BurpCrypto - A Collection Of Burpsuite Encryption Plug-Ins, Support AES/RSA/DES/ExecJs(execute JS Encryption Code In Burpsuite)
http://www.kitploit.com/2021/10/burpcrypto-collection-of-burpsuite.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/10/burpcrypto-collection-of-burpsuite.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
BurpCrypto - A Collection Of Burpsuite Encryption Plug-Ins, Support AES/RSA/DES/ExecJs(execute JS Encryption Code In Burpsuite)
Burpcrypto is a collection of burpsuite (https://www.kitploit.com/search/label/Burpsuite) encryption (https://www.kitploit.com/search/label/Encryption) plug-ins, supporting AES/RSA/DES/ExecJs(execute JS encryption code in burpsuite).
Build
$ mvn package
Usage
中文使用说明 (https://blog.wanghw.cn/burpcrypto)Download the precompiled jar (https://www.kitploit.com/search/label/JAR) package from Releases (https://github.com/whwlsfb/BurpCrypto/releases).Add this jar package to your burpsuite's Extensions.Switch to BurpCrypto tab, select you need Cipher tab.Set key or some value.press "Add processor", and give a name for this processor.Switch to Intruder->Payloads->Payload Processing.press "Add", select "Invoke Burp (https://www.kitploit.com/search/label/Burp) extension", and select processor you just created.press "Start attack", have fun!
Key Example
Aes Key(UTF8String): abcdefgabcdefg12Aes IV(UTF8String): abcdefgabcdefg12Rsa X509 Key: MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCC0hrRIjb3noDWNtbDpANbjt5Iwu2NFeDwU16Ec87ToqeoIm2KI+cOs81JP9aTDk/jkAlU97mN8wZkEMDr5utAZtMVht7GLX33Wx9XjqxUsDfsGkqNL8dXJklWDu9Zh80Ui2Ug+340d5dZtKtd+nv09QZqGjdnSp9PTfFDBY133QIDAQABRsa Modulus: ca27d90f03753cbbc9958011baf701ac99305b63f68e26ab5617593e01d2fb519127fb87bafbe6e0472ec3a038575fa292adadbc79390a955a61b29431f78f4734773048a45dcf100e23cabf2df11a55aa90cd6b024a44eed1096c3b9e1408d46aae54d7291b82fe4b7867c5eaa45e9cc0ba7f7ae3e5593337c7dcbace2d02ed2fbbff26c6df8a32bb26be80603fcd94c6c8dbd67878d77b37fedcf808e3d8f469aaa7c65d033d547a5c8ea9bdd5c89b836c65852f355a5efd9c7137a186a62b5eb0e052c8be3096d3b51133f8a8c108292a296c99d37bad42bcc3f6c39fa5e583582942b4fc4e7ff4b6779fff5bbaddc65b19c7c57d8cdb39b1a994e08d4a2f50793d8f707d069c380baf0f64bfdce3b35d0b5c5c59348a35a082012aaf4991080abf518b55787969ff24186cb95f7e7218c904cf1dcaeb5bed723e305b83f2e85d6f116d2c7400f9e49d904db8a5a3a0701cdb579fbf3128511acd0f789ece1233ed926d705b3b0dfa34bf33f5ae4bdc611a602aa03aaae13400bc7ad3813ea4474dc62de3d0cb1f5aac277d895a75d38f9b920938fa6b1de35bd6132798c122403c685bdb6e5e24bbd70cfb3e968da0b8affd398e539e7c1e7add09891780bcbd278f3900499ae09cee0dc62e3f92e70001bab6d46261d2801a37f80d84d0e39fce6eaedf106a61b5961960641b9db0e4e23c770e6370ac5d61c6c9eb0f07Rsa Exponent: 010001DES Key: 12345678DESede Key: 123456781234567812345678
Screenshots
AES Example:
___________________________
@hacking_Attack
@Hacking_Video
Build
$ mvn package
Usage
中文使用说明 (https://blog.wanghw.cn/burpcrypto)Download the precompiled jar (https://www.kitploit.com/search/label/JAR) package from Releases (https://github.com/whwlsfb/BurpCrypto/releases).Add this jar package to your burpsuite's Extensions.Switch to BurpCrypto tab, select you need Cipher tab.Set key or some value.press "Add processor", and give a name for this processor.Switch to Intruder->Payloads->Payload Processing.press "Add", select "Invoke Burp (https://www.kitploit.com/search/label/Burp) extension", and select processor you just created.press "Start attack", have fun!
Key Example
Aes Key(UTF8String): abcdefgabcdefg12Aes IV(UTF8String): abcdefgabcdefg12Rsa X509 Key: MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCC0hrRIjb3noDWNtbDpANbjt5Iwu2NFeDwU16Ec87ToqeoIm2KI+cOs81JP9aTDk/jkAlU97mN8wZkEMDr5utAZtMVht7GLX33Wx9XjqxUsDfsGkqNL8dXJklWDu9Zh80Ui2Ug+340d5dZtKtd+nv09QZqGjdnSp9PTfFDBY133QIDAQABRsa Modulus: ca27d90f03753cbbc9958011baf701ac99305b63f68e26ab5617593e01d2fb519127fb87bafbe6e0472ec3a038575fa292adadbc79390a955a61b29431f78f4734773048a45dcf100e23cabf2df11a55aa90cd6b024a44eed1096c3b9e1408d46aae54d7291b82fe4b7867c5eaa45e9cc0ba7f7ae3e5593337c7dcbace2d02ed2fbbff26c6df8a32bb26be80603fcd94c6c8dbd67878d77b37fedcf808e3d8f469aaa7c65d033d547a5c8ea9bdd5c89b836c65852f355a5efd9c7137a186a62b5eb0e052c8be3096d3b51133f8a8c108292a296c99d37bad42bcc3f6c39fa5e583582942b4fc4e7ff4b6779fff5bbaddc65b19c7c57d8cdb39b1a994e08d4a2f50793d8f707d069c380baf0f64bfdce3b35d0b5c5c59348a35a082012aaf4991080abf518b55787969ff24186cb95f7e7218c904cf1dcaeb5bed723e305b83f2e85d6f116d2c7400f9e49d904db8a5a3a0701cdb579fbf3128511acd0f789ece1233ed926d705b3b0dfa34bf33f5ae4bdc611a602aa03aaae13400bc7ad3813ea4474dc62de3d0cb1f5aac277d895a75d38f9b920938fa6b1de35bd6132798c122403c685bdb6e5e24bbd70cfb3e968da0b8affd398e539e7c1e7add09891780bcbd278f3900499ae09cee0dc62e3f92e70001bab6d46261d2801a37f80d84d0e39fce6eaedf106a61b5961960641b9db0e4e23c770e6370ac5d61c6c9eb0f07Rsa Exponent: 010001DES Key: 12345678DESede Key: 123456781234567812345678
Screenshots
AES Example:
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
ExecJs Example (Here is the modified MD5 (https://www.kitploit.com/search/label/MD5) algorithm):
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
Download BurpCrypto (https://github.com/whwlsfb/BurpCrypto)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - whwlsfb/BurpCrypto: BurpCrypto is a collection of burpsuite encryption plug-ins, support AES/RSA/DES/ExecJs(execute JS…
BurpCrypto is a collection of burpsuite encryption plug-ins, support AES/RSA/DES/ExecJs(execute JS encryption code in burpsuite). 支持多种加密算法或直接执行JS代码的用于爆破前端加密的BurpSuite插件 - whwlsfb/BurpCrypto
BurpCrypto - A Collection Of Burpsuite Encryption Plug-Ins, Support AES/RSA/DES/ExecJs(execute JS Encryption Code In Burpsuite)
Burpcrypto is a collection of burpsuite encryption plug-ins, supporting AES/RSA/DES/ExecJs(execute JS encryption code in burpsuite).Build$ mvn packageUsage中文使用说明Download the precompiled jar package from Releases.Add this jar package to your burpsuite's Extensions.Switch to BurpCrypto tab, select you need Cipher tab.Set key or some value.press "Add processor", and give a name for this processor.Switch to Intruder->Payloads->Payload Processing.press "Add", select "Invoke Burp extension", and select processor you just created.press "Start attack", have fun!Key ExampleAes Key(UTF8String): abcdefgabcdefg12Aes IV(UTF8String): abcdefgabcdefg12Rsa X509 Key: MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCC0hrRIjb3noDWNtbDpANbjt5Iwu2NFeDwU16Ec87ToqeoIm2KI+cOs81JP9aTDk/jkAlU97mN8wZkEMDr5utAZtMVht7GLX33Wx9XjqxUsDfsGkqNL8dXJklWDu9Zh80Ui2Ug+340d5dZtKtd+nv09QZqGjdnSp9PTfFDBY133QIDAQABRsa Modulus: ca27d90f03753cbbc9958011baf701ac99305b63f68e26ab5617593e01d2fb519127fb87bafbe6e0472ec3a038575fa292adadbc79390a955a61b29431f78f4734773048a45dcf100e23cabf2df11a55aa90cd6b024a44eed1096c3b9e1408d46aae54d7291b82fe4b7867c5eaa45e9cc0ba7f7ae3e5593337c7dcbace2d02ed2fbbff26c6df8a32bb26be80603fcd94c6c8dbd67878d77b37fedcf808e3d8f469aaa7c65d033d547a5c8ea9bdd5c89b836c65852f355a5efd9c7137a186a62b5eb0e052c8be3096d3b51133f8a8c108292a296c99d37bad42bcc3f6c39fa5e583582942b4fc4e7ff4b6779fff5bbaddc65b19c7c57d8cdb39b1a994e08d4a2f50793d8f707d069c380baf0f64bfdce3b35d0b5c5c59348a35a082012aaf4991080abf518b55787969ff24186cb95f7e7218c904cf1dcaeb5bed723e305b83f2e85d6f116d2c7400f9e49d904db8a5a3a0701cdb579fbf3128511acd0f789ece1233ed926d705b3b0dfa34bf33f5ae4bdc611a602aa03aaae13400bc7ad3813ea4474dc62de3d0cb1f5aac277d895a75d38f9b920938fa6b1de35bd6132798c122403c685bdb6e5e24bbd70cfb3e968da0b8affd398e539e7c1e7add09891780bcbd278f3900499ae09cee0dc62e3f92e70001bab6d46261d2801a37f80d84d0e39fce6eaedf106a61b5961960641b9db0e4e23c770e6370ac5d61c6c9eb0f07Rsa Exponent: 010001DES Key: 12345678DESede Key: 123456781234567812345678ScreenshotsAES Example:ExecJs Example (Here is the modified MD5 algorithm):Quick Crypto: Download BurpCrypto
Read more...
___________________________
@hacking_Attack
@Hacking_Video
Burpcrypto is a collection of burpsuite encryption plug-ins, supporting AES/RSA/DES/ExecJs(execute JS encryption code in burpsuite).Build$ mvn packageUsage中文使用说明Download the precompiled jar package from Releases.Add this jar package to your burpsuite's Extensions.Switch to BurpCrypto tab, select you need Cipher tab.Set key or some value.press "Add processor", and give a name for this processor.Switch to Intruder->Payloads->Payload Processing.press "Add", select "Invoke Burp extension", and select processor you just created.press "Start attack", have fun!Key ExampleAes Key(UTF8String): abcdefgabcdefg12Aes IV(UTF8String): abcdefgabcdefg12Rsa X509 Key: MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCC0hrRIjb3noDWNtbDpANbjt5Iwu2NFeDwU16Ec87ToqeoIm2KI+cOs81JP9aTDk/jkAlU97mN8wZkEMDr5utAZtMVht7GLX33Wx9XjqxUsDfsGkqNL8dXJklWDu9Zh80Ui2Ug+340d5dZtKtd+nv09QZqGjdnSp9PTfFDBY133QIDAQABRsa Modulus: ca27d90f03753cbbc9958011baf701ac99305b63f68e26ab5617593e01d2fb519127fb87bafbe6e0472ec3a038575fa292adadbc79390a955a61b29431f78f4734773048a45dcf100e23cabf2df11a55aa90cd6b024a44eed1096c3b9e1408d46aae54d7291b82fe4b7867c5eaa45e9cc0ba7f7ae3e5593337c7dcbace2d02ed2fbbff26c6df8a32bb26be80603fcd94c6c8dbd67878d77b37fedcf808e3d8f469aaa7c65d033d547a5c8ea9bdd5c89b836c65852f355a5efd9c7137a186a62b5eb0e052c8be3096d3b51133f8a8c108292a296c99d37bad42bcc3f6c39fa5e583582942b4fc4e7ff4b6779fff5bbaddc65b19c7c57d8cdb39b1a994e08d4a2f50793d8f707d069c380baf0f64bfdce3b35d0b5c5c59348a35a082012aaf4991080abf518b55787969ff24186cb95f7e7218c904cf1dcaeb5bed723e305b83f2e85d6f116d2c7400f9e49d904db8a5a3a0701cdb579fbf3128511acd0f789ece1233ed926d705b3b0dfa34bf33f5ae4bdc611a602aa03aaae13400bc7ad3813ea4474dc62de3d0cb1f5aac277d895a75d38f9b920938fa6b1de35bd6132798c122403c685bdb6e5e24bbd70cfb3e968da0b8affd398e539e7c1e7add09891780bcbd278f3900499ae09cee0dc62e3f92e70001bab6d46261d2801a37f80d84d0e39fce6eaedf106a61b5961960641b9db0e4e23c770e6370ac5d61c6c9eb0f07Rsa Exponent: 010001DES Key: 12345678DESede Key: 123456781234567812345678ScreenshotsAES Example:ExecJs Example (Here is the modified MD5 algorithm):Quick Crypto: Download BurpCrypto
Read more...
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest Tools!
BurpCrypto - A Collection Of Burpsuite Encryption Plug-Ins, Support AES/RSA/DES/ExecJs(execute JS Encryption Code In Burpsuite)
___________________________
@hacking_Attack
@Hacking_Video
BurpCrypto - A Collection Of Burpsuite Encryption Plug-Ins, Support AES/RSA/DES/ExecJs(execute JS Encryption Code In Burpsuite)
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
BurpCrypto - A Collection Of Burpsuite Encryption Plug-Ins, Support AES/RSA/DES/ExecJs(execute JS Encryption Code In Burpsuite)
Dark Reading: Attacks/Breaches
New Atom Silo Ransomware Group Targets Confluence Servers
An attack that took place over two days used a recently disclosed vulnerability in Atlassian's Confluence collaboration software.
___________________________
@hacking_Attack
@Hacking_Video
New Atom Silo Ransomware Group Targets Confluence Servers
An attack that took place over two days used a recently disclosed vulnerability in Atlassian's Confluence collaboration software.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
New Atom Silo Ransomware Group Targets Confluence Servers
An attack that took place over two days used a recently disclosed vulnerability in Atlassian's Confluence collaboration software.
hacking: security in practice
Is there any attack that actually works nowadays?
I started taking an ethical hacking course and it hasn’t taken much for mento realize that most of (if not all) of the attacks are only working in theory but not in real life.
Here’s what I mean: -ARP spoofing only works with HTTP and nowadays 90% of the websites that people usually visit (Facebook, gmail, google, Reddit etc) are using HTTPS.
-any malware application that you make if you’re good enough with social engineering to have someone download the .exe file and open it then it will have windows defender warning about the not secure developer and if you’re good enough with Python then maybe you have a chance to write yourself your own backdoor that since it was never used before maybe it won’t be intercepted by an antivirus
-WPA is obsolete and most of modern routers now use WPA2 which is practically uncrackable if people leave it set at default (which most people just do) and if they change it you have to be lucky enough that they chose a stupid password that is inside some word list otherwise you have no chance
And so on...
So is hacking still possible today?
And by hacking I don’t mean stupid scams or phishing emails (that also most likely will just fall in the spam folder)
submitted by /u/hatecall
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is there any attack that actually works nowadays?
I started taking an ethical hacking course and it hasn’t taken much for mento realize that most of (if not all) of the attacks are only working in theory but not in real life.
Here’s what I mean: -ARP spoofing only works with HTTP and nowadays 90% of the websites that people usually visit (Facebook, gmail, google, Reddit etc) are using HTTPS.
-any malware application that you make if you’re good enough with social engineering to have someone download the .exe file and open it then it will have windows defender warning about the not secure developer and if you’re good enough with Python then maybe you have a chance to write yourself your own backdoor that since it was never used before maybe it won’t be intercepted by an antivirus
-WPA is obsolete and most of modern routers now use WPA2 which is practically uncrackable if people leave it set at default (which most people just do) and if they change it you have to be lucky enough that they chose a stupid password that is inside some word list otherwise you have no chance
And so on...
So is hacking still possible today?
And by hacking I don’t mean stupid scams or phishing emails (that also most likely will just fall in the spam folder)
submitted by /u/hatecall
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is there any attack that actually works nowadays?
I started taking an ethical hacking course and it hasn’t taken much for mento realize that most of (if not all) of the attacks are only working in...
hacking: security in practice
Raspberry hacking
So today I went to a very famous mall in my city when I realized the cinema movies showtime was bugged and it was showing the raspbian default desktop. I wasn't able to look further into it because I wasn't carrying my laptop but what I found doing just a 2 minutes research was that the raspberry looked like there was enabled WiFi hotspot from the raspberries. Do you know if there's a way to remote access the raspberry if I crack the WiFi password? Is there any chance I can get into them? Any exploits to be shared? Thanks 4 your time :)
submitted by /u/Cevikre
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Raspberry hacking
So today I went to a very famous mall in my city when I realized the cinema movies showtime was bugged and it was showing the raspbian default desktop. I wasn't able to look further into it because I wasn't carrying my laptop but what I found doing just a 2 minutes research was that the raspberry looked like there was enabled WiFi hotspot from the raspberries. Do you know if there's a way to remote access the raspberry if I crack the WiFi password? Is there any chance I can get into them? Any exploits to be shared? Thanks 4 your time :)
submitted by /u/Cevikre
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Raspberry hacking
So today I went to a very famous mall in my city when I realized the cinema movies showtime was bugged and it was showing the raspbian default...
hacking: security in practice
A random scammer knew my name
I got a call from a scammer and after a while he somehow knew my full name. How's this possible?
submitted by /u/slylie07
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
A random scammer knew my name
I got a call from a scammer and after a while he somehow knew my full name. How's this possible?
submitted by /u/slylie07
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
A random scammer knew my name
A subreddit dedicated to hacking and hackers. Constructive collaboration and learning about exploits, industry standards, grey and white hat...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization
https://cdn-images-1.medium.com/max/2600/1*krdyo-n7Ogc0qX8rt0s_ow.jpeg
The Customer service week which holds every 1st week of the month of October has come to be recognized as the week we celebrate the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization
https://cdn-images-1.medium.com/max/2600/1*krdyo-n7Ogc0qX8rt0s_ow.jpeg
The Customer service week which holds every 1st week of the month of October has come to be recognized as the week we celebrate the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization
The Customer service week which holds every 1st week of the month of October has come to be recognized as the week we celebrate the…