Tetstack
219 subscribers
920 photos
28 videos
35 files
127 links
Download Telegram
I have used my school website( I know this is a massive OPSEC but our document is on paper it won't matter) and so found three vulnerabilities as seen on the screenshots. I will post my tool on github for everyone to access.
Not the best one i made but it looks great i guess
The tool is finally done
The tool is officially done and the repository is live for everyone to access.
​Following up on the spoiler from earlier where I tested it on my school website and found those three vulnerabilities, you can now grab the source code and run it on your own deployments.
​KASCVE is designed to be completely straightforward. You throw a website at it post-deployment, and it executes basic, advanced, and deep scans to check for known CVEs, parameter sanitization issues, and flaws like SQL injection.
​Instead of just giving you a standard report showing what's broken, it actually outputs a hardening matrix with the exact configuration patches for Nginx, Apache, and Laravel so you can secure your website straight away. It also includes an automated setup script to link the tool globally to your terminal environment.
​Quick start:

git clone https://github.com/PicasoTheDeal/KASCVE.git
cd KASCVE && sudo ./install.sh
KASCVE targetdomain.com


Go check out the repository, read through the documentation, and drop a star on the project:
https://github.com/PicasoTheDeal/KASCVE
urm sooo besoccer is also vulnerable, I think i made the wrong tool but as long as i say it is for defence i am okay with it.
if anyone git cloned it already thank you very much git clone again for some minor updates on the logic and security, works the same way i just added that so i won't be held accountable for your actions.
❤1
i would really earn a lot of money through this but mehhhh i am too lazy
And please don't try to scan big websites like Amazon or any other related your ip will be blacklisted.
Tetstack
Better...
Literally got the idea from jem stones I found in the living room
I am not a social type of guy but I love joining public groups to collect unique stickers, won't use them but they joining my pack.
I guess good night everyone
❤1
I need some money so I will start selling advanced version of the KASCVE tool known as KASCVE-BUG for specifically bug-bounty. If any one want to buy my tool it's for sale just PM me
So coming back to the point the deference bn KASCVE and KASCVE-BUG is KESCVE-BUG can test real world enterprise big website like Amazon or any other with out getting your ip blocked by the firewall cuz of high traffic, give full analysis on which CVE is where.
Public Version (Baseline)
​Single-Target Auditing – Requires manual execution against one endpoint or asset at a time.
​Passive Surface Mapping – Collects raw configuration data, server headers, and basic asset footprints.
​Raw Data Assessment – Provides a standard list of findings that require manual triage and analysis.
​Vulnerability Reporting – Identifies the issue but leaves the remediation strategy entirely up to the user.
​Standalone Script – Runs locally and requires manual environment configuration and active monitoring.


​
Premium Version (Upgraded)
​Multi-Target Campaigns – Automates wide-scope discovery across massive, bulk target lists simultaneously.
​Active Flaw Verification – Probes deeper using structural HTML form analysis and integrated fuzzing to expose high-impact vulnerabilities like missing Anti-CSRF tokens and SQLi entry points.
​Prioritized Severity Matrix – Automatically categorizes risks by threat level so you instantly know what to fix first.
​Production Remediation Blueprints – Delivers drop-in config fixes tailored specifically for deployment environments like Nginx, Apache, and Laravel.
​Global CLI Utility – Features an automated system installer, seamless environment setup, and built-in rate-limiting logic for safe, reliable scanning.