UNDERCODE TESTING
310 subscribers
311 photos
24 videos
173 files
29.8K links
๐Ÿฆ‘ World first platform which Collect & Analyzes every New hacking method.

+ Free AI Practice.

(New Bug Bounty Methods, Tools Updates, AI & Courses).

โœจ Services: Undercode.help/services

โœจyoutube.com/undercode

@Undercode_Testing
Download Telegram
Forwarded from Exploiting Crew (Pr1vAt3)
Forwarded from Exploiting Crew (Pr1vAt3)
๐Ÿฆ‘18 Must-Have Free Tools for Cybersecurity Enthusiasts ๐Ÿ›ก๏ธ

As a cybersecurity professional, staying ahead of the curve requires constant learning and hands-on practice. The good news? You donโ€™t need to break the bank to access industry-leading tools. Here's a curated list of 18 free cybersecurity tools to elevate your skillsโ€”whether you're a beginner or a seasoned expert!

๐Ÿ”ต 1. Kali Linux
The ultimate penetration testing operating system for ethical hackers.

๐Ÿ”ต 2. Wireshark
A network protocol analyzer that lets you capture and inspect data in real time.

๐Ÿ”ต 3. Burp Suite Community Edition
Perfect for web application security testing and vulnerability assessments.

๐Ÿ”ต 4. Gophish
An open-source phishing toolkit for creating realistic phishing campaigns.

๐Ÿ”ต 5. Aircrack-ng
Specializes in cracking WEP/WPA Wi-Fi passwords.

๐Ÿ”ต 6. Have I Been Pwned?
Check if your email or accounts have been compromised in data breaches.

๐Ÿ”ต 7. Metasploit Framework
A penetration testing powerhouse for exploiting vulnerabilities.

๐Ÿ”ต 8. Nikto
Scans web servers for dangerous files, outdated software, and misconfigurations.

๐Ÿ”ต 9. HackTheBox
An interactive training platform to sharpen your hacking skills.

๐Ÿ”ต 10. pfSense
A firewall and router solution for network protection.

๐Ÿ”ต 11. CyberChef
A versatile tool for analyzing, encrypting, and decoding data.

๐Ÿ”ต 12. Ghidra
An open-source reverse engineering tool by the NSA.

๐Ÿ”ต 13. Deshashed
Enhance email security by detecting exposed credentials.

๐Ÿ”ต 14. OpenVAS
A comprehensive vulnerability scanner for systems and networks.

๐Ÿ”ต 15. OSSEC
Monitor and prevent intrusions in your environment with this HIDS tool.

๐Ÿ”ต 16. SQLmap
Automatically detect and exploit SQL injection vulnerabilities.

๐Ÿ”ต 17. REMnux
Reverse engineering and malware analysis made accessible.

๐Ÿ”ต 18. Zed Attack Proxy (ZAP)
A web application security scanner for discovering vulnerabilities.


๐ŸŒŸ Why Use These Tools?
- Cost-Effective: Free but highly efficient.
- Industry Standard: Frequently used by professionals worldwide.
- Skill Development: Master critical areas like penetration testing, vulnerability analysis, and data protection.

Ref: Arun KL
@UndercodeCommunity
โ– โ–‚ โ–„ U๐•Ÿ๐”ปโ’บ๐ซฤ†๐”ฌ๐““โ“” โ–„ โ–‚ โ–
๐Ÿฆ‘๐—ฃ๐—ผ๐˜„๐—ฒ๐—ฟ๐—ฆ๐—ต๐—ฒ๐—น๐—น ๐—ฆ๐—ฒ๐—น๐—ณ-๐—ฃ๐˜„๐—ป ๐——๐—ฒ๐˜๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป

The Proofpoint blog outlines a social engineering tactic where threat actors deceive users into copying and pasting malicious PowerShell scripts, causing malware infections. Groups like TA571 use fake error messages to prompt script execution, delivering malware such as DarkGate and NetSupport. Despite needing significant user interaction, the attack's success hinges on sophisticated social engineering. I have developed a custom detection PowerShell Self-Pwn KQL to identify such scenarios and assist SecOps in isolating affected devices.

Ref: Steven Lim
@UndercodeCommunity
โ– โ–‚ โ–„ U๐•Ÿ๐”ปโ’บ๐ซฤ†๐”ฌ๐““โ“” โ–„ โ–‚ โ–
Forwarded from Exploiting Crew (Pr1vAt3)
Forwarded from Exploiting Crew (Pr1vAt3)
๐Ÿฆ‘Security collection for pro:

โœ…Worm Infection: https://lnkd.in/ez-kq98Y
โœ…Social Engineering: https://lnkd.in/e_FJbxDP
โœ…Information Leakage: https://lnkd.in/eeN8KX8g
โœ…Insider Abuse: https://lnkd.in/ep4p_THk
โœ…Customer Phishing: https://lnkd.in/ekTfY7vz
โœ…Scam: https://lnkd.in/eUHwG3fF
โœ…Trademark infringement: https://lnkd.in/e3P3xfeb
โœ…Phishing: https://lnkd.in/eYTi3RQ8
โœ…Ransomware: https://lnkd.in/eRkctdQn
โœ…Large_scale_compromise: https://lnkd.in/eYFF43b4
โœ…3rd-party_compromise: https://lnkd.in/e8SAu5MT
โœ…Windows Intrusion: https://lnkd.in/eXCpcx9V
โœ…Unix Linux lntrusionDetection: https://lnkd.in/eHkm6MMe
โœ…DDOS: https://lnkd.in/eQ7zZzVt
โœ…MaliciousNetworkBehaviour: https://lnkd.in/ewVZy2cs
โœ…Website-Defacement: https://lnkd.in/eraNiHcH
โœ…WindowsMalwareDetection: https://lnkd.in/ewEx_C6Y
โœ…Blackmail: https://lnkd.in/eW3zGcPs
โœ…SmartphoneMalware.pdf: https://lnkd.in/ezjyY4G9

Ref: Mohamad Hamadi
@UndercodeCommunity
โ– โ–‚ โ–„ U๐•Ÿ๐”ปโ’บ๐ซฤ†๐”ฌ๐““โ“” โ–„ โ–‚ โ–
Media is too big
VIEW IN TELEGRAM
๐Ÿฆ‘Takeover poc Video dem:

Password Reset Link not expiring after changing the email Leads To Account Takeover poc ๐Ÿšจ

๐Ÿ“ Description:
In this video, Iโ€™ll demonstrate a critical vulnerability where a password reset link remains active even after changing the registered email, leading to a potential account takeover exploit. This live PoC showcases the risk and offers insights into preventing such flaws.
๐Ÿฆ‘Top Free Java Projects:

1. Airline Reservation System:
- https://lnkd.in/dRFK2vPh

2. Data Visualization Software:
- https://lnkd.in/dVWVU8xn

3. Electricity Billing System:
- https://lnkd.in/dekycNXQ

4. E-Healthcare Management System:
- https://lnkd.in/dEkE2raN

5. Email Client Software:
- https://lnkd.in/d_qz7U9E

6. Library Management System:
- https://lnkd.in/dY7bDjFn

7. Network Packet Sniffer:
- https://lnkd.in/dXPtyzz4

8. Online Bank Management System:
- https://lnkd.in/d4Qzy8fN

9. Online Medical Management System:
- https://lnkd.in/dHciHGGz

10. Online Quiz Management System:
- https://lnkd.in/djKs3DJq

11. Online Survey System:
- https://lnkd.in/dw9Cmhix

12. RSS Feed Reader:
- https://lnkd.in/dupDQPnG

13. Smart City Project:
- https://lnkd.in/d3YT36aJ

14. Stock Management System:
- https://lnkd.in/dTb3hikj

15. Supply Chain Management System:
- https://lnkd.in/dAzJthMQ

16. Virtual Private Network:
- https://lnkd.in/dyEcgrFC

Ref: Rajat Gajbhiye
@UndercodeCommunity
โ– โ–‚ โ–„ U๐•Ÿ๐”ปโ’บ๐ซฤ†๐”ฌ๐““โ“” โ–„ โ–‚ โ–
Forwarded from Exploiting Crew (Pr1vAt3)
1733811306699.pdf
23.6 MB
Forwarded from Exploiting Crew (Pr1vAt3)
๐Ÿฆ‘How Was the TOR Attacker Caught? ๐Ÿ•ต๏ธโ™‚๏ธ

๐ŸŒ The Dark Web often seems like an untraceable haven for anonymity. But even in the world of TOR (The Onion Router), attackers can be caught! Hereโ€™s how:

1๏ธโƒฃ Human Error: Attackers often make small mistakes, like logging in from a non-TOR connection or revealing identifying details in their communications. Even a single misstep can be critical.

2๏ธโƒฃ Traffic Analysis: TOR masks your identity by routing traffic through multiple nodes. However, law enforcement can use advanced traffic correlation techniques to identify entry and exit points, especially when they control some TOR nodes.

3๏ธโƒฃ Compromised Nodes: Investigators may run malicious TOR nodes to intercept traffic. They analyze the data flowing through them, narrowing down potential suspects.

4๏ธโƒฃ Exploits: Vulnerabilities in TOR or the userโ€™s device/browser can be exploited to reveal real IP addresses. For example, Operation Onymous used malware to expose hidden server locations.

5๏ธโƒฃ Metadata Tracking: Even encrypted communications leave traces. Authorities piece together patterns, times, and behaviors to zero in on suspects.

๐Ÿ’ก Key Takeaway: No system is 100% secure. Cybercriminals often underestimate the combination of technical expertise and human ingenuity behind modern investigations.

Ref: Mahesh Girhe
@UndercodeCommunity
โ– โ–‚ โ–„ U๐•Ÿ๐”ปโ’บ๐ซฤ†๐”ฌ๐““โ“” โ–„ โ–‚ โ–
๐Ÿฆ‘Xss
#tips
1. Get endpoints from wayback.
2. And then knoxnl -i endpoints.txt -afb -sb 1
Forwarded from Exploiting Crew (Pr1vAt3)
๐Ÿฆ‘๐‚๐จ๐ฆ๐ฉ๐š๐ง๐ฒ ๐–๐ข๐ฌ๐ž ๐’๐๐‹ ๐ˆ๐ง๐ญ๐ž๐ซ๐ฏ๐ข๐ž๐ฐ ๐๐ฎ๐ž๐ฌ๐ญ๐ข๐จ๐ง๐ฌ

Here , I have listed out all SQL interview questions for your easy reference.

1. Amazon SQL Interview Question for Data Analyst Position [2-3 Year Of Experience ] | Data Analytics
https://lnkd.in/g2RzsKdq

2. Airbnb SQL Interview Question | Convert Comma Separated Values into Rows | Data Analytics
https://lnkd.in/gpMbU-dF

3. Adobe Interesting SQL Interview Question | Solving Using 2 Approaches | Data Analytics
https://lnkd.in/g_-_9ymd

4. Spotify SQL Interview Problem | Top 5 Artists | Aggregation and Window Functions in SQL
https://lnkd.in/gtfaugd3

5. L&T Technology Services SQL Interview Problem | Print Highest and Lowest Salary Employees in Each Department
https://lnkd.in/ggY82FJW

6. Ameriprise Financial Services, LLCSQL Interview Problem | Data Analytics
https://lnkd.in/gS_Yqq6c

7. Tiger Analytics SQL Interview Question for Data Engineering Position
https://lnkd.in/ghjE_CXp

8. PwC SQL Interview Question | BIG 4 |Normal vs Mentos Life ๐Ÿ˜Ž
https://lnkd.in/g9SkkX9x

9. Honeywell SQL Interview Question | Print Movie Stars (โญ โญ โญ โญโญ) For best movie in each Genre
https://lnkd.in/gSDgB9Me

10. Angel One Easy-Peasy SQL Interview Question for a Data Science Position
https://lnkd.in/geaU3we7

11. Practice FAANG SQL Interview Questions For Free | Ace The SQL Interview | Data Analytics
https://lnkd.in/g4AFgen3

12. Accenture SQL Interview Question | Database Case Sensitivity vs Insensitivity
https://lnkd.in/gR6F_8zf

13. American Express SQL Interview Question and Solution | Page Recommendation
https://lnkd.in/g_sMN26m

14. Fractal Analytics SQL Interview Question (Game of Thrones Database) | SQL for Data Engineer
https://lnkd.in/gGcsBms5

15. Netflix Data Cleaning and Analysis Project | End to End Data Engineering Project (SQL + Python)
https://lnkd.in/gS8mT7Fn

16. Swiggy Data Analyst SQL Interview Question and Answer
https://lnkd.in/gSyhmmhd

17. Cracked Myntra as Data Analyst with 1 Year Experience
https://lnkd.in/gekpAit8

18. PwC SQL Interview Question for a Data Analyst Position | SQL For Analytics
https://lnkd.in/gyD5Pjny

19. PayPal Data Engineer SQL Interview Question (and a secret time saving trick)
https://lnkd.in/gAJ_Ug79

20. Adobe Interesting SQL Interview Question | Solving Using 2 Approaches | Data Analytics
https://lnkd.in/gEEAfi8j

21. Walmart Labs SQL Interview Question for Senior Data Analyst Position | Data Analytics
https://lnkd.in/gRBPb-ms

22. PayPal SQL Interview Problem (Level Hard) | Advanced SQL Problem
https://lnkd.in/gGZaYt6N

Ref: Abhisek Sahu
@UndercodeCommunity
โ– โ–‚ โ–„ U๐•Ÿ๐”ปโ’บ๐ซฤ†๐”ฌ๐““โ“” โ–„ โ–‚ โ–
Forwarded from Exploiting Crew (Pr1vAt3)
๐Ÿฆ‘SQL Injection Detection Techniques"

SQL Injection remains a critical vulnerability in web applications. Detecting it early is key to protecting your data. Some effective detection techniques include.

Ref: Amit Kumar
@UndercodeCommunity
โ– โ–‚ โ–„ U๐•Ÿ๐”ปโ’บ๐ซฤ†๐”ฌ๐““โ“” โ–„ โ–‚ โ–
Forwarded from Exploiting Crew (Pr1vAt3)
๐Ÿฆ‘Roadmap for learning Low-Level Design (LLD):

โžค ๐—™๐˜‚๐—ป๐—ฑ๐—ฎ๐—บ๐—ฒ๐—ป๐˜๐—ฎ๐—น ๐—–๐—ผ๐—ป๐—ฐ๐—ฒ๐—ฝ๐˜๐˜€:

1. Basics OOP Concepts:
- https://lnkd.in/dhX-yYnb
2. SOLID Principles:
- https://lnkd.in/drsM7izj
3. DRY, YAGNI and KISS Principle:
- https://lnkd.in/d7Dk9Mpb
- https://lnkd.in/dvdm2mgR

โžค ๐——๐—ฒ๐˜€๐—ถ๐—ด๐—ป ๐—ฃ๐—ฎ๐˜๐˜๐—ฒ๐—ฟ๐—ป๐˜€

1. Creational Patterns
- Singleton, Factory Method, Abstract Factory, Builder, Prototype and Structural Patterns
- https://lnkd.in/dfr_3f-U
- https://lnkd.in/d2s88tuV

2. Adapter
- Facade, Decorator, Composite and Behavioral Patterns
- https://lnkd.in/dtiFe8AN

3. Strategy
- Iterator, Observer, Template Method, Command and State

โžค ๐—จ๐—ป๐—ถ๐—ณ๐—ถ๐—ฒ๐—ฑ ๐— ๐—ผ๐—ฑ๐—ฒ๐—น๐—ถ๐—ป๐—ด ๐—Ÿ๐—ฎ๐—ป๐—ด๐˜‚๐—ฎ๐—ด๐—ฒ (๐—จ๐— ๐—Ÿ)

1. Class Diagrams
- Class, Attributes, Methods, Interfaces, Abstract Class, Enumeration and Multiplicity
- https://lnkd.in/dxeh7vSz

2. Use Case, Sequence, Activity and State Machine Diagram
- https://lnkd.in/dgVYbmPA

โžค ๐—ช๐—ฎ๐˜๐—ฐ๐—ต ๐—ฅ๐—ฒ๐˜€๐—ผ๐˜‚๐—ฟ๐—ฐ๐—ฒ๐˜€:

1. Shrayansh Jain: https://lnkd.in/dhW5VmFa
2. Gaurav Sen: https://lnkd.in/dgjFGmXc
3. The Code Mate: https://lnkd.in/d8_6yTSN
4. Soumyajit Bhattacharyay: https://lnkd.in/dFe4t5gZ

โžค ๐—ง๐—ผ๐—ฝ ๐—ฅ๐—ฒ๐—ฝ๐—ผ๐˜€๐—ถ๐˜๐—ผ๐—ฟ๐—ถ๐—ฒ๐˜€ ๐˜๐—ผ ๐— ๐—ฎ๐˜€๐˜๐—ฒ๐—ฟ ๐—Ÿ๐—Ÿ๐——โ€‹:

- https://lnkd.in/dAb9m84N
- https://lnkd.in/dvzAdaGt
- https://lnkd.in/dXypcpR4
- https://lnkd.in/dBYMX7Ph

โžค ๐—ฃ๐—ฟ๐—ฎ๐—ฐ๐˜๐—ถ๐—ฐ๐—ฎ๐—น ๐—˜๐˜…๐—ฎ๐—บ๐—ฝ๐—น๐—ฒ๐˜€:

- Standard problem solutions: https://lnkd.in/dXypcpR4
- Practice questions: https://lnkd.in/dCMb2nFV

โžค ๐—ฆ๐—ฒ๐—น๐—ณ-๐—”๐˜€๐˜€๐—ฒ๐˜€๐˜€๐—บ๐—ฒ๐—ป๐˜:

- Question 1: https://lnkd.in/dQRCdKhs
- Question 2: https://lnkd.in/dHmEiE79

Just preparing for DSA is not going to get you selected. During technical interviews, you are expected to have some level of understanding of low-level designs.

Ref: Rajat GajbhiyeRajat Gajbhiye
@UndercodeCommunity
โ– โ–‚ โ–„ U๐•Ÿ๐”ปโ’บ๐ซฤ†๐”ฌ๐““โ“” โ–„ โ–‚ โ–
Forwarded from Exploiting Crew (Pr1vAt3)
๐Ÿฆ‘PowerShell-Hunter: Your New Favorite Event Log Analysis Tool!

๐Ÿ” Tired of drowning in PowerShell logs? We've got you covered:
โ€ข Smart pattern detection for malicious behaviors
โ€ข Risk scoring to prioritize threats
โ€ข Export to CSV/JSON for your workflow
โ€ข Extensible pattern matching

๐Ÿš€ Perfect for:
โ€ข Incident Response
โ€ข Threat Hunting
โ€ข Forensics
โ€ข SOC Analysis

๐Ÿ’ก Why PowerShell-Hunter?
โ€ข Process thousands of 4104 events in seconds
โ€ข Pre-configured detection patterns
โ€ข Catch encoded commands, suspicious downloads, and more
โ€ข Built by defenders, for defenders

๐Ÿ”ฅ Get started: https://github.com/MHaggis/PowerShell-Hunter

Ref: Michael H
@UndercodeCommunity
โ– โ–‚ โ–„ U๐•Ÿ๐”ปโ’บ๐ซฤ†๐”ฌ๐““โ“” โ–„ โ–‚ โ–
Forwarded from Exploiting Crew (Pr1vAt3)
๐Ÿฆ‘Get Your AI powered terminal assistant:

curl -sS https://raw.githubusercontent.com/ekkinox/yai/main/install.sh | bash