Download BurpCrypto (https://github.com/whwlsfb/BurpCrypto)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - whwlsfb/BurpCrypto: BurpCrypto is a collection of burpsuite encryption plug-ins, support AES/RSA/DES/ExecJs(execute JS…
BurpCrypto is a collection of burpsuite encryption plug-ins, support AES/RSA/DES/ExecJs(execute JS encryption code in burpsuite). 支持多种加密算法或直接执行JS代码的用于爆破前端加密的BurpSuite插件 - whwlsfb/BurpCrypto
BurpCrypto - A Collection Of Burpsuite Encryption Plug-Ins, Support AES/RSA/DES/ExecJs(execute JS Encryption Code In Burpsuite)
Burpcrypto is a collection of burpsuite encryption plug-ins, supporting AES/RSA/DES/ExecJs(execute JS encryption code in burpsuite).Build$ mvn packageUsage中文使用说明Download the precompiled jar package from Releases.Add this jar package to your burpsuite's Extensions.Switch to BurpCrypto tab, select you need Cipher tab.Set key or some value.press "Add processor", and give a name for this processor.Switch to Intruder->Payloads->Payload Processing.press "Add", select "Invoke Burp extension", and select processor you just created.press "Start attack", have fun!Key ExampleAes Key(UTF8String): abcdefgabcdefg12Aes IV(UTF8String): abcdefgabcdefg12Rsa X509 Key: MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCC0hrRIjb3noDWNtbDpANbjt5Iwu2NFeDwU16Ec87ToqeoIm2KI+cOs81JP9aTDk/jkAlU97mN8wZkEMDr5utAZtMVht7GLX33Wx9XjqxUsDfsGkqNL8dXJklWDu9Zh80Ui2Ug+340d5dZtKtd+nv09QZqGjdnSp9PTfFDBY133QIDAQABRsa Modulus: ca27d90f03753cbbc9958011baf701ac99305b63f68e26ab5617593e01d2fb519127fb87bafbe6e0472ec3a038575fa292adadbc79390a955a61b29431f78f4734773048a45dcf100e23cabf2df11a55aa90cd6b024a44eed1096c3b9e1408d46aae54d7291b82fe4b7867c5eaa45e9cc0ba7f7ae3e5593337c7dcbace2d02ed2fbbff26c6df8a32bb26be80603fcd94c6c8dbd67878d77b37fedcf808e3d8f469aaa7c65d033d547a5c8ea9bdd5c89b836c65852f355a5efd9c7137a186a62b5eb0e052c8be3096d3b51133f8a8c108292a296c99d37bad42bcc3f6c39fa5e583582942b4fc4e7ff4b6779fff5bbaddc65b19c7c57d8cdb39b1a994e08d4a2f50793d8f707d069c380baf0f64bfdce3b35d0b5c5c59348a35a082012aaf4991080abf518b55787969ff24186cb95f7e7218c904cf1dcaeb5bed723e305b83f2e85d6f116d2c7400f9e49d904db8a5a3a0701cdb579fbf3128511acd0f789ece1233ed926d705b3b0dfa34bf33f5ae4bdc611a602aa03aaae13400bc7ad3813ea4474dc62de3d0cb1f5aac277d895a75d38f9b920938fa6b1de35bd6132798c122403c685bdb6e5e24bbd70cfb3e968da0b8affd398e539e7c1e7add09891780bcbd278f3900499ae09cee0dc62e3f92e70001bab6d46261d2801a37f80d84d0e39fce6eaedf106a61b5961960641b9db0e4e23c770e6370ac5d61c6c9eb0f07Rsa Exponent: 010001DES Key: 12345678DESede Key: 123456781234567812345678ScreenshotsAES Example:ExecJs Example (Here is the modified MD5 algorithm):Quick Crypto: Download BurpCrypto
Read more...
___________________________
@hacking_Attack
@Hacking_Video
Burpcrypto is a collection of burpsuite encryption plug-ins, supporting AES/RSA/DES/ExecJs(execute JS encryption code in burpsuite).Build$ mvn packageUsage中文使用说明Download the precompiled jar package from Releases.Add this jar package to your burpsuite's Extensions.Switch to BurpCrypto tab, select you need Cipher tab.Set key or some value.press "Add processor", and give a name for this processor.Switch to Intruder->Payloads->Payload Processing.press "Add", select "Invoke Burp extension", and select processor you just created.press "Start attack", have fun!Key ExampleAes Key(UTF8String): abcdefgabcdefg12Aes IV(UTF8String): abcdefgabcdefg12Rsa X509 Key: MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCC0hrRIjb3noDWNtbDpANbjt5Iwu2NFeDwU16Ec87ToqeoIm2KI+cOs81JP9aTDk/jkAlU97mN8wZkEMDr5utAZtMVht7GLX33Wx9XjqxUsDfsGkqNL8dXJklWDu9Zh80Ui2Ug+340d5dZtKtd+nv09QZqGjdnSp9PTfFDBY133QIDAQABRsa Modulus: ca27d90f03753cbbc9958011baf701ac99305b63f68e26ab5617593e01d2fb519127fb87bafbe6e0472ec3a038575fa292adadbc79390a955a61b29431f78f4734773048a45dcf100e23cabf2df11a55aa90cd6b024a44eed1096c3b9e1408d46aae54d7291b82fe4b7867c5eaa45e9cc0ba7f7ae3e5593337c7dcbace2d02ed2fbbff26c6df8a32bb26be80603fcd94c6c8dbd67878d77b37fedcf808e3d8f469aaa7c65d033d547a5c8ea9bdd5c89b836c65852f355a5efd9c7137a186a62b5eb0e052c8be3096d3b51133f8a8c108292a296c99d37bad42bcc3f6c39fa5e583582942b4fc4e7ff4b6779fff5bbaddc65b19c7c57d8cdb39b1a994e08d4a2f50793d8f707d069c380baf0f64bfdce3b35d0b5c5c59348a35a082012aaf4991080abf518b55787969ff24186cb95f7e7218c904cf1dcaeb5bed723e305b83f2e85d6f116d2c7400f9e49d904db8a5a3a0701cdb579fbf3128511acd0f789ece1233ed926d705b3b0dfa34bf33f5ae4bdc611a602aa03aaae13400bc7ad3813ea4474dc62de3d0cb1f5aac277d895a75d38f9b920938fa6b1de35bd6132798c122403c685bdb6e5e24bbd70cfb3e968da0b8affd398e539e7c1e7add09891780bcbd278f3900499ae09cee0dc62e3f92e70001bab6d46261d2801a37f80d84d0e39fce6eaedf106a61b5961960641b9db0e4e23c770e6370ac5d61c6c9eb0f07Rsa Exponent: 010001DES Key: 12345678DESede Key: 123456781234567812345678ScreenshotsAES Example:ExecJs Example (Here is the modified MD5 algorithm):Quick Crypto: Download BurpCrypto
Read more...
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest Tools!
BurpCrypto - A Collection Of Burpsuite Encryption Plug-Ins, Support AES/RSA/DES/ExecJs(execute JS Encryption Code In Burpsuite)
___________________________
@hacking_Attack
@Hacking_Video
BurpCrypto - A Collection Of Burpsuite Encryption Plug-Ins, Support AES/RSA/DES/ExecJs(execute JS Encryption Code In Burpsuite)
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
BurpCrypto - A Collection Of Burpsuite Encryption Plug-Ins, Support AES/RSA/DES/ExecJs(execute JS Encryption Code In Burpsuite)
Dark Reading: Attacks/Breaches
New Atom Silo Ransomware Group Targets Confluence Servers
An attack that took place over two days used a recently disclosed vulnerability in Atlassian's Confluence collaboration software.
___________________________
@hacking_Attack
@Hacking_Video
New Atom Silo Ransomware Group Targets Confluence Servers
An attack that took place over two days used a recently disclosed vulnerability in Atlassian's Confluence collaboration software.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
New Atom Silo Ransomware Group Targets Confluence Servers
An attack that took place over two days used a recently disclosed vulnerability in Atlassian's Confluence collaboration software.
hacking: security in practice
Is there any attack that actually works nowadays?
I started taking an ethical hacking course and it hasn’t taken much for mento realize that most of (if not all) of the attacks are only working in theory but not in real life.
Here’s what I mean: -ARP spoofing only works with HTTP and nowadays 90% of the websites that people usually visit (Facebook, gmail, google, Reddit etc) are using HTTPS.
-any malware application that you make if you’re good enough with social engineering to have someone download the .exe file and open it then it will have windows defender warning about the not secure developer and if you’re good enough with Python then maybe you have a chance to write yourself your own backdoor that since it was never used before maybe it won’t be intercepted by an antivirus
-WPA is obsolete and most of modern routers now use WPA2 which is practically uncrackable if people leave it set at default (which most people just do) and if they change it you have to be lucky enough that they chose a stupid password that is inside some word list otherwise you have no chance
And so on...
So is hacking still possible today?
And by hacking I don’t mean stupid scams or phishing emails (that also most likely will just fall in the spam folder)
submitted by /u/hatecall
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is there any attack that actually works nowadays?
I started taking an ethical hacking course and it hasn’t taken much for mento realize that most of (if not all) of the attacks are only working in theory but not in real life.
Here’s what I mean: -ARP spoofing only works with HTTP and nowadays 90% of the websites that people usually visit (Facebook, gmail, google, Reddit etc) are using HTTPS.
-any malware application that you make if you’re good enough with social engineering to have someone download the .exe file and open it then it will have windows defender warning about the not secure developer and if you’re good enough with Python then maybe you have a chance to write yourself your own backdoor that since it was never used before maybe it won’t be intercepted by an antivirus
-WPA is obsolete and most of modern routers now use WPA2 which is practically uncrackable if people leave it set at default (which most people just do) and if they change it you have to be lucky enough that they chose a stupid password that is inside some word list otherwise you have no chance
And so on...
So is hacking still possible today?
And by hacking I don’t mean stupid scams or phishing emails (that also most likely will just fall in the spam folder)
submitted by /u/hatecall
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is there any attack that actually works nowadays?
I started taking an ethical hacking course and it hasn’t taken much for mento realize that most of (if not all) of the attacks are only working in...
hacking: security in practice
Raspberry hacking
So today I went to a very famous mall in my city when I realized the cinema movies showtime was bugged and it was showing the raspbian default desktop. I wasn't able to look further into it because I wasn't carrying my laptop but what I found doing just a 2 minutes research was that the raspberry looked like there was enabled WiFi hotspot from the raspberries. Do you know if there's a way to remote access the raspberry if I crack the WiFi password? Is there any chance I can get into them? Any exploits to be shared? Thanks 4 your time :)
submitted by /u/Cevikre
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Raspberry hacking
So today I went to a very famous mall in my city when I realized the cinema movies showtime was bugged and it was showing the raspbian default desktop. I wasn't able to look further into it because I wasn't carrying my laptop but what I found doing just a 2 minutes research was that the raspberry looked like there was enabled WiFi hotspot from the raspberries. Do you know if there's a way to remote access the raspberry if I crack the WiFi password? Is there any chance I can get into them? Any exploits to be shared? Thanks 4 your time :)
submitted by /u/Cevikre
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Raspberry hacking
So today I went to a very famous mall in my city when I realized the cinema movies showtime was bugged and it was showing the raspbian default...
hacking: security in practice
A random scammer knew my name
I got a call from a scammer and after a while he somehow knew my full name. How's this possible?
submitted by /u/slylie07
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
A random scammer knew my name
I got a call from a scammer and after a while he somehow knew my full name. How's this possible?
submitted by /u/slylie07
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
A random scammer knew my name
A subreddit dedicated to hacking and hackers. Constructive collaboration and learning about exploits, industry standards, grey and white hat...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization
https://cdn-images-1.medium.com/max/2600/1*krdyo-n7Ogc0qX8rt0s_ow.jpeg
The Customer service week which holds every 1st week of the month of October has come to be recognized as the week we celebrate the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization
https://cdn-images-1.medium.com/max/2600/1*krdyo-n7Ogc0qX8rt0s_ow.jpeg
The Customer service week which holds every 1st week of the month of October has come to be recognized as the week we celebrate the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization
The Customer service week which holds every 1st week of the month of October has come to be recognized as the week we celebrate the…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Major League Hacking Opens 10 Seats in Upcoming Fellowship Prep Class for TechTogether Community
https://cdn-images-1.medium.com/max/2600/1*FfP5_4jKdQsHQ72pNbAtMQ.png
If you want to hone your hacking skills MLH is opening 10 seats in their next Prep batch for TechTogether community members!
Continue reading on TechTogether »
___________________________
@hacking_Attack
@Hacking_Video
Major League Hacking Opens 10 Seats in Upcoming Fellowship Prep Class for TechTogether Community
https://cdn-images-1.medium.com/max/2600/1*FfP5_4jKdQsHQ72pNbAtMQ.png
If you want to hone your hacking skills MLH is opening 10 seats in their next Prep batch for TechTogether community members!
Continue reading on TechTogether »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Major League Hacking Opens 10 Seats in Upcoming Fellowship Prep Class for TechTogether Community
If you want to hone your hacking skills MLH is opening 10 seats in their next Prep batch for TechTogether community members!
hacking: security in practice
Is this a virus?
Hello, today I got a link in my instagram inbox from a hacked account.i clicked on the link since I didn't knew it was hacked.
This is the link: http://loveit275.xyz/g/?&ure=
After "=" was my IG username. The site only directed me back to the homepage of Instagram.
submitted by /u/bre999
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is this a virus?
Hello, today I got a link in my instagram inbox from a hacked account.i clicked on the link since I didn't knew it was hacked.
This is the link: http://loveit275.xyz/g/?&ure=
After "=" was my IG username. The site only directed me back to the homepage of Instagram.
submitted by /u/bre999
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is this a virus?
Hello, today I got a link in my instagram inbox from a hacked account.i clicked on the link since I didn't knew it was hacked. This is the...
hacking: security in practice
I have been observing dos attacks in my router log what can I do to stop them?
I have recently taken a look at my router log out of curiosity after installing my new router, and noticed a series of doss attacks coming in. The DoS attacks listed on my log are as follows Fraggle Attack, ACK Scan, snmpQueryDrop, RST Scan, TCP SYN Flood. I will disclose that I had made the mistake of using the WPS button to connect my printer to my network, but I had researched that it would make my router vulnerable while the WPS connection is attempting to be established. These attacks started on September 20 till today. I have taken a couple of steps to resolve: I have released, and renewed my IP, I have disconnected my modem and Router for a full 2 minutes each, and I have changed my wireless password for all My 2.4 and 5 ghz broadband to 99 randomized character passwords. The disconnection for the modem and router had temporarily stopped the attacks for about 30 minutes then The Fraggle Attacks started again soon after all the other types of attacks started again. I am debating exchanging my router for a new one or simply doing a factory data reset on the router. Thank you for your time and attention if this is the wrong subreddit if you may redirect me To the right Subreddit for additional help.
submitted by /u/TheSirInconsistent
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
I have been observing dos attacks in my router log what can I do to stop them?
I have recently taken a look at my router log out of curiosity after installing my new router, and noticed a series of doss attacks coming in. The DoS attacks listed on my log are as follows Fraggle Attack, ACK Scan, snmpQueryDrop, RST Scan, TCP SYN Flood. I will disclose that I had made the mistake of using the WPS button to connect my printer to my network, but I had researched that it would make my router vulnerable while the WPS connection is attempting to be established. These attacks started on September 20 till today. I have taken a couple of steps to resolve: I have released, and renewed my IP, I have disconnected my modem and Router for a full 2 minutes each, and I have changed my wireless password for all My 2.4 and 5 ghz broadband to 99 randomized character passwords. The disconnection for the modem and router had temporarily stopped the attacks for about 30 minutes then The Fraggle Attacks started again soon after all the other types of attacks started again. I am debating exchanging my router for a new one or simply doing a factory data reset on the router. Thank you for your time and attention if this is the wrong subreddit if you may redirect me To the right Subreddit for additional help.
submitted by /u/TheSirInconsistent
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
I have been observing dos attacks in my router log what can I do...
I have recently taken a look at my router log out of curiosity after installing my new router, and noticed a series of doss attacks coming in. The...
hacking: security in practice
Any exploit code for CVE-2020-12440
I've been digging through Google and exploit bds i haven't found one. Please help me find it. Thanks in advance.
submitted by /u/cdsdfdedsde
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Any exploit code for CVE-2020-12440
I've been digging through Google and exploit bds i haven't found one. Please help me find it. Thanks in advance.
submitted by /u/cdsdfdedsde
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Any exploit code for CVE-2020-12440
I've been digging through Google and exploit bds i haven't found one. Please help me find it. Thanks in advance.
Does anyone have any suggested reading for offensive C# on Windows?
https://www.reddit.com/r/redteamsec/comments/q1lxii/does_anyone_have_any_suggested_reading_for/
I was kind of disappointed by the "Gray Hat C#" book and I'm wondering if someone else has some better suggestions. I'm looking for a book/resource to learn how to get into C# for Windows but I'm swamped by web development material. Any suggestions to help me improve my tradecraft would be appreciated. Thanks submitted by /u/GuerrillaTom (https://www.reddit.com/user/GuerrillaTom)
[link] (https://www.reddit.com/r/redteamsec/comments/q1lxii/does_anyone_have_any_suggested_reading_for/) [comments] (https://www.reddit.com/r/redteamsec/comments/q1lxii/does_anyone_have_any_suggested_reading_for/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/q1lxii/does_anyone_have_any_suggested_reading_for/
I was kind of disappointed by the "Gray Hat C#" book and I'm wondering if someone else has some better suggestions. I'm looking for a book/resource to learn how to get into C# for Windows but I'm swamped by web development material. Any suggestions to help me improve my tradecraft would be appreciated. Thanks submitted by /u/GuerrillaTom (https://www.reddit.com/user/GuerrillaTom)
[link] (https://www.reddit.com/r/redteamsec/comments/q1lxii/does_anyone_have_any_suggested_reading_for/) [comments] (https://www.reddit.com/r/redteamsec/comments/q1lxii/does_anyone_have_any_suggested_reading_for/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
r/redteamsec on Reddit: Does anyone have any suggested reading for offensive C# on Windows?
Posted by u/[Deleted Account] - 19 votes and 16 comments