#EthicalHacking

2026-02-04

🚨 Active exploitation confirmed: CVE-2026-24061.

This isn't just theoretical, it's a massive exposure. With nearly 800,000 Telnet instances exposed globally across legacy IoT and outdated servers, the risk of a root-level compromise is real and immediate.

We have updated Pentest-Tools.com to help you validate your exposure:

πŸ“‘ Network Scanner - detects exposed Telnet services across your internal and external perimeters, identifying potentially vulnerable GNU Inetutils daemons.

🎯 Sniper Auto-Exploiter - safely executes a proof-of-concept to confirm if the authentication bypass is actually exploitable on your systems, providing the evidence needed to prioritize an immediate fix.

⚠️ Crucial detail: This critical vulnerability exists because telnetd fails to sanitize the USER environment variable. An attacker can simply supply -f root to bypass the login prompt entirely and gain instant, unauthenticated root shell access.

Attacks are happening in real-time. Validate your risk before it becomes a root-level compromise.

#offensivesecurity #ethicalhacking #infosec #cybersecurity

Check out more details about this critical vulnerability: pentest-tools.com/vulnerabilit

Detect with Network Scanner: pentest-tools.com/network-vuln

Validate with Sniper Auto-Exploiter: pentest-tools.com/exploit-help

CVE-2026-24061 - Network ScannerCVE-2026-24061 - Sniper Auto-ExploiterCVE-2026-24061
2026-02-03

January was all about detection depth and clarity.

Here we go with the most important updates in Pentest-Tools.com:

πŸ•·οΈ Deeper logic - the Website Scanner now hunts down CL.0 request smuggling and serialized objects inside JSON payloads.

🎯 Validate your exposure - you know the risks of React2Shell and FortiWeb. Now use Sniper: Auto-Exploiter to prove your patches actually hold up against real exploits.

βš“ Port-aware findings - we now group findings by port. Same vulnerability, different port? That is now a separate entry for cleaner reporting.

See the full breakdown on January updates here: pentest-tools.com/change-log

Until next time: Stay sharp. Stay human.

#Infosec #EthicalHacking #OffensiveSecurity

Wen Bin :verified:kongwenbin@infosec.exchange
2026-02-03

πŸ’‘ Understanding core network protocols is fundamental for any aspiring cyber security professional. One of the most common that you will encounter is SMB (Server Message Block).

In my latest video, I provide a detailed, beginner friendly walkthrough of the "DANCING" machine from Hack The Box, focusing entirely on SMB enumeration and access πŸš€

You will learn:
πŸ”Ή What SMB (Server Message Block) is and how it works
πŸ”Ή Common SMB ports (139 & 445) and why they matter
πŸ”Ή How to use Nmap for targeted service enumeration such as SMB services
πŸ”Ή How to enumerate SMB shares using smbclient
πŸ”Ή Understanding anonymous / misconfigured shares
πŸ”Ή Downloading files from SMB shares and capturing the flag

This is a perfect starting point for anyone new to ethical hacking.

πŸŽ₯ Watch the HTB DANCING walkthrough here:

youtube.com/watch?v=CpaBWeq9JU8

πŸ“‚ Full playlist:

youtube.com/playlist?list=PL2m

If you are transitioning into cybersecurity, bug bounty, or pentesting - this series is built for you.

Happy learning and keep hacking ethically πŸ”

#CyberSecurity #EthicalHacking #HackTheBox #PenetrationTesting #Learning #TechEducation #BeginnerHacking #HTBStartingPoint #Nmap #KaliLinux #SMB

Alonso Caballero / ReYDeSAlonso_ReYDeS@infosec.exchange
2026-02-02
πŸ΄β€β˜ οΈ El Curso Fundamentos de Hacking Γ‰tico estΓ‘ permanente disponible en el aula virtual para acceso inmediato. πŸ“² WhatsApp: https://wa.me/51949304030 πŸ’» https://www.reydes.com/e/Curso_Fundamentos_de_Hacking_Etico #cybersecurity #ethicalhacking #infosec #bugbounty #hacking

New daily playlist: the latest talks and tutorials in cybersecurity and hacking. Stay sharp, stay safe. πŸ‘‰ youtube.com/playlist?list=PLXq
#CyberSecurity #InfoSec #EthicalHacking #OnlineSafety #Phishing

New daily playlist: the latest talks and tutorials in cybersecurity and hacking. Stay sharp, stay safe. πŸ‘‰ youtube.com/playlist?list=PLXq
#CyberSecurity #InfoSec #EthicalHacking #OnlineSafety #Phishing

2026-02-01

Burp Suite: A Comprehensive Web Security Testing Tool for Beginners
Burp Suite is a powerful web application security testing tool primarily used by ethical hackers, penetration testers, and cybersecurity students. It intercepts, analyzes, and modifies HTTP/HTTPS traffic between the browser and a website to identify security vulnerabilities such as weak login systems, input validation issues, and authentication problems. The main components of Burp Suite include Proxy, Target, Repeater, Intruder, Scanner (Pro Version), Decoder, and Comparer. By intercepting and manipulating HTTPS traffic with its CA Certificate, users can safely analyze secure websites for learning and testing purposes. A real-life example involves testing a login page, intercepting the request using Burp Proxy, modifying parameters, and checking the server's response to discover potential security flaws. Key lesson: Burp Suite is an essential tool for beginners looking to learn web security testing and discover vulnerabilities in applications. #BugBounty #Cybersecurity #WebSecurity #PenTesting #EthicalHacking

shadowattackers.medium.com/bur

New daily playlist: the latest talks and tutorials in cybersecurity and hacking. Stay sharp, stay safe. πŸ‘‰ youtube.com/playlist?list=PLXq
#CyberSecurity #InfoSec #EthicalHacking #OnlineSafety #Phishing

New playlist online: from malware analysis to ethical hacking demos. Check it out here πŸ‘‰ youtube.com/playlist?list=PLXq
#Malware #EthicalHacking #CyberDefense #NetworkSecurity #IncidentResponse

New playlist online: from malware analysis to ethical hacking demos. Check it out here πŸ‘‰ youtube.com/playlist?list=PLXq
#Malware #EthicalHacking #CyberDefense #NetworkSecurity #IncidentResponse

New playlist online: from malware analysis to ethical hacking demos. Check it out here πŸ‘‰ youtube.com/playlist?list=PLXq
#Malware #EthicalHacking #CyberDefense #NetworkSecurity #IncidentResponse

Latest cyber & hacking videos compiled for you twice a day. Watch now & stay ahead of threats. πŸ”’ youtube.com/playlist?list=PLXq
#CyberSecurity #InfoSec #CloudSecurity #Phishing #EthicalHacking

Hack smarter, defend stronger. Catch the newest daily videos curated for security pros and learners. 🎯 youtube.com/playlist?list=PLXq
#CyberSecurity #ThreatIntelligence #EthicalHacking #DataSecurity #DarkWeb

Wen Bin :verified:kongwenbin@infosec.exchange
2026-01-27

Just published a new beginner-friendly walkthrough for Hack The Box Starting Point - FAWN (Tier 0).

This machine is an excellent introduction to FTP (File Transfer Protocol) and helps beginners understand:
πŸ”Ή How FTP works
πŸ”Ή Why FTP is insecure by design
πŸ”Ή What are the secure alternatives of FTP
πŸ”Ή How attackers enumerate services using Nmap
πŸ”Ή How anonymous FTP login works
πŸ”Ή What is the man command
πŸ”Ή How to retrieve files and capture the flag

Instead of rushing through commands, this walkthrough explains the concepts behind every step, which is something I wish I had when I first started learning ethical hacking.

If you are new to penetration testing or is an aspiring ethical hacker, Hack The Box Starting Point is a fantastic learning platform.

πŸŽ₯ Watch the FAWN walkthrough here:

youtube.com/watch?v=SLFJOEq5w6Y

πŸ“‚ Full playlist:

youtube.com/watch?v=OqxPRwP8t_

If you are transitioning into cybersecurity, bug bounty, or pentesting - this series is built for you.

Happy learning and keep hacking ethically πŸ”

#CyberSecurity #EthicalHacking #HackTheBox #PenetrationTesting #Learning #TechEducation #BeginnerHacking #HTBStartingPoint #Nmap #KaliLinux #FTP

New daily playlist: the latest talks and tutorials in cybersecurity and hacking. Stay sharp, stay safe. πŸ‘‰ youtube.com/playlist?list=PLXq
#CyberSecurity #InfoSec #EthicalHacking #OnlineSafety #Phishing

New daily playlist: the latest talks and tutorials in cybersecurity and hacking. Stay sharp, stay safe. πŸ‘‰ youtube.com/playlist?list=PLXq
#CyberSecurity #InfoSec #EthicalHacking #OnlineSafety #Phishing

New daily playlist: the latest talks and tutorials in cybersecurity and hacking. Stay sharp, stay safe. πŸ‘‰ youtube.com/playlist?list=PLXq
#CyberSecurity #InfoSec #EthicalHacking #OnlineSafety #Phishing

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst