home.social

#cyberchef — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cyberchef, aggregated by home.social.

  1. Организовал весь пентест-арсенал в одном месте: всё под рукой, офлайн и на русском

    Привет, Хабр. Я Александр, мне 33. Хакинг у меня хобби, а не работа: CTF, Hack The Box, иногда багбаунти по выходным. И каждый раз одно и то же. Открываешь тулзу — первым делом —help . Флагов экран, все на английском. Сидишь, вычитываешь, что тебе сейчас нужно. Собрал один флаг, переключился на второй — а как пишется первый, уже забыл. Снова —help . И по новой. На сборку одной команды уходит больше времени, чем на саму работу. Команду собрал. А дальше? nmap отработал, передо мной открытые порты — и я завис. За что хвататься? В каком порядке? Это знание у каждого где-то в голове, и достаёшь его каждый раз заново. Словарь. И где он лежит-то. /usr/share/wordlists ? seclists ? А подкаталог? Опять ls , find , вспоминаешь путь, который вбивал сто раз. Пейлоад. Лезешь в PayloadsAllTheThings — а там стена. Какой брать? На каком этапе? Что выстрелит, а что лежит для галочки? Непонятно. И так весь тест размазан по тридцати вкладкам. HackTricks, PayloadsAllTheThings, GTFOBins, revshells, рядом гугл с переводчиком — половина же на английском. Плюс папка своих заметок. Бесит. Особенно на вебе: нашёл точку, надо быстро прогнать пейлоады — а ты вместо дела вспоминаешь, где у тебя что лежит. В какой-то вечер я психанул и начал сваливать всё нужное в одно место. Локально, на русском, поиск по одной кнопке. Оно разрослось, и я сам не заметил, как это стало отдельным проектом. Выложил в опенсорс. Назвал ARS3NAL — тут без фантазии, арсенал он и есть арсенал.

    habr.com/ru/articles/1052866/

    #пентест #bug_bounty #open_source #информационная_безопасность #pentest #GTFOBins #CyberChef #payloads #методология_тестирования #ARS3NAL

  2. Организовал весь пентест-арсенал в одном месте: всё под рукой, офлайн и на русском

    Привет, Хабр. Я Александр, мне 33. Хакинг у меня хобби, а не работа: CTF, Hack The Box, иногда багбаунти по выходным. И каждый раз одно и то же. Открываешь тулзу — первым делом —help . Флагов экран, все на английском. Сидишь, вычитываешь, что тебе сейчас нужно. Собрал один флаг, переключился на второй — а как пишется первый, уже забыл. Снова —help . И по новой. На сборку одной команды уходит больше времени, чем на саму работу. Команду собрал. А дальше? nmap отработал, передо мной открытые порты — и я завис. За что хвататься? В каком порядке? Это знание у каждого где-то в голове, и достаёшь его каждый раз заново. Словарь. И где он лежит-то. /usr/share/wordlists ? seclists ? А подкаталог? Опять ls , find , вспоминаешь путь, который вбивал сто раз. Пейлоад. Лезешь в PayloadsAllTheThings — а там стена. Какой брать? На каком этапе? Что выстрелит, а что лежит для галочки? Непонятно. И так весь тест размазан по тридцати вкладкам. HackTricks, PayloadsAllTheThings, GTFOBins, revshells, рядом гугл с переводчиком — половина же на английском. Плюс папка своих заметок. Бесит. Особенно на вебе: нашёл точку, надо быстро прогнать пейлоады — а ты вместо дела вспоминаешь, где у тебя что лежит. В какой-то вечер я психанул и начал сваливать всё нужное в одно место. Локально, на русском, поиск по одной кнопке. Оно разрослось, и я сам не заметил, как это стало отдельным проектом. Выложил в опенсорс. Назвал ARS3NAL — тут без фантазии, арсенал он и есть арсенал.

    habr.com/ru/articles/1052866/

    #пентест #bug_bounty #open_source #информационная_безопасность #pentest #GTFOBins #CyberChef #payloads #методология_тестирования #ARS3NAL

  3. Организовал весь пентест-арсенал в одном месте: всё под рукой, офлайн и на русском

    Привет, Хабр. Я Александр, мне 33. Хакинг у меня хобби, а не работа: CTF, Hack The Box, иногда багбаунти по выходным. И каждый раз одно и то же. Открываешь тулзу — первым делом —help . Флагов экран, все на английском. Сидишь, вычитываешь, что тебе сейчас нужно. Собрал один флаг, переключился на второй — а как пишется первый, уже забыл. Снова —help . И по новой. На сборку одной команды уходит больше времени, чем на саму работу. Команду собрал. А дальше? nmap отработал, передо мной открытые порты — и я завис. За что хвататься? В каком порядке? Это знание у каждого где-то в голове, и достаёшь его каждый раз заново. Словарь. И где он лежит-то. /usr/share/wordlists ? seclists ? А подкаталог? Опять ls , find , вспоминаешь путь, который вбивал сто раз. Пейлоад. Лезешь в PayloadsAllTheThings — а там стена. Какой брать? На каком этапе? Что выстрелит, а что лежит для галочки? Непонятно. И так весь тест размазан по тридцати вкладкам. HackTricks, PayloadsAllTheThings, GTFOBins, revshells, рядом гугл с переводчиком — половина же на английском. Плюс папка своих заметок. Бесит. Особенно на вебе: нашёл точку, надо быстро прогнать пейлоады — а ты вместо дела вспоминаешь, где у тебя что лежит. В какой-то вечер я психанул и начал сваливать всё нужное в одно место. Локально, на русском, поиск по одной кнопке. Оно разрослось, и я сам не заметил, как это стало отдельным проектом. Выложил в опенсорс. Назвал ARS3NAL — тут без фантазии, арсенал он и есть арсенал.

    habr.com/ru/articles/1052866/

    #пентест #bug_bounty #open_source #информационная_безопасность #pentest #GTFOBins #CyberChef #payloads #методология_тестирования #ARS3NAL

  4. I'm looking forward to our cybersecurity capture the flag trying out together afternoon! This event is free and open for all genders. No registration required, just show up with your computer (or borrow one from us).
    More info on the website. :)

    And they're are always cockies, offline and with real life crumbles. 😅

    #it #cybersecurity #fliNTA #feminist #Frauen #linux #meetup #opensource #ctf #ccc #c3w #tu #University #selforganized #vienna #Austria #Wien #meetup #learning #workshop #cyberchef #hacking #ethicalHacking #redteaming
    #blueteaming
    @totientfunction @c3wien

  5. I'm looking forward to our cybersecurity capture the flag trying out together afternoon! This event is free and open for all genders. No registration required, just show up with your computer (or borrow one from us).
    More info on the website. :)

    And they're are always cockies, offline and with real life crumbles. 😅

    #it #cybersecurity #fliNTA #feminist #Frauen #linux #meetup #opensource #ctf #ccc #c3w #tu #University #selforganized #vienna #Austria #Wien #meetup #learning #workshop #cyberchef #hacking #ethicalHacking #redteaming
    #blueteaming
    @totientfunction @c3wien

  6. I'm looking forward to our cybersecurity capture the flag trying out together afternoon! This event is free and open for all genders. No registration required, just show up with your computer (or borrow one from us).
    More info on the website. :)

    And they're are always cockies, offline and with real life crumbles. 😅

    #it #cybersecurity #fliNTA #feminist #Frauen #linux #meetup #opensource #ctf #ccc #c3w #tu #University #selforganized #vienna #Austria #Wien #meetup #learning #workshop #cyberchef #hacking #ethicalHacking #redteaming
    #blueteaming
    @totientfunction @c3wien

  7. I'm looking forward to our cybersecurity capture the flag trying out together afternoon! This event is free and open for all genders. No registration required, just show up with your computer (or borrow one from us).
    More info on the website. :)

    And they're are always cockies, offline and with real life crumbles. 😅

    #it #cybersecurity #fliNTA #feminist #Frauen #linux #meetup #opensource #ctf #ccc #c3w #tu #University #selforganized #vienna #Austria #Wien #meetup #learning #workshop #cyberchef #hacking #ethicalHacking #redteaming
    #blueteaming
    @totientfunction @c3wien

  8. I'm looking forward to our cybersecurity capture the flag trying out together afternoon! This event is free and open for all genders. No registration required, just show up with your computer (or borrow one from us).
    More info on the website. :)

    And they're are always cockies, offline and with real life crumbles. 😅

    #it #cybersecurity #fliNTA #feminist #Frauen #linux #meetup #opensource #ctf #ccc #c3w #tu #University #selforganized #vienna #Austria #Wien #meetup #learning #workshop #cyberchef #hacking #ethicalHacking #redteaming
    #blueteaming
    @totientfunction @c3wien

  9. 🔎 XSS (HIGH, CVSS 7.2) in GCHQ CyberChef <11.0.0 (CVE-2026-42615): Improper input neutralization in Show Base64 offsets lets attackers inject scripts remotely — info theft/session hijack possible. No fix yet. Avoid untrusted input. radar.offseq.com/threat/cve-20 #OffSeq #CyberChef #XSS

  10. 🔎 XSS (HIGH, CVSS 7.2) in GCHQ CyberChef <11.0.0 (CVE-2026-42615): Improper input neutralization in Show Base64 offsets lets attackers inject scripts remotely — info theft/session hijack possible. No fix yet. Avoid untrusted input. radar.offseq.com/threat/cve-20 #OffSeq #CyberChef #XSS

  11. 🔎 XSS (HIGH, CVSS 7.2) in GCHQ CyberChef <11.0.0 (CVE-2026-42615): Improper input neutralization in Show Base64 offsets lets attackers inject scripts remotely — info theft/session hijack possible. No fix yet. Avoid untrusted input. radar.offseq.com/threat/cve-20 #OffSeq #CyberChef #XSS

  12. 🔎 XSS (HIGH, CVSS 7.2) in GCHQ CyberChef <11.0.0 (CVE-2026-42615): Improper input neutralization in Show Base64 offsets lets attackers inject scripts remotely — info theft/session hijack possible. No fix yet. Avoid untrusted input. radar.offseq.com/threat/cve-20 #OffSeq #CyberChef #XSS

  13. Sequence [TryHackMe] [Writeup]

    Room Info Name: Sequence Platform: TryHackMe Difficulty: Medium Link: https://tryhackme.com/room/sequence Description: Chain multiple vulnerabilities to take control of a system. Task 1: Challenge Robert made some last-minute updates to the review.thm website before heading off on vacation. He claims that the secret information of the financiers is fully protected. But are his defenses truly airtight? Your challenge is to exploit the vulnerabilities and gain complete control of the […]

    aredopseagle.wordpress.com/202

  14. Combine the Encode/Decode/Hash add-on with CyberChef operations in ZAP Encode/Decode Scripts for flexible encoding, decoding, and hashing in your testing workflow.
    zaproxy.org/blog/2026-02-17-en
    #zaproxy #appsec #cyberchef

  15. Combine the Encode/Decode/Hash add-on with CyberChef operations in ZAP Encode/Decode Scripts for flexible encoding, decoding, and hashing in your testing workflow.
    zaproxy.org/blog/2026-02-17-en
    #zaproxy #appsec #cyberchef

  16. Combine the Encode/Decode/Hash add-on with CyberChef operations in ZAP Encode/Decode Scripts for flexible encoding, decoding, and hashing in your testing workflow.
    zaproxy.org/blog/2026-02-17-en
    #zaproxy #appsec #cyberchef

  17. Combine the Encode/Decode/Hash add-on with CyberChef operations in ZAP Encode/Decode Scripts for flexible encoding, decoding, and hashing in your testing workflow.
    zaproxy.org/blog/2026-02-17-en
    #zaproxy #appsec #cyberchef

  18. Combine the Encode/Decode/Hash add-on with CyberChef operations in ZAP Encode/Decode Scripts for flexible encoding, decoding, and hashing in your testing workflow.
    zaproxy.org/blog/2026-02-17-en
    #zaproxy #appsec #cyberchef

  19. CyberChef is a very cool web app made by GCHQ.

    I originally found out about it because @UK_Daniel_Card tweeted about it a long time ago.

    I created a blog post about using CyberChef and self-hosting it with Docker.

    Check it out. thedxt.ca/2026/01/cyberchef/

    #Cyber #CyberChef #Docker

  20. CyberChef is a very cool web app made by GCHQ.

    I originally found out about it because @UK_Daniel_Card tweeted about it a long time ago.

    I created a blog post about using CyberChef and self-hosting it with Docker.

    Check it out. thedxt.ca/2026/01/cyberchef/

    #Cyber #CyberChef #Docker

  21. CyberChef is a very cool web app made by GCHQ.

    I originally found out about it because @UK_Daniel_Card tweeted about it a long time ago.

    I created a blog post about using CyberChef and self-hosting it with Docker.

    Check it out. thedxt.ca/2026/01/cyberchef/

    #Cyber #CyberChef #Docker

  22. CyberChef is a very cool web app made by GCHQ.

    I originally found out about it because @UK_Daniel_Card tweeted about it a long time ago.

    I created a blog post about using CyberChef and self-hosting it with Docker.

    Check it out. thedxt.ca/2026/01/cyberchef/

    #Cyber #CyberChef #Docker

  23. CyberChef is a very cool web app made by GCHQ.

    I originally found out about it because @UK_Daniel_Card tweeted about it a long time ago.

    I created a blog post about using CyberChef and self-hosting it with Docker.

    Check it out. thedxt.ca/2026/01/cyberchef/

    #Cyber #CyberChef #Docker

  24. This loading message on #cyberchef never made so much sense...

  25. This loading message on #cyberchef never made so much sense...

  26. This loading message on #cyberchef never made so much sense...

  27. This loading message on #cyberchef never made so much sense...

  28. This loading message on #cyberchef never made so much sense...

  29. #Cyberchef

    Sachen gibts
    ​:gura_laugh:​

    CyberChef is a simple, intuitive web app for carrying out all manner of "cyber" operations within a web browser. These operations include simple encoding like XOR and Base64, more complex encryption like AES, DES and Blowfish, creating binary and hexdumps, compression and decompression of data, calculating hashes and checksums, IPv6 and X.509 parsing, changing character encodings, and much more.

    The tool is designed to enable both technical and non-technical analysts to manipulate data in complex ways without having to deal with complex tools or algorithms. It was conceived, designed, built and incrementally improved by an analyst in their 10% innovation time over several years.
    #Love #Opensource

    https://other.li/cyberchef

  30. #Cyberchef

    Sachen gibts
    ​:gura_laugh:​

    CyberChef is a simple, intuitive web app for carrying out all manner of "cyber" operations within a web browser. These operations include simple encoding like XOR and Base64, more complex encryption like AES, DES and Blowfish, creating binary and hexdumps, compression and decompression of data, calculating hashes and checksums, IPv6 and X.509 parsing, changing character encodings, and much more.

    The tool is designed to enable both technical and non-technical analysts to manipulate data in complex ways without having to deal with complex tools or algorithms. It was conceived, designed, built and incrementally improved by an analyst in their 10% innovation time over several years.
    #Love #Opensource

    https://other.li/cyberchef

  31. #Cyberchef

    Sachen gibts
    ​:gura_laugh:​

    CyberChef is a simple, intuitive web app for carrying out all manner of "cyber" operations within a web browser. These operations include simple encoding like XOR and Base64, more complex encryption like AES, DES and Blowfish, creating binary and hexdumps, compression and decompression of data, calculating hashes and checksums, IPv6 and X.509 parsing, changing character encodings, and much more.

    The tool is designed to enable both technical and non-technical analysts to manipulate data in complex ways without having to deal with complex tools or algorithms. It was conceived, designed, built and incrementally improved by an analyst in their 10% innovation time over several years.
    #Love #Opensource

    https://other.li/cyberchef