Want a free scholarship pass to Black Hat USA? I have two to offer to the first two eligible students to complete all ten deserialization labs by 2359 UTC Friday
portswigger.net/web-security/d…
Wrote a script in bash this morning to automate the creation of virtual hosts in Apache2. It's fully automated and makes life a lot easier! Feel free to take a look: github.com/SpengeSec/Mult…
Wow, a lot of people asking for the script and asking for mentorship.
Methodology:
1) Identify bug bounty
2) Enumerate sub domains (I use amass, subfinder)
3) Feed those to httpprobe
4) Feed that list to a crawling tool
5) Feed that list to kxss
6) grep output for " (easiest win)
WooT! There is always a way. New #bugbounty#pentest short write up! Chain the bugs till you get what you want. #bugbountytip #bugbountytips #hacking Some steps were not mentionned. RT, Like and Comments are appreciated. For any pentest work DM me:) 🎉🎉
Officially confirmed by Mitre and Centreon.
CVE-2019-19699 affecting Centreon Infrastructure Monitoring Systems =< 19.10.
Found by me and TheCyberGeek.
#SpengeSec#TheCyberGeek#CVE#0day
Want to do some lazy bug bounty hunting today?
Get the ASN of a company by using this (in this case, Tesla):
whois -h whois.cymru.com $(dig +short tesla.com)
Then use the ASN filter in Shodan to scroll through their IP space.
shodan.io/search?query=a…
I just made my "Corsy" public ❤️
It scans for all known misconfigurations in CORS implementations (currently 10+ checks).
Github: github.com/s0md3v/Corsy
0 Followers 172 FollowingRecruiting webshell engineers to penetrate websites, with a monthly salary of up to $100,000. If interested, plea se contact https://t.co/MSn6xm1b8C
562 Followers 1K Followingkachow waz popn infosec weirdos it's yo girl rina back at it again with the FALSE POSITIVES.
DevSec @ ■■■■ - CogSci ∪ Infosec - she/her
#TMHC #FTS
415 Followers 5K FollowingMy scouting totem: Persistent Shoebill / Balaeniceps rex "We cannot change the direction of the wind but we can always adjust our sails" – Unknown
392 Followers 802 FollowingBetter to live real life instead of being #fake
Better to achieve something on your own feets instead of using others and achieving success.
Master of OSINT
24 Followers 73 FollowingInfosec community for noobs and professionals, we focus on helping newbies and rookies in the cybersecurity industry. Our passion is safety... what is yours?
212K Followers 3K FollowingSave your best highlights from Kindle, Twitter, Pocket, Instapaper, iBooks, and 30+ others.
Then revisit, search, organize, and export them seamlessly.
16K Followers 2K FollowingUpdates & Info on the new Reader app by @Readwise
Save, read, and highlight anything -- from articles to PDFs to tweets to newsletters (and much more)
9K Followers 416 FollowingViews are my own and do not reflect my employer.
Retweets are not endorsements.
I'm just sharing interesting things around the world.
392 Followers 802 FollowingBetter to live real life instead of being #fake
Better to achieve something on your own feets instead of using others and achieving success.
Master of OSINT
45K Followers 2K FollowingI will light the way by the bridges I burn.
Retired Senior SANS Instructor
IANS Faculty
Black Hills Information Security
Active Countermeasures
24 Followers 73 FollowingInfosec community for noobs and professionals, we focus on helping newbies and rookies in the cybersecurity industry. Our passion is safety... what is yours?
1K Followers 14 FollowingWe provide realistic, high-quality training labs that allows security students the opportunity to safely learn and practice penetration testing.
56K Followers 3 FollowingOfficial account maintained by the CVE™ Program to notify the community of new CVE IDs. Posts contain abbreviated details. Full CVE Records on https://t.co/ALn4YvUtom
2K Followers 97 FollowingI'm an engineer, Machine Learning hacker and CISSP. Speaker at Black Hat Arsenal, DEFCON Demo Labs/AI Village, PyconJP, CODE BLUE etc., All opinions are my own.