Joined December 2018
104 Photos and videos
Pinned Tweet
Linux Cmd Cheatsheet #Linux
14
367
1,188
Sec_Nerd07 retweeted
Feb 2
Offense at scale starts with an API. Today, we’re launching the XBOW Public API in Public Preview. Autonomous pentesting gave teams expert-level assessments in hours. But turning that capability into infrastructure required one more piece: programmatic access. Teams can now trigger and manage pentests across their entire portfolio; start, pause, resume, and monitor assessments at machine speed. Findings, assets, reports, and webhooks are all accessible through a production-ready API built to integrate directly into existing workflows. The result: run one pentest or one hundred with the same depth, autonomy, and exploit validation. No scheduling. No bottlenecks. No choosing which applications get coverage. Public Preview is live as of February 1, 2026. More here: bit.ly/45Kkq7V
1
12
104
12,265
Sec_Nerd07 retweeted
7 Top Hacking Gadgets
3
47
317
29,838
Sec_Nerd07 retweeted
🚨 New Writeup Alert! 🚨 "Bug Hunting for Real: Tools, Tactics, and Truths No One Talks About" by Ehtesham Ul Haq is now live on IW! Check it out here: infosecwriteups.com/661f6786… #writeup #bugbounty #reconnaissance #rewards #penetrationtesting
5
13
1,468
Sec_Nerd07 retweeted
5 May 2025
PentestGPT Solves Absolute Path Traversal Lab via Terminal 👇
7
23
197
13,380
Sec_Nerd07 retweeted
28 Nov 2024
In case you missed @GodfatherOrwa's Recon video, here you go. 🫡 Gain that knowledge: youtube.com/watch?si=RDw88Nf…
2
29
129
7,764
Sec_Nerd07 retweeted
CyberSecurity Study Guide Estimated Duration: 6-8 Months 👇
4
149
818
141,289
Sec_Nerd07 retweeted
OSINT Resources by Country Here you'll find a collection of links to various OSINT tools, websites, and projects that are specific to different countries. github.com/wddadk/OSINT-for-… #cybersecurity #OSINT
2
70
226
18,110
I just wrote a new blog on IOS pentesting after a while. I got this idea when I was stuck for an entire day while setting things up for this assessment. I noticed a lot has changed in this landscape. sahil-security-nerd07.medium… #CyberSecurity #Pentesting #IOSpentesting
1
30
Sec_Nerd07 retweeted
5 Dec 2023
GAP by @xnl_h4ck3r, is a must-have Burp extension. It parses paths/URLs from JS and pinpoints key params via the sus_params project from @G0LDEN_infosec and myself. Plus, it generates targeted custom wordlists! 👨‍💻 github.com/xnl-h4ck3r/GAP-Bu… 🎥 youtube.com/watch?v=Os3bN0zU…
2
81
379
28,097
Sec_Nerd07 retweeted
4 Dec 2023
Frida-Labs The repo contains a series of challenges for learning #Frida for #Android Exploitation. github.com/DERE-ad2001/Frida… #cybersecurity #infosec
1
58
162
9,624
Sec_Nerd07 retweeted
28 Nov 2023
GREAT NEWS FOR Cloud Computing Professionals and Career Seekers! 107-Hour AWS Cloud Project Bootcamp! It's all For FREE 😱! This is Great and an excellent resource for anyone looking to dive into the world of cloud computing. The AWS Cloud Project Bootcamp is a free comprehensive training to equip you with the skills and knowledge to successfully design, build, and implement a cloud project. The Course Cover the Following: - Introduction to Billing and Architecture - Fundamentals of App Containerization - Techniques in Distributed Tracing - Implementing Decentralized Authentication - Exploring Postgres and RDS - DynamoDB and Serverless Caching Concepts - Strategies for Deploying Containers - Solving CORS with Load Balancers and Custom Domains - Serverless Image Processing Techniques - CI/CD with CodePipeline, CodeBuild, and CodeDeploy - In-depth Learning on CloudFormation - Modern API Development Course Link: Link 1: youtube.com/watch?v=zA8guDqf… Link 2: freecodecamp.org/news/free-1…. Remember to Follow @ZabihullahAtal for valuable Resources, Tech Knowledge, Tech Updates, and Career Growth. DM me for Pro Advice and Solutions. All the best!
11
197
629
97,674
Sec_Nerd07 retweeted
How Companies Ship Code To Production
2
154
589
61,729
Sec_Nerd07 retweeted
26 Nov 2023
Designing secure web API access is crucial for protecting both user data and application integrity We outline two widely used authentication methods: Token-based Authentication and HMAC Authentication. Token-based Authentication 1. The user submits their credentials through the client application. 2. Upon verifying the credentials, the Authentication Server issues a token. This token is a string of characters representing the user's session, usually with an expiration time. 3. The client appends this token to the HTTP header of subsequent requests to the Web Server. 4. The Web Server validates the token and grants access to the requested resources. HMAC Authentication 1. The client requests an API key from the Authentication Server. 2. The Authentication Server provides an API key (private key) and a Public APP ID (public key). 3. The client creates an HMAC signature (hmac A) using attributes such as the Public APP ID, request URI, HTTP method, request content, timestamp, and a nonce. 4. The client sends a request with hmac A in the HTTP header to the Web Server. 5. Upon receiving the request, the Web Server generates its own HMAC signature (hmac B) using the same attributes and the stored API key. 6. The Web Server compares hmac A and hmac B. If they match, it means the request is authentic. 7. The server then provides the requested resource to the client. In both methods, sensitive information like passwords and API keys should be transmitted securely, often over HTTPS. Token-based authentication is generally simpler to implement and is stateless, while HMAC provides additional security by ensuring that the message has not been tampered with in transit. When securing APIs, do you implement your own auth or use third-party solutions? – Subscribe to our weekly newsletter to get a Free System Design PDF (158 pages): bit.ly/496keA7
6
159
661
96,516
Sec_Nerd07 retweeted
IP Address Classes
1
215
1,008
87,883
Sec_Nerd07 retweeted
Insecure Ports vs Secure Ports
2
236
725
68,430
Sec_Nerd07 retweeted
API architectural styles are one of key factors behind seamless applications. Tomorrow thousands of subscribers will learn about the most prominent API architectural styles. Join us to get the issue: blog.levelupcoding.co
25
1,121
4,061
420,185
Sec_Nerd07 retweeted
2 Oct 2023
ChopChop - Quickly Discover Sensitive Endpoints/Files/Folders - Repo: github.com/michelin/ChopChop - Creator: @michelin_eng - #cybersecuritytips #CybersecurityNews #bugbountytips #ctf #infosec
2
48
191
17,169
Sec_Nerd07 retweeted
2 Oct 2023
Explaining 8 Popular Network Protocols in 1 Diagram. The method to download the high-resolution PDF is available at the end. Network protocols are standard methods of transferring data between two computers in a network. 1. HTTP (HyperText Transfer Protocol) HTTP is a protocol for fetching resources such as HTML documents. It is the foundation of any data exchange on the Web and it is a client-server protocol. 2. HTTP/3 HTTP/3 is the next major revision of the HTTP. It runs on QUIC, a new transport protocol designed for mobile-heavy internet usage. It relies on UDP instead of TCP, which enables faster web page responsiveness. VR applications demand more bandwidth to render intricate details of a virtual scene and will likely benefit from migrating to HTTP/3 powered by QUIC. 3. HTTPS (HyperText Transfer Protocol Secure) HTTPS extends HTTP and uses encryption for secure communications. 4. WebSocket WebSocket is a protocol that provides full-duplex communications over TCP. Clients establish WebSockets to receive real-time updates from the back-end services. Unlike REST, which always “pulls” data, WebSocket enables data to be “pushed”. Applications, like online gaming, stock trading, and messaging apps leverage WebSocket for real-time communication. 5. TCP (Transmission Control Protocol) TCP is is designed to send packets across the internet and ensure the successful delivery of data and messages over networks. Many application-layer protocols build on top of TCP. 6. UDP (User Datagram Protocol) UDP sends packets directly to a target computer, without establishing a connection first. UDP is commonly used in time-sensitive communications where occasionally dropping packets is better than waiting. Voice and video traffic are often sent using this protocol. 7. SMTP (Simple Mail Transfer Protocol) SMTP is a standard protocol to transfer electronic mail from one user to another. 8. FTP (File Transfer Protocol) FTP is used to transfer computer files between client and server. It has separate connections for the control channel and data channel. – Subscribe to our newsletter to download the high-resolution PDF. After signing up, find the download link on the success page: bytebytego.ck.page/3581072b8…
77
4,420
17,304
2,856,585