Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Beginner’s Guide to MLH — Local Hack Day
https://cdn-images-1.medium.com/max/1068/0*crwYhAtxG3dK4q8b.jpg
Intro to Local Hack day:
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Beginner’s Guide to MLH — Local Hack Day
https://cdn-images-1.medium.com/max/1068/0*crwYhAtxG3dK4q8b.jpg
Intro to Local Hack day:
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Medium
Beginner’s Guide to MLH — Local Hack Day
Intro to Local Hack day:
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Linux for Hackers | Episode 01
https://cdn-images-1.medium.com/max/2240/1*v37x6zGyGNUhM9YbrT627g.png
What is Linux?
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Linux for Hackers | Episode 01
https://cdn-images-1.medium.com/max/2240/1*v37x6zGyGNUhM9YbrT627g.png
What is Linux?
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Medium
Linux for Hackers | Episode 01
What is Linux?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Planos mirabolantes criados por bandidos
https://cdn-images-1.medium.com/max/2600/1*LDs0s4EwFiCpWOPBNIFaQw.jpeg
O que é uma mente criminosa e até aonde é capaz de ir para se satisfazer, mesmo sabendo que aquilo que executa é nada mais que o puro mal?
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Planos mirabolantes criados por bandidos
https://cdn-images-1.medium.com/max/2600/1*LDs0s4EwFiCpWOPBNIFaQw.jpeg
O que é uma mente criminosa e até aonde é capaz de ir para se satisfazer, mesmo sabendo que aquilo que executa é nada mais que o puro mal?
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Medium
Planos mirabolantes criados por bandidos
O que é uma mente criminosa e até aonde é capaz de ir para se satisfazer, mesmo sabendo que aquilo que executa é nada mais que o puro mal?
hacking: security in practice
What realistic attack flows could a threat agent employ given an established MitM condition on a LAN/WLAN today?
In a theoretical scenario a threat agent was successful in establishing himself as MitM on a LAN/WLAN. He can read all the traffic between a target and the gateway. The target browses the web on a modern browser, sticks to HTTPS whenever possible and has HSTS enabled. They can, however, access an HTTP-only hyperlink if it shows up in a search result, for example. We assume no sensitive information will be sent through unencrypted channels nor the encrypted content can be tampered with without raising a warning on the browser.
The threat has persistent access to the network and time is not an issue. What kinds of attacks with realistic impact could this threat pull off?
One possibility could be preying on the network until an opportunity for injection of malicious JavaScript (e.g. a BEeF hook) presented itself through an unencrypted connection (the target visits an HTTP-only website or a script imports those resources unbeknownst to him).
What else?
submitted by /u/EONRaider
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
What realistic attack flows could a threat agent employ given an established MitM condition on a LAN/WLAN today?
In a theoretical scenario a threat agent was successful in establishing himself as MitM on a LAN/WLAN. He can read all the traffic between a target and the gateway. The target browses the web on a modern browser, sticks to HTTPS whenever possible and has HSTS enabled. They can, however, access an HTTP-only hyperlink if it shows up in a search result, for example. We assume no sensitive information will be sent through unencrypted channels nor the encrypted content can be tampered with without raising a warning on the browser.
The threat has persistent access to the network and time is not an issue. What kinds of attacks with realistic impact could this threat pull off?
One possibility could be preying on the network until an opportunity for injection of malicious JavaScript (e.g. a BEeF hook) presented itself through an unencrypted connection (the target visits an HTTP-only website or a script imports those resources unbeknownst to him).
What else?
submitted by /u/EONRaider
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
What realistic attack flows could a threat agent employ given an...
In a theoretical scenario a threat agent was successful in establishing himself as MitM on a LAN/WLAN. He can read all the traffic between a...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
MITMf headless install in Kali Linux 2021.x
After four days (and nights) I finally found the right way to install MITMf in Kali Linux 2021.3. Most MITMf installation guides for Kali 2021.x I found online are setting the virtualenvwrapper and Python 2.7 incorrectly and MITMf dependencies are either not satisfied or won't work when you run it in a new ZSH shell.
Here is a guide that covers the whole MITMf installation process in Kali Linux 2021 as well as a script that automates the install. Hope it helps.
submitted by /u/nexenta81
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
MITMf headless install in Kali Linux 2021.x
After four days (and nights) I finally found the right way to install MITMf in Kali Linux 2021.3. Most MITMf installation guides for Kali 2021.x I found online are setting the virtualenvwrapper and Python 2.7 incorrectly and MITMf dependencies are either not satisfied or won't work when you run it in a new ZSH shell.
Here is a guide that covers the whole MITMf installation process in Kali Linux 2021 as well as a script that automates the install. Hope it helps.
submitted by /u/nexenta81
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
MITMf headless install in Kali Linux 2021.x
After four days (and nights) I finally found the right way to install MITMf in Kali Linux 2021.3. Most MITMf installation guides for Kali 2021.x I...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Startup
https://cdn-images-1.medium.com/max/735/0*Mjj_ixwuvt5_yZob.png
Link: https://tryhackme.com/room/startup
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Startup
https://cdn-images-1.medium.com/max/735/0*Mjj_ixwuvt5_yZob.png
Link: https://tryhackme.com/room/startup
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Startup
Link: https://tryhackme.com/room/startup
The scene is set. A drowsy teenager awakens from his umpteen hours of sleep. He’s been looking forward to something. Maybe he wants to…Continue reading on Medium » (https://medium.com/@gesskay/lights-camera-bug%C3%A9dex-ce0b3232578c?source=rss------bug_bounty-5)
How Instagram Helped Me To Exploit XSS
https://infosecwriteups.com/how-instagram-helped-me-to-exploit-xss-f1772311ad1a?source=rss------bug_bounty-5
https://infosecwriteups.com/how-instagram-helped-me-to-exploit-xss-f1772311ad1a?source=rss------bug_bounty-5
AssalamuAlaikum Everyone. My Name is Farhan aka Fani Malik, a Bug Hunter. So, here I came up with an Interesting XSS Bug that I Found a…Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/how-instagram-helped-me-to-exploit-xss-f1772311ad1a?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
SharpML : Machine Learning Network Share Password Hunting Toolkit
SharpML is a proof of concept file share data mining tool using Machine Learning in Python and C#.
The tool is discussed in more detail on our blog here, but is summarised below also:
SharpML is C# and Python based tool that performs a number of operations with a view to mining file shares, querying Active Directory for users, dropping an ML model and associated rules, perfoming Active Directory authentication checks, with a view to automating the process of hunting for passwords in file shares by feeding the mined data into the ML model.
The ML model is written in Python, and has been developed using a custom algorithm to identify likelyhoods of passwords. The model has been compiled with PyInstaller and sits as resource file in the C# wrapper, which interops between itself, the data and the model. The program logic can be seen below:
https://1.bp.blogspot.com/-kMg24SzvZXI/YVWkBNZsD-I/AAAAAAAAK_g/V2yLFKHDQi0e5t8rcJMKdqLdHl4-DXWcwCLcBGAsYHQ/s1073/sharpml_logic.png
Currently it allows for a single file share to be assessed.
You will need to have read access to the file share you are targeting, after which the tool will perform its activities mostly autonomously.
There a compiled release in the release section, and it is to be noted that this tool is currently a PoC and subject to numerous improvements.
Usage
cmd.exe
C:> SharpML.exe -u \fileshare\d$
Cobalt Strike
execute-assembly SharpML.exe -u \fileshare\d$
Download
SharpML : Machine Learning Network Share Password Hunting Toolkit
SharpML is a proof of concept file share data mining tool using Machine Learning in Python and C#.
The tool is discussed in more detail on our blog here, but is summarised below also:
SharpML is C# and Python based tool that performs a number of operations with a view to mining file shares, querying Active Directory for users, dropping an ML model and associated rules, perfoming Active Directory authentication checks, with a view to automating the process of hunting for passwords in file shares by feeding the mined data into the ML model.
The ML model is written in Python, and has been developed using a custom algorithm to identify likelyhoods of passwords. The model has been compiled with PyInstaller and sits as resource file in the C# wrapper, which interops between itself, the data and the model. The program logic can be seen below:
https://1.bp.blogspot.com/-kMg24SzvZXI/YVWkBNZsD-I/AAAAAAAAK_g/V2yLFKHDQi0e5t8rcJMKdqLdHl4-DXWcwCLcBGAsYHQ/s1073/sharpml_logic.png
Currently it allows for a single file share to be assessed.
You will need to have read access to the file share you are targeting, after which the tool will perform its activities mostly autonomously.
There a compiled release in the release section, and it is to be noted that this tool is currently a PoC and subject to numerous improvements.
Usage
cmd.exe
C:> SharpML.exe -u \fileshare\d$
Cobalt Strike
execute-assembly SharpML.exe -u \fileshare\d$
Download
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Webstor : A Script To Quickly Enumerate All Websites Across All Of Your Organization’s Networks
Webstor is a tool implemented in Python under the MIT license for quickly enumerating all websites across all of your organization’s networks, storing their responses, and querying for known web technologies and versions, such as those with zero-day vulnerabilities. It is intended, in particular, to solve the unique problem presented in mid to large sized organizations with decentralized administration, wherein it can be almost impossible to track all of the web technologies deployed by various administrators distributed across different units and networks.
WebStor achieves its goal by performing the following actions:
1. Performs DNS zone transfers to collect an organization’s A and CNAME records.
2. Uses Masscan to scan for open HTTP/HTTPS ports on an organization’s net ranges, as well as any IP addresses outside those ranges that were present in the organization’s A and CNAME records.
3. Uses the Python requests library to collect all responses and store in a MariaDB database. All DNS names corresponding to an IP with open HTTP/HTTPS ports will be included in requests in addition to the IP address, so that sites using different headers will not cause a website to be missed.
4. Downloads Wappalyzer web technologies database and stores in MariaDB database, enabling users to query the location(s) of a common web technology by name.
5. Allows users to query the location(s) where custom regexes are contained within stored responses. Supported Platforms
WebStor presently will run on Linux systems. As it is written in Python, conversion to support Windows would be trivial and is likely to happen in the future. Prerequisites Applications
* Masscan
* If you will be using a cron job to update the database (typical), it is critical that you configure sudo nopasswd for any user executing Masscan scanning via WebStor.
* MariaDB 10.0.5 or later
* The default credentials tried by WebStor will be root and a blank password. See the “Secure options” section for configuring WebStor to use other usernames and passwords to connect to the database. Python libraries
* pip3 install dnspython
* pip3 install beautifulsoup4
* pip3 install mysql-connector-python
* pip3 install js-regex
* pip3 install gevent
* pip3 install requests Availability via PyPI
* If you are simply looking to run WebStor and not edit it, you may install the prerequisite applications and then use ‘sudo pip3 install webstor’.
* After installing WebStor via PyPI, webstor will be in the path and can be run with at the command line regardless of working directory with ‘webstor’ instead of ‘webstor.py’, e.g. ‘webstor -g’. Basic usage
webstor.py [-h] [–ADD-HTTP-PORT HTTPPORTTOADD] [–CLEAR-HTTP]
[–ADD-HTTPS-PORT HTTPSPORTTOADD] [–CLEAR-HTTPS]
[–ADD-CUSTOM-FINGERPRINT FINGERPRINT]
[–DELETE-CUSTOM-FINGERPRINT FINGERPRINTNAMETODELETE]
[–IMPORT-CUSTOM-FINGERPRINT IMPORTFINGERPRINTFILE]
[–CLEAR-CUSTOM-FINGERPRINTS] [–SHOW-CONFIG]
[–SHOW-CONFIG-FULL] [–RUN-MASSCAN]
[–SET-MASSCAN-RANGES SETSCANRANGES]
[–IMPORT-MASSCAN-RANGES IMPORTSCANRANGES]
[–DELETE-RANGE RANGETODELETE] [–ADD-PATH PATHTOADD]
[–DELETE-PATH PATHTODELETE] [–CLEAR-PATHS]
[–REFRESH-RESPONSES] [–SEARCH-PATTERN SEARCHPATTERN]
[–SEARCH-CUSTOM-FINGERPRINT SEARCHFINGERPRINT]
[–SEARCH-WAPPALYZER SEARCHWAPPALYZER] [–NO-TSIG-KEY]
[–TSIG-KEY-IMPORT IMPORTTSIGFILE]
[–TSIG-KEY-REPLACE REPLACEMENTTSIGFILE]
[–DELETE-TSIG TSIGTODELETE]
[–USE-TSIG-FILE-ONLY USETSIGFILEONLY]
[–DOWNLOAD-NEW-WAPPALYZER] [–LIST-WAPPALYZER-TECH-NAMES]
[–ZONE-XFER] [–ADD-DOMAIN DOMAINDETAILS]
[–DELETE-DOMAIN DOMAINTODELETE]
[–IMPORT-ZONE-FILE IMPORTZONEFILE] [–CLEAR-DOMAINS]
[–LIST-DOMAINS] [–LIST-OUTSIDE] [–SQL-CREDS SQLCREDSFILE]
optional arguments:
-h, –help show this help message and exit
–ADD-HTTP-PORT HTTPPORTTO[...]
Webstor : A Script To Quickly Enumerate All Websites Across All Of Your Organization’s Networks
Webstor is a tool implemented in Python under the MIT license for quickly enumerating all websites across all of your organization’s networks, storing their responses, and querying for known web technologies and versions, such as those with zero-day vulnerabilities. It is intended, in particular, to solve the unique problem presented in mid to large sized organizations with decentralized administration, wherein it can be almost impossible to track all of the web technologies deployed by various administrators distributed across different units and networks.
WebStor achieves its goal by performing the following actions:
1. Performs DNS zone transfers to collect an organization’s A and CNAME records.
2. Uses Masscan to scan for open HTTP/HTTPS ports on an organization’s net ranges, as well as any IP addresses outside those ranges that were present in the organization’s A and CNAME records.
3. Uses the Python requests library to collect all responses and store in a MariaDB database. All DNS names corresponding to an IP with open HTTP/HTTPS ports will be included in requests in addition to the IP address, so that sites using different headers will not cause a website to be missed.
4. Downloads Wappalyzer web technologies database and stores in MariaDB database, enabling users to query the location(s) of a common web technology by name.
5. Allows users to query the location(s) where custom regexes are contained within stored responses. Supported Platforms
WebStor presently will run on Linux systems. As it is written in Python, conversion to support Windows would be trivial and is likely to happen in the future. Prerequisites Applications
* Masscan
* If you will be using a cron job to update the database (typical), it is critical that you configure sudo nopasswd for any user executing Masscan scanning via WebStor.
* MariaDB 10.0.5 or later
* The default credentials tried by WebStor will be root and a blank password. See the “Secure options” section for configuring WebStor to use other usernames and passwords to connect to the database. Python libraries
* pip3 install dnspython
* pip3 install beautifulsoup4
* pip3 install mysql-connector-python
* pip3 install js-regex
* pip3 install gevent
* pip3 install requests Availability via PyPI
* If you are simply looking to run WebStor and not edit it, you may install the prerequisite applications and then use ‘sudo pip3 install webstor’.
* After installing WebStor via PyPI, webstor will be in the path and can be run with at the command line regardless of working directory with ‘webstor’ instead of ‘webstor.py’, e.g. ‘webstor -g’. Basic usage
webstor.py [-h] [–ADD-HTTP-PORT HTTPPORTTOADD] [–CLEAR-HTTP]
[–ADD-HTTPS-PORT HTTPSPORTTOADD] [–CLEAR-HTTPS]
[–ADD-CUSTOM-FINGERPRINT FINGERPRINT]
[–DELETE-CUSTOM-FINGERPRINT FINGERPRINTNAMETODELETE]
[–IMPORT-CUSTOM-FINGERPRINT IMPORTFINGERPRINTFILE]
[–CLEAR-CUSTOM-FINGERPRINTS] [–SHOW-CONFIG]
[–SHOW-CONFIG-FULL] [–RUN-MASSCAN]
[–SET-MASSCAN-RANGES SETSCANRANGES]
[–IMPORT-MASSCAN-RANGES IMPORTSCANRANGES]
[–DELETE-RANGE RANGETODELETE] [–ADD-PATH PATHTOADD]
[–DELETE-PATH PATHTODELETE] [–CLEAR-PATHS]
[–REFRESH-RESPONSES] [–SEARCH-PATTERN SEARCHPATTERN]
[–SEARCH-CUSTOM-FINGERPRINT SEARCHFINGERPRINT]
[–SEARCH-WAPPALYZER SEARCHWAPPALYZER] [–NO-TSIG-KEY]
[–TSIG-KEY-IMPORT IMPORTTSIGFILE]
[–TSIG-KEY-REPLACE REPLACEMENTTSIGFILE]
[–DELETE-TSIG TSIGTODELETE]
[–USE-TSIG-FILE-ONLY USETSIGFILEONLY]
[–DOWNLOAD-NEW-WAPPALYZER] [–LIST-WAPPALYZER-TECH-NAMES]
[–ZONE-XFER] [–ADD-DOMAIN DOMAINDETAILS]
[–DELETE-DOMAIN DOMAINTODELETE]
[–IMPORT-ZONE-FILE IMPORTZONEFILE] [–CLEAR-DOMAINS]
[–LIST-DOMAINS] [–LIST-OUTSIDE] [–SQL-CREDS SQLCREDSFILE]
optional arguments:
-h, –help show this help message and exit
–ADD-HTTP-PORT HTTPPORTTO[...]
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Webstor : A Script To Quickly Enumerate All Websites Across All Of Your Organization’s Networks Webstor is a tool implemented in Python under the MIT license for quickly enumerating all websites across all of your organization’s networks…
ADD, -a HTTPPORTTOADD
Add a custom HTTP port.
–CLEAR-HTTP, -aC Clear any custom HTTP ports and revert to default of
80.
–ADD-HTTPS-PORT HTTPSPORTTOADD, -b HTTPSPORTTOADD
Add a custom HTTPS port.
–CLEAR-HTTPS, -bC Clear any custom HTTPS ports and revert to default of
443.
–ADD-CUSTOM-FINGERPRINT FINGERPRINT, -c FINGERPRINT
Add a custom fingerprint in the form ,.
–DELETE-CUSTOM-FINGERPRINT FINGERPRINTNAMETODELETE, -cD FINGERPRINTNAMETODELETE
Delete a custom fingerprint by name.
–IMPORT-CUSTOM-FINGERPRINT IMPORTFINGERPRINTFILE, -cI IMPORTFINGERPRINTFILE
Import a custom fingerprint file with the path
specified.
–CLEAR-CUSTOM-FINGERPRINTS, -cC
Clears all custom fingerprints stored in DB.
–SHOW-CONFIG, -g Show current WebStor configuration (brief).
–SHOW-CONFIG-FULL, -gF
Show current WebStor configuration (full).
–RUN-MASSCAN, -m Runs a new port scan with Masscan on all configured
TCP ports for HTTP and HTTPS, against all configured
ranges and any IP addresses from DNS records that are
outside those ranges.
–SET-MASSCAN-RANGES SETSCANRANGES, -mR SETSCANRANGES
Scan range or ranges, replaces existing ranges in DB,
comma separated, such as: -s
10.10.0.0/16,10.13.0.0/16,192.168.1.0/24
–IMPORT-MASSCAN-RANGES IMPORTSCANRANGES, -mI IMPORTSCANRANGES
Import scan ranges (CIDR blocks) from a specified
file.
–DELETE-RANGE RANGETODELETE, -mD RANGETODELETE
Delete scan range.
–ADD-PATH PATHTOADD, -p PATHTOADD
Add paths for which to request and store responses
besides ‘/’.
–DELETE-PATH PATHTODELETE, -pD PATHTODELETE
Delete paths for which to request and store responses
besides ‘/’.
–CLEAR-PATHS, -pC Clear any custom URL request paths and revert to
default of ‘/’.
–REFRESH-RESPONSES, -r
Refresh URL responses in DB.
–SEARCH-PATTERN SEARCHPATTERN, -sP SEARCHPATTERN
Search for string or regular expression in WebStor
database.
–SEARCH-CUSTOM-FINGERPRINT SEARCHFINGERPRINT, -sC SEARCHFINGERPRINT
Search for technology by name of user-provided custom
fingerprint.
–SEARCH-WAPPALYZER SEARCHWAPPALYZER, -sW SEARCHWAPPALYZER
Search for technology by name (from Wappalyzer Tech
DB) in WebStor DB.
–NO-TSIG-KEY, -tN Do not use DNSSec TSIG key stored in database or a
file, even if present.
–TSIG-KEY-IMPORT IMPORTTSIGFILE, -tI IMPORTTSIGFILE
Import a specified TSIG key file into the database
–TSIG-KEY-REPLACE REPLACEMENTTSIGFILE, -tR REPLACEMENTTSIGFILE
Replace a TSIG key in the database with a specified
file
–DELETE-TSIG TSIGTODELETE, -dT TSIGTODELETE
Delete a TSIG key from the database by name.
–USE-TSIG-FILE-ONLY USETSIGFILEONLY, -tF USETSIGFILEONLY
Only use tsig file specified (full path), do not use
TSIGs stored in the DB. Applies to all domains,
limiting WebStor to one TSIG for zone transfers in the
current execution.
–DOWNLOAD-NEW-WAPPALYZER, -w
Download a new Wappalyzer fingerprints file directly
from GitHub. Overwrites existing Wappalyzer
fingerprint data.
–LIST-WAPPALYZER-TECH-NAMES, -wL
List the names of all Wappalyzer technologies in the
database.
–ZONE-XFER, -z Forces a new zone transfer using all domains, servers,
and associated TSIG keys in DB
–ADD-DOMAIN DOMAINDETAILS, -zA DOMAINDETAILS
Add a domain in the form ,,.
–DELETE-DOMAIN DOMAINTODELETE, -zD DOMAINTODELETE
Delete a DNS domain from the database by name.
–IMPORT-ZONE-FILE IMPORTZONEFILE, -zI IMPORTZONEFILE
Add domains for zone transfers from a file.
–CLEAR-DOMAINS, -zC Clears all DNS domains stored in DB.
–LIST-DOMAINS, -zL Lists all DNS domains stored in DB.
–LIST-OUTSIDE, -e Prints a list of all names and IPs from our zone
transfers that are outside defined net ranges.
–SQL-CREDS SQLCREDSFILE, -q SQLCREDSFILE
Use SQL credentials in file at specified path.
Steps to initially configure WebStor and populate database
NOTE: These steps assume your organization uses just one TSIG key for zone transfers and that all records can be queried from one DNS server. If this is not the case, see the secure/es[...]
Add a custom HTTP port.
–CLEAR-HTTP, -aC Clear any custom HTTP ports and revert to default of
80.
–ADD-HTTPS-PORT HTTPSPORTTOADD, -b HTTPSPORTTOADD
Add a custom HTTPS port.
–CLEAR-HTTPS, -bC Clear any custom HTTPS ports and revert to default of
443.
–ADD-CUSTOM-FINGERPRINT FINGERPRINT, -c FINGERPRINT
Add a custom fingerprint in the form ,.
–DELETE-CUSTOM-FINGERPRINT FINGERPRINTNAMETODELETE, -cD FINGERPRINTNAMETODELETE
Delete a custom fingerprint by name.
–IMPORT-CUSTOM-FINGERPRINT IMPORTFINGERPRINTFILE, -cI IMPORTFINGERPRINTFILE
Import a custom fingerprint file with the path
specified.
–CLEAR-CUSTOM-FINGERPRINTS, -cC
Clears all custom fingerprints stored in DB.
–SHOW-CONFIG, -g Show current WebStor configuration (brief).
–SHOW-CONFIG-FULL, -gF
Show current WebStor configuration (full).
–RUN-MASSCAN, -m Runs a new port scan with Masscan on all configured
TCP ports for HTTP and HTTPS, against all configured
ranges and any IP addresses from DNS records that are
outside those ranges.
–SET-MASSCAN-RANGES SETSCANRANGES, -mR SETSCANRANGES
Scan range or ranges, replaces existing ranges in DB,
comma separated, such as: -s
10.10.0.0/16,10.13.0.0/16,192.168.1.0/24
–IMPORT-MASSCAN-RANGES IMPORTSCANRANGES, -mI IMPORTSCANRANGES
Import scan ranges (CIDR blocks) from a specified
file.
–DELETE-RANGE RANGETODELETE, -mD RANGETODELETE
Delete scan range.
–ADD-PATH PATHTOADD, -p PATHTOADD
Add paths for which to request and store responses
besides ‘/’.
–DELETE-PATH PATHTODELETE, -pD PATHTODELETE
Delete paths for which to request and store responses
besides ‘/’.
–CLEAR-PATHS, -pC Clear any custom URL request paths and revert to
default of ‘/’.
–REFRESH-RESPONSES, -r
Refresh URL responses in DB.
–SEARCH-PATTERN SEARCHPATTERN, -sP SEARCHPATTERN
Search for string or regular expression in WebStor
database.
–SEARCH-CUSTOM-FINGERPRINT SEARCHFINGERPRINT, -sC SEARCHFINGERPRINT
Search for technology by name of user-provided custom
fingerprint.
–SEARCH-WAPPALYZER SEARCHWAPPALYZER, -sW SEARCHWAPPALYZER
Search for technology by name (from Wappalyzer Tech
DB) in WebStor DB.
–NO-TSIG-KEY, -tN Do not use DNSSec TSIG key stored in database or a
file, even if present.
–TSIG-KEY-IMPORT IMPORTTSIGFILE, -tI IMPORTTSIGFILE
Import a specified TSIG key file into the database
–TSIG-KEY-REPLACE REPLACEMENTTSIGFILE, -tR REPLACEMENTTSIGFILE
Replace a TSIG key in the database with a specified
file
–DELETE-TSIG TSIGTODELETE, -dT TSIGTODELETE
Delete a TSIG key from the database by name.
–USE-TSIG-FILE-ONLY USETSIGFILEONLY, -tF USETSIGFILEONLY
Only use tsig file specified (full path), do not use
TSIGs stored in the DB. Applies to all domains,
limiting WebStor to one TSIG for zone transfers in the
current execution.
–DOWNLOAD-NEW-WAPPALYZER, -w
Download a new Wappalyzer fingerprints file directly
from GitHub. Overwrites existing Wappalyzer
fingerprint data.
–LIST-WAPPALYZER-TECH-NAMES, -wL
List the names of all Wappalyzer technologies in the
database.
–ZONE-XFER, -z Forces a new zone transfer using all domains, servers,
and associated TSIG keys in DB
–ADD-DOMAIN DOMAINDETAILS, -zA DOMAINDETAILS
Add a domain in the form ,,.
–DELETE-DOMAIN DOMAINTODELETE, -zD DOMAINTODELETE
Delete a DNS domain from the database by name.
–IMPORT-ZONE-FILE IMPORTZONEFILE, -zI IMPORTZONEFILE
Add domains for zone transfers from a file.
–CLEAR-DOMAINS, -zC Clears all DNS domains stored in DB.
–LIST-DOMAINS, -zL Lists all DNS domains stored in DB.
–LIST-OUTSIDE, -e Prints a list of all names and IPs from our zone
transfers that are outside defined net ranges.
–SQL-CREDS SQLCREDSFILE, -q SQLCREDSFILE
Use SQL credentials in file at specified path.
Steps to initially configure WebStor and populate database
NOTE: These steps assume your organization uses just one TSIG key for zone transfers and that all records can be queried from one DNS server. If this is not the case, see the secure/es[...]