Полезные ссылки.

Discussion in 'Кухня' started by grimnir, 28 Feb 2019.

  1. grimnir

    grimnir Members of Antichat

    Joined:
    23 Apr 2012
    Messages:
    1,114
    Likes Received:
    830
    Reputations:
    231
    Отличный сборник по WAF ,что блокируют, как обойти. Рекомендую в закладки
    https://github.com/0xInfection/Awesome-WAF
    и сайт https://awesomelists.top подборки по темам на IT тематику.
     
    _________________________
    #1 grimnir, 28 Feb 2019
    Last edited: 28 Feb 2019
    Estet, Spinus, CKAP and 6 others like this.
    1. grimnir

      grimnir Members of Antichat

      Joined:
      23 Apr 2012
      Messages:
      1,114
      Likes Received:
      830
      Reputations:
      231
      https://github.com/ashutosh1206/Crypton
      Подборка, состоящая из объяснения и реализации всех существующих атак на различные системы шифрования, цифровых подписей, алгоритмов хеширования, а также примеров из состязаний CTF
       
      _________________________
      CKAP, Baskin-Robbins, crlf and 3 others like this.
      1. grimnir

        grimnir Members of Antichat

        Joined:
        23 Apr 2012
        Messages:
        1,114
        Likes Received:
        830
        Reputations:
        231
        https://github.com/secfigo/Awesome-Fuzzing
        Обширный список Fuzzing ресурсов (книги, курсы - платные и бесплатные, видео, инструменты, учебные пособия и уязвимые приложения для практики) для изучения фаззинга и начальных этапов разработки эксплойтов.
         
        _________________________
        Black dead, CKAP, BabaDook and 3 others like this.
        1. grimnir

          grimnir Members of Antichat

          Joined:
          23 Apr 2012
          Messages:
          1,114
          Likes Received:
          830
          Reputations:
          231
          https://github.com/1hack0/Facebook-Bug-Bounty-Write-ups
          Райтапы по ФБ
           
          _________________________
          CKAP, BabaDook, dooble and 4 others like this.
          1. grimnir

            grimnir Members of Antichat

            Joined:
            23 Apr 2012
            Messages:
            1,114
            Likes Received:
            830
            Reputations:
            231
            https://github.com/infosecn1nja/AD-Attack-Defense/blob/master/README.md
            Active Directory Kill Chain Attack & Defense
             
            _________________________
            curlyhair, CKAP, dooble and 1 other person like this.
            1. grimnir

              grimnir Members of Antichat

              Joined:
              23 Apr 2012
              Messages:
              1,114
              Likes Received:
              830
              Reputations:
              231
              https://github.com/snoopysecurity/awesome-burp-extensions
              большой список расширений для BurpSuite
               
              _________________________
              1. grimnir

                grimnir Members of Antichat

                Joined:
                23 Apr 2012
                Messages:
                1,114
                Likes Received:
                830
                Reputations:
                231
                https://github.com/SilverPoision/Rock-ON
                Rock-On is a all in one Recon tool that will just get a single entry of the Domain name and do all of the work alone.
                 
                _________________________
                dooble and Spinus like this.
                1. Baskin-Robbins

                  Baskin-Robbins Reservists Of Antichat

                  Joined:
                  15 Sep 2018
                  Messages:
                  239
                  Likes Received:
                  809
                  Reputations:
                  212
                  https://github.com/juliocesarfort/public-pentesting-reports
                   
                  fandor9, dooble and seostock like this.
                  1. Spinus

                    Spinus Level 8

                    Joined:
                    23 Sep 2018
                    Messages:
                    491
                    Likes Received:
                    2,906
                    Reputations:
                    12
                    https://github.com/FlatL1neAPT/Red-Team-soft
                    А это что бы не думать, какой тулзой?)) https://github.com/m4ll0k/Awesome-Hacking-Tools
                     
                    dbagrov, seostock and Baskin-Robbins like this.
                    1. Baskin-Robbins

                      Baskin-Robbins Reservists Of Antichat

                      Joined:
                      15 Sep 2018
                      Messages:
                      239
                      Likes Received:
                      809
                      Reputations:
                      212
                      Удобненько рассортировано, маленький must have
                      https://github.com/zardus/ctf-tools
                       
                      K800, Spinus and seostock like this.
                      1. eminlayer7788

                        eminlayer7788 Member

                        Joined:
                        31 Jul 2015
                        Messages:
                        202
                        Likes Received:
                        78
                        Reputations:
                        8
                        Top 10 web hacking techniques of 2022

                        https://portswigger.net/polls/top-10-web-hacking-techniques-2022
                         
                        1. eminlayer7788

                          eminlayer7788 Member

                          Joined:
                          31 Jul 2015
                          Messages:
                          202
                          Likes Received:
                          78
                          Reputations:
                          8
                          ImageMagick: The hidden vulnerability behind your online images

                          https://www.metabaseq.com/imagemagick-zero-days/

                          https://github.com/duc-nt/CVE-2022-44268-ImageMagick-Arbitrary-File-Read-PoC
                           
                          Baskin-Robbins, b3 and dooble like this.
                          1. eminlayer7788

                            eminlayer7788 Member

                            Joined:
                            31 Jul 2015
                            Messages:
                            202
                            Likes Received:
                            78
                            Reputations:
                            8
                            PHP 7.4's function name and opcode manipulation to execute function declared in non-top-level scope with the null terminator trick.

                            https://www.leavesongs.com/PENETRATION/php-challenge-2023-oct.html

                             
                            dooble likes this.
                            1. eminlayer7788

                              eminlayer7788 Member

                              Joined:
                              31 Jul 2015
                              Messages:
                              202
                              Likes Received:
                              78
                              Reputations:
                              8
                              https://portswigger.net/research/top-10-web-hacking-techniques-of-2023
                               
                              1. eminlayer7788

                                eminlayer7788 Member

                                Joined:
                                31 Jul 2015
                                Messages:
                                202
                                Likes Received:
                                78
                                Reputations:
                                8
                                https://www.ambionics.io/blog/iconv-cve-2024-2961-p1
                                https://www.ambionics.io/blog/iconv-cve-2024-2961-p2
                                 
                                dooble likes this.
                                1. eminlayer7788

                                  eminlayer7788 Member

                                  Joined:
                                  31 Jul 2015
                                  Messages:
                                  202
                                  Likes Received:
                                  78
                                  Reputations:
                                  8
                                  https://www.elttam.com/blog/plormbing-your-django-orm/#content
                                   
                                  CyberTro1n likes this.
                                  1. eminlayer7788

                                    eminlayer7788 Member

                                    Joined:
                                    31 Jul 2015
                                    Messages:
                                    202
                                    Likes Received:
                                    78
                                    Reputations:
                                    8
                                    Unveiling TE.0 HTTP Request Smuggling: Discovering a Critical Vulnerability in Thousands of Google Cloud Websites

                                    https://www.bugcrowd.com/blog/unvei...bility-in-thousands-of-google-cloud-websites/
                                     
                                    CyberTro1n likes this.
                                    1. eminlayer7788

                                      eminlayer7788 Member

                                      Joined:
                                      31 Jul 2015
                                      Messages:
                                      202
                                      Likes Received:
                                      78
                                      Reputations:
                                      8
                                      Free Webinar - Mastering Web Research with Burp Suite

                                      https://trailofbits.registration.goldcast.io/events/5cfde272-7934-44ca-915e-1a7a507d494e
                                       
                                      CyberTro1n likes this.
                                      1. dooble

                                        dooble Members of Antichat

                                        Joined:
                                        30 Dec 2016
                                        Messages:
                                        231
                                        Likes Received:
                                        601
                                        Reputations:
                                        145
                                        Очередной ресерч от Orange Tsai
                                        https://blog.orange.tw/2024/08/confusion-attacks-en.html

                                        1. How a single ? can bypass Httpd’s built-in access control and authentication.
                                        2. How unsafe RewriteRules can escape the Web Root and access the entire filesystem.
                                        3. How to leverage a piece of code from 1996 to transform an XSS into RCE.
                                         
                                        Spinus, joelblack and CyberTro1n like this.