Uploaded May 2020 | Updated September 2026, 2 weeks ago
How to Discover Hidden HTTP Parameters with Arjun
Full Tutorial: https://nulb.app/z4x2u
Subscribe to Null Byte: goo.gl/J6wEnH
Nick's Twitter: twitter.com/nickgodshall
Cyber Weapons Lab, Episode 155
When auditing a website, it can be difficult to find all of the HTTP parameters the page takes. In today's Cyber Weapons Lab video, we'll go over an automated tool for discovering those hidden parameters. That tool is called Arjun. Big shoutout to Null Byte user drd_ whose article inspired this episode!
To learn more, check out the article: https://nulb.app/z4x2u
Follow Null Byte on:
Twitter: twitter.com/nullbyte
Flipboard: https://flip.it/3.Gf_0
Website: null-byte.com
Weekly newsletter: eepurl.com/dE3Ovb
Vimeo: vimeo.com/channels/nullbyte
How to Discover Hidden HTTP Parameters with Arjun
Full Tutorial: https://nulb.app/z4x2u
Subscribe to Null Byte: goo.gl/J6wEnH
Nick's Twitter: twitter.com/nickgodshall
Cyber Weapons Lab, Episode 155
When auditing a website, it can be difficult to find all of the HTTP parameters the page takes. In today's Cyber Weapons Lab video, we'll go over an automated tool for discovering those hidden parameters. That tool is called Arjun. Big shoutout to Null Byte user drd_ whose article inspired this episode!
To learn more, check out the article: https://nulb.app/z4x2u
Follow Null Byte on:
Twitter: twitter.com/nullbyte
Flipboard: https://flip.it/3.Gf_0
Website: null-byte.com
Weekly newsletter: eepurl.com/dE3Ovb
Vimeo: vimeo.com/channels/nullbyte

![Exploit WebDAV on a Server & Get a Reverse Shell [Tutorial]
Get Our Premium Ethical Hacking Bundle (90% Off): https://nulb.app/cwlshop
How to Get a Shell with Web Distributed Authoring & Versioning
Full Tutorial: https://nulb.app/x4r43
Subscribe to Null Byte: https://goo.gl/J6wEnH
Nicks Twitter: https://twitter.com/nickgodshall
Cyber Weapons Lab, Episode 186
WebDAV lets users collaborate on web projects remotely, and it can also be used to transfer files. But it also is a huge security risk if it has been configured improperly. Pentesters, hackers, cybersecurity specialists, and others can exploit it, eventually getting a shell on the server. In this episode of Cyber Weapons Lab, well show you how it could be done using Metasploit to scan for WebDAV, DAVTest to test file execution policies, and Cadaver to upload a reverse shell and compromise the server.
To learn more, check out the article by drd_ on Null Byte: https://nulb.app/x4r43
Follow Null Byte on:
Twitter: https://twitter.com/nullbyte
Flipboard: https://flip.it/3.Gf_0
Website: https://null-byte.com
Weekly newsletter: https://eepurl.com/dE3Ovb
Vimeo: https://vimeo.com/channels/nullbyte Exploit WebDAV on a Server & Get a Reverse Shell [Tutorial]](https://i.ytimg.com/vi/U93B9QvuZP8/mqdefault.jpg)
![Use & Exit Vim (The Text Editor Every Hacker Should Be Familiar With) [Tutorial]
How To Use Viim on Your Kali System
Full Tutorial: http://bit.ly/VIMbasics
Subscribe to Null Byte: https://goo.gl/J6wEnH
Kodys Twitter: https://twitter.com/KodyKinzie
Text Editors in a terminal or command line setting can be a little confusing at first. A common text editor is Vim and its an editor every hacker should be familiar with. Today, well show you not only how to use it, but also how to exit Vim on this episode of Cyber Weapons Lab.
For a written reference, please check out Barrows article on Null Byte, which was the inspiration for this video guide: http://bit.ly/VIMbasics
Follow Null Byte on:
Twitter: https://twitter.com/nullbytewht
Flipboard: https://flip.it/3.Gf_0
Weekly newsletter: https://eepurl.com/dE3Ovb Use & Exit Vim (The Text Editor Every Hacker Should Be Familiar With) [Tutorial]](https://i.ytimg.com/vi/UIwcTU10F5k/mqdefault.jpg)
![Hackers Guide to Buying an ESP32 Camera Module [Tutorial]
Our Premium Ethical Hacking Bundle Is 90% Off: https://nulb.app/cwlshop
Comparing 3 Different ESP32 Cameras
Full Tutorial: https://nulb.app/x5mv2
Subscribe to Null Byte: https://goo.gl/J6wEnH
Kodys Twitter: https://twitter.com/KodyKinzie
Cyber Weapons Lab, Episode 206
The ESP32 is a cheap, powerful microcontroller capable of acting as a Wi-Fi camera module when paired with a camera. Because of this, there are many ESP32-based camera modules available online at low prices, but each comes with their own advantages and disadvantages. In this episode of Cyber Weapons Lab, we go over the most common models and the trade-offs between each one.
ESP32-CAM: https://amzn.to/2KiisVK
USB-C ESP32 Camera: https://amzn.to/3oOI9wf
ESP-EYE: https://amzn.to/3nQ6gcq
Using the ESP32-CAM: https://youtu.be/tx09GFGgVwA
To learn more, check out the article on Null Byte: https://nulb.app/x5mv2
Follow Null Byte on:
Twitter: https://twitter.com/nullbyte
Flipboard: https://flip.it/3.Gf_0
Website: https://null-byte.com
Weekly newsletter: https://eepurl.com/dE3Ovb
Vimeo: https://vimeo.com/channels/nullbyte Hackers Guide to Buying an ESP32 Camera Module [Tutorial]](https://i.ytimg.com/vi/UqzdbOcoF7Q/mqdefault.jpg)

![Use Netcat to Spawn Reverse Shells & Connect to Other Computers [Tutorial]
Get Our Premium Ethical Hacking Bundle (90% Off): https://nulb.app/cwlshop
How to Create Reverse Shells with Netcat
Full Tutorial: https://nulb.app/z3gcc
Subscribe to Null Byte: https://goo.gl/J6wEnH
Kodys Twitter: https://twitter.com/KodyKinzie
Cyber Weapons Lab, Episode 050
Netcat and Ncat are two useful tools for copying data across a network. To a hacker, the only limit to these tools utility is your imagination, and well demonstrate the ability to do everything from copying data across a local network to remotely controlling a computer with a reverse shell. Well show you how it works in this episode of Cyber Weapons Lab.
To learn more, check out the article: https://nulb.app/z3gcc
Follow Null Byte on:
Twitter: https://twitter.com/nullbyte
Flipboard: https://flip.it/3.Gf_0
Website: https://null-byte.com
Weekly newsletter: https://eepurl.com/dE3Ovb
Vimeo: https://vimeo.com/channels/nullbyte Use Netcat to Spawn Reverse Shells & Connect to Other Computers [Tutorial]](https://i.ytimg.com/vi/VF4In6rIPGc/mqdefault.jpg)
![Automate Remote SSH Control of Computers with Expect Scripts [Tutorial]
Our Premium Ethical Hacking Bundle Is 90% Off: https://nulb.app/cwlshop
How to Combine Expect & Bash Scripts
Full Tutorial: https://nulb.app/x6vub
Subscribe to Null Byte: https://goo.gl/J6wEnH
Kodys Twitter: https://twitter.com/KodyKinzie
Cyber Weapons Lab, Episode 210
Bash scripts are the normal way to get into automation. However, they have their limitations. In this episode of Cyber Weapons Lab, well look at those limitations and learn about an alternative called expect scripts. Which, can be useful when we need to respond to variables, such as when you log in via SSH.
To learn more, check out the article on Null Bytes site: https://nulb.app/x6vub
Automate tasks with Bash scripts: https://youtu.be/PPQ8m8xQAs8
Automate recon with Bash scripts: https://youtu.be/keK99avGLvQ
Follow Null Byte on:
Twitter: https://twitter.com/nullbyte
Flipboard: https://flip.it/3.Gf_0
Website: https://null-byte.com
Vimeo: https://vimeo.com/channels/nullbyte Automate Remote SSH Control of Computers with Expect Scripts [Tutorial]](https://i.ytimg.com/vi/Vt5S12U3F0k/mqdefault.jpg)
![Find Information from a Phone Number Using OSINT Tools [Tutorial]
Earn $$. Learn What You Need to Get Certified (90% Off): https://nulb.app/cwlshop
How to Run an OSINT Investigation on a Phone Number
Full Tutorial: http://bit.ly/PhoneOSINT
Subscribe to Null Byte: https://goo.gl/J6wEnH
Kodys Twitter: https://twitter.com/KodyKinzie
IMPORTANT (JUNE 6, 2019): The OSINT Tools by Mike Bazzel featured in this guide were taken down from his website due to increased DDoS-style attacks, as well as DMCAs and cease-and-desists from some of the tools included. Phoneinfoga will still work in this guide, but for the others, you can try using each companys individual tool instead. You can see how it used to work, however, in this video and on null-byte.com.
When running an OSINT investigation, a phone number can prove to be extremely useful in gathering information about a target. On this episode of Cyber Weapons Lab, well explore a couple tools you can use to extract information from a phone number. First, theres the command-line tool called Phoneinfoga, then theres the web app tool on the IntelTechniques website.
Follow Null Byte on:
Twitter: https://twitter.com/nullbytewht
Flipboard: https://flip.it/3.Gf_0
Weekly newsletter: https://eepurl.com/dE3Ovb Find Information from a Phone Number Using OSINT Tools [Tutorial]](https://i.ytimg.com/vi/WW6myutKBYk/mqdefault.jpg)
![Create Your Own Nmap Scripts Using Lua [Tutorial]
How to Code in Lua to Create Nmap Scripts
Full Tutorial: http://bit.ly/NmapLua
Subscribe to Null Byte: https://goo.gl/J6wEnH
Kodys Twitter: https://twitter.com/KodyKinzie
Nmap is a powerful tool for network scanning and analysis. On this episode of Cyber Weapons Lab, well teach you how to use Lua to code out your own Nmap script to run, that way youre not always relying on other hackers and pentesters scripts to get a job done.
Follow Null Byte on:
Twitter: https://twitter.com/nullbytewht
Flipboard: https://flip.it/3.Gf_0
Weekly newsletter: https://eepurl.com/dE3Ovb Create Your Own Nmap Scripts Using Lua [Tutorial]](https://i.ytimg.com/vi/Wb91wpCUx8Q/mqdefault.jpg)
![Lock Down Your DNS with a Pi-Hole for Safer Web Browsing at Home [Tutorial]
Our Premium Ethical Hacking Bundle Is 90% Off: https://nulb.app/cwlshop
How to Keep Grandma Safe from Phishing at Home
Full Tutorial: https://nulb.app/z4evg
Subscribe to Null Byte: https://goo.gl/J6wEnH
Michaels Twitter: https://twitter.com/The_Hoid
Cyber Weapons Lab, Episode 165
The Pi-hole is a very commonly used Raspberry Pi project aimed at blocking ads on your home network, but it also has the convenient ability to blacklist domain names. While blacklists are not perfect, they can add an extra layer of security to your home, and they are particularity good at helping protect the less tech-savvy. On this episode of Cyber Weapons Lab, well show you how its done and what it means to use one.
To learn more, check out the article: https://nulb.app/z4evg
Raspberry Pi options with Ethernet/Wi-Fi:
- Pi 4: https://amzn.to/2BN0E0i
- Pi 4 B: https://amzn.to/3hhRCss
- Pi 3 B: https://amzn.to/2XQ6QgD
- Pi 3 B+: https://amzn.to/2UwsEMt
Raspberry Pi options with just Wi-Fi:
- Pi 3 A+: https://amzn.to/2MO5RaI
- Pi Zero WH: https://amzn.to/30uFWgc
- Pi Zero W: https://amzn.to/2TzFtE6
Other things needed:
- Ethernet adapter (if using Wi-Fi only models): https://amzn.to/3cQ2MkV
- Ethernet cable (if using Ethernet): https://amzn.to/2AS7WQ1
- 16 GB MicroSD card: https://amzn.to/3f91rar
- Or 32 GB one: https://amzn.to/2YBFlqz
- SD card reader: https://amzn.to/30uojwX
- Power adapter: https://amzn.to/30dS3hp
Optional for a small display:
- Adafruit PiOLED display: https://amzn.to/2MSDhoh
- Pi Zero W/WH case: https://amzn.to/30tPFDm
Optional for a big display:
- Adafruit PiTFT Plus: https://amzn.to/2XQjIU3
- 20x20 pin header (if needed): https://amzn.to/2AS8FAJ
- Pi case: https://amzn.to/3fgzJbB
- Faceplate w/buttons: https://amzn.to/2MOaUrG
Follow Null Byte on:
Twitter: https://twitter.com/nullbyte
Flipboard: https://flip.it/3.Gf_0
Website: https://null-byte.com
Weekly newsletter: https://eepurl.com/dE3Ovb
Vimeo: https://vimeo.com/channels/nullbyte Lock Down Your DNS with a Pi-Hole for Safer Web Browsing at Home [Tutorial]](https://i.ytimg.com/vi/WfcrRnr2UlM/mqdefault.jpg)
