Another long (hacker) story thread 🧵
= Stealing checks worth millions & pwning a bank =
Here’s how I did it, so you can learn.
I was once contracted to do a penetration test on a bank…
Like, retweet, and follow for more hacker stories!
(1/x)
Easy way to find blind xss via Femida.
I have forked the repo and edited the files.
Just add your blind xss domain on payloads.txt and load the extension.
Add your scope and run spiders of gospiders then click Femida run proxy.
https://t.co/q2O62QTTv1
Thanks @hd_421@wish_iwas
HTML smuggling explained
'...will explain how a few lines of JavaScript have big impact on perimeter security.'
#infosec#pentest#redteam
https://t.co/DzhLLBsoeg
One way to find out the variations of passwords a person uses by email.
1. Go to https://t.co/bLqzpPu5ch (search in leaks)
2. Type in an email search
3. Copy the SHA-1 Hash of the password found.
4. Search for it in the database of decrypted hashes https://t.co/XUgKkr3V2n
#osint
List 1462 of tools for #osint from @andyblacz (Andy Black Associates)
Lots of basic resources for beginners, lots of tools to optimize your workflow. Some of it is outdated, but there is still a lot of useful stuff on the list.
https://t.co/Z8O867lBUs
#osint#socmint#geoint
Gopherus
If you know a place which is SSRF vulnerable then, this tool will help you to generate Gopher payload for exploiting SSRF to gain RCE
#infosec#pentest#bugbountytip
https://t.co/K51125CoN6