Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Pathprober - Probe And Discover HTTP Pathname Using Brute-Force Methodology And Filtered By Specific Word Or 2 Words At Once
http://www.kitploit.com/2021/07/pathprober-probe-and-discover-http.html
Probe and discover (https://www.kitploit.com/search/label/Discover) HTTP pathname using brute-force (https://www.kitploit.com/search/label/Brute-force) methodology and filtered by specific word or 2 words at once.
Purpose
Brute-forcing website (https://www.kitploit.com/search/label/Website) directories or HTTP pathname and validate using HTTP response code is not relevant anymore. This tool will help you to perform a penetration test, because it could validate the directories using specific-word or 2 words at once and the results will more accurate.
It will help you to find:
Web administrator/login panel Credential in some paths Third-party token Etc
Installation
git clone https://github.com/xchopath/pathprober
cd pathprober/

Requirements
pip3 install -r requirements.txt

Support
Multiple URL targets (in a file separated by newline) or single URL target Multiple paths (in a file separated by newline) or single path 1 word or 2 words (filter) Save valid results to another file Multi-threading
Sample usage
Multiple target, multiple path, and multiple words: python3 pathprober.py -T target.txt -P path.txt -w "APP_NAME" -w2 "DB_PASSWORD"
Single target, multiple path, and single word: python3 pathprober.py -t https://redacted.com/ -P path.txt -w "APP_NAME"
Multiple target, single path, multiple words, and save output to file: python3 pathprober.py -T target.txt -p /.env -w "APP_NAME" -w2 "TWILIO" -o output.txt

Need more help?
bash:~/pathprober$ python3 pathprober.py --help

___ ____ ___ _ _ ___ ____ ____ ___ ____ ____
|__] |__| | |__| |__] |__/ | | |__] |___ |__/
| | | | | | | | \ |__| |__] |___ | \
Probe HTTP pathname filtered by words

usage: pathprober.py [-h] [-t https://example.com] [-p pathname] [-T target.txt] [-P path.txt] [-w Word] [-w2 Word] [-o output.txt]

PathProber - Probe and discover HTTP pathname using brute-force methodology and filtered by specific word or 2 words at once

optional arguments:
-h, --help show this help message and exit
-t https://example.com
Single website target
-p pathname Single pathname
-T target.txt Multiple target separated by newline
-P path.txt Multiple pathname separated by newline
-w Word A word that you want to find in a path
-w2 Word A secon d word that you want to find in a path
-o output.txt Save the results to file

Contributors
@xchopath (https://github.com/xchopath) (from @zerobyte-id (https://github.com/zerobyte-id))

Download Pathprober (https://github.com/xchopath/pathprober)
Not valid bug that leads to us a multiple Valid Report in Facebook

I’m here again to share my 2nd and 3rd valid report. It’s all about page admin disclosure in Facebook Lite. In my Initial report, Facebook…Continue reading on Medium »
Read more...
In working my way towards learning the various, different bug types and their complexities, I gained a better understanding of how the…Continue reading on Medium » (https://mrigendrasoni.medium.com/dns-subdomains-a-tale-of-takeovers-99b50297abac?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
DNS, Subdomains & a tale of Takeovers

https://cdn-images-1.medium.com/max/852/1*GW4OSqANN5zzpeonqUFgKA.png
In working my way towards learning the various, different bug types and their complexities, I gained a better understanding of how the…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Thorchain why was it hacked? Review.

https://cdn-images-1.medium.com/max/600/0*1ihSgfqm4rKPUUrU
Hey guys. For 2 weeks, we were visited by several sad things about Thorchain, the first hack occurred last week, which allowed hackers to…

Continue reading on Medium »
hacking: security in practice
How do exploits even happen?

Newbie here, I'm just asking how the fuck exploits even happen, internet requests in most formats are just bytes to be read as data formats, JSON, Bytes for a file, just text; How the hell are exploits still ran into? It seems most of them like SQL Injection are only things due to old software, But hasnt the software been updated since then? How are these mistakes still ran into?

Any explanation would be helpful.

submitted by /u/Oracuda
[link] [comments]
DNS, Subdomains & a tale of Takeovers

In working my way towards learning the various, different bug types and their complexities, I gained a better understanding of how the…Continue reading on Medium »
Read more...
GraphQL Top 10: Attempt #1

My goal is to create GraphQL Top 10, and I was able to come up with 7 concrete issues and some generic ones, but excluding generic issues…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
Metasploit for Pentester: Database & Workspace

In this series of articles, we are focusing on the various mechanisms of the Metasploit Framework that can be used by Penetration Testers. Today we are going to learn about the workspace and database commands of the Metasploit Framework.  Table of Content Introduction Creating a Workspace Hosts Database Vulnerabilities Database

The post Metasploit for Pentester: Database & Workspace appeared first on Hacking Articles.