Here are a few thoughts about #RockYou2024(2021) while the hype train is running to the station "Everyone hack3d" with a stop at "why it's useless". Obviously, most compilations suffer from the garbage inside, and it's always better to know how the wordlist was crafted.
The ability to look at the entirety of a situation to see the bigger picture is critical, especially for application security.
What's the point of audits if all the vulnerabilities found remain in 50-page pentester reports or ci/cd Pipeline artifacts?
https://t.co/eWfS1havU2
Полевой набор пентестера
Ребята из Digital Security рассказывают о составе типового полевого набора, который пентестеры берут с собой, выезжая для проведения анализа беспроводных сетей или проектов в формате Red Team: https://t.co/w8L08LJWei
@hakluke Informative weaknesses mentioned in report is not making it less stronger. Just do it in a proper way! That's why we have an optional "weakness" flag for every finding reported. So it is pretty simple to separate them to different report sections with no info trash in main parts.
@hakluke Informative weaknesses mentioned in report is not making it less stronger. Just do it in a proper way! That's why we have an optional "weakness" flag for every finding reported. So it is pretty simple to separate them to different report sections with no info trash in main parts.
Hey everyone! I just launched a yet-another-new-free- project for subdomain discovery with online tools, screenshots, and automation. So it's time to have a look!
#pentest#bugbounty
Another enterprise WPA2 implementation flaw: subject name (hostname) of the server was checked using the substring function instead of doing an exact compare.
Here is a first draft on an NTLM relay mindmap 🙂 from authentication coercion to post-relay exploitation. I'll gladly update/correct it if you think there are things wrong or missing.
➡️Featured on The Hacker Recipes https://t.co/0y4cOkMcTb