๐จโ๐ป๐40 Commonly Targeted Ports by Hackers:
๐ Port 21 (FTP)
๐ช Port 22 (SSH)
๐ป Port 23 (Telnet)
๐ง Port 25 (SMTP)
๐ Port 53 (DNS)
๐ Port 80 (HTTP)
๐ Port 443 (HTTPS)
๐ฎ Port 3074 (Xbox Live)
๐ฒ Port 5060 (SIP)
๐ฒ Port 8080 (Proxy)
๐ Port 135 (RPC)
๐ฅ๏ธ Port 139 (NetBIOS)
๐ Port 1433 (MSSQL)
๐ฒ Port 1521 (Oracle)
๐ Port 1723 (PPTP)
๐ค Port 1900 (UPnP)
๐ฎ Port 2302 (DayZ)
๐จ๏ธ Port 3389 (RDP)
๐ Port 3306 (MySQL)
๐ธ๏ธ Port 4000 (Elasticsearch)
๐ Port 4444 (Metasploit)
๐ค Port 5000 (Python Flask)
๐ฎ Port 5555 (Android Debug Bridge)
๐ค Port 5900 (VNC)
๐ฅ๏ธ Port 6667 (IRC)
๐ง Port 6697 (IRC SSL)
๐ Port 8000 (HTTP Alt)
๐ฅ๏ธ Port 8081 (HTTP Proxy)
๐ Port 9100 (Printer)
๐ Port 9090 (Web Debugging)
๐ Port 445 (SMB)
๐ป Ports 5985/5986 (WinRM)
๐ Port 6379 (Redis)
๐ Port 6666 (IRC)
๐ง Port 993 (IMAP SSL)
๐ Port 995 (POP3 SSL)
๐ฒ Port 1434 (Microsoft SQL Monitor)
๐ Port 27017 (MongoDB)
๐ Port 28017 (MongoDB HTTP Interface)
๐ Port 21 (FTP)
๐ช Port 22 (SSH)
๐ป Port 23 (Telnet)
๐ง Port 25 (SMTP)
๐ Port 53 (DNS)
๐ Port 80 (HTTP)
๐ Port 443 (HTTPS)
๐ฎ Port 3074 (Xbox Live)
๐ฒ Port 5060 (SIP)
๐ฒ Port 8080 (Proxy)
๐ Port 135 (RPC)
๐ฅ๏ธ Port 139 (NetBIOS)
๐ Port 1433 (MSSQL)
๐ฒ Port 1521 (Oracle)
๐ Port 1723 (PPTP)
๐ค Port 1900 (UPnP)
๐ฎ Port 2302 (DayZ)
๐จ๏ธ Port 3389 (RDP)
๐ Port 3306 (MySQL)
๐ธ๏ธ Port 4000 (Elasticsearch)
๐ Port 4444 (Metasploit)
๐ค Port 5000 (Python Flask)
๐ฎ Port 5555 (Android Debug Bridge)
๐ค Port 5900 (VNC)
๐ฅ๏ธ Port 6667 (IRC)
๐ง Port 6697 (IRC SSL)
๐ Port 8000 (HTTP Alt)
๐ฅ๏ธ Port 8081 (HTTP Proxy)
๐ Port 9100 (Printer)
๐ Port 9090 (Web Debugging)
๐ Port 445 (SMB)
๐ป Ports 5985/5986 (WinRM)
๐ Port 6379 (Redis)
๐ Port 6666 (IRC)
๐ง Port 993 (IMAP SSL)
๐ Port 995 (POP3 SSL)
๐ฒ Port 1434 (Microsoft SQL Monitor)
๐ Port 27017 (MongoDB)
๐ Port 28017 (MongoDB HTTP Interface)
Today's Bug Bounty Blogs #12
1)Breaking the Barrier: Admin Panel Takeover Worth $3500
https://assassin-marcos.medium.com/breaking-the-barrier-admin-panel-takeover-worth-3500-78da79089ca3
2bugbounty #bugbountytip #bugbountytipsead to a Staging Environment with User Enumeration
https://ay0ub-n0uri.medium.com/a-critical-403-bypass-vulnerability-lead-to-a-staging-environment-with-user-enumeration-25b94ebadcfa
3)Reverse Engineering 101 : Transformation
https://medium.com/@krizzsrivastava/reverse-engineering-101-transformation-04de05821bb9
4)10 Essential OSINT CTF Challenges for Every Investigator
https://medium.com/@ninamaelainine/10-essential-osint-ctf-challenges-for-every-investigator-c573d75dc4cd
5)Cybersploit :1 vulnhub walkthrough
https://medium.com/@z6157881/cybersploit-1-vulnhub-walkthrough-8537c7b71dcf
1)Breaking the Barrier: Admin Panel Takeover Worth $3500
https://assassin-marcos.medium.com/breaking-the-barrier-admin-panel-takeover-worth-3500-78da79089ca3
2bugbounty #bugbountytip #bugbountytipsead to a Staging Environment with User Enumeration
https://ay0ub-n0uri.medium.com/a-critical-403-bypass-vulnerability-lead-to-a-staging-environment-with-user-enumeration-25b94ebadcfa
3)Reverse Engineering 101 : Transformation
https://medium.com/@krizzsrivastava/reverse-engineering-101-transformation-04de05821bb9
4)10 Essential OSINT CTF Challenges for Every Investigator
https://medium.com/@ninamaelainine/10-essential-osint-ctf-challenges-for-every-investigator-c573d75dc4cd
5)Cybersploit :1 vulnhub walkthrough
https://medium.com/@z6157881/cybersploit-1-vulnhub-walkthrough-8537c7b71dcf
Top 100+ Web Vulnerabilities, Categorised Into Various Types:
> Injection Vulnerabilities
1. SQL Injection (SQLi)
2. Cross-Site Scripting (XSS)
3. Cross-Site Request Forgery (CSRF)
4. Remote Code Execution (RCE)
5. Command Injection
6. XML Injection
7. LDAP Injection
8. XPath Injection
9. HTML Injection
10. Server-Side Includes (SSI) Injection
11. OS Command Injection
12. Blind SQL Injection
13. Server-Side Template Injection (SSTI)
14. CRLF Injection
15. NoSQL Injection
16. HQL Injection
> Broken Authentication and Session Management
17. Session Fixation
18. Brute Force Attack
19. Session Hijacking
20. Password Cracking
21. Weak Password Storage
22. Insecure Authentication
23. Cookie Theft
24. Credential Reuse
25. Insecure Login Pages
26. Insecure Session IDs
27. Predictable Login Credentials
> Sensitive Data Exposure
28. Inadequate Encryption
29. Insecure Direct Object References (IDOR)
30. Unencrypted Data Storage
31. Missing Security Headers
32. Insecure File Handling
33. Information Leakage in Logs
34. Hardcoded Secrets
> Security Misconfiguration
35. Default Passwords
36. Directory Listing
37. Unprotected API Endpoints
38. Open Ports and Services
39. Misconfigured Error Handling
40. Stack Traces Exposed
41. Verbose Error Messages
42. Insecure Default Configurations
43. Insufficient Backup Procedures
44. Misconfigured Security Headers (e.g., X-Frame-Options)
> Improper Access Controls
45. Information Disclosure
46. Unpatched Software
47. Misconfigured CORS
48. HTTP Security Headers Misconfiguration
49. Lack of Access Control on Administrative Interfaces
50. Directory Traversal
51. Weak File Permissions
> XML-Related Vulnerabilities
52. XML External Entity (XXE) Injection
53. XML Entity Expansion (XEE)
54. XML Bomb
55. XML Signature Wrapping
> Broken Access Control
56. Inadequate Authorization
57. Privilege Escalation
58. Forceful Browsing
59. Missing Function-Level Access Control
60. Unvalidated Redirects and Forwards
61. Excessive Data Exposure
> Insecure Deserialization
62. Remote Code Execution via Deserialization
63. Data Tampering
64. Object Injection
65. Type Confusion
> API Security Issues
66. Insecure API Endpoints
67. API Key Exposure
68. Lack of Rate Limiting
69. Inadequate Input Validation
70. Lack of Proper Authentication
71. Improper API Endpoint Security
> Insecure Communication
72. Man-in-the-Middle (MITM) Attack
73. Insufficient Transport Layer Security (TLS)
74. Insecure SSL/TLS Configuration
75. Insecure Communication Protocols
76. Deprecated Cryptographic Algorithms
77. Lack of Encryption in Transit
> Client-Side Vulnerabilities
78. DOM-based XSS
79. Insecure Cross-Origin Communication
80. Browser Cache Poisoning
81. Clickjacking
82. HTML5 Security Issues
83. Client-Side URL Redirection
84. Form Hijacking
85. WebSocket Security Issues
> Denial of Service (DoS)
86. Distributed Denial of Service (DDoS)
87. Application Layer DoS
88. Resource Exhaustion
89. Slowloris Attack
90. XML Denial of Service
91. HTTP Flood Attack
92. UDP Amplification Attack
> Other Web Vulnerabilities
93. Server-Side Request Forgery (SSRF)
94. HTTP Parameter Pollution (HPP)
95. Insecure Redirects and Forwards
96. File Inclusion Vulnerabilities (LFI/RFI)
97. Security Header Bypass
98. Inadequate Session Timeout
99. Insufficient Logging and Monitoring
100. Business Logic Vulnerabilities
101. API Abuse
102. JSON Web Token (JWT) Security Issues
103. Insufficient Anti-Automation Measures
> Mobile Web Vulnerabilities
104. Insecure Data Storage on Mobile Devices
105. Insecure Data Transmission on Mobile Devices
106. Insecure Mobile API Endpoints
107. Mobile App Reverse Engineering
108. Weak Mobile Authentication and Authorization
Missed anything? Comment & let everyone know!
Do you want a detailed blog on any vulnerability? let me know in a comments and I'll share!
Join These Channels For More:
@TheCyberMonks
@HundredxSecurity
@HackstackSecurity
@thecybersecuritychannel
> Injection Vulnerabilities
1. SQL Injection (SQLi)
2. Cross-Site Scripting (XSS)
3. Cross-Site Request Forgery (CSRF)
4. Remote Code Execution (RCE)
5. Command Injection
6. XML Injection
7. LDAP Injection
8. XPath Injection
9. HTML Injection
10. Server-Side Includes (SSI) Injection
11. OS Command Injection
12. Blind SQL Injection
13. Server-Side Template Injection (SSTI)
14. CRLF Injection
15. NoSQL Injection
16. HQL Injection
> Broken Authentication and Session Management
17. Session Fixation
18. Brute Force Attack
19. Session Hijacking
20. Password Cracking
21. Weak Password Storage
22. Insecure Authentication
23. Cookie Theft
24. Credential Reuse
25. Insecure Login Pages
26. Insecure Session IDs
27. Predictable Login Credentials
> Sensitive Data Exposure
28. Inadequate Encryption
29. Insecure Direct Object References (IDOR)
30. Unencrypted Data Storage
31. Missing Security Headers
32. Insecure File Handling
33. Information Leakage in Logs
34. Hardcoded Secrets
> Security Misconfiguration
35. Default Passwords
36. Directory Listing
37. Unprotected API Endpoints
38. Open Ports and Services
39. Misconfigured Error Handling
40. Stack Traces Exposed
41. Verbose Error Messages
42. Insecure Default Configurations
43. Insufficient Backup Procedures
44. Misconfigured Security Headers (e.g., X-Frame-Options)
> Improper Access Controls
45. Information Disclosure
46. Unpatched Software
47. Misconfigured CORS
48. HTTP Security Headers Misconfiguration
49. Lack of Access Control on Administrative Interfaces
50. Directory Traversal
51. Weak File Permissions
> XML-Related Vulnerabilities
52. XML External Entity (XXE) Injection
53. XML Entity Expansion (XEE)
54. XML Bomb
55. XML Signature Wrapping
> Broken Access Control
56. Inadequate Authorization
57. Privilege Escalation
58. Forceful Browsing
59. Missing Function-Level Access Control
60. Unvalidated Redirects and Forwards
61. Excessive Data Exposure
> Insecure Deserialization
62. Remote Code Execution via Deserialization
63. Data Tampering
64. Object Injection
65. Type Confusion
> API Security Issues
66. Insecure API Endpoints
67. API Key Exposure
68. Lack of Rate Limiting
69. Inadequate Input Validation
70. Lack of Proper Authentication
71. Improper API Endpoint Security
> Insecure Communication
72. Man-in-the-Middle (MITM) Attack
73. Insufficient Transport Layer Security (TLS)
74. Insecure SSL/TLS Configuration
75. Insecure Communication Protocols
76. Deprecated Cryptographic Algorithms
77. Lack of Encryption in Transit
> Client-Side Vulnerabilities
78. DOM-based XSS
79. Insecure Cross-Origin Communication
80. Browser Cache Poisoning
81. Clickjacking
82. HTML5 Security Issues
83. Client-Side URL Redirection
84. Form Hijacking
85. WebSocket Security Issues
> Denial of Service (DoS)
86. Distributed Denial of Service (DDoS)
87. Application Layer DoS
88. Resource Exhaustion
89. Slowloris Attack
90. XML Denial of Service
91. HTTP Flood Attack
92. UDP Amplification Attack
> Other Web Vulnerabilities
93. Server-Side Request Forgery (SSRF)
94. HTTP Parameter Pollution (HPP)
95. Insecure Redirects and Forwards
96. File Inclusion Vulnerabilities (LFI/RFI)
97. Security Header Bypass
98. Inadequate Session Timeout
99. Insufficient Logging and Monitoring
100. Business Logic Vulnerabilities
101. API Abuse
102. JSON Web Token (JWT) Security Issues
103. Insufficient Anti-Automation Measures
> Mobile Web Vulnerabilities
104. Insecure Data Storage on Mobile Devices
105. Insecure Data Transmission on Mobile Devices
106. Insecure Mobile API Endpoints
107. Mobile App Reverse Engineering
108. Weak Mobile Authentication and Authorization
Missed anything? Comment & let everyone know!
Do you want a detailed blog on any vulnerability? let me know in a comments and I'll share!
Join These Channels For More:
@TheCyberMonks
@HundredxSecurity
@HackstackSecurity
@thecybersecuritychannel
Today's Bug Bounty Blogs #13
1) Full Account Takeover | H1 Report
https://hackerone.com/reports/2542372
2) Open S3 Buckets Through Reconnaissance
https://offsec01.medium.com/open-s3-buckets-through-reconnaissance-920f8b35be47
3) My journey towards Bug Bounty and Ambassador World Cup 2023 Recap
https://g0ndaar.medium.com/my-journey-towards-bug-bounty-and-ambassador-world-cup-2023-recap-bc5fc1d00e72
4) Sauna Walkthrough โ Hack The Box
https://systemweakness.com/sauna-walkthrough-hack-the-box-2cdc5d3c4a56
5) Sunset vulnhub-CTF Challenge
https://medium.com/@far44hana22/sunset-vulnhub-walkthrough-48cd1459113d
6) Broker Tryhackme Writeup
https://bevijaygupta.medium.com/broker-tryhackme-writeup-b77b503e6a71
1) Full Account Takeover | H1 Report
https://hackerone.com/reports/2542372
2) Open S3 Buckets Through Reconnaissance
https://offsec01.medium.com/open-s3-buckets-through-reconnaissance-920f8b35be47
3) My journey towards Bug Bounty and Ambassador World Cup 2023 Recap
https://g0ndaar.medium.com/my-journey-towards-bug-bounty-and-ambassador-world-cup-2023-recap-bc5fc1d00e72
4) Sauna Walkthrough โ Hack The Box
https://systemweakness.com/sauna-walkthrough-hack-the-box-2cdc5d3c4a56
5) Sunset vulnhub-CTF Challenge
https://medium.com/@far44hana22/sunset-vulnhub-walkthrough-48cd1459113d
6) Broker Tryhackme Writeup
https://bevijaygupta.medium.com/broker-tryhackme-writeup-b77b503e6a71
๐ฅ1
Today's Bug Bounty Blogs #14
1)2FA Bypass - IDN Mischief
https://shahjerry33.medium.com/2fa-bypass-idn-mischief-157f06cb6904
2)Two Factor Authentication Bypass via using Victimโs DeviceID
https://medium.com/@cyberpro151/two-factor-authentication-bypass-via-using-victims-deviceid-b46afb4fe7a5
3)Burp Suite Filtering Trick โ Reducing Log Noise with TLS Pass-Through
https://theshaco.com/burp-suite-filtering-trick-reducing-log-noise-with-tls-pass-through-468d00fbc7dc
4)Hacking Large Corporations: The Art and Science of Reconnaissance
https://harshit3.medium.com/hacking-large-corporations-the-art-and-science-of-reconnaissance-1a6fc8f90616
More 4 Blogs to Read:
https://x.com/hetmehtaa/status/1827590184881598843
1)2FA Bypass - IDN Mischief
https://shahjerry33.medium.com/2fa-bypass-idn-mischief-157f06cb6904
2)Two Factor Authentication Bypass via using Victimโs DeviceID
https://medium.com/@cyberpro151/two-factor-authentication-bypass-via-using-victims-deviceid-b46afb4fe7a5
3)Burp Suite Filtering Trick โ Reducing Log Noise with TLS Pass-Through
https://theshaco.com/burp-suite-filtering-trick-reducing-log-noise-with-tls-pass-through-468d00fbc7dc
4)Hacking Large Corporations: The Art and Science of Reconnaissance
https://harshit3.medium.com/hacking-large-corporations-the-art-and-science-of-reconnaissance-1a6fc8f90616
More 4 Blogs to Read:
https://x.com/hetmehtaa/status/1827590184881598843
Google Dorks for Bug Bounty | Find Sensitive Information
1. Discovering Exposed Files:
- intitle:"index of" "site:http://site.com"
- filetype:log inurl:log site:http://site.com
- filetype:sql inurl:sql site:http://site.com
- filetype:env inurl:.env site:http://site.com
2. Finding Sensitive Directories:
- inurl:/phpinfo.php site:http://site.com
- inurl:/admin site:http://site.com
- inurl:/backup site:http://site.com
- inurl:wp- site:http://site.com
3. Exposed Configuration Files:
- filetype:config inurl:config site:http://site.com
- filetype:ini inurl:wp-config.php site:http://site.com
- filetype:json inurl:credentials site:http://site.com
4. Discovering Usernames and Passwords:
- intext:"password" filetype:log site:http://site.com
- intext:"username" filetype:log site:http://site.com
- filetype:sql "password" site:http://site.com
5. Finding Database Files:
- filetype:sql inurl:db site:http://site.com
- filetype:sql inurl:dump site:http://site.com
- filetype:bak inurl:db site:http://site.com
6. Exposed Git Repositories:
- inurl:".git" site:http://site.com
- inurl:"/.git/config" site:http://site.com
- intitle:"index of" ".git" site:http://site.com
7. Finding Publicly Exposed Emails:
- intext:"email" site:http://site.com
- inurl:"contact" intext:"
@site
.com" -www.site.com
- filetype:xls inurl:"email" site:http://site.com
8. Discovering Vulnerable Web Servers:
- intitle:"Apache2 Ubuntu Default Page: It works" site:http://site.com
- intitle:"Index of /" "Apache Server" site:http://site.com
- intitle:"Welcome to nginx" site:http://site.com
9. Finding API Keys:
- filetype:env "DB_PASSWORD" site:http://site.com
- intext:"api_key" filetype:env site:http://site.com
- intext:"AWS_ACCESS_KEY_ID" filetype:env site:http://site.com
10. Exposed Backup Files:
- filetype:bak inurl:backup site:http://site.com
- filetype:bak inurl:backup site:http://site.com
- filetype:zip inurl:backup site:http://site.com
- filetype:tgz inurl:backup site:http://site.com
#infosec #bugbounty #bugbountytips #100xSecurity #Hacking
1. Discovering Exposed Files:
- intitle:"index of" "site:http://site.com"
- filetype:log inurl:log site:http://site.com
- filetype:sql inurl:sql site:http://site.com
- filetype:env inurl:.env site:http://site.com
2. Finding Sensitive Directories:
- inurl:/phpinfo.php site:http://site.com
- inurl:/admin site:http://site.com
- inurl:/backup site:http://site.com
- inurl:wp- site:http://site.com
3. Exposed Configuration Files:
- filetype:config inurl:config site:http://site.com
- filetype:ini inurl:wp-config.php site:http://site.com
- filetype:json inurl:credentials site:http://site.com
4. Discovering Usernames and Passwords:
- intext:"password" filetype:log site:http://site.com
- intext:"username" filetype:log site:http://site.com
- filetype:sql "password" site:http://site.com
5. Finding Database Files:
- filetype:sql inurl:db site:http://site.com
- filetype:sql inurl:dump site:http://site.com
- filetype:bak inurl:db site:http://site.com
6. Exposed Git Repositories:
- inurl:".git" site:http://site.com
- inurl:"/.git/config" site:http://site.com
- intitle:"index of" ".git" site:http://site.com
7. Finding Publicly Exposed Emails:
- intext:"email" site:http://site.com
- inurl:"contact" intext:"
@site
.com" -www.site.com
- filetype:xls inurl:"email" site:http://site.com
8. Discovering Vulnerable Web Servers:
- intitle:"Apache2 Ubuntu Default Page: It works" site:http://site.com
- intitle:"Index of /" "Apache Server" site:http://site.com
- intitle:"Welcome to nginx" site:http://site.com
9. Finding API Keys:
- filetype:env "DB_PASSWORD" site:http://site.com
- intext:"api_key" filetype:env site:http://site.com
- intext:"AWS_ACCESS_KEY_ID" filetype:env site:http://site.com
10. Exposed Backup Files:
- filetype:bak inurl:backup site:http://site.com
- filetype:bak inurl:backup site:http://site.com
- filetype:zip inurl:backup site:http://site.com
- filetype:tgz inurl:backup site:http://site.com
#infosec #bugbounty #bugbountytips #100xSecurity #Hacking
๐1
Today's Bug Bounty Blogs #16
1)How I Bypassed 2FA and Earned My First Bounty $$$
https://anonysm.medium.com/how-i-bypassed-2fa-and-earned-my-first-bounty-3fdc58938347
2)Information Disclosure : 80+ Emails and LongID Disclosed !!
https://pushkarhax.medium.com/information-disclosure-80-emails-and-longid-disclosed-8952e2c6978b
3)Bug Bounty Methodology โ Step By Step Guide To Find Subdomains And Vulnerable URLs
https://medium.com/@shaikhminhaz1975/bug-bounty-methodology-step-by-step-guide-to-find-subdomains-and-vulnerable-urls-18bdd76e979f
4)Exposing Database Creds via SVN: A $400 Discovery
https://infosecwriteups.com/exposing-source-code-via-svn-a-400-discovery-9fc54b3f3f31
5)Blind SSRF vulnerability on 'cz.acronis.com'
https://hackerone.com/reports/1086206
6)Hack Your First PC: Ep.7 โ Demonstrate Your Skills
https://medium.com/@joshuapiesta/hack-your-first-pc-ep-7-demonstrate-your-skills-96930dea103d
7)Free CTF Challenge Pack: Easy Setup, Big Impact
https://medium.com/@josh.beck2006/free-ctf-challenge-pack-easy-setup-big-impact-142aee19b78e
8)IO Netgarage Levels 1 and 2 Walkthrough
https://systemweakness.com/io-netgarage-levels-1-and-2-walkthrough-66b60fb9e16e
9)picoCTF writeup: repetitions
https://medium.com/@omstaendlig/picoctf-writeup-repetitions-e37aa158416d
Hope you'll enjoy reading these blogs on Bug Bounty and CTFs, Keep Sharing!
Join These Channels For More:
@TheCyberMonks
@HundredxSecurity
@HackstackSecurity
@thecybersecuritychannel
1)How I Bypassed 2FA and Earned My First Bounty $$$
https://anonysm.medium.com/how-i-bypassed-2fa-and-earned-my-first-bounty-3fdc58938347
2)Information Disclosure : 80+ Emails and LongID Disclosed !!
https://pushkarhax.medium.com/information-disclosure-80-emails-and-longid-disclosed-8952e2c6978b
3)Bug Bounty Methodology โ Step By Step Guide To Find Subdomains And Vulnerable URLs
https://medium.com/@shaikhminhaz1975/bug-bounty-methodology-step-by-step-guide-to-find-subdomains-and-vulnerable-urls-18bdd76e979f
4)Exposing Database Creds via SVN: A $400 Discovery
https://infosecwriteups.com/exposing-source-code-via-svn-a-400-discovery-9fc54b3f3f31
5)Blind SSRF vulnerability on 'cz.acronis.com'
https://hackerone.com/reports/1086206
6)Hack Your First PC: Ep.7 โ Demonstrate Your Skills
https://medium.com/@joshuapiesta/hack-your-first-pc-ep-7-demonstrate-your-skills-96930dea103d
7)Free CTF Challenge Pack: Easy Setup, Big Impact
https://medium.com/@josh.beck2006/free-ctf-challenge-pack-easy-setup-big-impact-142aee19b78e
8)IO Netgarage Levels 1 and 2 Walkthrough
https://systemweakness.com/io-netgarage-levels-1-and-2-walkthrough-66b60fb9e16e
9)picoCTF writeup: repetitions
https://medium.com/@omstaendlig/picoctf-writeup-repetitions-e37aa158416d
Hope you'll enjoy reading these blogs on Bug Bounty and CTFs, Keep Sharing!
Join These Channels For More:
@TheCyberMonks
@HundredxSecurity
@HackstackSecurity
@thecybersecuritychannel
Medium
How I Bypassed 2FA and Earned My First Bounty $$$
Hacker Summary:
๐1
Today's Bug Bounty Blogs #17 | Series of Bug Bounty & CTF Blogs
1)Bypassed an Admin Panel Using SQL Payloads
https://th3m4rk5man.medium.com/bypassed-an-admin-panel-using-sql-4452a3f005d0
2)Bypassing airport security via SQL injection
https://ian.sh/tsa
3)Authorization bypass due to cache misconfiguration
https://rikeshbaniya.medium.com/authorization-bypass-due-to-cache-misconfiguration-fde8b2332d2d
4)My first XSS: Reflected XSS in hidden parameter
https://anonysm.medium.com/my-first-xss-reflected-xss-in-hidden-parameter-4142a02edfb1
5)Lord Of The Root: 1.0.1 Vulnhub Walkthrough
https://medium.com/@z6157881/lord-of-the-root-1-0-1-vulnhub-walkthrough-25f7161c7e7b
6)Solving the Prompt Airlines CTF
https://infosecwriteups.com/solving-the-prompt-airlines-ctf-2235c725050b
7)Crack The Hash Level 2 Tryhackme Writeup
https://bevijaygupta.medium.com/crack-the-hash-level-2-tryhackme-writeup-fb8eeb9edbfa
Join These Channels For More:
@TheCyberMonks
@HundredxSecurity
@HackstackSecurity
@thecybersecuritychannel
1)Bypassed an Admin Panel Using SQL Payloads
https://th3m4rk5man.medium.com/bypassed-an-admin-panel-using-sql-4452a3f005d0
2)Bypassing airport security via SQL injection
https://ian.sh/tsa
3)Authorization bypass due to cache misconfiguration
https://rikeshbaniya.medium.com/authorization-bypass-due-to-cache-misconfiguration-fde8b2332d2d
4)My first XSS: Reflected XSS in hidden parameter
https://anonysm.medium.com/my-first-xss-reflected-xss-in-hidden-parameter-4142a02edfb1
5)Lord Of The Root: 1.0.1 Vulnhub Walkthrough
https://medium.com/@z6157881/lord-of-the-root-1-0-1-vulnhub-walkthrough-25f7161c7e7b
6)Solving the Prompt Airlines CTF
https://infosecwriteups.com/solving-the-prompt-airlines-ctf-2235c725050b
7)Crack The Hash Level 2 Tryhackme Writeup
https://bevijaygupta.medium.com/crack-the-hash-level-2-tryhackme-writeup-fb8eeb9edbfa
Join These Channels For More:
@TheCyberMonks
@HundredxSecurity
@HackstackSecurity
@thecybersecuritychannel
Top 50 Digital Forensics Tools
Network Forensic Tools
- Nmap
- Wireshark
- Xplico
- Snort
- TCPDump
- The Slueth Kit
Mobile Forensics Tools
- Elcomspoft iOS Forensic Toolkit
- Mobile Verification Toolkit
- Oxygen Forensic
- MOBILedit
- Cellebrite UFED
- MSAB XRY
Malware Analysis Tools
- Wireshark
- YARA
- Malwarebytes
- VirusTotal
- Cuckoo Sandbox
- IDA Pro
Data Recovery Tools
- Recuva
- EaseUS Data Recovery
- TestDisk
- Stellar Data Recovery
- PhotoRec
- Disk Drill
Email Forensic Tools
- MailXaminer
- MailPro+
- Xtraxtor
- Aid4Mail
- eMailTrackerPro
- Autopsy
OSINT Tools
- Maltego
- Nmap
- OSINT Framework
- Shodan
- Recon-ng
- TheHavester
Live Forensics Tools
- OS Forensics
- Encase Live
- CAINE
- F-Response
- Kali Linux Forensic Mode
Memory Forensics Tools
- Volatility
- DumpIt
- memDump
- Access data FTK Imager
- Hibernation Recon
- WindowSCOPE
Cloud Forensic Tools
- Magnet AXIOM
- MSAB XRY Cloud
- Azure CLI
Network Forensic Tools
- Nmap
- Wireshark
- Xplico
- Snort
- TCPDump
- The Slueth Kit
Mobile Forensics Tools
- Elcomspoft iOS Forensic Toolkit
- Mobile Verification Toolkit
- Oxygen Forensic
- MOBILedit
- Cellebrite UFED
- MSAB XRY
Malware Analysis Tools
- Wireshark
- YARA
- Malwarebytes
- VirusTotal
- Cuckoo Sandbox
- IDA Pro
Data Recovery Tools
- Recuva
- EaseUS Data Recovery
- TestDisk
- Stellar Data Recovery
- PhotoRec
- Disk Drill
Email Forensic Tools
- MailXaminer
- MailPro+
- Xtraxtor
- Aid4Mail
- eMailTrackerPro
- Autopsy
OSINT Tools
- Maltego
- Nmap
- OSINT Framework
- Shodan
- Recon-ng
- TheHavester
Live Forensics Tools
- OS Forensics
- Encase Live
- CAINE
- F-Response
- Kali Linux Forensic Mode
Memory Forensics Tools
- Volatility
- DumpIt
- memDump
- Access data FTK Imager
- Hibernation Recon
- WindowSCOPE
Cloud Forensic Tools
- Magnet AXIOM
- MSAB XRY Cloud
- Azure CLI
Today's Bug Bounty Blogs #18
1)Hitting the jackpot with RCE!
https://medium.com/@gokulsspace/hitting-the-jackpot-with-rce-43755cac1415
2)How I Discovered a Critical Vulnerability that Most Bug Hunters Missedโฆ.๐ง
https://dkcyberz.medium.com/how-i-discovered-a-critical-vulnerability-that-most-bug-hunters-missed-b00f87cfb8b2
3)โLikeโ Bypass on Customer Reviews โ โฌ500 bounty
https://medium.com/@asharm.khan7/like-bypass-on-customer-reviews-500-bounty-b8d45a98c096
4)Juniper Networks RCE - Shodan - CVE Automation
https://www.youtube.com/watch?v=LNUGAxphelE
5)Critical Command Injection : CVE-2024-1212 | bug bounty poc
https://www.youtube.com/watch?v=JIhURKlnwbk
6)How to Hack Android Device | Ghost | Shodan
https://www.youtube.com/watch?v=klba8l6BngI
7)[#E05] Secure Code Review for Beginners: XML External Entity (XXE)
https://www.youtube.com/watch?v=HKDe1z7_AII
8)BTS Challenge: XSS Contexts and Polyglots
https://www.youtube.com/watch?v=UAPs18qBQzo
9)The Cartel Connection โ Walkthrough
https://medium.com/@unkn0wnus3r91/the-cartel-connection-3246fba35bbc
10)FFUF Web Parser
https://github.com/VikzSharma/ffufwebparser
Are you the author of these blogs? feel free to take the credit of yours, thanks for putting the efforts.
Contact me to get your blog featured on the next edition.
1)Hitting the jackpot with RCE!
https://medium.com/@gokulsspace/hitting-the-jackpot-with-rce-43755cac1415
2)How I Discovered a Critical Vulnerability that Most Bug Hunters Missedโฆ.๐ง
https://dkcyberz.medium.com/how-i-discovered-a-critical-vulnerability-that-most-bug-hunters-missed-b00f87cfb8b2
3)โLikeโ Bypass on Customer Reviews โ โฌ500 bounty
https://medium.com/@asharm.khan7/like-bypass-on-customer-reviews-500-bounty-b8d45a98c096
4)Juniper Networks RCE - Shodan - CVE Automation
https://www.youtube.com/watch?v=LNUGAxphelE
5)Critical Command Injection : CVE-2024-1212 | bug bounty poc
https://www.youtube.com/watch?v=JIhURKlnwbk
6)How to Hack Android Device | Ghost | Shodan
https://www.youtube.com/watch?v=klba8l6BngI
7)[#E05] Secure Code Review for Beginners: XML External Entity (XXE)
https://www.youtube.com/watch?v=HKDe1z7_AII
8)BTS Challenge: XSS Contexts and Polyglots
https://www.youtube.com/watch?v=UAPs18qBQzo
9)The Cartel Connection โ Walkthrough
https://medium.com/@unkn0wnus3r91/the-cartel-connection-3246fba35bbc
10)FFUF Web Parser
https://github.com/VikzSharma/ffufwebparser
Are you the author of these blogs? feel free to take the credit of yours, thanks for putting the efforts.
Contact me to get your blog featured on the next edition.
Medium
Hitting the jackpot with RCE!
Hey, so everyone was pushing me to write another write-up after the acceptance of my first ever bug bounty write up. So if you havenโtโฆ
Today's Bug Bounty Blogs #19
1)How I found My first P1 Bug which ended up โฆ.$?
https://medium.com/@yashsomalkar/how-i-found-my-first-p1-bug-which-ended-up-5e6cffdbb066
2)Google Dork Mastery Part 1 : Finding Hidden Critical Files with Google Dorks Like a Pro
https://enigma96.medium.com/google-dork-mastery-part-1-finding-hidden-critical-files-with-google-dorks-like-a-pro-d28ad159e9ae
3)How to Hunt for Sensitive Directories in Bug Bounty Hunting
https://bughunteralltime.medium.com/how-to-hunt-for-sensitive-directories-in-bug-bounty-hunting-f61a7f61d8fb
4)CyberSpace2024 ZipZone CTF : ZipSlip Vulnerability
https://starlox.medium.com/cyberspace2024-zipzone-ctf-zipslip-vulnerability-00489669feec
5)3108 Bahtera Siber Capture The Flag (CTF)
https://medium.com/@rectifyq/3108-bahtera-siber-capture-the-flag-ctf-draft-ca1be1751665
6)CyberSpace2024 Memory CTF : Interesting Forensics Challenge
https://starlox.medium.com/cyberspace2024-memory-ctf-interesting-forensics-challenge-0a76eb00f027
7)CyberSpace CTF 2024 โ sole
https://medium.com/@amiremohamadi/cyberspace-ctf-2024-sole-fc58c0566576
8)TryHackME Hammer WriteuP- By YoussefHossam
https://medium.com/@yh55694/tryhackme-hammer-writeup-by-youssefhossam-d4d625fdaa70
9)Jurassic Park Tryhackme writeup
https://bevijaygupta.medium.com/jurassic-park-tryhackme-writeup-fb2b53c4b202
10)Persistence TryHackme Writeup
https://bevijaygupta.medium.com/persistence-tryhackme-writeup-276165b948ec
Are you the author of these blogs? feel free to take the credit of yours, thanks for putting the efforts.
Contact me to get your blog featured on the next edition.
1)How I found My first P1 Bug which ended up โฆ.$?
https://medium.com/@yashsomalkar/how-i-found-my-first-p1-bug-which-ended-up-5e6cffdbb066
2)Google Dork Mastery Part 1 : Finding Hidden Critical Files with Google Dorks Like a Pro
https://enigma96.medium.com/google-dork-mastery-part-1-finding-hidden-critical-files-with-google-dorks-like-a-pro-d28ad159e9ae
3)How to Hunt for Sensitive Directories in Bug Bounty Hunting
https://bughunteralltime.medium.com/how-to-hunt-for-sensitive-directories-in-bug-bounty-hunting-f61a7f61d8fb
4)CyberSpace2024 ZipZone CTF : ZipSlip Vulnerability
https://starlox.medium.com/cyberspace2024-zipzone-ctf-zipslip-vulnerability-00489669feec
5)3108 Bahtera Siber Capture The Flag (CTF)
https://medium.com/@rectifyq/3108-bahtera-siber-capture-the-flag-ctf-draft-ca1be1751665
6)CyberSpace2024 Memory CTF : Interesting Forensics Challenge
https://starlox.medium.com/cyberspace2024-memory-ctf-interesting-forensics-challenge-0a76eb00f027
7)CyberSpace CTF 2024 โ sole
https://medium.com/@amiremohamadi/cyberspace-ctf-2024-sole-fc58c0566576
8)TryHackME Hammer WriteuP- By YoussefHossam
https://medium.com/@yh55694/tryhackme-hammer-writeup-by-youssefhossam-d4d625fdaa70
9)Jurassic Park Tryhackme writeup
https://bevijaygupta.medium.com/jurassic-park-tryhackme-writeup-fb2b53c4b202
10)Persistence TryHackme Writeup
https://bevijaygupta.medium.com/persistence-tryhackme-writeup-276165b948ec
Are you the author of these blogs? feel free to take the credit of yours, thanks for putting the efforts.
Contact me to get your blog featured on the next edition.
Medium
How I found My first P1 Bug which ended up โฆ.$?
Hello readers :)
Let me introduce Myself. I am a noob script kiddie. Trying my luck at Bug Bounty :) I also played CTFs for almost 3 yearsโฆ
Let me introduce Myself. I am a noob script kiddie. Trying my luck at Bug Bounty :) I also played CTFs for almost 3 yearsโฆ
Today's Bug Bounty Blogs #20
1)How I found a Broken Access Control by Reading API docs!
https://medium.com/@sanjaith3hacker/how-i-found-a-broken-access-control-by-reading-api-docs-e34219224076
2)Ultimate FFUF Cheatsheet: Advanced Fuzzing Tactics for Pro Bug Hunters!
https://medium.com/h7w/ultimate-ffuf-cheatsheet-advanced-fuzzing-tactics-for-pro-bug-hunters-492598750150
3)TryHackme โ Jack Write up
https://bevijaygupta.medium.com/tryhackme-jack-write-up-fab8279fb15d
4)Tryhackmeโs mKingdom Writeup by Alan Lundy
https://medium.com/@alanlundy23/tryhackmes-mkingdom-writeup-by-alan-lundy-afbc32278d97
5)Hardening Basics Part 1 TryHackme
https://systemweakness.com/hardening-basics-part-1-tryhackme-14ff5672d3d6
6)DriftingBlues: 6 Vulnhub Walkthrough
https://medium.com/@rzashirinov38/driftingblues-6-vulnhub-walkthrough-8db6ecdb3b46
7)Forensics Writeups | BlackHat MEA CTF Qualification 2024
https://medium.com/@mfaizanars/forensics-writeups-blackhat-mea-ctf-qualification-2024-648651defb26
Are you the author of these blogs? feel free to take the credit of yours, thanks for putting the efforts.
Contact me to get your blog featured on the next edition.
1)How I found a Broken Access Control by Reading API docs!
https://medium.com/@sanjaith3hacker/how-i-found-a-broken-access-control-by-reading-api-docs-e34219224076
2)Ultimate FFUF Cheatsheet: Advanced Fuzzing Tactics for Pro Bug Hunters!
https://medium.com/h7w/ultimate-ffuf-cheatsheet-advanced-fuzzing-tactics-for-pro-bug-hunters-492598750150
3)TryHackme โ Jack Write up
https://bevijaygupta.medium.com/tryhackme-jack-write-up-fab8279fb15d
4)Tryhackmeโs mKingdom Writeup by Alan Lundy
https://medium.com/@alanlundy23/tryhackmes-mkingdom-writeup-by-alan-lundy-afbc32278d97
5)Hardening Basics Part 1 TryHackme
https://systemweakness.com/hardening-basics-part-1-tryhackme-14ff5672d3d6
6)DriftingBlues: 6 Vulnhub Walkthrough
https://medium.com/@rzashirinov38/driftingblues-6-vulnhub-walkthrough-8db6ecdb3b46
7)Forensics Writeups | BlackHat MEA CTF Qualification 2024
https://medium.com/@mfaizanars/forensics-writeups-blackhat-mea-ctf-qualification-2024-648651defb26
Are you the author of these blogs? feel free to take the credit of yours, thanks for putting the efforts.
Contact me to get your blog featured on the next edition.
Medium
How I found a Broken Access Control by Reading API docs!
Hey everyone hope you all are doing good and Iโm combing back with new blog After long time because of my busy schedule. This is th3sanjaiโฆ
Today's Bug Bounty Blogs #21
1)Meta Bug Bounty โ Fuzzing โnetconsdโ for fun and profit โ part 3
https://blog.fadyothman.com/meta-bug-bounty-fuzzing-netconsd-for-fun-and-profit-part-3-127bb01d6756
2)Automating Subdomain Enumeration to Discover Critical Vulnerabilities
https://shubhamrooter.medium.com/automating-subdomain-enumeration-to-discover-critical-vulnerabilities-aa6158d35a8f
3)Google Dorks for Bug Bounty Part 3: Exposing Hidden Admin Panels & Login Portals
https://enigma96.medium.com/google-dorks-for-bug-bounty-part-3-exposing-hidden-admin-panels-login-portals-52b600e3f10b
4)OverTheWire Bandit: Levels 14โ33 Complete Walkthrough
https://medium.com/@KpCyberInfo/overthewire-bandit-levels-14-33-complete-walkthrough-dd36accef2f4
5)Log4j Exploit Lab: Reverse Shell with JNDI Exploit Kit
https://medium.com/@josh.beck2006/log4j-exploit-lab-reverse-shell-with-jndi-exploit-kit-21f015204e29
6)New methods of recon with OrwaGodfather
https://www.youtube.com/watch?v=5RyODeBjar4
7)SpideyX - A Web Reconnaissance Penetration Testing tool for Penetration Testers and Ethical Hackers that included with multiple mode with asynchronous concurrne performance.
https://github.com/RevoltSecurities/Spideyx
1)Meta Bug Bounty โ Fuzzing โnetconsdโ for fun and profit โ part 3
https://blog.fadyothman.com/meta-bug-bounty-fuzzing-netconsd-for-fun-and-profit-part-3-127bb01d6756
2)Automating Subdomain Enumeration to Discover Critical Vulnerabilities
https://shubhamrooter.medium.com/automating-subdomain-enumeration-to-discover-critical-vulnerabilities-aa6158d35a8f
3)Google Dorks for Bug Bounty Part 3: Exposing Hidden Admin Panels & Login Portals
https://enigma96.medium.com/google-dorks-for-bug-bounty-part-3-exposing-hidden-admin-panels-login-portals-52b600e3f10b
4)OverTheWire Bandit: Levels 14โ33 Complete Walkthrough
https://medium.com/@KpCyberInfo/overthewire-bandit-levels-14-33-complete-walkthrough-dd36accef2f4
5)Log4j Exploit Lab: Reverse Shell with JNDI Exploit Kit
https://medium.com/@josh.beck2006/log4j-exploit-lab-reverse-shell-with-jndi-exploit-kit-21f015204e29
6)New methods of recon with OrwaGodfather
https://www.youtube.com/watch?v=5RyODeBjar4
7)SpideyX - A Web Reconnaissance Penetration Testing tool for Penetration Testers and Ethical Hackers that included with multiple mode with asynchronous concurrne performance.
https://github.com/RevoltSecurities/Spideyx
Medium
Meta Bug Bounty โ Fuzzing โnetconsdโ for fun and profit โ part 3
Welcome to the final part in this series, this time we will talk about how to generate the test cases that we can use to fuzz netconsd, inโฆ
Today's Bug Bounty Blogs #25
1)From an Android Hook to RCE: $5000 Bounty
https://blog.voorivex.team/from-an-android-hook-to-rce-5000-bounty
2)SOQL injection in SalesForce earned me $$$$$
https://rooted0x01.medium.com/soql-injection-in-salesforce-apex-earned-me-903e3e9d8268
3)OAuth Non-Happy Path to ATO
https://blog.voorivex.team/oauth-non-happy-path-to-ato
4)Breaking Down Multipart Parsers: File upload validation bypass
https://blog.sicuranext.com/breaking-down-multipart-parsers-validation-bypass/
5)visit these website
https://lostsec.xyz/
https://ahmed-tarek.gitbook.io/sec-notes
6)The Blueprint to Your First $1,000+ Bounty
https://www.youtube.com/watch?v=8DnphDtFt3Y
7)Subdomain Enumeration ALL KINDS!
https://www.youtube.com/watch?v=6gY8cA3onkg
8)OTX_AlienVault_URL The OTX Scraper is a Bash script designed to fetch URLs associated with a given domain from AlienVault's Open Threat Exchange (OTX) platform.
https://github.com/Suryesh/OTX_AlienVault_URL
9)ex-param is an automated tool designed for finding reflected parameters for XSS vulnerabilities.
https://github.com/rootDR/ex-param
10)QuickSSRF - CAIDO Plugin
https://github.com/caido-community/quickssrf
1)From an Android Hook to RCE: $5000 Bounty
https://blog.voorivex.team/from-an-android-hook-to-rce-5000-bounty
2)SOQL injection in SalesForce earned me $$$$$
https://rooted0x01.medium.com/soql-injection-in-salesforce-apex-earned-me-903e3e9d8268
3)OAuth Non-Happy Path to ATO
https://blog.voorivex.team/oauth-non-happy-path-to-ato
4)Breaking Down Multipart Parsers: File upload validation bypass
https://blog.sicuranext.com/breaking-down-multipart-parsers-validation-bypass/
5)visit these website
https://lostsec.xyz/
https://ahmed-tarek.gitbook.io/sec-notes
6)The Blueprint to Your First $1,000+ Bounty
https://www.youtube.com/watch?v=8DnphDtFt3Y
7)Subdomain Enumeration ALL KINDS!
https://www.youtube.com/watch?v=6gY8cA3onkg
8)OTX_AlienVault_URL The OTX Scraper is a Bash script designed to fetch URLs associated with a given domain from AlienVault's Open Threat Exchange (OTX) platform.
https://github.com/Suryesh/OTX_AlienVault_URL
9)ex-param is an automated tool designed for finding reflected parameters for XSS vulnerabilities.
https://github.com/rootDR/ex-param
10)QuickSSRF - CAIDO Plugin
https://github.com/caido-community/quickssrf
Voorivex Team
From an Android Hook to RCE: $5000 Bounty
An Android hook chained into a remote code execution โ $5,000 bounty.
Today's Bug Bounty Blogs #27
1)How I Found My First Bug (RXSS)
https://medium.com/@a0xtrojan/how-i-found-my-first-bug-rxss-2ac44e94d628
2)Crack the Code: Master Default Admin Panel Passwords to Boost Your Bug Bounty Rewards
https://medium.com/infosecmatrix/a-list-of-default-admin-panel-passwords-to-boost-your-bug-bounty-67af4c4f45b2
3)Weird JavaScript files ๐ฅด
https://infosecwriteups.com/weird-javascript-files-7e6e7296e914
4)Web Cache Poisoning: Exploiting Trust in Cached Content
https://osintteam.blog/web-cache-poisoning-exploiting-trust-in-cached-content-362bb7c0d901
5)Bug Bounty Hunting Prerequisites
https://it4chis3c.medium.com/bug-bounty-hunting-prerequisites-964560919547
6)Ehxb | The Hidden Gateway CTF TryHackMe WriteUp
https://medium.com/@Ehxb/ehxb-the-hidden-gateway-ctf-tryhackme-writeup-a88fffdc98cb
7)eJPT : Host & Network Penetration Testing: Exploitation CTF 1
https://medium.com/@murat_kuzucu/ejpt-host-network-penetration-testing-exploitation-ctf-1-85cd5078e400
8)eJPT Host & Network Penetration Testing: Exploitation CTF 2
https://medium.com/@murat_kuzucu/ejpt-host-network-penetration-testing-exploitation-ctf-2-055d2969f1fe
9)Try Hack Me โ Brains Write-up
https://medium.com/@cyberboar/try-hack-me-brains-write-up-9a32e6b4d5d1
10)HTB: Sightless Writeup / Walkthrough
https://medium.com/@pk2212/htb-sightless-writeup-walkthrough-ea6f492c0b3c
Join These Channels For More:
@TheCyberMonks
@HundredxSecurity
@HackstackSecurity
@thecybersecuritychannel
1)How I Found My First Bug (RXSS)
https://medium.com/@a0xtrojan/how-i-found-my-first-bug-rxss-2ac44e94d628
2)Crack the Code: Master Default Admin Panel Passwords to Boost Your Bug Bounty Rewards
https://medium.com/infosecmatrix/a-list-of-default-admin-panel-passwords-to-boost-your-bug-bounty-67af4c4f45b2
3)Weird JavaScript files ๐ฅด
https://infosecwriteups.com/weird-javascript-files-7e6e7296e914
4)Web Cache Poisoning: Exploiting Trust in Cached Content
https://osintteam.blog/web-cache-poisoning-exploiting-trust-in-cached-content-362bb7c0d901
5)Bug Bounty Hunting Prerequisites
https://it4chis3c.medium.com/bug-bounty-hunting-prerequisites-964560919547
6)Ehxb | The Hidden Gateway CTF TryHackMe WriteUp
https://medium.com/@Ehxb/ehxb-the-hidden-gateway-ctf-tryhackme-writeup-a88fffdc98cb
7)eJPT : Host & Network Penetration Testing: Exploitation CTF 1
https://medium.com/@murat_kuzucu/ejpt-host-network-penetration-testing-exploitation-ctf-1-85cd5078e400
8)eJPT Host & Network Penetration Testing: Exploitation CTF 2
https://medium.com/@murat_kuzucu/ejpt-host-network-penetration-testing-exploitation-ctf-2-055d2969f1fe
9)Try Hack Me โ Brains Write-up
https://medium.com/@cyberboar/try-hack-me-brains-write-up-9a32e6b4d5d1
10)HTB: Sightless Writeup / Walkthrough
https://medium.com/@pk2212/htb-sightless-writeup-walkthrough-ea6f492c0b3c
Join These Channels For More:
@TheCyberMonks
@HundredxSecurity
@HackstackSecurity
@thecybersecuritychannel
Medium
How I Found My First Bug (RXSS)
ุจุณู
ุงููู ูุงูุตูุงุฉ ูุงูุณูุงู
ุนูู ูุจููุง ุงูู
ุฌุงูุฏ ุงูุดููุฏ
SOC 2 Trust Services Criteria Checklist
Map your Security, Availability, Integrity, Confidentiality & Privacy controls with this simple, practical guide.
https://hetmehta.com/soc2-tsc
Map your Security, Availability, Integrity, Confidentiality & Privacy controls with this simple, practical guide.
https://hetmehta.com/soc2-tsc
Powershell For Hackers: Exploitation Essentials
Practical guide on how to use PowerShell for hacking and penetration testing.
https://hetmehta.com/posts/powershell-for-hackers
Practical guide on how to use PowerShell for hacking and penetration testing.
https://hetmehta.com/posts/powershell-for-hackers
hetmehta.com
PowerShell for Hackers: Exploitation Essentials | hetmehta.com
A red teamerโs guide to PowerShell for post-exploitation: enum, privesc, persistence, and C2
10 FREE courses with certificates to boost your SIEM skills!
https://x.com/hetmehtaa/status/1912962144729203108
https://x.com/hetmehtaa/status/1912962144729203108
X (formerly Twitter)
Het Mehta (@hetmehtaa) on X
Splunk is offering 10 FREE courses with certificates to boost your SIEM skills!
Check it out! ๐งต
Check it out! ๐งต