Hackstack Security | Cyber Security Resources | OSCP CISSP OSWE CEH CISA Web3 Hacking
157 subscribers
8 photos
2 files
37 links
Hackstack Security is a leading authority in the realm of cybersecurity, offering a comprehensive Security Services designed to safeguard your digital assets.

Here on Telegram we aim to provide Free Resources which will help you to get better in Infosec
Download Telegram
Google Dorks for Bug Bounty | Find Sensitive Information

1. Discovering Exposed Files:
- intitle:"index of" "site:http://site.com"
- filetype:log inurl:log site:http://site.com
- filetype:sql inurl:sql site:http://site.com
- filetype:env inurl:.env site:http://site.com

2. Finding Sensitive Directories:
- inurl:/phpinfo.php site:http://site.com
- inurl:/admin site:http://site.com
- inurl:/backup site:http://site.com
- inurl:wp- site:http://site.com

3. Exposed Configuration Files:
- filetype:config inurl:config site:http://site.com
- filetype:ini inurl:wp-config.php site:http://site.com
- filetype:json inurl:credentials site:http://site.com

4. Discovering Usernames and Passwords:
- intext:"password" filetype:log site:http://site.com
- intext:"username" filetype:log site:http://site.com
- filetype:sql "password" site:http://site.com

5. Finding Database Files:
- filetype:sql inurl:db site:http://site.com
- filetype:sql inurl:dump site:http://site.com
- filetype:bak inurl:db site:http://site.com

6. Exposed Git Repositories:
- inurl:".git" site:http://site.com
- inurl:"/.git/config" site:http://site.com
- intitle:"index of" ".git" site:http://site.com

7. Finding Publicly Exposed Emails:
- intext:"email" site:http://site.com
- inurl:"contact" intext:"
@site
.com" -www.site.com
- filetype:xls inurl:"email" site:http://site.com

8. Discovering Vulnerable Web Servers:
- intitle:"Apache2 Ubuntu Default Page: It works" site:http://site.com
- intitle:"Index of /" "Apache Server" site:http://site.com
- intitle:"Welcome to nginx" site:http://site.com

9. Finding API Keys:
- filetype:env "DB_PASSWORD" site:http://site.com
- intext:"api_key" filetype:env site:http://site.com
- intext:"AWS_ACCESS_KEY_ID" filetype:env site:http://site.com

10. Exposed Backup Files:
- filetype:bak inurl:backup site:http://site.com
- filetype:bak inurl:backup site:http://site.com
- filetype:zip inurl:backup site:http://site.com
- filetype:tgz inurl:backup site:http://site.com

#infosec #bugbounty #bugbountytips #100xSecurity #Hacking
👍1
Today's Bug Bounty Blogs #16

1)How I Bypassed 2FA and Earned My First Bounty $$$
https://anonysm.medium.com/how-i-bypassed-2fa-and-earned-my-first-bounty-3fdc58938347

2)Information Disclosure : 80+ Emails and LongID Disclosed !!
https://pushkarhax.medium.com/information-disclosure-80-emails-and-longid-disclosed-8952e2c6978b

3)Bug Bounty Methodology — Step By Step Guide To Find Subdomains And Vulnerable URLs
https://medium.com/@shaikhminhaz1975/bug-bounty-methodology-step-by-step-guide-to-find-subdomains-and-vulnerable-urls-18bdd76e979f

4)Exposing Database Creds via SVN: A $400 Discovery
https://infosecwriteups.com/exposing-source-code-via-svn-a-400-discovery-9fc54b3f3f31

5)Blind SSRF vulnerability on 'cz.acronis.com'
https://hackerone.com/reports/1086206

6)Hack Your First PC: Ep.7 — Demonstrate Your Skills
https://medium.com/@joshuapiesta/hack-your-first-pc-ep-7-demonstrate-your-skills-96930dea103d

7)Free CTF Challenge Pack: Easy Setup, Big Impact
https://medium.com/@josh.beck2006/free-ctf-challenge-pack-easy-setup-big-impact-142aee19b78e

8)IO Netgarage Levels 1 and 2 Walkthrough
https://systemweakness.com/io-netgarage-levels-1-and-2-walkthrough-66b60fb9e16e

9)picoCTF writeup: repetitions
https://medium.com/@omstaendlig/picoctf-writeup-repetitions-e37aa158416d

Hope you'll enjoy reading these blogs on Bug Bounty and CTFs, Keep Sharing!

Join These Channels For More:

@TheCyberMonks
@HundredxSecurity
@HackstackSecurity
@thecybersecuritychannel
👍1
Top 50 Digital Forensics Tools

Network Forensic Tools
- Nmap
- Wireshark
- Xplico
- Snort
- TCPDump
- The Slueth Kit

Mobile Forensics Tools
- Elcomspoft iOS Forensic Toolkit
- Mobile Verification Toolkit
- Oxygen Forensic
- MOBILedit
- Cellebrite UFED
- MSAB XRY

Malware Analysis Tools
- Wireshark
- YARA
- Malwarebytes
- VirusTotal
- Cuckoo Sandbox
- IDA Pro

Data Recovery Tools
- Recuva
- EaseUS Data Recovery
- TestDisk
- Stellar Data Recovery
- PhotoRec
- Disk Drill

Email Forensic Tools
- MailXaminer
- MailPro+
- Xtraxtor
- Aid4Mail
- eMailTrackerPro
- Autopsy

OSINT Tools
- Maltego
- Nmap
- OSINT Framework
- Shodan
- Recon-ng
- TheHavester

Live Forensics Tools
- OS Forensics
- Encase Live
- CAINE
- F-Response
- Kali Linux Forensic Mode

Memory Forensics Tools
- Volatility
- DumpIt
- memDump
- Access data FTK Imager
- Hibernation Recon
- WindowSCOPE

Cloud Forensic Tools
- Magnet AXIOM
- MSAB XRY Cloud
- Azure CLI
Today's Bug Bounty Blogs #18

1)Hitting the jackpot with RCE!
https://medium.com/@gokulsspace/hitting-the-jackpot-with-rce-43755cac1415

2)How I Discovered a Critical Vulnerability that Most Bug Hunters Missed….🧐
https://dkcyberz.medium.com/how-i-discovered-a-critical-vulnerability-that-most-bug-hunters-missed-b00f87cfb8b2

3)“Like” Bypass on Customer Reviews — €500 bounty
https://medium.com/@asharm.khan7/like-bypass-on-customer-reviews-500-bounty-b8d45a98c096

4)Juniper Networks RCE - Shodan - CVE Automation
https://www.youtube.com/watch?v=LNUGAxphelE

5)Critical Command Injection : CVE-2024-1212 | bug bounty poc
https://www.youtube.com/watch?v=JIhURKlnwbk
6)How to Hack Android Device | Ghost | Shodan

https://www.youtube.com/watch?v=klba8l6BngI
7)[#E05] Secure Code Review for Beginners: XML External Entity (XXE)
https://www.youtube.com/watch?v=HKDe1z7_AII
8)BTS Challenge: XSS Contexts and Polyglots

https://www.youtube.com/watch?v=UAPs18qBQzo
9)The Cartel Connection — Walkthrough

https://medium.com/@unkn0wnus3r91/the-cartel-connection-3246fba35bbc
10)FFUF Web Parser

https://github.com/VikzSharma/ffufwebparser

Are you the author of these blogs? feel free to take the credit of yours, thanks for putting the efforts.

Contact me to get your blog featured on the next edition.
Today's Bug Bounty Blogs #19

1)How I found My first P1 Bug which ended up ….$?
https://medium.com/@yashsomalkar/how-i-found-my-first-p1-bug-which-ended-up-5e6cffdbb066

2)Google Dork Mastery Part 1 : Finding Hidden Critical Files with Google Dorks Like a Pro
https://enigma96.medium.com/google-dork-mastery-part-1-finding-hidden-critical-files-with-google-dorks-like-a-pro-d28ad159e9ae

3)How to Hunt for Sensitive Directories in Bug Bounty Hunting
https://bughunteralltime.medium.com/how-to-hunt-for-sensitive-directories-in-bug-bounty-hunting-f61a7f61d8fb

4)CyberSpace2024 ZipZone CTF : ZipSlip Vulnerability
https://starlox.medium.com/cyberspace2024-zipzone-ctf-zipslip-vulnerability-00489669feec

5)3108 Bahtera Siber Capture The Flag (CTF)
https://medium.com/@rectifyq/3108-bahtera-siber-capture-the-flag-ctf-draft-ca1be1751665

6)CyberSpace2024 Memory CTF : Interesting Forensics Challenge
https://starlox.medium.com/cyberspace2024-memory-ctf-interesting-forensics-challenge-0a76eb00f027

7)CyberSpace CTF 2024 — sole
https://medium.com/@amiremohamadi/cyberspace-ctf-2024-sole-fc58c0566576

8)TryHackME Hammer WriteuP- By YoussefHossam
https://medium.com/@yh55694/tryhackme-hammer-writeup-by-youssefhossam-d4d625fdaa70

9)Jurassic Park Tryhackme writeup
https://bevijaygupta.medium.com/jurassic-park-tryhackme-writeup-fb2b53c4b202

10)Persistence TryHackme Writeup
https://bevijaygupta.medium.com/persistence-tryhackme-writeup-276165b948ec


Are you the author of these blogs? feel free to take the credit of yours, thanks for putting the efforts.

Contact me to get your blog featured on the next edition.
Today's Bug Bounty Blogs #21

1)Meta Bug Bounty — Fuzzing “netconsd” for fun and profit — part 3
https://blog.fadyothman.com/meta-bug-bounty-fuzzing-netconsd-for-fun-and-profit-part-3-127bb01d6756

2)Automating Subdomain Enumeration to Discover Critical Vulnerabilities
https://shubhamrooter.medium.com/automating-subdomain-enumeration-to-discover-critical-vulnerabilities-aa6158d35a8f

3)Google Dorks for Bug Bounty Part 3: Exposing Hidden Admin Panels & Login Portals
https://enigma96.medium.com/google-dorks-for-bug-bounty-part-3-exposing-hidden-admin-panels-login-portals-52b600e3f10b

4)OverTheWire Bandit: Levels 14–33 Complete Walkthrough
https://medium.com/@KpCyberInfo/overthewire-bandit-levels-14-33-complete-walkthrough-dd36accef2f4

5)Log4j Exploit Lab: Reverse Shell with JNDI Exploit Kit
https://medium.com/@josh.beck2006/log4j-exploit-lab-reverse-shell-with-jndi-exploit-kit-21f015204e29

6)New methods of recon with OrwaGodfather
https://www.youtube.com/watch?v=5RyODeBjar4

7)SpideyX - A Web Reconnaissance Penetration Testing tool for Penetration Testers and Ethical Hackers that included with multiple mode with asynchronous concurrne performance.
https://github.com/RevoltSecurities/Spideyx
Today's Bug Bounty Blogs #25

1)From an Android Hook to RCE: $5000 Bounty
https://blog.voorivex.team/from-an-android-hook-to-rce-5000-bounty

2)SOQL injection in SalesForce earned me $$$$$
https://rooted0x01.medium.com/soql-injection-in-salesforce-apex-earned-me-903e3e9d8268

3)OAuth Non-Happy Path to ATO
https://blog.voorivex.team/oauth-non-happy-path-to-ato

4)Breaking Down Multipart Parsers: File upload validation bypass
https://blog.sicuranext.com/breaking-down-multipart-parsers-validation-bypass/

5)visit these website
https://lostsec.xyz/
https://ahmed-tarek.gitbook.io/sec-notes

6)The Blueprint to Your First $1,000+ Bounty
https://www.youtube.com/watch?v=8DnphDtFt3Y

7)Subdomain Enumeration ALL KINDS!
https://www.youtube.com/watch?v=6gY8cA3onkg

8)OTX_AlienVault_URL The OTX Scraper is a Bash script designed to fetch URLs associated with a given domain from AlienVault's Open Threat Exchange (OTX) platform.
https://github.com/Suryesh/OTX_AlienVault_URL

9)ex-param is an automated tool designed for finding reflected parameters for XSS vulnerabilities.
https://github.com/rootDR/ex-param

10)QuickSSRF - CAIDO Plugin
https://github.com/caido-community/quickssrf
SOC 2 Trust Services Criteria Checklist

Map your Security, Availability, Integrity, Confidentiality & Privacy controls with this simple, practical guide.

https://hetmehta.com/soc2-tsc