diff --git a/.github/scripts/gen-readme.py b/.github/scripts/gen-readme.py index defa2e0..c5fa351 100755 --- a/.github/scripts/gen-readme.py +++ b/.github/scripts/gen-readme.py @@ -6,11 +6,16 @@ REPO_ROOT = Path(__file__).resolve().parents[2] README = REPO_ROOT / "README.md" SKIP_DIRS = {".git", ".github", ".direnv"} SECTION_TITLE_OVERRIDES = {"osint": "OSINT"} +DESCRIPTION = "A personal collection of security notes and cheatsheets, covering offensive security and OSINT." FRONTMATTER_RE = re.compile(r"^---\n(.*?\n)---\n", re.DOTALL) FIELD_RE = re.compile(r'^(\w+):\s*"?(.*?)"?\s*$') -TOC_START = "" -TOC_END = "" +TOC_START = ( + "" +) +TOC_END = ( + "" +) def existing_toc_block(): @@ -62,6 +67,8 @@ def main(): lines = [ "# Sec Notes", "", + DESCRIPTION, + "", existing_toc_block(), "", ] diff --git a/README.md b/README.md index 6fb6d4d..4e46d0b 100644 --- a/README.md +++ b/README.md @@ -1,5 +1,7 @@ # Sec Notes +A personal collection of security notes and cheatsheets, covering offensive security and OSINT. + diff --git a/blog/default-passwords.md b/blog/default-passwords.md index 1b80fee..8c6172f 100644 --- a/blog/default-passwords.md +++ b/blog/default-passwords.md @@ -1,7 +1,6 @@ --- title: "The Password is 'admin': Why Default Credentials Are Still Breaking the Internet" description: "Default credentials like admin:admin remain one of the most exploited vulnerabilities on the internet. Learn why they're dangerous, how the Mirai botnet took down half the web with just 62 passwords, and how to protect your infrastructure: plus introducing default-creds, an open-source database to look up factory-set credentials in seconds." -image: "../../../public/images/blog/default-passwords.png" tags: ["botnet", "passwords", "cybersecurity"] publishDate: "2026-03-13" --- diff --git a/blog/github-users-osint.md b/blog/github-users-osint.md index f52b5ad..4251eef 100644 --- a/blog/github-users-osint.md +++ b/blog/github-users-osint.md @@ -1,7 +1,6 @@ --- title: "Unmasking Github Users: How to Identify the Person Behind Any Github Profile" description: "Ever wondered who is behind a specific Github username? This guide covers advanced OSINT techniques to deanonymize users, find hidden email addresses, and link Github accounts to real-world identities." -image: "../../../public/images/blog/github-osint-users.png" tags: ["osint", "github", "cybersecurity"] publishDate: "2026-01-01" --- diff --git a/osint/twitter-x.md b/osint/twitter-x.md index 4256dfa..e7c3f20 100644 --- a/osint/twitter-x.md +++ b/osint/twitter-x.md @@ -31,7 +31,7 @@ Every account has two identifiers: - **Handle**: `@username` (can change) - **User ID**: numeric, permanent (survives handle changes and suspensions) -Unlike [Bluesky](/notes/osint/bluesky), X now requires a login to browse most content in the browser. The free API tier (v2) is severely limited. Most open-source scraping tools that bypassed the API (Twint, snscrape, GetOldTweets3) are broken since the 2023 API lockdown. +Unlike [Bluesky](./bluesky.md), X now requires a login to browse most content in the browser. The free API tier (v2) is severely limited. Most open-source scraping tools that bypassed the API (Twint, snscrape, GetOldTweets3) are broken since the 2023 API lockdown. ## Account Enumeration diff --git a/web/directory-discovery.md b/web/directory-discovery.md index 407caa9..8c31d2d 100644 --- a/web/directory-discovery.md +++ b/web/directory-discovery.md @@ -18,7 +18,7 @@ publishDate: 2026-06-01 ## FFUF -See also [FFUF](/notes/web/ffuf) for fuzzing-based directory discovery. +See also [FFUF](./ffuf.md) for fuzzing-based directory discovery. ## Robots.txt diff --git a/web/subdomains-discovery.md b/web/subdomains-discovery.md index 8eeae8a..5afa55e 100644 --- a/web/subdomains-discovery.md +++ b/web/subdomains-discovery.md @@ -20,7 +20,7 @@ publishDate: 2026-06-01 ## FFUF -See also [FFUF](/notes/web/ffuf) for fuzzing-based subdomain discovery. +See also [FFUF](./ffuf.md) for fuzzing-based subdomain discovery. ## Google Dorking