π₯ Top 7 Nmap Hacks Every Cybersecurity Pro Should Know
Nmap isnβt just a port scanner - itβs a powerful recon tool that can uncover vulnerabilities, detect firewalls, and even evade security defenses.
Here are 7 Nmap hacks to level up your security game. π§΅
The number of Kenyan workers earning Sh50,000 to Sh100,000 monthly increased by 62,778 to 1,426,245 last year, according to KNBS.
Of the new 62,778 workers, 4,609 were men and 58,171 were women
Sites for CTF practice and Latest CVEsπ»βοΈ
Bandit - Aimed at absolute beginners and teaches the basics of remote server access.
https://t.co/BjS4x869dH
Natas - Teaches the basics of serverside web-security.
https://t.co/K7iMbWgIKU
Post Exploitation Basics - Learn the basics of post-exploitation and maintaining access with mimikatz, bloodhound, powerview and msfvenom.
https://t.co/aS4RjS1t7W
Smag Grotto - An obsecure boot to root machine.
https://t.co/zHTZJq927P
Dogcat - I made a website where you can look at pictures of dogs and/or cats! Exploit a PHP application via LFI and break out of a docker container.
https://t.co/cMEhtDQCBN
Buffer Overflow Prep - Practice stack-based buffer overflows.
https://t.co/EOZK8VCDSB
Break out the cage - Help Cage bring back his acting career and investigate the nefarious going on of his agent.
https://t.co/BB0k6cfnHI
Lian Yu - A beginner-level security challenge.
Insecure Kubernetes - Exploiting Kubernetes by leveraging a Grafana LFI vulnerability.
https://t.co/hqpShiZhwq
The Great Escape (docker) - Escaping docker container.
https://t.co/ghNGlJbUuO
Solr Exploiting Log4j - Explore CVE-2021-44228, a vulnerability in log4j affecting almost all software under the sun.
https://t.co/oHHSwUh7QP
Spring4Shell - Interactive lab for exploiting Spring4Shell (CVE-2022-22965) in the Java Spring Framework.
https://t.co/8GlFTMqwMd
Most Recent threats - Learn about the latest industry threats. Get hands-on experience identifying, exploiting, and mitigating critical vulnerabilities.
https://t.co/YNlSMGiFPg
Many people know SSH is encrypted, but this doesnβt mean using a password with it is safe.
The encryption only protects a password in transit from an eavesdropper. It does not protect your password if the remote system is compromised. It can be saved off in cleartext.
Loan Apps
I once performed forensics on a mobile device and a loan app on his phone had an exclusive permission.
Anytime you download a loan app, you give them access to your phone after you tick or agree to their the terms & conditions. This tells you that theyβll backdoor your phone and get access to your contacts. Thatβs how they reach your contacts and be sending your pictures to them if fail to repay the loan.
After disabling contact permission on your mobile device, online loan companies should no longer have access to your contacts. Disabling contact permission restricts the app's ability to access and use your contact list. However, it's important to note that any contacts that were previously stored in the loan company's database may still be retained by them.
If you are unsure of the Cybersecurity career path you want to focus on, go to youtube and search for βA day in the life seriesβ. E.g A day in the life of a GRC Specialist, Ethical Hacker, DevSecOps Engineer, Cloud Security specialist etc.
β οΈ Attention, Sysadmins! A newly discovered critical #vulnerability (CVE-2024-21410) in #Microsoft Exchange Server is currently being actively exploited.
Details here β https://t.co/5M0IxD6eTX
Attackers can hijack user accounts & gain admin-level control. Update ASAP!