Skip to content
View ajacobhack's full-sized avatar

Block or report ajacobhack

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
ajacobhack/README.md

ariel-jacob-banner-linkedin-hacker1

πŸ‘‰ About me!

I am pentester and cybersecurity consultant passionate about hacking and offensive security. I am certified in CEHv12 (Certified Ethical Hacker) EC-Council. I am proactive in learning and I am always trying new techniques and expanding my knowledge.

πŸš€ Projects

πŸ“Œ Tools - Scripts:

  • rogue-https-server.py: https server with python 3.10/3.11 for incoming TLS encrypted communications and checks of Out-of-bands attacks. Amoong features: free DNS and auto generating pem. Checks vulnerabilities like: External Service Interaction (DNS, HTTP), blind SSRF, REC PHP, XSS Stored with cookies exfiltration, Out-of-band SQL injection (OOB SQLi), Server Security Miscofiguration, among others.
  • awsbugseeker: script for testing on AWS cloud apps.
  • lootXploits: bash script for find exploits for exposed services.

πŸ“Œ Medium posts - My actual blog for hacking posts.

https://medium.com/@arielhacking

πŸ“Œ My website to share some articles on hacking techniques, guidance to get started in the field and interesting things on CyberSec. (replaced for Medium Blog)

https://hackingpulse.tech

πŸ“Œ Another of my projects is a Useful Hacks repository where I share useful commands for hacking and pentesting that serve as a quick cheatSheet.

πŸ‘Ί Experience

βš”οΈ I hack your stuff so you have better security I am passionate about Hacking and Offensive Security, proactive in learning and working, I constantly update myself and I have the initiative to find new perspectives and solutions. Among my skills are:

πŸ›‘ Pentesting of external and internal infrastructure.

πŸ›‘ Web Application Pentesting

πŸ›‘ Pentesting APIs

πŸ›‘ Pentesting Mobile Apps

πŸ›‘ OSINT

πŸ›‘ Oral and written English. Preparation of reports in English.

πŸ›‘ Threat Modeling

πŸ›‘ S-SDLC: Threat Modeling, secure code cheatsheets, Vulnerability management and supporting developers in remediating vulnerabilities, end-to-end project management.

πŸ›‘ Education: cybersecurity for devs

🏹 Tools & technologies:

πŸ›‘ Vulnerability scanning with professional tools (DAST): Nessus (Pro and Tenable Cloud for PCI DSS ASV Compliance), Acunetix, Burp Suite Pro, etc. Experience with debugging false positives and handling scanner paranoia levels.

πŸ›‘ Experience with Linux and Windows environments. Using Kali and Parrot for pentesting.

πŸ›‘ Experience with intrusion pentesting tools: NMAP, SQLMap, Metasploit framework, Burp Suite (Proxy, repeater, intruder; cookie tests); detection of privilege escalation vectors with automated tools and manually;

πŸ›‘ API hacking with Postman, Burp, Kiterunner;

πŸ›‘ Mobile Apps: Genymotion/AndroidStudio; static and dynamic tests with MobSF, ADB, APKTool, Frida, Drozer.

πŸ›‘ DoS with httpslowtest and hping3;

πŸ›‘ Footprinting with search engines (google dorks, Bing, etc), automated tools (theHarvester, Dig, WHOIS, AMASS), devices, technologies and geolocation (Netcraft, Shodan, Builtwith), social networks, email and metadata collection .

πŸ›‘ Knowledge of exploits, vulnerability ratings by CVE and CWE, and risk level by CVSS.

πŸ›‘ Frameworks/methodologies: OSSTMM, OWASP, MITER ATT&CK, EC-Council, Cyber ​​Kill Chain.

πŸ›‘ Knowledge of networks and communications: TCP/IP, UDP, ARP, DNS and DHCP. OSI model. Cryptography: secure and insecure encryption types; SSL and TLS protocols.

πŸ›‘ Knowledge of programming languages: Bash, Python, Javascript, PHP.

πŸ‘½ Social Skills:

Clear oral and written communication.

Adaptability, proactive learning.

Integrity: sincerity, morality, personal values, honesty.

Pinned Loading

  1. usefulhacks usefulhacks Public

    Useful hacks & tricks repo

    1

  2. lootXploits lootXploits Public

    Bash script for search and looting exploits for a open and detected services.

    Shell

  3. awsbugseeker awsbugseeker Public

    Python scripting to automate the search for vulnerabilities in AWS applications.

    Python 1

  4. rogue-https-server rogue-https-server Public

    Rogue HTTPS Server is a tool that allows you to create a Python 3.10/3.11 HTTPS/SSL server to receive encrypted connections, serve content, and run PHP scripts.

    Python 2