Forwarded from Backup Legal Mega
Introduction to the Steemit Crypto Currency Platform β637 MBβ
https://www.packtpub.com/application-development/introduction-steemit-crypto-currency-platform-video
https://mega.nz/#F!KpVljSSA!pkpijv6k0-6GdeCNtJVfJQ
https://www.packtpub.com/application-development/introduction-steemit-crypto-currency-platform-video
https://mega.nz/#F!KpVljSSA!pkpijv6k0-6GdeCNtJVfJQ
Packt
Introduction to the Steemit Crypto Currency Platform [Video] | Packt
Get Paid Steem CryptoCurrency To Blog and Comment On Steemit . Blogging for cash has never been easier!
π¦Bin For Spotify 3 Months Premium + ATRESplayer Premium
BIN: 5183024500xxxxxx
DATE: Rnd
CVV: Rnd
IP: USA πΊπΈ
β Spotify
β AteresPlayer
How use bin https://t.me/UnderCodeTesting/3768
BIN: 5183024500xxxxxx
DATE: Rnd
CVV: Rnd
IP: USA πΊπΈ
β Spotify
β AteresPlayer
How use bin https://t.me/UnderCodeTesting/3768
Forwarded from Backup Legal Mega
Beyond Beginner GameMaker Studio 2 - Creating A Full Tower Defense Game From Scratch β 5.8 GB
https://www.skillshare.com/classes/Beyond-Beginner-GameMaker-Studio-2-Creating-A-Full-Tower-Defense-Game-From-Scratch/3495473
https://mega.nz/#F!Uo0zxKoD!qQAZBugSYXffzPzpb67d5g
https://www.skillshare.com/classes/Beyond-Beginner-GameMaker-Studio-2-Creating-A-Full-Tower-Defense-Game-From-Scratch/3495473
https://mega.nz/#F!Uo0zxKoD!qQAZBugSYXffzPzpb67d5g
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
π¦MALWARE RESOURCES :
* [SMRT](https://github.com/pidydx/SMRT) - Sublime Malware Research Tool, a
plugin for Sublime 3 to aid with malware analyis.
* [strace](https://sourceforge.net/projects/strace/) - Dynamic analysis for
* [StringSifter](https://github.com/fireeye/stringsifter) - A machine learning tool
that automatically ranks strings based on their relevance for malware analysis.
* [Triton](https://triton.quarkslab.com/) - A dynamic binary analysis (DBA) framework.
* [Udis86](https://github.com/vmt/udis86) - Disassembler library and tool
for x86 and x86_64.
* [Vivisect](https://github.com/vivisect/vivisect) - Python tool for
malware analysis.
* [WinDbg](https://developer.microsoft.com/en-us/windows/hardware/download-windbg) - multipurpose debugger for the Microsoft Windows computer operating system, used to debug user mode applications, device drivers, and the kernel-mode memory dumps.
* [X64dbg](https://github.com/x64dbg/) - An open-source x64/x32 debugger for windows.
* [iocextract](https://github.com/InQuest/python-iocextract) - Advanced Indicator
of Compromise (IOC) extractor, Python library and command-line tool.
β 2020 GIT SOURCES
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
π¦MALWARE RESOURCES :
* [SMRT](https://github.com/pidydx/SMRT) - Sublime Malware Research Tool, a
plugin for Sublime 3 to aid with malware analyis.
* [strace](https://sourceforge.net/projects/strace/) - Dynamic analysis for
* [StringSifter](https://github.com/fireeye/stringsifter) - A machine learning tool
that automatically ranks strings based on their relevance for malware analysis.
* [Triton](https://triton.quarkslab.com/) - A dynamic binary analysis (DBA) framework.
* [Udis86](https://github.com/vmt/udis86) - Disassembler library and tool
for x86 and x86_64.
* [Vivisect](https://github.com/vivisect/vivisect) - Python tool for
malware analysis.
* [WinDbg](https://developer.microsoft.com/en-us/windows/hardware/download-windbg) - multipurpose debugger for the Microsoft Windows computer operating system, used to debug user mode applications, device drivers, and the kernel-mode memory dumps.
* [X64dbg](https://github.com/x64dbg/) - An open-source x64/x32 debugger for windows.
* [iocextract](https://github.com/InQuest/python-iocextract) - Advanced Indicator
of Compromise (IOC) extractor, Python library and command-line tool.
β 2020 GIT SOURCES
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
GitHub
pidydx/SMRT
Sublime Malware Research Tool. Contribute to pidydx/SMRT development by creating an account on GitHub.
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
π¦helpfull termux tool :
FEATURES :
>Grabb email passwords NEW!
>Check passwords leaked.
>Check hash code leaked.
>Check email leaked!
πΈπ½π π π°π»π»πΈπ π°π πΈπΎπ½ & π π π½ :
1οΈβ£
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
π¦helpfull termux tool :
FEATURES :
>Grabb email passwords NEW!
>Check passwords leaked.
>Check hash code leaked.
>Check email leaked!
πΈπ½π π π°π»π»πΈπ π°π πΈπΎπ½ & π π π½ :
1οΈβ£
sudo apt update && sudo apt install python3 python3-pip
2οΈβ£git clone https://github.com/GitHackTools/Leaked
3οΈβ£cd Leaked
4οΈβ£bash install_update.sh
5οΈβ£python3 leaked.py
6οΈβ£CHOOSE OPTIONS VIA NUMBER SIMPLY@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
DSResearch-InsideOnlineCardingCourses.pdf.pdf
1.8 MB
Russian CARDING -ENGLISH COMPLET
Forwarded from Backup Legal Mega
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
11 JavaScript Features Critical to Understand [727 MB]
https://www.udemy.com/course/11-javascript-features-critical-to-understand/
https://mega.nz/#F!wQ1lyQab!iJ7pacvWt5oYKFUcBtjz3A
Spring Boot Microservices and Spring Cloud [1.3 GB]
https://www.udemy.com/course/spring-boot-microservices-and-spring-cloud/
https://mega.nz/#F!z5MghYZQ!OJXC1YdmnRG5xgS_jmkHLA
Deep Reinforcement Learning: A Hands-on Tutorial in Python [1.48 GB]
https://www.udemy.com/course/deep-reinforcement-learning-a-hands-on-tutorial-in-python/
https://mega.nz/#F!GxtVHayI!wb3gAohVAZO622JeMSHRXA
Asynchronous JavaScript Deep Dive [2.08 GB]
https://www.udemy.com/course/asynchronous-javascript-deep-dive/
https://mega.nz/#F!OhdVCKwB!WvkGz-QqBFLo6P48bbV8gQ
Programming for Kids and Beginners: Learn to Code in Scratch [4.45 GB]
https://mega.nz/#F!f5NRjKjA!nQqEpOka_VJ7XnCKPxWv7g
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
11 JavaScript Features Critical to Understand [727 MB]
https://www.udemy.com/course/11-javascript-features-critical-to-understand/
https://mega.nz/#F!wQ1lyQab!iJ7pacvWt5oYKFUcBtjz3A
Spring Boot Microservices and Spring Cloud [1.3 GB]
https://www.udemy.com/course/spring-boot-microservices-and-spring-cloud/
https://mega.nz/#F!z5MghYZQ!OJXC1YdmnRG5xgS_jmkHLA
Deep Reinforcement Learning: A Hands-on Tutorial in Python [1.48 GB]
https://www.udemy.com/course/deep-reinforcement-learning-a-hands-on-tutorial-in-python/
https://mega.nz/#F!GxtVHayI!wb3gAohVAZO622JeMSHRXA
Asynchronous JavaScript Deep Dive [2.08 GB]
https://www.udemy.com/course/asynchronous-javascript-deep-dive/
https://mega.nz/#F!OhdVCKwB!WvkGz-QqBFLo6P48bbV8gQ
Programming for Kids and Beginners: Learn to Code in Scratch [4.45 GB]
https://mega.nz/#F!f5NRjKjA!nQqEpOka_VJ7XnCKPxWv7g
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
Udemy
11 JavaScript Features Critical to Understand
Important JavaScript Concept and Features Every Developer Should Know
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
π¦Apache Log Modules
Apache has several modules that are responsible for weblogs:
1οΈβ£mod_log_config . Keeps a log of requests made to the server. This is the main module, which is enabled by default, and it is he who saves information about requests. Basically, here we will consider this particular module and its settings. Provides access log operation .
2οΈβ£mod_log_debug . Additional custom debug logs. Enables Additional configurable debug logging. It has an experimental status.
3οΈβ£mod_log_forensic . Forensic registration of server requests. Provides Forensic (forensic logs).
4οΈβ£mod_logio . Registration of input and output bytes of each request. This module must be included in the Apache configuration if you want to log information about the amount of data transferred and / or received. Provides some of the features of the Access Log format (access log).
5οΈβ£Apache Core Features - The main Apache HTTP Server features that are always available. It also provides the operation of Error Log and Per-module logging .
6οΈβ£mod_cgi and mod_cgid . Provides the work of the CGI Script Execution Log.
Written by Undercode
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
π¦Apache Log Modules
Apache has several modules that are responsible for weblogs:
1οΈβ£mod_log_config . Keeps a log of requests made to the server. This is the main module, which is enabled by default, and it is he who saves information about requests. Basically, here we will consider this particular module and its settings. Provides access log operation .
2οΈβ£mod_log_debug . Additional custom debug logs. Enables Additional configurable debug logging. It has an experimental status.
3οΈβ£mod_log_forensic . Forensic registration of server requests. Provides Forensic (forensic logs).
4οΈβ£mod_logio . Registration of input and output bytes of each request. This module must be included in the Apache configuration if you want to log information about the amount of data transferred and / or received. Provides some of the features of the Access Log format (access log).
5οΈβ£Apache Core Features - The main Apache HTTP Server features that are always available. It also provides the operation of Error Log and Per-module logging .
6οΈβ£mod_cgi and mod_cgid . Provides the work of the CGI Script Execution Log.
Written by Undercode
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
π¦2020 BRUTEFORCE RDP BEST METHODE USING HYDRA THE FAMOUS TOOL-
Script for automatic scanning of the address list for the presence of open 3389 ports, and then selecting the method and starting busting pair login / password.
πΈπ½π π π°π»π»πΈπ π°π πΈπΎπ½ & π π π½ :
3οΈβ£Installing dependencies
4οΈβ£Running the script
π¦Tested On :
-Kali
-Parrot
-Debian 10/9
- work's for ubuntu Systems
π¦
https://www.youtube.com/watch?v=Kpl8l6YQq48&feature=youtu.be
ENJOY β€οΈππ»
β 2020 GIT SOURCES
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
π¦2020 BRUTEFORCE RDP BEST METHODE USING HYDRA THE FAMOUS TOOL-
RUSSIAN CODEScript for automatic scanning of the address list for the presence of open 3389 ports, and then selecting the method and starting busting pair login / password.
πΈπ½π π π°π»π»πΈπ π°π πΈπΎπ½ & π π π½ :
1οΈβ£git clone https://github.com/getdrive/Lazy-RDP
2οΈβ£cd Lazy-RDP && chmod +x hydra/configure hydra/hydra src/rdp_brute.sh patator.py start INSTALL
3οΈβ£Installing dependencies
./INSTALL
4οΈβ£Running the script
./start
π¦Tested On :
-Kali
-Parrot
-Debian 10/9
- work's for ubuntu Systems
π¦
VIDEO TUTORIAL (BRUTEFORCE RDP)https://www.youtube.com/watch?v=Kpl8l6YQq48&feature=youtu.be
ENJOY β€οΈππ»
β 2020 GIT SOURCES
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
YouTube
Lab Pentestit v.11 - RDP vs Lazy-RDP+MS16-032
Π Π²ΠΎΠΏΡΠΎΡΡ ΠΎ ΡΠΎΠΌ, ΠΊ ΡΠ΅ΠΌΡ ΠΌΠΎΠ³ΡΡ ΠΏΡΠΈΠ²Π΅ΡΡΠΈ ΡΠ»Π°Π±ΡΠ΅ ΠΏΠ°ΡΠΎΠ»ΠΈ, Π΄Π°ΠΆΠ΅ Π½Π΅ΠΏΡΠΈΠ²ΠΈΠ»Π΅Π³ΠΈΡΠΎΠ²Π°Π½Π½ΡΡ
Π°ΠΊΠΊΠ°ΡΠ½ΡΠΎΠ².
Link Lazy-RDP: https://github.com/getdrive/Lazy-RDP
Track: Electric Universe - Visiting Venus
Network diagram: https://drive.google.com/open?id=1RfsGBmTA-BaD5XA2xQC08nfgN9eiG0Pr
Link Lazy-RDP: https://github.com/getdrive/Lazy-RDP
Track: Electric Universe - Visiting Venus
Network diagram: https://drive.google.com/open?id=1RfsGBmTA-BaD5XA2xQC08nfgN9eiG0Pr
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
π¦How to change x11vnc options without restarting the service ??
> The x11vnc service can be controlled remotely, for example, terminate its work or change options on the fly. To do this, use the same command that runs the VNC server, that is, x11vnc with the -remote option . This option has two aliases: -R and -r
The list of supported commands is large, let's consider only a few examples:
To install an already running VNC server, use any of the following commands:
1οΈβ£x11vnc -remote stop<font></font>
x11vnc -R stop
2οΈβ£To enable shared connections:
x11vnc -R shared
3οΈβ£The following command will scale the desktop:
x11vnc -R scale:3/4
π¦The command to allow connections if the VNC server was started with the -deny_all option :
1οΈβ£ x11vnc -remote nodeny
To run a sequence of commands, use something like this:
2οΈβ£x11vnc -R 'script
To read commands from a file, use:
x11vnc -R script:file...
3οΈβ£A file can consist of several lines and use the ' # ' symbol for commenting. In any case, you need to use split ' ; 'to separate each team.
written by Undercode
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
π¦How to change x11vnc options without restarting the service ??
> The x11vnc service can be controlled remotely, for example, terminate its work or change options on the fly. To do this, use the same command that runs the VNC server, that is, x11vnc with the -remote option . This option has two aliases: -R and -r
The list of supported commands is large, let's consider only a few examples:
To install an already running VNC server, use any of the following commands:
1οΈβ£x11vnc -remote stop<font></font>
x11vnc -R stop
2οΈβ£To enable shared connections:
x11vnc -R shared
3οΈβ£The following command will scale the desktop:
x11vnc -R scale:3/4
π¦The command to allow connections if the VNC server was started with the -deny_all option :
1οΈβ£ x11vnc -remote nodeny
To run a sequence of commands, use something like this:
2οΈβ£x11vnc -R 'script
To read commands from a file, use:
x11vnc -R script:file...
3οΈβ£A file can consist of several lines and use the ' # ' symbol for commenting. In any case, you need to use split ' ; 'to separate each team.
written by Undercode
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
Forwarded from Backup Legal Mega
Practical PLC Programming (PLC II) β1.66 GBβ
https://www.udemy.com/course/plc_programming/
https://mega.nz/#F!igcEkCAI!Ml8NqStrX3jFiep_kFT1qg
https://www.udemy.com/course/plc_programming/
https://mega.nz/#F!igcEkCAI!Ml8NqStrX3jFiep_kFT1qg
Udemy
Applied Logic (Level 2)
This course will give an intermediate-level student the experience necessary to originate complex, logical solutions.
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
π¦#DefinitionS HACKING TERMS
1οΈβ£SOCIAL WORKERS VULNERABILITY :
When you specifically Google:) /Baidu social worker, the answer is social work, we said that social workers would have nothing to do with this. Social workers are called social engineering, which is a technology that studies the weakness of human nature to attack. For instance the website administrator is called Xiao Ming.Then the administrator password of the website is likely to be xiaoming, or even xiaohong, why is it with Xiaohong? Because it may be the person Xiao Ming likes, of course, it may also have xiaofeng, but the probability is very low, at least much lower than the previous two. Social work attacks are usually attacked with this idea. To put it simply, you can also understand it as human flesh, and some of the materials that are extracted from human flesh on the Internet all use social engineering technology. Xiaofeng gives a simple example. For example, if you are looking for the qq number of a star, you can search for the name of his company in the qq group. The xx company group may appear, and then you know how to find the qq number.
2οΈβ£WebShell
WebShell is a command environment that exists in the form of asp, php, jsp and other web files, and it can also be called a web page backdoor. After a hacker has invaded a website, these asp or php backdoor files are usually mixed with the normal web page files in the WEB directory of the website server, and they are usually hidden deeper because they cannot be found by the administrator and cannot be accessed after being deleted. Take control. A website is hung with a webshell backdoor, basically you can do whatever you want, you can modify any part of the website or delete it. The web transactions between hackers are carried out through webshell. For example, how much do I spend to buy webshell permissions for this website, and the attacker is responsible for finding a way to put a webshell backdoor in this website, so that everyone should understand.
ENJOY π¦ππ»
written by Undercode
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
π¦#DefinitionS HACKING TERMS
1οΈβ£SOCIAL WORKERS VULNERABILITY :
When you specifically Google:) /Baidu social worker, the answer is social work, we said that social workers would have nothing to do with this. Social workers are called social engineering, which is a technology that studies the weakness of human nature to attack. For instance the website administrator is called Xiao Ming.Then the administrator password of the website is likely to be xiaoming, or even xiaohong, why is it with Xiaohong? Because it may be the person Xiao Ming likes, of course, it may also have xiaofeng, but the probability is very low, at least much lower than the previous two. Social work attacks are usually attacked with this idea. To put it simply, you can also understand it as human flesh, and some of the materials that are extracted from human flesh on the Internet all use social engineering technology. Xiaofeng gives a simple example. For example, if you are looking for the qq number of a star, you can search for the name of his company in the qq group. The xx company group may appear, and then you know how to find the qq number.
2οΈβ£WebShell
WebShell is a command environment that exists in the form of asp, php, jsp and other web files, and it can also be called a web page backdoor. After a hacker has invaded a website, these asp or php backdoor files are usually mixed with the normal web page files in the WEB directory of the website server, and they are usually hidden deeper because they cannot be found by the administrator and cannot be accessed after being deleted. Take control. A website is hung with a webshell backdoor, basically you can do whatever you want, you can modify any part of the website or delete it. The web transactions between hackers are carried out through webshell. For example, how much do I spend to buy webshell permissions for this website, and the attacker is responsible for finding a way to put a webshell backdoor in this website, so that everyone should understand.
ENJOY π¦ππ»
written by Undercode
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
π¦A REAL extremely buggy web app 2020 RECOMMENDED BY Undercode :
FEATURES :
SQL, HTML, iFrame, SSI, OS Command, PHP, XML, XPath, LDAP and SMTP injections
Blind SQL injection and Blind OS Command injection
Boolean-based and time-based Blind SQL injections
Drupageddon and Drupalgeddon2 (CVE-2018-7600)
AJAX and Web Services issues (JSON/XML/SOAP)
Heartbleed vulnerability (OpenSSL) + detection script included
Shellshock vulnerability (CGI)
Cross-Site Scripting (XSS) and Cross-Site Tracing (XST)
phpMyAdmin BBCode Tag XSS
Cross-Site Request Forgery (CSRF)
Information disclosures: favicons, version info, custom headers,...
Unrestricted file uploads and backdoor files
Old, backup & unreferenced files
Authentication, authorization and session management issues
Password and CAPTCHA attacks
Insecure DistCC, FTP, NTP, Samba, SNMP, VNC, WebDAV configurations
Arbitrary file access with Samba
Directory traversals and unrestricted file access
Local and remote file inclusions (LFI/RFI)
Server Side Request Forgery (SSRF)
XML External Entity attacks (XXE)
Man-in-the-Middle attacks (HTTP/SMTP)
HTTP parameter pollution and HTTP verb tampering
Denial-of-Service (DoS) attacks: Slow Post, SSL-Exhaustion, XML Bomb,...
POODLE vulnerability
BREACH/CRIME/BEAST SSL attacks
HTML5 ClickJacking and web storage issues
Insecure iFrame (HTML5 sandboxing)
Insecure cryptographic storage
Cross-Origin Resource Sharing (CORS) issues
Cross-domain policy file attacks (Flash/Silverlight)
Local privilege escalations: udev, sendpage
Cookie and password reset poisoning
Host header attacks: password reset poisoning en cache pollutions
PHP CGI remote code execution
Dangerous PHP Eval function
Local and remote buffer overflows (BOF)
phpMyAdmin and SQLiteManager vulnerabilities
Nginx web server vulnerabilities
HTTP response splitting, unvalidated redirects and forwards
WSDL SOAP vulnerabilities
Form-based authentication and No-authentication modes
Active Directory LDAP integration
Fuzzing possibilities
and much more...
HINT: download our bee-box VM > it has ALL necessary extensions
bee-box is compatible with VMware and VirtualBox!
πΈπ½π π π°π»π»πΈπ π°π πΈπΎπ½ :
DOWNLOAD APP :
https://sourceforge.net/projects/bwapp/
ENJOY π¦ππ»
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
π¦A REAL extremely buggy web app 2020 RECOMMENDED BY Undercode :
FEATURES :
SQL, HTML, iFrame, SSI, OS Command, PHP, XML, XPath, LDAP and SMTP injections
Blind SQL injection and Blind OS Command injection
Boolean-based and time-based Blind SQL injections
Drupageddon and Drupalgeddon2 (CVE-2018-7600)
AJAX and Web Services issues (JSON/XML/SOAP)
Heartbleed vulnerability (OpenSSL) + detection script included
Shellshock vulnerability (CGI)
Cross-Site Scripting (XSS) and Cross-Site Tracing (XST)
phpMyAdmin BBCode Tag XSS
Cross-Site Request Forgery (CSRF)
Information disclosures: favicons, version info, custom headers,...
Unrestricted file uploads and backdoor files
Old, backup & unreferenced files
Authentication, authorization and session management issues
Password and CAPTCHA attacks
Insecure DistCC, FTP, NTP, Samba, SNMP, VNC, WebDAV configurations
Arbitrary file access with Samba
Directory traversals and unrestricted file access
Local and remote file inclusions (LFI/RFI)
Server Side Request Forgery (SSRF)
XML External Entity attacks (XXE)
Man-in-the-Middle attacks (HTTP/SMTP)
HTTP parameter pollution and HTTP verb tampering
Denial-of-Service (DoS) attacks: Slow Post, SSL-Exhaustion, XML Bomb,...
POODLE vulnerability
BREACH/CRIME/BEAST SSL attacks
HTML5 ClickJacking and web storage issues
Insecure iFrame (HTML5 sandboxing)
Insecure cryptographic storage
Cross-Origin Resource Sharing (CORS) issues
Cross-domain policy file attacks (Flash/Silverlight)
Local privilege escalations: udev, sendpage
Cookie and password reset poisoning
Host header attacks: password reset poisoning en cache pollutions
PHP CGI remote code execution
Dangerous PHP Eval function
Local and remote buffer overflows (BOF)
phpMyAdmin and SQLiteManager vulnerabilities
Nginx web server vulnerabilities
HTTP response splitting, unvalidated redirects and forwards
WSDL SOAP vulnerabilities
Form-based authentication and No-authentication modes
Active Directory LDAP integration
Fuzzing possibilities
and much more...
HINT: download our bee-box VM > it has ALL necessary extensions
bee-box is compatible with VMware and VirtualBox!
πΈπ½π π π°π»π»πΈπ π°π πΈπΎπ½ :
DOWNLOAD APP :
https://sourceforge.net/projects/bwapp/
ENJOY π¦ππ»
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
SourceForge
bWAPP
Download bWAPP for free. an extremely buggy web app ! bWAPP, or a buggy web application, is a free and open source deliberately insecure web application. bWAPP helps security enthusiasts, developers and students to discover and to prevent web vulnerabilities.