Pentester
2.94K subscribers
120 photos
3 videos
163 files
2.77K links
- Offensive Security (Red Teaming / PenTesting)
- BlueTeam (OperationSec, TreatHunting, DFIR)
- Reverse Engineering / Malware Analisys
- Web Security
Download Telegram
Need to know the internal AD Domain name from outside? Find their Skype or Lync server and then:

nmap -p443 --script http-ntlm-info --script-args http-ntlm-info.root=/WebTicket/WebTicketService.svc skype.example.local
GitHub - The-Cracker-Technology/ANDRAX-Mobile-Pentest: ANDRAX The first and unique Penetration Testing platform for Android smartphones
https://github.com/The-Cracker-Technology/ANDRAX-Mobile-Pentest/
If you use #BurpSuite and Firefox, your Burp probably catches a bunch of distracting Firefox traffic like captive portal detection, OCSP, update checks etc.
To have this traffic bypass burp proxy, you can use FoxyProxy allow/deny lists. My config is at: https://t.co/Z6K9ybGO59