S3桶安全侦查手法 https://securitycipher.medium.com/s3-bucket-recon-2d7c2bbf41ef #pentest
Hashtags
DN42 access 本服务为那些无法轻松访问自身网络的用户以及希望体验 dn42 但又不想承担维护自有网络成本的用户提供 dn42 连接 默认情况下,地址从/96地址块中分配,如果您希望租用独立的/96前缀或更大的地址空间,请按照联系方式联系我 所有公开的PoP均已屏蔽来自中国境内的 IP 地址。如果您确实需要dn42 access,请与我联系并提供合理的理由 该服务由AS4242423377提供 - - - - - - - The service provides DN42 connectivity to members who cannot easily access their own networks, as well as to those who would like to explore DN42 without the overhead of maintaining their own network. By default, addresses are allocated from a /96 block. If you wish to lease a dedicated /96 prefix or a larger address space, please contact me using the methods provided in the contact information. All publicly accessible PoP are blocked for IPs originating from within China. DN42 access from within China is not publicly available. If you genuinely require access, please contact me and provide a valid justification. Hosted by AS4242423377. Policy 本服务需要花费时间和金钱才能运行,但为了您的利益,我们免费提供。使用本服务是一种特权,而非权利。您必须合理使用本服务,以确保其他用户也能继续享受同样的便利。任何滥用、误用或干扰服务或其他用户的行为都可能导致您的访问权限立即被暂停或终止。 滥用行为包括但不限于: - 过度使用资源 - 黑客攻击、病毒、木马等,或任何其他可能损害服务或对服务及其用户造成风险的干扰行为 - 传播可能导致民事或刑事责任的不良内容 - - - - - - - This service require real time and financial resources to operate, yet are provided free of charge for your benefit. Access to the services is a privilege, not a right. You must use the services responsibly and considerately to ensure that other users can continue to enjoy the same opportunities. Any misuse, abuse, or activities that disrupt the service or other users may result in immediate suspension or termination of access. Abuse could include, but is not limited to: - Excessive use of resources - Hacking, viruses, trojans etc or any other disruption that could harm or create risk to the services or its users - Distribution of objectional content that could create a civil or criminal liability PoP ## Toronto, Canada Prefix: fdb6:fc6a:e66c:724f:fad1:d2cf::/96 Zerotier: 4753cf475f65b0fb ## Los Angeles, USA coming soon #announcement#service
Hashtags
搜索 #pentest
S3桶安全侦查手法 https://securitycipher.medium.com/s3-bucket-recon-2d7c2bbf41ef #pentest
Hashtags
网络安全相关简写英文全称 https://public.cyber.mil/acronyms/ #pentest
Hashtags
史上最大密码泄露下载:RockYou2024 密码汇编泄露近 100 亿 RockYou2024 是迄今为止最大的密码汇编泄露事件,泄露数据文档中竟包含 9948575739 个独特的明文密码 下载地址: https://s3.timeweb.cloud/fd51ce25-6f95e3f8-263a-4b13-92af-12bc265adb44/rockyou2024.zip https://cybernews.com/security/rockyou2024-largest-password-compilation-leak/ https://fastupload.io/1824d409732f30be https://disk.yandex.ru/d/1spMBmxcEnN95g #pentest
Hashtags
ICS Pentesting Tools A curated list of tools related to Industrial Control System (ICS) security and Penetration Testing https://github.com/kh4sh3i/ICS-Pentesting-Tools #pentest
Hashtags
隐写工具,将任何文件转换成图片,隐藏在图片中。 https://github.com/JoshuaKasa/van-gonography #pentest#github🐥[威胁情报]
使用 BYODLL 技术绕过 LSA 保护 https://github.com/itm4n/PPLrevenant #pentest#redteam
关于多家厂商设备通杀0day 影响平台 H3C-下一代防火墙安恒信息 -明御安全网关MAiPU -安全网关D_Link-下一代防火墙HUAWEI -公司产品迈普通信技术股份有限公司安全网关博达通信 -下一代防火墙任天行网络安全管理系统\安全审计系统安博通应用网关 烽火网络安全审计 瑞斯康达科技发展股份有限公司安全路由器 任子行网络安全审计系统 绿盟安全审计系统 深圳市鑫塔科技有限公司 第二代防火墙海康威视安全网关优炫防火墙(抄的安恒明御,源代码在前端中注释掉了) SG-8000深度安全网关网御星云上网行为管理系统 360上网行为审计系统 /sslvpn/sslvpn_client.php?client=logoImg&img=x%20/tmp|echo%20%60whoami%60%20|te #pentest#redteam🐥[威胁情报]
Azure AD 渗透测试流程图汇总 #pentest#redteam 🐥[威胁情报]
博彩网站渗透实战代码审计拿下后台、数据库 https://forum.butian.net/share/334 #好文推荐#pentest
一次GraphQL的探索 GraphQL 是一种面向数据的 API 查询风格,GraphQL并没有绑定数据库,交互逻辑是客户端→GraphQL→后端代码→数据。传统API实现功能一般是一个api对应一个功能,而在GraphQL中,用户请求的url路径固定,只需要改变请求的post内容,无需维护多个api。 https://mp.weixin.qq.com/s/lgCyIqQx0y8YnItpsfwjeg #好文推荐#pentest🐥[威胁情报]
nginx内存马:nginx module 支持动态加载so,通过 __attribute ((constructor))的方式绕过nginx module version check,可以编译出适应所有nginx版本的module。使用header_filter可以取得命令执行的参数,通过body_filter可以返回命令执行后的结果 https://github.com/veo/nginx_shell #工具分享#pentest
Pentest Collaboration Framework By @ drakylar Tool which will help you to store/modify/share information about pentest/web analysis projects. OpenSource, Portable, CrossPlatform & Free. - Generate reports by user-defined templates - Integration with more than 15 tools - API - HTTP sniffer connected to project - Network graph - One-click deploy at Heroku/AWS - Notes, Hosts, Issues, Credentials, Chats Demo: http://testing-pcf.herokuapp.com/ Gitlab: https://gitlab.com/invuls/pentest-projects/pcf @PentestCollaborationFramework #pcf#pentest