Hi @TeamYouTube@YouTubeIndia Recently, my video "How to use John The Ripper" reached 50k views, but was unexpectedly taken down for violating guidelines 😢 It's disheartening as other similar videos exist for years without any issues.
Please help!!!
A few days ago I had something to celebrate, I wanted to share with my friends though which is why all the challenges over the past days... to round off this drop party
250 x CNWPP course material [CERT SOLD SEPERATLY!] For freeeeeeeee
https://t.co/d5mAwib8mz
50 CWE's every ethical hacker should know, which ones did I miss? Add your own in the comments!
https://t.co/3WTZpag52d
CWE-20: Improper Input Validation
CWE-22: Path Traversal
CWE-77: Command Injection
CWE-78: OS Command Injection
CWE-79: Cross-site Scripting (XSS)
CWE-80: Basic XSS
CWE-89: SQL Injection
CWE-90: LDAP Injection
CWE-94: Code Injection
CWE-99: HTTP Response Splitting
CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers
CWE-120: Buffer Copy without Checking Size of Input
CWE-126: Buffer Overread
CWE-131: Incorrect Calculation of Buffer Size
CWE-134: Uncontrolled Format String
CWE-190: Integer Overflow or Wraparound
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CWE-209: Information Exposure Through an Error Message
CWE-213: Intentional Information Exposure
CWE-215: Information Exposure Through Debug Information
CWE-235: Improper Handling of Extra Parameters
CWE-250: Execution with Unnecessary Privileges
CWE-284: Improper Access Control
CWE-306: Missing Authentication for Critical Function
CWE-307: Improper Restriction of Excessive Authentication Attempts
CWE-311: Missing Encryption of Sensitive Data
CWE-312: Cleartext Storage of Sensitive Information
CWE-319: Cleartext Transmission of Sensitive Information
CWE-352: Cross-Site Request Forgery (CSRF)
CWE-362: Race Condition
CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
CWE-384: Session Fixation
CWE-400: Uncontrolled Resource Consumption
CWE-416: Use After Free
CWE-426: Untrusted Search Path
CWE-434: Unrestricted Upload of File with Dangerous Type
CWE-472: External Control of Assumed-Immutable Web Parameter
CWE-476: NULL Pointer Dereference
CWE-494: Download of Code Without Integrity Check
CWE-502: Deserialization of Untrusted Data
CWE-521: Weak Password Requirements
CWE-522: Insufficiently Protected Credentials
CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
CWE-611: Improper Restriction of XML External Entity Reference (XXE)
CWE-614: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
CWE-732: Incorrect Permission Assignment for Critical Resource
CWE-759: Use of a One-Way Hash without a Salt
CWE-798: Use of Hard-coded Credentials
CWE-807: Reliance on Untrusted Inputs in a Security Decision
CWE-918: Server-Side Request Forgery (SSRF)
Took a long time but managed to put up all of my notes I created for the OSCP Exam: https://t.co/ezpxaxLGee
These aren't really the lab notes, this is a curated gist of everything I learnt throughout the journey of preparation and didn't want to lose.
#oscp#infosec
Giveaway time!
We are going to send a t-shirt and few goodies to one person who follows @PentesterLab and likes this tweet !!
And we are going to give a 1-year voucher to someone who RT this tweet!
Giveaway time!
We are going to send a t-shirt and few goodies to one person who follows @PentesterLab and likes this tweet !!
And we are going to give a 1-year voucher to someone who RT this tweet!
Giveaway time!
We are going to send a t-shirt and few goodies to one person who follows
@PentesterLab
and likes this tweet !!
And we are going to give a 1-year voucher to someone who RT this tweet!
My OSCP is scheduled for next Friday. So far I have done:
189 rooms on THM
118 flags on HTB
39 machine on PWK
37 boxes from @rana__khalil blog
10 of the OSCP labs by @TJ_Null
windows and linux privesc courses from @0xTib3rius
What else do you recommend to prepare? #offsec
Thank you so much @0xAadi for the one month subscription voucher of @tryhackme . 😄😄✌️
This voucher will help @anurag_sourav more, so I decided to give it to him.😄
I hope you will utilize it well.✌️
Thanks, @0xAadi😁
@parasarora06@tryhackme I was in my first year of college (Btech cybersecurity)when, i learnt about this from my friend, that time i didn't know much about cybersecurity. After a month i became regular in solving challenges of different rooms. And after a year of learning i qualified eJPT and then CEH.
5th Giveaway Alert 🔥
I'm giving away a 1-month @tryhackme subscription
To Enter in the Giveaway:
1. Retweet
2. Share your story of how you got started in infosec
The winner will be selected at the end of this month
#infosecurity#Giveaway#tryhackme#bugbounty#Learn
A small gift from my side to all bug bounty hunters.
My 8 hour long burp suite focused course for free.
(one lucky person who RT will get #IWCON2022 ticket )
#bugbountytips#bugbounty#infosec
(rt & share + enjoy)
https://t.co/U0ezdf8KOs
@tryhackme It's been a year since i have been doing rooms on @tryhackme and yet i learn new things on every new room i do.
And it has helped me to start my career in cyber security, and clear eJPT and CEH practical.