pythoncike's profile picture. security research,red team memeber,code reviewer

RandomHt

@pythoncike

security research,red team memeber,code reviewer

RandomHt รีโพสต์แล้ว

发现一款 Chrome 插件,用于将网页文档以原样式保存到本地浏览器数据库,不用担心隐私泄漏,不依赖网络,支持关键词快速搜索和检索功能,节约磁盘空间同时减少浏览器内存的使用。github.com/wvit/web-docum…


RandomHt รีโพสต์แล้ว

A small gift from my side to all bug bounty hunters. My 8 hour long burp suite focused course for free. share to someone who need it. #bugbountytips #bugbounty #infosec (rt & share + enjoy) udemy.com/course/bug-bou…


RandomHt รีโพสต์แล้ว

CVE-2022-0824 Webmin revshell - Post-Auth Reverse. PoC github.com/faisalfs10x/We…

cyber_advising's tweet image. CVE-2022-0824 Webmin revshell -  Post-Auth Reverse.
PoC
github.com/faisalfs10x/We…

RandomHt รีโพสต์แล้ว

Talk about 2 POC of DirtyPipe(CVE-2022-0847) Original POC: dirtypipe.cm4all.com is able to overwrite arbitrary file with offset like ./exp /etc/passwd 5 ":0:0:rootx" Improved POC: haxx.in/files/dirtypip… is able to overwrite a SUID program like ./exp /usr/bin/su

phithon_xg's tweet image. Talk about 2 POC of DirtyPipe(CVE-2022-0847)
Original POC: dirtypipe.cm4all.com is able to overwrite arbitrary file with offset like ./exp /etc/passwd 5 ":0:0:rootx"
Improved POC: haxx.in/files/dirtypip… is able to overwrite a SUID program like ./exp /usr/bin/su
phithon_xg's tweet image. Talk about 2 POC of DirtyPipe(CVE-2022-0847)
Original POC: dirtypipe.cm4all.com is able to overwrite arbitrary file with offset like ./exp /etc/passwd 5 ":0:0:rootx"
Improved POC: haxx.in/files/dirtypip… is able to overwrite a SUID program like ./exp /usr/bin/su

RandomHt รีโพสต์แล้ว

Top 25 Browser Extensions for Pentesters and Bugbounty Hunters (2022) p1boom.com/2022/02/top25-… Did i miss something? #bugbounty #bugbountytips #infosec #Pentesting


RandomHt รีโพสต์แล้ว

Found an XSS filter that allows SVG-based tags? Try the 'use' element, you can import a SVG via a data url and execute JavaScript automatically! portswigger.net/web-security/c…

PortSwiggerRes's tweet image. Found an XSS filter that allows SVG-based tags? Try the 'use' element, you can import a SVG via a data url and execute JavaScript automatically!

portswigger.net/web-security/c…

RandomHt รีโพสต์แล้ว

✅ A Tip for SQL Injection WAF Bypass

ptswarm's tweet image. ✅ A Tip for SQL Injection WAF Bypass

Happy year’s 2022, I learning Java code review and codeql.

pythoncike's tweet image. Happy year’s 2022, I learning Java code review and codeql.

RandomHt รีโพสต์แล้ว

Most popular key word in #Linux with definitions that’s help u to learn more about who to use it in linux platform. #CyberSecurity #cybercrime #الامن_السيبراني

bnsihli's tweet image. Most popular key word in #Linux with definitions that’s help u to learn more about who to use it in linux platform.

#CyberSecurity 
#cybercrime 
#الامن_السيبراني

RandomHt รีโพสต์แล้ว

In this tweet, I will explain to you How to find Leaking AWS Keys.

h4x0r_dz's tweet image. In this tweet, I will explain to you How to find Leaking AWS Keys.

RandomHt รีโพสต์แล้ว

#update St8out - Extra one-liner for reconnaissance gist.github.com/dwisiswant0/5f… Workflow: metabigor > findomain & amass > filter-resolved > subjack > dig > nmap > webanalyze > dirsearch > LinkFinder > cors-blimey > gowitness > Arjun > meg > gf #bugbountytips


RandomHt รีโพสต์แล้ว

I added a script to generate the PDF & archive for my #OSCP Exam Report Template in Markdown, as I saw a lot of people where creating their own scripts. github.com/noraj/OSCP-Exa…


xss cheat from xiangcao

pythoncike's tweet image. xss cheat from xiangcao

learn hack in Twitter


RandomHt รีโพสต์แล้ว

If you didn't know, you can use Sn1per to retrieve a targets ASN, full subnet list and IP's via 'recon' mode. These can easily be fed into Sn1per using 'discover' mode to scan full subnets and enumerate all hosts. 😎 xerosecurity.com #bugbounty #netsec #infosec #offsec

xer0dayz's tweet image. If you didn't know, you can use Sn1per to retrieve a targets ASN, full subnet list and IP's via 'recon' mode. These can easily be fed into Sn1per using 'discover' mode to scan full subnets and enumerate all hosts. 😎

xerosecurity.com 

#bugbounty #netsec #infosec #offsec

RandomHt รีโพสต์แล้ว

Are you ready to takeover subdomains? ;) I have developed a tool to scan subdomain takeover vulnerabilities. Found 300+ vulnerable subdomains on Twitter,Yahoo,Pinterest,Periscope,Spotify,HarvardUni,StanfordUni,BerkeleyUni,YaleUni,PrincetonUni... Its free! hackking.net/subdomain-take…


RandomHt รีโพสต์แล้ว

Confirmed. Everyone is affected. Or you are not on the Internet.

I have a major #Databreach announcement tomorrow - 1.2 BILLION people exposed from a single organization. More details soon. @lilyhnewman @troyhunt @MayhemDayOne @DataViperIO



United States เทรนด์

Loading...

Something went wrong.


Something went wrong.