Skip to content
GainSec

GainSec

Where OSINT, Hacking, Penetration Testing, Privacy, Piracy, Information Security, Cyber Security and Law are a lifestyle.

  • Home
  • Projects
  • Shop
  • Resume & CV
  • Press
  • Inquiries
  • About Me
  • Archives
  • Cart
  • $0.00 0 items

Category: Penetration Testing

CVE-2022-37857, CVE-2022-37163, CVE-2022-37164 Hardcoded Credentials/Weak Password Policies

A location sharing open source server and android client was found to hardcode credentials and allow weak passwords by default (including blank passwords!)

gainsec Android Hacking, CVE, Hacking Android, Mobile Penetration Testing, Pentesting Android, Vulnerablility/Security Research Leave a comment August 7, 2022August 1, 2026

CVE-2022-35142, CVE-2022-35143, CVE-2022-35144 – DoS, XSS and Weak Password Policy in Renato a Markdown powered knowledge base

Multiple new CVEs discovered and disclosed! XSS, DoS and a weak password policy!

gainsec CVE, Vulnerablility/Security Research, Web Application Pen Testing Leave a comment August 4, 2022August 1, 2026

CVE-2022-34613, CVE-2022-34618, CVE-2022-34619 – Multiple XSS (And more) in Mealie

Multiple new CVEs discovered and disclosed! XSS, file uploads and more!

gainsec CVE, Vulnerablility/Security Research, Web Application Pen Testing Leave a comment August 2, 2022August 1, 2026

CVE-2022-34625 – Server-Side Template Injection to Remote Code Execution (SSTI) to (RCE) in Mealie – A lesson in patience

A detailed walkthrough of CVE-2022-34625 aka a Server-Side Template Injection (SSTI) to Remote Code Execution (RCE)

gainsec CVE, Vulnerablility/Security Research, Web Application Pen Testing Leave a comment August 2, 2022August 1, 2026

Azure Cloud Pen Testing Software Suite

A great collection of scripts for attacking and defending Azure environments. Perfect for any azure cloud security assessment, audit or penetration test.

gainsec Azure Penetration Testing, Cloud Penetration Testing, Everything Else Leave a comment April 15, 2022August 1, 2026

Should I add this Repo to TreeHouse Wordlists?

You tell me what you think of this wordlist repo? Is it worth adding?

gainsec Everything Else, TreeHouse Wordlists Leave a comment April 5, 2022August 1, 2026

CLI Web Discovery Alternative to Dirb, Dirsearch, Etc

A great alternative to have for web discovery during web app pen tests or bug bounties.

gainsec Bug Bounty, Everything Else, Web Application Pen Testing Leave a comment March 21, 2022August 1, 2026

All in One RF/HID reader/writer smaller then the ProxMark?!

A great and useful device for any physical penetration test or hardware hacking engagement.

gainsec Everything Else, Hardware, Physical Penetration Test, Physical Security Leave a comment March 17, 2022August 1, 2026

An Azure AD Recon and Exploitation Framework

A toolset for performing recon and exploiting an Azure AD instance.

gainsec Azure Penetration Testing, Cloud, Cloud Penetration Testing, Everything Else Leave a comment March 5, 2022August 1, 2026

Holy Smokes Batman! Another big repo of Bug Bounty Reports, Cheat sheets, Checklists and more!

Another Repo of Web Application and API Bug Bounty, Penetration test and security assessment documents, reports and more!

gainsec API Penetration Testing, Everything Else, Web Application Pen Testing Leave a comment February 25, 2022August 1, 2026

Posts navigation

Older posts
Newer posts

Follow

  • GitHub
  • X
  • Instagram
  • Tumblr
  • Pinterest
  • LinkedIn
  • YouTube
  • LinkedIn
  • Twitch
  • Facebook
  • Etsy
Loading Comments...