Thread 🧵:📷 Here is how I Do my Recon fast automated bug bounty
1) we are not using any kind of paid service to do automation 🔥
2) We use https://t.co/I9Ctoaphzp for hacking open terminal
#infosec#bugbountytips#Hacking#cybersecurity
⚙️ Zydra
Zydra es una herramienta de recuperación de contraseñas de archivos. Utiliza la búsqueda por diccionario o el método de fuerza bruta para descifrar contraseñas.
Archivos soportados:
▶️ RAR
▶️ ZIP
▶️ PDF
https://t.co/MlJyefMf5i
Awesome Cyber
List of #cybersecurity related tools from @landoncrabtree:
Operating Systems
Defense Evasion
OSINT
Reconaissance
Social Engineering
Leaked Credentials
Web Exploitation
Reverse Engineering
Malware Analysis
Hardening
CTF stuff
and more.
https://t.co/Its5ATtRiN
BHTikTok Plus updated to v2.2.1
This update contains only small bugfixes (thanks to @Contiinent for bug report)
Another update will come later. Thanks for patience ❤
Tweaks and IPA available at the link below:
https://t.co/ZVqIcB0zLE
GitHub - IvanGlinkin/Fast-Google-Dorks-Scan: The OSINT project, the main idea of which is to collect all the possible Google dorks search combinations and to find the information about the specific web-site: common admin panels, https://t.co/xAddZGFROu
Alert ⚠️
vm2, a widely used Node.js library, has severe security flaws (CVSS 9.8/10) allowing attackers to escape sandboxes and run malicious code.
Project is discontinued. DO NOT use in production apps.
Check PoCs by @0x10n
1. https://t.co/gv4S9VqxUg
2. https://t.co/rUAJ1sslGQ
💻 What to look for on a site with IIS?
1. Use shortscan to search for short (and possibly full) filenames and extensions.
- shortscan : - https://t.co/g2EIuBES1T
2. Check for reverse proxy and try directory traversal:
/backend/ -> 10.0.0.1/api/
/backend/..%2Ftest -> 10.0.0.1/test
- You can read more here :- https://t.co/SGoeW63Rjc
3. When we can get the file expansion, we look at the keys in web.conf and try to get the RCE through deserialization.
- Read about it here :- https://t.co/RjxwZs9GKK
4. Trying to load files .asp , .aspx , .ashx and so on
- Full list here :- https://t.co/2CEhDWrUNj
👀 Check Out Old Tweets Of @TodayCyberNews
#CyberSecurity #bugbountytips #BugBounty #infosec #iis #rce
Quick introduction for beginners to Trusted Execution Environment (TEE) heap exploitation (BGET used by OP-TEE)
Credits @phi1010
https://t.co/vPieHtIUH5
#tee#cybersecurity
If you know any:
▪ Cybersecurity professional
▪ SOC analyst
that's looking to belt another certification.
This $130 USD Splunk Certified Cybersecurity Defense Certification is currently FREE and it won't be for long.
Exam details:
Level: Intermediate
Prerequisites: None
Length: 75 minutes*
Format: 60 multiple choice questions*
You can check out other details here:
https://t.co/HQS6zOi6lY
GitHub - gosom/google-maps-scraper: This is a scraper written in Go that allows you to extract data from Google Map. It automates web browsing and extracts data such as the name, address, phone number, website URL, rating, reviews number, latitude and https://t.co/E9W6HS2Gc4