Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
jsFinder is a command-line tool written in Go that scans web pages to find JavaScript files linked in the HTML source code. It searches for any attribute that can contain a JavaScript file (e.g., src, href, data-main, etc.) and extracts the URLs of the files to a text file. The tool is designed to be simple to use, and it supports reading URLs from a file or from standard input. jsFinder is useful for web developers and security professionals who want to find and analyze the JavaScript files used by a web application. By analyzing the JavaScript files, it's possible to understand the functionality of the application and detect any security vulnerabilities (https://www.kitploit.com/search/label/vulnerabilities) or sensitive information (https://www.kitploit.com/search/label/Sensitive%20Information) leakage.
Features Reading URLs from a file or from stdin using command line (https://www.kitploit.com/search/label/Command%20Line) arguments. Running multiple HTTP GET requests concurrently to each URL. Limiting the concurrency of HTTP GET requests using a flag. Using a regular expression to search for JavaScript files in the response body of the HTTP GET requests. Writing the found JavaScript files to a file specified in the command line arguments or to a default file named "output.txt". Printing informative messages to the console indicating the status of the program's execution and the output file's location. Allowing the program to run in verbose or silent mode using a flag. Installation jsfinder requires Go 1.20 to install successfully.Run the following command to get the repo : go install -v github.com/kacakb/jsfinder@latest Usage To see which flags you can use with the tool, use the -h flag. jsfinder -h Flag Description -l Specifies the filename to read URLs from. -c Specifies the maximum number of concurrent requests to be made. The default value is 20. -s Runs the program in silent mode. If this flag is not set, the program runs in verbose mode. -o Specifies the filename to write found URLs to. The default filename is output.txt. -read Reads URLs from stdin instead of a file specified by the -l flag. Demo I
If you want to read from stdin and run the program in silent mode, use this command: cat list.txt| jsfinder -read -s -o js.txt   II
If you want to read from a file, you should specify it with the -l flag and use this command: jsfinder -l list.txt -s -o js.txt You can also specify the concurrency with the -c flag.The default value is 20. If you want to read from a file, you should specify it with the -l flag and use this command: jsfinder -l list.txt -c 50 -s -o js.txt TODOs Adding new features Improving performance Adding a cookie (https://www.kitploit.com/search/label/Cookie) flag Reading regex from a file Integrating the kacak (https://github.com/kacakb/kacak) tool (coming soon) Screenshot
Contact If you have any questions, feedback or collaboration (https://www.kitploit.com/search/label/Collaboration) suggestions related to this project, please feel free to contact me via:e-mail (mailto:kacakbatuhan@protonmail.com)

Download Jsfinder (https://github.com/kacakb/jsfinder)
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Jsfinder - Fetches JavaScript Files Quickly And Comprehensively

https://blogger.googleusercontent.com/img/a/AVvXsEhSGc5-LtkIdVkddGFaiOoiTCJZ7t5S1ULN9qUNYxtiXQWIsL3WqGiN31HMpE2-H3YWBNXLgqJXIFniaxf_CmdBosXiw4WftmRYAp1j-MfL5KKkAzD0URMeywy5JW2zxf2qIc7oYkzWJ0gYahqCyNxI_eG5K31fYc7dYpdtj9883XGSOQi9EQnVg702Hg=w640-h640 jsFinder is a command-line tool written in Go that scans web pages to find JavaScript files linked in the HTML source code. It searches for any attribute that can contain a JavaScript file (e.g., src, href, data-main, etc.) and extracts the URLs of the files to a text file. The tool is designed to be simple to use, and it supports reading URLs from a file or from standard input.

jsFinder is useful for web developers and security professionals who want to find and analyze the JavaScript files used by a web application. By analyzing the JavaScript files, it's possible to understand the functionality of the application and detect any security vulnerabilities or sensitive information leakage. Features* Reading URLs from a file or from stdin using command line arguments.
* Running multiple HTTP GET requests concurrently to each URL.
* Limiting the concurrency of HTTP GET requests using a flag.
* Using a regular expression to search for JavaScript files in the response body of the HTTP GET requests.
* Writing the found JavaScript files to a file specified in the command line arguments or to a default file named "output.txt".
* Printing informative messages to the console indicating the status of the program's execution and the output file's location.
* Allowing the program to run in verbose or silent mode using a flag. Installationjsfinder requires Go 1.20 to install successfully.Run the following command to get the repo : go install -v github.com/kacakb/jsfinder@latestUsageTo see which flags you can use with the tool, use the -h flag. jsfinder -h Flag Description -l Specifies the filename to read URLs from. -c Specifies the maximum number of concurrent requests to be made. The default value is 20. -s Runs the program in silent mode. If this flag is not set, the program runs in verbose mode. -o Specifies the filename to write found URLs to. The default filename is output.txt. -read Reads URLs from stdin instead of a file specified by the -l flag. DemoIhttps://camo.githubusercontent.com/ab1dc7868ff8b762f93c950b6c04becb5a2e0a7e0ccc248208b5f506677b6034/68747470733a2f2f61736369696e656d612e6f72672f612f456874626377793149456f527166586e524f514732627241612e737667 If you want to read from stdin and run the program in silent mode, use this command: cat list.txt| jsfinder -read -s -o js.txtIIhttps://camo.githubusercontent.com/03976d9a6a6414729a822eb49167ad4fb4512c342fb9e84c922d205a7d0d9289/68747470733a2f2f61736369696e656d612e6f72672f612f644f745632587264747371467a6b59457971765062396d72592e737667 If you want to read from a file, you should specify it with the -l flag and use this command: jsfinder -l list.txt -s -o js.txtYou can also specify the concurrency with the -c flag.The default value is 20. If you want to read from a file, you should specify it with the -l flag and use this command: jsfinder -l list.txt -c 50 -s -o js.txtTODOs* Adding new features
* Improving performance
* Adding a cookie flag
* Reading regex from a file
* Integrating the kacak tool (coming soon) Screenshothttps://blogger.googleusercontent.com/img/a/AVvXsEgAPN47gy1yXotgHvDbX56jrTrIZOAugA_srdB-H5RZQS3bZJxHKZ1YHb5-z7GNEd09anc25yKv6yb9kMZl3Qa10uXXCTPCFVJckbyU1o09FIwWoO1hqrCBaD3lcL_PpOiydZMFE3No2VwJ7ZdDx3asAY-LfG8xngB_26GToDWThyyGPTl5XZ-aloozmA=w640-h220 ContactIf you have any questions, feedback or collaboration suggestions related to this project, please feel free to contact me via: e-mail Download Jsfinder
hacking: security in practice
Thelinuxchoice/self-xss

Does anybody have any link that could redirect me to the copy of thelinuxchoice/self-xss package , its definitely deleted from github and couldn't find it using google dorks either.

submitted by /u/Electro2077
[link] [comments]
hacking: security in practice
proxychains timeout error

I try to use it to connect to proxies but it always gives me timeout error even though the proxies work when i use them in browser and proxychains works when i connect to tor only with it but it doesn't when i use it to connect to proxies because of timeout error

submitted by /u/Sea-Helicopter-5233
[link] [comments]
hacking: security in practice
Step-by-Step Breakdown of the New OAuth Vulnerability (CVE-2023-28131) in a framework used in hundreds of websites and Apps

The vulnerability was published today in a blog post, which explains the issue in detail with images and extra explanation:
https://salt.security/blog/a-new-oauth-vulnerability-that-may-impact-hundreds-of-online-services

Make sure you are not impacted :)

If you are not familiar with OAuth, then I think it's a really great chance to learn about how OAuth works 💻💻

submitted by /u/iva3210
[link] [comments]
Dark Reading: Attacks/Breaches
5 Questions to Ask When Evaluating a New Cybersecurity Technology

Any new cybersecurity technology should be not just a neutral addition to a security stack but a benefit to the other technologies or people managing them.