Forwarded from Zishan Ahamed Thandar 🇮🇳
🔰 Updated Bug Bounty tool List!
dnscan https://github.com/rbsec/dnscan
Knockpy https://github.com/guelfoweb/knock
Sublist3r https://github.com/aboul3la/Sublist3r
massdns https://github.com/blechschmidt/massdns
nmap https://nmap.org
masscan https://github.com/robertdavidgraham/masscan
EyeWitness https://github.com/ChrisTruncer/EyeWitness
DirBuster https://sourceforge.net/projects/dirbuster/
dirsearch https://github.com/maurosoria/dirsearch
Gitrob https://github.com/michenriksen/gitrob
git-secrets https://github.com/awslabs/git-secrets
sandcastle https://github.com/yasinS/sandcastle
bucket_finder https://digi.ninja/projects/bucket_finder.php
GoogD0rker https://github.com/ZephrFish/GoogD0rker/
Wayback Machine https://web.archive.org
waybackurls https://gist.github.com/mhmdiaa/adf6bff70142e5091792841d4b372050
Sn1per https://github.com/1N3/Sn1per/
XRay https://github.com/evilsocket/xray
wfuzz https://github.com/xmendez/wfuzz/
patator https://github.com/lanjelot/patator
datasploit https://github.com/DataSploit/datasploit
hydra https://github.com/vanhauser-thc/thc-hydra
changeme https://github.com/ztgrace/changeme
MobSF https://github.com/MobSF/Mobile-Security-Framework-MobSF/
Apktool https://github.com/iBotPeaches/Apktool
dex2jar https://sourceforge.net/projects/dex2jar/
sqlmap http://sqlmap.org/
oxml_xxe https://github.com/BuffaloWill/oxml_xxe/
XXE Injector https://github.com/enjoiz/XXEinjector
The JSON Web Token Toolkit https://github.com/ticarpi/jwt_tool
ground-control https://github.com/jobertabma/ground-control
ssrfDetector https://github.com/JacobReynolds/ssrfDetector
LFISuit https://github.com/D35m0nd142/LFISuite
GitTools https://github.com/internetwache/GitTools
dvcs-ripper https://github.com/kost/dvcs-ripper
tko-subs https://github.com/anshumanbh/tko-subs
HostileSubBruteforcer https://github.com/nahamsec/HostileSubBruteforcer
Race the Web https://github.com/insp3ctre/race-the-web
ysoserial https://github.com/GoSecure/ysoserial
PHPGGC https://github.com/ambionics/phpggc
CORStest https://github.com/RUB-NDS/CORStest
Retire-js https://github.com/RetireJS/retire.js
getsploit https://github.com/vulnersCom/getsploit
Findsploit https://github.com/1N3/Findsploit
bfac https://github.com/mazen160/bfac
WPScan https://wpscan.org/
CMSMap https://github.com/Dionach/CMSmap
Amass https://github.com/OWASP/Amass
Extra Tools
http://projectdiscovery.io
====================
Hacking Telegram Groups
https://BugCrowd.t.me
https://HackerTrain.t.me
https://BugCrowdChat.t.me
Hacking Telegram Channel
https://www.tgoop.com/hackersHandbook
https://www.tgoop.com/HackTheBox_Training
https://www.tgoop.com/ZishanAdThandarChannel
My LinkedIN:
https://www.linkedin.com/in/zishanadthandar/
My Link Tree:
https://zishanadthandar.github.io/linktree/
WhatsApp Community:
https://chat.whatsapp.com/GR2RD11phmy7mTWlGiALNE
dnscan https://github.com/rbsec/dnscan
Knockpy https://github.com/guelfoweb/knock
Sublist3r https://github.com/aboul3la/Sublist3r
massdns https://github.com/blechschmidt/massdns
nmap https://nmap.org
masscan https://github.com/robertdavidgraham/masscan
EyeWitness https://github.com/ChrisTruncer/EyeWitness
DirBuster https://sourceforge.net/projects/dirbuster/
dirsearch https://github.com/maurosoria/dirsearch
Gitrob https://github.com/michenriksen/gitrob
git-secrets https://github.com/awslabs/git-secrets
sandcastle https://github.com/yasinS/sandcastle
bucket_finder https://digi.ninja/projects/bucket_finder.php
GoogD0rker https://github.com/ZephrFish/GoogD0rker/
Wayback Machine https://web.archive.org
waybackurls https://gist.github.com/mhmdiaa/adf6bff70142e5091792841d4b372050
Sn1per https://github.com/1N3/Sn1per/
XRay https://github.com/evilsocket/xray
wfuzz https://github.com/xmendez/wfuzz/
patator https://github.com/lanjelot/patator
datasploit https://github.com/DataSploit/datasploit
hydra https://github.com/vanhauser-thc/thc-hydra
changeme https://github.com/ztgrace/changeme
MobSF https://github.com/MobSF/Mobile-Security-Framework-MobSF/
Apktool https://github.com/iBotPeaches/Apktool
dex2jar https://sourceforge.net/projects/dex2jar/
sqlmap http://sqlmap.org/
oxml_xxe https://github.com/BuffaloWill/oxml_xxe/
XXE Injector https://github.com/enjoiz/XXEinjector
The JSON Web Token Toolkit https://github.com/ticarpi/jwt_tool
ground-control https://github.com/jobertabma/ground-control
ssrfDetector https://github.com/JacobReynolds/ssrfDetector
LFISuit https://github.com/D35m0nd142/LFISuite
GitTools https://github.com/internetwache/GitTools
dvcs-ripper https://github.com/kost/dvcs-ripper
tko-subs https://github.com/anshumanbh/tko-subs
HostileSubBruteforcer https://github.com/nahamsec/HostileSubBruteforcer
Race the Web https://github.com/insp3ctre/race-the-web
ysoserial https://github.com/GoSecure/ysoserial
PHPGGC https://github.com/ambionics/phpggc
CORStest https://github.com/RUB-NDS/CORStest
Retire-js https://github.com/RetireJS/retire.js
getsploit https://github.com/vulnersCom/getsploit
Findsploit https://github.com/1N3/Findsploit
bfac https://github.com/mazen160/bfac
WPScan https://wpscan.org/
CMSMap https://github.com/Dionach/CMSmap
Amass https://github.com/OWASP/Amass
Extra Tools
http://projectdiscovery.io
====================
Hacking Telegram Groups
https://BugCrowd.t.me
https://HackerTrain.t.me
https://BugCrowdChat.t.me
Hacking Telegram Channel
https://www.tgoop.com/hackersHandbook
https://www.tgoop.com/HackTheBox_Training
https://www.tgoop.com/ZishanAdThandarChannel
My LinkedIN:
https://www.linkedin.com/in/zishanadthandar/
My Link Tree:
https://zishanadthandar.github.io/linktree/
WhatsApp Community:
https://chat.whatsapp.com/GR2RD11phmy7mTWlGiALNE
GitHub
GitHub - rbsec/dnscan
Contribute to rbsec/dnscan development by creating an account on GitHub.
Forwarded from Zishan Ahamed Thandar 🇮🇳
Client Side Template Injection to Cross Site Scripting
via Vulnerable AngularJS dependencies exploit
https://youtu.be/Ayfh93tqAgw
Must SUBSCRIBE for future update
via Vulnerable AngularJS dependencies exploit
https://youtu.be/Ayfh93tqAgw
Must SUBSCRIBE for future update
YouTube
Coinjar XSS PoC | Client side Template Injection to Reflected XSS [Rewarded NOTHING]
Coinjar | Client side Template Injection to Reflected XSS
Vulnerability on AngularJS
Reported on 2 February, 19
Fixed on March, 19
They Never replied (they claimed falsely on there program page that they replied in three days) and they fixed it.
When I contacted…
Vulnerability on AngularJS
Reported on 2 February, 19
Fixed on March, 19
They Never replied (they claimed falsely on there program page that they replied in three days) and they fixed it.
When I contacted…
image_2024-08-13_22-52-20.png
2.9 MB
Cross Site Scripting Mindmap
Forwarded from Zishan Ahamed Thandar 🇮🇳
⚠️⚠️⚠️ Cyber Security Job Post Scam (Must Watch)
https://youtu.be/T7STBch1N0w
https://youtu.be/T7STBch1N0w
YouTube
Sophisticated Job Post Scam [ EXPOSED ]! How Phishing SCAM Leads to Cryptocurrency Loss (MUST WATCH)
🚨 WARNING: A new, sophisticated job post scam is targeting job seekers with the potential for devastating cryptocurrency losses! In this video, we uncover the shocking details behind a modern phishing scheme that uses fake job advertisements to steal your…
Hunting methodology and experience of my First Stored XSS on Edmodo.com
https://github.com/ZishanAdThandar/WriteUps/blob/main/bugbounty/1.md
https://github.com/ZishanAdThandar/WriteUps/blob/main/bugbounty/1.md
GitHub
WriteUps/bugbounty/1.md at main · ZishanAdThandar/WriteUps
CTF and Bug Bounty Hunting WriteUps. . Contribute to ZishanAdThandar/WriteUps development by creating an account on GitHub.
Forwarded from CTF Training
BurpSuite Proxy Toggle Lite
A lightweight addon for firefox to switch proxy in one click. Easy to use, save times and consumes less RAM. Also, it's a Open Source.
Source Code https://github.com/ZishanAdThandar/burptoggle
Firefox AddOn Page https://addons.mozilla.org/en-US/firefox/addon/burp-proxy-toggler-lite
#tools #burpsuite #firefox #addon #infosectools #cybersec
A lightweight addon for firefox to switch proxy in one click. Easy to use, save times and consumes less RAM. Also, it's a Open Source.
Source Code https://github.com/ZishanAdThandar/burptoggle
Firefox AddOn Page https://addons.mozilla.org/en-US/firefox/addon/burp-proxy-toggler-lite
#tools #burpsuite #firefox #addon #infosectools #cybersec
GitHub
GitHub - ZishanAdThandar/burptoggle: Burp Suite Proxy Toggler Lite Add-on for Mozilla Firefox.
Burp Suite Proxy Toggler Lite Add-on for Mozilla Firefox. - GitHub - ZishanAdThandar/burptoggle: Burp Suite Proxy Toggler Lite Add-on for Mozilla Firefox.
The best Hacking Courses & Certs (not all these)? Your roadmap to Pentester success.
https://youtu.be/Zfz3ZN2dTDM
https://youtu.be/Zfz3ZN2dTDM
YouTube
The best Hacking Courses & Certs (not all these)? Your roadmap to Pentester success.
This is your path to becoming a Pentester in 2023. The best courses and best cert. Big thanks to Rana for answering so many of your questions!
Thanks for the cool Solar Generator Jackery!
Official Jackery website:
USA: https://jackery.com/products/solar…
Thanks for the cool Solar Generator Jackery!
Official Jackery website:
USA: https://jackery.com/products/solar…
Forwarded from Zishan Ahamed Thandar 🇮🇳
Burp suite proxy toggler firefox addOn
Install | Source Code
Pros:
1. Open Source, FOSS
2. Totally Free
3. Just one click to switch (Saves a lot of time)
4. Easy to use
5. Very Lite Weight, Takes almost no RAM, Saves Memory
6. Pre-configured for Burp Suite Proxy
7. Specially made for Pentesters and Bug Bounty Hunters
Source Code | Firefox AddON Install»
Join Our Discord»
Install | Source Code
Pros:
1. Open Source, FOSS
2. Totally Free
3. Just one click to switch (Saves a lot of time)
4. Easy to use
5. Very Lite Weight, Takes almost no RAM, Saves Memory
6. Pre-configured for Burp Suite Proxy
7. Specially made for Pentesters and Bug Bounty Hunters
Source Code | Firefox AddON Install»
Join Our Discord»
addons.mozilla.org
Burp Proxy Switch Toggle Lite by ZishanAdThandar – Get this Extension for 🦊 Firefox (en-US)
Download Burp Proxy Switch Toggle Lite by ZishanAdThandar for Firefox. Ethical Hackers|Bug Hunters|Pentesters|Cyber Security Researcher.
Lightweight Burp Proxy switch.
Note: Goto "about:addons" > "Extensions > Click on Burp >"Allow" "Run in Private Windows"…
Lightweight Burp Proxy switch.
Note: Goto "about:addons" > "Extensions > Click on Burp >"Allow" "Run in Private Windows"…
KHALED RAES COMPLETED OSCP+ IN JUST TWO MONTHS
https://medium.com/@0xkhaled/how-i-passed-oscp-in-two-months-14685a324e83
Join our Discord: https://discord.gg/T47v67eVT4
https://medium.com/@0xkhaled/how-i-passed-oscp-in-two-months-14685a324e83
Join our Discord: https://discord.gg/T47v67eVT4
Medium
How I passed OSCP+ in two months
In this blog, I will share my exam journey, starting from the first day, till passing the exam. DISCLAIMER!! Don’t miss the tips and…
Forwarded from Zishan Ahamed Thandar 🇮🇳
0xdf coming to bsides Pakistan live session
https://www.linkedin.com/events/7264218646950858752/about/
https://www.linkedin.com/events/7264218646950858752/about/
Linkedin
Gupshup Talk - 0xdf | LinkedIn
Welcome to BsidesPK Gupshup talks. We invite professional guests for a casual talk with the community and discuss their perspectives about the field of cybersecurity, discuss about their journey in the field and answer questions from the community.
Forwarded from CTF Training
This cheatsheet is aimed at the CTF Players and Beginners to help them understand the fundamentals of Privilege Escalation with examples.
https://github.com/Ignitetechnologies/Privilege-Escalation
Join our Discord: https://discord.gg/T47v67eVT4
https://github.com/Ignitetechnologies/Privilege-Escalation
Join our Discord: https://discord.gg/T47v67eVT4
GitHub
GitHub - Ignitetechnologies/Privilege-Escalation: This cheasheet is aimed at the CTF Players and Beginners to help them understand…
This cheasheet is aimed at the CTF Players and Beginners to help them understand the fundamentals of Privilege Escalation with examples. - Ignitetechnologies/Privilege-Escalation
Forwarded from CTF Training
YouTube
[$500] Reflected XSS on HackerOne $500 Bounty! 💰 Reported by @todayisnew Bug Bounty Report Explained
Reflected XSS reported to hackerone.com by todayisnew
Rewarded $450 + $50
Report: https://hackerone.com/reports/840759
💡 Stay till the end for exclusive bug bounty hunting tips!
🔥 Don’t forget to Like, Comment, and Subscribe for more awesome content!
🎯 Hashtags:…
Rewarded $450 + $50
Report: https://hackerone.com/reports/840759
💡 Stay till the end for exclusive bug bounty hunting tips!
🔥 Don’t forget to Like, Comment, and Subscribe for more awesome content!
🎯 Hashtags:…