Bypassing Character Limit — XSS Using Spanned Payload
Hello, I am Syed Mushfik Hasan Tahsin aka SMHTahsin33, an 18 Y/O Cyber Security Enthusiast from Bangladesh. I am into Infosec due to…Continue reading on InfoSec Write-ups »
Read more...
Hello, I am Syed Mushfik Hasan Tahsin aka SMHTahsin33, an 18 Y/O Cyber Security Enthusiast from Bangladesh. I am into Infosec due to…Continue reading on InfoSec Write-ups »
Read more...
Reconnaissance tools that every pen tester and bug bunty hunter should know.
https://medium.com/geekculture/reconnaissance-tools-that-every-pen-tester-and-bug-bunty-hunter-should-know-18c02717d786?source=rss------bug_bounty-5
https://medium.com/geekculture/reconnaissance-tools-that-every-pen-tester-and-bug-bunty-hunter-should-know-18c02717d786?source=rss------bug_bounty-5
There are many tools available for performing reconnaissance, but some of them stand out for their features, functionality, and popularity.Continue reading on Geek Culture » (https://medium.com/geekculture/reconnaissance-tools-that-every-pen-tester-and-bug-bunty-hunter-should-know-18c02717d786?source=rss------bug_bounty-5)
Pen Testing vs Bug Bounty
https://medium.com/@phobias.memetic0s/pen-testing-vs-bug-bounty-75944ee55208?source=rss------bug_bounty-5
Penetration testing (pen testing) and bug bounty programs are means of discovering security vulnerabilities from an adversary’s point of…Continue reading on Medium » (https://medium.com/@phobias.memetic0s/pen-testing-vs-bug-bounty-75944ee55208?source=rss------bug_bounty-5)
https://medium.com/@phobias.memetic0s/pen-testing-vs-bug-bounty-75944ee55208?source=rss------bug_bounty-5
Penetration testing (pen testing) and bug bounty programs are means of discovering security vulnerabilities from an adversary’s point of…Continue reading on Medium » (https://medium.com/@phobias.memetic0s/pen-testing-vs-bug-bounty-75944ee55208?source=rss------bug_bounty-5)
GitGraber: A Tool for Finding Sensitive Information in GitHub Repositories
https://medium.com/@cuncis/gitgraber-a-tool-for-finding-sensitive-information-in-github-repositories-5bb092e253f5?source=rss------bug_bounty-5
https://medium.com/@cuncis/gitgraber-a-tool-for-finding-sensitive-information-in-github-repositories-5bb092e253f5?source=rss------bug_bounty-5
GitGraber is an open-source tool developed by Hisxo that can be used to scan GitHub repositories for sensitive information. The tool uses…Continue reading on Medium » (https://medium.com/@cuncis/gitgraber-a-tool-for-finding-sensitive-information-in-github-repositories-5bb092e253f5?source=rss------bug_bounty-5)
Mobile ops
https://www.reddit.com/r/Pentesting/comments/11rku0g/mobile_ops/
<!-- SC_OFF -->I need to know what a good secure preferable cheap laptop that I can put parrot os or kali on. Thanks <!-- SC_ON --> submitted by /u/Ctap70 (https://www.reddit.com/user/Ctap70)
[link] (https://www.reddit.com/r/Pentesting/comments/11rku0g/mobile_ops/) [comments] (https://www.reddit.com/r/Pentesting/comments/11rku0g/mobile_ops/)
https://www.reddit.com/r/Pentesting/comments/11rku0g/mobile_ops/
<!-- SC_OFF -->I need to know what a good secure preferable cheap laptop that I can put parrot os or kali on. Thanks <!-- SC_ON --> submitted by /u/Ctap70 (https://www.reddit.com/user/Ctap70)
[link] (https://www.reddit.com/r/Pentesting/comments/11rku0g/mobile_ops/) [comments] (https://www.reddit.com/r/Pentesting/comments/11rku0g/mobile_ops/)
BeyondTrust AD Bridge Open Post-Exploitation
https://www.reddit.com/r/redteamsec/comments/11rf7kk/beyondtrust_ad_bridge_open_postexploitation/
submitted by /u/v1brio (https://www.reddit.com/user/v1brio)
[link] (https://ricardojba.github.io/BeyondTrust-AD-Bridge-Open-Post-Exploitation/) [comments] (https://www.reddit.com/r/redteamsec/comments/11rf7kk/beyondtrust_ad_bridge_open_postexploitation/)
https://www.reddit.com/r/redteamsec/comments/11rf7kk/beyondtrust_ad_bridge_open_postexploitation/
submitted by /u/v1brio (https://www.reddit.com/user/v1brio)
[link] (https://ricardojba.github.io/BeyondTrust-AD-Bridge-Open-Post-Exploitation/) [comments] (https://www.reddit.com/r/redteamsec/comments/11rf7kk/beyondtrust_ad_bridge_open_postexploitation/)
Exploiting CVE-2023-23397: Microsoft Outlook Elevation of Privilege Vulnerability
https://www.reddit.com/r/redteamsec/comments/11rfc4e/exploiting_cve202323397_microsoft_outlook/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://www.mdsec.co.uk/2023/03/exploiting-cve-2023-23397-microsoft-outlook-elevation-of-privilege-vulnerability/) [comments] (https://www.reddit.com/r/redteamsec/comments/11rfc4e/exploiting_cve202323397_microsoft_outlook/)
https://www.reddit.com/r/redteamsec/comments/11rfc4e/exploiting_cve202323397_microsoft_outlook/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://www.mdsec.co.uk/2023/03/exploiting-cve-2023-23397-microsoft-outlook-elevation-of-privilege-vulnerability/) [comments] (https://www.reddit.com/r/redteamsec/comments/11rfc4e/exploiting_cve202323397_microsoft_outlook/)
Goblob: A fast enumeration tool for publicly exposed Azure Storage blobs
https://www.reddit.com/r/redteamsec/comments/11rhhz7/goblob_a_fast_enumeration_tool_for_publicly/
submitted by /u/Macmod- (https://www.reddit.com/user/Macmod-)
[link] (https://github.com/Macmod/goblob) [comments] (https://www.reddit.com/r/redteamsec/comments/11rhhz7/goblob_a_fast_enumeration_tool_for_publicly/)
https://www.reddit.com/r/redteamsec/comments/11rhhz7/goblob_a_fast_enumeration_tool_for_publicly/
submitted by /u/Macmod- (https://www.reddit.com/user/Macmod-)
[link] (https://github.com/Macmod/goblob) [comments] (https://www.reddit.com/r/redteamsec/comments/11rhhz7/goblob_a_fast_enumeration_tool_for_publicly/)
How do I test the CovertVPN connection in cobalt strike?
https://www.reddit.com/r/redteamsec/comments/11rmdv6/how_do_i_test_the_covertvpn_connection_in_cobalt/
<!-- SC_OFF -->I have created a VPN interface in my current session and believe that I can successfully connect to the network it is tunnling to, however I don't know how to test if it can see what's on the other network since I don't know what is on the other network and I also can't seem to find ways to test it since much of the info online is old and outdated (or the interface has changed so drastically over the years that they no longer apply). I am wanting a simple way to test if the VPN client it working besides seeing traffic leaving and arriving in the console, that's not convincing enough. <!-- SC_ON --> submitted by /u/baronobeefdip2 (https://www.reddit.com/user/baronobeefdip2)
[link] (https://www.reddit.com/r/redteamsec/comments/11rmdv6/how_do_i_test_the_covertvpn_connection_in_cobalt/) [comments] (https://www.reddit.com/r/redteamsec/comments/11rmdv6/how_do_i_test_the_covertvpn_connection_in_cobalt/)
https://www.reddit.com/r/redteamsec/comments/11rmdv6/how_do_i_test_the_covertvpn_connection_in_cobalt/
<!-- SC_OFF -->I have created a VPN interface in my current session and believe that I can successfully connect to the network it is tunnling to, however I don't know how to test if it can see what's on the other network since I don't know what is on the other network and I also can't seem to find ways to test it since much of the info online is old and outdated (or the interface has changed so drastically over the years that they no longer apply). I am wanting a simple way to test if the VPN client it working besides seeing traffic leaving and arriving in the console, that's not convincing enough. <!-- SC_ON --> submitted by /u/baronobeefdip2 (https://www.reddit.com/user/baronobeefdip2)
[link] (https://www.reddit.com/r/redteamsec/comments/11rmdv6/how_do_i_test_the_covertvpn_connection_in_cobalt/) [comments] (https://www.reddit.com/r/redteamsec/comments/11rmdv6/how_do_i_test_the_covertvpn_connection_in_cobalt/)
How do I fetch the Beacon IDs in cobalt strike?
https://www.reddit.com/r/redteamsec/comments/11rmh6k/how_do_i_fetch_the_beacon_ids_in_cobalt_strike/
<!-- SC_OFF -->I need this to be doable through the console of cobalt strike or through an aggressor script. Much of what I am finding on the matter is outdated and I don't know a lot about some of the internal methods of the scripting environment. I need a way to programmatically identify the Beacon IDs that are currently residing on the teams server. For now I have just been going through the logs directory which is a bit time consuming and confusing at times when you deal with multiple beacons. <!-- SC_ON --> submitted by /u/baronobeefdip2 (https://www.reddit.com/user/baronobeefdip2)
[link] (https://www.reddit.com/r/redteamsec/comments/11rmh6k/how_do_i_fetch_the_beacon_ids_in_cobalt_strike/) [comments] (https://www.reddit.com/r/redteamsec/comments/11rmh6k/how_do_i_fetch_the_beacon_ids_in_cobalt_strike/)
https://www.reddit.com/r/redteamsec/comments/11rmh6k/how_do_i_fetch_the_beacon_ids_in_cobalt_strike/
<!-- SC_OFF -->I need this to be doable through the console of cobalt strike or through an aggressor script. Much of what I am finding on the matter is outdated and I don't know a lot about some of the internal methods of the scripting environment. I need a way to programmatically identify the Beacon IDs that are currently residing on the teams server. For now I have just been going through the logs directory which is a bit time consuming and confusing at times when you deal with multiple beacons. <!-- SC_ON --> submitted by /u/baronobeefdip2 (https://www.reddit.com/user/baronobeefdip2)
[link] (https://www.reddit.com/r/redteamsec/comments/11rmh6k/how_do_i_fetch_the_beacon_ids_in_cobalt_strike/) [comments] (https://www.reddit.com/r/redteamsec/comments/11rmh6k/how_do_i_fetch_the_beacon_ids_in_cobalt_strike/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Keeping Instagram Safe and Secure
https://cdn-images-1.medium.com/max/1280/1*Q6XhE5TeLtGm9nsGIUxncQ.jpeg
Instagram is a popular social media platform that has become a vital part of many people’s lives. As with any social media platform, there…
Continue reading on Medium »
Keeping Instagram Safe and Secure
https://cdn-images-1.medium.com/max/1280/1*Q6XhE5TeLtGm9nsGIUxncQ.jpeg
Instagram is a popular social media platform that has become a vital part of many people’s lives. As with any social media platform, there…
Continue reading on Medium »