Hackstack Security | Cyber Security Resources | OSCP CISSP OSWE CEH CISA Web3 Hacking
157 subscribers
8 photos
2 files
37 links
Hackstack Security is a leading authority in the realm of cybersecurity, offering a comprehensive Security Services designed to safeguard your digital assets.

Here on Telegram we aim to provide Free Resources which will help you to get better in Infosec
Download Telegram
Today's Bug Bounty Blogs #21

1)Meta Bug Bounty — Fuzzing “netconsd” for fun and profit — part 3
https://blog.fadyothman.com/meta-bug-bounty-fuzzing-netconsd-for-fun-and-profit-part-3-127bb01d6756

2)Automating Subdomain Enumeration to Discover Critical Vulnerabilities
https://shubhamrooter.medium.com/automating-subdomain-enumeration-to-discover-critical-vulnerabilities-aa6158d35a8f

3)Google Dorks for Bug Bounty Part 3: Exposing Hidden Admin Panels & Login Portals
https://enigma96.medium.com/google-dorks-for-bug-bounty-part-3-exposing-hidden-admin-panels-login-portals-52b600e3f10b

4)OverTheWire Bandit: Levels 14–33 Complete Walkthrough
https://medium.com/@KpCyberInfo/overthewire-bandit-levels-14-33-complete-walkthrough-dd36accef2f4

5)Log4j Exploit Lab: Reverse Shell with JNDI Exploit Kit
https://medium.com/@josh.beck2006/log4j-exploit-lab-reverse-shell-with-jndi-exploit-kit-21f015204e29

6)New methods of recon with OrwaGodfather
https://www.youtube.com/watch?v=5RyODeBjar4

7)SpideyX - A Web Reconnaissance Penetration Testing tool for Penetration Testers and Ethical Hackers that included with multiple mode with asynchronous concurrne performance.
https://github.com/RevoltSecurities/Spideyx
Today's Bug Bounty Blogs #25

1)From an Android Hook to RCE: $5000 Bounty
https://blog.voorivex.team/from-an-android-hook-to-rce-5000-bounty

2)SOQL injection in SalesForce earned me $$$$$
https://rooted0x01.medium.com/soql-injection-in-salesforce-apex-earned-me-903e3e9d8268

3)OAuth Non-Happy Path to ATO
https://blog.voorivex.team/oauth-non-happy-path-to-ato

4)Breaking Down Multipart Parsers: File upload validation bypass
https://blog.sicuranext.com/breaking-down-multipart-parsers-validation-bypass/

5)visit these website
https://lostsec.xyz/
https://ahmed-tarek.gitbook.io/sec-notes

6)The Blueprint to Your First $1,000+ Bounty
https://www.youtube.com/watch?v=8DnphDtFt3Y

7)Subdomain Enumeration ALL KINDS!
https://www.youtube.com/watch?v=6gY8cA3onkg

8)OTX_AlienVault_URL The OTX Scraper is a Bash script designed to fetch URLs associated with a given domain from AlienVault's Open Threat Exchange (OTX) platform.
https://github.com/Suryesh/OTX_AlienVault_URL

9)ex-param is an automated tool designed for finding reflected parameters for XSS vulnerabilities.
https://github.com/rootDR/ex-param

10)QuickSSRF - CAIDO Plugin
https://github.com/caido-community/quickssrf
SOC 2 Trust Services Criteria Checklist

Map your Security, Availability, Integrity, Confidentiality & Privacy controls with this simple, practical guide.

https://hetmehta.com/soc2-tsc