Hacking on Medium
How may your file uploads get hacked?
https://cdn-images-1.medium.com/max/962/0*pNs55tIWxtHS0bOO.png
Shared from Danubius IT Solutions’ tech blog.
Continue reading on Medium »
How may your file uploads get hacked?
https://cdn-images-1.medium.com/max/962/0*pNs55tIWxtHS0bOO.png
Shared from Danubius IT Solutions’ tech blog.
Continue reading on Medium »
Medium
How may your file uploads get hacked?
Shared from Danubius IT Solutions’ tech blog.
Hacking on Medium
CVE-2023-2859: Stored HTML injection in folderName affecting Admin in TeamPass < 3.0.9
https://cdn-images-1.medium.com/max/1082/1*QFP10FO635S92Fk6XYmz1Q.png
Hi,
Continue reading on Medium »
CVE-2023-2859: Stored HTML injection in folderName affecting Admin in TeamPass < 3.0.9
https://cdn-images-1.medium.com/max/1082/1*QFP10FO635S92Fk6XYmz1Q.png
Hi,
Continue reading on Medium »
Medium
CVE-2023-2859: Stored HTML injection in folderName affecting Admin in TeamPass < 3.0.9
Hi,
Hacking on Medium
Programming: Unleashing the Power of Digital Creation
Introduction:
In today’s interconnected world, programming has become a fundamental skill that empowers individuals to shape the digital…
Continue reading on Medium »
Programming: Unleashing the Power of Digital Creation
Introduction:
In today’s interconnected world, programming has become a fundamental skill that empowers individuals to shape the digital…
Continue reading on Medium »
Medium
Programming: Unleashing the Power of Digital Creation
Introduction: In today’s interconnected world, programming has become a fundamental skill that empowers individuals to shape the digital…
Hacking on Medium
[HTB] Armageddon靶機 Write-Up
https://cdn-images-1.medium.com/max/770/1*3pYZ0pxeXDgDaMSKvUCYgA.png
Hack The Box Armageddon machine Write-Up
Continue reading on Medium »
[HTB] Armageddon靶機 Write-Up
https://cdn-images-1.medium.com/max/770/1*3pYZ0pxeXDgDaMSKvUCYgA.png
Hack The Box Armageddon machine Write-Up
Continue reading on Medium »
Medium
[HTB] Armageddon靶機 Write-Up
Hack The Box Armageddon machine Write-Up
Jsfinder - Fetches JavaScript Files Quickly And Comprehensively
https://www.kitploit.com/2023/05/jsfinder-fetches-javascript-files.html
https://www.kitploit.com/2023/05/jsfinder-fetches-javascript-files.html
jsFinder is a command-line tool written in Go that scans web pages to find JavaScript files linked in the HTML source code. It searches for any attribute that can contain a JavaScript file (e.g., src, href, data-main, etc.) and extracts the URLs of the files to a text file. The tool is designed to be simple to use, and it supports reading URLs from a file or from standard input. jsFinder is useful for web developers and security professionals who want to find and analyze the JavaScript files used by a web application. By analyzing the JavaScript files, it's possible to understand the functionality of the application and detect any security vulnerabilities (https://www.kitploit.com/search/label/vulnerabilities) or sensitive information (https://www.kitploit.com/search/label/Sensitive%20Information) leakage.
Features Reading URLs from a file or from stdin using command line (https://www.kitploit.com/search/label/Command%20Line) arguments. Running multiple HTTP GET requests concurrently to each URL. Limiting the concurrency of HTTP GET requests using a flag. Using a regular expression to search for JavaScript files in the response body of the HTTP GET requests. Writing the found JavaScript files to a file specified in the command line arguments or to a default file named "output.txt". Printing informative messages to the console indicating the status of the program's execution and the output file's location. Allowing the program to run in verbose or silent mode using a flag. Installation jsfinder requires Go 1.20 to install successfully.Run the following command to get the repo : go install -v github.com/kacakb/jsfinder@latest Usage To see which flags you can use with the tool, use the -h flag. jsfinder -h Flag Description -l Specifies the filename to read URLs from. -c Specifies the maximum number of concurrent requests to be made. The default value is 20. -s Runs the program in silent mode. If this flag is not set, the program runs in verbose mode. -o Specifies the filename to write found URLs to. The default filename is output.txt. -read Reads URLs from stdin instead of a file specified by the -l flag. Demo I
Features Reading URLs from a file or from stdin using command line (https://www.kitploit.com/search/label/Command%20Line) arguments. Running multiple HTTP GET requests concurrently to each URL. Limiting the concurrency of HTTP GET requests using a flag. Using a regular expression to search for JavaScript files in the response body of the HTTP GET requests. Writing the found JavaScript files to a file specified in the command line arguments or to a default file named "output.txt". Printing informative messages to the console indicating the status of the program's execution and the output file's location. Allowing the program to run in verbose or silent mode using a flag. Installation jsfinder requires Go 1.20 to install successfully.Run the following command to get the repo : go install -v github.com/kacakb/jsfinder@latest Usage To see which flags you can use with the tool, use the -h flag. jsfinder -h Flag Description -l Specifies the filename to read URLs from. -c Specifies the maximum number of concurrent requests to be made. The default value is 20. -s Runs the program in silent mode. If this flag is not set, the program runs in verbose mode. -o Specifies the filename to write found URLs to. The default filename is output.txt. -read Reads URLs from stdin instead of a file specified by the -l flag. Demo I
If you want to read from stdin and run the program in silent mode, use this command: cat list.txt| jsfinder -read -s -o js.txt II
If you want to read from a file, you should specify it with the -l flag and use this command: jsfinder -l list.txt -s -o js.txt You can also specify the concurrency with the -c flag.The default value is 20. If you want to read from a file, you should specify it with the -l flag and use this command: jsfinder -l list.txt -c 50 -s -o js.txt TODOs Adding new features Improving performance Adding a cookie (https://www.kitploit.com/search/label/Cookie) flag Reading regex from a file Integrating the kacak (https://github.com/kacakb/kacak) tool (coming soon) Screenshot
Contact If you have any questions, feedback or collaboration (https://www.kitploit.com/search/label/Collaboration) suggestions related to this project, please feel free to contact me via:e-mail (mailto:kacakbatuhan@protonmail.com)
Download Jsfinder (https://github.com/kacakb/jsfinder)
Download Jsfinder (https://github.com/kacakb/jsfinder)
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Jsfinder - Fetches JavaScript Files Quickly And Comprehensively
https://blogger.googleusercontent.com/img/a/AVvXsEhSGc5-LtkIdVkddGFaiOoiTCJZ7t5S1ULN9qUNYxtiXQWIsL3WqGiN31HMpE2-H3YWBNXLgqJXIFniaxf_CmdBosXiw4WftmRYAp1j-MfL5KKkAzD0URMeywy5JW2zxf2qIc7oYkzWJ0gYahqCyNxI_eG5K31fYc7dYpdtj9883XGSOQi9EQnVg702Hg=w640-h640 jsFinder is a command-line tool written in Go that scans web pages to find JavaScript files linked in the HTML source code. It searches for any attribute that can contain a JavaScript file (e.g., src, href, data-main, etc.) and extracts the URLs of the files to a text file. The tool is designed to be simple to use, and it supports reading URLs from a file or from standard input.
jsFinder is useful for web developers and security professionals who want to find and analyze the JavaScript files used by a web application. By analyzing the JavaScript files, it's possible to understand the functionality of the application and detect any security vulnerabilities or sensitive information leakage. Features* Reading URLs from a file or from stdin using command line arguments.
* Running multiple HTTP GET requests concurrently to each URL.
* Limiting the concurrency of HTTP GET requests using a flag.
* Using a regular expression to search for JavaScript files in the response body of the HTTP GET requests.
* Writing the found JavaScript files to a file specified in the command line arguments or to a default file named "output.txt".
* Printing informative messages to the console indicating the status of the program's execution and the output file's location.
* Allowing the program to run in verbose or silent mode using a flag. Installationjsfinder requires Go 1.20 to install successfully.Run the following command to get the repo :
* Improving performance
* Adding a cookie flag
* Reading regex from a file
* Integrating the kacak tool (coming soon) Screenshothttps://blogger.googleusercontent.com/img/a/AVvXsEgAPN47gy1yXotgHvDbX56jrTrIZOAugA_srdB-H5RZQS3bZJxHKZ1YHb5-z7GNEd09anc25yKv6yb9kMZl3Qa10uXXCTPCFVJckbyU1o09FIwWoO1hqrCBaD3lcL_PpOiydZMFE3No2VwJ7ZdDx3asAY-LfG8xngB_26GToDWThyyGPTl5XZ-aloozmA=w640-h220 ContactIf you have any questions, feedback or collaboration suggestions related to this project, please feel free to contact me via: e-mail Download Jsfinder
Jsfinder - Fetches JavaScript Files Quickly And Comprehensively
https://blogger.googleusercontent.com/img/a/AVvXsEhSGc5-LtkIdVkddGFaiOoiTCJZ7t5S1ULN9qUNYxtiXQWIsL3WqGiN31HMpE2-H3YWBNXLgqJXIFniaxf_CmdBosXiw4WftmRYAp1j-MfL5KKkAzD0URMeywy5JW2zxf2qIc7oYkzWJ0gYahqCyNxI_eG5K31fYc7dYpdtj9883XGSOQi9EQnVg702Hg=w640-h640 jsFinder is a command-line tool written in Go that scans web pages to find JavaScript files linked in the HTML source code. It searches for any attribute that can contain a JavaScript file (e.g., src, href, data-main, etc.) and extracts the URLs of the files to a text file. The tool is designed to be simple to use, and it supports reading URLs from a file or from standard input.
jsFinder is useful for web developers and security professionals who want to find and analyze the JavaScript files used by a web application. By analyzing the JavaScript files, it's possible to understand the functionality of the application and detect any security vulnerabilities or sensitive information leakage. Features* Reading URLs from a file or from stdin using command line arguments.
* Running multiple HTTP GET requests concurrently to each URL.
* Limiting the concurrency of HTTP GET requests using a flag.
* Using a regular expression to search for JavaScript files in the response body of the HTTP GET requests.
* Writing the found JavaScript files to a file specified in the command line arguments or to a default file named "output.txt".
* Printing informative messages to the console indicating the status of the program's execution and the output file's location.
* Allowing the program to run in verbose or silent mode using a flag. Installationjsfinder requires Go 1.20 to install successfully.Run the following command to get the repo :
go install -v github.com/kacakb/jsfinder@latestUsageTo see which flags you can use with the tool, use the -h flag. jsfinder -h Flag Description -l Specifies the filename to read URLs from. -c Specifies the maximum number of concurrent requests to be made. The default value is 20. -s Runs the program in silent mode. If this flag is not set, the program runs in verbose mode. -o Specifies the filename to write found URLs to. The default filename is output.txt. -read Reads URLs from stdin instead of a file specified by the -l flag. DemoIhttps://camo.githubusercontent.com/ab1dc7868ff8b762f93c950b6c04becb5a2e0a7e0ccc248208b5f506677b6034/68747470733a2f2f61736369696e656d612e6f72672f612f456874626377793149456f527166586e524f514732627241612e737667 If you want to read from stdin and run the program in silent mode, use this command: cat list.txt| jsfinder -read -s -o js.txtIIhttps://camo.githubusercontent.com/03976d9a6a6414729a822eb49167ad4fb4512c342fb9e84c922d205a7d0d9289/68747470733a2f2f61736369696e656d612e6f72672f612f644f745632587264747371467a6b59457971765062396d72592e737667 If you want to read from a file, you should specify it with the -l flag and use this command: jsfinder -l list.txt -s -o js.txtYou can also specify the concurrency with the -c flag.The default value is 20. If you want to read from a file, you should specify it with the -l flag and use this command: jsfinder -l list.txt -c 50 -s -o js.txtTODOs* Adding new features* Improving performance
* Adding a cookie flag
* Reading regex from a file
* Integrating the kacak tool (coming soon) Screenshothttps://blogger.googleusercontent.com/img/a/AVvXsEgAPN47gy1yXotgHvDbX56jrTrIZOAugA_srdB-H5RZQS3bZJxHKZ1YHb5-z7GNEd09anc25yKv6yb9kMZl3Qa10uXXCTPCFVJckbyU1o09FIwWoO1hqrCBaD3lcL_PpOiydZMFE3No2VwJ7ZdDx3asAY-LfG8xngB_26GToDWThyyGPTl5XZ-aloozmA=w640-h220 ContactIf you have any questions, feedback or collaboration suggestions related to this project, please feel free to contact me via: e-mail Download Jsfinder
hacking: security in practice
Thelinuxchoice/self-xss
Does anybody have any link that could redirect me to the copy of thelinuxchoice/self-xss package , its definitely deleted from github and couldn't find it using google dorks either.
submitted by /u/Electro2077
[link] [comments]
Thelinuxchoice/self-xss
Does anybody have any link that could redirect me to the copy of thelinuxchoice/self-xss package , its definitely deleted from github and couldn't find it using google dorks either.
submitted by /u/Electro2077
[link] [comments]
Reddit
r/hacking on Reddit: Thelinuxchoice/self-xss
Posted by u/Electro2077 - No votes and no comments
hacking: security in practice
Is there a specific hacking area/branch that you can do as a hobby? If yes what would you pick?
I was wondering if hacking as a hobby is possible. If yes what area of hacking would you pick and why?
Thank you in advance.
submitted by /u/TolisKoutro
[link] [comments]
Is there a specific hacking area/branch that you can do as a hobby? If yes what would you pick?
I was wondering if hacking as a hobby is possible. If yes what area of hacking would you pick and why?
Thank you in advance.
submitted by /u/TolisKoutro
[link] [comments]
Reddit
r/hacking on Reddit: Is there a specific hacking area/branch that you can do as a hobby? If yes what would you pick?
Posted by u/TolisKoutro - No votes and no comments
hacking: security in practice
proxychains timeout error
I try to use it to connect to proxies but it always gives me timeout error even though the proxies work when i use them in browser and proxychains works when i connect to tor only with it but it doesn't when i use it to connect to proxies because of timeout error
submitted by /u/Sea-Helicopter-5233
[link] [comments]
proxychains timeout error
I try to use it to connect to proxies but it always gives me timeout error even though the proxies work when i use them in browser and proxychains works when i connect to tor only with it but it doesn't when i use it to connect to proxies because of timeout error
submitted by /u/Sea-Helicopter-5233
[link] [comments]
Reddit
r/hacking on Reddit: proxychains timeout error
Posted by u/Sea-Helicopter-5233 - No votes and no comments
hacking: security in practice
Step-by-Step Breakdown of the New OAuth Vulnerability (CVE-2023-28131) in a framework used in hundreds of websites and Apps
The vulnerability was published today in a blog post, which explains the issue in detail with images and extra explanation:
https://salt.security/blog/a-new-oauth-vulnerability-that-may-impact-hundreds-of-online-services
Make sure you are not impacted :)
If you are not familiar with OAuth, then I think it's a really great chance to learn about how OAuth works 💻💻
submitted by /u/iva3210
[link] [comments]
Step-by-Step Breakdown of the New OAuth Vulnerability (CVE-2023-28131) in a framework used in hundreds of websites and Apps
The vulnerability was published today in a blog post, which explains the issue in detail with images and extra explanation:
https://salt.security/blog/a-new-oauth-vulnerability-that-may-impact-hundreds-of-online-services
Make sure you are not impacted :)
If you are not familiar with OAuth, then I think it's a really great chance to learn about how OAuth works 💻💻
submitted by /u/iva3210
[link] [comments]
Reddit
r/hacking on Reddit: Step-by-Step Breakdown of the New OAuth Vulnerability (CVE-2023-28131) in a framework used in hundreds of…
Posted by u/iva3210 - 194 votes and 13 comments