Forwarded from C.I.T. Security
Софт, статьи, книги, базы данных и многое другое. Воруем все самое интересное с просторов телеграма и форумов.
🤵Информационные войны и разведка: @cit_psyop
🧑🎓Курсы: @cit_course
🕵️Боты: @citsearch3_bot
@citsearch2bot
🤵Информационные войны и разведка: @cit_psyop
🧑🎓Курсы: @cit_course
🕵️Боты: @citsearch3_bot
@citsearch2bot
❤3
Ghostint Tracker — приложение для веб-расследований и картографии OSINT нового поколения. Чтобы централизовать, визуализировать и обогатить ваши запросы, она объединит динамические графические связи (React Flow), синхронную мировую картографию (React-Leaflet) и искусственный гибрид двойного интеллекта (Locale & Avancee).
https://tracker.prohacking77.me/
https://github.com/jollncoelho/Zhetikal_OSINT_tracker
https://www.youtube.com/watch?v=mQl5btUpOwc
📱 Telegram | 🌐 ВК | 📲 MAX
📲 RUTUBE | 🌍 VK Видео
https://tracker.prohacking77.me/
https://github.com/jollncoelho/Zhetikal_OSINT_tracker
https://www.youtube.com/watch?v=mQl5btUpOwc
Please open Telegram to view this post
VIEW IN TELEGRAM
❤2
OSINT Browser Extensions — это справочный список полезных плагинов и расширений для веб-браузеров, предназначенный для специалистов по разведке по открытым источникам и аналитиков информационной безопасности.
— В репозитории собраны утилиты, систематизированные по категориям (поиск по изображениям, анализ социальных сетей, извлечение метаданных, работа с веб-архивами и анализ сетевых заголовков), которые помогают упростить и ускорить сбор цифровых следов непосредственно в процессе веб-серфинга.
#OSINT #Browser #Extensions #Recon #Investigation #Awesome | Лаборатория хакера
Please open Telegram to view this post
VIEW IN TELEGRAM
❤2
Большая коллекция OSINT ресурсов (подборки инструментов, сайты с тасками, новостные каналы и блоги, книги, OSINT сообщества и прочее)
https://start.me/p/DPYPMz/the-ultimate-osint-collection
https://start.me/p/DPYPMz/the-ultimate-osint-collection
Start.me
The Ultimate OSINT Collection - Start.me
A collection of the very best OSINT related materials, resources, trainings, guides, sites, tool collections, and more.
❤2
OSINT BOOKS
Github repo with list of books about Open Source Intelligence, investigations techniques, online privacy etc
https://github.com/ubikron/OSINT-Books
Github repo with list of books about Open Source Intelligence, investigations techniques, online privacy etc
https://github.com/ubikron/OSINT-Books
❤2
OSINT WORLD MAP
Together with @Adk, we created OSINT WORLD MAP — a curated collection of links to OSINT tools, websites, and projects, organized by geographic location. It includes:
• 193 UN member states
• Dependent territories
• Special administrative regions
• Partially recognized states and disputed territories
• Other regions
👉 https://map.wddadk.com
Just select or search for the country you need — and that’s it. All relevant OSINT tools and resources are listed right in front of you. If you have new links make PR here https://github.com/wddadk/OSINT-for-countries
Together with @Adk, we created OSINT WORLD MAP — a curated collection of links to OSINT tools, websites, and projects, organized by geographic location. It includes:
• 193 UN member states
• Dependent territories
• Special administrative regions
• Partially recognized states and disputed territories
• Other regions
Just select or search for the country you need — and that’s it. All relevant OSINT tools and resources are listed right in front of you. If you have new links make PR here https://github.com/wddadk/OSINT-for-countries
Please open Telegram to view this post
VIEW IN TELEGRAM
❤3
Выпустил свой легковесный инструмент для визуального анализа связей и построения карт расследований прямо в браузере — без установки, без серверов, без регистрации.
Nexus сделан с упором на лёгкость и приватность. Скачал, открыл в браузере и сразу можно строить связи. Результат сохраняется в один файл, который лежит у вас на компьютере. Его можно в любой момент снова открыть в приложении и продолжить с того места, где остановились. Также доска расследований сохраняется каждые тридцать секунд в кэше браузера, поэтому, если вы закрыли вкладку, то можете снова открыть и продолжить работу. Готовый файл также можно передать другому человеку, у которого есть этот же инструмент.
Что умеет:
-
-
-
-
-
Быстрый старт:
1. Скачиваете файл и открываете в браузере.
2. Кликаете правой кнопкой мыши по пустому холсту и выбираете нужный объект.
3. Кликаете по объекту левой кнопкой мыши, открывается боковая панель. Там можно редактировать свойства объекта, добавлять информацию, менять цвет, загружать изображение, менять тип объекта и иконку.
4. Когда на холсте есть два объекта, их можно соединить связью, перетащив её от одного объекта к другому. Если начать тянуть связь и кликнуть на пустое место холста, откроется панель выбора объекта, и новый объект сразу будет связан со старым. Связи можно настраивать: менять цвет, форму, добавлять название и так далее.
5. При необходимости можно добавлять текст и фигуры.
Nexus будет обновляться по мере необходимости.
Please open Telegram to view this post
VIEW IN TELEGRAM
❤2
Netryx Astra V2
Опенсорсная геолокация street-level фото - определяет координаты по одному снимку. Матчит не против картинок из интернета, как реверс-поиск, а против базы street-view панорам, поэтому отрабатывает даже на безымянном перекрёстке. В демо автора хватило мелкого кропа здания без метаданных, чтобы сузить поиск до километрового радиуса.
Пайплайн на MegaLoc (CVPR 2025) и MASt3R, крутится локально, нужен GPU и ~2 ГБ диска на город. Индексация города занимает часы, поэтому сделали обмен готовыми индексами - один прогнал город, остальные скачали за минуты. Есть облако netryx.live без установки, но на 30% менее точное.
➡️ https://github.com/sparkyniner/Netryx-Astra-V2-Geolocation-Tool
#osint #geoint #geolocation #tools #ai
📱 Offensive OSINT
Опенсорсная геолокация street-level фото - определяет координаты по одному снимку. Матчит не против картинок из интернета, как реверс-поиск, а против базы street-view панорам, поэтому отрабатывает даже на безымянном перекрёстке. В демо автора хватило мелкого кропа здания без метаданных, чтобы сузить поиск до километрового радиуса.
Пайплайн на MegaLoc (CVPR 2025) и MASt3R, крутится локально, нужен GPU и ~2 ГБ диска на город. Индексация города занимает часы, поэтому сделали обмен готовыми индексами - один прогнал город, остальные скачали за минуты. Есть облако netryx.live без установки, но на 30% менее точное.
#osint #geoint #geolocation #tools #ai
Please open Telegram to view this post
VIEW IN TELEGRAM
❤5👍1
AmnesiaStealer: a multi-stage Rust-based macOS infostealer that hijacks Chromium browsers
The landing page at https://github.aoitour.com reproduces GitHub's dark theme, the Octocat mark and a "Verified Publisher" badge next to a "Download for macOS" heading. Rather than offering a download, it presents a "Terminal installation" box framed as a convenience for advanced users, with a one-click Copy button and numbered instructions to open Terminal through Spotlight, paste, press Return and, at step three, "Enter your device password and confirm the installation." The same counterfeit GitHub page has also been observed in Atomic (AMOS) and MacSync stealer campaigns, so the lure template is shared across families rather than unique to AmnesiaStealer.
https://www.jamf.com/blog/amnesia-stealer-macos-infostealer-clickfix/
The landing page at https://github.aoitour.com reproduces GitHub's dark theme, the Octocat mark and a "Verified Publisher" badge next to a "Download for macOS" heading. Rather than offering a download, it presents a "Terminal installation" box framed as a convenience for advanced users, with a one-click Copy button and numbered instructions to open Terminal through Spotlight, paste, press Return and, at step three, "Enter your device password and confirm the installation." The same counterfeit GitHub page has also been observed in Atomic (AMOS) and MacSync stealer campaigns, so the lure template is shared across families rather than unique to AmnesiaStealer.
https://www.jamf.com/blog/amnesia-stealer-macos-infostealer-clickfix/
❤1
C.I.T. Security
AmnesiaStealer: a multi-stage Rust-based macOS infostealer that hijacks Chromium browsers The landing page at https://github.aoitour.com reproduces GitHub's dark theme, the Octocat mark and a "Verified Publisher" badge next to a "Download for macOS" heading.…
macos-hybrid-stealer~.x64.bndb
31.8 MB
I made a binaryninja database for that, you can explore it
❤2👍1
https://t.me/Phone_Number_To_FB_BOT
A simple Telegram bot to search whether a phone number or email is connected to social media accounts.
10 free requests every 8 hours.
#OSINT #Phone #Email
A simple Telegram bot to search whether a phone number or email is connected to social media accounts.
10 free requests every 8 hours.
#OSINT #Phone #Email
❤2
Telegram Bots for OSINT
@Phone_Number_To_FB_BOT - Phone number lookup bot for linked Facebook profiles and related search results.
@X4188RQ_bot - Russian Bot to search Social Profiles
https://telegram.me/J0283KT_bot?start=ref1952774532 - Russian data search bot to search phone number, full name, email, TIN, VIN, SSN, VKontakte, Insta, Facebook and OK
https://t.me/V775NY_bot?start=BMYkO-o - Same bot as above in english language
@K970MB_bot - Search name, photo, phone, email, inn, passport, snils, plate number, vin, telegram ID, username, tg comment
@b412_4_bot - Telescan is a service for finding people within Telegram. We collect historical data: groups, messages within them, and username change history.
https://t.me/unamer_tg_profiles_bot - Search Telegram Usernames with history
@M5398JG_bot - 10 free requests per day for GRAM addresses, dns names, telegram id, usernames, anonymous numbers, exchange ids, ETH addresses, token names
@Z3390HT_bot - Check Telegram username, user id, contact, sticker, link, forwarded messages, etc.
@V965HT_bot - Another TG checker bot, currently offline
https://t.me/B7710GD_bot?start=ref_4hOVcgkRrpj - Bot to search messages by user id, username, link or forwarded messages
https://t.me/SocialMediaLeaksBOT?start=BMYkO-o - Social Media Bot to search full name, username, ip, email, etc. in leaks. Once subscribed, you can search and see results uncensored
@Phone_Number_To_FB_BOT - Phone number lookup bot for linked Facebook profiles and related search results.
@X4188RQ_bot - Russian Bot to search Social Profiles
https://telegram.me/J0283KT_bot?start=ref1952774532 - Russian data search bot to search phone number, full name, email, TIN, VIN, SSN, VKontakte, Insta, Facebook and OK
https://t.me/V775NY_bot?start=BMYkO-o - Same bot as above in english language
@K970MB_bot - Search name, photo, phone, email, inn, passport, snils, plate number, vin, telegram ID, username, tg comment
@b412_4_bot - Telescan is a service for finding people within Telegram. We collect historical data: groups, messages within them, and username change history.
https://t.me/unamer_tg_profiles_bot - Search Telegram Usernames with history
@M5398JG_bot - 10 free requests per day for GRAM addresses, dns names, telegram id, usernames, anonymous numbers, exchange ids, ETH addresses, token names
@Z3390HT_bot - Check Telegram username, user id, contact, sticker, link, forwarded messages, etc.
@V965HT_bot - Another TG checker bot, currently offline
https://t.me/B7710GD_bot?start=ref_4hOVcgkRrpj - Bot to search messages by user id, username, link or forwarded messages
https://t.me/SocialMediaLeaksBOT?start=BMYkO-o - Social Media Bot to search full name, username, ip, email, etc. in leaks. Once subscribed, you can search and see results uncensored
Telegram
Unamer
Telegram profiles history search.
https://t.me/unamer_news
https://t.me/unamer_news
❤2
Tutorials - blacksun.box.sk.zip
1.5 MB
Black Sun Research Facility (BSRF) - The Legendary Hacker Archive
🔮 What Is This?
This is an archive from Black Sun Research Facility (BSRF) , one of the most legendary hacker/cybersecurity knowledge repositories from the late 1990s and early 2000s. It's a massive collection of tutorials, lectures, and tools covering programming, networking, cryptography, and hacking techniques from the golden age of internet underground culture.
📅 Brief History
Late 1990s: Black Sun (blacksun.box.sk) emerges as a premier hacker resource
1999-2004: Peak popularity - thousands of tutorials, active community
2004: The original site goes offline, but mirrors preserve the content
2020s: The archive survives as a "digital time capsule" of early hacker culture
📂 What's Inside the Archive
The archive contains over 100+ files organized into these categories
Important Disclaimer: This content is OBSOLETE - but the educational value is a historical artifact of the early cybersecurity culture.
Black Sun was one of the first big hacker knowledge bases on the internet. This archive is a piece of history, not a practical guide. Use it to understand where cybersecurity culture came from—not to break into networks today.
Online: https://marado.github.io/mirror-blacksun.box.sk/blacksun.box.sk/
This is an archive from Black Sun Research Facility (BSRF) , one of the most legendary hacker/cybersecurity knowledge repositories from the late 1990s and early 2000s. It's a massive collection of tutorials, lectures, and tools covering programming, networking, cryptography, and hacking techniques from the golden age of internet underground culture.
Late 1990s: Black Sun (blacksun.box.sk) emerges as a premier hacker resource
1999-2004: Peak popularity - thousands of tutorials, active community
2004: The original site goes offline, but mirrors preserve the content
2020s: The archive survives as a "digital time capsule" of early hacker culture
The archive contains over 100+ files organized into these categories
📁 coding/ → C++, Perl, Python, PHP, HTML, Assembly tutorials
📁 encrypt/ → Cryptography (RSA, PGP, SSL, DES, Quantum)
📁 hardware/ → PC building, overclocking, memory guides
📁 history/ → Hacker culture and historical documents
📁 humor/ → Hacker jokes and flame wars
📁 irc/ → IRC bots, eggdrops, IRC wars
📁 lecture/ → Educational lectures on hacking and programming
📁 net/ → Network hacking, DoS, trojans, proxies
📁 novell/ → Novell NetWare hacking (obsolete now!)
📁 tools/ → Password crackers and utilities
📁 unix/ → Linux/Unix security and shell scripting
📁 win/ → Windows registry, debug, and system tricks
Important Disclaimer: This content is OBSOLETE - but the educational value is a historical artifact of the early cybersecurity culture.
Black Sun was one of the first big hacker knowledge bases on the internet. This archive is a piece of history, not a practical guide. Use it to understand where cybersecurity culture came from—not to break into networks today.
Online: https://marado.github.io/mirror-blacksun.box.sk/blacksun.box.sk/
"Black Sun was the Google of hacking before Google existed."
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥5❤2
Forwarded from быдло.jazz
Олдскул или модерн? v4 vs. v6?
Годы доверия к классике или активная разработка современного инструмента?
Не скринах PGPony, софт и криптоядро идут отдельными репо. Под iOS тоже есть вариант, но мне не интересно.
Собственно, знакомьтесь - современная альтернатива всеми любимому OpenKeychain, а если не знаете что это, то, скорее всего, вы лютый терминальный красноглаз или, что более вероятно, не используете OpenPGP на Android и "шифрование" для вас - это просто какое-то слово на букву "ша". Для вас распишу подробнее.
Шифрование/подпись/расшифровка - три базовые операции PGP:
шифрование - превращает текст/файл в нечитаемый блок, открыть который сможет только получатель своим приватным ключом
подпись - к сообщению прикрепляется криптографическую "печать", получатель убеждается, что писал именно Jazz и текст не подменили
расшифровка - обратная операция, вашим приватным ключом открывается то, что зашифровали конкретно для вас, и заодно проверяется чужая подпись.
В чем отличия, плюсы и минусы по сравнению с OpenKeychain?
Лошадка поддерживает v4 и v6 - два поколения формата OpenPGP. OK - только v4.
Лошадка может в HW-ключи по NFC (YubiKey 5, Token2) - вместо того чтобы держать приватный ключ в памяти телефона, он хранится на физической железке (смарткарта/токен). Чтобы что-то подписать или расшифровать, достаточно приложить её к телефону через NFC и ввести PIN. Ключ никогда не покидает карту, даже если телефон скомпрометирован, вытащить ключ нельзя. Генерация ключа прямо на карте, новый приватный ключ рождается внутри токена и физически никогда не существует на телефоне. На телефоне только софт для управления (удалить, сменить пин и тд.).
Чего нет в PGPony? Системный OpenPGP API. То есть нативный бэкенд для почты типа K-9/Thunderbird, связка с XMPP-клиентом и все за что сообщество ценит OpenKeychain - хрен вам. Но, возможно и хотелось бы - добавится.
Вывод: PGPony даёт более современный формат (v6) с лучшей целостностью и защитой паролем, но реализуется это преимущество только когда обе стороны на v6. Базовая криптография одинаковая.
Возвращаясь к началу, что же выбрать? Это, на данный момент, концептуально отличающиеся инструменты. Один может дополнить другой или решать совершенно разные задачи, связанные с шифрованием. Но без подобных инструментов никаких разговоров о приватности и безопасности не может быть по определению.
Годы доверия к классике или активная разработка современного инструмента?
Не скринах PGPony, софт и криптоядро идут отдельными репо. Под iOS тоже есть вариант, но мне не интересно.
Собственно, знакомьтесь - современная альтернатива всеми любимому OpenKeychain, а если не знаете что это, то, скорее всего, вы лютый терминальный красноглаз или, что более вероятно, не используете OpenPGP на Android и "шифрование" для вас - это просто какое-то слово на букву "ша". Для вас распишу подробнее.
Шифрование/подпись/расшифровка - три базовые операции PGP:
шифрование - превращает текст/файл в нечитаемый блок, открыть который сможет только получатель своим приватным ключом
подпись - к сообщению прикрепляется криптографическую "печать", получатель убеждается, что писал именно Jazz и текст не подменили
расшифровка - обратная операция, вашим приватным ключом открывается то, что зашифровали конкретно для вас, и заодно проверяется чужая подпись.
В чем отличия, плюсы и минусы по сравнению с OpenKeychain?
Лошадка поддерживает v4 и v6 - два поколения формата OpenPGP. OK - только v4.
Лошадка может в HW-ключи по NFC (YubiKey 5, Token2) - вместо того чтобы держать приватный ключ в памяти телефона, он хранится на физической железке (смарткарта/токен). Чтобы что-то подписать или расшифровать, достаточно приложить её к телефону через NFC и ввести PIN. Ключ никогда не покидает карту, даже если телефон скомпрометирован, вытащить ключ нельзя. Генерация ключа прямо на карте, новый приватный ключ рождается внутри токена и физически никогда не существует на телефоне. На телефоне только софт для управления (удалить, сменить пин и тд.).
Чего нет в PGPony? Системный OpenPGP API. То есть нативный бэкенд для почты типа K-9/Thunderbird, связка с XMPP-клиентом и все за что сообщество ценит OpenKeychain - хрен вам. Но, возможно и хотелось бы - добавится.
Вывод: PGPony даёт более современный формат (v6) с лучшей целостностью и защитой паролем, но реализуется это преимущество только когда обе стороны на v6. Базовая криптография одинаковая.
Возвращаясь к началу, что же выбрать? Это, на данный момент, концептуально отличающиеся инструменты. Один может дополнить другой или решать совершенно разные задачи, связанные с шифрованием. Но без подобных инструментов никаких разговоров о приватности и безопасности не может быть по определению.
🔥2❤1