Web Security | Bug hunting
@cybersecurityresources
7.18K
subscribers
46
photos
2
files
473
links
A web penetration testing / General cybersecurity / Network related topics channel that provides direct links for interesting resources and notes.
Download Telegram
Join
Web Security | Bug hunting
7.18K subscribers
Web Security | Bug hunting
https://medium.com/@ar_arvind/facebook-bug-bounty-reading-whatsapp-contacts-list-without-unlocking-the-device-a40e9c660a42
Medium
WhatsApp Bug Bounty: Reading contacts list without unlocking the device
A bug allows anyone who has the victim’s phone to read all their contact list without unlocking the security lock
Web Security | Bug hunting
https://medium.com/@valeriyshevchenko/jenkins-rce-poc-or-simple-pre-auth-remote-code-execution-on-the-server-d18b868a77cb
Medium
Jenkins RCE PoC or simple pre-auth remote code execution on the Server.
Once upon a time, a friend of mine asked me a question — "Do you know any fresh RCE for the Jenkins environment ?". I was informed already…
Web Security | Bug hunting
https://brutelogic.com.br/blog/xss-via-http-headers/
Web Security | Bug hunting
https://medium.com/@osamaavvan/json-csrf-to-formdata-attack-eb65272376a2
Medium
JSON CSRF To FormData Attack
So you guys must be aware of CSRF attack, if not then here is a short intro:
Web Security | Bug hunting
https://jivoi.github.io/2015/08/21/pentest-tips-and-tricks-number-2/
EK
Pentest Tips and Tricks #2
Pentest Handy Tips and Tricks - part 2.
Web Security | Bug hunting
https://andripwn.github.io/Labs/XSS/
Web Security | Bug hunting
https://github.com/ebertti/awesome-telegram
GitHub
GitHub - ebertti/awesome-telegram: Collection great groups, channels, bots and libraries for Telegram
Collection great groups, channels, bots and libraries for Telegram - ebertti/awesome-telegram
Web Security | Bug hunting
https://pastebin.com/SkTLFQ4N
Pastebin
Ehtools Framework Installation - Pastebin.com
Pastebin.com is the number one paste tool since 2002. Pastebin is a website where you can store text online for a set period of time.
Web Security | Bug hunting
https://githacktools.blogspot.com/2019/01/avet-antivirus-evasion-tool.html
Web Security | Bug hunting
https://medium.com/@danangtriatmaja/bug-bounty-self-xss-clickjacking-good-xss-tokopedia-8df7a65e0955
Medium
[ BUG BOUNTY ] Self XSS + ClickJacking = Good XSS | Tokopedia
Hi sobat, bagaimana kabarnya ? semoga senantiasa sehat selalu dan diberikan kelancaran dalam aktifitasnya. ^-^
Web Security | Bug hunting
https://medium.com/@pratiky054/graphql-bug-to-steal-anyones-address-fc34f0374417
Medium
Graphql Abuse to Steal Anyone’s Address
Introduction
Web Security | Bug hunting
https://twitter.com/nullenc0de/status/1169307702692069376
Twitter
Paul Seekamp
How I got Domain Admin today. Relay creds>SAM dump>PTH> read cleartxt 1) cme smb <CIDR> --gen-relay-list smbrelay.txt 2) ntlmrelayx.py -tf smbrelay.txt 3) Wait for admin hash (500) 4) cme smb <CIDR> -u username -H NTHASH --lsa 5) cat /root/.cme/logs/*.secrets…
Web Security | Bug hunting
https://medium.com/@tarekmohamed_20773/add-new-user-with-admin-permission-and-takeover-the-organization-6318ee10154a
Medium
Add new user with Admin permission and takeover the organization
Taregt : redacted.com
Web Security | Bug hunting
https://github.com/hisxo/gitGraber
GitHub
GitHub - hisxo/gitGraber: gitGraber: monitor GitHub to search and find sensitive data in real time for different online services…
gitGraber: monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github, Mailgun, Facebook, Twitter, Heroku, Stripe... - hisxo...
Web Security | Bug hunting
https://blog.usejournal.com/graphql-bug-to-steal-anyones-address-fc34f0374417
Medium
Graphql Abuse to Steal Anyone’s Address
Introduction
Web Security | Bug hunting
https://medium.com/@saadahmedx/complete-web-server-access-46d19279a2b
Medium
Complete Web Server Access
Hi guy I am back with another POC that I found in PRIVATE program on bugcrowd let get started. So let assume the SITE name private.com I…
Web Security | Bug hunting
https://medium.com/@cc1h2e1/write-up-of-two-http-requests-smuggling-ff211656fe7d
Medium
Write up of two HTTP Requests Smuggling
This article about how I found two sites for HTTP Request Smuugling
Web Security | Bug hunting
https://medium.com/@heinthantzin/how-does-my-recon-win-250-in-15-minutes-a1992508b911
Medium
How does my recon win $250 in 15 minutes
Hi there again,
Web Security | Bug hunting
https://medium.com/@jayateerthag/google-referer-leak-bug-434f6293ce66
Medium
GOOGLE REFERER LEAK BUG
I followed the usual Recon process after enumerating subdomains ,
Web Security | Bug hunting
http://tweetedtimes.com/v/1939
Web Security | Bug hunting
cyberscurity books :
https://mega.nz/#F!oawFzJiI!nYW_l4i1a61QtyuS18GnnA
mega.nz
MEGA provides free cloud storage with convenient and powerful always-on privacy. Claim your free 20GB now
TWeb.init({scrollToPost:'cybersecurityresources/155'});