Skip to main content

Recently Updated Pages

XSS Payloads

Payloads

File is attached but it was copied from: https://github.com/ismailtasdelen/xss-payload-list.git ...

Updated 4 years ago by Togoboi

Configure Firewall & Splunk

Splunk CTF

Open Firewall When we try to access the login via internal network we won't be able to establish...

Updated 4 years ago by Togoboi

Splunk Installation

Splunk CTF

Before we install splunk we need to change some settings. First we remove the "virbr0" network i...

Updated 4 years ago by Togoboi

ARP Poisoning

Network

ARP Poisoning With ARP Poisoning you are able to be the Man in the middle and with that you can ...

Updated 4 years ago by Togoboi

SQLi

Web Applications

SQL injection in general SQL Injection is when an attacker enters a malicious or malformed query...

Updated 4 years ago by Togoboi

LFI - Local File Inclusion

Web Applications

An LFI vulnerability is found in various web applications. As an example, in the PHP, the followi...

Updated 4 years ago by Togoboi

Stabilize a Shell

Privilege Escalation

As soon you was able to get a shell on the target you can spawn a stabilized bash shell python -...

Updated 4 years ago by Togoboi

WinLin PEAS

Privilege Escalation

linPEAS LinPEAS is a script that search for possible paths to escalate privileges on Linux/Unix*...

Updated 4 years ago by Togoboi

Windows Vulnerabilities

Privilege Escalation

Printspoofer PrintSpoofer exploit that can be used to escalate service user permissions on Windo...

Updated 4 years ago by Togoboi

SUID PrivEsc Python

Privilege Escalation

SUID PrivEsc Python Some files has Permissions to be executed by any user with full permissions ...

Updated 4 years ago by Togoboi

Get the fuck out

Privilege Escalation

GTFOBins GTFOBins is a curated list of Unix binaries that can be used to bypass local security r...

Updated 4 years ago by Togoboi

WP Scan

Scanning

Sometimes your target has running a WordPress website running on their end. There is also a too...

Updated 4 years ago by Togoboi

NMAP

Scanning

NMAP in general NMAP is a free open source “Network Mapper” for network exploration or security ...

Updated 4 years ago by Togoboi

Nikto

Scanning

Nikto Nikto is a perl based security testing tool and this means it will run on most operating s...

Updated 4 years ago by Togoboi

FTP & SAMBA

Scanning

FTP Sometimes anonymous login is allowed on a FTP server. ftp <server/ip> During the login you...

Updated 4 years ago by Togoboi

Enum4Linux

Scanning

Enum4linux is a tool for enumerating information from Windows and Samba systems and is capable of...

Updated 4 years ago by Togoboi

GoBuster

Scanning

GoBuster scans the most common directories which are used on a WebApp / Website. To run this scan...

Updated 4 years ago by Togoboi

SSH Tunneling

Brute Force

Sometimes it can be that a target network is in another subnet and you are not able to access it ...

Updated 4 years ago by Togoboi

John the Ripper

Brute Force

John in general John the Ripper (JTR) is a fast, free and open-source password cracker.We will u...

Updated 4 years ago by Togoboi

Hydra

Brute Force

Hydra is a parallelized login cracker which supports numerous protocols to attack. It is very fas...

Updated 4 years ago by Togoboi