Pentester
2.82K subscribers
117 photos
3 videos
163 files
2.76K links
- Offensive Security (Red Teaming / PenTesting)
- BlueTeam (OperationSec, TreatHunting, DFIR)
- Reverse Engineering / Malware Analisys
- Web Security
Download Telegram
1
Network_Pentesting_Mindmap.pdf
11.7 MB
#Infographics
"Network Nightmare" Mindmap, 2023.

// It is a mindmap for conducting network attacks. It will be useful to pentesters/red team operators
👍2
Gitlab_Security_Audit.pdf
466 KB
"Source Code Audit on Git for Open Source Technology Improvement Fund (OSTIF)", 2023.
CVE-2022-39952:
Unauthenticated RCE in Fortinet FortiNAC
https://github.com/Florian-R0th/CVE-2022-39952
CVE-2023-23752:
CMS Joomla - unauthorized access to webservice endpoints
https://github.com/WhiteOwl-Pub/CVE-2023-23752
DiffCSP.pdf
868.5 KB
#Research
"DiffCSP: Finding Browser Bugs in Content Security Policy Enforcement through Differential Testing", 2023.
#reversing
1. apk sh - Bash script that makes reverse engineering Android apps easier, automating some repetitive tasks
https://github.com/ax/apk.sh#getting-started
2. Sekiryu - Python script for automatic decompilation and analysis of binary files with ChatGPT and Ghidra (IDA & Binja support soon)
https://github.com/20urc3/Sekiryu
👍1
Android_Non-SDK_Srv_API_Sec.pdf
560.5 KB
#Mobile_Security
"A Systematic Study of Android Non-SDK (Hidden) Service API Security", 2022.

ServiceAudit tool - Android Service Helper bypass vulnerabilties detecting:
https://github.com/fripSide/ServiceAudit

Android static analysis repository:
https://github.com/krizzsk/HackersCave4StaticAndroidSec/blob/main/Android%20Research/research-articles.md
Jenkins Security Alert: New Security Flaws Could Allow Code Execution Attacks

https://thehackernews.com/2023/03/jenkins-security-alert-new-security.html