Kn1ght

36 posts

Kn1ght

Kn1ght

@hrxknight

Web Penetration Tester, Security researcher, bug bounty hunter 🐞 Vietnamese 🇻🇳🇻🇳🇻🇳

Katılım Ağustos 2024
173 Takip Edilen9 Takipçiler
Kn1ght retweetledi
Nasreddine Bencherchali
Nasreddine Bencherchali@nas_bench·
I have spent some time this past day to investigate NodeJS source code and how a typical process tree from a react/next.js app will look like. If you are building detections for React2Shell give this a read. as it'll help you identify the right strings to use to filter down FPs and what anomalous look might like. github.com/nasbench/Misc-…
Nasreddine Bencherchali tweet mediaNasreddine Bencherchali tweet mediaNasreddine Bencherchali tweet media
English
2
29
126
13.3K
Kn1ght retweetledi
Dluka
Dluka@4kulD·
🚨XSS Found🚨 1⃣ katana -u "url" -d 5 -ps -pss waybackarchive,commoncrawl,alienvault -kf -jc -fx -ef woff,css,png,svg,jpg,woff2,jpeg,gif,svg thx man @coffinxp7 🥂 2⃣ nuclei -t /string/dast/ -dast -headless 3⃣ Confirm payloads!
Dluka tweet media
English
6
62
393
20.2K
Kn1ght retweetledi
Coffin
Coffin@lostsec_·
After going through all the comments and questions about setting up IDN domains and using Punycode based emails, I finally made a video that covers everything step by step. I’m confident this will help many of you land some serious bounties! youtu.be/Cj1sOFHDClM?si…
YouTube video
YouTube
English
17
37
297
63K
Kn1ght retweetledi
Mr_mars_hacker
Mr_mars_hacker@Mr_mars_hacker·
"Business logic allows any user to be blocked from creating an account" @jeetpal2007/business-logic-allows-any-user-to-be-blocked-from-creating-an-account-6a7ab7013ccc" target="_blank" rel="nofollow noopener">medium.com/@jeetpal2007/b… #bugbounty #bugbountytips
English
0
32
83
4.2K
Kn1ght retweetledi
Intigriti
Intigriti@intigriti·
Want to master client-side bugs? 😎 Check out this extensive GitHub repository with tens of different resources curated by @zomasec! 🔗 github.com/zomasec/client…
Intigriti tweet media
English
3
98
362
18.8K
Kn1ght retweetledi
Alexandrio
Alexandrio@alexbindrei·
Vibe coding? Nah, Hacking with a vibe 🌆🗽
Alexandrio tweet media
English
18
25
481
27.3K
Kn1ght retweetledi
Gospel
Gospel@4osp3l·
While learning and practicing website application security and exploitation, also learn to hack APIs effectively. portswigger.net/web-security/l…
Gospel tweet media
English
1
8
65
2.8K
Kn1ght retweetledi
Clint Gibler
Clint Gibler@clintgibler·
🔥 𝐀𝐈 𝐑𝐞𝐝 𝐓𝐞𝐚𝐦𝐢𝐧𝐠 𝐏𝐥𝐚𝐲𝐠𝐫𝐨𝐮𝐧𝐝 𝐋𝐚𝐛𝐬 from @Microsoft 12 free labs to up-level your hacking skills from the “AI Red Teaming in Practice” Black Hat training, covering: - Credential exfiltration - Extracting a secret from the metaprompt - Indirect prompt injection - and more! Super cool that this was open sourced, huge shout-out to Dr. Amanda Minnich (AIRT), Gary L., Martin Pouliot, and anyone else involved 🙏 🔗 github.com/microsoft/AI-R…
Clint Gibler tweet media
English
2
86
259
15.8K
Kn1ght retweetledi
Burp Suite
Burp Suite@Burp_Suite·
Want to quickly and easily import BChecks and Bambdas to your library? 👀 Check out Extensibility Helper on the BApp Store! 📄 Pull scripts directly from the PortSwigger community repositories, or provide your own for a custom store experience.
English
2
10
65
4.1K
Kn1ght retweetledi
Yousef
Yousef@iYousefAlotaibi·
Built a Burp Suite extension to run SQLmap directly from the GUI. No more saving HTTP requests + jumping to terminal. Just: – Mark param with * – Right-click → Send to SQLmap – Pick options → Run Linux-only for now. Windows support coming soon. Full write-up: @YousefAlotaibi/burp-suite-integration-with-sqlmap-8ee7c65e2a1e" target="_blank" rel="nofollow noopener">medium.com/@YousefAlotaib#BurpSuite #SQLmap #CyberSecurity #BugBounty #RedTeam #infosec
Yousef tweet media
English
12
100
594
29.3K