Using Third Party resource for Cybersecurity & Pen Testing (W
Hacking sometimes does not mean that you work Like Movies. it can be anything resistant in your way. removing those things that can make… Using Third Party resource for Cybersecurity & Pen Testing (W-A-T-L-A-1) Hacking sometimes does
Quick overview
| Field | Detail |
|---|---|
| Topic | information |
| Guide | Using Third Party resource for Cybersecurity & Pen Testing (W |
| Tags | information, resources, com, json, twitter, time |
| Length | About 1185 words |
| Practice rule | Authorized labs only — stay ethical |
Hacking sometimes does not mean that you work Like Movies. it can be anything resistant in your way. removing those things that can make…
Using Third Party resource for Cybersecurity & Pen Testing (W-A-T-L-A-1)
Hacking sometimes does not mean that you work Like Movies. it can be anything resistant in your way. removing those things that can make small or large-scale things.
for example, you are using a Chrome extension that has a Timer. every 50 minutes it asks you to wait for 30 minutes so what you will do?
- Write big code that can remove that timer
- make a small change that makes Your work easy
answer Is a small action that helps You to solve your problem
It is often very useful to look over the thing that you know how to use something that someone has made Something made by someone else. these thing is beneficial for both people
- firstly those who have no knowledge about cyber security .
- And on the other hand there are those who have knowledge but do not know how to use these things For example, a person has made a brick, we should know what the brick is made of.
Version : 0.02 :
The flawing article still in update each time when i will update put major updates. on some points we must need Basic information and language’s understanding,
And today we will see the how using third party resources can help you and save your time before that we need to understand about for what purpose we are going to use that thing and we will see that uh how can we use uh publicly available resources that is based on MIT license or GPL so it’s very important to understand how actually these small resources can make our life much easier.
As we know we are going to use in this lecture bash and Python which is one of the famous language. So I will go to the Internet and find the publicly available resources most of time.
I will go to exploit DB and search it what kind of resources I need and how can I modify that.
Before searching for a thing we need to make sure if our resources are are is available so is that a verified or unverified.
unverified vs verified :
different between verified if our resources is unverified or someone submit any kind of vulnerability that was tested by uh platform and other user so they mark it so anyone can understand what is going on there.
verified resources is very important because it’s saved much time that you need for other tasks complete.
unverified resources :
Alot of time unverified resources contain P1P2 vulnerabilities that can be informative and doesn’t have any value but a lot of time we can uh utilize unverified script or any kind of third party resources that can help us to modify and use it for yourself so let’s begin .
if the vulnerabilities or any issue You found not make any changes will be closed in informative.
informative vulnerabilities :
informative vulnerabilities can contain basic information lets tack one basic information

i this i find a area that was contain a Json File, we know its come from api line that can contain information but the response was not so good.
Json File:
Most of time important information can be leak In Jsons that also can help us to find SQL Injection Help.
we tried using Browser to open that link

lets start try to bypass this using bash script that i fount on githuB . i tryed to run bash script but it not worke.
with the one quote offline that we have first line we will test umm that will be present in any area
Let's try to do some forensic for the script and let's see how actually script working.
When I open the script in my Visual Studio code it tell me that it’s using request methods with different headers.
If you have a knowledge about headers what are the headers and how actually it work. we will see this thing in deeply otherwise I will cover this hydro section in next tutorial.
Headers are the place where it can contains the information of your browser sessions and sometime it contains your cookies information it can be stored in your browser and sometimes your website also take this information to process.
POST /api/login HTTP/1.1
Host: www.imran-niaz.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.131 Safari/537.36
Accept: application/json
Content-Type: application/json
Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
Content-Length: 56
{"username": "imran-niaz", "password": "d23141s3ds5d5sf46s5f"}this is a basic information t
lets see some advance level
The provided command is a curl command, which is a tool used for making HTTP requests from the command line. Let's break down the various components of the command:
curl -i -s -k -X $'POST' \
-H $'Host: twitter.com' -H $'Content-Length: 20' -H $'Sec-Ch-Ua: \"Not;A=Brand\";v=\"99\", \"Chromium\";v=\"106\"' -H $'X-Twitter-Client-Language: en' -H $'X-Csrf-Token: eeb78ddd8c3a1c91b3399be623473ddf' -H $'Sec-Ch-Ua-Mobile: ?0' -H $'Authorization: Bearer AAAAAAAAAAAAAAAAAAAAANRILgAAAAAAnNwIzUejRCOuH5E6I8xnZz4puTs%3D1Zv7ttfk8LF81IUq16cHjhLTvJu4FA33AGWWjCpTnA' -H $'User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.5249.62 Safari/537.36' -H $'Content-Type: application/json' -H $'X-Guest-Token: 1578837947993817089' -H $'X-Twitter-Active-User: yes' -H $'Sec-Ch-Ua-Platform: \"Linux\"' -H $'Accept: */*' -H $'Origin: https://twitter.com' -H $'Sec-Fetch-Site: same-origin' -H $'Sec-Fetch-Mode: cors' -H $'Sec-Fetch-Dest: empty' -H $'Referer: https://twitter.com/' -H $'Accept-Encoding: gzip, deflate' -H $'Accept-Language: en-US,en;q=0.9' \
-b $'guest_id_marketing=v1%3A166525927051892461; guest_id_ads=v1%3A166525927051892461; personalization_id=\"v1_5GPsl58kIMnOavrmZijzqw==\"; guest_id=v1%3A166525927051892461; ct0=eeb78ddd8c3a1c91b3399be623473ddf; gt=1578837947993817089' \
--data-binary $'{\"provider\":\"apple\"}' \
$'https://twitter.com/i/api/1.1/onboarding/sso_init.json'curl -i -s -k -X $'POST' \
-H $'Host: twitter.com' -H $'Content-Length: 20' -H $'Sec-Ch-Ua: \"Not;A=Brand\";v=\"99\", \"Chromium\";v=\"106\"' -H $'X-Twitter-Client-Language: en' -H $'X-Csrf-Token: eeb78ddd8c3a1c91b3399be623473ddf' -H $'Sec-Ch-Ua-Mobile: ?0' -H $'Authorization: Bearer AAAAAAAAAAAAAAAAAAAAANRILgAAAAAAnNwIzUejRCOuH5E6I8xnZz4puTs%3D1Zv7ttfk8LF81IUq16cHjhLTvJu4FA33AGWWjCpTnA' -H $'User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.5249.62 Safari/537.36' -H $'Content-Type: application/json' -H $'X-Guest-Token: 1578837947993817089' -H $'X-Twitter-Active-User: yes' -H $'Sec-Ch-Ua-Platform: \"Linux\"' -H $'Accept: */*' -H $'Origin: https://twitter.com' -H $'Sec-Fetch-Site: same-origin' -H $'Sec-Fetch-Mode: cors' -H $'Sec-Fetch-Dest: empty' -H $'Referer: https://twitter.com/' -H $'Accept-Encoding: gzip, deflate' -H $'Accept-Language: en-US,en;q=0.9' \
-b $'guest_id_marketing=v1%3A166525927051892461; guest_id_ads=v1%3A166525927051892461; personalization_id=\"v1_5GPsl58kIMnOavrmZijzqw==\"; guest_id=v1%3A166525927051892461; ct0=eeb78ddd8c3a1c91b3399be623473ddf; gt=1578837947993817089' \
--data-binary $'{\"provider\":\"apple\"}' \
$'https://twitter.com/i/api/1.1/onboarding/sso_init.json'-iincludes the response headers in the output.-ssilences the progress meter or error messages.-kallows connections to SSL sites without certificates.-Xspecifies the HTTP request method asPOST.-Hadds various headers to the request, such asHost,Content-Length,Authorization,User-Agent,Content-Type, and more.-bincludes the specified cookies in the request.--data-binaryincludes the specified data payload in the request.
Using Nmap for Finding Open targets
this incloud the information with basis information if you Life to watch you can fallow me on Facebook .
Scanning large Lavel Network for Pen testinig | Scanning large Lavel Network for Pen testinig | By…Scanning large Lavel Network for Pen testinig fb.watch
Finding Target Public server with errors .
Frequently asked questions
What is this guide about information?
Using Third Party resource for Cybersecurity & Pen Testing (W explains practical, ethical notes on information. Use it as a structured walkthrough — then practice only in authorized labs.
Who is this information article for?
Readers who want clear, street-level guidance on information without hype. Beginners and intermediate practitioners both benefit.
How do I practice information safely?
Stay in scope: systems you own or have written permission to test. Keep notes, verify findings, and never attack live targets without authorization.