Working on releasing a CommandoWeb, @FireEye tool. This docker container will be filled with all different web testing tools, dependencies, and code that can help you during the different phases of your engagements, bug bounty hunting, AppSec research and more!!
I don't care how advanced you are...
Every once in a while, you need to revisit the fundamentals of your technology knowledge.
Do yourself a favor... enroll in an introductory course with updated materials.
You might be surprised at what you've missed.
@Alra3ees To increase the chances of finding a vulnerability, you should add a step using GoSpider to help spider to application to find more potential endpoints, then a quick find/replace to see {targets}
๐จ๐จThis is your friendly reminder, we (@Mandiant) are looking for a **researcher/threat hunter** to join us
- diving into cool tradecraft
- tracking down big game threat groups
What are you waiting for? ๐Research is a blast! (the team is cool too) https://t.co/pJg3B2sLOb
Found a really interesting reverse proxy vulnerability where the frontend authorization check parsed/validated the integer from the string (123/\?& == 123) then passed the whole argument to the internal API. You could access other people's data via id=YOUR_ID/../VICTIM_ID, and...
The Docker image will contain tools for these separate phases:
Information Gathering
Discovery
Application Configuration
Input Validation
Injection Tools
Bruteforce and fuzzing tools - with corresponding wordlists
Cracking tools such as JTR/Hashcat
Working on releasing a CommandoWeb, @FireEye tool. This docker container will be filled with all different web testing tools, dependencies, and code that can help you during the different phases of your engagements, bug bounty hunting, AppSec research and more!!
This container aims to have all of the sufficient tools and wordlists without research, dependency issues, installation, and have a successful web app engagement.