@sec_hub93028 One of the question that I usually asked to candidates. How many cookies are usually allowed for a single domain that a web developer can store in a modern browser? The answer can be in a range
@sec_hub93028 Keep an eye on DNS traffic patterns. High volumes of requests from single sources. Also, Track DNS query rates and flag sudden spikes. For the mitigation, I can think of using DNSSEC implementation to verify DNS responses
@sudoxSATYA I usually start with whoami /all following to the list of app and if something running internally. If nothing works out than vulnerable services..just keep digging until get the SYSTEM shell.
Running nmap scan and if you notice `clock-skew: 10s` in the host script result, it means that your clock is 10 seconds off from the host machine. Interesting #Nmap Fact.
@LenovoCanada You guys don't know how to design a keyboard for Thinkpad. Who gives the PhDn button right next to right key. Its been months and I still mistype keys
Flight HTB Pawned. What a box it was...Trust the process and methodologies when performing Priv Esc. #OffSec#OSCP#hackthebox#htb#PenTesting
https://t.co/X6PXJrTuG5