β β β Uππ»βΊπ«6π¬πβ β β β
π¦Automate your termux work
-txtool is made to help you for easly pentesting in termux,
πΈπ½π π π°π»π»πΈπ π°π πΈπΎπ½ & π π π½ :
1οΈβ£
Enjoyβ€οΈππ»
β Topic git sources
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
β β β Uππ»βΊπ«6π¬πβ β β β
π¦Automate your termux work
-txtool is made to help you for easly pentesting in termux,
πΈπ½π π π°π»π»πΈπ π°π πΈπΎπ½ & π π π½ :
1οΈβ£
$ git clone https://github.com/kuburan/txtool.git
2οΈβ£$ cd txtool
3οΈβ£$ apt install python2
4οΈβ£$ ./install.py
5οΈβ£$ txtool
6οΈβ£for ssh backdoor access, txtool used paramiko python library that required PyNacl if you have an error installing PyNacl, follow my steps:> $ apt-get install --assume-yes libsodium libsodium-dev
> $ SODIUM_INSTALL=system pip2 install pynacl
7οΈβ£choose options via numb Enjoyβ€οΈππ»
β Topic git sources
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
β β β Uππ»βΊπ«6π¬πβ β β β
β β β Uππ»βΊπ«6π¬πβ β β β
π¦Popular free gift card websites :
π§ββοΈhttps://www.oneopinion.com
π§ββοΈhttps://dollarsprout.go2cloud.org/aff_c?offer_id=36&aff_id=2&aff_sub=earn-free-gift-cards
π§ββοΈhttps://www.thecardcloset.com/
π§ββοΈhttps://www.cdkeys.com/
π§ββοΈhttps://www.offgamers.com/
π§ββοΈhttps://www.giftcardmall.com/
π§ββοΈhttps://www.egifter.com/
π§ββοΈhttps://www.carddelivery.com/
π§ββοΈhttps://www.igp.com/
π§ββοΈhttps://www.pcgamesupply.com/
π§ββοΈhttps://www.mygiftcardsupply.com/
π§ββοΈhttps://www.woohoo.in/
π§ββοΈhttps://www.g2a.com/
π§ββοΈhttps://www.giftinix.com/
π§ββοΈhttps://www.giftcards.com/
π§ββοΈhttps://www.cardcash.com/
π§ββοΈhttps://joinhoney.com/ref/qedtrpr
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
β β β Uππ»βΊπ«6π¬πβ β β β
π¦Popular free gift card websites :
π§ββοΈhttps://www.oneopinion.com
π§ββοΈhttps://dollarsprout.go2cloud.org/aff_c?offer_id=36&aff_id=2&aff_sub=earn-free-gift-cards
π§ββοΈhttps://www.thecardcloset.com/
π§ββοΈhttps://www.cdkeys.com/
π§ββοΈhttps://www.offgamers.com/
π§ββοΈhttps://www.giftcardmall.com/
π§ββοΈhttps://www.egifter.com/
π§ββοΈhttps://www.carddelivery.com/
π§ββοΈhttps://www.igp.com/
π§ββοΈhttps://www.pcgamesupply.com/
π§ββοΈhttps://www.mygiftcardsupply.com/
π§ββοΈhttps://www.woohoo.in/
π§ββοΈhttps://www.g2a.com/
π§ββοΈhttps://www.giftinix.com/
π§ββοΈhttps://www.giftcards.com/
π§ββοΈhttps://www.cardcash.com/
π§ββοΈhttps://joinhoney.com/ref/qedtrpr
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
β β β Uππ»βΊπ«6π¬πβ β β β
π¦Best BTC buying pages use Spammed CC / IBAN
Γll documents and
other security protocols required
Coinmama.com
cex.io
coinbase.com
Bitpanda.com
pro.coinbase.com
bitstamp.net
Kraken.com
blockchain.com
bitcoin.com
β β β Uππ»βΊπ«6π¬πβ β β β
Γll documents and
other security protocols required
Coinmama.com
cex.io
coinbase.com
Bitpanda.com
pro.coinbase.com
bitstamp.net
Kraken.com
blockchain.com
bitcoin.com
β β β Uππ»βΊπ«6π¬πβ β β β
β β β Uππ»βΊπ«6π¬πβ β β β
π¦Chrome malicious extension steals personal data and has been downloaded over 30 million times
#News !!!
> Googleβs Chrome Web Store was hit by the largest surveillance activity to date. As of May 2020, the campaign successfully stolen data from users worldwide by downloading malicious extensions more than 32 million times.
> Awake's security threat research team released a research report stating that it discovered a large-scale global surveillance campaign that used the nature of Internet domain registration and browser capabilities to monitor and steal from multiple regions and industry segments User data. Research shows that this criminal activity is promoted by a single Internet domain registrar: CommuniGal Communication Ltd. (GalComm).
> And said that by using the trust as a domain name registrar, GalComm has enabled malicious activity, and the malicious activity has been found in more than one hundred networks inspected. In addition, even in complex organizations that have invested heavily in cybersecurity, malicious activities can be hidden by bypassing multiple layers of security controls.
> Awake pointed out in the report that there are 26,079 accessible domains registered through GalComm, of which more than 15,000 domains are malicious or suspicious.
> In the past three months alone, it has collected 111 malicious or forged Chrome extensions using GalComm domains, which are used for attacker's command and control infrastructure and/or as loader pages for extensions. These extensions can take screenshots, read the clipboard, get credential tokens stored in cookies or parameters, and get user keystrokes (such as passwords).
π¦Examples of tricks to install malicious Chrome extensions
> As of May 2020, the number of downloads of these 111 malicious extensions has reached 32,962,951 times. Awake said the company has partnered with Google to remove these extensions from the Chrome Web Store.
In response to this, Moshe Fogel, the person in charge of GalComm, stated in a communication with Reuters, βGalΠ‘omm is not involved in any malicious activities. It can be said that on the contrary, we cooperate with law enforcement and security agencies to do our best to prevent them.β After Awake Security published a report and listed all suspicious domain names, Moshe Fogel also said that the use of these domain names was almost inactive and would continue to investigate other domain names.
@UNdercodeNews
β β β Uππ»βΊπ«6π¬πβ β β β
π¦Chrome malicious extension steals personal data and has been downloaded over 30 million times
#News !!!
> Googleβs Chrome Web Store was hit by the largest surveillance activity to date. As of May 2020, the campaign successfully stolen data from users worldwide by downloading malicious extensions more than 32 million times.
> Awake's security threat research team released a research report stating that it discovered a large-scale global surveillance campaign that used the nature of Internet domain registration and browser capabilities to monitor and steal from multiple regions and industry segments User data. Research shows that this criminal activity is promoted by a single Internet domain registrar: CommuniGal Communication Ltd. (GalComm).
> And said that by using the trust as a domain name registrar, GalComm has enabled malicious activity, and the malicious activity has been found in more than one hundred networks inspected. In addition, even in complex organizations that have invested heavily in cybersecurity, malicious activities can be hidden by bypassing multiple layers of security controls.
> Awake pointed out in the report that there are 26,079 accessible domains registered through GalComm, of which more than 15,000 domains are malicious or suspicious.
> In the past three months alone, it has collected 111 malicious or forged Chrome extensions using GalComm domains, which are used for attacker's command and control infrastructure and/or as loader pages for extensions. These extensions can take screenshots, read the clipboard, get credential tokens stored in cookies or parameters, and get user keystrokes (such as passwords).
π¦Examples of tricks to install malicious Chrome extensions
> As of May 2020, the number of downloads of these 111 malicious extensions has reached 32,962,951 times. Awake said the company has partnered with Google to remove these extensions from the Chrome Web Store.
In response to this, Moshe Fogel, the person in charge of GalComm, stated in a communication with Reuters, βGalΠ‘omm is not involved in any malicious activities. It can be said that on the contrary, we cooperate with law enforcement and security agencies to do our best to prevent them.β After Awake Security published a report and listed all suspicious domain names, Moshe Fogel also said that the use of these domain names was almost inactive and would continue to investigate other domain names.
@UNdercodeNews
β β β Uππ»βΊπ«6π¬πβ β β β
Forwarded from UNDERCODE SECURITY
kmspico.zip
3 MB
ACTIVATE ANY WINDOWS -OFFICE 2020 NEW -ZIP-PASSWORD 12345
> turn of antivirus& install-official Kmsenjoyβ€οΈππ»
(safe)
β β β Uππ»βΊπ«6π¬πβ β β β
π¦MITM ATTACK VIA TERMUX BEST WAY 2020 :
? man-in-the-middle attack (MITM),
> also known as a hijack attack is an attack where the attacker secretly relays and possibly alters the communications between two parties who believe that they are directly communicating with each other. One example of a MITM attack is active eavesdropping, in which the attacker makes independent connections with the victims and relays messages between them to make them believe they are talking directly to each other over a private connection, when in fact the entire conversation is controlled by the attacker
WELL HOW TO DO ?
πΈπ½π π π°π»π»πΈπ π°π πΈπΎπ½ & π π π½ :
1οΈβ£
CHECK THIS VID : https://www.youtube.com/watch?v=hqbi86I6KhU
Share usβ€οΈππ»
β Topic sources 2020
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
β β β Uππ»βΊπ«6π¬πβ β β β
π¦MITM ATTACK VIA TERMUX BEST WAY 2020 :
? man-in-the-middle attack (MITM),
> also known as a hijack attack is an attack where the attacker secretly relays and possibly alters the communications between two parties who believe that they are directly communicating with each other. One example of a MITM attack is active eavesdropping, in which the attacker makes independent connections with the victims and relays messages between them to make them believe they are talking directly to each other over a private connection, when in fact the entire conversation is controlled by the attacker
WELL HOW TO DO ?
πΈπ½π π π°π»π»πΈπ π°π πΈπΎπ½ & π π π½ :
1οΈβ£
$ git clone https://github.com/websploit/websploit.git
2οΈβ£$ cd websploit
3οΈβ£$ python setup.py install
4οΈβ£Select module :
wsf > use arp_spoof
with options command you can see options of current module:
wsf > arp_spoof > options
Change options with set command:
wsf > arp_spoof > set target 192.168.1.24
Finally run module via execute command:
wsf > arp_spoof > execute
π¦STILL GE TROUBLE ?CHECK THIS VID : https://www.youtube.com/watch?v=hqbi86I6KhU
Share usβ€οΈππ»
β Topic sources 2020
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
β β β Uππ»βΊπ«6π¬πβ β β β
Forwarded from Free Premium Accounts Telegram Channel - Netflix - Spotify
Please open Telegram to view this post
VIEW IN TELEGRAM
Forwarded from Free Premium Accounts Telegram Channel - Netflix - Spotify
Please open Telegram to view this post
VIEW IN TELEGRAM
Forwarded from Free Premium Accounts Telegram Channel - Netflix - Spotify
Please open Telegram to view this post
VIEW IN TELEGRAM
Forwarded from Free Premium Accounts Telegram Channel - Netflix - Spotify
Please open Telegram to view this post
VIEW IN TELEGRAM
Forwarded from Free Premium Accounts Telegram Channel - Netflix - Spotify
Please open Telegram to view this post
VIEW IN TELEGRAM
Forwarded from UNDERCODE SECURITY
β β β Uππ»βΊπ«6π¬πβ β β β
π¦INSTALL UBUNTU ON TERMUX WITHOUT ROOT :
FASTEST WAY :
πΈπ½π π π°π»π»πΈπ π°π πΈπΎπ½ & π π π½ :
1οΈβ£Update termux: apt-get update && apt-get upgrade -y
2οΈβ£Install wget: apt-get install wget -y
3οΈβ£Install proot: apt-get install proot -y
4οΈβ£Install git: apt-get install git -y
5οΈβ£Go to HOME folder: cd ~
6οΈβ£Download script: git clone https://github.com/MFDGaming/ubuntu-in-termux.git
7οΈβ£Go to script folder: cd ubuntu-in-termux
8οΈβ£Give execution permission: chmod +x ubuntu.sh
9οΈβ£Run the script: ./ubuntu.sh -y
πNow just start ubuntu: ./startubuntu.sh
Share usβ€οΈππ»
β Topic sources 2020
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
β β β Uππ»βΊπ«6π¬πβ β β β
π¦INSTALL UBUNTU ON TERMUX WITHOUT ROOT :
FASTEST WAY :
πΈπ½π π π°π»π»πΈπ π°π πΈπΎπ½ & π π π½ :
1οΈβ£Update termux: apt-get update && apt-get upgrade -y
2οΈβ£Install wget: apt-get install wget -y
3οΈβ£Install proot: apt-get install proot -y
4οΈβ£Install git: apt-get install git -y
5οΈβ£Go to HOME folder: cd ~
6οΈβ£Download script: git clone https://github.com/MFDGaming/ubuntu-in-termux.git
7οΈβ£Go to script folder: cd ubuntu-in-termux
8οΈβ£Give execution permission: chmod +x ubuntu.sh
9οΈβ£Run the script: ./ubuntu.sh -y
πNow just start ubuntu: ./startubuntu.sh
Share usβ€οΈππ»
β Topic sources 2020
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
β β β Uππ»βΊπ«6π¬πβ β β β
GitHub
GitHub - MFDGaming/ubuntu-in-termux: This is a script by which you can install Ubuntu in your termux application without a rootedβ¦
This is a script by which you can install Ubuntu in your termux application without a rooted device - MFDGaming/ubuntu-in-termux
I saw many sellers they sell our stuff & open sources & accounts from @premiumhostTG
AND THEY COMBINE OUR STUFF IN GB SHIT LINKS AND SEND π€£π€£π€£π€£
AND THEY COMBINE OUR STUFF IN GB SHIT LINKS AND SEND π€£π€£π€£π€£
β β β Uππ»βΊπ«6π¬πβ β β β
π¦ALL YOU NEED TO KNOW ABOUT SIDE-CHANNEL ATTACK :
WHAT IS SIDE-CHANNEL ATTACK ?
> Side-channel attacks are all threats focused on knowledge obtained from the computer program execution, rather than flaws in the code itself (e.g. cryptanalysis and device bugs). Timing information, power use, electromagnetic interference, or even sound can provide an additional source of information that can be used.
πΈπ½π π π°π»π»πΈπ π°π πΈπΎπ½ & π π π½ :
A SMALL GUIDE FOR THIS 2020 TOOL :
Using Unicorn as a basis, Rainbow aims to provide an easy scripting interface to loosely emulate embedded binaries, trace them to perform side-channels, and (sometime in the near future :) )simulate fault injections.
-This is to allow quick and easy testing of physical attack resistance of code snippets, in order to help developers have a first evaluation of the resistance of their code.
1οΈβ£
https://m.youtube.com/watch?v=3v5Von-oNUg
π¦related advanced tools https://github.com/Ledger-Donjon/lascar
Share usβ€οΈππ»
β Topic sources 2020
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
β β β Uππ»βΊπ«6π¬πβ β β β
π¦ALL YOU NEED TO KNOW ABOUT SIDE-CHANNEL ATTACK :
WHAT IS SIDE-CHANNEL ATTACK ?
> Side-channel attacks are all threats focused on knowledge obtained from the computer program execution, rather than flaws in the code itself (e.g. cryptanalysis and device bugs). Timing information, power use, electromagnetic interference, or even sound can provide an additional source of information that can be used.
πΈπ½π π π°π»π»πΈπ π°π πΈπΎπ½ & π π π½ :
A SMALL GUIDE FOR THIS 2020 TOOL :
Using Unicorn as a basis, Rainbow aims to provide an easy scripting interface to loosely emulate embedded binaries, trace them to perform side-channels, and (sometime in the near future :) )simulate fault injections.
-This is to allow quick and easy testing of physical attack resistance of code snippets, in order to help developers have a first evaluation of the resistance of their code.
1οΈβ£
git clone https://github.com/Ledger-Donjon/rainbow.git
2οΈβ£cd rainbow
3οΈβ£python3 setup.py install
4οΈβ£Examples:
In the ./examples/ folder, you will find:
βx64_pimpmyxor.py : basic emulation of this challenge
βCortexM_AES : a simple ARM Thumb AES
βHacklu2009 : a side-channel solution of a whitebox challenge
βHW_analysis : a side-channel simulation of a pin comparison, and a fault injection simulation
βledger_ctf2 : side-channel solution of a whitebox challenge
βOAES : an x86 whitebox tracing example that discards useless instructions
βSecAESSTM32 : a starting point to test ANSSI's STM32 secure AES implementation
5οΈβ£Grab a device or generic emulator like so
from rainbow.devices import rainbow_stm32f215
from rainbow.generics import rainbow_x86
e = rainbow_stm32f215(sca_mode=False)
> Loading a binary
e.load('file', typ='.elf')
File type is guessed on the extension when possible (.elf, .hex).
6οΈβ£Starting the emulation is done like so:
e.start(start_address, stop_address, count=number_of_instructions)
Just like with unicorn. The underlying Unicorn instance is always available as e.emu.
π¦More : 1 h 22 minhttps://m.youtube.com/watch?v=3v5Von-oNUg
π¦related advanced tools https://github.com/Ledger-Donjon/lascar
Share usβ€οΈππ»
β Topic sources 2020
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
β β β Uππ»βΊπ«6π¬πβ β β β
YouTube
16. Side-Channel Attacks
MIT 6.858 Computer Systems Security, Fall 2014
View the complete course: http://ocw.mit.edu/6-858F14
Instructor: Nickolai Zeldovich
In this lecture, Professor Zeldovich discusses side-channel attacks, specifically timing attacks.
License: Creative Commonsβ¦
View the complete course: http://ocw.mit.edu/6-858F14
Instructor: Nickolai Zeldovich
In this lecture, Professor Zeldovich discusses side-channel attacks, specifically timing attacks.
License: Creative Commonsβ¦
β β β Uππ»βΊπ«6π¬πβ β β β
π¦Netflix accounts new methode :
1οΈβ£ Get a VPN and a new browser to preserve your identity.
nordvpn or sock5 or any trial good anonymous services
2οΈβ£ Netflix for polland or brazil
Google. In this way the connection starts from Brazil by a legitimate search on Google.com.br
netflix will open as brazil or polland depend on option you choose
Once you enter the site you have to sign up for the 1 month trial.
3οΈβ£Signing up
Choose one of the plans you 'd like the most. As you won't have to pay for it, you can also pick
This profile enables you to link to Ultra HD concurrently for a span of one month.
4οΈβ£You will need a temporary email to signup. I can recommend using https://temp-mail.org/ which allows you to generate an email of your choice without registration
5οΈβ£Choose a password for your Netflix account, now you will be asked for a payment method..
6οΈβ£ Payment method
Select "Debito Em Conta" as form of payment. This approach can be interpreted as "simple bank debit"
Bank
You'll set both values like a bank account number such that Netflix knows you 're a Brazilian citizen and
You have a bank account which is valid.
Visit https:/www.4devs.com.br / gerador de cpf and generate a number for your CPF. Please ensure "SP" is set as
"Early stadium do CPF." Export the CPF into the billing form for Netflix ..
Now visit https:/www.situacaocadastral.com.br/ and paste the same CPF even with a name it returns you.
Title then you can move ahead with the tutorial, then you have to move back to the start of stage 4, then repeat the test!!
cardingteam.cc
The last thing to copy is bank account, and it is the one that gives more trouble, but we found a way to
obtain it too.
1) Visit https://www.4devs.com.br/gerador_conta_bancaria
2) Pick βCaixaβ, βBradescoβ or βSantanderβ as Banco, pick βSPβ as Estado. (Caixa is recommended)
3) Keep generating bank account until you get one that begins with β001β, β013β, β023β or β037β
If you receive an account that starts with 1 of these 4 approved variations, you will copy the account
Amount inside the Netflix website and paste it (remember "Agencia").
You 're able to get started. Netflix will be offering you her warm welcome to the service at this stage. You've done it!
This account lasts 1 month, and can be transferred to some other language account by heading to
"My profile" and then "english" and pick the one you want.
Here are some profiles that we have created over the past 2 days, that will last 1 full month ...
Repeat after expiry cycle for more!
enjoy β€οΈππ»
rewritten
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
β β β Uππ»βΊπ«6π¬πβ β β β
π¦Netflix accounts new methode :
1οΈβ£ Get a VPN and a new browser to preserve your identity.
nordvpn or sock5 or any trial good anonymous services
2οΈβ£ Netflix for polland or brazil
Google. In this way the connection starts from Brazil by a legitimate search on Google.com.br
netflix will open as brazil or polland depend on option you choose
Once you enter the site you have to sign up for the 1 month trial.
3οΈβ£Signing up
Choose one of the plans you 'd like the most. As you won't have to pay for it, you can also pick
This profile enables you to link to Ultra HD concurrently for a span of one month.
4οΈβ£You will need a temporary email to signup. I can recommend using https://temp-mail.org/ which allows you to generate an email of your choice without registration
5οΈβ£Choose a password for your Netflix account, now you will be asked for a payment method..
6οΈβ£ Payment method
Select "Debito Em Conta" as form of payment. This approach can be interpreted as "simple bank debit"
Bank
You'll set both values like a bank account number such that Netflix knows you 're a Brazilian citizen and
You have a bank account which is valid.
Visit https:/www.4devs.com.br / gerador de cpf and generate a number for your CPF. Please ensure "SP" is set as
"Early stadium do CPF." Export the CPF into the billing form for Netflix ..
Now visit https:/www.situacaocadastral.com.br/ and paste the same CPF even with a name it returns you.
Title then you can move ahead with the tutorial, then you have to move back to the start of stage 4, then repeat the test!!
cardingteam.cc
The last thing to copy is bank account, and it is the one that gives more trouble, but we found a way to
obtain it too.
1) Visit https://www.4devs.com.br/gerador_conta_bancaria
2) Pick βCaixaβ, βBradescoβ or βSantanderβ as Banco, pick βSPβ as Estado. (Caixa is recommended)
3) Keep generating bank account until you get one that begins with β001β, β013β, β023β or β037β
If you receive an account that starts with 1 of these 4 approved variations, you will copy the account
Amount inside the Netflix website and paste it (remember "Agencia").
You 're able to get started. Netflix will be offering you her warm welcome to the service at this stage. You've done it!
This account lasts 1 month, and can be transferred to some other language account by heading to
"My profile" and then "english" and pick the one you want.
Here are some profiles that we have created over the past 2 days, that will last 1 full month ...
Repeat after expiry cycle for more!
enjoy β€οΈππ»
rewritten
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
β β β Uππ»βΊπ«6π¬πβ β β β
Temp Mail
Temp Mail - Disposable Temporary Email
Keep spam out of your mail and stay safe - just use a disposable temporary email address! Protect your personal email address from spam with Temp-mail