Forwarded from Exploiting Crew (Pr1vAt3)
๐ฆHow Was the TOR Attacker Caught? ๐ต๏ธโ๏ธ
๐ The Dark Web often seems like an untraceable haven for anonymity. But even in the world of TOR (The Onion Router), attackers can be caught! Hereโs how:
1๏ธโฃ Human Error: Attackers often make small mistakes, like logging in from a non-TOR connection or revealing identifying details in their communications. Even a single misstep can be critical.
2๏ธโฃ Traffic Analysis: TOR masks your identity by routing traffic through multiple nodes. However, law enforcement can use advanced traffic correlation techniques to identify entry and exit points, especially when they control some TOR nodes.
3๏ธโฃ Compromised Nodes: Investigators may run malicious TOR nodes to intercept traffic. They analyze the data flowing through them, narrowing down potential suspects.
4๏ธโฃ Exploits: Vulnerabilities in TOR or the userโs device/browser can be exploited to reveal real IP addresses. For example, Operation Onymous used malware to expose hidden server locations.
5๏ธโฃ Metadata Tracking: Even encrypted communications leave traces. Authorities piece together patterns, times, and behaviors to zero in on suspects.
๐ก Key Takeaway: No system is 100% secure. Cybercriminals often underestimate the combination of technical expertise and human ingenuity behind modern investigations.
Ref: Mahesh Girhe
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
๐ The Dark Web often seems like an untraceable haven for anonymity. But even in the world of TOR (The Onion Router), attackers can be caught! Hereโs how:
1๏ธโฃ Human Error: Attackers often make small mistakes, like logging in from a non-TOR connection or revealing identifying details in their communications. Even a single misstep can be critical.
2๏ธโฃ Traffic Analysis: TOR masks your identity by routing traffic through multiple nodes. However, law enforcement can use advanced traffic correlation techniques to identify entry and exit points, especially when they control some TOR nodes.
3๏ธโฃ Compromised Nodes: Investigators may run malicious TOR nodes to intercept traffic. They analyze the data flowing through them, narrowing down potential suspects.
4๏ธโฃ Exploits: Vulnerabilities in TOR or the userโs device/browser can be exploited to reveal real IP addresses. For example, Operation Onymous used malware to expose hidden server locations.
5๏ธโฃ Metadata Tracking: Even encrypted communications leave traces. Authorities piece together patterns, times, and behaviors to zero in on suspects.
๐ก Key Takeaway: No system is 100% secure. Cybercriminals often underestimate the combination of technical expertise and human ingenuity behind modern investigations.
Ref: Mahesh Girhe
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
Forwarded from Exploiting Crew (Pr1vAt3)
๐ฆ๐๐จ๐ฆ๐ฉ๐๐ง๐ฒ ๐๐ข๐ฌ๐ ๐๐๐ ๐๐ง๐ญ๐๐ซ๐ฏ๐ข๐๐ฐ ๐๐ฎ๐๐ฌ๐ญ๐ข๐จ๐ง๐ฌ
Here , I have listed out all SQL interview questions for your easy reference.
1. Amazon SQL Interview Question for Data Analyst Position [2-3 Year Of Experience ] | Data Analytics
https://lnkd.in/g2RzsKdq
2. Airbnb SQL Interview Question | Convert Comma Separated Values into Rows | Data Analytics
https://lnkd.in/gpMbU-dF
3. Adobe Interesting SQL Interview Question | Solving Using 2 Approaches | Data Analytics
https://lnkd.in/g_-_9ymd
4. Spotify SQL Interview Problem | Top 5 Artists | Aggregation and Window Functions in SQL
https://lnkd.in/gtfaugd3
5. L&T Technology Services SQL Interview Problem | Print Highest and Lowest Salary Employees in Each Department
https://lnkd.in/ggY82FJW
6. Ameriprise Financial Services, LLCSQL Interview Problem | Data Analytics
https://lnkd.in/gS_Yqq6c
7. Tiger Analytics SQL Interview Question for Data Engineering Position
https://lnkd.in/ghjE_CXp
8. PwC SQL Interview Question | BIG 4 |Normal vs Mentos Life ๐
https://lnkd.in/g9SkkX9x
9. Honeywell SQL Interview Question | Print Movie Stars (โญ โญ โญ โญโญ) For best movie in each Genre
https://lnkd.in/gSDgB9Me
10. Angel One Easy-Peasy SQL Interview Question for a Data Science Position
https://lnkd.in/geaU3we7
11. Practice FAANG SQL Interview Questions For Free | Ace The SQL Interview | Data Analytics
https://lnkd.in/g4AFgen3
12. Accenture SQL Interview Question | Database Case Sensitivity vs Insensitivity
https://lnkd.in/gR6F_8zf
13. American Express SQL Interview Question and Solution | Page Recommendation
https://lnkd.in/g_sMN26m
14. Fractal Analytics SQL Interview Question (Game of Thrones Database) | SQL for Data Engineer
https://lnkd.in/gGcsBms5
15. Netflix Data Cleaning and Analysis Project | End to End Data Engineering Project (SQL + Python)
https://lnkd.in/gS8mT7Fn
16. Swiggy Data Analyst SQL Interview Question and Answer
https://lnkd.in/gSyhmmhd
17. Cracked Myntra as Data Analyst with 1 Year Experience
https://lnkd.in/gekpAit8
18. PwC SQL Interview Question for a Data Analyst Position | SQL For Analytics
https://lnkd.in/gyD5Pjny
19. PayPal Data Engineer SQL Interview Question (and a secret time saving trick)
https://lnkd.in/gAJ_Ug79
20. Adobe Interesting SQL Interview Question | Solving Using 2 Approaches | Data Analytics
https://lnkd.in/gEEAfi8j
21. Walmart Labs SQL Interview Question for Senior Data Analyst Position | Data Analytics
https://lnkd.in/gRBPb-ms
22. PayPal SQL Interview Problem (Level Hard) | Advanced SQL Problem
https://lnkd.in/gGZaYt6N
Ref: Abhisek Sahu
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
Here , I have listed out all SQL interview questions for your easy reference.
1. Amazon SQL Interview Question for Data Analyst Position [2-3 Year Of Experience ] | Data Analytics
https://lnkd.in/g2RzsKdq
2. Airbnb SQL Interview Question | Convert Comma Separated Values into Rows | Data Analytics
https://lnkd.in/gpMbU-dF
3. Adobe Interesting SQL Interview Question | Solving Using 2 Approaches | Data Analytics
https://lnkd.in/g_-_9ymd
4. Spotify SQL Interview Problem | Top 5 Artists | Aggregation and Window Functions in SQL
https://lnkd.in/gtfaugd3
5. L&T Technology Services SQL Interview Problem | Print Highest and Lowest Salary Employees in Each Department
https://lnkd.in/ggY82FJW
6. Ameriprise Financial Services, LLCSQL Interview Problem | Data Analytics
https://lnkd.in/gS_Yqq6c
7. Tiger Analytics SQL Interview Question for Data Engineering Position
https://lnkd.in/ghjE_CXp
8. PwC SQL Interview Question | BIG 4 |Normal vs Mentos Life ๐
https://lnkd.in/g9SkkX9x
9. Honeywell SQL Interview Question | Print Movie Stars (โญ โญ โญ โญโญ) For best movie in each Genre
https://lnkd.in/gSDgB9Me
10. Angel One Easy-Peasy SQL Interview Question for a Data Science Position
https://lnkd.in/geaU3we7
11. Practice FAANG SQL Interview Questions For Free | Ace The SQL Interview | Data Analytics
https://lnkd.in/g4AFgen3
12. Accenture SQL Interview Question | Database Case Sensitivity vs Insensitivity
https://lnkd.in/gR6F_8zf
13. American Express SQL Interview Question and Solution | Page Recommendation
https://lnkd.in/g_sMN26m
14. Fractal Analytics SQL Interview Question (Game of Thrones Database) | SQL for Data Engineer
https://lnkd.in/gGcsBms5
15. Netflix Data Cleaning and Analysis Project | End to End Data Engineering Project (SQL + Python)
https://lnkd.in/gS8mT7Fn
16. Swiggy Data Analyst SQL Interview Question and Answer
https://lnkd.in/gSyhmmhd
17. Cracked Myntra as Data Analyst with 1 Year Experience
https://lnkd.in/gekpAit8
18. PwC SQL Interview Question for a Data Analyst Position | SQL For Analytics
https://lnkd.in/gyD5Pjny
19. PayPal Data Engineer SQL Interview Question (and a secret time saving trick)
https://lnkd.in/gAJ_Ug79
20. Adobe Interesting SQL Interview Question | Solving Using 2 Approaches | Data Analytics
https://lnkd.in/gEEAfi8j
21. Walmart Labs SQL Interview Question for Senior Data Analyst Position | Data Analytics
https://lnkd.in/gRBPb-ms
22. PayPal SQL Interview Problem (Level Hard) | Advanced SQL Problem
https://lnkd.in/gGZaYt6N
Ref: Abhisek Sahu
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
lnkd.in
LinkedIn
This link will take you to a page thatโs not on LinkedIn
Forwarded from Exploiting Crew (Pr1vAt3)
๐ฆSQL Injection Detection Techniques"
SQL Injection remains a critical vulnerability in web applications. Detecting it early is key to protecting your data. Some effective detection techniques include.
Ref: Amit Kumar
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
SQL Injection remains a critical vulnerability in web applications. Detecting it early is key to protecting your data. Some effective detection techniques include.
Ref: Amit Kumar
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
Forwarded from Exploiting Crew (Pr1vAt3)
๐ฆRoadmap for learning Low-Level Design (LLD):
โค ๐๐๐ป๐ฑ๐ฎ๐บ๐ฒ๐ป๐๐ฎ๐น ๐๐ผ๐ป๐ฐ๐ฒ๐ฝ๐๐:
1. Basics OOP Concepts:
- https://lnkd.in/dhX-yYnb
2. SOLID Principles:
- https://lnkd.in/drsM7izj
3. DRY, YAGNI and KISS Principle:
- https://lnkd.in/d7Dk9Mpb
- https://lnkd.in/dvdm2mgR
โค ๐๐ฒ๐๐ถ๐ด๐ป ๐ฃ๐ฎ๐๐๐ฒ๐ฟ๐ป๐
1. Creational Patterns
- Singleton, Factory Method, Abstract Factory, Builder, Prototype and Structural Patterns
- https://lnkd.in/dfr_3f-U
- https://lnkd.in/d2s88tuV
2. Adapter
- Facade, Decorator, Composite and Behavioral Patterns
- https://lnkd.in/dtiFe8AN
3. Strategy
- Iterator, Observer, Template Method, Command and State
โค ๐จ๐ป๐ถ๐ณ๐ถ๐ฒ๐ฑ ๐ ๐ผ๐ฑ๐ฒ๐น๐ถ๐ป๐ด ๐๐ฎ๐ป๐ด๐๐ฎ๐ด๐ฒ (๐จ๐ ๐)
1. Class Diagrams
- Class, Attributes, Methods, Interfaces, Abstract Class, Enumeration and Multiplicity
- https://lnkd.in/dxeh7vSz
2. Use Case, Sequence, Activity and State Machine Diagram
- https://lnkd.in/dgVYbmPA
โค ๐ช๐ฎ๐๐ฐ๐ต ๐ฅ๐ฒ๐๐ผ๐๐ฟ๐ฐ๐ฒ๐:
1. Shrayansh Jain: https://lnkd.in/dhW5VmFa
2. Gaurav Sen: https://lnkd.in/dgjFGmXc
3. The Code Mate: https://lnkd.in/d8_6yTSN
4. Soumyajit Bhattacharyay: https://lnkd.in/dFe4t5gZ
โค ๐ง๐ผ๐ฝ ๐ฅ๐ฒ๐ฝ๐ผ๐๐ถ๐๐ผ๐ฟ๐ถ๐ฒ๐ ๐๐ผ ๐ ๐ฎ๐๐๐ฒ๐ฟ ๐๐๐โ:
- https://lnkd.in/dAb9m84N
- https://lnkd.in/dvzAdaGt
- https://lnkd.in/dXypcpR4
- https://lnkd.in/dBYMX7Ph
โค ๐ฃ๐ฟ๐ฎ๐ฐ๐๐ถ๐ฐ๐ฎ๐น ๐๐ ๐ฎ๐บ๐ฝ๐น๐ฒ๐:
- Standard problem solutions: https://lnkd.in/dXypcpR4
- Practice questions: https://lnkd.in/dCMb2nFV
โค ๐ฆ๐ฒ๐น๐ณ-๐๐๐๐ฒ๐๐๐บ๐ฒ๐ป๐:
- Question 1: https://lnkd.in/dQRCdKhs
- Question 2: https://lnkd.in/dHmEiE79
Just preparing for DSA is not going to get you selected. During technical interviews, you are expected to have some level of understanding of low-level designs.
Ref: Rajat GajbhiyeRajat Gajbhiye
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
โค ๐๐๐ป๐ฑ๐ฎ๐บ๐ฒ๐ป๐๐ฎ๐น ๐๐ผ๐ป๐ฐ๐ฒ๐ฝ๐๐:
1. Basics OOP Concepts:
- https://lnkd.in/dhX-yYnb
2. SOLID Principles:
- https://lnkd.in/drsM7izj
3. DRY, YAGNI and KISS Principle:
- https://lnkd.in/d7Dk9Mpb
- https://lnkd.in/dvdm2mgR
โค ๐๐ฒ๐๐ถ๐ด๐ป ๐ฃ๐ฎ๐๐๐ฒ๐ฟ๐ป๐
1. Creational Patterns
- Singleton, Factory Method, Abstract Factory, Builder, Prototype and Structural Patterns
- https://lnkd.in/dfr_3f-U
- https://lnkd.in/d2s88tuV
2. Adapter
- Facade, Decorator, Composite and Behavioral Patterns
- https://lnkd.in/dtiFe8AN
3. Strategy
- Iterator, Observer, Template Method, Command and State
โค ๐จ๐ป๐ถ๐ณ๐ถ๐ฒ๐ฑ ๐ ๐ผ๐ฑ๐ฒ๐น๐ถ๐ป๐ด ๐๐ฎ๐ป๐ด๐๐ฎ๐ด๐ฒ (๐จ๐ ๐)
1. Class Diagrams
- Class, Attributes, Methods, Interfaces, Abstract Class, Enumeration and Multiplicity
- https://lnkd.in/dxeh7vSz
2. Use Case, Sequence, Activity and State Machine Diagram
- https://lnkd.in/dgVYbmPA
โค ๐ช๐ฎ๐๐ฐ๐ต ๐ฅ๐ฒ๐๐ผ๐๐ฟ๐ฐ๐ฒ๐:
1. Shrayansh Jain: https://lnkd.in/dhW5VmFa
2. Gaurav Sen: https://lnkd.in/dgjFGmXc
3. The Code Mate: https://lnkd.in/d8_6yTSN
4. Soumyajit Bhattacharyay: https://lnkd.in/dFe4t5gZ
โค ๐ง๐ผ๐ฝ ๐ฅ๐ฒ๐ฝ๐ผ๐๐ถ๐๐ผ๐ฟ๐ถ๐ฒ๐ ๐๐ผ ๐ ๐ฎ๐๐๐ฒ๐ฟ ๐๐๐โ:
- https://lnkd.in/dAb9m84N
- https://lnkd.in/dvzAdaGt
- https://lnkd.in/dXypcpR4
- https://lnkd.in/dBYMX7Ph
โค ๐ฃ๐ฟ๐ฎ๐ฐ๐๐ถ๐ฐ๐ฎ๐น ๐๐ ๐ฎ๐บ๐ฝ๐น๐ฒ๐:
- Standard problem solutions: https://lnkd.in/dXypcpR4
- Practice questions: https://lnkd.in/dCMb2nFV
โค ๐ฆ๐ฒ๐น๐ณ-๐๐๐๐ฒ๐๐๐บ๐ฒ๐ป๐:
- Question 1: https://lnkd.in/dQRCdKhs
- Question 2: https://lnkd.in/dHmEiE79
Just preparing for DSA is not going to get you selected. During technical interviews, you are expected to have some level of understanding of low-level designs.
Ref: Rajat GajbhiyeRajat Gajbhiye
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
lnkd.in
LinkedIn
This link will take you to a page thatโs not on LinkedIn
Forwarded from Exploiting Crew (Pr1vAt3)
๐ฆPowerShell-Hunter: Your New Favorite Event Log Analysis Tool!
๐ Tired of drowning in PowerShell logs? We've got you covered:
โข Smart pattern detection for malicious behaviors
โข Risk scoring to prioritize threats
โข Export to CSV/JSON for your workflow
โข Extensible pattern matching
๐ Perfect for:
โข Incident Response
โข Threat Hunting
โข Forensics
โข SOC Analysis
๐ก Why PowerShell-Hunter?
โข Process thousands of 4104 events in seconds
โข Pre-configured detection patterns
โข Catch encoded commands, suspicious downloads, and more
โข Built by defenders, for defenders
๐ฅ Get started: https://github.com/MHaggis/PowerShell-Hunter
Ref: Michael H
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
๐ Tired of drowning in PowerShell logs? We've got you covered:
โข Smart pattern detection for malicious behaviors
โข Risk scoring to prioritize threats
โข Export to CSV/JSON for your workflow
โข Extensible pattern matching
๐ Perfect for:
โข Incident Response
โข Threat Hunting
โข Forensics
โข SOC Analysis
๐ก Why PowerShell-Hunter?
โข Process thousands of 4104 events in seconds
โข Pre-configured detection patterns
โข Catch encoded commands, suspicious downloads, and more
โข Built by defenders, for defenders
๐ฅ Get started: https://github.com/MHaggis/PowerShell-Hunter
Ref: Michael H
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
GitHub
GitHub - MHaggis/PowerShell-Hunter: PowerShell tools to help defenders hunt smarter, hunt harder.
PowerShell tools to help defenders hunt smarter, hunt harder. - MHaggis/PowerShell-Hunter
Forwarded from Exploiting Crew (Pr1vAt3)
This media is not supported in your browser
VIEW IN TELEGRAM
Forwarded from Exploiting Crew (Pr1vAt3)
๐ฆGet Your AI powered terminal assistant:
curl -sS https://raw.githubusercontent.com/ekkinox/yai/main/install.sh | bash
Forwarded from Exploiting Crew (Pr1vAt3)
๐ฆLooking for a comprehensive MySQL Blind (Time-Based) SQL Injection Payload List? Here's a handy collection of payloads to help you in your testing process. Perfect for bug bounty hunters, penetration testers, and security researchers.
@UndercodeCommunity
Ref: AMIT KUMARAMIT KUMAR
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
@UndercodeCommunity
Ref: AMIT KUMARAMIT KUMAR
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
Forwarded from Exploiting Crew (Pr1vAt3)
๐ฆFree Courses + Certification (New Collections):
Google Data Analytics
๐ https://lnkd.in/gv4whkFn
Advanced Google Analytics
๐ https://lnkd.in/gnswTs7t
Google Project Management
๐ https://lnkd.in/geUMD3K9
Foundations of Project Management
๐ https://lnkd.in/gJCjD6us
1. IBM Project Manager
๐https://lnkd.in/gTaaHHPQ
3. IBM Data Analyst
๐https://lnkd.in/gMingmB2
4. IBM Data Analytics with Excel and R
๐https://lnkd.in/gejqD9ry
5. IBM Data Science
๐https://lnkd.in/guyY26Ye
6. IBM Data Engineering
๐https://lnkd.in/geFjWDCj
7. IBM AI Engineering
๐https://lnkd.in/gQpHeu7e
3-Learn SQL Basics for Data Science:
๐https://lnkd.in/gKcT3SdP
4-Excel for Business :
๐https://lnkd.in/geHAfHAK
5-Python for Everybody :
๐https://lnkd.in/gUga4caw
6-Data Analysis Visualization Foundations :
๐https://lnkd.in/geWz5T-v
7-Machine Learning Specialization:
๐https://lnkd.in/gCZqk6-J
8-Introduction to Data Science:
๐https://lnkd.in/gK_C8XKy
1. Microsoft Azure Data Scientist Associate
๐ https://lnkd.in/gaX-nhS3
2. Microsoft Cybersecurity Analyst Professional
๐ https://lnkd.in/g_WYd7iw
3. Microsoft Power BI Data Analyst Professional
๐ https://lnkd.in/gi2FQkf7
4. Microsoft Azure Data Engineering Associate (DP-203) Professional
๐ https://lnkd.in/ggUAK2zx
5. Microsoft Azure Developer Associate (AZ-204) Professional
๐ https://lnkd.in/gF99Jh_s
6. Microsoft Azure Security Engineer Associate (AZ-500) Professional
๐ https://lnkd.in/gqgBVvUc
@UndercodeCommunity
Ref: Vikas SinghVikas Singh
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
Google Data Analytics
๐ https://lnkd.in/gv4whkFn
Advanced Google Analytics
๐ https://lnkd.in/gnswTs7t
Google Project Management
๐ https://lnkd.in/geUMD3K9
Foundations of Project Management
๐ https://lnkd.in/gJCjD6us
1. IBM Project Manager
๐https://lnkd.in/gTaaHHPQ
3. IBM Data Analyst
๐https://lnkd.in/gMingmB2
4. IBM Data Analytics with Excel and R
๐https://lnkd.in/gejqD9ry
5. IBM Data Science
๐https://lnkd.in/guyY26Ye
6. IBM Data Engineering
๐https://lnkd.in/geFjWDCj
7. IBM AI Engineering
๐https://lnkd.in/gQpHeu7e
3-Learn SQL Basics for Data Science:
๐https://lnkd.in/gKcT3SdP
4-Excel for Business :
๐https://lnkd.in/geHAfHAK
5-Python for Everybody :
๐https://lnkd.in/gUga4caw
6-Data Analysis Visualization Foundations :
๐https://lnkd.in/geWz5T-v
7-Machine Learning Specialization:
๐https://lnkd.in/gCZqk6-J
8-Introduction to Data Science:
๐https://lnkd.in/gK_C8XKy
1. Microsoft Azure Data Scientist Associate
๐ https://lnkd.in/gaX-nhS3
2. Microsoft Cybersecurity Analyst Professional
๐ https://lnkd.in/g_WYd7iw
3. Microsoft Power BI Data Analyst Professional
๐ https://lnkd.in/gi2FQkf7
4. Microsoft Azure Data Engineering Associate (DP-203) Professional
๐ https://lnkd.in/ggUAK2zx
5. Microsoft Azure Developer Associate (AZ-204) Professional
๐ https://lnkd.in/gF99Jh_s
6. Microsoft Azure Security Engineer Associate (AZ-500) Professional
๐ https://lnkd.in/gqgBVvUc
@UndercodeCommunity
Ref: Vikas SinghVikas Singh
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
lnkd.in
LinkedIn
This link will take you to a page thatโs not on LinkedIn
Forwarded from Exploiting Crew (Pr1vAt3)
๐ฆTop Password Reset Functionality Bugs
๐ก๏ธ
Testing password reset flows is critical to ensuring account security. Hereโs a checklist of common vulnerabilities to watch out for:
No rate limiting
Token leakage
Email manipulation
Self-XSS risks
Brute force reset attempts
Each of these bugs can lead to serious account takeovers (critical vulnerability) if overlooked. What other password reset vulnerabilities have you come across in your tests?
Ref: Amit Kumar
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
๐ก๏ธ
Testing password reset flows is critical to ensuring account security. Hereโs a checklist of common vulnerabilities to watch out for:
No rate limiting
Token leakage
Email manipulation
Self-XSS risks
Brute force reset attempts
Each of these bugs can lead to serious account takeovers (critical vulnerability) if overlooked. What other password reset vulnerabilities have you come across in your tests?
Ref: Amit Kumar
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
๐ฆThis one command is enough to knock down your entire wifi.
-S : Send syn packets
--flood : Sent packets as fast as possible
Simple DOS attack, works really well on non-enterprise networks. Implement firewall/filter rules in your router to avoid these attacks.
However in some cases it can increase resources usage on router that could still lead to crashes.
Ref: Steven Lim
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
-S : Send syn packets
--flood : Sent packets as fast as possible
Simple DOS attack, works really well on non-enterprise networks. Implement firewall/filter rules in your router to avoid these attacks.
However in some cases it can increase resources usage on router that could still lead to crashes.
Ref: Steven Lim
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
Forwarded from Exploiting Crew (Pr1vAt3)
๐ฆTop Shodan Dorks for Finding Sensitive IoT Data ๐
Are you testing IoT devices and systems for vulnerabilities? Shodan, the search engine for internet-connected devices, can reveal critical data with the right queries.
This cheat sheet contains useful Shodan dorks to identify exposed services, misconfigurations, and unsecured devices, such as: โ Open ports: 23 (Telnet), 21 (FTP), 3306 (MySQL)
โ Exposed services: PostgreSQL, MongoDB, Apache, Jenkins, MikroTik
โ Sensitive information: "MongoDB Server Information," "200 OK" responses, and certificate details
Some highlights include:
Finding unprotected remote desktops (port:3389)
Identifying insecure databases (port:27017, MongoDB authentication disabled)
Locating industrial devices and firmware (port:5006,5007 Mitsubishi)
Why does this matter?
IoT devices are often overlooked and can serve as easy targets for attackers if not properly secured. By searching for exposed ports and services, security researchers can help organizations address these risks proactively.
๐ข A friendly reminder: Use this knowledge responsibly. Only test systems you have permission to access!
Ref: AMIT KUMARAMIT KUMAR
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
Are you testing IoT devices and systems for vulnerabilities? Shodan, the search engine for internet-connected devices, can reveal critical data with the right queries.
This cheat sheet contains useful Shodan dorks to identify exposed services, misconfigurations, and unsecured devices, such as: โ Open ports: 23 (Telnet), 21 (FTP), 3306 (MySQL)
โ Exposed services: PostgreSQL, MongoDB, Apache, Jenkins, MikroTik
โ Sensitive information: "MongoDB Server Information," "200 OK" responses, and certificate details
Some highlights include:
Finding unprotected remote desktops (port:3389)
Identifying insecure databases (port:27017, MongoDB authentication disabled)
Locating industrial devices and firmware (port:5006,5007 Mitsubishi)
Why does this matter?
IoT devices are often overlooked and can serve as easy targets for attackers if not properly secured. By searching for exposed ports and services, security researchers can help organizations address these risks proactively.
๐ข A friendly reminder: Use this knowledge responsibly. Only test systems you have permission to access!
Ref: AMIT KUMARAMIT KUMAR
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ