Information Security
408 subscribers
157 photos
5 videos
9 files
2.28K links
Information Security News

we are @sec_nerd twin brother
Download Telegram
#bugbountytip #bugbounty Directory listing bypass payloads : Any file name or folder name ..%3B/
/%20../
/.ssh/authorized_keys
/.ssh/known_hosts
/%2e%2e/google.com
..%3B/////////////////////////////////
Return a list of endpoints from a swagger.json.
Pass them to your fuzzer(s), +profit?

curl -s hxxps://petstore.swagger.io/v2/swagger.json | jq '.paths | keys[]'

#bugbounty #bugbountytips #redteam #security #oneliner #bash
Lots to dive into this week's CryptOsint.

U.S. Treasury tries its hand at graphic design, Paul Singer & Jack Dorsey make up, AND Russian oligarchs are investing in Telegram's ICO.


https://mailchi.mp/782847570f22/us-treasury-shows-how-chinese-nationals-launder-money-for-dprk
No Privilege Escalating through standard methods ?

whoami /priv

If you got one of these == win 😏


SeBackupPrivilege, SeDebugPrivilege, SeTakeOwnershipPrivilege, SeTcbPrivilege, SeCreateToken Privilege, SeLoadDriver Privilege, SeImpersonate

#infosec #pentest #redteam