mirror of
https://github.com/anotherhadi/sec-notes.git
synced 2026-10-05 07:48:23 +02:00
c695c1207077561dae56fe51a276ea30f70bcea4
Sec Notes
A personal collection of security notes and cheatsheets, covering offensive security and OSINT.
Blog
- The Password is 'admin': Why Default Credentials Are Still Breaking the Internet: Default credentials like admin:admin remain one of the most exploited vulnerabilities on the internet. Learn why they're dangerous, how the Mirai botnet took down half the web with just 62 passwords, and how to protect your infrastructure: plus introducing default-creds, an open-source database to look up factory-set credentials in seconds.
- Unmasking Github Users: How to Identify the Person Behind Any Github Profile: Ever wondered who is behind a specific Github username? This guide covers advanced OSINT techniques to deanonymize users, find hidden email addresses, and link Github accounts to real-world identities.
Linux
- GRUB Boot Bypass: Physical access techniques to get a root shell by editing GRUB boot parameters.
- Linux Privilege Escalation: Common misconfigurations and weaknesses to check when escalating privileges on Linux.
Network
- FTP: Enumeration, exploitation and post-exploitation techniques for FTP servers.
- NFS: Enumeration, mounting and privilege escalation techniques for NFS shares.
- Nmap: Host discovery, port scanning, service detection and NSE scripting
- RDP: Enumeration, exploitation and post-exploitation techniques for RDP servers.
- SSH: Enumeration, exploitation and post-exploitation techniques for SSH servers.
- Telnet: Enumeration, exploitation and post-exploitation techniques for Telnet servers.
OSINT
- Bluesky: Enumeration, search operators, API endpoints and tools for investigating Bluesky accounts.
- Information Gathering: Essential cybersecurity cheatsheet for Information Gathering and Open Source Intelligence (OSINT). Discover data related to emails, domains, usernames, and images using both command line and online tools.
- Sock Puppets: Essential cheatsheet on creating and managing Sock Puppets (fake identities) for ethical security research and Open Source Intelligence (OSINT), focusing on maintaining separation from personal data and bypassing common verification.
- Tips: A cheatsheet of practical tips and unconventional methods for Open Source Intelligence (OSINT), focusing on advanced data visualization, information leakage detection, and utilizing web archives for historical data.
- X / Twitter: Enumeration, search operators, deleted content recovery and tools for investigating X accounts.
Web
- Directory Discovery: Techniques and tools for discovering hidden directories and files on web servers.
- FFUF: Reference and usage examples for ffuf, a fast web fuzzer for directories, endpoints and subdomains.
- Subdomains Discovery: Methods and tools for enumerating subdomains of a target domain.
Languages
Python
70.7%
Nix
29.3%