We published an open-sourced log4j-scanner derived from scanners created by other members of the open-source community. This tool is intended to help organizations identify potentially vulnerable web services affected by the log4j vulnerabilities: https://t.co/af8uszW8K4
I was going to do a thread on how to get started in bug bounty and hacking, but realized @0xAshFox and I put in a lot of work to make this repo happen. https://t.co/AkG6IihgCN
I think it's time for an update though. Any suggestions?
Detect if it's a Windows or Linux system through a single command after achieving RCE:
echo windowste^st linuxte$st
Windows will print: windowstest linuxte$st
Linux will print: windowste^st linuxtest
Artificial inflation of page popularity through the posing of inane questions that in turn artificially inflate the respondents’ sense of intelligence thus gaining massive levels of engagement as otherwise smart people fall for that one simple trick give me the shits 💩
Exactly something look for to get started with web pentesting learning. Kudos!!! To every beginner out there, feel like a best way to start out.
Thanks @stokfredrik
DON'T BUY MY HOW TO GET STARTED IN BUG BOUNTY COURSE! - Do these 500+ FREE exercises instead!
https://t.co/zU6AxACgQ2
No I don't have a course, but massive shoutout to @PortSwigger@tryhackme@CTFchallenge@Hacker0x01@intigriti and more, for their awesome free stuff!
Burp Suite > Proxy > Options > TLS Pass Through.
Add these:
.*\.google\.com
.*\.gstatic\.com
.*\.mozilla\.com
.*\.googleapis\.com
.*\.pki\.goog
No more noise in your logs! #bugbountytips
Recent security concerns around WhatsApp made you switch to Signal/Telegram? Remember Zoom at the start of the pandemic? Hackers gravitate to popular technologies & look for ways to exploit it. Be cautious/stay skeptical. Nothing in the news about it, just stay vigilant.