trinhdoanmanh's profile picture. 😎

trinh doan manh

@trinhdoanmanh

😎

trinh doan manh reposted

Again and again #Ghauri proving its getting better in detecting #SQLinjection. I tested this target using SQLMAP over an hour but the result was negative, but Ghauri detected the injection point. @r0oth3x49, great job man. 💪💪 #BugBounty

nav1n0x's tweet image. Again and again #Ghauri proving its getting better in detecting #SQLinjection. I tested this target using SQLMAP over an hour but the result was negative, but Ghauri detected the injection point. @r0oth3x49, great job man. 💪💪 #BugBounty
nav1n0x's tweet image. Again and again #Ghauri proving its getting better in detecting #SQLinjection. I tested this target using SQLMAP over an hour but the result was negative, but Ghauri detected the injection point. @r0oth3x49, great job man. 💪💪 #BugBounty

trinh doan manh reposted

/1 How do Apple Pay and Google Pay handle sensitive card info? The diagram below shows the differences. Both approaches are very secure, but the implementations are different. To understand the difference, we break down the process into two flows.

alexxubyte's tweet image. /1 How do Apple Pay and Google Pay handle sensitive card info?

The diagram below shows the differences. Both approaches are very secure, but the implementations are different. To understand the difference, we break down the process into two flows.

trinh doan manh reposted

If you haven't yet seen, this is how we hacked a BIG bank 😱 . With @infosec_au , We were able to gain RCE on more than 100 different subdomains by exploiting a 0day we discovered. Reported through their #bugbounty program. Enjoy the read! blog.assetnote.io/2022/05/03/hac…

HusseiN98D's tweet image. If you haven't yet seen, this is how we hacked a BIG bank 😱 . With @infosec_au , We were able to gain RCE on more than 100 different subdomains by exploiting a 0day we discovered. Reported through their #bugbounty program. Enjoy the read!

blog.assetnote.io/2022/05/03/hac…

trinh doan manh reposted

AD Pentest mindmap upgrade : Full version: github.com/Orange-Cyberde… xmind version (slow, the map is big) : xmind.net/m/5dypm8/ Fell free to tell me what is missing !

M4yFly's tweet image. AD Pentest mindmap upgrade :
Full version: github.com/Orange-Cyberde… 

xmind version (slow, the map is big) :
xmind.net/m/5dypm8/

Fell free to tell me what is missing !

trinh doan manh reposted

CVE-2021-39115 Jira Service Management Server Template Injection in Email Templates jira.atlassian.com/browse/JSDSERV…


trinh doan manh reposted

Get a free preview of our AWS Security Bootcamp! In 30 minutes, instructor Jeswin Mathai shows you how to prevent attackers from performing privilege escalation and resource abuse: bit.ly/2TnpqwY

SecurityTube's tweet image. Get a free preview of our AWS Security Bootcamp! In 30 minutes, instructor Jeswin Mathai shows you how to prevent attackers from performing privilege escalation and resource abuse: bit.ly/2TnpqwY

trinh doan manh reposted

Leaked Facebook DB [ 550 M ] 😱🕵️📱- Perú [8,075,317] 😕🇵🇪

CryptoInsane's tweet image. Leaked Facebook DB [ 550 M ] 😱🕵️📱- Perú [8,075,317] 😕🇵🇪
CryptoInsane's tweet image. Leaked Facebook DB [ 550 M ] 😱🕵️📱- Perú [8,075,317] 😕🇵🇪

trinh doan manh reposted

Just got my first $10k bounty on @Hacker0x01. Bug: The site was trying to add document from AWS bucket to the main site with POST request,it contains Param named KEY with URL path as value. I tried directory traversal on that param,and it dislcose full bucket with credentials.

_Base_64's tweet image. Just got my first $10k bounty on @Hacker0x01.
Bug: The site was trying to add document from AWS bucket to the main site with POST request,it contains Param named KEY with URL path as value. I tried directory traversal on that param,and it dislcose full bucket with credentials.

trinh doan manh reposted

Much like Amass, a lot of people don't use Nmap to its full potential. Here's a bunch of tips on how I use actually use Nmap. If you get something out of this article, share it! medium.com/@hakluke/haklu…


trinh doan manh reposted

trinh doan manh reposted

Why our army still had to eat and sleep in the forest to make room for you to isolate in the hospital, so how can you eat a meal with 200,000 VND? When it's more than the value of our daily meal? #ApologizeToVietNam #기르던개에게다리물렸다

hoongkhuyeen's tweet image. Why our army still had to eat and sleep in the forest to make room for you to isolate in the hospital, so how can you eat a meal with 200,000 VND? When it's more than the value of our daily meal?
 #ApologizeToVietNam #기르던개에게다리물렸다
hoongkhuyeen's tweet image. Why our army still had to eat and sleep in the forest to make room for you to isolate in the hospital, so how can you eat a meal with 200,000 VND? When it's more than the value of our daily meal?
 #ApologizeToVietNam #기르던개에게다리물렸다
hoongkhuyeen's tweet image. Why our army still had to eat and sleep in the forest to make room for you to isolate in the hospital, so how can you eat a meal with 200,000 VND? When it's more than the value of our daily meal?
 #ApologizeToVietNam #기르던개에게다리물렸다

trinh doan manh reposted

🔒CryptoTester v1.4.0.1 for #Ransomware Analysis 🔍 New: Embedded Chrysanthemum.jpg/Desert.jpg inputs, Ctrl+F/G/O/S shortcuts, display selection length (and DWORD parsing), some menu icons, and enabled Compress button.

demonslay335's tweet image. 🔒CryptoTester v1.4.0.1 for #Ransomware Analysis 🔍
New: Embedded Chrysanthemum.jpg/Desert.jpg inputs, Ctrl+F/G/O/S shortcuts, display selection length (and DWORD parsing), some menu icons, and enabled Compress button.
demonslay335's tweet image. 🔒CryptoTester v1.4.0.1 for #Ransomware Analysis 🔍
New: Embedded Chrysanthemum.jpg/Desert.jpg inputs, Ctrl+F/G/O/S shortcuts, display selection length (and DWORD parsing), some menu icons, and enabled Compress button.
demonslay335's tweet image. 🔒CryptoTester v1.4.0.1 for #Ransomware Analysis 🔍
New: Embedded Chrysanthemum.jpg/Desert.jpg inputs, Ctrl+F/G/O/S shortcuts, display selection length (and DWORD parsing), some menu icons, and enabled Compress button.

trinh doan manh reposted

As part of my work at Vincss, our team recently analyzed malicious code embedded within document file that targeted to Viet Nam. You can see the write-up here.blog.vincss.net/2019/12/re009-…


trinh doan manh reposted

Our brand new XSS cheat sheet is now live, with hundreds of modern vectors, developed by @garethheyes portswigger.net/web-security/c…


trinh doan manh reposted

Do not hardcode your email and database credentials in programs, or if you do, make sure it won't get out from the system(s) where it should run... Especially if you are a CERT/sec people of a bank. Anyone can explain this to NBRB/Belarusbank? That "Mr.Robot" name anyway... 😂

malwrhunterteam's tweet image. Do not hardcode your email and database credentials in programs, or if you do, make sure it won't get out from the system(s) where it should run... Especially if you are a CERT/sec people of a bank.
Anyone can explain this to NBRB/Belarusbank?
That "Mr.Robot" name anyway...
😂
malwrhunterteam's tweet image. Do not hardcode your email and database credentials in programs, or if you do, make sure it won't get out from the system(s) where it should run... Especially if you are a CERT/sec people of a bank.
Anyone can explain this to NBRB/Belarusbank?
That "Mr.Robot" name anyway...
😂

trinh doan manh reposted

Flare-Emu - Powered by IDA Pro and the Unicorn emulation framework that provides scriptable emulation features for the x86, x86_64, ARM, and ARM64 architectures to reverse engineers ift.tt/2niO4ig


trinh doan manh reposted

"Starting with Windows Kernel Exploitation – part 1 – setting up the lab" hshrzd.wordpress.com/2017/05/28/sta…


Loading...

Something went wrong.


Something went wrong.