HackerOne
@HackerOne
11K
subscribers
644
photos
31
videos
79
files
2.74K
links
Community :
@Sec0x01
@Bug0x
Download Telegram
Join
HackerOne
11K subscribers
HackerOne
https://gist.github.com/PaulSec/0f5faff83246b37fe9d3d5a2f5fc9fe0
Gist
Small noscript to bypass AV that triggers Invoke-Mimikatz with shitty rules
Small noscript to bypass AV that triggers Invoke-Mimikatz with shitty rules - invoke_evasion.sh
HackerOne
HackerOne
HackerOne
https://github.com/Warflop/Whoisleak
GitHub
Warflop/Whoisleak
This tool queries the emails that registered the domain and verifies if they were leaked in some data leak. - Warflop/Whoisleak
HackerOne
https://github.com/dark-lbp/isf
GitHub
GitHub - dark-lbp/isf: ISF(Industrial Control System Exploitation Framework),a exploitation framework based on Python
ISF(Industrial Control System Exploitation Framework),a exploitation framework based on Python - dark-lbp/isf
HackerOne
HackerOne
https://blog.malwarebytes.com/security-world/2018/04/malwarebytes-crackme-2-another-challenge/
Malwarebytes Labs
Malwarebytes CrackMe 2: try another challenge
Last November, we launched the first Malwarebytes CrackMe. Encouraged by an overwhelmingly positive response, we decided to repeat the game—this time making it even harder and more fun.
HackerOne
Write up
👆
https://secrary.com/CrackMe/hasherezadeCrackme2/
secrary[dot]com::blog
Malwarebytes CrackMe 2 by hasherazade
https://secrary.com - Does it matter?
HackerOne
https://medium.com/@y.shahinzadeh/nodejs-application-pentest-tips-improper-uri-handling-in-express-390b3a07cb3e
Medium
NodeJS Application Pentest Tips - Improper URI Handling in Express
Web application penetration test methodologies have many concepts/tests in common. However, each language and infrastructure has its own…
HackerOne
https://medium.com/@the.bilal.rizwan/wordpress-xmlrpc-php-common-vulnerabilites-how-to-exploit-them-d8d3c8600b32
Medium
Wordpress xmlrpc.php -common vulnerabilites & how to exploit them
Hello there! , whats up ? ,Bilal Rizwan here hope your doing great & having fun learning from the community like I am.
HackerOne
https://github.com/sc0tfree/mentalist/blob/master/README.md
GitHub
mentalist/README.md at master · sc0tfree/mentalist
Mentalist is a graphical tool for custom wordlist generation. It utilizes common human paradigms for constructing passwords and can output the full wordlist as well as rules compatible with Hashcat...
HackerOne
HackerOne
https://github.com/hausec/ADAPE-Script
GitHub
GitHub - hausec/ADAPE-Script: Active Directory Assessment and Privilege Escalation Script
Active Directory Assessment and Privilege Escalation Script - hausec/ADAPE-Script
HackerOne
Forwarded from
Bug Bounty
(
Amir Offensive
)
http://zhchbin.github.io/2017/08/30/Uber-XSS-via-Cookie/
zhchbin
[BBP系列二] Uber XSS via Cookie
This write up is about part of my latest XSS report to Uber@hackerone. Sorry for my poor English first of all, I will try my best to explain this XSS problem throughly. JSONP RequestSeveral months ago
HackerOne
HackerOne
HackerOne
HackerOne
https://security.szurek.pl/gitbucket-unauthenticated-rce.html
HackerOne
https://www.youtube.com/watch?v=PKIdGnx1KIg
YouTube
[PL] Jak działa exploit zdalnego wykonania kodu (RCE) w GitBucket
Jeśli jesteś programistą i chcesz zobaczyć jak proste błędy w kodzie mogą prowadzić do zdalnego wykonania kodu na serwerze to ten film jest dla Ciebie. Tłuma...
HackerOne
https://github.com/rpranshu/EternalView
GitHub
GitHub - rpranshu/EternalView: EternalView is an all in one basic information gathering and vulnerability assessment tool
EternalView is an all in one basic information gathering and vulnerability assessment tool - rpranshu/EternalView
HackerOne
https://getstream.io/blog/winds-2-0-its-time-to-revive-rss/
getstream.io
Winds 2.0: It’s Time to Revive RSS - The Stream Blog
I love using RSS to follow the programming and tech news I care about. Unfortunately, t…
TWeb.init({scrollToPost:'HackerOne/1943'});