Latest posts

CTF Training
22 Sept, 11:07
forwarded from @bugcrowd
🚨 New Bug Bounty Breakdown is Live! 🚨I just opened the vault on a 2019 SQL Injection (SQLi) I found on EC-Council's infrastructure.In this video, I walk through: 🔹 The original PoC and vulnerable search parameter 🔹 How it exposed backend MySQL databases 🔹 The Zendesk disclosure timeline & remediation 🔹 Landing a spot on the Bug Bounty Hall of Fame! 🏆Watch the full walkthrough here 👇 🔗 https://youtu.be/hwGjbeEOIwMYouTubeHow a Critical SQL Injection was Found in EC-Council’s InfrastructureIn this video, I walk through an old SQL Injection vulnerability discovered and responsibly disclosed to EC-Council back in August 2019 on store.eccouncil.org. The issue involved a search parameter flaw that exposed raw MySQL database error logs and query…
CTF Training
11 Sept, 02:24
forwarded from @zishanhack
Your Firefox deserves a better terminal.CyberTerminus: a dark, cyber-inspired Firefox theme built for people who live in terminals, browsers, and security labs.If that sounds like your setup, give it a try:https://addons.mozilla.org/en-US/firefox/addon/zishanadthandar-cyberterminus/Firefox Add-onsaddons.mozilla.orgCyberTerminus – Get this Theme forDownload CyberTerminus for Firefox. ZishanAdThandar CyberTerminus is a sleek, hacker-inspired Firefox dark theme. Featuring deep blacks, neon green (#39FF14), cyan (#0AFFEF), and sharp red (#FF3131), it mirrors a terminal’s glow. With vibrant accents and…1,170Open in Telegram
CTF Training
22 Jun, 15:36
https://t.me/addlist/Bqw26iGfReYyMGZlTelegramZishanHackZishan Ahamed Thandar invites you to add the folder “ZishanHack”, which includes 6 chats.4,990Open in Telegram
CTF Training
2 May, 16:49
forwarded from @zishanhack
📌 Official Announcement from ZishanHackIf you're preparing for OSCP / OSCP+, this is important.After months of refining, testing, and personally using it across multiple labs and real exam environments, I’ve released a premium OSCP Command Cheatsheet (Obsidian Edition) on:👉 https://zishanhack.comIt is a professional, exam-focused Obsidian vault built to give learners: - A clean command-first structure - Fast workflow navigation - Practical enumeration to exploitation flow - Realistic privilege escalation patterns - Pivoting & tunneling references - Zero clutter - Pure exam-ready efficiency - Many OSCP learners waste months building their notes from scratch. This vault removes that burden entirely.I created it because the OSCP journey becomes significantly easier when your notes are:ZishanHackZishanHack | Red Team Notes, Checklists & Security ResourcesBattle-tested OSCP, CRTA & OSWP notes and tools plus a web security checklist for pentesters and bug bounty hunters. Instant access with lifetime updates.
CTF Training
23 Mar, 14:04
forwarded from @bugcrowd
🚀 OSCP COMMANDS – OBSIDIAN VAULT Save Hours in the Exam. Instant Command Recall.OSCP isn't about knowing what tool exists. It's about recalling the right command instantly — under pressure, without panic.📦 What's Inside: • Enumeration – FTP, SSH, SMB, HTTP, DNS, LDAP, RDP • Privilege Escalation – Linux & Windows decision trees • Web Exploitation – SQLi, file upload, LFI/RFI bypass • Active Directory – Domain enum, lateral movement • Post-Exploitation – Cred dumping, persistence⚡️ Why Obsidian: 🔗 Internal links between techniques 🔍 Instant search across commands 🧠 Knowledge graph for connections ✏️ Easy to extend with your notes🎁 What You Get:
CTF Training
22 Feb, 05:07
## 🚀 Ultimate Web Security Checklist — Now AvailableIf you’re into bug bounty, pentesting, or structured web app testing, this will save you serious time.The Ultimate Web Security Checklist is a professionally organized reference guide built to help you test applications methodically — without missing important areas.Inside you’ll get:✅ 300+ structured security test points ✅ Coverage across major vulnerability categories ✅ Clear, organized testing flow ✅ Practical tool references ✅ Clean, easy-to-use PDF formatThis is not a course.It’s a disciplined testing framework for those who already understand web security and want a repeatable, professional approach.Stop relying on memory. Start relying on structure.ZishanHackUltimate Web Security Checklist 202632-page PDF with 300+ specific security tests for SQLi, XSS, SSRF, and API vulnerabilities.
CTF Training
8 Jan, 16:17
forwarded from @zishanhack
📌 Official Announcement from ZishanHackIf you're preparing for OSCP / OSCP+, this is important.After months of refining, testing, and personally using it across multiple labs and real exam environments, I’ve released a premium OSCP Command Cheatsheet (Obsidian Edition) on:👉 https://zishanhack.comIt is a professional, exam-focused Obsidian vault built to give learners: - A clean command-first structure - Fast workflow navigation - Practical enumeration to exploitation flow - Realistic privilege escalation patterns - Pivoting & tunneling references - Zero clutter - Pure exam-ready efficiency - Many OSCP learners waste months building their notes from scratch. This vault removes that burden entirely.I created it because the OSCP journey becomes significantly easier when your notes are:ZishanHackZishanHack | Red Team Notes, Checklists & Security ResourcesBattle-tested OSCP, CRTA & OSWP notes and tools plus a web security checklist for pentesters and bug bounty hunters. Instant access with lifetime updates.
CTF Training
29 Dec 2025, 16:13
📌 Official Announcement from ZishanHackIf you're preparing for OSCP / OSCP+, this is important.After months of refining, testing, and personally using it across multiple labs and real exam environments, I’ve released a premium OSCP Command Cheatsheet (Obsidian Edition) on:👉 https://zishanhack.comIt is a professional, exam-focused Obsidian vault built to give learners: - A clean command-first structure - Fast workflow navigation - Practical enumeration to exploitation flow - Realistic privilege escalation patterns - Pivoting & tunneling references - Zero clutter - Pure exam-ready efficiency - Many OSCP learners waste months building their notes from scratch. This vault removes that burden entirely.I created it because the OSCP journey becomes significantly easier when your notes are:ZishanHackZishanHack | Red Team Notes, Checklists & Security ResourcesBattle-tested OSCP, CRTA & OSWP notes and tools plus a web security checklist for pentesters and bug bounty hunters. Instant access with lifetime updates.
CTF Training
21 Dec 2025, 05:03
forwarded from @bugcrowd
🔐 Ultimate Web Security Checklist for Bug Bounty HunterBuilt by an active bug bounty hunter for professionals who want real, practical results — not recycled blog content.You’ll get:✅ Tactical recon to exploitation flow ✅ Field-tested tools, payloads, and scripts ✅ Covers real-world XSS, IDOR, SSRF, APIs, Cloud, Business Logic, and more ✅ Made to level up hunters, pentesters, and CTF players🧠 Used by security professionals worldwide. 🚀 Perfect for live hacking prep, client audits, and fast bug validation.📥 Get instant access now → 👉 https://zishanhack.com⚠️ Limited-Time Deal Active — Almost 90% OFF This discount will expire without warning. Don't miss it.


CTF Training
29 Nov 2025, 16:50
forwarded from @bugcrowd
🚀 New Tool for Pentesters & Bug Bounty HuntersI’ve released a Firefox addon that makes proxy switching instant. Burp → Tor → Direct in ONE click ⚡️No manual proxy setup. No repeated configuration. Just pure speed.Demo Video: https://youtu.be/lu_f-74wVME Addon Download: https://addons.mozilla.org/en-US/firefox/addon/hackerproxypro/ Source Code: https://github.com/ZishanAdThandar/HackerProxyProIf you use Burp Suite or Tor regularly, this addon will save you serious time. Give it a try and let me know your thoughts.YouTubeInstant Burp & Tor Proxy Switching for Pentesters (Game-Changing Addon)Instant Burp & Tor Proxy Switching for Pentesters (Game-Changing Addon) — SEO Description Take your pentesting and bug bounty workflow to the next level with this game-changing browser addon that lets you switch between Burp Suite, Tor, and Direct mode instantly…
CTF Training
25 Nov 2025, 06:17
[ Try this firefox proxy addon ]$ Features - Burp Suite Proxy in one click - TOR proxy in one click (when tor service is running on port 9050) - Onion site access in firefox - Lite on RAM - Easy to understand - Faster than all other similarhttps://addons.mozilla.org/en-US/firefox/addon/hackerproxypro/addons.mozilla.orgHacker Proxy Pro by ZishanAdThandar – Get this Extension forDownload Hacker Proxy Pro by ZishanAdThandar for Firefox. Ethical Hackers|Bug Hunters|Pentesters|Cyber Security Researcher. Lightweight Open Source Proxy Switch. Note: Goto "about:addons" : "Extensions : Click on HackerProxyPro : "Allow" "Run in Private Windows"…
CTF Training
8 Nov 2025, 17:48
forwarded from @bugcrowd
# Check Website Dorker Pro is now available for free as fully open source project https://github.com/ZishanAdThandar/WebsiteDorkerPro## Installation Commandpython3 -m pip install website-dorker-pro## Usage### GUI Interfacewebsitedorkerpro --gui # or wdp --gui### CLI Interface# Quick reconnaissance scan websitedorkerpro example.com --quick-scan

CTF Training pinned Deleted message
28 Oct 2025, 17:38
Messages in this channel will no longer be automatically deleted
28 Oct 2025, 17:36
Channel created
9 Jul 2023, 17:12
Related Channels
Other channels in the same section of the catalogue.
