Github tools
2.74K subscribers
33 photos
2 videos
58 files
361 links
Github useful scripts and tools
Download Telegram

Brute-force Instagram accounts

Pure-L0G1C is a handy utility for carrying out a password brute-force attack on IS accounts.
The work of the program is organized through a proxy, in order to ensure anonymity.
If successful, it creates an account.txt file in the folder that contains all the data found.

Installation:

• apt update && apt upgrade - y
• apt install python python-pip git
• git clone https://github.com/Pure-L0G1C/Instagram
cd Pure-L0G1C

Launch:

• python3 instagram.py <login> <wordli
st> <mode>

<login> victim login
<wordlist> file with passwords, it can be found on the Internet
<mode> brute force mode:
-m a number, which can be 0, 1, 2, or 3. The default is zero.

Modes
0 - 64 passwords at a time
1 - 128 passwords at a time
2 - 256 passwords at a time
3 - 51
2 passwords at a time
​Protection against DDoS attacks!

Good day! Today we will show you one very interesting project that is designed to protect against DOS and DDoS attacks. This project is called Anti-DDOS. In fact, it uses all the necessary protection configurations, but it only works on the Linux operating system.

Let's go!

1. To install, use:
git clone https://github.com/ismailtasdelen/Anti-DDOS.git
2. Use is carried out by entering the following commands:
cd Anti-DDOS
$ bash ./anti-ddos.sh

With Anti-DDOS, you can take the necessary steps to protect your servers and applications from this type of attack.

Useful software only for the smartest kids!💾‌‌

🔖 S.E. Note. The Book of Secret Knowledge.

🖖🏻 Hello user_name.

• Today I am sharing with you a very useful repo, which contains a huge amount of information for every taste. The information will be useful to all readers of our community and not only.

• Guides, tools, articles, various cheat sheets, blogs, life hacks and more: https://github.com/trimstray/the-book-of-secret-knowledge

📦 Ready-made VM images for quick deployment and experimentation.


🖖🏻 Hello user_name.

• Today I
have selected for you a list of repositories with ready-made images for VirtualBox and VMWare virtual machines. Very handy for quick deployment as test benches.

• Free VirtualBox Images from the developers of VirtualBox.
• A collection of p
rebuilt VMs from Oracle.
• Absolute
ly any VM configurations based on Linux and Open Sources.
• VMwar
e image with older versions of Windows (98, 2000, XP)

• VM o
n iOS and MacOS:
https://getutm.app
https://mac.getutm.app
Images:
https://mac.getutm.app/gallery/
https://github.com/utmapp/vm-downloads/releases

Your S.E.‌

✉️ Silence and SMS Ping. Find out the status of the subscriber and encrypt SMS messages.

This information can be important in certain circumstances.

🖖🏻 Hello user_name.

• Let's tak
e a little break from the #SI topic and talk about some useful #Android apps. Today we will talk about software, thanks to which you can stay in touch without the presence of the Internet and maintain the confidentiality of correspondence. In addition, we will talk about an interesting application that will allow you to find out the status of a subscriber.

• Let's start with the SMS Ping application: In simple words, thanks to this application you can send a silent SMS to any phone number and find out the status of the target (online / offline). The SMS message will not be displayed to the person who received the request, but you can determine whether your contact's phone is working or not.

• Application is open source: https://github.com/itds-consulting/android-silent-ping-sms
• You can download it here: https://f-droid.org/ru/packages/com.itds.sms.ping/

• Now let's talk about Silence: This is an application that allows you to easily encrypt SMS and local database, replaces the standard SMS application, uses the Signal encryption protocol and is open source. As already mentioned, the tool will help you stay in touch if there are problems with the Internet connection and will ensure the confidentiality of correspondence.

• Official site: https://silence.im/
• Source code: https://git.silence.dev/Silence/Silence-Android/
• Download here: https://f-droid.org/packages/org.smssecure.smssecure/

‼️ Do not forget about our selection of offline messengers, share this information with family and friends and stay in touch. Your S.E. #Android #Privacy‌‌
Exploit Pack Pro 15.07
#exploit‌‌


Exploit Pack Pro 15.07 (as instructed to use in VM)

#exploit‌‌
Burp Pro 2022.2 +
#soft #burp #web‌‌


Burp Pro 2022.2 + detailed installation instructions inside


#soft #burp #web‌‌
BurpBountyData.zip
205.5 KB
+ profiles for Burp Bounty‌‌
THE EVOLUTION OF EVIL CORP (2022).pdf
15.8 MB
EvilCorp

#malware #report‌‌


A cool analysis of the tools of the sensational group EvilCorp

#malware #report‌‌
Cylera Labs Kwampirs Shamoon Technical Report (2022).pdf
19 MB
This document details the tactics and tools of APT Orangeworm and Shamoon, as well as the connections between the groups.

#apt #malware #report‌‌
Delegating Kerberos to bypass Kerberos delegation limitation.



#ad #pentest #redteam #blueteam‌‌
Insomnihack 2022 - Delegating Kerberos.pdf
14.4 MB
Insomnihack 2022 - Delegating Kerberos.pdf

😵‍💫 Phishing. Browser within a browser.

No, today we will not
talk about a well-known meme, today we will talk about a new method of phishing attacks.

🖖🏻 Hello use
r_name.

• Back in 2020, Ragnar Locker (ransomware) was installed on the victim's PC using a virtual machine. Those. the locker dragged a full-fledged virtual machine to the attacked host, in which it was launched, then it got access to the host file system and encrypted the data. Perfect bypass of anti-virus protection, isn't it? By the way, Ragnar Locker was aimed at business. An example is the attack on the electricity supplier Energias de Portugal. Presumably, 10 terabytes of data were stolen from them, and the attackers demanded 1,580 bitcoins for decryption.

• But today we will talk about something else, although the direction and idea of ​​such attacks will be similar to the style described above. The essence of this method is to simulate a browser window in a browser, for example, to phish authentication data.

• Suppose that the victim goes to a certain resource, wants to log in using a Google/Microsoft/Apple account, clicks on the appropriate button, then a window with a login form appears, the victim looks at the address bar and checks the legitimacy of the resource, enters data and they are successfully sent to the attacker ...

• Thanks to the
magic of HTML, CSS and JavaScript, it is almost impossible to distinguish between a real and a phishing window (example), including the URL: https://mrd0x.com/browser-in-the-browser-phishing-attack/

• If you are interested in this method, then you can download various login forms (for different services) on GitHub, the repo includes various templates for Windows and Mac, and has several design options (dark and light mode). Will be useful for social engineers and Red Team: https://github.com/mrd0x/BITB

Your S.E. #SI #Phishing‌‌


Such posts are only posted in our github channel
2