Hacking Articles – Telegram
Hacking Articles
12.9K subscribers
680 photos
133 files
437 links
House of Pentester
Download Telegram
🚨 Master CTF & OSCP+ Exams — Real-World Challenges, Real-World Exploits.

🧠 Practical attack paths. 💻 Hands-on labs. 🎯 Exam-ready hacking skills.

🔗 Register Now → https://forms.gle/bowpX9TGEs41GDG99
📲 Chat on WhatsApp → https://wa.me/message/HIOPPNENLOX6F1
💥 Only ₹41,000 / $495 – Limited Seats

Why Join?

⦁ Practice privilege escalation (Windows & Linux), tunneling & pivoting
⦁ Master web application, AD, and client-side attacks
⦁ Solve real-world vulnerabilities with public exploits
⦁ Live CTF-style labs & exam-focused preparation
⦁ Bonus: Professional reporting techniques & post-exploit tips

🎓 Perfect For:
✔️ OSCP / OSEP / CRTP / CRTO aspirants
✔️ Red Teamers practicing CTF scenarios
✔️ Pentesters sharpening post-exploitation skills
✔️ Ethical hackers preparing for real-world assessments

💡 Not just another CTF practice.
This is hands-on attack simulation, built by hackers who solve these challenges daily.

📧 info@ignitetechnologies.in
🌐 www.ignitetechnologies.in
3
Containers Attacks
6
AWS Security
2
AWS S3 Attack & Defend
3
AWS EC2 Attack and Defend
1
Docker Architecture
1
CLI Tools for Linux Admin
1
🚀 AI Penetration Training (Online) – Register Now! 🚀

🔗 Register here: https://forms.gle/bowpX9TGEs41GDG99
💬 WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

📧 Email: info@ignitetechnologies.in

Limited slots available! Hurry up to secure your spot in this exclusive training program offered by Ignite Technologies.

🧠 LLM Architecture
🔐 LLM Security Principles
🗄️ Data Security in AI Systems
🛡️ Model Security
🏗️ Infrastructure Security
📜 OWASP Top 10 for LLMs
⚙️ LLM Installation and Deployment
📡 Model Context Protocol (MCP)
🚀 Publishing Your Model Using Ollama
🔍 Introduction to Retrieval-Augmented Generation (RAG)
🌐 Making Your AI Application Public
📊 Types of Enumeration Using AI
🎯 Prompt Injection Attacks
🐞 Exploiting LLM APIs: Real-World Bug Scenarios
🔑 Password Leakage via AI Models
🎭 Indirect Prompt Injection Techniques
⚠️ Misconfigurations in LLM Deployments
👑 Exploitation of LLM APIs with Excessive Privileges
📝 Content Manipulation in LLM Outputs
📤 Data Extraction Attacks on LLMs
🔒 Securing AI Systems
🧾 System Prompts and Their Security Implications
🤖 Automated Penetration Testing with AI
2
Grep Cheat Sheet for Sysadmin
2
IP Command Cheat sheet
1
1
Comprehensive Guide on Cross-Site Scripting (XSS)

Twitter: https://lnkd.in/e7yRpDpY
🔥 Telegram: https://news.1rj.ru/str/hackinarticles

In this article, we’ll take a tour to Cross–Site Scripting and would learn how an attacker executes malicious JavaScript codes over at the input parameters and generates such pop-ups, in order to deface the web-application or to hijack the active user’s session.

📘 What is JavaScript?
🎯 JavaScript Event Handlers
💥 Introduction to Cross-Site Scripting (XSS)
⚠️ Impact of Cross-Site Scripting

🧬 Types of XSS
🔁 Reflected XSS
💾 Stored XSS
🧩 OM-based XSS

🎯 Cross-Site Scripting Exploitation
🔐 Credential Capturing
🍪 Cookie Capture
🧪 Fuzzing
  🧰 Burp Suite
  🕷️ XSSer

🛡️ Mitigation Steps
API Penetration Testing Training (Online)

🔗 Register here: https://forms.gle/bowpX9TGEs41GDG99
💬 WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

📧 Email: info@ignitetechnologies.in

Hurry up, get enrolled yourself with Ignite Technologies’ fully exclusive Training Program "API Penetration Testing Training."

✔️ Table of Content

📘 Course Introduction
🔍 How API works with Web application
⚖️ Types of APIs and their advantages/disadvantages
🔎 Analysing HTTP request and response headers
🛡️ API Hacking methodologies
📄 Enumerate web pages and analyse functionalities
🕵️ API passive reconnaissance Strategies
🚀 API active reconnaissance (Kite runner)
🔧 Introduction to POSTMAN
🔍 Testing for Excessive data exposure
📂 Directory indexing / brute force
🔑 Password mutation
🎯 Password spray attacks against web application
🛡️ Introduction to JSON Web Token
🕵️ Hunting for JWT authentication vulnerabilities
💣 Exploiting JWT unverified signature
🔓 Cracking JWT secret keys
🚫 Bypass JWT removing signature
💉 Exploit jku header injection
🔧 Exploit KID in JSON web tokens
🔐 Attacking 0Auth 2.0
📊 Introduction to OWASP TOP 10 API
⚔️ Hunting and exploiting XXS in API
🕵️ Testing for the ReDOS attack in the API web application
💥 Exploiting XML vulnerabilities
🔧 WordPress XML-RPC attack
🌐 Exploiting WSDL/SOAP to RFI
🤖 API Automated Vulnerability scanning
💉 Testing SQL/NoSQL Injection in an API
🔓 Exploiting object-level access control
🔧 Exploiting Function level access control
📡 Testing in-band SSRF vulnerabilities in an API
🌍 Testing out-band SSRF vulnerabilities in an API
⚙️ Testing OS Command Injection
Exploiting Java deserialization vulnerabilities
🗂️ Testing for improper assets management
📦 Testing for Mass assignment vulnerabilities
🚧 Bypass filter, space, and blacklisted characters
🔐 Bypass Captcha and MFA
📋 Remediations and Reporting
1