Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Results
The results page, simply shows results that have been created by a task. The results table shows the basic metadata of the result, but also provides a “Details” button which can be used to investigate the result further. As mentioned all results have some kind of output file, if a result is a link the file will be a copy of the HTML of the page. Furthermore screenshot (https://www.kitploit.com/search/label/Screenshot) functionality is provided to assist in keeping a photographic record of a result. Both the output and screenshot file will be deleted if the result is deleted.Note: This page only loads the latest 1000 results, for optimisation of the web application.

___________________________
@hacking_Attack
@Hacking_Video
For optimisation purposes, the results table only displays some of the general information regarding a result, to investigate a result further, the user should use the Details button. The details page allows the user to view the soft copy of the result's link and provides the ability for a user to generate a screenshot.

___________________________
@hacking_Attack
@Hacking_Video
Tasks
The tasks page shows all created task, and provides the ability for the user to run each task. This page doesn’t have a limit on tasks; however, don’t go crazy creating tasks, you can always add a list to a task, rather than having the same task created multiple times for one search. So really you shouldn’t have any more than 50 tasks. Tasks have caching and logging for each which can be found in the “protected/output” directory under the tasks name, ex. Google Search is called “google”. If you need to remove the cache, you can edit/delete the appropriate cache file.

___________________________
@hacking_Attack
@Hacking_Video
All the plugins are open-source, free to individuals, just like the rest of the code. Furthermore, feel free to use the pre-existing libraries used in other plugins. If you are creating or editting a plugin, make sure to understand that when you run it for the first time, the web app may reload to reload the python cache. This is normal.
Account Settings
This page changes according to the user's privileges, if a user is an admin, they have the ability to change their password as well as other user's passwords, they can block and unblock users, demote and promote users' privileges, and of course create new users and delete existing users.
Additionally users with administrative privileges can check and edit input, output, and core configuration of the tool.
The account page looks as per below for administrative users:

___________________________
@hacking_Attack
@Hacking_Video
The account page looks as per below for non-administrative users:

___________________________
@hacking_Attack
@Hacking_Video
Identities
This concept was introduced in v3.6 of the Scrummage platform, this page is not to be confused with the Account Settings page. Account Settings is for managing users of the Scrummage platform itself, identities, is an entirely optional feature, where if rows are present, the information within can be used when executing tasks.
This is the main page, depicting a table with a faux identity created for documentation purposes:

___________________________
@hacking_Attack
@Hacking_Video
Identities can be created one of three ways:Individual creation (Use the "Create Identity" function.) 

___________________________
@hacking_Attack
@Hacking_Video
Bulk upload of identities (Use the "Bulk Upload" function.) 

___________________________
@hacking_Attack
@Hacking_Video
Apache 0 Day !!

Hello Hunters! Today’s topic is about CVE 2021–41773. Without further delay let’s get start.Continue reading on Medium »
Read more...
If I obtain a sites API key, can this be used maliciously?
https://www.reddit.com/r/redteamsec/comments/q2jjry/if_i_obtain_a_sites_api_key_can_this_be_used/

Hello legends, I've stumbled across an AWS API key in a sites json file - as I lack knowledge on API related technology I'm unsure if this can be used maliciously or not. Can it be used in an attack? I don't want to report my finding to said site if it's actually not a big deal. Thanks! submitted by /u/HotHeadStayingCold (https://www.reddit.com/user/HotHeadStayingCold)
[link] (https://www.reddit.com/r/redteamsec/comments/q2jjry/if_i_obtain_a_sites_api_key_can_this_be_used/) [comments] (https://www.reddit.com/r/redteamsec/comments/q2jjry/if_i_obtain_a_sites_api_key_can_this_be_used/)

___________________________
@hacking_Attack
@Hacking_Video
App Bug Hunting……A Goldmine Skill?

Every person in today's world uses Mobile. Everyone uses mobile applications. Everyone stores their personal information on mobiles and…Continue reading on Medium »
Read more...