𝐂𝐲𝐛𝐞𝐫 𝐄𝐱𝐩𝐥𝐨𝐢𝐭 𝐒𝐞𝐜 🇰🇭
описание
👋Welcome to Cyber Exploit Sec! A community to learn, explore, and master penetration testing and bug bounty, ethical hacking, and all things cybersecurity.
288
подписчиков
Охват к подписчикам
22,6%
ERR
Реакции к просмотрам
0,34%
15 на 42 постов
Пересылки к просмотрам
1,14%
51
Постов в день
1,3
всего 42
Где отзываются чаще
доля реакций к просмотрам- 12 авг.ក្នុងមេរៀននេះ អ្នកនឹងស្គាល់ពីរបៀបដែល Burp Suite អាចប្រើសម្រាប់ Intercept, Inspect និង Modify HTTP/HTTPS Requests រវាង Browser និង Server ដើម្បីស្វែងរក និងយល់ពីបញ្ហាសុវត្ថិភាព ដូចជា IDOR, SQL Injection, XSS, Authentication និងបញ្ហាផ្សេងៗទៀត។ សូមមកកាន់ទីនេះដើម្បីយល់ពីរBurp Suite https://youtu.be/0OrPznyG6SA4,26%
- 3 авг.Hacking movie collocation2,35%
- 22 июл.без подписи2,35%
- 3 авг.I am excited to announce that in just 20 days, we are launching KhmerSec Lab, a new platform designed to elevate the cybersecurity skills of our local community. We are building more than just a Capture The Flag (CTF) arena; we are building a space where defenders, pentesters, and students can sharpen their expertise in a hands-on environment. Stay tuned for our official launch in 20 days. Visit our landing page to follow the countdown and get notified as soon as we go live: lab.khmersec.com 🌐 Website • Main Website: https://khmersec.com/ • Documentation & Learning: https://primer.khmersec.com/ • lab : https://lab.khmersec.com/ • Privacy Policy: https://khmersec.com/privacy • Terms of Service: https://khmersec.com/terms #CyberSecurity #InfoSec #KhmerSec1,32%
- 7 июл.ចង់ក្លាយជា Red Teamer? មនុស្សជាច្រើនគិតថា Red Team = Hack Website ប៉ុណ្ណោះ។ តែការពិត Red Team គឺជាការវាយតម្លៃសុវត្ថិភាពដោយសីលធម៌ដើម្បីសាកល្បងថាប្រព័ន្ធអាចការពារការវាយប្រហារបានកម្រិតណា។ អ្វីដែលគួររៀន៖ - Linux & Windows Fundamentals - Networking (TCP/IP, DNS, HTTP/HTTPS) - Active Directory Basics - Programming (Python, Bash, PowerShell) - Web Security (OWASP Top 10) - Privilege Escalation - OPSEC និងការសរសេរ Report Tools ដែលគួរស្គាល់៖ • Nmap • Burp Suite / Caido • BloodHound • Impacket • CrackMapExec / NetExec • Metasploit • Wireshark • Hashcat • John the Ripper Platforms សម្រាប់អនុវត្ត៖ • Hack The Box • TryHackMe • PortSwigge • OverTheWire • VulnHub • pico ctf Note ៖ កុំសាកល្បងលើ Website ឬ Server ដែលអ្នកមិនមានការអនុញ្ញាត។ រៀននិងអនុវត្តនៅក្នុង Lab ឬដែលមានការអនុញ្ញាតតែប៉ុណ្ណោះ (ទំនួលខុសត្រូវ និងសីលធម៌) #RedTeam #KhmerCyber #KhmerSec1,00%
- 22 янв.💉 SQLMap – Basic to Advanced A quick overview of SQLMap, a widely used security testing tool that helps professionals identify and validate SQL injection vulnerabilities in authorized environments. From basic detection to advanced assessment techniques, SQLMap supports secure development, vulnerability analysis, and strengthening web application defenses. 🔖 #infosec #cybersecurity #appsec #pentesting #security0,76%
- 23 янв.¶¶phisherprice Multi-Functional Pentest Tool, Command Them All From One Script. #recon #cracking #Th3inspector #networking #TermuxToolx #nethunter cd phisherprice chmod +x phisherprice.sh sudo ./phisherprice.sh or sudo bash phisherprice.sh ¶¶ Changing API Key : ¶¶ Example : sudo nano phisherprice.sh https://rapidapi.com/blackbunny/api/bank-card-bin-num-check https://apilayer.com/marketplace/email_verification-api https://apilayer.com/marketplace/number_verification-api https://www.shodan.io │Main Menu ├────────────────── │1 │Recon │2 │Cracking │3 │AutoxSploits │4 │Networking │5 │C.Y.O xSploits │6 │AutoExif │7 │SE Toolkit │8 │Start Th3inspector │u │Update Script │c │Contact Information ├───────────────0,35%
- 5 дек.Bypass-Four03 is a powerful bash tool designed to help testers bypass HTTP 403 forbidden errors through various path and header manipulation techniques. It also includes fuzzing for HTTP methods and protocol versions, making it a versatile addition to any web security researcher's toolkit. ⏬ Link : https://github.com/nazmul-ethi/Bypass-Four03 #bypass #bugbountytip #bugbountytips #bugbounty #cyber_exploit_sec0,27%
- 29 янв.Hey Hunter's, DarkShadow is here back again! hunting backup is a underestimate vulnerability which missed by many bug bounty hunters. Find API endpoints via reading js or api documentation (if available). Then play with various request methods (e g. GET, POST) also you might use my this provided simple and effective Wordlist: /api/v1/backup/create /api/v1/backup/export /api/v1/backup/download/{id} /api/v1/backup/restore /api/v1/backup/schedule /api/v1/backup/config /api/setup/backup /api/admin/system/backup/run /api/manage/backup/snapshot /api/settings/maintenance/backup /api/system/export-data /api/db/backup/start /api/db/dump /api/v1/database/snapshot /api/v1/sql/backup /api/v1/storage/archive /api/v1/sync/backup /api/v1/volumes/{id}/snapshot /api/v1/backups/checkpoints Guys I'll soon upload a detailed write-up about "Google Authenticator" workflow fundamentals and chain reaction for bypass it. Until show your love ❤️ #bugbountytips #missconfig0,25%
- 1 янв.Laravel RCE Exploitation Toolkit 🤕 Purpose: Exploits Laravel RCE vulnerability by using a known APP_KEY to generate a malicious payload that leads to remote code execution. If successful, it writes a backdoor to the server and logs the URL ⭐ 💻 Github #Exploit #laravel #Rce #Rcr_Exploit0,25%
- 18:08https://blog.khmersec.com/blog/sql-injection-in-modern-orms/ SQL Injection in Modern ORMs: Still Possible, Still Dangerous0,00%
- 18:08https://blog.khmersec.com/blog/cors-csrf-primer/ CORS, CSRF, and the Modern Web: A Practical Primer0,00%