Kabir πŸ•‰ Profile picture
Jan 18, 2022 β€’ 10 tweets β€’ 3 min read β€’ Read on X
- #100DaysOfHacking with πŸ“’Notes (included in the end).
- Day - 3
- 1. Users and Privileges. ⬇
~# ls -la
List for checking permissions ⬇ Image
`d` - directory
`-` - file Image
`rwx`
r w x
read write execute Image
rwxr-xr-x
-------------------------
3 groups are here
1- `rwx` 2- `r-x` 3- `r-w` Image
1. d`rwx`r-xr-x - Owner of the file
All permissions are there.
This permissions setting that a particular group has
In this case can do read, write and execute. Image
2. drwx`r-x`r-x - Member of the group
The next set of three here is actually the permissions for the members of the group that own the file
In this case, can do only read and execute. Image
3. drwxr-x`r-x` - For all the users on the machine
In this case, we have read and execute permissions. Image
/tmp - dir is having all permissions

While hacking, we might actually upload it into the temp folder because that's where we can execute those files

It's all about insecure configurations. Image
- Retweet (for reach) if you like,
- #100DaysOfHacking with πŸ“’Notes ⬇
- github.com/kabir0x17/100D…

β€’ β€’ β€’

Missing some Tweet in this thread? You can try to force a refresh
γ€€

Keep Current with Kabir πŸ•‰

Kabir πŸ•‰ Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @kabir0x23

May 9, 2022
Continue...

Bug Bounty Checklist for Web App - Part - 2

Risky Functionality - File Uploads:
- Test that acceptable file types are whitelisted
- Test that file size limits, upload frequency and total file counts are defined and are enforced
- Test that file contents match the defined file type
- Test that all file uploads have Anti-Virus scanning in-place.
- Test that unsafe filenames are sanitised
- Test that uploaded files are not directly accessible within the web root
- Test that uploaded files are not served on the same hostname/port
- Test that files and other media are integrated with the authentication and authorisation schemas
Read 7 tweets
May 9, 2022
Bug Bounty Checklist for Web App
Source: ~@owasp

Recon on wildcard domain:

- Run amass
- Run subfinder
- Run assetfinder
- Run dnsgen
- Run massdns
- Use httprobe
- Run aquatone (screenshot for alive host)
Single Domain:

Scanning:
- Nmap scan
- Burp crawler
- ffuf (directory and file fuzzing)
- hakrawler/gau/paramspider
- Linkfinder
- Url with Android application
Manual checking:
- Shodan
- Censys
- Google dorks
- Pastebin
- Github
- OSINT
Read 24 tweets
Jan 20, 2022
Golden Tips + Resources To get Job/Internships + For self Development

Only these Best Resources you need to start πŸ“ˆ
Opensource, Web Development, Programming, DevOps and all Cyber Security Resources Included ⬇
🧡πŸ”₯
[ Open-source ]
Open Source Plays Important role in Self Development + in Job/Internships resume.

What is Open Source & How to Start?
by @kunalstwt

25+ Paid Open Source Programs and Internships
by @kunalstwt
Best Open Source Guidance Channel + My Fav Channel On youtube

youtube.com/c/eddiejaoude/… by @eddiejaoude

Website: eddiehub.org
Read 27 tweets
Jan 19, 2022
- #100DaysOfHacking with
- πŸ“’Notes (included in the last).
- Day - 4
- Viewing Creating Editing Files.
1. print the "hello"
β”Œβ”€β”€(rootπŸ’€kali)-[~/twt]
└─ echo "hello"
>> hello
2. Save "hello" into the files
β”Œβ”€β”€(rootπŸ’€kali)-[~/twt]
└─ echo "hey" > hey.txt

β”Œβ”€β”€(rootπŸ’€kali)-[~/twt]
└─ cat hey.txt
Read 7 tweets
Jan 18, 2022
- #100DaysOfHacking with
- πŸ“’ Notes (included in the last).
- Day - 3 (must checkout)
- 2. File Permission-modifications (in detail). ⬇
File permissions can be viewed using the `ls` command.
Here is an example:

β”Œβ”€β”€(rootπŸ’€kali)-[~/twt]
└─ # ls -l filename.txt Image
The write, read, and execute permissions have the following number value: Image
Read 6 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(