ABG3 @ABG314
Joined August 2020-
Tweets174
-
Followers11
-
Following722
-
Likes231
Fortinet did it again. Do they hire 2 year olds to code their software? I don’t get it… The gift that keeps on giving. CVE-2024-21762 Workaround : disable SSL VPN 🤦♂️ fortiguard.fortinet.com/psirt/FG-IR-24…
JavaScript Analysis for Pentesters | kpwn.de kpwn.de/2023/05/javasc…
We see a lot of threat actors in our Incident Response cases who disable or tamper with the local AV. The website privacy.sexy has a copy & paste script to turn off most of Defenders features. [1] How many of these modifications (or deactivations) will trigger an alert in your environment? @DebugPrivilege has written an excellent article about the various event logs Windows Defenders creates, in which event. [2] Run the commands on a test system, and look for gaps in your monitoring 🤓 [1] privacy.sexy [2] m365internals.com/2021/07/05/why…
THIS is an APT. No "cmd /c net user", just technical capability that's almost indistinguishable from magic
A very good writeup:- medium.com/@bug4y0u/how-i…
Super easy bug for new bug hunters 1. Login to the website and go to the profile/settings page 2. Logout 3. Press the back button of the browser 4. If you landed back on the profile/settings page credit: @dirtycoder0124 #BugBountytips #BugBounty #BugBountytip #infosec
Question of the day🤔: How to bypass rate limit restrictions on authentication endpoints? 🛡️ This is often one of the first checks when assessing a target but is frequently overlooked when there are restrictions. However, I've successfully bypassed over 50+ restrictions in my early days! 💪 Bounties can range anywhere from $250 to $3000, depending on the complexity of the issue. 💰 Have you encountered a login page or a forgot password page with OTP where rate limits have been introduced? 🕵️♂️ Here's how you can bypass some of these implementations: 1️⃣ 🕵️♀️ Google Captchas implemented? No worries, always try removing the captcha parameter or replace it with null and send the request without the captcha. Sometimes a fallback method allows you to get past the captcha requirement, making it vulnerable to a lack of rate limiting. 2️⃣ 🌐 IP restricted? Check if your IP was blocked and attempt to make a request using a different IP. If that works, you're in luck! You can usually bypass these limitations through IP rotation. Services like Brightproxy or Burp Suite IP rotate extension can assign a new IP address with every request. 3️⃣ 🤖 If nothing works, try appending %0d or %0d before the username (e.g., %[email protected]). This can sometimes trick the server into checking if %[email protected] is locked. If not, while processing the login attempt, it strips the %0d and makes an attempt for [email protected]. It's possible that %[email protected] may be blocked too after 5 attempts. In that case, keep appending an additional %0d after every 5 attempts (e.g., %0d%[email protected] and vice versa). 4️⃣ 🤯 Rate limit properly implemented? Always look for an alternative login or forgot password endpoint. This could be on one of the target's mobile apps or a legacy endpoint in the JS file. 5️⃣ 😓 None of the above methods work? Don't worry, we've got some more explicit tricks, and I'll be talking about them soon! Stay tuned! 🤫 Lesson of the day: Never assume that an endpoint is adequately protected against rate limit issues. Always explore ways to penetrate/bypass the implementation, and you'll be surprised at the results and win some nice bounties! 💎💰 #SecurityTips #BugBounty #HackerOne #BugCrowd #InfoSec #BugBountyTips 🔒🔍🔓🦠🕶️
200+ Hacking / Infosec pdfs Remember, always use this knowledge ethically and legally to make the digital realm safer for all! Check it out here : drive.google.com/drive/u/0/mobi… please follow me🚀🚀 like ❤️❤️❤️ Share this post to spread the word! 👍 #infosec #CyberSecurity #EthicalHacking #FollowMe #infosec #Hacking #infosecurity #Malware #BugBountytips #CTF #BugBounty #vulnerability #pwn #CyberSecurityAwareness #CyberSecurity #CyberSecuritytips @SaveToNotion @threadreaderapp
🚀 Exciting News! 🚀 I've just conquered the Twister machine in my OSCP journey! 🕵️♂️💻 👨💻 Now, I'm sharing my code and notes to help YOU tackle Twister and ace your OSCP too! 🎯 🔗 Check out ==-Nmap==== nmap -p- -sT -sV -A $IP nmap -p- -sC -sV $IP --0pen nmap -p- --script=vuln $IP ###HTTP-Methods nmap --script http-methods --script-args http-methods. url-path='/webs ite ' ### sed IPs: grep -oE '((1? [0-9] [0-9]? |2[0-4] [0- 9] |25[0-5])\.){3} (1? [0-9] [0-9]? |2 [0-4] [0-9] |25 [0-5] ) ' FILE --Script smb-enum-shares =EE======= =E==EE====E============E== EEE=E==E==: =========: ==zWPScan & SSL wpscan--url $URL --disable-tls-checks - -enumerate p --enumerate t --enumerate u ===WPScan Brute Forceing: wpscan --url $URL --disable-t ls-checks - U users -P /usr/share/wordlists/ rockyou. txt ==Aggressive Plugin Detection: wpscan --url $URL plugins-detection aggressive --enumerate p ======================================== c==Nikto with SSL and Evasion nikto --host $IP -ssl -evasion 1 SEE EVASION MODALITIES. E=================================== ==dns_recon dnsrecon -d yourdomain. com == ===9obuster directory gobuster dir -u $URL -W /opt/SecLists/Dis covery/Web- Content/ raft-medium-directories. txt -k - t 30 ===gobuster files gobuster dir -u $URL -W /opt/SecLists/Dis covery/Web- Content/raft-medium-files. txt -k -t 30 ==00buster for SubDoma in brute forcing: gobuster dns -d doma in.org -w /opt/SecLists/Discovery/DNS/subdomains- toplmillion-110000. txt -t 30 "just make sure any DNS name you find resolves to an in-scope address before you test it! ====E=======: =H==E====E====E===E==== ==Extract IPs from a text file. grep -o '[0-9]\{1, 3\}\. [0-9]\{1,3\}\. [0- 9]\{1,3\}\. [0-9]\{1, 3\}' nmapfile. txt ===Wfuzz XSS Fuzzing===: wfuzz -C -Z file, /opt/SecLists/Fuzzing/XSS,/XSS- BruteLogic. txt "$URL" wfuzz -C -Z file, /opt/SecLists/ Fuzzing/XSS,/XSS- JhaddiX. txt "$URL" ===C0MMAND INJECTION WITH POST DATA wfuzz -C -Z file, /opt/SecLists/Fuzzing/command- injection-commix. txt -d "doi=FUZZ" "$URL" ===Test for Paramter Existence! wfuzz -C -Z file, /opt/SecLists/Dis covery /Web- Content/burp-parameter-names. txt "$URL" ===AUTHENTICATED FUZZING DIRECTORIES: wfuzz -C -Z file, /opt/SecLists/Dis cove ry/Web- Content/ raft-medium-directories . txt --hc 404 -d "SESSIONID=value" "$URL" =AUTHENTICATED FILE FUZZING: wfuzz -C -Z file, /opt/SecLists/Discove ry/Web- Content/ raft-med ium-files . txt --hc 404 - d "SESSIONID=value" "$URL" ===FUZZ Directories : wfuzz -C -Z file, /opt/SecLists/Dis covery/Web- Content/ raft-la rge-d irectories. txt --hc 404 "$URL" ===FUZZ FILES: wfuzz -C -Z file, /opt/SecLists/Dis covery/Web- Content/ raft-la rge-files . txt --hc 404 "$URL" 📚 Learn, practice, and let's achieve OSCP success together! 💪🏆 #OSCP #Cybersecurity #EthicalHacking #TwisterMachine #InfoSec #GitHub #LearnToHack @SaveToNotion @threadreaderapp
OSCP 2023 Exam Preparation Guide lnkd.in/dsAUXNph by John J Extra Links: lnkd.in/dCjZGXPq lnkd.in/dfmqy7wd lnkd.in/dfGCpV4Z lnkd.in/dEvfjCxu lnkd.in/d3bv3JKk lnkd.in/eBee79k lnkd.in/e__s4AH lnkd.in/ev4B-ZF lnkd.in/euApgZ8 lnkd.in/eKimv9k lnkd.in/eNXxRUy lnkd.in/eJNZ64U lnkd.in/e_Hw2fK lnkd.in/e6V2VE6 lnkd.in/eUa7m6y lnkd.in/eWhpmU9 lnkd.in/eJCfshN lnkd.in/d_U9SQ9 lnkd.in/dPPtpejv lnkd.in/drKhHYfd lnkd.in/dmvipXdp lnkd.in/dW_29vyQ lnkd.in/dV7SUxbx lnkd.in/dKmvdTNj #OSCP #OSCPPreparation #Hacking #EthicalHacker #PenTest #OffensiveSecurity #Certified #penetrationtesting #AD #activedirectory
We just released Reflective Call Stack Detections and Evasions! This was co-authored by our @XForce Red intern Dylan Tran @d_tranman! Dylan is wicked smart and it was fun working with him! Check it out!🥷 securityintelligence.com/x-force/reflec…
🌶️ GPTFUZZER: Red Teaming Large Language Models with Auto-Generated Jailbreak Prompts 🌶️ paper: arxiv.org/abs/2309.10253 "GPTFuzz automates the generation of jailbreak templates for red-teaming LLMs" "results indicate that GPTFuzz consistently produces jailbreak templates with a high success rate, surpassing human-crafted templates" "GPTFuzz achieves over 90% attack success rates against ChatGPT and Llama-2" with @dataisland99 @xingxinyu
Active Directory Cheat Sheet github.com/Integration-IT…
When investigating a suspicious process on Linux, try this:
strings /proc/
Juniper J-Web - Remote Code Execution 🔥 - CVE-2023-36845
Nearly 14,000 Juniper devices are affected, as a search on Shodan shows:
Dork : title:"Juniper" http.favicon.hash:2141724739
Poc:
curl
"Fast Guide" - net, dclist, nltest, adfind, kerberoast, seatbelt, net-gpppassword, sharefinder, etc. #ContiLeaks
ShareFinder: How Threat Actors Discover File Shares - The DFIR Report thedfirreport.com/2023/01/23/sha…
Full statement from ALPHV, regarding the attack on MGM Resorts. 🧵 1/2
JoeFella📯🇩🇪�... @FellaJS
6K Followers 5K Following NIE WIEDER muß heißen, wir schützen auch andere vor einem WIEDER! 🇺🇦 @fellajs.bsky.social
F. Mosel🪐 @friedhelm_mosel
11K Followers 10K Following 🇩🇪-Der Unbeugsame-🇪🇺 ich bin für Frieden, ich bin für die Ukraine 🇺🇦Ruhm der Ukraine🇺🇦, putin ist ein Völkermörder
Megan Gerald @Megansm_Gerald
10 Followers 356 Following Found different beauties from all US states 😉 They are ready to meet Nudes in profile! Watching this https://t.co/6NTyHqKwQV
Xappy @theXappy
142 Followers 635 Following Security Researcher 🩺 Into Windows(.NET)/iOS/protocols reversing and forensics.
Ruth @ruth_kuehn71
2K Followers 4K Following
Jason Knight @knightmese
242 Followers 1K Following Miami Hurricanes and Dallas Cowboys fan. Percussive maintenance network admin. Both sides suck. Arrest Epstein’s clients.
jade @jaded_boots
388 Followers 250 Following MILF + HOTWIFE💜I’d say we are all here to have some fun and excitement. I definitely don’t look like the dirty little whore I am on the inside. Cum on…
Kristi @Kristi57150275
65 Followers 5K Following 💛🌝 I'm Кгisti!⁉️ Нeге is mу album аnd my nакеd photоs!)) Vote foг mе, please:😗 https://t.co/be36zAnjW9
Fishing With The Wils... @WilsonsFishing
952 Followers 674 Following Husband and Wife who love fishing and the outdoors.
Mac @MarteaseLures
12K Followers 12K Following Custom Fishing Lure Maker Owner MarTease Lures/Precision Lures Oregon Ducks football junkie
Mrgunsngear @Mrgunsngear
376K Followers 4K Following The Mrgunsngear Channel Twitter page. We are an organization dedicated to restoring the civil rights of Americans 🇺🇸
Blue Team News @blueteamsec1
57K Followers 9K Following The cybersecurity home for the latest #BlueTeam, #DFIR, and #ThreatHunting news and tools.
Nicolas Krassas @Dinosn
158K Followers 777 Following Head of Threat & Vulnerability Mgmt @ Henkel AG & Co. KGaA https://t.co/NC1orlKZLB Posting content that I find interesting.
Hacking Articles @hackinarticles
301K Followers 480 Following House of Pentesters Join us: https://t.co/Y6XOlSP7YA
Horizon3 Attack Team @Horizon3Attack
12K Followers 54 Following @Horizon3ai Attack Team | Security Research | Exploit Dev | TTPs
Max Ircobo @NAFOfrumzl
24K Followers 12K Following Been hacked, and all I got was some sh*tty followers and one month of blue check.
🎗️Тато Ве�... @ajohna
23K Followers 24K Following Here to support Ukraine - Слава Україні! NO 2 moscal law, NO 2 muscovy influence, NO 2 Putin mafia. MUGA Fo Shur
Richard Woodruff 🇺... @frontlinekit
134K Followers 10K Following 🇬🇧 British volunteer supporting Ukraine since 2022. We Don't Make Drones. Awarded for contributions to the AFU by General Valerii Zaluzhnyi 🎖 Based in Lviv.
Fellaraktar🇺🇦 @fellaraktar
46K Followers 3K Following #NAFO #WeAreNAFO - Slava Ukraini - NAFO Expansionist - Nonsense Pronouncer - Meme Creator - Anglo F’n Saxon - Trained Zamboni Driver - Volunteer @wilendhornets
Ben 🌻🍉🎗️ @FreeUkraine91
42K Followers 20K Following And you will know the truth, and the truth will set you free - John 8:32. Hiding under Putin’s desk, waiting to strike. Fella. 🐱
Ïndrek Lobus 🇪�... @IndrekLobus
17K Followers 10K Following philosophy PhD, software developer, #PrimitiveBalticHooligan, #NAFO fella, we ourselves will become sons of bitches if only to spite ruZZia, Слава Україні!
Сен-Клер @MthrSuperiorBen
38K Followers 10K Following @uafemmechanics Founder, mentor of Female Mechanics Club of Kramatorsk💕 Слава Україні!🔧👩🏼🔧🇺🇦
Кобзар 🇨🇦... @CanadianKobzar
46K Followers 4K Following 🪙Toonie Tuesday. 🐝Wild Hornets. 🐱Angels of Donbas. 🧵Kobzar Chronicles. ⬛️🟧Hirnyky ⚒️ I’m back. again.
Gavril Ducu 🇷🇴�... @DucuGavril
39K Followers 16K Following born by the KGB raised by the CIA mindreader digital ventriloquist #fella #WeAreNAFO Heavy Bonker Award 🏅⚡Every coffee helps #Edumacation and the @NAFOforum👇
Joachim Fallert @jfallert
14K Followers 8K Following Familienvater, Inhaber Ingenieurbüro, Oberst d.R. (OF-5), Landesvorsitzender Reservistenverband BW, FDGO+Wehrpflicht-Fan, hier mit meiner privaten Meinung.
Anna @AnnaDeMilanese
57K Followers 19K Following Geopolitik & Militärstrategie. 🌍 Analysen, Nachrichten zu globalen Konflikten, hybrider Kriegsführung, Focus USA, Europa, Ukraine, Russland. ♟️
JoeFella📯🇩🇪�... @FellaJS
6K Followers 5K Following NIE WIEDER muß heißen, wir schützen auch andere vor einem WIEDER! 🇺🇦 @fellajs.bsky.social
F. Mosel🪐 @friedhelm_mosel
11K Followers 10K Following 🇩🇪-Der Unbeugsame-🇪🇺 ich bin für Frieden, ich bin für die Ukraine 🇺🇦Ruhm der Ukraine🇺🇦, putin ist ein Völkermörder
ClancysSon/ #Fellaweb... @ClancysSon
9K Followers 4K Following #Haltung! #StillStanding! #Westbindung #Wölki 🇺🇦, 🇮🇱, CIA, Mossad, #NAFO #FckPutim, #FckRussia, #FckTrump ⛔️: DM, Replies
domjazeduch 💉💉�... @domjazeduch
7K Followers 7K Following Ich bin zu jung, um meine Biografie zu schreiben und zu alt, um ewig jung zu bleiben. Putin ist der Enkel von Stalins Koch. #NAFOfellas see a fella, add a fella
AA1973 | 🇺🇦 �... @Andreas_Adam
5K Followers 7K Following #SAVEMARIUPOL // #STANDUPFORUKRAINE ++ #ArmUkraineNow ++ #WaffenlieferungsUltras ++ #IStandWithRoderichKiesewetter
TwaffoCeo @MattPPea
14K Followers 10K Following "biggest scum on the Internet" - D. Sacks 🇬🇧🇺🇦🇮🇱🇬🇪 https://t.co/qcxUbLeKjC https://t.co/JZJxOInTYC Propaganda analyst and debunker
Klaus Römer @KlausRmer5
2K Followers 2K Following Ceci n'est pas un Fella NAFO expansion is non negotiable. Ceterum censeo imperium muscovium esse delendum. Never again is now. F*ck Nazis!
Hoplite Industries @Hoplite_Ind
20K Followers 131 Following Advancing the next generation of tactical technology
krus🪖 @krus_chiki
116K Followers 3K Following Purveyor of Fine Antiquities Import/Export. OSINT. follows/retweets not endorsements
Louis vil LeGun @LouisvilleGun
53K Followers 2K Following Firearms retard. DZ enthusiast. British opinions on gun control stopped being relevant in 1776. Trigger warning: I have opinions on things other than guns too.
PNWGUERRILLA @pnwguerrilla
116K Followers 838 Following OWNER of ODGGSUPPLY, I sell Military Surplus & stuff. Youtube: https://t.co/P6dOxdGBuS
Goon_Vibes_Only @VibesGoon
5K Followers 2K Following
Shadz @Shadzey1
54K Followers 4K Following Abyss Watcher, Appalachian Sneak Reaper & Wendigo | #1A #2A | Sun Eater | Sometimes cool | Omertà is law. | Esse quam videri | 🏴☠️
War Doll @thewardoll
43K Followers 471 Following PREPARE THE WAY 🏴 Apparel and Media Production since 2015.
Kron @Kronykal
46K Followers 1K Following TOP SECRET // NOFORN - Likes != Agreement. I’m complicated.
Psyware @Psy_ware
21K Followers 1K Following 2A Absolutist, lock picking, grappling, psychology. Designer of hoodies, chaser of hobbies.
Stephan Berger @malmoeb
29K Followers 1K Following Head of Investigations @InfoGuardAG https://t.co/A5lnFAu7eX
Garbage Human @GarbageHuman24
455K Followers 972 Following Monitoring and documenting the collapse in real time
Signal @signalapp
622K Followers 23 Following Signal is a nonprofit end-to-end encrypted communications app. Privacy isn’t an optional mode, it’s the way Signal works. Every message, every call, every time.
Austinn Jay @austin88998833
351 Followers 826 Following I don’t do deposits, buy phone cards or any other bullshit up front. P411 Verified + 33 1/3 https://t.co/yceJMCiNyO…
DB Firearms @ArthurClaudeen
25K Followers 982 Following Guncad Magnate Follower of Jesus Christ Check your local and state laws; I am not responsible for your felonies
Cthulhu ( ;,;) @Cthulhu_Answers
15K Followers 6K Following ( ;,;) 🌮 🐙 ⛤ Gravitic Propulsion Engineer, Threat Landscaper, Eldritch Historian, Defcon TentacleOps, Xitter Mall Cop #CoT
End Wokeness @EndWokeness
3.9M Followers 1K Following Fighting, exposing, and mocking wokeness. DM for submissions
Aveees @The_Aveees
15K Followers 113 Following Owner and Founder of Aves Engineering & Aves Rails. Firearm Designer and Additive Manufacturing Enthusiast.
























