white2hack 📚 – Telegram
white2hack 📚
12.4K subscribers
4.8K photos
135 videos
1.96K files
2.26K links
Кибербез. Книги, гайды, how to, ликбез. Аналитика, тренды, карьера, эвенты. Этичный хакинг и защита своих данных

🔊 Связь @w2hack_feed_bot
💬 Чат https://news.1rj.ru/str/+VdkEIWudTi5m3dsA
💡 Консультация https://forms.gle/iB9iX3BwyxJM4Ktx5
🏛 Обмен -- private --
Download Telegram
Social Engineering Attacks: Creating a Fake SMS Message

SMS messages or commonly referred to as text messages is a protocol originally developed in the 1980-1980s and first implemented on the European mobile standard GSM in the 1990-1990s has since been implemented into nearly every mobile communication protocol. It allows the users to send a short message (SMS is an acronym for short message service) of less than 160 characters from one person to another over the mobile network. It has become a ubiquitous feature of mobile communication in the 21st century.

Let’s take a look at how you can send fake SMS messages.

GitHub
Article

#hacktools
👍5
Get account takeover via IDOR form JWT

Today I’m gonna explain how I got IDOR and exploit it to make account takeover.

Source

#web #AppSec
👍2🔥2
How does a Combination Lock work_Gif.gif
14.9 MB
UP-SOLVING Combination Lock

I'm gonna explaining how i solved the Combination Lock problem solving

Source
YouTube

#useful #fun
🔥2🤔1
Media is too big
VIEW IN TELEGRAM
How does a Combination Lock work

#fun
😁4👍1
Bypassing 403s like a PRO! ($2,100): Broken Access control

This article highlights my way of dealing with 403s and how I managed to get a P1 in minutes!

Source
403 Bypasser Burp extension

#web
👍2🔥2
Facebook bug: A Journey from Code Execution to S3 Data Leak

A Tale of Two Threats: OS Command Injection and Data Leak in Meta’s (formerly Facebook) Careers Platform

Source

#web
🔥2👍1
Forwarded from CyberSecBastion
JWT Attacks (intro , attacks , Real world scenario and Mitigation)

#AppSec
👍4
Forwarded from CyberSecBastion
JWT Attacks_2023.pdf
2 MB
PDF - JWT Attacks (intro , attacks , Real world scenario and Mitigation)
🔥3
Forwarded from CyberSecBastion
Nuclei Vuln Scanner

Fast and customisable vulnerability scanner based on simple YAML based DSL.

Nuclei is used to send requests across targets based on a template, leading to zero false positives and providing fast scanning on a large number of hosts. Nuclei offers scanning for a variety of protocols, including TCP, DNS, HTTP, SSL, File, Whois, Websocket, Headless etc. With powerful and flexible templating, Nuclei can be used to model all kinds of security checks.

GitHub

#tools
👍4
A Quick Guide to Information Security Standards

#useful
👍3
A Quick Guide to Information Security Standards.pdf
1.6 MB
A Quick Guide to Information Security Standards
👍3
Oh.. My God😄

#fun
😁10🤣32
Azure AD Security Config Analyzer (AADSCA)

We decided to take alternative approach for chapter 6 and we are not covering possible Azure AD attack path. This time, the focus is on on proactive side, how organizations can monitor and strengthen Azure AD's security posture. For this purpose we created 'Azure AD Security Config Analyzer' aka 'AADSCA' solution.

GitHub
Official page

#windows
🔥3👍1
Какой вопрос - такой и ответ :):)

#fun
😁102
Email Incident Response

Email security incidents pose a high risk to a business & organization. The risk includes phishing, business email compromise (BEC) unauthorized access etc. This article describes some unique incident actions for email compromise cases.

Source

#forensic
👍3