DevCyberSecurity
1.26K subscribers
230 photos
8 videos
59 files
306 links
"Welcome to DevCyberSecurity! ๐Ÿ›ก

Stay ahead in the ever-evolving world of cybersecurity with our channel. Here, we share valuable insights, latest trends, cutting-edge techniques, and resources tailored for developers and cybersecurity enthusiasts alike
Download Telegram
โšซ๏ธ100 Useful shortcut keys in ZAP (OWASP Zed Attack Proxy):

1. Ctrl+O: Open file
2. Ctrl+S: Save file
3. Ctrl+N: New session
4. Ctrl+Q: Quit ZAP
5. Ctrl+R: Refresh
6. Ctrl+Shift+N: New tab
7. Ctrl+Tab: Switch to next tab
8. Ctrl+Shift+Tab: Switch to previous tab
9. Ctrl+W: Close tab
10. Ctrl+Shift+W: Close all tabs
11. Ctrl+T: Start/Stop scanning
12. Ctrl+G: Generate report
13. Ctrl+Shift+G: Generate report with parameters
14. Ctrl+H: Show/hide the attack panel
15. Ctrl+Shift+H: Show/hide the HTTP panel
16. Ctrl+P: Show/hide the parameters panel
17. Ctrl+Shift+P: Show/hide the parameters panel and reset the parameters
18. Ctrl+U: Show/hide the user interface panel
19. Ctrl+B: Show/hide the breakpoints panel
20. Ctrl+F: Find text
21. Ctrl+Shift+F: Find next occurrence
22. Ctrl+Alt+F: Find previous occurrence
23. Ctrl+Z: Undo
24. Ctrl+Y: Redo
25. Ctrl+A: Select all
26. Ctrl+X: Cut
27. Ctrl+C: Copy
28. Ctrl+V: Paste
29. Ctrl+Shift+V: Paste special
30. Ctrl+D: Duplicate
31. Ctrl+K: Delete
32. Ctrl+Shift+K: Delete all
33. Ctrl+I: Intercept on/off
34. Ctrl+Shift+I: Reissue last request
35. Ctrl+L: Spider
36. Ctrl+Shift+L: Spider and attack
37. Ctrl+J: Forced browsing
38. Ctrl+Shift+J: Forced browsing and attack
39. Ctrl+M: Active scan
40. Ctrl+Shift+M: Active scan and attack
41. Ctrl+X: Exclude from scan
42. Ctrl+E: Exclude from spider
43. Ctrl+R: Reenable selected items
44. Ctrl+Shift+X: Reenable all items
45. Ctrl+Shift+E: Reenable all excluded items
46. Ctrl+Shift+R: Reset session
47. F1: Show help
48. F5: View/fuzz last request/URL
49. F6: View/fuzz history URLs
50. F7: View/fuzz URLs in sitemap
51. F8: View/fuzz site map URLs
52. F9: View/fuzz site tree URLs
53. F10: View/fuzz sites URLs
54. F11: View/fuzz context URLs
55. F12: View/fuzz include URLs
56. Alt+F4: Close ZAP
57. Alt+F: File menu
58. Alt+E: Edit menu
59. Alt+V: View Menu
60. Alt+S: Session menu
61. Alt+H: Tools menu
62. Alt+T: Reports menu
63. Alt+O: Options menu
64. Alt+H: Help menu
65. Alt+1: Switch to Home tab
66. Alt+2: Switch to Alerts tab
67. Alt+3: Switch to Sites tab
68. Alt+4: Switch to History tab
69. Alt+5: Switch to Scope tab
70. Alt+6: Switch to Proxy tab
71. Alt+7: Switch to Spider tab
72. Alt+8: Switch to Active Scan tab
73. Alt+9: Switch to Fuzzer tab
74. Alt+0: Switch to Scripts tab
75. Alt+Shift+1: Switch to Filters tab
76. Alt+Shift+2: Switch to Find tab
77. Alt+Shift+3: Switch to Breakpoints tab
78. Alt+Shift+4: Switch to Output tab
79. Alt+Shift+5: Switch to Parameters tab
80. Alt+Shift+6: Switch to Request tab
81. Alt+Shift+7: Switch to Response tab
82. Alt+Shift+8: Switch to Break tab
83. Alt+Shift+9: Switch to Attack tab
84. Alt+Shift+0: Switch to Note tab
85. Shift+F5: View/fuzz in scope URLs
86. Shift+F6: View/fuzz out of scope URLs
87. Shift+F7: View/fuzz fuzz URLs
88. Shift+F8: View/fuzz hidden URLs
89. Shift+F9: View/fuzz wildcard URLs
90. Shift+F10: View/fuzz regexp URLs
91. Shift+F11: View/fuzz HTTP URLs
92. Shift+F12: View/fuzz AJAX URLs
93. Shift+Ctrl+S: Save session
94. Shift+Ctrl+A: Open recent session
95. Shift+Ctrl+Q: Quit ZAP with prompt
96. Shift+Ctrl+R: Reopen last closed tab
97. Shift+Ctrl+C: Close current tab
98. Shift+Ctrl+P: View in browser
99. Shift+Ctrl+E: Export to context menu
100. Shift+Ctrl+U: Import from context menu

๐ŸŽฉ https://t.me/DevCyberSecurity
๐Ÿ‘3
whatsapp_hacking_qrl:

๐Ÿ”ฐ HACK WHATSAPP WITH QRL JACKING ๐Ÿ”ฐ

๐Ÿ”ฒ QRLJacking or Quick Response Code Login Jacking is a simple-but-nasty attack vector affecting all the applications that relays on โ€œLogin with QR codeโ€ feature as a secure way to login into accounts which aims for hijacking users session by attackers. ๐Ÿ”ฒ


๐Ÿ”ถ Installation ๐Ÿ”ท

apt update && apt install git

apt install python && apt install python3

pip install --upgrade pip

git clone https://github.com/OWASP/QRLJacking.git

cd QRLJacking

cd QRLJacker

chmod +x *

pip install -r requirements.txt

python3 QrlJacker.py

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

`โ€ข....


YouTube channel ๐Ÿ‘‰



https://www.youtube.com/channel/UCTscVHNT4BjfsnuG_t9KMOg?sub_confirmation=1
โค2๐Ÿ‘2
Here's the list of bug hunting tools:

1. Burp Suite ๐Ÿ›
2. OWASP ZAP (Zed Attack Proxy) ๐Ÿ›ก
3. Nmap ๐ŸŒ
4. Metasploit ๐Ÿ› 
5. Wireshark ๐Ÿ–ฅ
6. Nikto ๐Ÿ•ต๏ธโ€โ™‚๏ธ
7. SQLMap ๐Ÿ—บ
8. Acunetix ๐Ÿ•ท
9. Nessus ๐Ÿš€
10. OpenVAS ๐Ÿšช
11. BeEF (Browser Exploitation Framework) ๐Ÿ„
12. Shodan ๐Ÿ”
13. Wfuzz ๐ŸŒ€
14. DirBuster ๐Ÿšช
15. XSStrike ๐Ÿ’ฅ
16. SQLMate ๐Ÿค
17. Sublist3r ๐ŸŽฏ
18. Hydra ๐Ÿ
19. Skipfish ๐ŸŸ
20. Recon-ng ๐Ÿ•ต๏ธโ€โ™‚๏ธ
21. Masscan ๐Ÿ›ฐ
22. Wappalyzer ๐Ÿ“Š
23. Gitrob ๐Ÿ•ต๏ธโ€โ™‚๏ธ
24. Gobuster ๐Ÿ”ฆ
25. XSSer ๐Ÿ’ข
26. Joomscan ๐Ÿ•ต๏ธโ€โ™‚๏ธ
27. WPScan ๐Ÿ”
28. EyeWitness ๐Ÿ‘€
29. Fiddler ๐ŸŽป
30. sqlninja ๐Ÿฅท
31. Vega ๐ŸŒŸ
32. Arachni ๐Ÿ•ท
33. DirSearch ๐Ÿ”
34. httrack ๐Ÿƒโ€โ™‚๏ธ
35. CMSmap ๐Ÿ—บ
36. DVWA (Damn Vulnerable Web Application) ๐Ÿ˜ˆ
37. Docker Bench for Security ๐Ÿ‹
38. Amass ๐Ÿ“ˆ
39. WPScan ๐Ÿ”
40. Zed Attack Proxy ๐Ÿ›ก
41. SonarQube ๐Ÿ›ก
42. ClamAV ๐Ÿฆช
43. OSSEC ๐Ÿ”
44. Tripwire ๐Ÿ›ก
45. AIDE (Advanced Intrusion Detection Environment) ๐Ÿ›ก
46. Fail2Ban ๐Ÿšซ
47. Lynis ๐Ÿง
48. Snort ๐Ÿฝ
49. Suricata ๐Ÿฆˆ
50. Security Onion ๐Ÿง…

Happy bug hunting!

https://t.me/DevCyberSecurity
๐Ÿ”ฐ Hydra
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”
hackethics138
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”
Hydra: Password-cracking tool for brute-force attacks on login systems.
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”
Installation:

apt install proot-distro

proot-distro list

proot-distro install ubuntu

proot-distro login ubuntu

apt update

apt upgrade -y

apt install hydra -y

hydra -h
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”
Always log in to Ubuntu if you want to use Hydra.

proot-distro login ubuntu

hydra -h
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”
Usage:

./hydra -l admin -p password ftp://localhost/

./hydra -L adminlist.txt -p test ftp://localhost/ 

hydra -l admin -P passwords.txt ftp://localhost/

hydra -L logins.txt -P passwords.txt ftp://localhost/

In Hydra, lowercase (-L) for usernames, uppercase (-p) for wordlists. Example:
hydra -L login.txt -p adminlogin ftp://example/
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”
  โ™ฅ๏ธ  Telegram Channel - โ™ฅ๏ธ

https://t.me/DevCyberSecurity
How To Make Fud Metasploit Payload; 2023 Method

Today We are Going To Learn How To Make Full Undetected Payload of metasploit payload, and we will try to bypass Antivirus So, First we need to create Metasploit payload then we will make fud. read more

โšœ๏ธCovered in contents
1. Why we need to make fud?
2. Why hackers make fud malware
3. Antivirus bypass
4. Easy Steps
5. Available Free Requirements
6. Demo Practically Video available

๐Ÿ™ Learn Now
https://www.xploitpoison.com/2022/11/make-fud-metasploit-payload.html

โค๏ธ Created by โค๏ธ -:

https://t.me/DevCyberSecurity
ุงุฏุงุฉ ุงุฎุชุฑุงู‚ ูƒุงู…ูŠุฑุฉ ุงูŠ ู‡ุงุชู ุจุงู„ุทุฑูŠู‚ุฉ ุงู„ุตุญูŠุญุฉ ุนุจุฑ ุงุฏุงุฉ WishFish ุนู„ูŠ ุชุทุจูŠู‚ Termux

โ€ข ู„ุชุซุจูŠุช ุงู„ุงุฏุงุฉ โค๏ธโœจ

apt update

apt upgrade

apt install php

apt install wget

apt install openssh

git clone https://github.com/kinghacker0/WishFish

โ€ข ู„ูุชุญ ุงู„ุงุฏุงุฉ โค๏ธโœจ

cd Wishfish

bash wishfish.sh
๐Ÿ”–#SEARCH ENGINES FOR PENTESTERS

01. shodan.io โ€”> (Server , Vulnerabilities)
02. google.com โ€”> (Dorks)
03. wigle.net โ€”> (Wifi Networks)
04. grep.app โ€”> (Codes Search)
05. app.binaryedge.io โ€”> (Threat Intelligence)
06. onyphe.io โ€”> (Server)
07. viz.greynoise.io โ€”> (Threat Intelligence)
08. censys.io โ€”> (Server)
09. hunter.io โ€”> (Email Addresses)
10. fofa.info โ€”> (Threat Intelligence)
11. zoomeye.org โ€”> (Threat Intelligence)
12. leakix.net โ€”> (Threat Intelligence)
13. intelx.io โ€”> (OSINT)
14. app.netlas.io โ€”> (Attack Surface)
15. searchcode.com โ€”> (Code Search)
16. urlscan.io โ€”> (Threat Intelligence)
17. publicwww.com โ€”> (Code Search)
18. fullhunt.io โ€”> (Attack Surface)
19. socradar.io โ€”> (Threat Intelligence)
20. binaryedge.io โ€”> (Attack Surface)
21. ivre.rocks โ€”> (Server)
22. crt.sh โ€”> (Certificate Search)
23. vulners.com โ€”> (Vulnerabilities)
24. pulsedive.com โ€”> (Threat Intelligence)

โ€” Share & Support Us โ€”

https://t.me/DevCyberSecurity
๐Ÿ”ฅ1
Email & Username OSINT have many crossovers due to the methodology of say, using the first part of an email as an username. It is fair to say that this is a lucrative business and some resources start of as free but then bring in a payment structure. Some of the below may need you to sign up for a free account, some platforms offer a free trial. Don't forget Google advanced searching is another option, websites can be searched by simply manipulating the URL structure to include the username in the domain. Also don't forget to manipulate the username itself, replace O with a 0 for example.



๐Ÿ‘‰https://github.com/cqcore/Email-Username-OSINT?tab=readme-ov-file
๐Ÿ‘1
How many people think that I should launch a digital forensics course on my channel?
Anonymous Poll
93%
Yes
7%
NO
๐Ÿ‘4