Shinning Star

Let your star shine …

  • LinkedIn
  • facebook
  • Twitter
  • github
  • Home
  • About Me
  • Success-story
    • My OSCP Journey
    • My OSWE journey
    • My OSEP journey
    • My OSDA Journey
    • My CISSP Journey
  • Cyber security
    • Pentest
    • Bug hunting
    • Open source
  • Contact

Category - pentest

  • bughunting
  • pentest

BurpBugFinder – Custom Burp extender

November 10, 2022
by AdminStar@
9 min read
Add Comment

I’m thrilled to publish my first BurpSuite plugin that I’ve built. The purpose is to find bugs on websites without typing any code, just by doing a normal browsing. This first version focuses only on XSS vulnerability...

Continue reading

  • pentest
  • tutorial

Active directory account takeover with shadow credential : AddKeyCredentialLink abuse

November 4, 2022
by AdminStar@
10 min read
Add Comment

In this post I would like to talk about shadow credential attack that can be exploited by abusing AddKeyCredentialLink privilege in an Active Directory Infrastructure. 1-What is shadow credential ? It is a technique allowing an...

Continue reading

  • pentest
  • tutorial

WSUS privilege escalation

November 4, 2022
by AdminStar@
10 min read
Add Comment

Recently, I’ve discovered a new way to escalate privilege on windows through WSUS when HTTP protocol is used instead of HTTPS. In this quick explanation I’ll describe what WSUS is, explain how to detect the vulnerability and...

Continue reading

  • pentest

SQL Injection whitebox approach (final part)

September 8, 2022
by AdminStar@
11 min read
Add Comment

SQL Injection whitebox approach (final part) Dear readers, in parts 1 and 2, we worked on files and patterns identification, enabling database logging and sending requests with a custom python script. In this 3rd and final...

Continue reading

  • pentest

SQL Injection whitebox approach (part2)

August 30, 2022
by AdminStar@
11 min read
Add Comment

SQL Injection whitebox approach (part2) In the part 1 of this serie, we worked on : Identification of the files we want to deal with; Defining the pattern we will be looking for in the file, for us to inject our payload (GET...

Continue reading

  • pentest

SQL Injection whitebox approach (part1)

August 22, 2022
by AdminStar@
12 min read
Add Comment

SQL Injection whitebox approach (part1) Have you ever been in a situation where you have a bunch of code to review ? Let’s take an example of Atutor, a fully working Learning Management System (LMS) available at  which...

Continue reading

  • pentest

Linux privilege escalation

November 7, 2020
by AdminStar@
10 min read
Add Comment

After many months of updating my privileges escalation skills on Linux, I’ve decided to release a script. I have written this based on my experiences with more than 150 linux boxes. While there is already many scripts for...

Continue reading

  • pentest

Windows privilege-escalation guide

July 13, 2020
by AdminStar@
14 min read
Add Comment

Hi people! Here I am writing a quick guide for windows privilege escalation. If you’re learning pentesting, this can help you. This guide is based on my own experience, feel free to customize it.   We are assuming you...

Continue reading

Previous 1 2
Copyright © 2025. Created by Meks. Powered by WordPress.
  • Home
  • About Me
  • Success-story
    • My OSCP Journey
    • My OSWE journey
    • My OSEP journey
    • My OSDA Journey
    • My CISSP Journey
  • Cyber security
    • Pentest
    • Bug hunting
    • Open source
  • Contact
  • LinkedIn
  • facebook
  • Twitter
  • github