Konstantin :C_H: · @kpwn
61 followers · 206 posts · Server infosec.exchange

academy is fucking awesome and I recommend that to everybody who want to learn about

#portswigger #cybersecurity

Last updated 2 years ago

Konstantin · @kpwn
11 followers · 48 posts · Server infosec.exchange

provides a practice exam. Instead of two, there is just one application to solve.
In my preparation, I failed the practice exam several times. Donβ€˜t get discouraged when you fail, but learn from your mistakes.

portswigger.net/web-security/c

#portswigger

Last updated 2 years ago

Solved: Username enumeration via response timing

#burpsuite #portswigger #owasp #appsec #studying

Last updated 2 years ago

Solved: Username enumeration via subtly different responses

#portswigger #burpsuite #appsec

Last updated 2 years ago

rffuste · @rffuste
14 followers · 11 posts · Server infosec.exchange

How your scanner app can be tested?
Do you want to test your brand new scanner app? How to know if the app detects the vulnerabilities it should?

Thanks to Portswigger now we have Gin and Juice Shop. This is a vulnerable web shop where your scanner app can be tested.

The application can be found here: ginandjuice.shop

Happy scan! 😈
rffuste.com/2023/01/23/how-you

#pills #portswigger #webscan

Last updated 2 years ago

ChickenPwny · @ChickenPwny
473 followers · 3196 posts · Server infosec.exchange

Next, is adding in into the api to make the processes even easier. XD

#portswigger #burp

Last updated 2 years ago

SQL injection with filter bypass via XML encoding solved!!

#portswigger #burpsuite #appsec

Last updated 2 years ago

Blind SQL injection with out-of-band data exfiltration solved!!

#portswigger #appsec #burpsuite

Last updated 2 years ago

Back to studying daily on portswigger labs. Prepare to be sick of me.

#burpsuite #portswigger #appsec

Last updated 2 years ago

For all my Burp Suite users on MacOS:

For all the Burp extensions that will run something "in terminal" and you want that terminal to be iTerm2, create a shell script with the following content, link it to /usr/local/bin/iterm or something, and set it as the terminal command in your Burp extensions.

Here I'm using it with the (awesome) Custom Send To extension for sending requests directly. from Burp to a number of different tools like SQLMap, Wfuzz, Gobuster etc. The script will open a new tab in iTerm and run the command specified.

You're welcome!

Script: gist.github.com/n0kovo/0e893c7

Custom Send To:
github.com/bytebutcher/burp-se

#iterm2 #burpsuite #appsec #burp #portswigger #bugbounty #infosec #pentesting #websecurity #techtips

Last updated 2 years ago

Pretty excited that I made it to level 8! I’ve been grinding through all of the easy rooms and it’s been so rewarding. I feel like I’m learning so much! Aside from THM I’m not sure what else to do. Maybe or @Hacker0x01 ? So many options to choose from

#portswigger

Last updated 2 years ago

Sanjaymenon :mastodon: · @sanjaymenon
48 followers · 112 posts · Server mastodon.social

PortSwigger wants your feedback in the new Burp Suite API is codenamed "Montoya"
portswigger.net/blog/new-burp-

#API #burpsuite #portswigger #proxy #security

Last updated 2 years ago

ChickenPwny · @ChickenPwny
416 followers · 1973 posts · Server infosec.exchange

Hmmm, best way to start from nothing to doing BB. Two years of study need to study for but may not need to pass or take exam Network plus. Doing lots of ctfs that are progressively harder, till you are comfortable. Do academy labs all of them, you may skip secc5ions for sqli but you should be confident In technique. Xss depending, but more the better.

You may do BB and portswigger at same time, do one vuln a week then hunt for the vuln for a week. You should Learn it pretty well through repition

#portswigger

Last updated 2 years ago

Ryan :donor:​ · @chmod777
79 followers · 134 posts · Server infosec.exchange

@Colin_Mac I just signed up for LetsDefend.io and so far I'm digging that. SOC analyst/Blue Team focused. I did a handful of lessons and then subscribed since they had a 50% off

Other resources I've signed up for but haven't fully explored yet:

PortSwigger, Hack the Box, TryHackMe




#portswigger #hackthebox #letsdefend #tryhackme

Last updated 2 years ago

Claudio · @sonoclaudio
163 followers · 80 posts · Server mastodon.insicurezzadigitale.com