wsqm7/prospective_employer_sent_me_a_project/) [comments] (https://www.reddit.com/r/Pentesting/comments/10wsqm7/prospective_employer_sent_me_a_project/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Why Some Cloud Services Vulnerabilities Are So Hard to Fix
Five months after AWS customers were alerted about three vulnerabilities, nearly none had plugged the holes. The reasons why underline a need for change.
Why Some Cloud Services Vulnerabilities Are So Hard to Fix
Five months after AWS customers were alerted about three vulnerabilities, nearly none had plugged the holes. The reasons why underline a need for change.
Darkdump2 - Search The Deep Web Straight From Your Terminal
http://www.kitploit.com/2023/02/darkdump2-search-deep-web-straight-from.html
http://www.kitploit.com/2023/02/darkdump2-search-deep-web-straight-from.html
About Darkdump (https://www.kitploit.com/search/label/Darkdump) (Recent Notice - 12/27/22) Darkdump is a simple script written in Python3.11 in which it allows users to enter a search term (query) in the command line (https://www.kitploit.com/search/label/Command%20Line) and darkdump will pull all the deep web sites relating to that query. Darkdump2.0 is here, enjoy! Installation git clone https://github.com/josh0xA/darkdump
cd darkdump
python3 -m pip install -r requirements.txt
python3 darkdump.py --help
Usage Example 1: python3 darkdump.py --query programming
Example 2: python3 darkdump.py --query="chat rooms"
Example 3: python3 darkdump.py --query hackers (https://www.kitploit.com/search/label/Hackers) --amount 12
Note: The 'amount' argument filters the number of results outputted
Usage With Increased Anonymity Darkdump Proxy: python3 darkdump.py --query bitcoin (https://www.kitploit.com/search/label/Bitcoin) -p
Menu
____ _ _
| \ ___ ___| |_ _| |_ _ _____ ___
| | | .'| _| '_| . | | | | . |
|____/|__,|_| |_,_|___|___|_|_|_| _|
|_|
Developed By: Josh Schiavone
https://github.com/josh0xA
joshschiavone.com
Version 2.0
usage: darkdump.py [-h] [-v] [-q QUERY] [-a AMOUNT] [-p]
options:
-h, --help show this help message and exit
-v, --version returns darkdump's version
-q QUERY, --query QUERY
the keyword or string you want to search on the deepweb
-a AMOUNT, --amount AMOUNT
the amount of results you want to retrieve (default: 10)
-p, --proxy use darkdump proxy to increase anonymity
Visual
cd darkdump
python3 -m pip install -r requirements.txt
python3 darkdump.py --help
Usage Example 1: python3 darkdump.py --query programming
Example 2: python3 darkdump.py --query="chat rooms"
Example 3: python3 darkdump.py --query hackers (https://www.kitploit.com/search/label/Hackers) --amount 12
Note: The 'amount' argument filters the number of results outputted
Usage With Increased Anonymity Darkdump Proxy: python3 darkdump.py --query bitcoin (https://www.kitploit.com/search/label/Bitcoin) -p
Menu
____ _ _
| \ ___ ___| |_ _| |_ _ _____ ___
| | | .'| _| '_| . | | | | . |
|____/|__,|_| |_,_|___|___|_|_|_| _|
|_|
Developed By: Josh Schiavone
https://github.com/josh0xA
joshschiavone.com
Version 2.0
usage: darkdump.py [-h] [-v] [-q QUERY] [-a AMOUNT] [-p]
options:
-h, --help show this help message and exit
-v, --version returns darkdump's version
-q QUERY, --query QUERY
the keyword or string you want to search on the deepweb
-a AMOUNT, --amount AMOUNT
the amount of results you want to retrieve (default: 10)
-p, --proxy use darkdump proxy to increase anonymity
Visual
Ethical Notice The developer of this program, Josh Schiavone, is not resposible for misuse of this data gathering (https://www.kitploit.com/search/label/Gathering) tool. Do not use darkdump to navigate websites that take part in any activity that is identified as illegal under the laws and regulations of your government. May God bless you all. License MIT License
Copyright (c) Josh Schiavone
Download Darkdump (https://github.com/josh0xA/darkdump)
Copyright (c) Josh Schiavone
Download Darkdump (https://github.com/josh0xA/darkdump)
Reflected XSS on Target with tough WAF ( WAF Bypass )
https://jowin922.medium.com/reflected-xss-on-target-with-tough-waf-waf-bypass-3b7efd1ef2bc?source=rss------bug_bounty-5
https://jowin922.medium.com/reflected-xss-on-target-with-tough-waf-waf-bypass-3b7efd1ef2bc?source=rss------bug_bounty-5