Just dropped a new article on Medium.
Real-life blind XXE exploitation by outputting results via Java exceptions in log files. Check it out for the details.
https://t.co/nk9G3rNrqO
In the world of penetration testing, we often encounter fully restricted machines in our target network.
In my latest Medium article, I've sheared a simple method that I use to set up a reverse SSH proxy.
🔗Find my article here: https://t.co/KdtFCDRr0J
🛠️ SocketSleuth extension aims to enhance Burp Suite's websocket testing capabilities and make testing websocket based applications easier.
#BurpSuite#BugBounty
https://t.co/L4g2eHma3g
❓Interested what is behind those long #Python SSTI payloads?
Here is my small article on basics of Jinja template injection💉.
https://t.co/dqW4OB8PYu
#BugBounty#Pentesting#Hacking
🤖🧹Using a robot vacuum cleaner at home?
Besides regular pentesting, a cybergeek should spend his spare time having some fun. Threfore, I've explored if my robot vacuum could do more than just tidying up.
Read all about it here: https://t.co/iJtngIOAIE
🪟 Facing IIS default page?
Try short filename enum.
⚒️This is an old tool and the code is a spaghetti, but it is capable to tackle even the latest IIS (IIS 10 on Windows Server 2022)
https://t.co/YQXaYBij18
#Pentesting#BugBounty#Hacking
🔥This repository contains a Python script that allows bug bounty hunters and security researchers to collect all Nuclei YAML templates from various public repositories.
https://t.co/9xrjyNSgth
#BugBounty#Pentesting
Best tools for decompiling and rebuilding .NET binaries.
DotPeek https://t.co/qPPjSvSOIk
ILSpy https://t.co/HoditVj0eZ
DnSpy https://t.co/iReTo5mO5Y
Share with me, if you know some handy tools.
#security#assesment#pentest
Wow, I am not a #BlueTeam, though seeing these tools making me interested.
🔥The Open Source Security Platform. Unified XDR and #SIEM protection for endpoints and cloud workloads.🔥
Check @NetworkChuck video to get an overview:
https://t.co/OrtpKM8gJ5
https://t.co/iO4PqfTFRV
Pycript enables users to encrypt and decrypt requests and response for manual and automated application penetration testing.
#Portswigger#BurpSuite#BugBounty#Pentesting
https://t.co/ICDaORdjqX
🔥DOM clobbering cheatsheet by @0xTib3rius
DOM clobbering is a technique in which you inject HTML into a page to manipulate the DOM and ultimately change the behavior of JavaScript on the page.
https://t.co/v8JTKiq53C