Forwarded from โคอออ๐๐๐๐ ๐๐๐๐
๐ข ASH Tunnel :
VPS installer :
ููุฏู ููู ุงูุชุญุฏูุซ ุงูุฌุฏูุฏ ุงูุฎุงุต ุจุจุฑููุณู ASH HTTP ุงูู ูุฌูุฏ ูู ุณูุฑูุจุช ุงูinstaller ุงูุฑุณู ู ุงูุฎุงุต ุจูุง.
ููุฏ ุชู ุชุบููุฑู ู ู ุจุฑูุชููู HTTP ุฅูู HTTP + WS ุญูุซ ูุนู ูุงู ูู ููุณ ุงูููุช ูููุณ ุงูู ูุงูุฐุ ูููุชูุฌุฉุ ุชู ูุฒุน ุจุฑูุชูููู WS ุงูุฐู ูุนู ู ุจุดูู ู ููุตู
ููู ูู ูููู ุงูุชุบููุฑ ุจูู ููุง ู ู ูุฐูู ุงูุจุฑูุชูููููู ุนูุฏู ุง ุฃุฑูุฏ ูุงุญุฏุง ูููู ุ
- ุงูุฃู ุฑ ุณููุ ุฅุฐุง ููุช ุชุฑูุฏ ุงุณุชุนู ุงู ุจุฑูุชูููู ุงูWSุ ุฃุนูู ุนู 'Upgrade: websocket' ุฏุงุฎู ุงูุจุงูููุฏ ุงูุฎุงุต ุจูุ ุฅุฐุง ููุช ุชุฑูุฏ ุงุณุชุนู ุงู ุจุฑูุชูููู ุงูHTTPุ ููุง ุชุนูู ุนููุง ูู ุงูุจุงูููุฏ ุงูุฎุงุต ุจู
ุจุงูููุฏ header ุฌุฏูุฏ : [sameresponse]
ู ุง ูุงุฆุฏุฉ ูุฐู ุงูู ูุฒุฉ ุงูุฌุฏูุฏุฉ ุ
- ุชููู ุจุงูุญุตูู ุนูู ุงูุฅุณุชุฌุงุจุฉ ุงูุฎุงุตุฉ ุจุงูููุณุช ุงูู ูุฌูุฏ ุฏุงุฎู ุงูุจุงูููุฏ ุงูุฎุงุต ูุชููู ุจุฅุฑุฌุงุนู ููclient ุงูุฎุงุต ุจู
ููู ุฃุณุชุนู ููุง ุ
- ูุฌุจ ุฃู ุชุนูููุง ุชู ุงู ุง ูู ุงูุฌุงูุจ ุงูุฃูุณุฑ ู ู ุงูheader ุงูุฎุงุต ุจุงู'Host'
ู ุซุงู :
ูุจู :
GET /cdn-cgi/trace HTTP/1.1[crlf]Host: www.google.com[crlf][crlf]
ุจุนุฏ :
GET /cdn-cgi/trace HTTP/1.1[crlf][sameresponse]Host: www.google.com[crlf][crlf]
โ ู ูุงุญุธุฉ :
ุฅุฐุง ุชู ุงูุฅุนูุงู ุนู [sameresponse] ููู ุงูheader ุงูุฎุงุต ุจุงู'host' ููุณ ู ูุฌูุฏุงุ ูุณูุชู ุชุฌุงูุฒ ู ูุฒุฉ ุงู[sameresponse] ูุณุชุนุทู ุงูุฅุฌุงุจุฉ ุงูุฅูุชุฑุงุถูุฉ 200 OK
VPS installer :
ููุฏู ููู ุงูุชุญุฏูุซ ุงูุฌุฏูุฏ ุงูุฎุงุต ุจุจุฑููุณู ASH HTTP ุงูู ูุฌูุฏ ูู ุณูุฑูุจุช ุงูinstaller ุงูุฑุณู ู ุงูุฎุงุต ุจูุง.
ููุฏ ุชู ุชุบููุฑู ู ู ุจุฑูุชููู HTTP ุฅูู HTTP + WS ุญูุซ ูุนู ูุงู ูู ููุณ ุงูููุช ูููุณ ุงูู ูุงูุฐุ ูููุชูุฌุฉุ ุชู ูุฒุน ุจุฑูุชูููู WS ุงูุฐู ูุนู ู ุจุดูู ู ููุตู
ููู ูู ูููู ุงูุชุบููุฑ ุจูู ููุง ู ู ูุฐูู ุงูุจุฑูุชูููููู ุนูุฏู ุง ุฃุฑูุฏ ูุงุญุฏุง ูููู ุ
- ุงูุฃู ุฑ ุณููุ ุฅุฐุง ููุช ุชุฑูุฏ ุงุณุชุนู ุงู ุจุฑูุชูููู ุงูWSุ ุฃุนูู ุนู 'Upgrade: websocket' ุฏุงุฎู ุงูุจุงูููุฏ ุงูุฎุงุต ุจูุ ุฅุฐุง ููุช ุชุฑูุฏ ุงุณุชุนู ุงู ุจุฑูุชูููู ุงูHTTPุ ููุง ุชุนูู ุนููุง ูู ุงูุจุงูููุฏ ุงูุฎุงุต ุจู
ุจุงูููุฏ header ุฌุฏูุฏ : [sameresponse]
ู ุง ูุงุฆุฏุฉ ูุฐู ุงูู ูุฒุฉ ุงูุฌุฏูุฏุฉ ุ
- ุชููู ุจุงูุญุตูู ุนูู ุงูุฅุณุชุฌุงุจุฉ ุงูุฎุงุตุฉ ุจุงูููุณุช ุงูู ูุฌูุฏ ุฏุงุฎู ุงูุจุงูููุฏ ุงูุฎุงุต ูุชููู ุจุฅุฑุฌุงุนู ููclient ุงูุฎุงุต ุจู
ููู ุฃุณุชุนู ููุง ุ
- ูุฌุจ ุฃู ุชุนูููุง ุชู ุงู ุง ูู ุงูุฌุงูุจ ุงูุฃูุณุฑ ู ู ุงูheader ุงูุฎุงุต ุจุงู'Host'
ู ุซุงู :
ูุจู :
GET /cdn-cgi/trace HTTP/1.1[crlf]Host: www.google.com[crlf][crlf]
ุจุนุฏ :
GET /cdn-cgi/trace HTTP/1.1[crlf][sameresponse]Host: www.google.com[crlf][crlf]
โ ู ูุงุญุธุฉ :
ุฅุฐุง ุชู ุงูุฅุนูุงู ุนู [sameresponse] ููู ุงูheader ุงูุฎุงุต ุจุงู'host' ููุณ ู ูุฌูุฏุงุ ูุณูุชู ุชุฌุงูุฒ ู ูุฒุฉ ุงู[sameresponse] ูุณุชุนุทู ุงูุฅุฌุงุจุฉ ุงูุฅูุชุฑุงุถูุฉ 200 OK
GitHub
GitHub - ASHANTENNA/VPNScript: Bash script installer of specific protocols for ASH Tunnel application : UDP, HTTP, SSL, WS, DNSTTโฆ
Bash script installer of specific protocols for ASH Tunnel application : UDP, HTTP, SSL, WS, DNSTT, DoH, DoT, DNS2TCP, BadVPN UDPGW - ASHANTENNA/VPNScript
Forwarded from โคอออ๐๐๐๐ ๐๐๐๐
Example 1 :
Both HTTP and WS have the same port, and both are working properly, the trigger between both of them is 'Upgrade: websocket'
Both HTTP and WS have the same port, and both are working properly, the trigger between both of them is 'Upgrade: websocket'
Forwarded from โคอออ๐๐๐๐ ๐๐๐๐
Example 2 : [sameresponse] feature
โค2
โค20๐12๐11๐ฅ9
โค13๐6๐ฏ3๐1
๐ This isnโt a joke. xdtools messed with the wrong person.
Some of you are asking: "Whatโs going on?"
Let me break it down real simple:
A certain app called xdtools thought it was invincible.
Their dev leaked sensitive configs from other apps just to look cool.
He mocked people. Acted like nobody could touch him.
I gave him a chance to stop.
I offered peace.
He laughed.
So I accessed xdtools from the inside.
I now have:
โ Full source code
โ All project settings
โ His VIP system logic
โ API keys
โ Build files
โ Databases
He panicked and shut the app down.
Tried to play it off like โheโs done with it.โ Cute.
No โ heโs just done. Period.
#ZTvsXdtools #KnowYourPlace #xdexposed
Some of you are asking: "Whatโs going on?"
Let me break it down real simple:
A certain app called xdtools thought it was invincible.
Their dev leaked sensitive configs from other apps just to look cool.
He mocked people. Acted like nobody could touch him.
I gave him a chance to stop.
I offered peace.
He laughed.
So I accessed xdtools from the inside.
I now have:
โ Full source code
โ All project settings
โ His VIP system logic
โ API keys
โ Build files
โ Databases
He panicked and shut the app down.
Tried to play it off like โheโs done with it.โ Cute.
No โ heโs just done. Period.
Welcome to the show๐ฝโ
#ZTvsXdtools #KnowYourPlace #xdexposed
โค5๐ฅ2๐ค2
xdtools.txt
1.6 MB
You kept talking like your project was some high-security fortress.
Turns outโฆ it was more like a broken tent.
Today, Iโm dropping the first piece of proof.
Nothing too damaging just enough to make you sweat.
โ Internal file structure
โ Partial project logic
โ Real evidence of access
โ Still not even 10% of what I have
I wonโt drop everything at once.
Why?
Because I want you and everyone watching to understand just how fragile your entire build was.
More coming.
Only louder.
#ZeroTrace
Turns outโฆ it was more like a broken tent.
Today, Iโm dropping the first piece of proof.
Nothing too damaging just enough to make you sweat.
โ Internal file structure
โ Partial project logic
โ Real evidence of access
โ Still not even 10% of what I have
I wonโt drop everything at once.
Why?
Because I want you and everyone watching to understand just how fragile your entire build was.
More coming.
Only louder.
#ZeroTrace
โ2โค1
Forwarded from 33 T.P.S
Screenshot_20250713-121827.png
6.6 KB
Keep laughing ๐