Pentester
2.94K subscribers
120 photos
3 videos
163 files
2.77K links
- Offensive Security (Red Teaming / PenTesting)
- BlueTeam (OperationSec, TreatHunting, DFIR)
- Reverse Engineering / Malware Analisys
- Web Security
Download Telegram
A Pentester's Guide - Part 3 (OSINT, Breach Dumps, & Password Spraying)
https://delta.navisec.io/osint-for-pentesters-part-3-password-spraying-methodology/
Chaining Multiple Vulnerabilities + WAF bypass to Account Takeover in almost all Alibaba’s websites
https://medium.com/@y.shahinzadeh/chaining-multiple-vulnerabilities-waf-bypass-to-account-takeover-in-almost-all-alibabas-websites-f8643eaa2855
Need to escalate privs? Have access to PowerShell? Pull the command history. PS v5 now logs everything!

cat (Get-PSReadlineOption).HistorySavePath
or
cat (Get-PSReadlineOption).HistorySavePath | sls password
or
cat (Get-PSReadlineOption).HistorySavePath | sls accountpassword
PHP deserialization techniques DRUPAL 1-CLICK TO RCE EXPLOIT CHAIN DETAILED

/sites/default/files/pictures/<YYYY-MM>/_0
instead of:
/sites/default/files/pictures/<YYYY-MM>/profile_pic.gif.

[Demo] https://t.co/ZkHof6sDzy
https://t.co/etmxwSWEBD
Invisi-Shell : Hide your Powershell script in plain sight (Bypass all Powershell security features) : https://t.co/Zsy5Bp4tJH

Presentation : Goodbye Obfuscation - Hello InvisiShell Hiding Your Powershell Script in Plain Sight : https://t.co/awYN09bcVE
This repository contains all the noise and artifacts surrounding the development of a new implementation of #Meterpreter that is intended to run on the CLR.

https://t.co/8qKOnis9N7