# VeryLazyTech

## VeryLazyTech - Cybersecurity & Hacking Insights

- [VeryLazyTech Hacking Guide](https://www.verylazytech.com/welcome/verylazytech-aboutme.md): 🔒 Welcome to VeryLazyTech's Cybersecurity Corner! 🔒
- [Support VeryLazyTech](https://www.verylazytech.com/welcome/support-verylazytech.md)
- [CVE - POC](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc.md)
- [Unauthenticated RCE Flaw in Rejetto HTTP File Server - CVE-2024-23692](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc/cve-2024-23692.md)
- [POC - CVE-2024–4956 - Nexus Repository Manager 3 Unauthenticated Path Traversal](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc/poc-cve-2024-4956-nexus-repository-manager-3-unauthenticated-path-traversal.md)
- [POC - CVE-2024-45241: Path Traversal in CentralSquare's CryWolf](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc/poc-cve-2024-45241-path-traversal-in-centralsquares-crywolf.md)
- [Telerik Auth Bypass CVE-2024-4358](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc/telerik-auth-bypass-cve-2024-4358.md)
- [Check Point Security Gateways Information Disclosure - CVE-2024-24919](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc/check-point-security-gateways-information-disclosure-cve-2024-24919.md)
- [CVE-2024-23897 - Jenkins File Read Vulnerability](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc/cve-2024-23897-jenkins-file-read-vulnerability.md)
- [CVE-2024–10914- Command Injection Vulnerability in name parameter for D-Link NAS](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc/cve-2024-10914-command-injection-vulnerability-in-name-parameter-for-d-link-nas.md): POC - CVE-2024–10914 - Command Injection Vulnerability in name parameter for D-Link NAS
- [POC - CVE-2024-21534 Jsonpath-plus vulnerable to Remote Code Execution (RCE)](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc/poc-cve-2024-21534-jsonpath-plus-vulnerable-to-remote-code-execution-rce.md): POC - CVE-2024-21534 Jsonpath-plus vulnerable to Remote Code Execution (RCE) due to improper input sanitization
- [CVE-2024-9935 - PDF Generator Addon for Elementor Page Builder <= 1.7.5 - Unauthenticated Arbitrary](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc/cve-2024-9935-pdf-generator-addon-for-elementor-page-builder-less-than-1.7.5-unauthenticated-arbitra.md): POC - CVE-2024-9935 - PDF Generator Addon for Elementor Page Builder <= 1.7.5 - Unauthenticated Arbitrary
- [CVE-2024-50623- Cleo Unrestricted file upload and download](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc/cve-2024-50623-cleo-unrestricted-file-upload-and-download.md)
- [POC - WordPress File Upload plugin, in the wfu\_file\_downloader.php file before version <= 4.24.11](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc/poc-wordpress-file-upload-plugin-in-the-wfu_file_downloader.php-file-before-version-less-than-4.24.1.md): WordPress File Upload plugin, in the wfu\_file\_downloader.php file before version <= 4.24.11
- [POC - Remote and unauthenticated attacker can send crafted HTTP requests to RCE - cve-2025-3248](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc/poc-remote-and-unauthenticated-attacker-can-send-crafted-http-requests-to-rce-cve-2025-3248.md)
- [POC - CVE-2025–2539 File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc/poc-cve-2025-2539-file-away-less-than-3.9.9.0.1-missing-authorization-to-unauthenticated-arbitrary-f.md)
- [POC - CVE-2025-29306 FOXCMS /images/index.html Code Execution Vulnerability](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc/poc-cve-2025-29306-foxcms-images-index.html-code-execution-vulnerability.md)
- [CVE-2025–64446 — A Red Team Offensive Playbook for FortiWeb RCE via Path Traversal + Authentication](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc/cve-2025-64446-a-red-team-offensive-playbook-for-fortiweb-rce-via-path-traversal-+-authentication.md)
- [GitHub Dorks](https://www.verylazytech.com/dorks/github-dorks.md)
- [Top Hacking Books for 2024: FREE and Paid](https://www.verylazytech.com/resources/editor.md): Boost your cybersecurity skills with VeryLazyTech’s self-study resources—learn the lazy way!
- [How to Study for OSCP with the PWK Book PDF](https://www.verylazytech.com/resources/markdown.md)
- [Top 20 phishing tools to use in 2024](https://www.verylazytech.com/resources/top-20-phishing-tools-to-use-in-2024.md)
- [Top 8 Bug Bounty Books for 2025: Must-Reads for Ethical Hackers](https://www.verylazytech.com/resources/top-8-bug-bounty-books-for-2025-must-reads-for-ethical-hackers.md)
- [Top Hacking Tools and Skills You Need to Learn in 2025](https://www.verylazytech.com/resources/top-hacking-tools-and-skills-you-need-to-learn-in-2025.md)
- [Penetration Testing & Hacking Tools List](https://www.verylazytech.com/resources/penetration-testing-and-hacking-tools-list.md)
- [Top Cybersecurity Books by Topic](https://www.verylazytech.com/resources/top-cybersecurity-books-by-topic.md): Looking for the best cybersecurity books? This list covers ethical hacking, OSINT, red teaming, malware analysis, and more—organized by topic for easy access.
- [The Ultimate Penetration Testing Methodology (2025 Edition)](https://www.verylazytech.com/resources/the-ultimate-penetration-testing-methodology-2025-edition.md)
- [Client Side Template Injection (CSTI)](https://www.verylazytech.com/pentesting-web/client-side-template-injection-csti.md)
- [Identify a Server’s Origin IP](https://www.verylazytech.com/pentesting-web/identify-a-servers-origin-ip.md)
- [2FA/MFA/OTP Bypass](https://www.verylazytech.com/pentesting-web/2fa-mfa-otp-bypass.md)
- [IDOR](https://www.verylazytech.com/pentesting-web/idor.md): Learn to uncover more IDORs the lazy way with VeryLazyTech—tips, tricks, and hacks revealed!
- [Open Redirect](https://www.verylazytech.com/pentesting-web/open-redirect.md): Open Redirect (also known as Unvalidated Redirects and Forwards) occurs when a web application accepts user-supplied input and redirects the user to an arbitrary URL without proper validation.
- [Subdomain Takeover](https://www.verylazytech.com/pentesting-web/subdomain-takeover.md)
- [CMS Wp/Durpal/Joomla/etc..](https://www.verylazytech.com/pentesting-web/cms-wp-durpal-joomla-etc...md)
- [Penetration Testing WiFi Networks](https://www.verylazytech.com/pentesting-web/penetration-testing-wifi-networks.md)
- [Client-Side Path Traversal](https://www.verylazytech.com/pentesting-web/client-side-path-traversal.md)
- [Clickjacking](https://www.verylazytech.com/pentesting-web/clickjacking.md): Explore clickjacking attacks with VeryLazyTech—techniques, exploits, and lazy prevention tips!
- [Command Injection](https://www.verylazytech.com/pentesting-web/command-injection.md)
- [JWT Vulnerabilities](https://www.verylazytech.com/pentesting-web/jwt-vulnerabilities.md)
- [Bypass rating limit](https://www.verylazytech.com/pentesting-web/bypass-rating-limit.md): Bypass rate limits like a pro with VeryLazyTech—advanced exploits and lazy techniques unveiled!
- [CORS - Misconfigurations & Bypass](https://www.verylazytech.com/pentesting-web/cors-misconfigurations-and-bypass.md)
- [LDAP Injection](https://www.verylazytech.com/pentesting-web/ldap-injection.md)
- [File upload vulnerabilities](https://www.verylazytech.com/pentesting-web/file-upload-vulnerabilities.md)
- [Content Security Policy (CSP) bypass](https://www.verylazytech.com/pentesting-web/content-security-policy-csp-bypass.md)
- [Brute Force - Services, web, local, tools & wordlists](https://www.verylazytech.com/pentesting-web/brute-force-services-web-local-tools-and-wordlists.md): A comprehensive brute force guide covering web logins, APIs, and local services like IMAP, MySQL, and LDAP using tools like Hydra, Medusa, Legba, and more.
- [Shellshock](https://www.verylazytech.com/pentesting-web/shellshock.md)
- [Copy of Copy of Tampatle Duplicate](https://www.verylazytech.com/pentesting-web/copy-of-copy-of-tampatle-duplicate.md)
- [XSS](https://www.verylazytech.com/pentesting-web/xss.md)
- [Practical Linux Commands](https://www.verylazytech.com/linux/practical-linux-commands.md)
- [Bypassing Bash Restrictions - Rbash](https://www.verylazytech.com/linux/bypassing-bash-restrictions-rbash.md)
- [Privilege escalation - Linux](https://www.verylazytech.com/linux/privilege-escalation-linux.md)
- [Linux Environment Variables](https://www.verylazytech.com/linux-environment-variables.md)
- [Active Directory Methodology](https://www.verylazytech.com/windows/images-and-media.md)
- [Antivirus (AV) Bypass](https://www.verylazytech.com/windows/antivirus-av-bypass.md): In this guide, we provide a deep dive into Windows Antivirus (AV) and Endpoint Detection and Response (EDR) bypass techniques, empowering red teamers and advanced penetration testers with up-to-date,
- [Practical Windows Commands](https://www.verylazytech.com/windows/practical-windows-commands.md)
- [100+ Windows CMD Commands](https://www.verylazytech.com/windows/100+-windows-cmd-commands.md)
- [FTP - Port 21](https://www.verylazytech.com/network-pentesting/ftp-port-21.md)
- [SSH- Port 22](https://www.verylazytech.com/network-pentesting/ssh-port-22.md)
- [Telnet - Port 23](https://www.verylazytech.com/network-pentesting/telnet-port-23.md)
- [SMTP/s - Port 25,465,587](https://www.verylazytech.com/network-pentesting/smtp-s-port-25-465-587.md)
- [WHOIS - Port 43](https://www.verylazytech.com/network-pentesting/whois-port-43.md)
- [TACACS+ - Port 49](https://www.verylazytech.com/network-pentesting/tacacs+-port-49.md)
- [DNS - Port 53](https://www.verylazytech.com/network-pentesting/dns-port-53.md)
- [TFTP/Bittorrent-tracker - Port 69/UDP](https://www.verylazytech.com/network-pentesting/tftp-bittorrent-tracker-port-69-udp.md)
- [Finger - Port 79](https://www.verylazytech.com/network-pentesting/finger-port-79.md)
- [Web - Port 80,443](https://www.verylazytech.com/network-pentesting/web-port-80-443.md): Ports 80 and 443 are the primary ports for web traffic, with port 80 handling unencrypted HTTP traffic and port 443 managing encrypted HTTPS traffic.
- [Kerberos - Port 88](https://www.verylazytech.com/network-pentesting/kerberos-port-88.md): Master pentesting Kerberos on port 88 with VeryLazyTech’s lazy methodology—exploits included!
- [POP - Port 110/995](https://www.verylazytech.com/network-pentesting/pop-port-110-995.md)
- [Portmapper - Port 111/TCP/UDP](https://www.verylazytech.com/network-pentesting/portmapper-port-111-tcp-udp.md)
- [Ident - Port 113](https://www.verylazytech.com/network-pentesting/ident-port-113.md)
- [NTP - Port 123/UDP](https://www.verylazytech.com/network-pentesting/ntp-port-123-udp.md)
- [MSRPC - Port 135, 539](https://www.verylazytech.com/network-pentesting/msrpc-port-135-539.md)
- [NetBios - Port 137,138,139](https://www.verylazytech.com/network-pentesting/netbios-port-137-138-139.md)
- [SMB - Port 139 445](https://www.verylazytech.com/network-pentesting/smb-port-139-445.md)
- [IMAP - Port 143, 993](https://www.verylazytech.com/network-pentesting/imap-port-143-993.md)
- [SNMP - Ports  161, 162, 10161, and 10162/UDP](https://www.verylazytech.com/network-pentesting/snmp-ports-161-162-10161-and-10162-udp.md)
- [IRC - Ports 194,6667,6660-7000](https://www.verylazytech.com/network-pentesting/irc-ports-194-6667-6660-7000.md): IRC, initially a plain text protocol, was assigned 194/TCP by IANA but is commonly run on 6667/TCP and similar ports to avoid needing root privileges for operation.
- [Check Point Firewall - Port 264](https://www.verylazytech.com/network-pentesting/check-point-firewall-port-264.md)
- [LDAP - Ports 389, 636, 3268, 3269](https://www.verylazytech.com/network-pentesting/ldap-ports-389-636-3268-3269.md)
- [IPsec/IKE VPN - Port 500/UDP](https://www.verylazytech.com/network-pentesting/ipsec-ike-vpn-port-500-udp.md)
- [Modbus - Port 502](https://www.verylazytech.com/network-pentesting/modbus-port-502.md): Modbus is a communication protocol used in industrial automation to allow devices like programmable logic controllers (PLCs) to talk to each other.
- [Rexec - Port 512](https://www.verylazytech.com/network-pentesting/rexec-port-512.md): It is a service that allows you to execute a command inside a host if you know valid credentials (username and password).
- [Rlogin - Port 513](https://www.verylazytech.com/network-pentesting/rlogin-port-513.md)
- [Rsh - Port 514](https://www.verylazytech.com/network-pentesting/rsh-port-514.md)
- [Line Printer Daemon (LPD) - Port 515](https://www.verylazytech.com/network-pentesting/line-printer-daemon-lpd-port-515.md)
- [Apple Filing Protocol (AFP) - PORT 548](https://www.verylazytech.com/network-pentesting/apple-filing-protocol-afp-port-548.md)
- [RTSP - Port 554, 8554](https://www.verylazytech.com/network-pentesting/rtsp-port-554-8554.md)
- [IPMI - Port 623/UDP/TCP](https://www.verylazytech.com/network-pentesting/ipmi-port-623-udp-tcp.md)
- [Internet Printing Protocol (IPP) - Port 631](https://www.verylazytech.com/network-pentesting/internet-printing-protocol-ipp-port-631.md)
- [EPP - Port 700](https://www.verylazytech.com/network-pentesting/epp-port-700.md)
- [Rsync - Port 873](https://www.verylazytech.com/network-pentesting/rsync-port-873.md)
- [Rusersd Service - Port 1026](https://www.verylazytech.com/network-pentesting/rusersd-service-port-1026.md)
- [Socks - Port 1080](https://www.verylazytech.com/network-pentesting/socks-port-1080.md)
- [Java RMI - RMI-IIOP - Port 1098/1099/1050](https://www.verylazytech.com/network-pentesting/java-rmi-rmi-iiop-port-1098-1099-1050.md)
- [MSSQL  (Microsoft SQL Server) - Port 1433](https://www.verylazytech.com/network-pentesting/mssql-microsoft-sql-server-port-1433.md): Master pentesting MSSQL on port 1433 with VeryLazyTech’s guide—exploits, tips, and more!
- [Oracle TNS Listener - Port 1521,1522-1529](https://www.verylazytech.com/network-pentesting/oracle-tns-listener-port-1521-1522-1529.md)
- [PPTP - Port 1723](https://www.verylazytech.com/pptp-port-1723.md)
- [MQTT (Message Queuing Telemetry Transport) - Port 1883](https://www.verylazytech.com/mqtt-message-queuing-telemetry-transport-port-1883.md)
- [Compaq HP Insight Manager - Port 2301, 2381](https://www.verylazytech.com/compaq-hp-insight-manager-port-2301-2381.md)
- [NFS Service - Port 2049](https://www.verylazytech.com/nfs-service-port-2049.md)
- [Docker - Port 2375,2376](https://www.verylazytech.com/docker-port-2375-2376.md)
- [Squid - Port 3128](https://www.verylazytech.com/squid-port-3128.md)
- [iScsi - Port 3260](https://www.verylazytech.com/iscsi-port-3260.md)
- [SAPRouter - Port 3299](https://www.verylazytech.com/saprouter-port-3299.md)
- [MySql - Port 3306](https://www.verylazytech.com/mysql-port-3306.md)
- [RDP - PORT 3389](https://www.verylazytech.com/rdp-port-3389.md)
- [Distcc - Port 3632](https://www.verylazytech.com/distcc-port-3632.md)
- [Subversion (SVN) Server -Port 3690](https://www.verylazytech.com/subversion-svn-server-port-3690.md)
- [WS-Discovery - Port 3702/UDP](https://www.verylazytech.com/ws-discovery-port-3702-udp.md)
- [Erlang Port Mapper Daemon - PORT 4369](https://www.verylazytech.com/erlang-port-mapper-daemon-port-4369.md)
- [Cisco Smart Install - PORT 4786](https://www.verylazytech.com/cisco-smart-install-port-4786.md)
- [OPC UA - PORT 4840](https://www.verylazytech.com/opc-ua-port-4840.md)
- [Docker Registry - PORT 5000](https://www.verylazytech.com/docker-registry-port-5000.md)
- [Multicast DNS (mDNS) and DNS-SD - PORT 5353/UDP](https://www.verylazytech.com/multicast-dns-mdns-and-dns-sd-port-5353-udp.md)
- [Postgresql - PORT 5432,5433](https://www.verylazytech.com/postgresql-port-5432-5433.md)
- [Android Debug Bridge (ADB) - PORT 5555](https://www.verylazytech.com/android-debug-bridge-adb-port-5555.md)
- [Kibana - Port 5601](https://www.verylazytech.com/kibana-port-5601.md)
- [AMQP (RabbitMQ) - Port 5671/5672](https://www.verylazytech.com/amqp-rabbitmq-port-5671-5672.md)
- [VNC - Port 5800/5801/5900/5901](https://www.verylazytech.com/vnc-port-5800-5801-5900-5901.md)
- [CouchDB - Port 5984,6984](https://www.verylazytech.com/couchdb-port-5984-6984.md)
- [WinRM - Port 5985, 5986](https://www.verylazytech.com/winrm-port-5985-5986.md)
- [X11 - Port 6000](https://www.verylazytech.com/x11-port-6000.md)
- [Redis - Port 6379](https://www.verylazytech.com/redis-port-6379.md)
- [Apache Jserv Protocol (AJP) - Port 8009](https://www.verylazytech.com/apache-jserv-protocol-ajp-port-8009.md)
- [InfluxDB - Port 8086](https://www.verylazytech.com/influxdb-port-8086.md)
- [Splunkd - Port 8089](https://www.verylazytech.com/splunkd-port-8089.md)
- [Bitcoin - Port 8333, 18333, 38333, 18444](https://www.verylazytech.com/bitcoin-port-8333-18333-38333-18444.md)
- [FastCGI - Port 9000](https://www.verylazytech.com/fastcgi-port-9000.md)
- [HSQLDB - Port 9001](https://www.verylazytech.com/hsqldb-port-9001.md)
- [Cassandra - Port 9042, 9160](https://www.verylazytech.com/cassandra-port-9042-9160.md)
- [PJL (Printer Job Language) - Port 9100](https://www.verylazytech.com/pjl-printer-job-language-port-9100.md)
- [Elasticsearch - Port 9200](https://www.verylazytech.com/elasticsearch-port-9200.md)
- [Network Data Management Protocol (NDMP) - PORT 10000](https://www.verylazytech.com/network-data-management-protocol-ndmp-port-10000.md)
- [Memcache - Port 11211](https://www.verylazytech.com/memcache-port-11211.md)
- [RabbitMQ Management - Port 15672](https://www.verylazytech.com/rabbitmq-management-port-15672.md)
- [GlusterFS - Port 24007, 24008, 24009, 49152](https://www.verylazytech.com/glusterfs-port-24007-24008-24009-49152.md)
- [MongoDB - Port 27017, 27018](https://www.verylazytech.com/mongodb-port-27017-27018.md)
- [PPPP (CS2) P2P Cameras - Port 32100 UDP](https://www.verylazytech.com/pppp-cs2-p2p-cameras-port-32100-udp.md)
- [Tiller / Helm - Port 44134](https://www.verylazytech.com/tiller-helm-port-44134.md)
- [EtherNet/IP - Port 44818](https://www.verylazytech.com/ethernet-ip-port-44818.md)
- [Tamplate](https://www.verylazytech.com/tamplate.md)
- [File Transfer Cheatsheet: Windows and Linux](https://www.verylazytech.com/post-exploitation/file-transfer-cheatsheet-windows-and-linux.md): File transfer is a critical component in post-exploitation, penetration testing, and red teaming.
- [Kali Linux - Installation](https://www.verylazytech.com/technical-guides/kali-linux-installation.md)
- [Search Exploits](https://www.verylazytech.com/technical-guides/search-exploits.md): Stop Wasting Time! The Secret Method to Find Exploits in Minutes
- [Pivoting & Tunneling](https://www.verylazytech.com/technical-guides/pivoting-and-tunneling.md)
- [Prompt injection](https://www.verylazytech.com/hacking-ai/prompt-injection.md)
- [Data poisoning](https://www.verylazytech.com/hacking-ai/data-poisoning.md): Injecting malicious or misleading data into the training dataset to bias results.
- [Backdoor attacks](https://www.verylazytech.com/hacking-ai/backdoor-attacks.md): Placing hidden triggers in the model so it behaves differently when specific input patterns appear.
- [Prompt Injection & Jailbreaking](https://www.verylazytech.com/hacking-ai/prompt-injection-and-jailbreaking.md)
