Skweez - fast domain crawler and wordlist generator
https://www.reddit.com/r/redteamsec/comments/qtyo38/skweez_fast_domain_crawler_and_wordlist_generator/
submitted by /u/edermi (https://www.reddit.com/user/edermi)
[link] (https://github.com/edermi/skweez) [comments] (https://www.reddit.com/r/redteamsec/comments/qtyo38/skweez_fast_domain_crawler_and_wordlist_generator/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/qtyo38/skweez_fast_domain_crawler_and_wordlist_generator/
submitted by /u/edermi (https://www.reddit.com/user/edermi)
[link] (https://github.com/edermi/skweez) [comments] (https://www.reddit.com/r/redteamsec/comments/qtyo38/skweez_fast_domain_crawler_and_wordlist_generator/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Skweez - fast domain crawler and wordlist generator
Posted in r/redteamsec by u/edermi • 8 points and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Clash - A Rule-Based Tunnel In Go
https://blogger.googleusercontent.com/img/a/AVvXsEjrc9pWmwyXU03cXJkN33j6uF-bZ_PVzNJS-RmTjNLCzqQ4OjLt7jx9LFW5qfegQGKWmeoxKEh4MFAu8_kxqsc0qrKDzjbgoonWcuSxCdRGydWVhfAggp3w-jSOHqIuD5o04coCEb1NxSt51sdYZ-Tpq_9gmkexJzyoOPZo1ISYwHI_ly3o1aUOffq05w=s320
A rule-based tunnel in Go.
Features
* Local HTTP/HTTPS/SOCKS server with authentication support
* VMess, Shadowsocks, Trojan, Snell protocol support for remote connections
* Built-in DNS server that aims to minimize DNS pollution attack impact, supports DoH/DoT upstream and fake IP.
* Rules based off domains, GEOIP, IPCIDR or Process to forward packets to different nodes
* Remote groups allow users to implement powerful rules. Supports automatic fallback, load balancing or auto select node based off latency
* Remote providers, allowing users to get node lists remotely instead of hardcoding in config
* Netfilter TCP redirecting. Deploy Clash on your Internet gateway with
* Comprehensive HTTP RESTful API controller
Premium Features
* TUN mode on macOS, Linux and Windows. Doc
* Match your tunnel by Script
* Rule Provider
Getting Started
Documentations are now moved to GitHub Wiki.
Premium Release
Release
Development
If you want to build an application that uses clash as a library, check out the the GitHub Wiki
Credits
* riobard/go-shadowsocks2
* v2ray/v2ray-core
* WireGuard/wireguard-go
License
This software is released under the GPL-3.0 license.
Download Clash
___________________________
@hacking_Attack
@Hacking_Video
Clash - A Rule-Based Tunnel In Go
https://blogger.googleusercontent.com/img/a/AVvXsEjrc9pWmwyXU03cXJkN33j6uF-bZ_PVzNJS-RmTjNLCzqQ4OjLt7jx9LFW5qfegQGKWmeoxKEh4MFAu8_kxqsc0qrKDzjbgoonWcuSxCdRGydWVhfAggp3w-jSOHqIuD5o04coCEb1NxSt51sdYZ-Tpq_9gmkexJzyoOPZo1ISYwHI_ly3o1aUOffq05w=s320
A rule-based tunnel in Go.
Features
* Local HTTP/HTTPS/SOCKS server with authentication support
* VMess, Shadowsocks, Trojan, Snell protocol support for remote connections
* Built-in DNS server that aims to minimize DNS pollution attack impact, supports DoH/DoT upstream and fake IP.
* Rules based off domains, GEOIP, IPCIDR or Process to forward packets to different nodes
* Remote groups allow users to implement powerful rules. Supports automatic fallback, load balancing or auto select node based off latency
* Remote providers, allowing users to get node lists remotely instead of hardcoding in config
* Netfilter TCP redirecting. Deploy Clash on your Internet gateway with
iptables.* Comprehensive HTTP RESTful API controller
Premium Features
* TUN mode on macOS, Linux and Windows. Doc
* Match your tunnel by Script
* Rule Provider
Getting Started
Documentations are now moved to GitHub Wiki.
Premium Release
Release
Development
If you want to build an application that uses clash as a library, check out the the GitHub Wiki
Credits
* riobard/go-shadowsocks2
* v2ray/v2ray-core
* WireGuard/wireguard-go
License
This software is released under the GPL-3.0 license.
Download Clash
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Pentester Lab: S2–052 VM Walktrough
https://cdn-images-1.medium.com/max/1004/0*zMULv-3zz579X4if.png
Bu makinede bizlere Apache Struts 2 framework kullanan web sunucusunda uzakta komut çalıştırabildiğini(RCE) göstermektedir.
Continue reading on Medium »
Pentester Lab: S2–052 VM Walktrough
https://cdn-images-1.medium.com/max/1004/0*zMULv-3zz579X4if.png
Bu makinede bizlere Apache Struts 2 framework kullanan web sunucusunda uzakta komut çalıştırabildiğini(RCE) göstermektedir.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Karkinos — PenTest para Iniciantes
https://cdn-images-1.medium.com/max/628/0*g7BKEbY-Fm25tfkB.png
O Karkinos é uma ferramenta que esta em evolução e que ate o momento disponibiliza recursos que podem auxiliá-lo durante um PenTest ou em…
Continue reading on 100security »
Karkinos — PenTest para Iniciantes
https://cdn-images-1.medium.com/max/628/0*g7BKEbY-Fm25tfkB.png
O Karkinos é uma ferramenta que esta em evolução e que ate o momento disponibiliza recursos que podem auxiliá-lo durante um PenTest ou em…
Continue reading on 100security »
hacking: security in practice
Government Bug Bounty
Governments should provide Bug Bounty programs otherwise the hacker if they find a vulnerability has an incentive to sell the vulnerability to criminals.
A few months ago I did a post regarding the oil industry in america that was very successful in this section of reddit. Obviously it was a small vulnerability but I sent more than one email to cisa.gov and the problem was fixed only after months and no one from the US government thanked me.
Now I find myself to have found a very serious vulnerability that would allow a "solarwinds" multiplied by 10.
But in spite of my effort to do incessant research and study I am not rewarded.
Give me a computer and 15 hours of time and I find a serious vulnerability in some company. One small mistake, one capable person and solarwinds 2 will show up again.
Now imagine that someone walks into one of the 5 Big IT security companies that provide security software to government agencies and critical companies.
Selling a vulnerability in one of these companies to a hostile intelligence agency can make more than 10 million but can cause billions in damage.
Governments around the world think about it!
submitted by /u/LargeTrader
[link] [comments]
Government Bug Bounty
Governments should provide Bug Bounty programs otherwise the hacker if they find a vulnerability has an incentive to sell the vulnerability to criminals.
A few months ago I did a post regarding the oil industry in america that was very successful in this section of reddit. Obviously it was a small vulnerability but I sent more than one email to cisa.gov and the problem was fixed only after months and no one from the US government thanked me.
Now I find myself to have found a very serious vulnerability that would allow a "solarwinds" multiplied by 10.
But in spite of my effort to do incessant research and study I am not rewarded.
Give me a computer and 15 hours of time and I find a serious vulnerability in some company. One small mistake, one capable person and solarwinds 2 will show up again.
Now imagine that someone walks into one of the 5 Big IT security companies that provide security software to government agencies and critical companies.
Selling a vulnerability in one of these companies to a hostile intelligence agency can make more than 10 million but can cause billions in damage.
Governments around the world think about it!
submitted by /u/LargeTrader
[link] [comments]
reddit
Government Bug Bounty
Governments should provide Bug Bounty programs otherwise the hacker if they find a vulnerability has an incentive to sell the vulnerability to...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
FBI email system reportedly hacked to send fake DHS cyberattack messages
https://external-preview.redd.it/6iwPiFsbsZQOQI3JbftaSyL3FxwvDwI1fJ2ygtZ8Hug.jpg?width=640&crop=smart&auto=webp&s=3337ec3b578ffa62ff97c3a75b6c201ccdc91094 submitted by /u/DrinkMoreCodeMore
[link] [comments]
FBI email system reportedly hacked to send fake DHS cyberattack messages
https://external-preview.redd.it/6iwPiFsbsZQOQI3JbftaSyL3FxwvDwI1fJ2ygtZ8Hug.jpg?width=640&crop=smart&auto=webp&s=3337ec3b578ffa62ff97c3a75b6c201ccdc91094 submitted by /u/DrinkMoreCodeMore
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
What are some essentials to keep on a hardrive
Other than a bootable image and wordlists what else should a person keep on a hardrive
submitted by /u/Background_Gene_3657
[link] [comments]
What are some essentials to keep on a hardrive
Other than a bootable image and wordlists what else should a person keep on a hardrive
submitted by /u/Background_Gene_3657
[link] [comments]
reddit
What are some essentials to keep on a hardrive
Other than a bootable image and wordlists what else should a person keep on a hardrive
hacking: security in practice
How long would it take to crack a password thats just numbers and Capital letters
With a shitty a gpu and cup of course. For a wpa2 wifi pass
submitted by /u/newearth420
[link] [comments]
How long would it take to crack a password thats just numbers and Capital letters
With a shitty a gpu and cup of course. For a wpa2 wifi pass
submitted by /u/newearth420
[link] [comments]
reddit
How long would it take to crack a password thats just numbers and...
With a shitty a gpu and cup of course. For a wpa2 wifi pass
TakeOver Path Directory Public/NonPublic Via Non-Validated Input Username Profile URL
https://aidilarf.medium.com/takeover-path-directory-public-nonpublic-via-non-validated-input-username-profile-url-f4f291d63af?source=rss------bug_bounty-5
https://aidilarf.medium.com/takeover-path-directory-public-nonpublic-via-non-validated-input-username-profile-url-f4f291d63af?source=rss------bug_bounty-5
Assalamualaikum Bug Hunter & Hi EveryoneContinue reading on Medium » (https://aidilarf.medium.com/takeover-path-directory-public-nonpublic-via-non-validated-input-username-profile-url-f4f291d63af?source=rss------bug_bounty-5)