mirror of
https://github.com/anotherhadi/sec-notes.git
synced 2026-10-05 07:48:23 +02:00
@@ -6,11 +6,16 @@ REPO_ROOT = Path(__file__).resolve().parents[2]
|
||||
README = REPO_ROOT / "README.md"
|
||||
SKIP_DIRS = {".git", ".github", ".direnv"}
|
||||
SECTION_TITLE_OVERRIDES = {"osint": "OSINT"}
|
||||
DESCRIPTION = "A personal collection of security notes and cheatsheets, covering offensive security and OSINT."
|
||||
|
||||
FRONTMATTER_RE = re.compile(r"^---\n(.*?\n)---\n", re.DOTALL)
|
||||
FIELD_RE = re.compile(r'^(\w+):\s*"?(.*?)"?\s*$')
|
||||
TOC_START = "<!-- START doctoc generated TOC please keep comment here to allow auto update -->"
|
||||
TOC_END = "<!-- END doctoc generated TOC please keep comment here to allow auto update -->"
|
||||
TOC_START = (
|
||||
"<!-- START doctoc generated TOC please keep comment here to allow auto update -->"
|
||||
)
|
||||
TOC_END = (
|
||||
"<!-- END doctoc generated TOC please keep comment here to allow auto update -->"
|
||||
)
|
||||
|
||||
|
||||
def existing_toc_block():
|
||||
@@ -62,6 +67,8 @@ def main():
|
||||
lines = [
|
||||
"# Sec Notes",
|
||||
"",
|
||||
DESCRIPTION,
|
||||
"",
|
||||
existing_toc_block(),
|
||||
"",
|
||||
]
|
||||
|
||||
@@ -1,5 +1,7 @@
|
||||
# Sec Notes
|
||||
|
||||
A personal collection of security notes and cheatsheets, covering offensive security and OSINT.
|
||||
|
||||
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
|
||||
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
|
||||
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
---
|
||||
title: "The Password is 'admin': Why Default Credentials Are Still Breaking the Internet"
|
||||
description: "Default credentials like admin:admin remain one of the most exploited vulnerabilities on the internet. Learn why they're dangerous, how the Mirai botnet took down half the web with just 62 passwords, and how to protect your infrastructure: plus introducing default-creds, an open-source database to look up factory-set credentials in seconds."
|
||||
image: "../../../public/images/blog/default-passwords.png"
|
||||
tags: ["botnet", "passwords", "cybersecurity"]
|
||||
publishDate: "2026-03-13"
|
||||
---
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
---
|
||||
title: "Unmasking Github Users: How to Identify the Person Behind Any Github Profile"
|
||||
description: "Ever wondered who is behind a specific Github username? This guide covers advanced OSINT techniques to deanonymize users, find hidden email addresses, and link Github accounts to real-world identities."
|
||||
image: "../../../public/images/blog/github-osint-users.png"
|
||||
tags: ["osint", "github", "cybersecurity"]
|
||||
publishDate: "2026-01-01"
|
||||
---
|
||||
|
||||
+1
-1
@@ -31,7 +31,7 @@ Every account has two identifiers:
|
||||
- **Handle**: `@username` (can change)
|
||||
- **User ID**: numeric, permanent (survives handle changes and suspensions)
|
||||
|
||||
Unlike [Bluesky](/notes/osint/bluesky), X now requires a login to browse most content in the browser. The free API tier (v2) is severely limited. Most open-source scraping tools that bypassed the API (Twint, snscrape, GetOldTweets3) are broken since the 2023 API lockdown.
|
||||
Unlike [Bluesky](./bluesky.md), X now requires a login to browse most content in the browser. The free API tier (v2) is severely limited. Most open-source scraping tools that bypassed the API (Twint, snscrape, GetOldTweets3) are broken since the 2023 API lockdown.
|
||||
|
||||
## Account Enumeration
|
||||
|
||||
|
||||
@@ -18,7 +18,7 @@ publishDate: 2026-06-01
|
||||
|
||||
## FFUF
|
||||
|
||||
See also [FFUF](/notes/web/ffuf) for fuzzing-based directory discovery.
|
||||
See also [FFUF](./ffuf.md) for fuzzing-based directory discovery.
|
||||
|
||||
## Robots.txt
|
||||
|
||||
|
||||
@@ -20,7 +20,7 @@ publishDate: 2026-06-01
|
||||
|
||||
## FFUF
|
||||
|
||||
See also [FFUF](/notes/web/ffuf) for fuzzing-based subdomain discovery.
|
||||
See also [FFUF](./ffuf.md) for fuzzing-based subdomain discovery.
|
||||
|
||||
## Google Dorking
|
||||
|
||||
|
||||
Reference in New Issue
Block a user