Hackstack Security | Cyber Security Resources | OSCP CISSP OSWE CEH CISA Web3 Hacking
157 subscribers
8 photos
2 files
37 links
Hackstack Security is a leading authority in the realm of cybersecurity, offering a comprehensive Security Services designed to safeguard your digital assets.

Here on Telegram we aim to provide Free Resources which will help you to get better in Infosec
Download Telegram
Top 10 Tools for Bug Bounty Hunting


Core Tools

1. Burp Suite:
The most essential tool for web application security testing. It offers a comprehensive suite of features for intercepting, modifying, and analyzing web traffic.

2. Nmap: A versatile network scanning tool used for discovering hosts, services, and vulnerabilities on a network.

3. FFUF: A fast web fuzzer that helps in discovering hidden directories, files, and parameters.

Intelligence Gathering

4. Amass: An open-source tool for conducting subdomain enumeration and asset discovery.
5. ReconFTW: Open-source reconnaissance tool for gathering information.

Vulnerability Scanning and Exploitation

6. Nuclei: A fast and lightweight vulnerability scanner for finding vulnerabilities using YAML-based templates.

7. SQLmap: A powerful penetration testing framework for SQL injection and database takeover.

8. WPScan: Specifically designed for WordPress vulnerability scanning.

Additional Tools:

9. Kali Linux: A Debian-based Linux distribution with a pre-installed set of penetration testing tools.

10. Wireshark: A packet analyzer for capturing and analyzing network traffic.

I know these are just few of them! Add more in the comments.
The 5 Most Used Security Frameworks

1. ISO 27001:
- Leading in recognition, it offers a comprehensive approach to information security.

2. NIST Cybersecurity Framework:
- More common in the USA to manage cybersecurity risks.

3. CIS Controls:
- Simple and effective best practices for cybersecurity.

4. COBIT:
- Focuses on governance and management of enterprise IT.

5. PCI DSS:
- Essential for all organizations that process credit card transactions.

And Why Does ISO 27001 Certification Stand at the Top?

- Universal Recognition: ISO 27001 is globally recognized and respected.
- Flexibility: Suitable for companies of every size and industry.
- Risk Management: Provides a solid framework for managing security risks.
- Building Trust: Signals to customers and partners that their data is secure.
- Competitive Advantage: Can open the door to new business opportunities.

More: https://www.getronics.com/the-top-five-cyber-security-frameworks/

More: https://complianceforge.com/solutions/nist-csf
👨‍💻👉40 Commonly Targeted Ports by Hackers:


    🔒 Port 21 (FTP)
    🚪 Port 22 (SSH)
    💻 Port 23 (Telnet)
    📧 Port 25 (SMTP)
    🌐 Port 53 (DNS)
    🌐 Port 80 (HTTP)
    🔒 Port 443 (HTTPS)
    🎮 Port 3074 (Xbox Live)
    📲 Port 5060 (SIP)
    🎲 Port 8080 (Proxy)
    📁 Port 135 (RPC)
    🖥️ Port 139 (NetBIOS)
    🔓 Port 1433 (MSSQL)
    🎲 Port 1521 (Oracle)
    🔓 Port 1723 (PPTP)
    📤 Port 1900 (UPnP)
    🎮 Port 2302 (DayZ)
    🖨️ Port 3389 (RDP)
    🔒 Port 3306 (MySQL)
    🕸️ Port 4000 (Elasticsearch)
    📂 Port 4444 (Metasploit)
    📤 Port 5000 (Python Flask)
    🎮 Port 5555 (Android Debug Bridge)
    📤 Port 5900 (VNC)
    🖥️ Port 6667 (IRC)
    📧 Port 6697 (IRC SSL)
    📂 Port 8000 (HTTP Alt)
    🖥️ Port 8081 (HTTP Proxy)
    🔓 Port 9100 (Printer)
    📂 Port 9090 (Web Debugging)
    📁 Port 445 (SMB)
    💻 Ports 5985/5986 (WinRM)
    🔄 Port 6379 (Redis)
    📂 Port 6666 (IRC)
    📧 Port 993 (IMAP SSL)
    🔒 Port 995 (POP3 SSL)
    🎲 Port 1434 (Microsoft SQL Monitor)
    📂 Port 27017 (MongoDB)
    🌐 Port 28017 (MongoDB HTTP Interface)
Top 100+ Web Vulnerabilities, Categorised Into Various Types:

> Injection Vulnerabilities
1. SQL Injection (SQLi)
2. Cross-Site Scripting (XSS)
3. Cross-Site Request Forgery (CSRF)
4. Remote Code Execution (RCE)
5. Command Injection
6. XML Injection
7. LDAP Injection
8. XPath Injection
9. HTML Injection
10. Server-Side Includes (SSI) Injection
11. OS Command Injection
12. Blind SQL Injection
13. Server-Side Template Injection (SSTI)
14. CRLF Injection
15. NoSQL Injection
16. HQL Injection

> Broken Authentication and Session Management
17. Session Fixation
18. Brute Force Attack
19. Session Hijacking
20. Password Cracking
21. Weak Password Storage
22. Insecure Authentication
23. Cookie Theft
24. Credential Reuse
25. Insecure Login Pages
26. Insecure Session IDs
27. Predictable Login Credentials

> Sensitive Data Exposure
28. Inadequate Encryption
29. Insecure Direct Object References (IDOR)
30. Unencrypted Data Storage
31. Missing Security Headers
32. Insecure File Handling
33. Information Leakage in Logs
34. Hardcoded Secrets

> Security Misconfiguration
35. Default Passwords
36. Directory Listing
37. Unprotected API Endpoints
38. Open Ports and Services
39. Misconfigured Error Handling
40. Stack Traces Exposed
41. Verbose Error Messages
42. Insecure Default Configurations
43. Insufficient Backup Procedures
44. Misconfigured Security Headers (e.g., X-Frame-Options)

> Improper Access Controls
45. Information Disclosure
46. Unpatched Software
47. Misconfigured CORS
48. HTTP Security Headers Misconfiguration
49. Lack of Access Control on Administrative Interfaces
50. Directory Traversal
51. Weak File Permissions

> XML-Related Vulnerabilities
52. XML External Entity (XXE) Injection
53. XML Entity Expansion (XEE)
54. XML Bomb
55. XML Signature Wrapping

> Broken Access Control
56. Inadequate Authorization
57. Privilege Escalation
58. Forceful Browsing
59. Missing Function-Level Access Control
60. Unvalidated Redirects and Forwards
61. Excessive Data Exposure

> Insecure Deserialization
62. Remote Code Execution via Deserialization
63. Data Tampering
64. Object Injection
65. Type Confusion

> API Security Issues
66. Insecure API Endpoints
67. API Key Exposure
68. Lack of Rate Limiting
69. Inadequate Input Validation
70. Lack of Proper Authentication
71. Improper API Endpoint Security

> Insecure Communication
72. Man-in-the-Middle (MITM) Attack
73. Insufficient Transport Layer Security (TLS)
74. Insecure SSL/TLS Configuration
75. Insecure Communication Protocols
76. Deprecated Cryptographic Algorithms
77. Lack of Encryption in Transit

> Client-Side Vulnerabilities
78. DOM-based XSS
79. Insecure Cross-Origin Communication
80. Browser Cache Poisoning
81. Clickjacking
82. HTML5 Security Issues
83. Client-Side URL Redirection
84. Form Hijacking
85. WebSocket Security Issues

> Denial of Service (DoS)
86. Distributed Denial of Service (DDoS)
87. Application Layer DoS
88. Resource Exhaustion
89. Slowloris Attack
90. XML Denial of Service
91. HTTP Flood Attack
92. UDP Amplification Attack

> Other Web Vulnerabilities
93. Server-Side Request Forgery (SSRF)
94. HTTP Parameter Pollution (HPP)
95. Insecure Redirects and Forwards
96. File Inclusion Vulnerabilities (LFI/RFI)
97. Security Header Bypass
98. Inadequate Session Timeout
99. Insufficient Logging and Monitoring
100. Business Logic Vulnerabilities
101. API Abuse
102. JSON Web Token (JWT) Security Issues
103. Insufficient Anti-Automation Measures

> Mobile Web Vulnerabilities
104. Insecure Data Storage on Mobile Devices
105. Insecure Data Transmission on Mobile Devices
106. Insecure Mobile API Endpoints
107. Mobile App Reverse Engineering
108. Weak Mobile Authentication and Authorization

Missed anything? Comment & let everyone know!

Do you want a detailed blog on any vulnerability? let me know in a comments and I'll share!

Join These Channels For More:

@TheCyberMonks
@HundredxSecurity
@HackstackSecurity
@thecybersecuritychannel
Google Dorks for Bug Bounty | Find Sensitive Information

1. Discovering Exposed Files:
- intitle:"index of" "site:http://site.com"
- filetype:log inurl:log site:http://site.com
- filetype:sql inurl:sql site:http://site.com
- filetype:env inurl:.env site:http://site.com

2. Finding Sensitive Directories:
- inurl:/phpinfo.php site:http://site.com
- inurl:/admin site:http://site.com
- inurl:/backup site:http://site.com
- inurl:wp- site:http://site.com

3. Exposed Configuration Files:
- filetype:config inurl:config site:http://site.com
- filetype:ini inurl:wp-config.php site:http://site.com
- filetype:json inurl:credentials site:http://site.com

4. Discovering Usernames and Passwords:
- intext:"password" filetype:log site:http://site.com
- intext:"username" filetype:log site:http://site.com
- filetype:sql "password" site:http://site.com

5. Finding Database Files:
- filetype:sql inurl:db site:http://site.com
- filetype:sql inurl:dump site:http://site.com
- filetype:bak inurl:db site:http://site.com

6. Exposed Git Repositories:
- inurl:".git" site:http://site.com
- inurl:"/.git/config" site:http://site.com
- intitle:"index of" ".git" site:http://site.com

7. Finding Publicly Exposed Emails:
- intext:"email" site:http://site.com
- inurl:"contact" intext:"
@site
.com" -www.site.com
- filetype:xls inurl:"email" site:http://site.com

8. Discovering Vulnerable Web Servers:
- intitle:"Apache2 Ubuntu Default Page: It works" site:http://site.com
- intitle:"Index of /" "Apache Server" site:http://site.com
- intitle:"Welcome to nginx" site:http://site.com

9. Finding API Keys:
- filetype:env "DB_PASSWORD" site:http://site.com
- intext:"api_key" filetype:env site:http://site.com
- intext:"AWS_ACCESS_KEY_ID" filetype:env site:http://site.com

10. Exposed Backup Files:
- filetype:bak inurl:backup site:http://site.com
- filetype:bak inurl:backup site:http://site.com
- filetype:zip inurl:backup site:http://site.com
- filetype:tgz inurl:backup site:http://site.com

#infosec #bugbounty #bugbountytips #100xSecurity #Hacking
👍1
Today's Bug Bounty Blogs #16

1)How I Bypassed 2FA and Earned My First Bounty $$$
https://anonysm.medium.com/how-i-bypassed-2fa-and-earned-my-first-bounty-3fdc58938347

2)Information Disclosure : 80+ Emails and LongID Disclosed !!
https://pushkarhax.medium.com/information-disclosure-80-emails-and-longid-disclosed-8952e2c6978b

3)Bug Bounty Methodology — Step By Step Guide To Find Subdomains And Vulnerable URLs
https://medium.com/@shaikhminhaz1975/bug-bounty-methodology-step-by-step-guide-to-find-subdomains-and-vulnerable-urls-18bdd76e979f

4)Exposing Database Creds via SVN: A $400 Discovery
https://infosecwriteups.com/exposing-source-code-via-svn-a-400-discovery-9fc54b3f3f31

5)Blind SSRF vulnerability on 'cz.acronis.com'
https://hackerone.com/reports/1086206

6)Hack Your First PC: Ep.7 — Demonstrate Your Skills
https://medium.com/@joshuapiesta/hack-your-first-pc-ep-7-demonstrate-your-skills-96930dea103d

7)Free CTF Challenge Pack: Easy Setup, Big Impact
https://medium.com/@josh.beck2006/free-ctf-challenge-pack-easy-setup-big-impact-142aee19b78e

8)IO Netgarage Levels 1 and 2 Walkthrough
https://systemweakness.com/io-netgarage-levels-1-and-2-walkthrough-66b60fb9e16e

9)picoCTF writeup: repetitions
https://medium.com/@omstaendlig/picoctf-writeup-repetitions-e37aa158416d

Hope you'll enjoy reading these blogs on Bug Bounty and CTFs, Keep Sharing!

Join These Channels For More:

@TheCyberMonks
@HundredxSecurity
@HackstackSecurity
@thecybersecuritychannel
👍1