CSbyGB - Pentips
⌘Ctrlk
Buy me a tea
CSbyGB - Pentips
    • Welcome to CSbyGB's Pentips
    • Basics
    • DNS
    • FTP
    • HTTP & HTTPS
    • IMAP
    • IPMI
    • MSSQL
    • MYSQL
    • NFS
    • Oracle TNS
    • POP3
    • RDP
    • RPC
    • Rservices
    • Rsync
    • SMB
    • SMTP
    • SNMP
    • SSH
    • VOIP and related protocols
    • Winrm
    • WMI
    • Useful tips when you find unknown ports
    • Introduction
    • Information Gathering
    • Scanning & Enumeration
    • Exploitation (basics)
    • Password Attacks
    • Post Exploitation
    • Lateral Movement
    • Proof-of-Concept
    • Post-Engagement
    • MITRE ATT&CK
    • External Pentest
    • Introduction to HTTP and web
    • Enumeration
    • OWASP Top 10
    • General Methodo & Misc Tips
    • Web Services and API
    • Vunerabilities and attacks
      • Clickjacking
      • CORS (Misconfigurations)
      • CSRF
      • SSRF
      • Bypass captcha
      • Template Injection (client and server side)
      • MFA bypass
      • XXE
    • Exposed git folder
    • Docker exploitation and Docker vulnerabilities
    • Websockets
    • Android
    • IOS
    • Wireless pentest
    • Cloud Pentest
    • Google Cloud Platform
    • AWS
    • Thick Client
    • ATM
    • IoT
    • Secure code review
    • Java notes for Secure Code Review
    • MITRE ATLAS
    • OWASP ML and LLM
    • Hugging face
    • AI Python
    • Gemini
    • Ollama
    • Web Application and API Pentest Checklist
    • Linux Privesc Checklist
    • Mobile App Pentest Checklist
    • Burpsuite
    • Android Studio
    • Frida
    • CrackMapExec
    • Netcat and alternatives
    • Nmap
    • Nuclei
    • Evil Winrm
    • Metasploit
    • Covenant
    • Mimikatz
    • Passwords, Hashes and wordlist tools
    • WFuzz
    • WPScan
    • Powershell Empire
    • Curl
    • Vulnerability Scanning tools
    • Payload Tools
    • Out of band Servers
    • STEWS
    • Webcrawlers
    • Websocat
    • General tips
    • Setup your pentest lab
    • Initial Foothold
    • Useful commands and tools for pentest on Linux
    • Privilege Escalation
    • Offensive windows
    • Enumeration and general Win tips
    • Privilege Escalation
    • Active Directory
    • Attacking Active Directory
    • Post-Compromise Enumeration
    • Post Compromise Attacks
    • Persistence
    • AV Evasion
    • Weaponization
    • Useful commands in Powershell, CMD and Sysinternals
    • Windows Internals
    • Python programming
    • My scripts
    • Kotlin
    • Assembly
    • Buffer Overflow - Stack based - Winx86
    • Buffer Overflow - Stack based - Linux x86
    • OSINT
    • Create an OSINT lab
    • Sock Puppets
    • Search engines
    • OSINT Images
    • OSINT Email
    • OSINT Password
    • OSINT Usernames
    • OSINT People
    • OSINT Social Media
    • OSINT Websites
    • OSINT Business
    • OSINT Wireless
    • OSINT Tools
    • Write an OSINT report
    • Flipper Zero
    • OMG cables
    • Rubber ducky
    • File transfers between target and attacking machine
    • Maintaining Access
    • Pivoting
    • Cleaning up
    • How to report your findings
    • Red Team
    • Defenses Enumeration
    • AV Evasion
    • Hackthebox Tracks
    • Hackthebox Writeups
    • TryHackme Writeups
    • Giskard Red Writeups
    • Vulnmachines Writeups
    • Mobile Hacking Lab
    • Portswigger Web Security Academy - XSS
    • Portswigger Web Security Academy - Web LLM attacks
    • PS - Web cache deception
    • OWASP projects and challenges writeups
    • Vulnerable APIs
    • Various Platforms
    • How to make a gitbook
    • Marp
    • Linux Tips
    • Docker
    • VSCodium
    • Git Tips
    • Obsidian
    • Running Samsung Notes on Linux via a Windows VM
    • Durable skills wheel/Roue des compétences durables
    • Projects
    • My Talks about Web Pentest
    • My talks about Android Application hacking
    • Other of my talks and Podcast
    • A list of random resources
Powered by GitBook
For the complete documentation index, see llms.txt. This page is also available as Markdown.
ChatGPT
  1. Web Pentesting
  2. Vunerabilities and attacks

MFA bypass

Resources

  • Cheatsheet - 15 Methods to Bypass 2FA Mechanism - rashahacks

  • 5 different methods for 2FA Bypass Techniques - Muhammad Noman Khalid

PreviousTemplate Injection (client and server side)NextXXE

Last updated 2 years ago