Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Security researcher finds exposed endpoint with DHS terrorist watchlist containing nearly 2 million records
https://external-preview.redd.it/-xxG05tWKKSEQWGMKP8lagDDtYms_FCcrFgZsr-mx8Q.jpg?width=640&crop=smart&auto=webp&s=eb79cb70008a38aff32c082c26df5016e45c0f1b submitted by /u/selfagency
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Security researcher finds exposed endpoint with DHS terrorist watchlist containing nearly 2 million records
https://external-preview.redd.it/-xxG05tWKKSEQWGMKP8lagDDtYms_FCcrFgZsr-mx8Q.jpg?width=640&crop=smart&auto=webp&s=eb79cb70008a38aff32c082c26df5016e45c0f1b submitted by /u/selfagency
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Security researcher finds exposed endpoint with DHS terrorist...
Posted in r/hacking by u/selfagency • 1 point and 0 comments
hacking: security in practice
How to control multiple drones?
So I saw a video form Michael Reeves where he took control of a bunch of drones. But of course he’s skips thro the explanation stuff so I’m confused on wha he meant. It’s looked like he was ssh or Telnetting into each drone, and giving them all the same ip or something, and then using the router as a way to register all the drones so that that doesn’t mess them up? I don’t know.
submitted by /u/lt_Matthew
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to control multiple drones?
So I saw a video form Michael Reeves where he took control of a bunch of drones. But of course he’s skips thro the explanation stuff so I’m confused on wha he meant. It’s looked like he was ssh or Telnetting into each drone, and giving them all the same ip or something, and then using the router as a way to register all the drones so that that doesn’t mess them up? I don’t know.
submitted by /u/lt_Matthew
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to control multiple drones?
So I saw a video form Michael Reeves where he took control of a bunch of drones. But of course he’s skips thro the explanation stuff so I’m...
hacking: security in practice
Recovering deleted Telegram data
I'm requesting a professional to assist me to recover a deleted telegram chat. I accidentally deleted a telegram chat for my partner, and it contains years of content/information.
I've tried exporting telegram data, but as I had deleted the chat twice, it doesn't show anything now.
Is anyone able to recover said chat from the cloud if possible? I am willing to compensate as needed.
submitted by /u/ganymedeocean
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Recovering deleted Telegram data
I'm requesting a professional to assist me to recover a deleted telegram chat. I accidentally deleted a telegram chat for my partner, and it contains years of content/information.
I've tried exporting telegram data, but as I had deleted the chat twice, it doesn't show anything now.
Is anyone able to recover said chat from the cloud if possible? I am willing to compensate as needed.
submitted by /u/ganymedeocean
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Recovering deleted Telegram data
I'm requesting a professional to assist me to recover a deleted telegram chat. I accidentally deleted a telegram chat for my partner, and it...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
API Security : Lack of Resources & Rate Limiting
https://cdn-images-1.medium.com/max/678/1*ehreVNLv9WABd8v_Ev8ACA.png
What is Application Programming Interface/API?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
API Security : Lack of Resources & Rate Limiting
https://cdn-images-1.medium.com/max/678/1*ehreVNLv9WABd8v_Ev8ACA.png
What is Application Programming Interface/API?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
API Security : Lack of Resources & Rate Limiting
What is Application Programming Interface/API?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HACK SCHOOL GRADES
https://cdn-images-1.medium.com/max/600/1*OlE3bT_82Lg-U01Q9ugZhg.jpeg
Email: cyberforcehackers@gmail.com
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
HACK SCHOOL GRADES
https://cdn-images-1.medium.com/max/600/1*OlE3bT_82Lg-U01Q9ugZhg.jpeg
Email: cyberforcehackers@gmail.com
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
HACK SCHOOL GRADES
Email: cyberforcehackers@gmail.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Has Your Mind Been Hacked? Check These Things.
https://cdn-images-1.medium.com/max/1728/1*zLB4JPjpwe4lNc6cFUF3bw.jpeg
First of all, when your mind is hacked, you won’t exactly know it so it’s sort of tricky to figure it out and even trickier to do…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Has Your Mind Been Hacked? Check These Things.
https://cdn-images-1.medium.com/max/1728/1*zLB4JPjpwe4lNc6cFUF3bw.jpeg
First of all, when your mind is hacked, you won’t exactly know it so it’s sort of tricky to figure it out and even trickier to do…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Has Your Mind Been Hacked? Check These Things.
First of all, when your mind is hacked, you won’t exactly know it so it’s sort of tricky to figure it out and even trickier to do something…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
[THM] Chronicle — Fuzzing, Firefox et BufferOverflow
https://cdn-images-1.medium.com/max/600/1*bocHn5ej_CcM6UOU2qEoRg.png
Nouvelle machine sur TryHackMe : Chronicle. Dans le cadre de cette machine, plusieurs techniques nouvelles pour moi et de nouvelles…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
[THM] Chronicle — Fuzzing, Firefox et BufferOverflow
https://cdn-images-1.medium.com/max/600/1*bocHn5ej_CcM6UOU2qEoRg.png
Nouvelle machine sur TryHackMe : Chronicle. Dans le cadre de cette machine, plusieurs techniques nouvelles pour moi et de nouvelles…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
[THM] Chronicle — Fuzzing, Firefox et BufferOverflow
Nouvelle machine sur TryHackMe : Chronicle. Dans le cadre de cette machine, plusieurs techniques nouvelles pour moi et de nouvelles…
XLMMacroDeobfuscator - Extract And Deobfuscate XLM Macros (A.K.A Excel 4.0 Macros)
http://www.kitploit.com/2021/08/xlmmacrodeobfuscator-extract-and.html
http://www.kitploit.com/2021/08/xlmmacrodeobfuscator-extract-and.html
XLMMacroDeobfuscator can be used to decode (https://www.kitploit.com/search/label/Decode) obfuscated XLM macros (also known as Excel 4.0 macros). It utilizes an internal XLM emulator (https://www.kitploit.com/search/label/Emulator) to interpret the macros, without fully performing the code. It supports both xls, xlsm, and xlsb formats. It uses xlrd2 (https://github.com/DissectMalware/xlrd2), pyxlsb2 (https://github.com/DissectMalware/pyxlsb2) and its own parser to extract cells and other information from xls, xlsb and xlsm files, respectively. You can also find XLM grammar in xlm-macro-lark.template (https://github.com/DissectMalware/XLMMacroDeobfuscator/blob/master/XLMMacroDeobfuscator/xlm-macro.lark.template)
Installing the emulator
Install using pip pip install XLMMacroDeobfuscator
Installing the latest development pip install -U https://github.com/DissectMalware/xlrd2/archive/master.zip
pip install -U https://github.com/DissectMalware/pyxlsb2/archive/master.zip
pip install -U https://github.com/DissectMalware/XLMMacroDeobfuscator/archive/master.zip
Running the emulator
To deobfuscate (https://www.kitploit.com/search/label/Deobfuscate) macros in Excel documents: xlmdeobfuscator --file document.xlsm
To only get the deobfuscated macros and without any indentation: xlmdeobfuscator --file document.xlsm --no-indent --output-formula-format "[[INT-FORMULA]]"
To export the output in JSON format xlmdeobfuscator --file document.xlsm --export-json result.json
To see a sample JSON output, please check this link (https://pastebin.com/bwmS7mi0) out. To use a config file xlmdeobfuscator --file document.xlsm -c default.config
default.config file must be a valid json file, such as: {
"no-indent": true,
"output-formula-format": "[[CELL-ADDR]] [[INT-FORMULA]]",
"non-interactive": true,
"output-level": 1
}
Command Line
emulation after N seconds (0: not interruption N>0: stop emulation after N seconds) ">
_ _______
|\ /|( \ ( )
( \ / )| ( | () () |
\ (_) / | | | || || |
) _ ( | | | |(_)| |
/ ( ) \ | | | | | |
( / \ )| (____/\| ) ( |
|/ \|(_______/|/ \|
______ _______ _______ ______ _______ _______ _______ _______ _________ _______ _______
( __ \ ( ____ \( ___ )( ___ \ ( ____ \|\ /|( ____ \( ____ \( ___ )\__ __/( ___ )( ____ )
| ( \ )| ( \/| ( ) || ( ) )| ( \/| ) ( || ( \/| ( \/| ( ) | ) ( | ( ) || ( )|
| | ) || (__ | | | || (__/ / | (__ | | | || (_____ | | | (___) | | | | | | || (____)|
| | | || __) | | | || __ ( | __) | | | |(_____ )| | | ___ | | | | | | || __)
| | ) || ( | | | || ( \ \ | ( | | | | ) || | | ( ) | | | | | | || (\ (
| (__/ )| (____/\| (___) || )___) )| ) | (___) |/\____) || (____/\| ) ( | | | | (___) || ) \ \__
(______/ (_______/(_______)|/ \___/ |/ (_______)\_______)(_______/|/ \| )_( (_______)|/ \__/
XLMMacroDeobfuscator(v0.1.7) - https://github.com/DissectMalware/XLMMacroDeobfuscator
usage: deobfuscator.py [-h] [-c FILE_PATH] [-f FILE_PATH] [-n] [-x] [-2]
[--with-ms-excel] [-s] [-d DAY]
[--output-formula-format OUTPUT_FORMULA_FORMAT]
[--no-indent] [--export-json FILE_PATH]
[--start-point CELL_ADDR] [-p PASSWORD]
[-o OUTPUT_LEVEL]
optional arguments:
-h, --help show this help message and exit
-c FILE_PATH, --config_file FILE_PATH
Specify a config file (must be a valid JSON file)
-f FILE_PATH, --file FILE_PATH
The path of a XLSM file
-n , --noninteractive Disable interactive shell
-x, --extract-only Only extract cells without any emulation
Installing the emulator
Install using pip pip install XLMMacroDeobfuscator
Installing the latest development pip install -U https://github.com/DissectMalware/xlrd2/archive/master.zip
pip install -U https://github.com/DissectMalware/pyxlsb2/archive/master.zip
pip install -U https://github.com/DissectMalware/XLMMacroDeobfuscator/archive/master.zip
Running the emulator
To deobfuscate (https://www.kitploit.com/search/label/Deobfuscate) macros in Excel documents: xlmdeobfuscator --file document.xlsm
To only get the deobfuscated macros and without any indentation: xlmdeobfuscator --file document.xlsm --no-indent --output-formula-format "[[INT-FORMULA]]"
To export the output in JSON format xlmdeobfuscator --file document.xlsm --export-json result.json
To see a sample JSON output, please check this link (https://pastebin.com/bwmS7mi0) out. To use a config file xlmdeobfuscator --file document.xlsm -c default.config
default.config file must be a valid json file, such as: {
"no-indent": true,
"output-formula-format": "[[CELL-ADDR]] [[INT-FORMULA]]",
"non-interactive": true,
"output-level": 1
}
Command Line
emulation after N seconds (0: not interruption N>0: stop emulation after N seconds) ">
_ _______
|\ /|( \ ( )
( \ / )| ( | () () |
\ (_) / | | | || || |
) _ ( | | | |(_)| |
/ ( ) \ | | | | | |
( / \ )| (____/\| ) ( |
|/ \|(_______/|/ \|
______ _______ _______ ______ _______ _______ _______ _______ _________ _______ _______
( __ \ ( ____ \( ___ )( ___ \ ( ____ \|\ /|( ____ \( ____ \( ___ )\__ __/( ___ )( ____ )
| ( \ )| ( \/| ( ) || ( ) )| ( \/| ) ( || ( \/| ( \/| ( ) | ) ( | ( ) || ( )|
| | ) || (__ | | | || (__/ / | (__ | | | || (_____ | | | (___) | | | | | | || (____)|
| | | || __) | | | || __ ( | __) | | | |(_____ )| | | ___ | | | | | | || __)
| | ) || ( | | | || ( \ \ | ( | | | | ) || | | ( ) | | | | | | || (\ (
| (__/ )| (____/\| (___) || )___) )| ) | (___) |/\____) || (____/\| ) ( | | | | (___) || ) \ \__
(______/ (_______/(_______)|/ \___/ |/ (_______)\_______)(_______/|/ \| )_( (_______)|/ \__/
XLMMacroDeobfuscator(v0.1.7) - https://github.com/DissectMalware/XLMMacroDeobfuscator
usage: deobfuscator.py [-h] [-c FILE_PATH] [-f FILE_PATH] [-n] [-x] [-2]
[--with-ms-excel] [-s] [-d DAY]
[--output-formula-format OUTPUT_FORMULA_FORMAT]
[--no-indent] [--export-json FILE_PATH]
[--start-point CELL_ADDR] [-p PASSWORD]
[-o OUTPUT_LEVEL]
optional arguments:
-h, --help show this help message and exit
-c FILE_PATH, --config_file FILE_PATH
Specify a config file (must be a valid JSON file)
-f FILE_PATH, --file FILE_PATH
The path of a XLSM file
-n , --noninteractive Disable interactive shell
-x, --extract-only Only extract cells without any emulation
-2, --no-ms-excel [Deprecated] Do not use MS Excel to process XLS files
--with-ms-excel Use MS Excel to process XLS files
-s, --start-with-shell
Open an XLM shell before interpreting the macros in
the input
-d DAY, --day DAY Specify the day of month
--output-formula-format OUTPUT_FORMULA_FORMAT
Specify the format for output formulas ([[CELL-ADDR]],
[[INT-FORMULA]], and [[STATUS]]
--no-indent Do not show indent before formulas
--export-json FILE_PATH
Export the output to JSON
--start-point CELL_ADDR
Start interpretation from a specific cell address
-p PASSWORD, --password PASSWORD
Password to decrypt t he protected document
-o OUTPUT_LEVEL, --output-level OUTPUT_LEVEL
Set the level of details to be shown (0:all commands,
1: commands no jump 2:important commands 3:strings in
important commands).
--timeout N stop emulation after N seconds (0: not interruption
N>0: stop emulation after N seconds)
Library
The following example shows how XLMMacroDeobfuscator can be used in a python project to deobfuscate XLM macros: from XLMMacroDeobfuscator.deobfuscator import process_file
result = process_file(file='path/to/an/excel/file',
noninteractive= True,
noindent= True,
output_formula_format='[[CELL-ADDR]], [[INT-FORMULA]]',
return_deobfuscated= True,
timeout= 30)
for record in result:
print(record) note: the xlmdeofuscator logo will not be shown when you use it as a library
Requirements
Please read requirements.txt to get the list of python libraries that XLMMacroDeobfuscator is dependent on. xlmdeobfuscator can be executed on any OS to extract and deobfuscate macros in xls, xlsm, and xlsb files. You do not need to install MS Excel. Note: if you want to use MS Excel (on Windows), you need to install pywin32 library (https://www.kitploit.com/search/label/Library) and use --with-ms-excel switch. If --with-ms-excel is used, xlmdeobfuscator, first, attempts to load xls files with MS Excel, if it fails it uses xlrd2 library (https://github.com/DissectMalware/xlrd2).
Project Using XLMMacroDeofuscator
XLMMacroDeofuscator is adopted in the following projects: CAPE Sandbox (https://github.com/ctxis/CAPE) FAME (https://certsocietegenerale.github.io/fame/) REMNUX (https://remnux.org/) IntelOwl (https://github.com/intelowlproject/IntelOwl) Assemblyline 4 (https://cybercentrecanada.github.io/assemblyline4_docs/) by Canadian Centre for Cyber Security Please contact me if you incorporated XLMMacroDeofuscator in your project.
How to Contribute
If you found a bug or would like to suggest an improvement, please create a new issue on the issues page (https://github.com/DissectMalware/XLMMacroDeobfuscator/issues). Feel free to contribute to the project forking the project and submitting a pull request. You can reach me (@DissectMlaware) on Twitter (https://twitter.com/DissectMalware) via a direct message.
Download XLMMacroDeobfuscator (https://github.com/DissectMalware/XLMMacroDeobfuscator)
--with-ms-excel Use MS Excel to process XLS files
-s, --start-with-shell
Open an XLM shell before interpreting the macros in
the input
-d DAY, --day DAY Specify the day of month
--output-formula-format OUTPUT_FORMULA_FORMAT
Specify the format for output formulas ([[CELL-ADDR]],
[[INT-FORMULA]], and [[STATUS]]
--no-indent Do not show indent before formulas
--export-json FILE_PATH
Export the output to JSON
--start-point CELL_ADDR
Start interpretation from a specific cell address
-p PASSWORD, --password PASSWORD
Password to decrypt t he protected document
-o OUTPUT_LEVEL, --output-level OUTPUT_LEVEL
Set the level of details to be shown (0:all commands,
1: commands no jump 2:important commands 3:strings in
important commands).
--timeout N stop emulation after N seconds (0: not interruption
N>0: stop emulation after N seconds)
Library
The following example shows how XLMMacroDeobfuscator can be used in a python project to deobfuscate XLM macros: from XLMMacroDeobfuscator.deobfuscator import process_file
result = process_file(file='path/to/an/excel/file',
noninteractive= True,
noindent= True,
output_formula_format='[[CELL-ADDR]], [[INT-FORMULA]]',
return_deobfuscated= True,
timeout= 30)
for record in result:
print(record) note: the xlmdeofuscator logo will not be shown when you use it as a library
Requirements
Please read requirements.txt to get the list of python libraries that XLMMacroDeobfuscator is dependent on. xlmdeobfuscator can be executed on any OS to extract and deobfuscate macros in xls, xlsm, and xlsb files. You do not need to install MS Excel. Note: if you want to use MS Excel (on Windows), you need to install pywin32 library (https://www.kitploit.com/search/label/Library) and use --with-ms-excel switch. If --with-ms-excel is used, xlmdeobfuscator, first, attempts to load xls files with MS Excel, if it fails it uses xlrd2 library (https://github.com/DissectMalware/xlrd2).
Project Using XLMMacroDeofuscator
XLMMacroDeofuscator is adopted in the following projects: CAPE Sandbox (https://github.com/ctxis/CAPE) FAME (https://certsocietegenerale.github.io/fame/) REMNUX (https://remnux.org/) IntelOwl (https://github.com/intelowlproject/IntelOwl) Assemblyline 4 (https://cybercentrecanada.github.io/assemblyline4_docs/) by Canadian Centre for Cyber Security Please contact me if you incorporated XLMMacroDeofuscator in your project.
How to Contribute
If you found a bug or would like to suggest an improvement, please create a new issue on the issues page (https://github.com/DissectMalware/XLMMacroDeobfuscator/issues). Feel free to contribute to the project forking the project and submitting a pull request. You can reach me (@DissectMlaware) on Twitter (https://twitter.com/DissectMalware) via a direct message.
Download XLMMacroDeobfuscator (https://github.com/DissectMalware/XLMMacroDeobfuscator)
hacking: security in practice
Just fire a general manager! Like dude, dont even work here!
So I'm finished up with a job interview, I've git my hair gelled back, red business shirt, professional pants, shoes and belt. As I walk into the Walgreens, I can overhear a customer bitching and moaning about who knows what, typical male Karen.
I grab my shit and I go to check out, make Karen approaches me and demands I fire both the GM and the girl at the register who wouldn't help her.
I have nothing better to do, so i tell him I'm not in a position to fire her.
Guy keeps mouthing off talking about how since I'm dressed the way I am, either I own the place, or I'm her boss.
I'm holding back laughter at this point, and I ask the man what the problem is. Guy is causing shit over an expired coupon.
I roll my eyes and walk back to the counter, the GM starts to say something, but I tell her to zip it.
I punch a few keys on the keyboard and ask the customer his number, punching it in, I look to him and say "so here's whats gonna happen. Ive uploaded your photo to our central database, barred you from all Walgreens locations worldwide, and activated the silent alarm. You've got about 30 seconds to get out of here before you're arrested for trespassing.
The guy bolted.
Gm and cashiers are laughing they're asses off because they know none of it was true. I pay for my shit and leave.
Social engineering is fun.
submitted by /u/Captain-Crunch1989
[link] [comments]
Just fire a general manager! Like dude, dont even work here!
So I'm finished up with a job interview, I've git my hair gelled back, red business shirt, professional pants, shoes and belt. As I walk into the Walgreens, I can overhear a customer bitching and moaning about who knows what, typical male Karen.
I grab my shit and I go to check out, make Karen approaches me and demands I fire both the GM and the girl at the register who wouldn't help her.
I have nothing better to do, so i tell him I'm not in a position to fire her.
Guy keeps mouthing off talking about how since I'm dressed the way I am, either I own the place, or I'm her boss.
I'm holding back laughter at this point, and I ask the man what the problem is. Guy is causing shit over an expired coupon.
I roll my eyes and walk back to the counter, the GM starts to say something, but I tell her to zip it.
I punch a few keys on the keyboard and ask the customer his number, punching it in, I look to him and say "so here's whats gonna happen. Ive uploaded your photo to our central database, barred you from all Walgreens locations worldwide, and activated the silent alarm. You've got about 30 seconds to get out of here before you're arrested for trespassing.
The guy bolted.
Gm and cashiers are laughing they're asses off because they know none of it was true. I pay for my shit and leave.
Social engineering is fun.
submitted by /u/Captain-Crunch1989
[link] [comments]
reddit
Just fire a general manager! Like dude, dont even work here!
So I'm finished up with a job interview, I've git my hair gelled back, red business shirt, professional pants, shoes and belt. As I walk into the...
hacking: security in practice
international online masters degree in cybersecurity that doesnt cost a fortune?
while the pandemic is happening, i feel that im not doing anything productive in my life, so i want to possibly able to get an online masters degree in cybersecurity since i feel that the pandemic will still last a long time
i know there are a lot of online masters degree but they are really expensive and some do not accept international students.. i am also not a graduate of computer science / computer engineering or any IT related field
so any recommendations on international online masters degree in cybersecurity that doesnt cost a fortune?
also maybe you have recommendations for international online masters degree in computer science?
thanks
submitted by /u/darkalimdor18
[link] [comments]
international online masters degree in cybersecurity that doesnt cost a fortune?
while the pandemic is happening, i feel that im not doing anything productive in my life, so i want to possibly able to get an online masters degree in cybersecurity since i feel that the pandemic will still last a long time
i know there are a lot of online masters degree but they are really expensive and some do not accept international students.. i am also not a graduate of computer science / computer engineering or any IT related field
so any recommendations on international online masters degree in cybersecurity that doesnt cost a fortune?
also maybe you have recommendations for international online masters degree in computer science?
thanks
submitted by /u/darkalimdor18
[link] [comments]
reddit
international online masters degree in cybersecurity that doesnt...
while the pandemic is happening, i feel that im not doing anything productive in my life, so i want to possibly able to get an online masters...
hacking: security in practice
How I use owasp zap spider or active scan to look for parameters that is reflected with random string that leave to reflect xss?
I attack testphp.vulnweb.com with spider and active scan. It show alot of parameters. artist=1 (http://testphp.vulnweb.com/artists.php?artist=1), cat=1(http://testphp.vulnweb.com/listproducts.php?cat=1), name=ZAP&text=&submit=add+message(POST:guestbook.php()(name,submit,text), etc. But I don't understand how it scan for parameters that leave to xss attack. Does it have a fuzz option (Beside fuzz from attack). I want spider or active scan to start fuzzing for parameters in testphp.vulnweb.com with my random string (random parameters).
submitted by /u/BlackAndroid18
[link] [comments]
How I use owasp zap spider or active scan to look for parameters that is reflected with random string that leave to reflect xss?
I attack testphp.vulnweb.com with spider and active scan. It show alot of parameters. artist=1 (http://testphp.vulnweb.com/artists.php?artist=1), cat=1(http://testphp.vulnweb.com/listproducts.php?cat=1), name=ZAP&text=&submit=add+message(POST:guestbook.php()(name,submit,text), etc. But I don't understand how it scan for parameters that leave to xss attack. Does it have a fuzz option (Beside fuzz from attack). I want spider or active scan to start fuzzing for parameters in testphp.vulnweb.com with my random string (random parameters).
submitted by /u/BlackAndroid18
[link] [comments]
reddit
How I use owasp zap spider or active scan to look for parameters...
I attack testphp.vulnweb.com with spider and active scan. It show alot of parameters. artist=1 (http://testphp.vulnweb.com/artists.php?artist=1),...