Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
First to understand postMessage xss attack you need to understand this two things :Continue reading on Medium » (https://medium.com/@youghourtaghannei/postmessage-xss-vulnerability-on-private-program-18e773e1a1ba?source=rss------bug_bounty-5)
PostMessage Xss vulnerability on private program

First to understand postMessage xss attack you need to understand this two things :Continue reading on Medium »
Read more...
How I Scored 1K Bounty Using Waybackurls

Approaching a target from all anglesContinue reading on Medium »
Read more...
Noob Question Regarding Certs
https://www.reddit.com/r/Pentesting/comments/owmif7/noob_question_regarding_certs/

<!-- SC_OFF -->I had a noob question regarding which certs, or route to take for beginners. Apologies if this is a redundant question, but I can't seem to find one regarding this specifically. As a beginner, would it be possible to just go straight for the eJPT while doing tryhackme, hackthebox, CTFs and move up from there? I know the general consensus is to first study for the CompTIA route of the A+, Network+, then Sec+. I'm studying the A+ at the moment, but it is really difficult to find practicality for pentesting, such as troubleshooting a printer (but I could be wrong?). To be frank, it is extremely boring stuff. I've dabbled about 15 hours in tryhackme and it was very interesting. From what I've seen, the eJPT touches the relevent basics of the CompTIA certs in regards to pentesting, correct? Please let me know what you think. Tl;dr: Beginner route: 1) eJPT + tryhackme, hackthebox, CTFs, then move up. Or 2) CompTIA A+, Net+, Sec+, then move up. <!-- SC_ON --> submitted by /u/Crypto011000 (https://www.reddit.com/user/Crypto011000)
[link] (https://www.reddit.com/r/Pentesting/comments/owmif7/noob_question_regarding_certs/) [comments] (https://www.reddit.com/r/Pentesting/comments/owmif7/noob_question_regarding_certs/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Penetration Testing with Google

https://cdn-images-1.medium.com/max/620/0*p6_KqIyH9ly5B4lF.jpg
As we know, there are plenty of search engines. We have Bing, Yahoo, DuckDuckGo, Dogpile, lxquick, etc but the most popular is Google. We…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HackTheBox - Chatterbox

https://cdn-images-1.medium.com/max/600/0*6vn94_Gw7P5jjb6U.png
Bu, OSCP için HackTheBox adında yayınlayacağım emekliye ayrılmış HTB makinelerinden oluşacak olan bir dizi blogun 2. blogu. TJ_Null…

Continue reading on Medium »
Domhttpx - A Google Search Engine Dorker With HTTP Toolkit Built With Python, Can Make It Easier For You To Find Many URLs/IPs At Once With Fast Time
http://www.kitploit.com/2021/08/domhttpx-google-search-engine-dorker.html
domhttpx is a google search engine dorker (https://github.com/MarioVilas/googlesearch) with HTTP toolkit (https://www.kitploit.com/search/label/Toolkit) built with python, can make it easier for you to find many URLs/IPs at once with fast time.
Usage

Flags
This will display help for the tool. Here are all the switches it supports. Flag Description Example -ip, --only-ip Show output as IP only domhttpx --only-ip -od, --only-domain Show output as domain only domhttpx --only-domain -rp, --real-path Extract real path domhttpx -k [keyword] -a [amount] --real-path -p, --path Custom path url domhttpx -k [keyword] -a [amount] --path [custom_path] -sc, --status-code Extract status code domhttpx -k [keyword] -a [amount] --status-code -t, --title Extract title page domhttpx -k [keyword] -a [amount] --title -ws, --web-server Extract web server domhttpx -k [keyword] -a [amount] --server -cr, --check-result Check list result domhttpx --check-result -sr, --show-result Show result content domhttpx --show-result result.txt -rr, --remove-result Remove result file domhttpx --remove-result result.txt -o, --output File to write output domhttpx -k [keyword] -a [amount] -o output.txt -s, --silent Show only subdomains (https://www.kitploit.com/search/label/Subdomains) in output domhttpx -k [keyword] -a [amount] --silent -v, --version Show current program version domhttpx --version
Basic Usage
domhttpx.py --keyword [keyword] --amount [amount] ">> domhttpx.py --keyword [keyword] --amount [amount]
One keyword
domhttpx.py --keyword pentesting --amount 5 ">> domhttpx.py --keyword pentesting --amount 5
Multiple keyword
domhttpx.py --keyword "pentesting basic" --amount 5 '>> domhttpx.py --keyword "pentesting basic" --amount 5
Extract Title Page
domhttpx.py --keyword "pentesting basic" --amount 5 --title '>> domhttpx.py --keyword "pentesting basic" --amount 5 --title
Extract Title Page from Real Path
domhttpx.py --keyword "pentesting basic" --amount 5 --title --real-path '>> domhttpx.py --keyword "pentesting basic" --amount 5 --title --real-path
Extract Web Server
domhttpx.py --keyword "pentesting basic" --amount 5 --web-server '>> domhttpx.py --keyword "pentesting basic" --amount 5 --web-server
Running Example

Running domHttpx with default command
This will run an automatic search tool with the specified keyword and number ➤ domhttpx.py --keyword indonesia --amount 20

_ _ _ _ _
__| |___ _ __ | || | |_| |_ _ ____ __
/ _` / _ \ ' \| __ | _| _| '_ \ \ /
\__,_\___/_|_|_|_||_|\__|\__| .__/_\_\
|_| v1.0.0

naufalardhani.com

https://www.suara.com
https://www.suara.com
https://www.suara.com
https://en.wikipedia.org
https://en.wikipedia.org
https://en.wikipedia.org
https://en.wikipedia.org
https://en.wikipedia.org
https://id.wikipedia.org
https://id.wikipedia.org
https://id.wikipedia.org
https://id.wikipedia.org
https://id.wikipedia.org
https://www.indonesia.travel
https://www.britannica.com
https://indonesia.go.id
https://www.garuda-indonesia.com
https://wikitravel.org
https://www.aljazeera.com
https://www.worldbank.org


[INFO] Searching domain for indonesia keyword
[INFO] Found 20 domain

Show output as IP
domhttpx.py --keyword indonesia --amount 9 --only-ip

_ _ _ _ _
__| |___ _ __ | || | |_| |_ _ ____ __
/ _` / _ \ ' \| __ | _| _| '_ \ \ /
\__,_\___/_|_|_|_||_|\__|\__| .__/_\_\
|_| v1.0.0

naufalardhani.com

54.192.146.34
103.102.166.224
104.93.220.176
104.18.19.221
202.89.117.193
104.18.11.196
172.67.161.37
104.93.115.155
199.232.44.143


[INFO] Searching IP for indonesia keyword
[INFO] Found 9 IP

Extracts the real path
domhttpx.py --keyword indonesia --amount 9 --real-path

_ _ _ _ _
__| |___ _ __ | || | |_| |_ _ ____ __
/ _` / _ \ ' \| __ | _| _| '_ \ \ /
\__,_\___/_|_|_|_||_|\__|\__| .__/_\_\
|_| v1.0.0

naufalardhani.com

https://www.suara.com/entertainment/2021/07/01/211333/6-aktor-indonesia-main-di-film-hollywood-tak-cuma-andalkan-tampang
https://en.wikipedia.org/wiki/Indonesia
https://www.indonesia.travel/id/en/home
https://www.britannica.com/place/Indonesia
https://indonesia.go.id/
https://www.garuda-indonesia.com/
https://wikitravel.org/en/Indonesia
https://www.aljazeera.com/where/indonesia/
https://www.lonelyplanet.com/indonesia


[INFO] Searching domain for indonesia keyword
[INFO] Found 9 domain

Extracts status code
domhttpx.py --keyword "Indonesia Basketball League" --amount 10 --status-code

_ _ _ _ _
__| |___ _ __ | || | |_| |_ _ ____ __
/ _` / _ \ ' \| __ | _| _| '_ \ \ /
\__,_\___/_|_|_|_||_|\__|\__| .__/_\_\
|_| v1.0.0

naufalardhani.com

https://en.wikipedia.org [200]
https://iblindonesia.com [200]
https://iblindonesia.com [200]
https://iblindonesia.com [200]
https://iblindonesia.com [200]
https://iblindonesia.com [200]
https://twitter.com [200]
https://twitter.com [200]
https://en.wikipedia.org [200]
https://en.wikipedia.org [200]


[INFO] Searching domain for Indonesia Basketball League keyword
[INFO] Found 10 domain

Extracts title page
domhttpx.py --keyword "Ananta Dandy" --amount 10 --real-path --title

_ _ _ _ _
__| |___ _ __ | || | |_| |_ _ ____ __
/ _` / _ \ ' \| __ | _| _| '_ \ \ /
\__,_\___/_|_|_|_||_|\__|\__| .__/_\_\
|_| v1.0.0

naufalardhani.com

https://www.dbl.id/camp/1/campers/98/ananta-dandy [Campers - Ananta Dandy]
https://www.dbl.id/u/profile/12379/ananta-dandy [Ananta Dandy Profile | DBL ID]
https://www.instagram.com/anantadandy/?hl=en [Page Not Found • Instagram]
https://play.fiba3x3.com/players/d3a6cc16-fd25-424d-a3a4-62515c5cd075 [Ananta Dandy]
https://www.youtube.com/watch?v=DghZd7E3YL0 [Ananta Dandy - Rakan - Rafie - Saddam & Zee Bikin Komunitas #Basket Komplek | Isinya Jagoan Semua ! - YouTube]
https://www.youtube.com/watch?v=J4oOSmfOlmA [Next in Line #12: Ananta Dandy Tentang Bermain melawan Filipin & Motivasi Untuk Ju ara DBL. - YouTube]
https://www.youtube.com/watch?v=A4xu1aMWCy0 [ANANTA DANDY DAN MUHAMAD HAFIZH | DYNAMIC DUO DARI SMAN 71 JAKARTA - YouTube]
https://archive.fiba.com/pages/eng/fa/player/p/pid/137281/sid/13264/tid/302/tid2//_/2017_SEABA_U16_Championship_for_Men/index.html [Ananta Dandy Putra Tarigan's profile | 2017 SEABA U16 Championship for Men | ARCHIVE.FIBA.COM]
http://sman71.sch.id/2020/08/data-sementara-alumni-siswa-sman-71-tahun-2020-yang-diterima-di-ptn/ [Data Sementara Alumni Siswa SMAN 71 Tahun 2020 yang Diterima di PTN – SMAN 71]
https://www.mainbasket.com/r/6522/muhamad-hafizh-gua-ingin-jadi-pemain-indonesia-pertama-di-nba [Muhamad Hafizh: Gua Ingin Jadi Pemain Indonesia Pertama di NBA - mainbasket.com]


[INFO] Searching domain for Ananta Dandy keyword
[INFO] Found 10 domain

Help & Bugs
If you are still confused (https://www.kitploit.com/search/label/Confused) or find a bug, please open the issue (https://github.com/naufalardhani/domhttpx/issues). All bug reports are appreciated, and will be responded to as soon as possible thanks!
Thanks
@MarioVilas (https://github.com/MarioVilas/) - domhttpx uses dorker from the googlesearch (https://github.com/MarioVilas/googlesearch) package made by him @projectdiscovery (https://github.com/projectdiscovery) - because I was inspired by their project which is httpx (https://github.com/projectdiscovery/httpx/), that's why I made domhttpx @p4kl0nc4t (https://github.com/p4kl0nc4t) - who has given many solutions in making domHttpx