Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
CarPunk : The Car Hacking Toolkit

CarPunk IS VERY SIMILAR TO CANghost, ONLY THE DEFFERENCE IS, IT COMES WITH OPTIONS TO ENABLE OR DISABLE INTERFACE AND BASIC SNIFFING AS EXTRA.

* IT WORKS ON BOTH SIMULATION & REAL CARS.
* HAS THE OPTIONS TO RECORD AND PLAY THE CAN PACKETS.
* NO ANY ARGUMENTS REQUIRED WHEN RUNNING BUT NEED CHANGES(Interface & Name for logfile), IF YOU’RE TRYING IN REAL-WORLD.
* TESTED ON UBUNTU WITH BOTH SIMULATOR & REAL CARS.

THINGS TO DO BEFORE RUNNING CARPUNK

* YOU HAVE TO LOAD YOUR CANBUS DRIVER MANUALLY, CARPUNK ONLY DOES UP AND DOWN.
* OPEN carpunk.sh FILE INTO YOUR FAVORITE TEXT-EDITOR AND CHANGE THE INTERFACE AND LOG-FILENAME AS PER YOUR NEED. DELAFULT INTERFCE IS vcan0 & carpunk AS LOG-FILENAME.
* Installation & Usage of CarPunk :

git clone https://github.com/souravbaghz/CarPunk
cd CarPunk
sudo bash carpunk.sh
https://blogger.googleusercontent.com/img/a/AVvXsEhCqc_1M1I_4YgT-CZ9BFEBLTkDWD_7vLNmByECwTBKSSlGIpu7XWpysKcOqbNhSBXfz1tUvaCsHewiXVwjpOanSMEEU23JTl2YjCJ8uJw6SZ0q-6j8KyqfxlG44Xmh3jRGunlHaIECBMPz511HXjA8XPbAi5WM4EMFNYpiWUlDD5xn0Vm7ORcr5-2c=s1851
* [1] UP the CAN Interface : To Enable/UP the CAN Interface.
* [2] Down the CAN Interface : Make The CAN Interface Down.
* [3] Start the Basic Sniffing : To Start Sniffing Only(get terminal clear as soon as you stop it by ctrl+c).
* [4] Record the CAN Packets : To Capture/Record The CAN Packets Into File(as carpunk1.log- name will be carpunk2.log,carpunk3.log,so on for multiple times).
* [5] Play the CAN Packets : Replay The CAN Packets Which You Captured Earlier(Need to specify the log-file. e.g: carpunk1.log).
* [0] Exit : To Exit The CarPunk Script.
Download

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
GIF
Kali Linux Tutorials
BurpCrypto : A Collection Of Burpsuite Encryption Plug-Ins, Support AES/RSA/DES/ExecJs(execute JS Encryption Code In Burpsuite)

Burpcrypto is a collection of burpsuite encryption plug-ins, supporting AES/RSA/DES/ExecJs(execute JS encryption code in burpsuite).

Build

$ mvn package

Usage

中文使用说明

* Download the precompiled jar package from Releases.
* Add this jar package to your burpsuite’s Extensions.
* Switch to BurpCrypto tab, select you need Cipher tab.
* Set key or some value.
* press “Add processor”, and give a name for this processor.
* Switch to Intruder->Payloads->Payload Processing.
* press “Add”, select “Invoke Burp extension”, and select processor you just created.
* press “Start attack”, have fun!

Key Example

* Aes Key(UTF8String): abcdefgabcdefg12
* Aes IV(UTF8String): abcdefgabcdefg12
* Rsa X509 Key: MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCC0hrRIjb3noDWNtbDpANbjt5Iwu2NFeDwU16Ec87ToqeoIm2KI+cOs81JP9aTDk/jkAlU97mN8wZkEMDr5utAZtMVht7GLX33Wx9XjqxUsDfsGkqNL8dXJklWDu9Zh80Ui2Ug+340d5dZtKtd+nv09QZqGjdnSp9PTfFDBY133QIDAQAB
* Rsa Modulus: ca27d90f03753cbbc9958011baf701ac99305b63f68e26ab5617593e01d2fb519127fb87bafbe6e0472ec3a038575fa292adadbc79390a955a61b29431f78f4734773048a45dcf100e23cabf2df11a55aa90cd6b024a44eed1096c3b9e1408d46aae54d7291b82fe4b7867c5eaa45e9cc0ba7f7ae3e5593337c7dcbace2d02ed2fbbff26c6df8a32bb26be80603fcd94c6c8dbd67878d77b37fedcf808e3d8f469aaa7c65d033d547a5c8ea9bdd5c89b836c65852f355a5efd9c7137a186a62b5eb0e052c8be3096d3b51133f8a8c108292a296c99d37bad42bcc3f6c39fa5e583582942b4fc4e7ff4b6779fff5bbaddc65b19c7c57d8cdb39b1a994e08d4a2f50793d8f707d069c380baf0f64bfdce3b35d0b5c5c59348a35a082012aaf4991080abf518b55787969ff24186cb95f7e7218c904cf1dcaeb5bed723e305b83f2e85d6f116d2c7400f9e49d904db8a5a3a0701cdb579fbf3128511acd0f789ece1233ed926d705b3b0dfa34bf33f5ae4bdc611a602aa03aaae13400bc7ad3813ea4474dc62de3d0cb1f5aac277d895a75d38f9b920938fa6b1de35bd6132798c122403c685bdb6e5e24bbd70cfb3e968da0b8affd398e539e7c1e7add09891780bcbd278f3900499ae09cee0dc62e3f92e70001bab6d46261d2801a37f80d84d0e39fce6eaedf106a61b5961960641b9db0e4e23c770e6370ac5d61c6c9eb0f07
* Rsa Exponent: 010001
* DES Key: 12345678
* DESede Key: 123456781234567812345678

Screenshots

AES Example:
https://1.bp.blogspot.com/-jz5UtZAmt4w/YV2d4YZsexI/AAAAAAAALCs/jbwM3zTeuvYxdf23rK0gGW_qRMQB1vgbgCLcBGAsYHQ/s1409/1.gif
ExecJs Example (Here is the modified MD5 algorithm):
https://1.bp.blogspot.com/--D5NTnQsoVs/YV2fbyR7EhI/AAAAAAAALC0/1s92_bJxso40eASDbelps1c3_HByAbeyQCLcBGAsYHQ/s1297/2.gif
Quick Crypto:
https://1.bp.blogspot.com/-899xj4IgMEM/YV2glZ6m_rI/AAAAAAAALC8/BawsFGyiB0spder-9qxOpPCIzr6yckGuACLcBGAsYHQ/s1048/3.gif

Download

___________________________
@hacking_Attack
@Hacking_Video
Finding known exploits for bugbounties.

Hello everyone, in this blog we will be looking at how I found criticals on a private program using known vulnerabilities. This is a…Continue reading on Medium »
Read more...
Into the art of Binary Exploitation 0x000003 [Prominence of Integer-Overflow]

Hey hackers , I’m back again with another portion of our enterprise, the binary exploitation series. In case you’re perusing my article…Continue reading on InfoSec Write-ups »
Read more...
Deep Web
Does anyone have a cock.li invite code?

I can't for the love of god find one, it's basically clicking from one dead link to another. This post might look dumb, but I got nothing to lose by posting here so why not amirite?

submitted by /u/GFollower
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video