πŸ”₯OSCP TrainingπŸ”₯πŸ›‘βš”οΈπŸ‘¨πŸ»β€πŸ’»
8.1K subscribers
162 photos
1 video
27 files
64 links
Offensive Security Certified Professional
@WebHacking
@pfsense
@WifiHacking
πŸ”°For safer days
Download Telegram
If you need to intercept the Android traffic through BurpSuite:
1)Ensure Burp is listening to more than the loopback address
2)Allow inbound traffic on the Firewall
3)Use ADB to run "settings put global http_proxy IP PORT"
4)Download and trust the CA from http://IP/cert
5)WIN
πŸ‘10πŸ€”2
Forwarded from Web Hacking
Remote File Inclusion (RFI)
πŸ‘12πŸ”₯5
Forwarded from Web Hacking
Rate limit bypass using some custom headers:

X-Forwarded-For: IP
X-Forwarded-IP: IP
X-Client-IP: IP
X-Remote-IP: IP
X-Originating-IP: IP
X-Host: IP
X-Client: IP
πŸ‘3πŸ€”2
Forwarded from Web Hacking
403 bypass techniques
πŸ‘2❀1
Forwarded from Web Hacking
Bypassing Rate Limit Protection
πŸ‘8
When trying for XSS if alert() is blocked you can use an alternative like:

1. Confirm
2. Prompt
3. Eval
4. Write

@WebHacking
πŸ‘23
Bug Bounty Tip

Want to learn HTTP Request Smuggling?

Check out this incredible Workshop with over 120 minutes of theory, videos, and practice using Docker Labs


https://gosecure.github.io/request-smuggling-workshop/#0
πŸ‘14❀1
403 Bypass tricks...
❀9πŸ‘5πŸ€”4πŸ‘Ž2