COOK — THE WORDLISTS FRAMEWORK
https://medium.com/@giteshnxtlvl/cook-the-wordlists-framework-1b28f59ff5d5?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@giteshnxtlvl/cook-the-wordlists-framework-1b28f59ff5d5?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
COOK 2.0— THE WORDLISTS FRAMEWORK
Cook is a powerful tool to simplify wordlist generation, modification, updating, searching, and storing them. To generate words permutation. I use it to guess files and directories for IIS…
Continue reading on Medium » (https://medium.com/@giteshnxtlvl/cook-the-wordlists-framework-1b28f59ff5d5?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
COOK 2.0— THE WORDLISTS FRAMEWORK
Cook is a powerful tool to simplify wordlist generation, modification, updating, searching, and storing them. To generate words permutation. I use it to guess files and directories for IIS…
hacking: security in practice
personal blog for write-ups
Hello guys,
I want to develop my own blog website to share my experiments in reverse engineering kernel and games and also my hardware hacking experiments. Would you please list links the most elegant hacking-related blogs you saw
submitted by /u/botta633
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
personal blog for write-ups
Hello guys,
I want to develop my own blog website to share my experiments in reverse engineering kernel and games and also my hardware hacking experiments. Would you please list links the most elegant hacking-related blogs you saw
submitted by /u/botta633
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
personal blog for write-ups
Hello guys, I want to develop my own blog website to share my experiments in reverse engineering kernel and games and also my hardware hacking...
hacking: security in practice
Secure Messaging
This isn't really a hacking question but a security question, and sorry of this is a stupid question but I want to be more of the grid so, would discord or snap chat be better for secure and private communication? I just want to know what the safest way to talk to my friends online is, I wouldn't use what's app or facebook because they would mine my data.
submitted by /u/DarkMetro888
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Secure Messaging
This isn't really a hacking question but a security question, and sorry of this is a stupid question but I want to be more of the grid so, would discord or snap chat be better for secure and private communication? I just want to know what the safest way to talk to my friends online is, I wouldn't use what's app or facebook because they would mine my data.
submitted by /u/DarkMetro888
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Secure Messaging
This isn't really a hacking question but a security question, and sorry of this is a stupid question but I want to be more of the grid so, would...
hacking: security in practice
Does iOS log incoming call data somewhere in program files?
I’m trying to prove the identity of a harassing phone caller. He is an abusive person and should not be contacting me.
I’ve tried reaching out to my carrier and they were no help, just listed the caller as unknown. I have good reason to believe he is calling from an internet based phone app in order to disguise his identity. So that got me thinking, since the call is actually being placed through the internet, would there be a way to determine where the call originated from, such as a static IP address from his home internet router? Is there some sort of code log within my phone that I might be able to retrieve this info from?
I’ve downloaded “trap call” so I’ll see if that works in the event he calls again. I do also have voicemails that he has left but no idea if there’s any viable info I could recover from them.
Thanks!
submitted by /u/HyperActivHyperDrive
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Does iOS log incoming call data somewhere in program files?
I’m trying to prove the identity of a harassing phone caller. He is an abusive person and should not be contacting me.
I’ve tried reaching out to my carrier and they were no help, just listed the caller as unknown. I have good reason to believe he is calling from an internet based phone app in order to disguise his identity. So that got me thinking, since the call is actually being placed through the internet, would there be a way to determine where the call originated from, such as a static IP address from his home internet router? Is there some sort of code log within my phone that I might be able to retrieve this info from?
I’ve downloaded “trap call” so I’ll see if that works in the event he calls again. I do also have voicemails that he has left but no idea if there’s any viable info I could recover from them.
Thanks!
submitted by /u/HyperActivHyperDrive
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Does iOS log incoming call data somewhere in program files?
I’m trying to prove the identity of a harassing phone caller. He is an abusive person and should not be contacting me. I’ve tried reaching out to...
Breaking Application’s Logic to DOS Attack
Hey guys,
Recently I had found a bug which was fine enough to deserve this post. So, I thought of writing it up here. I can not disclose…
Read more...
Hey guys,
Recently I had found a bug which was fine enough to deserve this post. So, I thought of writing it up here. I can not disclose…
Read more...
Top 5 Best Books for Bug Bounty Hunting
https://akashroxstarz.medium.com/top-5-best-books-for-bug-bounty-hunting-55769949b53c?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://akashroxstarz.medium.com/top-5-best-books-for-bug-bounty-hunting-55769949b53c?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Top 5 Best Books for Bug Bounty Hunting 📖
Best for Bug Bounty Business😉
Best for Bug Bounty Business😉Continue reading on Medium » (https://akashroxstarz.medium.com/top-5-best-books-for-bug-bounty-hunting-55769949b53c?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Top 5 Best Books for Bug Bounty Hunting 📖
Best for Bug Bounty Business😉
Hacking Articles Tips Tricks Videos Tutorials
GIF
KitPloit - PenTest Tools!
Ppmap - A Scanner/Exploitation Tool Written In GO, Which Leverages Prototype Pollution To XSS By Exploiting Known Gadgets
http://1.bp.blogspot.com/-iP9i_8VMqr4/YPiojQGNE-I/AAAAAAAAjao/361K5qU2dXcjLf491-8oXKkJ2Twb9uYdwCK4BGAYYCw/w640-h562/ppmap_1-703557.gif
A simple scanner/exploitation tool written in GO which automatically exploits known and existing gadgets (checks for specific variables in the global context) to perform XSS via Prototype Pollution. NOTE: The program only exploits known gadgets, but does not cover code analysis or any advanced Prototype Pollution exploitation, which may include custom gadgets.
Requirements
Make sure to have chromedp installed:
Installation
*
Automatically
* Download the already compiled binary here
* Give it the permission to execute
*
Manually (compile it yourself)
* Clone the project:
* Change directory to ppmap folder:
* Build the binary
Usage
Using the program is very simple, you can either:
*
scan a directory/file (or even just the website):
*
or endpoint:
For mass scanning:
Demo
http://1.bp.blogspot.com/-iP9i_8VMqr4/YPiojQGNE-I/AAAAAAAAjao/361K5qU2dXcjLf491-8oXKkJ2Twb9uYdwCK4BGAYYCw/w640-h562/ppmap_1-703557.gif
Feel free to test the tool on the following websites as a part of demonstration:
https://msrkp.github.io/pp/2.html
https://ctf.nikitastupin.com/pp/known.html
Workflow
* Identify if the website is vulnerable to Prototype Pollution by heuristic scan
* Fingerprint the known gadgets (checks for specific variables in the global context)
* Display the final exploit & ready to perform XSS
Credits
Many thanks to @Tomnomnom for the inspiration: https://www.youtube.com/watch?v=Gv1nK6Wj8qM&t=1558s
The workflow of this program is hugely based on this article: https://infosecwriteups.com/javascript-prototype-pollution-practice-of-finding-and-exploitation-f97284333b2
The fingerprint javascript file is based on this git: https://gist.github.com/nikitastupin/b3b64a9f8c0eb74ce37626860193eaec
Download Ppmap
___________________________
@hacking_Attack
@Hacking_Video
Ppmap - A Scanner/Exploitation Tool Written In GO, Which Leverages Prototype Pollution To XSS By Exploiting Known Gadgets
http://1.bp.blogspot.com/-iP9i_8VMqr4/YPiojQGNE-I/AAAAAAAAjao/361K5qU2dXcjLf491-8oXKkJ2Twb9uYdwCK4BGAYYCw/w640-h562/ppmap_1-703557.gif
A simple scanner/exploitation tool written in GO which automatically exploits known and existing gadgets (checks for specific variables in the global context) to perform XSS via Prototype Pollution. NOTE: The program only exploits known gadgets, but does not cover code analysis or any advanced Prototype Pollution exploitation, which may include custom gadgets.
Requirements
Make sure to have chromedp installed:
go get -u github.com/chromedp/chromedpInstallation
*
Automatically
* Download the already compiled binary here
* Give it the permission to execute
chmod +x ppmap*
Manually (compile it yourself)
* Clone the project:
git clone https://github.com/kleiton0x00/ppmap.git* Change directory to ppmap folder:
cd ~/ppmap* Build the binary
go build ppmap.goUsage
Using the program is very simple, you can either:
*
scan a directory/file (or even just the website):
echo 'https://target.com/index.html' | ./ppmap*
or endpoint:
echo 'http://target.com/something/?page=home' | ./ppmapFor mass scanning:
cat url.txt | ./ppmapwhere url.txt contains all url(s) in column.Demo
http://1.bp.blogspot.com/-iP9i_8VMqr4/YPiojQGNE-I/AAAAAAAAjao/361K5qU2dXcjLf491-8oXKkJ2Twb9uYdwCK4BGAYYCw/w640-h562/ppmap_1-703557.gif
Feel free to test the tool on the following websites as a part of demonstration:
https://msrkp.github.io/pp/2.html
https://ctf.nikitastupin.com/pp/known.html
Workflow
* Identify if the website is vulnerable to Prototype Pollution by heuristic scan
* Fingerprint the known gadgets (checks for specific variables in the global context)
* Display the final exploit & ready to perform XSS
Credits
Many thanks to @Tomnomnom for the inspiration: https://www.youtube.com/watch?v=Gv1nK6Wj8qM&t=1558s
The workflow of this program is hugely based on this article: https://infosecwriteups.com/javascript-prototype-pollution-practice-of-finding-and-exploitation-f97284333b2
The fingerprint javascript file is based on this git: https://gist.github.com/nikitastupin/b3b64a9f8c0eb74ce37626860193eaec
Download Ppmap
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Ppmap - A Scanner/Exploitation Tool Written In GO, Which Leverages Prototype Pollution To XSS By Exploiting Known Gadgets
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is X-Frame-Options header?
https://cdn-images-1.medium.com/max/1191/1*M7QGo83Xz321_Atv8E-ryA.png
In this article we are going to discuss about the X-Frame-Option HTTP security header used to protect the website from clickjacking…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
What is X-Frame-Options header?
https://cdn-images-1.medium.com/max/1191/1*M7QGo83Xz321_Atv8E-ryA.png
In this article we are going to discuss about the X-Frame-Option HTTP security header used to protect the website from clickjacking…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is X-Frame-Options header?
In this article we are going to discuss about the X-Frame-Option HTTP security header used to protect the website from clickjacking…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
COOK — THE WORDLISTS FRAMEWORK
https://cdn-images-1.medium.com/max/840/1*M1jbSMkLiEDqIZfW-YCvEg.png
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
COOK — THE WORDLISTS FRAMEWORK
https://cdn-images-1.medium.com/max/840/1*M1jbSMkLiEDqIZfW-YCvEg.png
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
COOK 2.0— THE WORDLISTS FRAMEWORK
Cook is a powerful tool to simplify wordlist generation, modification, updating, searching, and storing them. To generate words permutation. I use it to guess files and directories for IIS…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Top 5 Best Books for Bug Bounty Hunting
https://cdn-images-1.medium.com/max/600/1*VhK5SK32vnrwQPjqLWfi2g.png
Best for Bug Bounty Business😉
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Top 5 Best Books for Bug Bounty Hunting
https://cdn-images-1.medium.com/max/600/1*VhK5SK32vnrwQPjqLWfi2g.png
Best for Bug Bounty Business😉
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Top 5 Best Books for Bug Bounty Hunting 📖
Best for Bug Bounty Business😉
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is Pegasus spyware?
https://cdn-images-1.medium.com/max/656/1*_z15B0ymTbDe_jTqUacqbQ.png
This might be the name for possibly one of the most powerful and sophisticated spyware developed by a private company.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
What is Pegasus spyware?
https://cdn-images-1.medium.com/max/656/1*_z15B0ymTbDe_jTqUacqbQ.png
This might be the name for possibly one of the most powerful and sophisticated spyware developed by a private company.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is Pegasus spyware?
This might be the name for possibly one of the most powerful and sophisticated spyware developed by a private company. Pegasus is a spyware…