Hey hackers! These are our favorite resources shared by pentesters and bug hunters last week.

This issue covers the week from 28 of June to 05 of July.

Our favorite 5 hacking items

1. Webinar of the week

This is an excellent introduction to cloud security for pentesters and bug hunters. If you’ve ever felt intimidated by AWS testing, this is a perfect opportunity to tackle this topic. You’ll learn about cloud computing, the difference between IaaS, PaaS and SaaS, common misconfigurations of four components of AWS (including AWS S3 and IAM) with examples and links to writeups.

2. Writeup of the week

I’ve never thought that the file name specified during a file upload could be saved to a database, and so potentially vulnerable to SQL injection!

It seems like an unusual entry point for this kind of attacks. So it’s good to know and add to one’s list of locations to fuzz for SQL injection.

3. Conference of the week

When I first saw the name of this conference, I thought it was only about passwords, hashes and crypto (because of the word “SALT”).

But it’s actually very eclectic with talks on interesting offensive security topics like: reversing Android apps, why MD5 is so weak, JSON Web tokens, Curl, red teaming & open source, Jenkins security, etc.

And with brilliant speakers like Orange Tsai and Louis Nyffenegger, I’m sure quality is there too.

4. Tool of the week

Asset Discover is a Burp Suite extension that passively collects asset-related information. While you’re browsing the target app, it parses responses and extracts the following assets: domains, subdomains, IP addresses, S3 buckets, DigitalOcean space URLs and Azure Blob URLs.

Having this kind of information passively gathered and easily accessible is interesting. It’s worth testing.

5. Article of the week

Being obsessed with offensive security, defense is not my forte. But it’s interesting to consider both to be able to understand the other side (developers, clients, bug bounty programs…) and, if necessary, advise them on how to remedy bugs or up their security.

This article provides multiple practices that can help avoid breaches, with links to resources (tools, checklists, people to follow, articles, etc).

It’s good to know for both hackers and defenders.

Other amazing things we stumbled upon this week

Videos

Podcasts

Webinars & Webcasts

Conferences

Slides only

Tutorials

Medium to advanced

Beginners corner

Writeups

Challenge writeups

Pentest writeups

Responsible(ish) disclosure writeups

Bug bounty writeups

See more writeups on The list of bug bounty writeups.

If you don’t have time

Cazador & Introduction

FridaLoader: A quick and dirty app to download & launch Frida x86 on Genymotion. Useful during Android engagements when you don’t want to download & run the @fridadotre Server on the device every time

iframeBusterXSS: Tool for identifying iFrameBuster files (which often contain easy XSS)

Glorified Grep & Introduction

CollabOzark: A simple tool which helps the researchers track SSRF, RCE, Blind XSS, XXE, External Resource Access payloads triggers

Slothy: Open source information gathering tool from publicly available sites against a target domain

CRLF-Injection-Scanner: Command line tool for testing CRLF injection on list of domains

KNOXSS Community Edition

Recon: Easy Fast recon script

Hershell: Multiplatform reverse shell generator

Misc. pentest & bug bounty resources

Challenges

Articles

News

Bug bounty news

Vulnerabilities

Breaches & Attacks

Malicious apps/sites

Other news

Non technical

Tweeted this week

We created a collection of our favorite pentest & bug bounty related tweets shared this past week. You’re welcome to read them directly on Twitter: Tweets from 06/28/2019 to 07/05/2019.

Curated by Pentester Land & Sponsored by Intigriti

Have a nice week folks!

If you want to be notified when new articles (including this newsletter) are published, you can subscribe to this blog.

And if you enjoyed reading this, please consider sharing it, leaving a comment, suggestions, questions…