hacking: security in practice
Really looking for a friendly hacker to recover my stolen crypto
Hey guys. Seems really weird for me to ask someone for help, but i woke up having a damn near heart attack- someone hacked my metamask account and stole everything i possessed in crypto. I am 22 and am in the middle of switching jobs, and was using my crypto earnings to keep by. I have all the etherscans of when this wallet recieved all my coins, and i just wanna know if there is any way i, or one of you, can take my money back from this a-hole. I had about 3000 in crypto stolen, and would love to pay anyone who can safely get it back !! Counting on one of you at this point. Cheers❤️ -parker
Fyi, ive never shared my seed phrase or password with anyone or anything. I run vpn and have done everything i could to keep my money safe
I really appreciate you guys taking the time to read!!! From the bottom of my heart
submitted by /u/starhunkk
[link] [comments]
Really looking for a friendly hacker to recover my stolen crypto
Hey guys. Seems really weird for me to ask someone for help, but i woke up having a damn near heart attack- someone hacked my metamask account and stole everything i possessed in crypto. I am 22 and am in the middle of switching jobs, and was using my crypto earnings to keep by. I have all the etherscans of when this wallet recieved all my coins, and i just wanna know if there is any way i, or one of you, can take my money back from this a-hole. I had about 3000 in crypto stolen, and would love to pay anyone who can safely get it back !! Counting on one of you at this point. Cheers❤️ -parker
Fyi, ive never shared my seed phrase or password with anyone or anything. I run vpn and have done everything i could to keep my money safe
I really appreciate you guys taking the time to read!!! From the bottom of my heart
submitted by /u/starhunkk
[link] [comments]
reddit
Really looking for a friendly hacker to recover my stolen crypto
Hey guys. Seems really weird for me to ask someone for help, but i woke up having a damn near heart attack- someone hacked my metamask account and...
hacking: security in practice
How to Bypass FRP in android?
submitted by /u/Dr_FUHRER
[link] [comments]
How to Bypass FRP in android?
submitted by /u/Dr_FUHRER
[link] [comments]
reddit
How to Bypass FRP in android?
Posted in r/hacking by u/Dr_FUHRER • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Cyber Criminal Try Exploit ‘PrintNightmare’ Flaws in Ransomware to Top Companies
https://cdn-images-1.medium.com/max/1024/1*vEijaqsf54Nyx5UBbm9jXg.jpeg
Security investigators at Cisco Talos and CrowdStrike tracked down gangs trying to exploit bugs on Microsoft Windows called…
Continue reading on Medium »
Cyber Criminal Try Exploit ‘PrintNightmare’ Flaws in Ransomware to Top Companies
https://cdn-images-1.medium.com/max/1024/1*vEijaqsf54Nyx5UBbm9jXg.jpeg
Security investigators at Cisco Talos and CrowdStrike tracked down gangs trying to exploit bugs on Microsoft Windows called…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Utilities and VSCode Extensions to Make Developer’s Life Easier
https://cdn-images-1.medium.com/max/1920/1*0jxLUqJdXEvbmZMUI450yg.jpeg
Utilities and VSCode extensions to make developer’s life easier.
Continue reading on Medium »
Utilities and VSCode Extensions to Make Developer’s Life Easier
https://cdn-images-1.medium.com/max/1920/1*0jxLUqJdXEvbmZMUI450yg.jpeg
Utilities and VSCode extensions to make developer’s life easier.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Port scanner
https://cdn-images-1.medium.com/max/1200/1*DXqoxSy4Rqih3no2_LhWxA.png
Port scanning é uma técnica em que consiste procurar possíveis portas abertas em um host; Quando você acessa algum site, acaba permitindo…
Continue reading on Medium »
Port scanner
https://cdn-images-1.medium.com/max/1200/1*DXqoxSy4Rqih3no2_LhWxA.png
Port scanning é uma técnica em que consiste procurar possíveis portas abertas em um host; Quando você acessa algum site, acaba permitindo…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Nmap for Pentester: Dictionary Attack
We will process the showcase for Nmap Brute NSE Script for dictionary attack in this article since Nmap is such a large tool that it can't be covered in one post.
If you're wondering whether or not a brute-force assault using Nmap is doable.<o:p
Yes, Nmap includes an NSE-based script that can perform dictionary brute force attacks on secured services.<o:p Table of Contents<o:p· FTP Brute Force<o:p
· SSH Brute Force<o:p
· Telnet Brute Force<o:p
· SMB Brute Force<o:p
· Pqsql Brute Force<o:p
· HTTP-form-brute Brute Force<o:p
The Nmap Scripting Engine (NSE) is one of Nmap's most powerful and flexible features. It allows users to write (and share) simple scripts to automate a wide variety of networking tasks. Those scripts are then executed in parallel with the speed and efficiency you expect from Nmap. The core of the Nmap Scripting Engine is an embeddable Lua interpreter. The second part of the Nmap Scripting Engine is the NSE Library, which connects Lua and Nmap.<o:p
NSE scripts define a list of categories they belong to. Currently defined categories are auth, broadcast, brute, default. discovery, dos, exploit, external, fuzzer, intrusive, malware, safe, version, and vuln. <o:p
But I mentioned above that in this we will demonstrating the Nmap Brute script. These scripts use brute force attacks to guess the authentication credentials of a remote server. Nmap contains scripts for brute-forcing dozens of protocols, including HTTP-brute, oracle-brute, SNMP-brute, etc.<o:p
To list all nse scripts for brute forces :<o:p
locate *.nse |grep Brute<o:p https://1.bp.blogspot.com/-ysPdk6NP3fE/YRjb26vAHOI/AAAAAAAAyLo/s7o1e2o3HBYDY_5pTP0neCFeAbRkcM_hgCLcBGAsYHQ/s16000/1.png Simply specify -sCto enable the most common scripts. Or specify the --scriptoption to choose your scripts to execute by providing categories, script file names, or the name of directories full of scripts you wish to execute. You can customize some scripts by providing arguments to them via --script-argsand --script-args-fileoptions.<o:p FTP Brute Force<o:pPerforms brute force password auditing against FTP servers. All we need are dictionaries for usernames and passwords, which will be passed as arguments.<o:p
nmap -p21 --script ftp-brute.nse --script-args userdb=users.txt,passdb=pass.txt 192.168.1.150<o:p https://1.bp.blogspot.com/-a76kN7BTqts/YRjcHPaFV_I/AAAAAAAAyLw/3eJe8bf8r9URWOPEQewqE2xfRurPK_7rwCLcBGAsYHQ/s16000/2.png SSH Brute Force<o:pPerforms brute-force password guessing against ssh servers and connection timeout (default: "5s"). All we need are dictionaries for usernames and passwords, which will be passed as arguments.<o:p
nmap -p22 --script ssh-brute.nse --script-args userdb=users.txt,passdb=pass.txt 192.168.1.150<o:p https://1.bp.blogspot.com/-y7fTExpKpHA/YRjcStKdVDI/AAAAAAAAyL0/hbWSJsRhZX0SB7GY-lYQfMuJxA3-16pgACLcBGAsYHQ/s16000/3.png For valid username and password combination, it will dump the credential.<o:p https://1.bp.blogspot.com/-IlLKmj3jRqM/YRjcbOtgP5I/AAAAAAAAyL8/z4DYrstlxTk1xN4hnP28ijZBVlcXXikVgCLcBGAsYHQ/s16000/4.png Telnet Brute Force<o:pPerforms brute-force password auditing against telnet servers and connection timeout (default: "5s"). All we need are dictionaries for usernames and passwords, which will be passed as arguments.<o:p
nmap -p23 --script telnet-brute.nse --script-args userdb=users.txt,passdb=pass.txt 192.168.1.150<o:p https://1.bp.blogspot.com/-BDXqRGS4hhk/YRjcg8HPghI/AAAAAAAAyMA/ZQjyVecViIcws4HVQkToZLiYJvpDLj7gwCLcBGAsYHQ/s16000/5.png SMB Brute Force<o:pAttempts to guess SMB username/password combinations, saving identified combinations for use in other sc[...]
Nmap for Pentester: Dictionary Attack
We will process the showcase for Nmap Brute NSE Script for dictionary attack in this article since Nmap is such a large tool that it can't be covered in one post.
If you're wondering whether or not a brute-force assault using Nmap is doable.<o:p
Yes, Nmap includes an NSE-based script that can perform dictionary brute force attacks on secured services.<o:p Table of Contents<o:p· FTP Brute Force<o:p
· SSH Brute Force<o:p
· Telnet Brute Force<o:p
· SMB Brute Force<o:p
· Pqsql Brute Force<o:p
· HTTP-form-brute Brute Force<o:p
The Nmap Scripting Engine (NSE) is one of Nmap's most powerful and flexible features. It allows users to write (and share) simple scripts to automate a wide variety of networking tasks. Those scripts are then executed in parallel with the speed and efficiency you expect from Nmap. The core of the Nmap Scripting Engine is an embeddable Lua interpreter. The second part of the Nmap Scripting Engine is the NSE Library, which connects Lua and Nmap.<o:p
NSE scripts define a list of categories they belong to. Currently defined categories are auth, broadcast, brute, default. discovery, dos, exploit, external, fuzzer, intrusive, malware, safe, version, and vuln. <o:p
But I mentioned above that in this we will demonstrating the Nmap Brute script. These scripts use brute force attacks to guess the authentication credentials of a remote server. Nmap contains scripts for brute-forcing dozens of protocols, including HTTP-brute, oracle-brute, SNMP-brute, etc.<o:p
To list all nse scripts for brute forces :<o:p
locate *.nse |grep Brute<o:p https://1.bp.blogspot.com/-ysPdk6NP3fE/YRjb26vAHOI/AAAAAAAAyLo/s7o1e2o3HBYDY_5pTP0neCFeAbRkcM_hgCLcBGAsYHQ/s16000/1.png Simply specify -sCto enable the most common scripts. Or specify the --scriptoption to choose your scripts to execute by providing categories, script file names, or the name of directories full of scripts you wish to execute. You can customize some scripts by providing arguments to them via --script-argsand --script-args-fileoptions.<o:p FTP Brute Force<o:pPerforms brute force password auditing against FTP servers. All we need are dictionaries for usernames and passwords, which will be passed as arguments.<o:p
nmap -p21 --script ftp-brute.nse --script-args userdb=users.txt,passdb=pass.txt 192.168.1.150<o:p https://1.bp.blogspot.com/-a76kN7BTqts/YRjcHPaFV_I/AAAAAAAAyLw/3eJe8bf8r9URWOPEQewqE2xfRurPK_7rwCLcBGAsYHQ/s16000/2.png SSH Brute Force<o:pPerforms brute-force password guessing against ssh servers and connection timeout (default: "5s"). All we need are dictionaries for usernames and passwords, which will be passed as arguments.<o:p
nmap -p22 --script ssh-brute.nse --script-args userdb=users.txt,passdb=pass.txt 192.168.1.150<o:p https://1.bp.blogspot.com/-y7fTExpKpHA/YRjcStKdVDI/AAAAAAAAyL0/hbWSJsRhZX0SB7GY-lYQfMuJxA3-16pgACLcBGAsYHQ/s16000/3.png For valid username and password combination, it will dump the credential.<o:p https://1.bp.blogspot.com/-IlLKmj3jRqM/YRjcbOtgP5I/AAAAAAAAyL8/z4DYrstlxTk1xN4hnP28ijZBVlcXXikVgCLcBGAsYHQ/s16000/4.png Telnet Brute Force<o:pPerforms brute-force password auditing against telnet servers and connection timeout (default: "5s"). All we need are dictionaries for usernames and passwords, which will be passed as arguments.<o:p
nmap -p23 --script telnet-brute.nse --script-args userdb=users.txt,passdb=pass.txt 192.168.1.150<o:p https://1.bp.blogspot.com/-BDXqRGS4hhk/YRjcg8HPghI/AAAAAAAAyMA/ZQjyVecViIcws4HVQkToZLiYJvpDLj7gwCLcBGAsYHQ/s16000/5.png SMB Brute Force<o:pAttempts to guess SMB username/password combinations, saving identified combinations for use in other sc[...]
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles|Raj Chandel's Blog Nmap for Pentester: Dictionary Attack We will process the showcase for Nmap Brute NSE Script for dictionary attack in this article since Nmap is such a large tool that it can't be covered in one post. If you're wondering…
ripts. Every effort will be made to get a genuine list of users and to validate each username before utilizing them. When a username is identified, it is not only displayed but also kept in the Nmap registry for future use by other Nmap scripts. <o:p
All we need are dictionaries for usernames and passwords, which will be passed as arguments.<o:p
nmap -p445 --script smb-brute.nse --script-args userdb=users.txt,passdb=pass.txt 192.168.1.150<o:p https://1.bp.blogspot.com/-FruUgSTwlqc/YRjcl33fZ2I/AAAAAAAAyME/4fvWgR1Koq4QvuJ00JtZGg1Bn4PWKoSUgCLcBGAsYHQ/s16000/6.png Postgres Brute Force<o:pPerforms brute-force password auditing against telnet servers and connection timeout (default: "5s"). All we need are dictionaries for usernames and passwords, which will be passed as arguments.<o:p
nmap -p5432 --script pgsql-brute --script-args userdb=users.txt,passdb=pass.txt 192.168.1.150<o:p https://1.bp.blogspot.com/-zLh1ChMitQg/YRjcx5V0VVI/AAAAAAAAyMQ/9nPyduXiDIoWlPevWL23c_EG7XfK1jCnACLcBGAsYHQ/s16000/7.png Mysql Brute Force<o:pPerforms brute-force password auditing against Mysql servers and connection timeout (default: "5s"). All we need are dictionaries for usernames and passwords, which will be passed as arguments. <o:p
nmap -p3306 --script mysql-brute --script-args userdb=users.txt 192.168.1.150<o:p https://1.bp.blogspot.com/-ySD0vB7LfA8/YRjc7Ri7yOI/AAAAAAAAyMY/ccpl3Bjij2Yd5FgBOwDJmD3gmxsJbwZlACLcBGAsYHQ/s16000/8.png HTTP Brute Force<o:pPerforms brute force password auditing against HTTP form-based authentication. This script uses the unpwdb and brute libraries to perform password guessing. Any successful guesses are stored in the nmap registry, using the creds library, for other scripts to use.<o:p https://1.bp.blogspot.com/-QCuqpzXFc3M/YRjdZkpUdhI/AAAAAAAAyMk/5Y2Mv0knE-QPhx5S2NyY54CyB4HYSakrACLcBGAsYHQ/s16000/9.png nmap -p 80 --script=http-form-brute --script-args "userdb=users.txt,passdb=pass.txt,http-form-brute.path=/dvwa/login.php" 192.168.1.150<o:p https://1.bp.blogspot.com/-j9xT9QxZGvM/YRjdgi4SfUI/AAAAAAAAyMs/GlVGV3VKKVQppIOxNoK814J3RqzKfERiwCLcBGAsYHQ/s16000/10.png Ms-SQL Brute Force<o:pPerforms brute-force password auditing against Ms-SQL servers and connection timeout (default: "5s"). All we need are dictionaries for usernames and passwords, which will be passed as arguments. <o:p
nmap -p1433 --script ms-sql-brute --script-args userdb=users.txt,passdb=pass.txt 192.168.1.146<o:p https://1.bp.blogspot.com/--xtuvDT2T2k/YRjdsAPQfxI/AAAAAAAAyM0/pGAj5VbypN4zRKywS33VfwuaJ9IsZKHEQCLcBGAsYHQ/s16000/12.png Refence: https://nmap.org/book/nse-usage.html#nse-categories https://nmap.org/nsedoc/scripts/http-form-brute.html<o:p
All we need are dictionaries for usernames and passwords, which will be passed as arguments.<o:p
nmap -p445 --script smb-brute.nse --script-args userdb=users.txt,passdb=pass.txt 192.168.1.150<o:p https://1.bp.blogspot.com/-FruUgSTwlqc/YRjcl33fZ2I/AAAAAAAAyME/4fvWgR1Koq4QvuJ00JtZGg1Bn4PWKoSUgCLcBGAsYHQ/s16000/6.png Postgres Brute Force<o:pPerforms brute-force password auditing against telnet servers and connection timeout (default: "5s"). All we need are dictionaries for usernames and passwords, which will be passed as arguments.<o:p
nmap -p5432 --script pgsql-brute --script-args userdb=users.txt,passdb=pass.txt 192.168.1.150<o:p https://1.bp.blogspot.com/-zLh1ChMitQg/YRjcx5V0VVI/AAAAAAAAyMQ/9nPyduXiDIoWlPevWL23c_EG7XfK1jCnACLcBGAsYHQ/s16000/7.png Mysql Brute Force<o:pPerforms brute-force password auditing against Mysql servers and connection timeout (default: "5s"). All we need are dictionaries for usernames and passwords, which will be passed as arguments. <o:p
nmap -p3306 --script mysql-brute --script-args userdb=users.txt 192.168.1.150<o:p https://1.bp.blogspot.com/-ySD0vB7LfA8/YRjc7Ri7yOI/AAAAAAAAyMY/ccpl3Bjij2Yd5FgBOwDJmD3gmxsJbwZlACLcBGAsYHQ/s16000/8.png HTTP Brute Force<o:pPerforms brute force password auditing against HTTP form-based authentication. This script uses the unpwdb and brute libraries to perform password guessing. Any successful guesses are stored in the nmap registry, using the creds library, for other scripts to use.<o:p https://1.bp.blogspot.com/-QCuqpzXFc3M/YRjdZkpUdhI/AAAAAAAAyMk/5Y2Mv0knE-QPhx5S2NyY54CyB4HYSakrACLcBGAsYHQ/s16000/9.png nmap -p 80 --script=http-form-brute --script-args "userdb=users.txt,passdb=pass.txt,http-form-brute.path=/dvwa/login.php" 192.168.1.150<o:p https://1.bp.blogspot.com/-j9xT9QxZGvM/YRjdgi4SfUI/AAAAAAAAyMs/GlVGV3VKKVQppIOxNoK814J3RqzKfERiwCLcBGAsYHQ/s16000/10.png Ms-SQL Brute Force<o:pPerforms brute-force password auditing against Ms-SQL servers and connection timeout (default: "5s"). All we need are dictionaries for usernames and passwords, which will be passed as arguments. <o:p
nmap -p1433 --script ms-sql-brute --script-args userdb=users.txt,passdb=pass.txt 192.168.1.146<o:p https://1.bp.blogspot.com/--xtuvDT2T2k/YRjdsAPQfxI/AAAAAAAAyM0/pGAj5VbypN4zRKywS33VfwuaJ9IsZKHEQCLcBGAsYHQ/s16000/12.png Refence: https://nmap.org/book/nse-usage.html#nse-categories https://nmap.org/nsedoc/scripts/http-form-brute.html<o:p
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
Nmap for Pentester: Password Cracking
We will process the showcase for Nmap Brute NSE Script for dictionary attack in this article since Nmap is such a large tool that it can’t be covered in one post. If you’re wondering whether or not a brute-force assault using Nmap is doable. Yes, Nmap includes an NSE-based script
The post Nmap for Pentester: Password Cracking appeared first on Hacking Articles.
Nmap for Pentester: Password Cracking
We will process the showcase for Nmap Brute NSE Script for dictionary attack in this article since Nmap is such a large tool that it can’t be covered in one post. If you’re wondering whether or not a brute-force assault using Nmap is doable. Yes, Nmap includes an NSE-based script
The post Nmap for Pentester: Password Cracking appeared first on Hacking Articles.
hacking: security in practice
Fileviewpro
Can I trust fileviewpro,I have a bunch of crypt12 files that I need to open. So, I'm thinking of downloading fileviewpro.
submitted by /u/risheath
[link] [comments]
Fileviewpro
Can I trust fileviewpro,I have a bunch of crypt12 files that I need to open. So, I'm thinking of downloading fileviewpro.
submitted by /u/risheath
[link] [comments]
reddit
Fileviewpro
Can I trust fileviewpro,I have a bunch of crypt12 files that I need to open. So, I'm thinking of downloading fileviewpro.
hacking: security in practice
OSCP THM HTB
hey guys!
I want to take the THM pentest+ and OSCP path for become a better at PT and start to do CTF in HTB for prepare to the OSCP exam.
Would you recommend to me to do this? does THM would make me ready? what do you think about that?
Thanks guys!
submitted by /u/Puzzleheaded-Bird-30
[link] [comments]
OSCP THM HTB
hey guys!
I want to take the THM pentest+ and OSCP path for become a better at PT and start to do CTF in HTB for prepare to the OSCP exam.
Would you recommend to me to do this? does THM would make me ready? what do you think about that?
Thanks guys!
submitted by /u/Puzzleheaded-Bird-30
[link] [comments]
reddit
OSCP THM HTB
hey guys! I want to take the THM pentest+ and OSCP path for become a better at PT and start to do CTF in HTB for prepare to the OSCP exam. Would...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Tko-Subs - A Tool That Can Help Detect And Takeover Subdomains With Dead DNS Records
https://1.bp.blogspot.com/-xkHEQwETQ-k/YRIUN6igf9I/AAAAAAAAptQ/5OQv9-YtJ-0RqpIExQ0LiFPUFgP2j8J-gCNcBGAsYHQ/w640-h426/tko-subs.png This tool allows:
*
To check whether a subdomain can be taken over because it has:
* a dangling CNAME pointing to a CMS provider (Heroku, Github, Shopify, Amazon S3, Amazon CloudFront, etc.) that can be taken over.
* a dangling CNAME pointing to a non-existent domain name
* one or more wrong/typoed NS records pointing to a nameserver that can be taken over by an attacker to gain control of the subdomain's DNS records
*
To actually take over those subdomain by providing a flag
*
To specify your own CMS providers and check for them via the providers-data.csv file. In that file, you would mention the CMS name, their CNAME value, their string that you want to look for and whether it only works over HTTP or not. Check it out for some examples. Disclaimer: DONT BE A JERK!Needless to mention, please use this tool very very carefully. The authors won't be responsible for any consequences. By default, this tool does not allow taking over of subdomains. If you want to do it, just specify the
Once the tool is downloaded, type
The next thing we need to do is to get the following information:
* Github's Personal Access Token - Make sure this token has the rights to create repositories, references, contents, etc. You can create this token here - https://github.com/settings/tokens
* Heroku Username and API key
* Heroku app name - You can create a static app on Heroku with whatever you want to be displayed on its homepage by following the instructions here - https://gist.github.com/wh1tney/2ad13aa5fbdd83f6a489. Once you create that app, use that app name in the flag (see below). We will use that app to takeover the domain (with the dangling CNAME to another Heroku app).
NOTE - You only need these values if you want to take over subdomains. By default, that's not required.
Required Go Packages to build.
* the
* the
Tko-Subs - A Tool That Can Help Detect And Takeover Subdomains With Dead DNS Records
https://1.bp.blogspot.com/-xkHEQwETQ-k/YRIUN6igf9I/AAAAAAAAptQ/5OQv9-YtJ-0RqpIExQ0LiFPUFgP2j8J-gCNcBGAsYHQ/w640-h426/tko-subs.png This tool allows:
*
To check whether a subdomain can be taken over because it has:
* a dangling CNAME pointing to a CMS provider (Heroku, Github, Shopify, Amazon S3, Amazon CloudFront, etc.) that can be taken over.
* a dangling CNAME pointing to a non-existent domain name
* one or more wrong/typoed NS records pointing to a nameserver that can be taken over by an attacker to gain control of the subdomain's DNS records
*
To actually take over those subdomain by providing a flag
-takeover. Currently, take over is only supported for Github Pages and Heroku Apps and by default the take over functionality is off.*
To specify your own CMS providers and check for them via the providers-data.csv file. In that file, you would mention the CMS name, their CNAME value, their string that you want to look for and whether it only works over HTTP or not. Check it out for some examples. Disclaimer: DONT BE A JERK!Needless to mention, please use this tool very very carefully. The authors won't be responsible for any consequences. By default, this tool does not allow taking over of subdomains. If you want to do it, just specify the
-takeoverflag. Pre-requisitesWe need GO installed. Once you have GO, just type go get github.com/anshumanbh/tko-substo download the tool.Once the tool is downloaded, type
tko-subs -h.The next thing we need to do is to get the following information:
* Github's Personal Access Token - Make sure this token has the rights to create repositories, references, contents, etc. You can create this token here - https://github.com/settings/tokens
* Heroku Username and API key
* Heroku app name - You can create a static app on Heroku with whatever you want to be displayed on its homepage by following the instructions here - https://gist.github.com/wh1tney/2ad13aa5fbdd83f6a489. Once you create that app, use that app name in the flag (see below). We will use that app to takeover the domain (with the dangling CNAME to another Heroku app).
NOTE - You only need these values if you want to take over subdomains. By default, that's not required.
Required Go Packages to build.
go get github.com/bgentry/heroku-go
go get github.com/gocarina/gocsv
go get github.com/google/go-github/github
go get github.com/olekukonko/tablewriter
go get golang.org/x/net/publicsuffix
go get golang.org/x/oauth2
go get github.com/miekg/dns How to run?Once you have everything installed, cdinto the directory and type: tko-subs -domains=domains.txt -data=providers-data.csv -output=output.csvIf you want to take over as well, the command would be: tko-subs -domains=domains.txt -data=providers-data.csv -output=output.csv -takeover -githubtoken=<github-token -herokuusername=<heroku-username -herokuapikey=<heroku-api-key -herokuappname=<heroku-app-nameIf you just want to check for a single domain, type: tko-subs -domain <domain-nameIf you just want to check for multiple domains, type: tko-subs -domain <domain-name-1,<domain-name-2By default:* the
domainsflag is set to domains.txt* the dataflag is set to providers-data.csv* the outputflag is set to output.csv* the takeoverflag is not set so no take over by default* the
domainflag is NOT set so it will always check for all the domains mentioned in the domains.txtfile. If the domainflag is mentioned, it will only check that domain [...]
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! Tko-Subs - A Tool That Can Help Detect And Takeover Subdomains With Dead DNS Records https://1.bp.blogspot.com/-xkHEQwETQ-k/YRIUN6igf9I/AAAAAAAAptQ/5OQv9-YtJ-0RqpIExQ0LiFPUFgP2j8J-gCNcBGAsYHQ/w640-h426/tko-subs.png This tool allows:…
and ignore the
* the
* name: The name of the provider (e.g. github)
* cname: The CNAME used to map a website to the provider's content (e.g. github.io)
* string: The error message returned for an unclaimed subdomain (e.g. "There isn't a GitHub Pages site here")
* http: Whether to use http (not https, which is the default) to connect to the site (true/false) How is the output formatted?Domain,CNAME,Provider,IsVulnerable,IsTakenOver,Response
* Domain: The domain checked
* CNAME: The CNAME of the domain
* Provider: The provider the domain was found to be using
* IsVulnerable: Whether the domain was found to be vulnerable or not (true/false)
* IsTakenOver: Whether the domain was taken over or not (true/false)
* Response: The message that the subdomain was checked against
If a dead DNS record is found,
* See if they have a misbehaving authoritative nameserver; if they do, we mark that domain as vulnerable.
* See if they have dangling CNAME records aka dead DNS records; if they do we mark that domain as vulnerable.
* If a subdomain passes these two tests, it tries to curl them and get back a response and then try to see if that response matches any of the data provider strings mentioned in the providers-data.csv file.
* If the response matches, we mark that domain as vulnerable.
* Next, depending upon whether the
* For example, to takeover a Github Page, the code will:
* Create a repo
* Create a branch
* Upload
* Similarly, for Heroku apps, the code will:
* Add the dangling domain to your Heroku app (whose name you will be providing in the .env file)
* And, that's it! Future Work* Take CMS name and regex from user or .env file and then automatically hook them into the tool to be able to find it. DONE
* Add takeovers for more CMS
* Add more CMS providers Credits* Thanks to Luke Young (@TheBoredEng) for helping me out with the go-github library.
* Thanks to Frans Rosen (@fransrosen) for helping me understand the technical details that are required for some of the takeovers.
* Thanks to Mohammed Diaa (@mhmdiaa) for taking time to implement the provider data functionality and getting the code going.
* Thanks to high-stakes for a much needed code refresh. Changelog
* Added sample domains.txt file to test against
* mhmdiaa added the logic for dead DNS takeovers. Updated documentation. Thanks a lot!
* Made it easier to install and run
* Instead of checking using Golang's net packages' LookupCNAME function, made it to just use dig since that gives you dead DNS records as well. More attack surface!! Download Tko-Subs
domains.txtfile, even if present* the
threadsflag is set to 5So, simply running tko-subswould run with the default values mentioned above. How is providers-data.csv formatted?name,cname,string,http* name: The name of the provider (e.g. github)
* cname: The CNAME used to map a website to the provider's content (e.g. github.io)
* string: The error message returned for an unclaimed subdomain (e.g. "There isn't a GitHub Pages site here")
* http: Whether to use http (not https, which is the default) to connect to the site (true/false) How is the output formatted?Domain,CNAME,Provider,IsVulnerable,IsTakenOver,Response
* Domain: The domain checked
* CNAME: The CNAME of the domain
* Provider: The provider the domain was found to be using
* IsVulnerable: Whether the domain was found to be vulnerable or not (true/false)
* IsTakenOver: Whether the domain was taken over or not (true/false)
* Response: The message that the subdomain was checked against
If a dead DNS record is found,
Provideris left empty. If a misbehaving nameserver is found, Providerand CNAMEare left empty What is going on under the hood?This will iterate over all the domains (concurrently using GoRoutines) in the subdomains.txtfile and:* See if they have a misbehaving authoritative nameserver; if they do, we mark that domain as vulnerable.
* See if they have dangling CNAME records aka dead DNS records; if they do we mark that domain as vulnerable.
* If a subdomain passes these two tests, it tries to curl them and get back a response and then try to see if that response matches any of the data provider strings mentioned in the providers-data.csv file.
* If the response matches, we mark that domain as vulnerable.
* Next, depending upon whether the
takeoverflag is mentioned or not, it will try to take over that vulnerable subdomain.* For example, to takeover a Github Page, the code will:
* Create a repo
* Create a branch
gh-pagesin that repo* Upload
CNAMEand index.htmlto the gh-pagesbranch in that repo. Here, CNAMEcontains the domain that needs to be taken over. index.htmlcontains the text This domain is temporarily suspendedthat is to be displayed once the domain is taken over.* Similarly, for Heroku apps, the code will:
* Add the dangling domain to your Heroku app (whose name you will be providing in the .env file)
* And, that's it! Future Work* Take CMS name and regex from user or .env file and then automatically hook them into the tool to be able to find it. DONE
* Add takeovers for more CMS
* Add more CMS providers Credits* Thanks to Luke Young (@TheBoredEng) for helping me out with the go-github library.
* Thanks to Frans Rosen (@fransrosen) for helping me understand the technical details that are required for some of the takeovers.
* Thanks to Mohammed Diaa (@mhmdiaa) for taking time to implement the provider data functionality and getting the code going.
* Thanks to high-stakes for a much needed code refresh. Changelog
5/27* Added new Dockerfile reducing the size of the image* Added sample domains.txt file to test against
* mhmdiaa added the logic for dead DNS takeovers. Updated documentation. Thanks a lot!
11/6* high-stakes issues a PR with a bunch of new code that fixes a few bugs and makes the code cleaner 9/22* Added an optional flag to check for single domain* Made it easier to install and run
6/25* Made the code much more faster by implementing goroutines* Instead of checking using Golang's net packages' LookupCNAME function, made it to just use dig since that gives you dead DNS records as well. More attack surface!! Download Tko-Subs