Web Security | Bug hunting
@cybersecurityresources
7.3K
subscribers
46
photos
2
files
473
links
A web penetration testing / General cybersecurity / Network related topics channel that provides direct links for interesting resources and notes.
Download Telegram
Join
Web Security | Bug hunting
7.3K subscribers
Web Security | Bug hunting
https://medium.com/secjuice/php-ssrf-techniques-9d422cb28d51
Medium
PHP SSRF Techniques
How to bypass filter_var(), preg_match() and parse_url()
Web Security | Bug hunting
https://www.xudongz.com/blog/2017/idn-phishing/
Xudongz
Phishing with Unicode Domains - Xudong Zheng
Vulnerability in Chrome, Firefox, and Opera makes users susceptible to phishing with Unicode domains
Web Security | Bug hunting
https://youtu.be/l0YsEk_59fQ
YouTube
GitHub Recon and Sensitive Data Exposure
Welcome to Bugcrowd University – GitHub Recon and Sensitive Data
Exposure! This guide will help you to locate a targeted company’s
GitHub repositories and identify any sensitive data that may be
exposed within.
Web Security | Bug hunting
https://rhinosecuritylabs.com/aws/bypassing-ip-based-blocking-aws/
Rhino Security Labs
Bypassing IP Based Blocking with AWS API Gateway
In order to bypass IP based blocking, we at Rhino Security Labs created a Burp Suite extension that uses AWS API Gateway to change your IP on every request.
Web Security | Bug hunting
https://highon.coffee/blog/penetration-testing-tools-cheat-sheet/
highon.coffee
Pen Testing Tools Cheat Sheet
Penetration testing tools cheat sheet, a high level overview / quick reference cheat sheet for penetration testing.
Web Security | Bug hunting
https://pastebin.com/5mBudvMt
Pastebin
Web Penetration Testing Arsenal - Pastebin.com
Pastebin.com is the number one paste tool since 2002. Pastebin is a website where you can store text online for a set period of time.
Web Security | Bug hunting
The Bug Hunters Methodology (UNDERGOING CLEANUP)
https://github.com/jhaddix/tbhm
GitHub
GitHub - jhaddix/tbhm: The Bug Hunters Methodology
The Bug Hunters Methodology. Contribute to jhaddix/tbhm development by creating an account on GitHub.
Web Security | Bug hunting
https://resources.infosecinstitute.com/file-inclusion-attacks/#gref
Infosec Resources
File Inclusion Attacks
A file inclusion vulnerability allows an attacker to access unauthorized or sensitive files available on the web server or to execute malicious files on
Web Security | Bug hunting
https://medium.com/swlh/attacking-sites-using-csrf-ba79b45b6efe
Medium
Attacking Sites Using CSRF
From CSRF to user information leak, XSS and full account takeover.
Web Security | Bug hunting
https://medium.com/@YumiSec/how-to-bypass-a-2fa-with-a-http-header-ce82f7927893
Medium
How to bypass a 2FA with a HTTP header
Hi everyone and welcome back on this new write-up.
Web Security | Bug hunting
https://medium.com/@ar_arvind/facebook-bug-bounty-reading-whatsapp-contacts-list-without-unlocking-the-device-a40e9c660a42
Medium
WhatsApp Bug Bounty: Reading contacts list without unlocking the device
A bug allows anyone who has the victim’s phone to read all their contact list without unlocking the security lock
Web Security | Bug hunting
https://medium.com/@valeriyshevchenko/jenkins-rce-poc-or-simple-pre-auth-remote-code-execution-on-the-server-d18b868a77cb
Medium
Jenkins RCE PoC or simple pre-auth remote code execution on the Server.
Once upon a time, a friend of mine asked me a question — "Do you know any fresh RCE for the Jenkins environment ?". I was informed already…
Web Security | Bug hunting
https://brutelogic.com.br/blog/xss-via-http-headers/
Web Security | Bug hunting
https://medium.com/@osamaavvan/json-csrf-to-formdata-attack-eb65272376a2
Medium
JSON CSRF To FormData Attack
So you guys must be aware of CSRF attack, if not then here is a short intro:
Web Security | Bug hunting
https://jivoi.github.io/2015/08/21/pentest-tips-and-tricks-number-2/
EK
Pentest Tips and Tricks #2
Pentest Handy Tips and Tricks - part 2.
Web Security | Bug hunting
https://andripwn.github.io/Labs/XSS/
Web Security | Bug hunting
https://github.com/ebertti/awesome-telegram
GitHub
GitHub - ebertti/awesome-telegram: Collection great groups, channels, bots and libraries for Telegram
Collection great groups, channels, bots and libraries for Telegram - ebertti/awesome-telegram
Web Security | Bug hunting
https://pastebin.com/SkTLFQ4N
Pastebin
Ehtools Framework Installation - Pastebin.com
Pastebin.com is the number one paste tool since 2002. Pastebin is a website where you can store text online for a set period of time.
Web Security | Bug hunting
https://githacktools.blogspot.com/2019/01/avet-antivirus-evasion-tool.html
Web Security | Bug hunting
https://medium.com/@danangtriatmaja/bug-bounty-self-xss-clickjacking-good-xss-tokopedia-8df7a65e0955
Medium
[ BUG BOUNTY ] Self XSS + ClickJacking = Good XSS | Tokopedia
Hi sobat, bagaimana kabarnya ? semoga senantiasa sehat selalu dan diberikan kelancaran dalam aktifitasnya. ^-^
Web Security | Bug hunting
https://medium.com/@pratiky054/graphql-bug-to-steal-anyones-address-fc34f0374417
Medium
Graphql Abuse to Steal Anyone’s Address
Introduction