Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
7.4 Lab: User role can be modified in user profile | 2023
https://cdn-images-1.medium.com/max/1366/1*jHVKyFva9YSISG0BJ-4ueA.png
This Lab has an admin panel at /admin. It’s only accessible to logged-in users with a roleid of 2, Solve the lab by accessing the admin…
Continue reading on Medium »
7.4 Lab: User role can be modified in user profile | 2023
https://cdn-images-1.medium.com/max/1366/1*jHVKyFva9YSISG0BJ-4ueA.png
This Lab has an admin panel at /admin. It’s only accessible to logged-in users with a roleid of 2, Solve the lab by accessing the admin…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Bank Account Keeps Getting Hacked
https://cdn-images-1.medium.com/max/840/1*kTXWfrN2XqT2S7xNaA9RRA.gif
Visit our website to gain access to unlimited money transfer hacks🌐Visit: https://phantomhacker.su/ 📧Email: phantomhackings@gmail.com…
Continue reading on Medium »
Bank Account Keeps Getting Hacked
https://cdn-images-1.medium.com/max/840/1*kTXWfrN2XqT2S7xNaA9RRA.gif
Visit our website to gain access to unlimited money transfer hacks🌐Visit: https://phantomhacker.su/ 📧Email: phantomhackings@gmail.com…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Telegram Jumia Log Hack
https://cdn-images-1.medium.com/max/840/1*kTXWfrN2XqT2S7xNaA9RRA.gif
Visit our website to gain access to unlimited money transfer hacks🌐Visit: https://phantomhacker.su/ 📧Email: phantomhackings@gmail.com
Continue reading on Medium »
Telegram Jumia Log Hack
https://cdn-images-1.medium.com/max/840/1*kTXWfrN2XqT2S7xNaA9RRA.gif
Visit our website to gain access to unlimited money transfer hacks🌐Visit: https://phantomhacker.su/ 📧Email: phantomhackings@gmail.com
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is Linux and Why Do Hackers Use It?
https://cdn-images-1.medium.com/max/1500/1*mQxg0FvD2pYUy8qz6DH7Iw.png
the operating system of future tech
Continue reading on Medium »
What is Linux and Why Do Hackers Use It?
https://cdn-images-1.medium.com/max/1500/1*mQxg0FvD2pYUy8qz6DH7Iw.png
the operating system of future tech
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
BMO Hacked
https://cdn-images-1.medium.com/max/840/1*kTXWfrN2XqT2S7xNaA9RRA.gif
Visit our website to gain access to unlimited money transfer hacks🌐Visit: https://phantomhacker.su/ 📧Email: phantomhackings@gmail.com
Continue reading on Medium »
BMO Hacked
https://cdn-images-1.medium.com/max/840/1*kTXWfrN2XqT2S7xNaA9RRA.gif
Visit our website to gain access to unlimited money transfer hacks🌐Visit: https://phantomhacker.su/ 📧Email: phantomhackings@gmail.com
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Bank Accounts Being Hacked
https://cdn-images-1.medium.com/max/840/1*kTXWfrN2XqT2S7xNaA9RRA.gif
Visit our website to gain access to unlimited money transfer hacks🌐Visit: https://phantomhacker.su/ 📧Email: phantomhackings@gmail.com…
Continue reading on Medium »
Bank Accounts Being Hacked
https://cdn-images-1.medium.com/max/840/1*kTXWfrN2XqT2S7xNaA9RRA.gif
Visit our website to gain access to unlimited money transfer hacks🌐Visit: https://phantomhacker.su/ 📧Email: phantomhackings@gmail.com…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
PPID Spoofer
https://cdn-images-1.medium.com/max/886/1*FjNTvry6xPdAjHZRS5xhlg.png
Welcome to this intriguing article where we delve into the world of PPID Spoofer, a powerful yet concerning malware tool designed to…
Continue reading on Medium »
PPID Spoofer
https://cdn-images-1.medium.com/max/886/1*FjNTvry6xPdAjHZRS5xhlg.png
Welcome to this intriguing article where we delve into the world of PPID Spoofer, a powerful yet concerning malware tool designed to…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HTB Write-up — ‘Fawn’ box [VERY EASY]
https://cdn-images-1.medium.com/max/1200/1*nDygSy6HafhrGYTmStLFwA.png
A practical approach to help you complete this box.
Continue reading on Medium »
HTB Write-up — ‘Fawn’ box [VERY EASY]
https://cdn-images-1.medium.com/max/1200/1*nDygSy6HafhrGYTmStLFwA.png
A practical approach to help you complete this box.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hacking Road Map
https://cdn-images-1.medium.com/max/2600/1*jmE2OrXvWynoamub7z_sew.png
👨💻 Subject : Hacking Road Map
Continue reading on Medium »
Hacking Road Map
https://cdn-images-1.medium.com/max/2600/1*jmE2OrXvWynoamub7z_sew.png
👨💻 Subject : Hacking Road Map
Continue reading on Medium »
7.4 Lab: User role can be modified in user profile | 2023
This Lab has an admin panel at /admin. It’s only accessible to logged-in users with a roleid of 2, Solve the lab by accessing the admin…Continue reading on Medium »
Read more...
This Lab has an admin panel at /admin. It’s only accessible to logged-in users with a roleid of 2, Solve the lab by accessing the admin…Continue reading on Medium »
Read more...
Medium
7.4 Lab: User role can be modified in user profile | 2023
This Lab has an admin panel at /admin. It’s only accessible to logged-in users with a roleid of 2, Solve the lab by accessing the admin…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Furlzz – Advanced iOS URL Scheme Fuzzing Made Easy
Furlzz is a small fuzzer written to test out iOS URL schemes. It does so by attaching to the application using Frida and based on the input/seed it mutates the data and tries to open the mutated URL.
Furlzz works in-process, meaning you aren’t actually opening the URL using apps such as SpringBoard. furlzz supports universal links which are being used with
Download prebuilt binaries from here or do it manually.
To manually install furlzz, do:
* Follow the instructions for devkit documented here
* Run
There are basically two ways you can go with fuzzing using
* give base URL (
* just give base URL without
furlzz supports two post-process methods right now; url and base64. The first one does URL encode on the mutated input while the second one generates base64 from it. Fuzzing
1. Figure out the method of opening URLs inside the application (with
2. Find out base url
3. Create some inputs
4. Pass the flags to
5. Most of the time, values have to be URL encoded, so use
6. Adjust timeout if you would like to go with slower fuzzing
7. If the crash happen, replay it with
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg9MVrMahVd9Qq4khnGxQkSyexdC9aJdNxzG6N4ge2WIhzbrHaiTi8L4AV3E3trZmtiTIyvOKY2XbU2Fx8x6msqcvs_Z7PHeoBGH3BrdVqQYKX6z43GgBufbv2Av261Qjy5NGgalKVxlWJ-RQYwB37OxOgXQTSyxVzixtT-HAaIvT3whzhbHv4X1A_Z8XDK/s16000/telegram.webp Mutations
*
*
*
*
*
*
*
*
*
Right now furlzz supports two methods of opening URLs:
*
*
*
*
* For the method of
* For the method of
* For the method of
PRs are more than welcome to extend any functionality inside the furlzz
➖ Sent by @TheFeedReaderBot ➖
Furlzz – Advanced iOS URL Scheme Fuzzing Made Easy
Furlzz is a small fuzzer written to test out iOS URL schemes. It does so by attaching to the application using Frida and based on the input/seed it mutates the data and tries to open the mutated URL.
Furlzz works in-process, meaning you aren’t actually opening the URL using apps such as SpringBoard. furlzz supports universal links which are being used with
scene:continueUserActivity. InstallationDownload prebuilt binaries from here or do it manually.
To manually install furlzz, do:
* Follow the instructions for devkit documented here
* Run
go install github.com/nsecho/furlzz@latest Usage $ furlzz fuzz --help
Fuzz URL scheme
Usage:
furlzz fuzz [flags]
Flags:
-a, --app string Application name to attach to (default "Gadget")
-b, --base string base URL to fuzz
-c, --crash ignore previous crashes
-d, --delegate string if the method is scene_activity, you need to specify UISceneDelegate class
-f, --function string apply the function to mutated input (url, base64)
-h, --help help for fuzz
-i, --input string path to input directory
-m, --method string method of opening url (delegate, app) (default "delegate")
-r, --runs uint number of runs
-s, --scene string scene class name
-t, --timeout uint sleep X seconds between each case (default 1)
-u, --uiapp string UIApplication name There are basically two ways you can go with fuzzing using
furlzz:* give base URL (
--base) with FUZZ keyword in it along with --input directory containing inputs* just give base URL without
FUZZ keyword which would fuzz the raw base url passed (less efficient)furlzz supports two post-process methods right now; url and base64. The first one does URL encode on the mutated input while the second one generates base64 from it. Fuzzing
1. Figure out the method of opening URLs inside the application (with
frida-trace for example)2. Find out base url
3. Create some inputs
4. Pass the flags to
furlzz fuzz5. Most of the time, values have to be URL encoded, so use
--function url6. Adjust timeout if you would like to go with slower fuzzing
7. If the crash happen, replay it with
furlzz crash passing created session and crash fileshttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg9MVrMahVd9Qq4khnGxQkSyexdC9aJdNxzG6N4ge2WIhzbrHaiTi8L4AV3E3trZmtiTIyvOKY2XbU2Fx8x6msqcvs_Z7PHeoBGH3BrdVqQYKX6z43GgBufbv2Av261Qjy5NGgalKVxlWJ-RQYwB37OxOgXQTSyxVzixtT-HAaIvT3whzhbHv4X1A_Z8XDK/s16000/telegram.webp Mutations
*
insert – inserts random byte at random location inside the input*
del – deletes random byte*
substitute – substitute byte at random position with random byte*
byteOp – takes random byte and random position inside the string and do arithmetic operation on them (+, -, *, /)*
duplicateRange – duplicates random range inside the original string random number of times*
bitFlip – flips the bit at random position inside random location inside input*
bitmask – applies random bitmask on random location inside the string*
duplicate – duplicates original string random number of times (2 < 10)*
multiple – run other mutations random number of times URL Open MethodsRight now furlzz supports two methods of opening URLs:
*
delegate when the application uses -[AppDelegate application:openURL:options:]*
app when the application is using -[UIApplication openURL:]*
scene_activity – when the application is using -[UISceneDelegate scene:continueUserActivity]*
scene_context when the application is using -[UISceneDelegate scene:openURLContexts:] Additional Flags* For the method of
scene_activity you need to pass the UISceneDelegate class name* For the method of
delegate you need to pass the AppDelegate class name* For the method of
scene_context you need to pass UISceneDelegate class namePRs are more than welcome to extend any functionality inside the furlzz
➖ Sent by @TheFeedReaderBot ➖
Mencari Encryption Key dengan bantuan ChatGPT
https://aminudin.medium.com/mencari-encryption-key-dengan-bantuan-chatgpt-a6db0e738269?source=rss------bug_bounty-5
https://aminudin.medium.com/mencari-encryption-key-dengan-bantuan-chatgpt-a6db0e738269?source=rss------bug_bounty-5