pentest_tm | Unsorted

Telegram-канал pentest_tm - PenTest Team

14642

Subscribe to a channel

PenTest Team

🗒 Optimizing Blind SQL Injection Detection with Content-Length Differences

https://bountysecurity.ai/blogs/news/optimizing-blind-sql-injection-detection-with-content-length-differences


@PenTest_Tm

Читать полностью…

PenTest Team

🗒 Bypass Upload Tricky

https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Upload%20Insecure%20Files

@PenTest_Tm

Читать полностью…

PenTest Team

🗒 Subdomain Takeover Vulnerability



@PenTest_Tm

Читать полностью…

PenTest Team

GIT files Dorks

Universal for Google, Bing etc

https://github.com/Proviesec/google-dorks/blob/main/google-dorks-for-git-files.txt

Bug Bounty Dorks

Universal for Google, Bing etc


https://github.com/hackingbharat/bug-bounty-dorks-archive/blob/main/bbdorks

@PenTest_Tm

Читать полностью…

PenTest Team

🗒 XSS Bypass Cloudflare WAF


%3CSVG/oNlY=1%20ONlOAD=confirm(document.domain)%3E


@PenTest_Tm

Читать полностью…

PenTest Team

Log files Dorks
Universal for Google, Bing etc:

https://github.com/Proviesec/google-dorks/blob/main/google-dorks-best-log.txt


@PenTest_Tm

Читать полностью…

PenTest Team

🗒 Accessing PostgreSQL Database Records


@PenTest_Tm

Читать полностью…

PenTest Team

🗒 Login Bypass


https://rajput623929.medium.com/bug-bounty-tutorial-login-bypass-technique-d7508856b2a1

@PenTest_Tm

Читать полностью…

PenTest Team

@cryptosignalsfree12

بچهایی که تو کار کریپتو هستن میتونید استفاده کنید

Читать полностью…

PenTest Team

بچها جلو جلو عیدتون مبارک ❤️

Читать полностью…

PenTest Team

🗒 Server Side Template Injection Payload List

{7*7}
*{7*7}
{{7*7}}
[[7*7]]
${7*7}
@(7*7)
<?=7*7?>
<%= 7*7 %>
${= 7*7}
{{= 7*7}}
${{7*7}}
#{7*7}
[=7*7]

اگر 49 بدهد ، هدف آسیب پذیر است


@PenTest_Tm

Читать полностью…

PenTest Team

🗒 How we applied advanced fuzzing techniques to cURL


https://blog.trailofbits.com/2024/03/01/toward-more-effective-curl-fuzzing/



@PenTest_Tm

Читать полностью…

PenTest Team

🗒 Bypass Cloudflare protected sites with sqlmap

بچها یه مقاله عالی برای بایپس WAF با sqlmap


pkhadka56/bypass-cloudflare-protected-sites-with-sqlmap-64b1644b0414" rel="nofollow">https://medium.com/@pkhadka56/bypass-cloudflare-protected-sites-with-sqlmap-64b1644b0414



@PenTest_Tm

Читать полностью…

PenTest Team

🗒 File Upload Cheatsheet



@PenTest_Tm

Читать полностью…

PenTest Team

@PenTest_Tm

Читать полностью…

PenTest Team

@cryptosignalsfree12

بچهایی که تو کار کریپتو هستن میتونید استفاده کنید

Читать полностью…

PenTest Team

🗒 Extract IPS From list of domains and then you can conduct your FUZZ/Manually check them for SDE /BAC , Ports , ..etc

grep -o '[0-9]\{1,3\}\.[0-9]\{1,3\}\.[0-9]\{1,3\}\.[0-9]\{1,3\}'



@PenTest_Tm

Читать полностью…

PenTest Team

🗒 Wordpress Plugin Background Image Cropper v1.2 - Remote Code Execution

آسیب پذیری RCE از افزونه وردپرسیه Background Image CROPPER ورژن 1.2


https://www.exploit-db.com/exploits/51998


@PenTest_Tm

Читать полностью…

PenTest Team

🗒 Bug Bounty Cheat Sheets
SSRF
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Server%20Side%20Request%20Forgery

https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/ssrf.md

CRLF

https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/CRLF%20Injection

https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/crlf.md

@PenTest_Tm

Читать полностью…

PenTest Team

🗒 Bug Bounty Cheat Sheets

XSS:
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/xss.md

https://github.com/ismailtasdelen/xss-payload-list

SQLI:

https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/sqli.md

@PenTest_Tm

Читать полностью…

PenTest Team

Google dorks

Link1
Link2
Link3
Link4
Link5
Link6
Link7

@PenTest_Tm

Читать полностью…

PenTest Team

🗒 How I Found Multiple XSS Vulnerabilities Using Unknown Techniques


https://infosecwriteups.com/how-i-found-multiple-xss-vulnerabilities-using-unknown-techniques-74f8e705ea0d


@PenTest_Tm

Читать полностью…

PenTest Team

🗒 One-click Account Take Over



https://dynnyd20.medium.com/one-click-account-take-over-e500929656ea

@PenTest_Tm

Читать полностью…

PenTest Team

🗒Open Redirect via Non\-Latin Subdomain in vcc\-\*\.8x8\.com/AGUI/test\.php


https://hackerone.com/reports/2331473


@PenTest_Tm

Читать полностью…

PenTest Team

🗒 XSSLite Stealer‌‌



@PenTest_Tm

Читать полностью…

PenTest Team

🗒 Signal Labs - Vulnerability Research & Fuzzing

Читать полностью…

PenTest Team

🗒 Cross-Site Scripting (XSS) Explained!

How to Bug Bounty

https://www.youtube.com/watch?v=ej2O4lOUzRc



@PenTest_Tm

Читать полностью…

PenTest Team

🗒 bypass XSS Cloudflare WAF

Encoded Payload
&#34;&gt;&lt;track/onerror=&#x27;confirm\%601\%60&#x27;&gt;

Clean Payload
"><track/onerror='confirm1'>


@PenTest_Tm

Читать полностью…

PenTest Team

@PenTest_Tm

Читать полностью…

PenTest Team

@PenTest_Tm

Читать полностью…
Subscribe to a channel