JJebitokinsharonjebitok.com·Sep 23 · 6 min readOverheard at Breakfast: OSINT - image x Gmail x Gravatar profile & Base64 (TryHackMe)Link to the CTF challenge on TryHackMe: Overheard at Breakfast Concierge Briefing The breakfast terrace is loud this morning, clinking cutlery, espresso machines, the usual chatter. One guest couldn'00
FHFaiz Hussainincybersecurity-insights.hashnode.dev·Sep 13 · 4 min readHow Hackers Find Information About a Website — An Introduction to ReconnaissanceA web application rarely exposes its entire attack surface through its homepage. Behind a single domain may exist APIs, subdomains, cloud services, authentication portals, development environments, th12J
Oodufuwababajide77inkay-security-labs.hashnode.dev·Sep 10 · 3 min readThe Analyst's Guide to OSINT: Mastering GitHub Dorks and SearXNGReconnaissance is the foundation of any successful security operation. Whether you are actively hunting for exposed assets or analyzing threat intelligence, the quality of your data dictates the succe00
JJebitokinsharonjebitok.com·Sep 7 · 12 min readContent Discovery (TryHackMe)What Is Content Discovery? Firstly, we should ask, in the context of web application security, what is content? Content can be many things, a file, video, picture, backup, a website feature. When we t00
JJebitokinsharonjebitok.com·Sep 6 · 20 min readChallenges: Grep (TryHackMe)Challenge on TryHackMe: Grep Introduction TryHackMe's Grep room bills itself as an OSINT challenge under the Red Teaming path, and that framing turned out to be the whole point. Coming into this box e00
Xxvzf_optinxvzfopt.hashnode.dev·Sep 1 · 5 min readHarvesting OSINT from Search Engine results with SerpApi and Recon-NGXIntroduction In today’s short blog we’ll be taking a look at how I’ve recently harnessed the power of SerpApi to create the latest Recon-NGX module: the SerpApi LinkedIn Harvester. This is a slight de00
DJDevy Jonesindevyjones.hashnode.dev·Sep 1 · 5 min readFinding Exposed APIs and Services: A Developer's Guide with ScanSearchAs developers, we're constantly building and deploying services. While we focus on functionality and user experience, it's equally critical to understand the external attack surface our applications p00
DJDevy Jonesindevyjones.hashnode.dev·Aug 29 · 5 min readFinding Network Device Info Programmatically: A Python & ScanSearch GuideFinding Network Device Info Programmatically: A Python & ScanSearch Guide As developers, we often face the challenge of understanding the external network footprint of our applications, infrastructure01O
DJDevy Jonesindevyjones.hashnode.dev·Aug 21 · 5 min readFinding Exposed APIs and Services: A Practical Guide for DevelopersAs developers, we're constantly building and deploying services, often exposing APIs and other network endpoints to the internet. While this is necessary for functionality, it also introduces a signif00
SSunnyincybersecurity-learning.hashnode.dev·Aug 13 · 15 min readTryHackMe Passive Reconnaissance Beginner-Friendly Learning GuideIntroduction I recently completed the Passive Reconnaissance room on TryHackMe as part of my ongoing cybersecurity learning journey. Reconnaissance is one of the most important phases in cybersecurity00