hax_3xploit's profile picture. SRT@Synack • OSCP •  C|EH • eWPT • eJPT

ABDULLAH

@hax_3xploit

SRT@Synack • OSCP • C|EH • eWPT • eJPT

Pinned

Finally earned it!!! Should've done that a lot earlier, but all the effort was worth it. I'm officially OSCP Certified now! Honestly, it was one hell of a ride that I can’t forget. Thanks @offsectraining credential.net/bb89aa00-1952-…


ABDULLAH reposted

Seeing someone’s credentials are always a dopamine! When you come across a puppetDB instance dont forget to check the endpoint /pdb/query/v4/resources . . #bugbounty #bugbountytips #hackerone #bugcrowd #hack #pentest #TogetherWeHitHarder

GokTest's tweet image. Seeing someone’s credentials are always a dopamine!
When you come across a puppetDB instance dont forget to check the endpoint /pdb/query/v4/resources
.
.

#bugbounty #bugbountytips #hackerone #bugcrowd #hack #pentest #TogetherWeHitHarder

ABDULLAH reposted

Thanks to everyone who joined my DEFCON33 talk!🎉 For those of you who missed it and are interested in seeing how we can extract cleartext credentials and bypass MFA directly from the official Microsoft login page, I just uploaded the recording to YouTube: youtu.be/z6GJqrkL0S0

RedByte1337's tweet image. Thanks to everyone who joined my DEFCON33 talk!🎉
For those of you who missed it and are interested in seeing how we can extract cleartext credentials and bypass MFA directly from the official Microsoft login page, I just uploaded the recording to YouTube:
youtu.be/z6GJqrkL0S0

ABDULLAH reposted

Active Directory computers should be reviewed about once a year. Old operating systems can hold back security progress like keeping SMBv1 and NTLMv1 active. Inactive computers should be discovered and disabled when no longer in use (and eventually removed). The OperatingSystem &…

PyroTek3's tweet image. Active Directory computers should be reviewed about once a year. Old operating systems can hold back security progress like keeping SMBv1 and NTLMv1 active. Inactive computers should be discovered and disabled when no longer in use (and eventually removed).

The OperatingSystem &…

ABDULLAH reposted

جموں کشمیر کے انقلابی شاعر احمد فرہاد کے کیس نے مسلہ جموں کشمیر کو ایک نئی ڈائمینشن دے دی۔جج صاحب کو کہنا چایے تھا کہ یہ چیف سیکریٹری ،لینٹ افسران وہاں سے فورا واپس بلاؤ پاکستان کی فرنچائز سیاسی پارٹیوں پر جموں کشمیر میں با بندی لگاو، افواج واپس بلاو۔ #Free_Jammu_Kashmir


ABDULLAH reposted

The government of Pakistan told Islamabad High Court that "Azad Kashmir" is a "foreign territory." Hamid Mir: Azad Kashmir PM said I did not call the Rangers, then who sent the Rangers to Azad Kashmir.? #ReleaseAhmadFarhad


ABDULLAH reposted

پوری دنیا یہ مناظر دیکھ رہی ہے کہ پاکستانی فوج نے اپنے زیرانتظام کشمیر میں شہریوں کو شہید کردیا ہے اور یہ وہی کشمیر ہے جس کے وسائل پر پاکستانی فوج 74 سال سے قابض ہے اور انکے نام پر الگ سے اپنی پاکستانی عوام کو جذباتی بلیک میل کرکے ہر سال کھربوں روپے کھاتی ہے #RightSMovementAJK


ABDULLAH reposted

پنجاب ایک لینڈ لاک وسائل سے خالی زمین ہے جس کی معیشت کا زیادہ حصہ زراعت اور انڈسٹری پر قائم ہے۔ زراعت کےلئے پانی اور انڈسٹری کےلئے بجلی و گیس پختونخوا،کشمیر اور بلوچستان سے لوٹ کر مہیا کئے جاتے ہیں اگر باقی صوبوں کی لوٹ مار بند کر دیا تو یونیورسٹی چھوڑ گھر بھی آباد نہیں رکھ سکوگے

پنجاب کے تعلیمی اداروں میں پہلا حق پنجابیوں کا ہے۔

shahzad_nasir7's tweet image. پنجاب کے تعلیمی اداروں میں پہلا حق پنجابیوں کا ہے۔


ABDULLAH reposted

#RightsMovementAJK Zindabad. آر پار کشمیر پر کشمیریوں کا حق تسلیم کیا جائے۔


ABDULLAH reposted

It was so hard for me to record this i've mustered up the courage to actually speak up about it after an year. Never in my life thought i would be begging for justice for my own brother like this. Life is truly unfair. #arrestSyedBaqir #JusticeforSulaimanBabar


ABDULLAH reposted

“Setting Up an iOS Pentesting Lab on a Non-Jailbroken iDevice” by Abdullah Khawaja infosecwriteups.com/setting-up-an-…

Alra3ees's tweet image. “Setting Up an iOS Pentesting Lab on a Non-Jailbroken iDevice” by Abdullah Khawaja
infosecwriteups.com/setting-up-an-…

ABDULLAH reposted

🔐Secrets no one will share with you - Here's a technique that might grant you access to takeover other users' accounts using "Login with Facebook": Are you working on a target site that supports "Login with Facebook"? Disable email sharing during Facebook login and be ready…

Jayesh25_'s tweet image. 🔐Secrets no one will share with you - Here's a technique that might grant you access to takeover other users' accounts using "Login with Facebook":

Are you working on a target site that supports "Login with Facebook"?

Disable email sharing during Facebook login and be ready…

ABDULLAH reposted

Bug Bounty Tips: 🐛💰 Here's a simple bug bounty tip for shopping site targets that can earn you some serious $$$$. I've stumbled upon 10+ similar issues on shopping sites that allow guest checkouts 🛒. Many overlook these issues because they require placing an order 📦.…

Jayesh25_'s tweet image. Bug Bounty Tips: 🐛💰 Here's a simple bug bounty tip for shopping site targets that can earn you some serious $$$$. 

I've stumbled upon 10+ similar issues on shopping sites that allow guest checkouts 🛒. 

Many overlook these issues because they require placing an order 📦.…

ABDULLAH reposted

Examples of Israeli tech to boycott: SentinelOne (the cowards) Cybereason Checkpoint Checkmarx Wiz Aqua Security CyberArk NICE systems Monday Wix (the scammers favorite phishing platform) Cellebrite Armis Pentera Snyk


ABDULLAH reposted

Bug Bounty Tips: 🐛🔐 Unlocking Important Resources with Email Verification Bypass Working on a target where email verification is crucial? Imagine a scenario where gaining access to a specific domain, like example[.]com, could grant you entry into a victim's workspace, allowing…

Jayesh25_'s tweet image. Bug Bounty Tips: 🐛🔐 Unlocking Important Resources with Email Verification Bypass

Working on a target where email verification is crucial? Imagine a scenario where gaining access to a specific domain, like example[.]com, could grant you entry into a victim's workspace, allowing…

ABDULLAH reposted

IIS Hacking tips from the latest episode with the master himself @infosec_au: 1. NEVER leave that blue IIS page un-touched "You see that blue page that comes up when you hit an IIS server? That should be your point where you think, I'm gonna find criticals on this bad boy.


ABDULLAH reposted

[1/4] If you have an Android app that you really want to reverse, but all constants are obfuscated, this advice may save tons of time

_bagipro's tweet image. [1/4]
If you have an Android app that you really want to reverse, but all constants are obfuscated, this advice may save tons of time

ABDULLAH reposted

How to extract SSL certificate and DNS info from an ASN! 🤩 Use naabu to scan for open HTTPS ports and nuclei template ssl-dns-names to extract SSL certificate and DNS info! ⚛️ Nuclei's asnmap integration sorts out the rest 💪 #CyberSecurity #PortScanning #Nuclei101

pdnuclei's tweet image. How to extract SSL certificate and DNS info from an ASN! 🤩

Use naabu to scan for open HTTPS ports and nuclei template ssl-dns-names to extract SSL certificate and DNS info! 

⚛️ Nuclei's asnmap integration sorts out the rest 💪

#CyberSecurity #PortScanning #Nuclei101

Loading...

Something went wrong.


Something went wrong.