PinnedPublished inT3CHFull Account Takeover via Password Reset Link ManipulationIntroduction In 2021, while exploring the diverse landscape of cybersecurity vulnerabilities reported by the bug bounty community, I came…Feb 1, 2024Feb 1, 2024
PinnedPublished inSystem WeaknessUsing Shodan to Find and Exploit FTP Servers with Anonymous Access: A Step-by-Step GuideThis tutorial will walk you through a simple yet effective method to identify FTP servers that allow anonymous access. Anonymous FTP access…Jun 12, 2024Jun 12, 2024
PinnedTop 3 Essential Tools for Directory and File Enumeration in Penetration TestingIn the dynamic world of cybersecurity, bug hunting, and penetration testing are crucial for identifying and mitigating vulnerabilities. An…Jan 2, 2024Jan 2, 2024
Published inSystem WeaknessCVE-2024–53677: A Critical Vulnerability in Apache Struts Exposing Over 83,000 TargetsA critical vulnerability, CVE-2024–53677, has been identified in the popular Apache Struts framework, threatening the security of thousands…Dec 18, 2024Dec 18, 2024
Published inT3CHUnveiling DetectDee: Advanced OSINT for Social Media Account DiscoveryOne such promising tool is DetectDee, an open-source project designed to identify social media accounts using usernames, email addresses…Dec 16, 2024Dec 16, 2024
Published inSystem WeaknessUnlock the Secrets of Mobile Security: Advanced IMEI Tools and Techniques Exposed!Advanced IMEI Modification: Ethical Insights and High-Level Techniques for Cybersecurity ProfessionalsDec 11, 20241Dec 11, 20241
Published inSystem WeaknessA Deep Dive into Nmap Scripts for Web Application TestingA Step-by-Step Guide to Leveraging Nmap’s Most Advanced Scripts for Comprehensive Web Application Security AnalysisNov 13, 2024Nov 13, 2024
Published inSystem WeaknessBeware of the Malicious Python Package ‘fabrice’: How Typosquatting is Stealing AWS CredentialsUnderstanding how a malicious PyPI package targeted unsuspecting developers to exfiltrate AWS credentials and establish backdoors on Linux…Nov 10, 2024Nov 10, 2024
CVE-2023–32191: Why You Need to Patch Your Rancher Kubernetes Engine (RKE) NOW to Avoid…A new vulnerability appears with a CVSS score of 10, it’s a five-alarm fire for IT and security teams. This is the case with…Nov 9, 2024Nov 9, 2024