Commit Graph

893 Commits

Author SHA1 Message Date
Gorgamite
ff3b45e0b7
Added LinPEAS to Linux Privesc.
I very strongly recommend adding LinPEAS to the enumeration tools. LinPEAS is arguably the best linux privesc enumeration tool out there. If you haven't used it, I'd try it out. It highlights all relevant information with color coded text, and you can pass it parameters to control the thoroughness of the scan. You should add WinPEAS for windows privesc as well.
2020-10-29 03:50:05 -07:00
Gorgamite
1f96d34ddf
Specifying alternative access method through SSH
Specifying alternative access method through SSH since SSH is assumed to be running on the Linux machine. Read id_rsa for that user to obtain the SSH private key.
2020-10-25 02:51:07 -07:00
Swissky
955557d175
Merge pull request #272 from op01/master
add type juggling example
2020-10-23 18:30:32 +02:00
OOP
f2e3078915 add reference 2020-10-23 23:15:59 +07:00
OOP
35f2834eaa add type juggling example 2020-10-23 23:12:45 +07:00
Swissky
e9c0581fa6
Merge pull request #270 from bolli95/master
Tabnabbing explanation added
2020-10-20 11:34:13 +02:00
Swissky
0f125243ab
Update README.md 2020-10-20 11:34:02 +02:00
Max Boll
33ab643c0d
Rename Tabnabbing.md to README.md 2020-10-20 11:24:39 +02:00
Max Boll
fae1f339e2
typos fixed 2020-10-20 11:22:25 +02:00
Max Boll
3671248485 typing errors fixed 2020-10-20 11:20:56 +02:00
Max Boll
a026ad0727 tabnabbing.md added 2020-10-20 11:17:01 +02:00
Swissky
7f90601372
Merge pull request #269 from marcan2020/patch-9
Add Password Reset Via Username Collision
2020-10-19 00:18:57 +02:00
marcan2020
3a5f98e177
Add Password Reset Via Username Collision 2020-10-18 18:13:18 -04:00
Swissky
7510307a59
Merge pull request #264 from d4rkc0nd0r/patch-5
Update README.md
2020-10-18 22:30:56 +02:00
Swissky
bf7fc8939b
Merge pull request #268 from marcan2020/patch-8
Update big CVEs list
2020-10-18 22:30:21 +02:00
marcan2020
94d37e057c
Update big CVEs list
- Add EternalBlue and BlueKeep CVEs
- Move Heartbleed and Shellshock in the "older" section since they were found more than 5 years ago
2020-10-18 16:17:03 -04:00
Swissky
8a59b22a64
Merge pull request #267 from Rude-Monkey/master
Fix(Docs): Correcting typos on the repo
2020-10-17 23:06:44 +02:00
Vincent Gilles
0b90094002 Fix(Docs): Correcting typos on the repo 2020-10-17 22:52:35 +02:00
Swissky
4a4df791ed
Merge pull request #266 from marcan2020/patch-6
Add Python bind shell
2020-10-17 20:58:21 +02:00
marcan2020
693349da56
Add Python bind shell 2020-10-17 14:52:36 -04:00
Swissky
b641131f27 SSTI - Pebble update 2020-10-17 12:25:50 +02:00
Swissky
5a1ae58a59 Sticky Notes Windows + Cobalt SMB 2020-10-16 11:35:15 +02:00
Swissky
3368084b2d CS Beacon - SMB Error Code 2020-10-15 17:22:00 +02:00
Swissky
b32f4754d7 Keytab + schtasks 2020-10-15 12:35:05 +02:00
Siddharth Reddy
483d8796d5
Update README.md 2020-10-09 18:17:06 +05:30
Swissky
2ab1c58dac
Merge pull request #261 from SiddTim/patch-3
Update README.md
2020-10-09 14:45:50 +02:00
Swissky
3e159534b8
Merge pull request #262 from SiddTim/patch-4
Update Cassandra Injection.md
2020-10-09 14:44:45 +02:00
Siddharth Reddy
fdc44ce84e
Update Cassandra Injection.md
Broken link [Injection In Apache Cassandra – Part I - Rodolfo - EternalNoobs](https://eternalnoobs.com/injection-in-apache-cassandra-part-i/)
2020-10-09 18:10:12 +05:30
Siddharth Reddy
dbc3cb38ea
Update README.md
Page not found [Local file inclusion mini list - Penetrate.io](https://penetrate.io/2014/09/25/local-file-inclusion-mini-list/).
2020-10-09 17:59:30 +05:30
Swissky
913f2d2381
Merge pull request #253 from yoavbls/add-cloudflared
Use cloudflared to expose internal services
2020-10-09 10:34:26 +02:00
Swissky
0f098c8a2c
Merge pull request #251 from ritiksahni/patch-1
Removed broken link
2020-10-09 10:33:43 +02:00
Swissky
a8319b94ff
Merge pull request #259 from SiddTim/patch-1
Update Cassandra Injection.md
2020-10-09 10:31:58 +02:00
Swissky
f03da2a53e
Merge pull request #260 from SiddTim/patch-2
Update MSSQL Injection.md
2020-10-09 10:31:48 +02:00
Siddharth Reddy
f284045ba6
Update MSSQL Injection.md
Broken link [Sqlinjectionwiki - MSSQL](http://www.sqlinjectionwiki.com/categories/1/mssql-sql-injection-cheat-sheet/) .
2020-10-09 12:53:21 +05:30
Siddharth Reddy
f66c53ee25
Update Cassandra Injection.md
Broken link [https://hack2learn.pw/cassandra/login.php]
2020-10-09 12:45:28 +05:30
Swissky
c9be68f0a1 Privilege File Write - Update 2020-10-08 16:51:11 +02:00
Swissky
0df0cc9cf8 Privileged File Write 2020-10-08 16:39:25 +02:00
Swissky
52b0cd6030 Ligolo Reverse Tunneling 2020-10-08 11:23:12 +02:00
Swissky
7014cb37d2
Merge pull request #258 from Shad0wMazt3r/master
Added YouTube Channels
2020-10-08 10:04:59 +02:00
Swissky
5c810b0e62
Update YOUTUBE.md 2020-10-08 10:01:45 +02:00
Pratyaksha Beri
6b03d32af0
Added a lot more content 2020-10-08 10:21:49 +05:30
Pratyaksha Beri
559fd9dcf8
Added STÖK 2020-10-08 09:53:29 +05:30
Swissky
63270e4d42
Delete Logs-files.txt
Fix for https://github.com/swisskyrepo/PayloadsAllTheThings/issues/141
2020-10-07 22:25:25 +02:00
Swissky
417c972871
Merge pull request #257 from vavkamil/vavkamil/cache-deception
Update `Web Cache Deception` section
2020-10-07 20:16:14 +02:00
Kamil Vavra
7229b45f3a
Update References
- remove broken link
- add Entanglement article
- add Web Security Academy links
2020-10-07 19:31:46 +02:00
Kamil Vavra
aedf84283a
Sort the intruder wordlist
Sorted alphabetically for better visibility
2020-10-07 19:20:16 +02:00
Kamil Vavra
73a94b3de7
Update list of headers
Sync with current wordlist from param-miner
2020-10-07 19:15:22 +02:00
Swissky
4a63544b75 CORS Fix typo 2020-10-06 23:17:34 +02:00
Swissky
d6feb565ce
Merge pull request #254 from irotem/irotem-traversal-patch-1
Added traversal bypass of nginx/alb
2020-10-04 14:18:07 +02:00
irotem
e8744406f9
Added traversal bypass of nginx/alb 2020-10-04 12:42:51 +03:00