josh_ruppe's profile picture. I Test Pens @ Nordstrom, Founder of @hackers_against, Security Researcher & Speaker, Eater of Delicious Burgers, Running Man, #DC470, #DC404

Joshua Ruppe

@josh_ruppe

I Test Pens @ Nordstrom, Founder of @hackers_against, Security Researcher & Speaker, Eater of Delicious Burgers, Running Man, #DC470, #DC404

Joshua Ruppe reposted

some ways to bypass 403 1- using space symbols exmaple: /admin -> 403 /admin%09 -> 200 /admin%20 -> 200 2- use traversal Example: /admin -> 403 /..;/admin -> 200 you can fuzz with traversal sometimes that's end with results Example: /..;/FUZZ #bugbountytips #BugBounty

0x_rood's tweet image. some ways to bypass 403

1- using space symbols
exmaple:
/admin -> 403
/admin%09 -> 200
/admin%20 -> 200

2- use traversal
Example:
/admin -> 403
/..;/admin -> 200

you can fuzz with traversal sometimes that's end with results

Example: /..;/FUZZ

#bugbountytips #BugBounty

Joshua Ruppe reposted

You can use ChatGPT for offensive security !!! Learn in this thread. #infosec #bugbountytips


Joshua Ruppe reposted

30 cybersecurity search engines for researchers: 1. Dehashed—View leaked credentials. 2. SecurityTrails—Extensive DNS data. 3. DorkSearch—Really fast Google dorking. 4. ExploitDB—Archive of various exploits. 5. ZoomEye—Gather information about targets.


Joshua Ruppe reposted

3 websites you should definitely bookmark if you're a pentester 🧵👇🏾👇🏾


This is a great list!

This post is unavailable.

Joshua Ruppe reposted

Tips to find your Public IP from command line.

qusaialhaddad's tweet image. Tips to find your Public IP from command line.

Joshua Ruppe reposted

What's missing? KERBEROS ABUSE •ASREP Roast •ASREQ (kerbrute – enum users) •ASREQ Roast •Kerberoast •Golden Ticket •Silver Ticket •Diamond Ticket •Sapphire Ticket •Bronze Ticket •Unconstrained Delegation •Constrained Delegation 1/2


Enjoy the complimentary anxiety.

Welcome to cybersecurity. The more you learn, the less you know.



RIP to the legend. A terrible loss ;(

You are never, ever too “junior” to talk to anyone in Infosec. There’s no bar you must pass, talk you must give, code you must write before you’re qualified to nerd out with someone. Anyone. Really. Trust me, the “famous” nerds miss the heck out of you.



I feel like I remember reading about this in a 2600 magazine back in the day. Nonetheless, what a ride these two paragraphs are.

learning about the "Quadro Tracker", a bomb/drug/person-locating device a bunch of cops & school districts bought in the 90s that turned out to just be a box of dead ants

Jackapedia_'s tweet image. learning about the "Quadro Tracker", a bomb/drug/person-locating device a bunch of cops & school districts bought in the 90s that turned out to just be a box of dead ants
Jackapedia_'s tweet image. learning about the "Quadro Tracker", a bomb/drug/person-locating device a bunch of cops & school districts bought in the 90s that turned out to just be a box of dead ants
Jackapedia_'s tweet image. learning about the "Quadro Tracker", a bomb/drug/person-locating device a bunch of cops & school districts bought in the 90s that turned out to just be a box of dead ants


learning about the "Quadro Tracker", a bomb/drug/person-locating device a bunch of cops & school districts bought in the 90s that turned out to just be a box of dead ants

Jackapedia_'s tweet image. learning about the "Quadro Tracker", a bomb/drug/person-locating device a bunch of cops & school districts bought in the 90s that turned out to just be a box of dead ants
Jackapedia_'s tweet image. learning about the "Quadro Tracker", a bomb/drug/person-locating device a bunch of cops & school districts bought in the 90s that turned out to just be a box of dead ants
Jackapedia_'s tweet image. learning about the "Quadro Tracker", a bomb/drug/person-locating device a bunch of cops & school districts bought in the 90s that turned out to just be a box of dead ants


Joshua Ruppe reposted

Today is the first official day of Hackers Against Hate being in operation. While there is some more work being done behind the scenes, the public facing portion has been completed. It has been a long road to get to this point, but it has been well worth it. 1/2


Oh hey, its me.

clever employers are starting to figure out the strengths of working *with* this

caseyjohnellis's tweet image. clever employers are starting to figure out the strengths of working *with* this


Need to quickly generate a reverse shell? Need it in emoji PHP? Node? Ruby? revshells.com is a pretty cool tool that was pointed out to me earlier this week. You can pre-populate source and listener IPs/Ports, the shell you want to use, etc. 👍🏼


This past week has been a really long year ;(


United States Trends

Loading...

Something went wrong.


Something went wrong.