backuplso | Unsorted

Telegram-канал backuplso - Offensive LSO

3275

[This Channel is not intended to violate any condition of use. Copyright Disclaimer Under Section 107 of Copyright Act 1976, allowance is made for "fair use" for purposes such as criticism, comment, news reporting, teaching, scholarship, and research.]

Subscribe to a channel

Offensive LSO

Download For509 Sans :

/channel/+GpP6DvyK9f9mYzZk

Читать полностью…

Offensive LSO

The Top Hacker Methodologies

❤ Share & Support Us

📰 @BackupLSO
📚 @LibrarySecOfficial

Читать полностью…

Offensive LSO

Hi everyone last week there was a wave of Telegram channel blocks in the OSINT community, and my second channel @osintgit was among those affected. Most channels have already been restored, but mine remains blocked. Please help forward the following message to Telegram support:

The @osintgit channel has been blocked. It contained links to articles, presentations from the author’s conference talks, and publicly available tools related to information security. The channel never published personal data or any other prohibited content. Please unblock this channel and remove the restrictions on.

Colleagues in the field have already managed to get the message through; with enough visibility we can do the same.

Please send the message to Telegram support bots:
@PressBot
@AmeliaTearheart
@BotSupport

Also use Telegram Support: Open Settings → “Ask a Question” → proceed to the question.

And email their official addresses:
dmca@telegram.org
security@telegram.org
recover@telegram.org
abuse@telegram.org
support@telegram.org

I would be grateful for reposts of this post  it greatly increases the chances of getting the channel unblocked.

Читать полностью…

Offensive LSO

❤ Share & Support Us

📰 @BackupLSO
📚 @LibrarySecOfficial

Читать полностью…

Offensive LSO

📌 THB-WP101 | Web Penetration Testing Fundamentals

یادگیری چند آسیب‌پذیری و ابزار، به‌ تنهایی برای تبدیل شدن به یک Web Pentester کافی نیست.

یک وب پنتستر باید بتواند یک Web Application را ساختاریافته بررسی کند؛ Attack Surface و نقاط ورودی را شناسایی کند، Authentication و Access Control را ارزیابی کند، Vulnerabilityها را Validate کرده و Impact و مسیر حمله را مستند کند.

دوره ما با تمرکز بر همین مهارت‌ها طراحی شده است.


📌 تخفیف ویژه دوره به مناسبت زادروز کمبوجیه، پسر کوروش بزرگ
🔥
⏳ ۴۰–۵۰ ساعت | 🛠 ۸۰–۹۰٪ عملی | 💻 آنلاین | 🎓 مقدماتی

🎥 ویدئوی معرفی | 📚 سرفصلها | 📄 توضیحات تکمیلی

👤 مدرس: مهندس محمد طاهری
🗓شروع: ۱ مهر ۱۴۰۵
💰 ارزش اصلی دوره: ۵،۹۰۰،۰۰۰ تومان
💰 استاندارد: ۳,۹۸۹,۰۰۰ تومان
🔥
تخفیف : ۲,۵۲۰,۰۰۰ تومان
📌 دوره آفلاین در اختیارتون قرار میگیره + گروه پشتیبانی

⚠️ این دوره برای یادگیری صرف ابزار و Payloadهای آماده نیست.

هدف، توانایی تحلیل و اجرای مستقل فرآیند تست یک Web Application جدید است.

🔥 فقط به مدت ۲۴ ساعت : تخفیف روی این دوره هست.


🔥 شیوه یادگیری

📌 ثبت‌ نام :
@ThbxSupport

@TryHackBox

Читать полностью…

Offensive LSO

❤ Share & Support Us

📰 @BackupLSO
📚 @LibrarySecOfficial

Читать полностью…

Offensive LSO

🚨SQL Injection Cheat Sheet

❤ Share & Support Us

📰 @BackupLSO
📚 @LibrarySecOfficial

Читать полностью…

Offensive LSO

🛡️ Bug Bounty Tip: Test IDOR + Web Cache Deception Together

When hunting IDORs, always check for web cache deception on the same endpoints:

1. As User A, access a sensitive resource like /api/invoices/123 (also try appending .css or .js).
2. As User B, repeat the exact same URL with identical headers.
3. Only change the Cookie/Auth token.

If User B receives User A's 200 OK response from cache → you've likely found a critical vulnerability!

This combo can lead to account takeover-level impacts.

❤ Share & Support Us

📰 @BackupLSO
📚 @LibrarySecOfficial

Читать полностью…

Offensive LSO

Common Security Issues in Financially Oriented Web Applications

❤ Share & Support Us

📰 @BackupLSO
📚 @LibrarySecOfficial

Читать полностью…

Offensive LSO

⚡Google Dorks - Cloud Storage: site:http://s3.amazonaws.com "target[.]com" site:http://blob.core.windows.net "target[.]com" site:http://googleapis.com "target[.]com" site:http://drive.google.com "target[.]com"

👉Find buckets and sensitive data.
Combine:

site:
http://s3.amazonaws.com | site:http://blob.core.windows.net | site:http://googleapis.com | site:http://drive.google.com "target[.]com"

Add something to narrow the results: "confidential” “privileged" “not for public release”

✅Credit- Mike Takahashi



Save

❤ Share & Support Us

📰 @BackupLSO
📚 @LibrarySecOfficial

Читать полностью…

Offensive LSO

⚠️HackLabs is a collection of hands-on vulnerable labs designed to practice web exploitation, privilege escalation, Active Directory attacks, and general pentesting techniques in a safe environment.

⚠️ For educational and authorized testing only.

🔗 https://github.com/afsh4ck/HackLabs

❤ Share & Support Us

📰 @BackupLSO
📚 @LibrarySecOfficial

Читать полностью…

Offensive LSO

📌Bug Bounty Tip: Finding Confidential Documents Fast

✅Admins often leave these unredacted files online by mistake, making them a high-medium severity finding for bug bounty programs.

❤ Share & Support Us

📰 @BackupLSO
📚 @LibrarySecOfficial

Читать полностью…

Offensive LSO

Hi everyone,
I’m currently developing an AI-powered chatbot on Telegram focused on the field of Cyber Security.
If you’re interested in investing in this project or would like to learn more, feel free to reach out to me.
Looking forward to connecting.

@RedTeamKitBot

Читать полностью…

Offensive LSO

😈Turn your Burp Suite findings into clean, professional cards, ready for reports, bug bounty submissions, and social sharing.

🚨https://github.com/JFOZ1010/repshot

❤ Share & Support Us

📰 @BackupLSO
📚 @LibrarySecOfficial

Читать полностью…

Offensive LSO

⚠️403 bypass tools for bug bounty hunters:

bypass-403 → https://github.com/iamj0ker/bypass-403
nomore403 → https://github.com/devploit/nomore403
4-ZERO-3 → https://github.com/Dheerajmadhukar/4-ZERO-3
byp4xx → https://github.com/lobuhi/byp4xx
dontgo403 → https://github.com/mbrg/dontgo403

❤ Share & Support Us

📰 @BackupLSO
📚 @LibrarySecOfficial

Читать полностью…

Offensive LSO

📚 مجموعه کتابهای کاربردی در دنیای امنیت


مهارت واقعی با خواندن شروع میشود، اما با تمرین و تجربه ساخته میشود؛ کتابی را انتخاب کن که قدم بعدی تو در مسیر حرفه‌ای شدن باشد.


📖 کتابچه "Mimikatz: تسلط عملی بر تکنیک‌های پیشرفته حملات Active Directory" از مقدماتی تا پیشرفته.

📕 جزئیات بیشتر کتاب

💰 قیمت : ۲۵۰ تومان

📖 وایرشارک برای ردتیمرها: از پایه تا پیشرفته

📕 جزئیات بیشتر کتاب

💰 قیمت : ۲۵۰ تومان

📖 شکار عملی باگ بانتی : از Recon تا Bounty واقعی : متدولوژی و شناسایی و آسیب پذیری های دنیای واقعی

📕 جزئیات بیشتر کتاب

💰 قیمت : ۳۶۰ تومان

📖 کتابچه Kerberos For Pentesters

📕 جزئیات بیشتر کتاب

💰 قیمت : ۲۶۹ تومان


ممکنه در آینده قیمت کتاب‌ ها تغییر کنه و افزایش داشته باشه بنابراین اگر قصد خرید دارید، قیمت فعلی فرصت خوبی برای تهیه کتاب‌ هاست.

📌 جهت خرید به ایدی زیر پیام دهید:
@THBxSupport

Читать полностью…

Offensive LSO

https://x.com/OffensivePwn/status/2103223998326648863

#Privacy

Читать полностью…

Offensive LSO

Archive Sans :

/channel/+GpP6DvyK9f9mYzZk

Archive OffSec :

/channel/+nNgh2rGVWbs1N2Y0


Archive TCM Security :

/channel/+ukI7oEgYw1djOTVk

Archive alteredsecurity :

/channel/+pj98dN_ZmCwwYzI8

Archive eLearnSecurity :

/channel/+Uk0Q1W0KtGNmOWI0

Archive Ec Council :

/channel/+PbuNXZjyEpMzMGU0


Archive Cyber Security Course :

/channel/+pKh9NHDwEyIyZTE0

Archive Red Team :

/channel/+pNaEuYkdeeo4MmI0

Читать полностью…

Offensive LSO

🤖🤖 JOIN THE Librarysec Backup COMMUNITY! 🤖🤖

Welcome to our mirrored Telegram group, designed to be a backup for our main LibrarySec Telegram channel in case of any unforeseen issues.

Stay updated with the latest in cybersecurity: e-Books, guides, market trends, wordwide analytics, industry insiders, educational resources, ethical hacking, data protection, and more.

💰 JOIN NOW! 💰

30 day's invite links

Don’t forget to stay tuned and follow us for any updates!

Читать полностью…

Offensive LSO

🔐 Testing 2FA in Web Applications?
Don’t just test the OTP.

A real 2FA assessment means checking the entire authentication flow account binding, token reuse, rate limiting, session state, backup codes, recovery flows, API logic, and more.

We turned these checks into a practical Web Pentesting Field Checklist you can keep beside you during assessments.

🎯 Built for:

• Bug Bounty Hunters
• Web Pentesters
• Security Researchers
• CTF Players

💰 Get it for just $1

Small price. Useful checklist. No unnecessary theory.

👉 Get the 2FA Bypass Field Checklist : $1

📩 To purchase, send us a message :

@LibrarySecOfficialBot

Читать полностью…

Offensive LSO

❤ Share & Support Us

📰 @BackupLSO
📚 @LibrarySecOfficial

Читать полностью…

Offensive LSO

PenTesting Agent : is an AI agent framework for black-box security testing, supporting bug bounty, red-team, and penetration testing workflows.

red team ops, Automated recon & exploitation, smart task trees, multi-agent collab, and seamless tool chaining like Nmap, Metasploit, SQLMap, Amass etc

https://github.com/GH05TCREW/pentestagent

❤ Share & Support Us

📰 @BackupLSO
📚 @LibrarySecOfficial

Читать полностью…

Offensive LSO

❤ Share & Support Us

📰 @BackupLSO
📚 @LibrarySecOfficial

Читать полностью…

Offensive LSO

url/?f=etc/passwd ==> 403
encode etc/passwd as base64

url/?f=L2V0Yy9wYXNzd2Q= ==> 200


you can use this trick in SQL , SSTI , XSS , LFI , Etc...

❤ Share & Support Us

📰 @BackupLSO
📚 @LibrarySecOfficial

Читать полностью…

Offensive LSO

WAF Bypass Techniques + Tools

Here are some powerful tools and methods to help you bypass Web Application Firewalls during bug hunting:

🔥 Tools:
- wafw00f — WAF fingerprinting tool
→ https://github.com/EnableSecurity/wafw00f
- bypass-firewalls-by-DNS-history — Discover origin IPs via old DNS records
→ https://github.com/vincentcox/bypass-firewalls-by-DNS-history
- CloudFail — Excellent for bypassing Cloudflare
→ https://github.com/m0rtem/CloudFail

🔥 Effective Bypass Techniques:

1. Origin IP Discovery — Use historical DNS records (Censys, etc.) to find the real server IP and connect directly.
2. Dev/Staging Subdomains — These often don’t have WAF protection.
3. Case Variations — Try SeLeCt instead of SELECT
4. Comment Injection — SE//LECT
5. Multiple Encodings — URL → Double URL → Unicode, etc.
6. Parameter Pollution — ?id=1&id=2
7. HTTP Method Swap — Change from GET → POST → PUT
8. Content-Type Swap — Switch between form-data, JSON, XML
9. HTTP/2 Cleartext — Some WAFs only inspect HTTP/1.1

Quick WAF Detection Command:

curl -I https://target.com | grep -iE "server|cdn|cf-|x-"


Save this for your next bug bounty hunt! 🔥

❤ Share & Support Us

📰 @BackupLSO
📚 @LibrarySecOfficial

Читать полностью…

Offensive LSO

Roadmap for Cyber Security & Ai Security

/channel/+390M0bSj10BiMDJk


Membership is only for 100 people.

⭕ For 47

Читать полностью…

Offensive LSO

CloudRip Fast Cloudflare bypass scanner. A tool that helps you find the real IP addresses hiding behind Cloudflare by checking subdomains.

https://github.com/moscovium-mc/CloudRip


❤ Share & Support Us

📰 @BackupLSO
📚 @LibrarySecOfficial

Читать полностью…

Offensive LSO

Claude-BugHunter — Turn Claude Code into a Senior Bug Hunter & Red Team Operator 🤖💀

A powerful skill bundle built for bug bounty hunters and external red teams.

• 51 specialized security skills
• 15 slash commands for automated workflows
• 681 real disclosed report patterns
• Coverage across Web, API, Cloud, OAuth, SAML, GraphQL, SSRF, IDOR, XSS, RCE & more
• Enterprise attack paths for M365, Okta, VPNs, SharePoint & VMware
• Built-in triage, validation, reporting & evidence hygiene workflows
• Burp MCP integration and engagement tracking

From recon and vulnerability discovery to validation and report writing, Claude automatically loads the right skills based on what you're testing.

🔗 https://github.com/elementalsouls/Claude-BugHunter

❤ Share & Support Us

📰 @BackupLSO
📚 @LibrarySecOfficial

Читать полностью…

Offensive LSO

2FA Bypass
https://github.com/0xmaximus/Galaxy-Bugbounty-Checklist/tree/main/2FA%20bypass

❤ Share & Support Us

📰 @BackupLSO
📚 @LibrarySecOfficial

Читать полностью…

Offensive LSO

🔥CVE-2026-41940 cPanel/WHM Authentication Bypass - Detection Artifact Generator

🚨
https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py

❤ Share & Support Us

📰 @BackupLSO
📚 @LibrarySecOfficial

Читать полностью…
Subscribe to a channel