Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
requirements="tor grep sed openssl basez git qrencode pandoc lynx gzip tar python3-stem ${dialog_box} ${web_server}" ## search pkg name for your OSEdit with sed (use insert option -> sed -i''):sed "s|tor_user=.*|tor_user=\"tor\"|" .onionrcSetup the enviromentDetermine the enviromental variable ${ONIONSERVICE_PWD} and add the directory to ${PATH}.add the enviromental variable to find the repo-> exporting this variable possibilitate calling it from inside shell scripts.add directory to path -> call the scripts from any directory as if they were commands (without indicating the path to them or prepending with the shell name).For this, you have two options:Easy: run from inside the cloned repository and it will use the same path as in${PWD}:./setup/setup.shDevelopment: set the variable manually using the absolute path without trailing "/" at the end. Favorable for integrating into other projects. Run from any directory (need to specify the path)./setup/setup.sh -s -p /PATH/TO/ONIONSERVICE/REPO && . ~/."${SHELL##*/}"rcUsageThe repo is now in your $PATH, if you have setup the environment as described above. This means you can call the scripts as if they were any other command.ScriptsThere are some ways to call the scripts, evaluate the advantages and disadvantages:CommandSpecifying shellAdvantagesfollows the shebang, can be used from any directorycan choose the shellDisadvantagesthe scripts must be executableignores the shebang, needs to specify path if not in the same directorySyntaxonionservice-clish onionservice-cliDocumentationTake a loot at the documentation inside docs folder. Read:any markdown file formatted on the shell:ls docs/*.md
pandoc "${ONIONSERVICE_PWD}"/docs/CONTRIBUTING.md | lynx -stdinthe CLI manual (https://github.com/nyxnor/onionservice/blob/main/docs/ONIONSERVICE-CLI.md):man onionservice-cliPortabilityShellsFull compatibility with any POSIX compliant shells: dash, bash, ksh, mksh, yash, ashThe default POSIX shell of your unix-like operating system may vary depending on your system (FreeBSD and NetBSD uses ash, OpenBSD uses ksh, Debian uses dash), but it has a symbolic link leading to it on /usr/bin/sh and/or /bin/sh.Tweak to be compatible with non-POSIX compliant shells::Z SHell (zsh) -> zsh --emulate sh -c onionservice-tuiOperating systemsWorks unix-like operating systems, tested by the maintainer mostly on GNU/Linux Debian 11. Work is being done for *bsd systems, sed is using this trick (https://unix.stackexchange.com/a/401928).Service managersCurrently only systemd is available, planning on implementing SysV, Runit, OpenRC.RequirementsGeneral:Unix-like system.any POSIX shells: dash 0.5.4+, bash 2.03+, ksh 88+, mksh R28+, zsh 3.1.9+, yash 2.29+, busybox ash 1.1.3+ etc.systemd (for tor and vanguards control) - for now, different services managers is a goalsudo privileges.blank lines between Hidden Services blocks in the torrc.HiddenServiceDir different path than DataDir - DataDir/services.Path for folders variables must not contain trainling "/" at the end of the variables on .onionrc (Incorrect: ~/onionservice/, Correct: ~/onionservice).Packages:tor >= 0.3.5grep >=2.0sed >= 2.0python3-stem >=1.8.0openssl >= 1.1basez >= 1.6.2git >= 2.0qrencode >= 4.1.1pandoclynxtargzipThe packages are downloaded when setting up the environment with setup.sh (https://github.com/nyxnor/onionservice/blob/main/setup/setup.sh), the packages that are requirements are specified on .onionrc (https://github.com/nyxnor/onionservice/blob/main/.onionrc). The absolute minimum you can go to is tor grep sed, and you will be limited to enable, disable and renew services.CreditsInspirationsThese are projects that inspires OnionService development, each with their own unique characteristic.OnionShare CLI (https://github.com/onionshare/onionshare/tree/develop/cli) possibilitates ephemeral onion services that never touch the disk and can be run on Tails or Whonix easily. It provides onion authentication, focusing on running servers to send and
receive files, chat and host a static website. OnionService evolved by watching the sharing capabilities of OnionShare and converting them to shellscript.RaspiBlitz (https://github.com/rootzoll/raspiblitz/blob/v1.7/home.admin/config.scripts/internet.hiddenservice.sh) provides a ton of bitcoin related services that can be run over tor, so onion services is the choice to access your node from outside LAN. OnionService started by forking Blitz script to remove hardcoded paths.TorBox (https://github.com/radio24/TorBox) is an easy to use, anonymizing router that creates a separate WiFi that routes the encrypted network data over the Tor network. It also helps configuring bridges and other countermeasures to bypass censorship. OnionService aims to help people on surveillance countries to communicate privately.

Download Onionservice (https://github.com/nyxnor/onionservice)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Bypassing File Extension Filters

อัปโหลดไฟล์ไปยังเว็บเซิร์ฟเวอร์โดยการ bypass เปลี่ยนนามสกุลไฟล์

Continue reading on Medium »
hacking: security in practice
How much work goes into a kernel exploit?

So. Recently, the very talented members of the PS4 jailbreaking community managed to get us our first new WebKit exploit in over three years. It's great, having the ability to run my own programs on my PS4. However, this is only the first step.

Everyone is wanting a kernel exploit. This would be the first step towards custom firmware and truly unlocking the PS4. However, I'm curious... How much work goes into a kernel exploit?

I know we aren't getting it any time soon, but if we were to get it, how much work would need to be done to get it?

(Keep in mind that the most IT knowledge is on system hardening, and preventing hacking so actually hacking is outside of what I know...)

submitted by /u/forcedreset1
[link] [comments]
hacking: security in practice
USB password

Hi I’m only so and so good with the hacking side of coding but I believe that this falls in the category I am trying to make a program that will Be saved on a usb and will run whenever it is plugged in the code will be a password enterer So basically once i plug in the usb the code on it will run and automatically sign me in by entering my password so like a rubber ducky only without the brute force part lol

submitted by /u/Biguy15z
[link] [comments]
hacking: security in practice
How are hackers tracked?

Like for example you hack someone’s bank account. You make transactions to random accounts just for fun. How is it possible that you were exposed as the culprit?

submitted by /u/Unknown_ZZ
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Onionservice - Manage Your Onion Services Via CLI Or TUI On Unix-like Operating System With A POSIX Compliant Shell

https://blogger.googleusercontent.com/img/a/AVvXsEifTeM3jvuBVldW18VyO8h5-vWf4xFx99Y1ZbEyxX1WNVVBgLQKvRFwUw7dD3LjEXcC7kv1Tl5mmqrgH0XihD51JASF4t9Uu4KwPkzd1Nt0fcRwA2hr7bna18ZS2JVUK9bpA8DlYUQToyNyszp8QH7fRXPzpfdNflf875WF1_FapPhS6GOS0jTMEKuTng=w640-h430 Feature-rich Onion Service manager for UNIX-like operating systems written in POSIX conformant shellscriptA collection of Onion Services features implemented for Unix-like systems following the Portable Operating System Interface standard.

WARNING: do not trust this repo yet, backup your hs keys in another location. This project has not been released and should be considered for development only.

Quick link to this repository: https://git.io/onionservice IntroductionImageshttps://blogger.googleusercontent.com/img/a/AVvXsEifTeM3jvuBVldW18VyO8h5-vWf4xFx99Y1ZbEyxX1WNVVBgLQKvRFwUw7dD3LjEXcC7kv1Tl5mmqrgH0XihD51JASF4t9Uu4KwPkzd1Nt0fcRwA2hr7bna18ZS2JVUK9bpA8DlYUQToyNyszp8QH7fRXPzpfdNflf875WF1_FapPhS6GOS0jTMEKuTng=w640-h430 https://blogger.googleusercontent.com/img/a/AVvXsEgcTNAcbO_42Gw2xtwy_VbCBm-ANeSUz0SJhwz4k03ttKVqJ_fdi6eZNcjfJ0u3lAeHg5VFseZXTogB1i-j-zxYverV7GnP9PgIHKmqg67UGdBvR2V3li1afEA5U8q9yIjyfeY0441F_JlTPROYTAQKSqaoyfRZD8MOtr9fz90OHOo3YWJbe1BxMVGLRQ=w640-h332 EchosystemOnion Services are the Hidden Services of Tor which use onion routing as its base for stablishing private connections. They offer:

* Location hiding - IP address aren't used, so your location is protected.
* End-to-end authentication - Only the owner of the hs secret key can host the same onion, so no impersonation is possible, no man-in-the-middle.
* End-to-end encryption - Traffic is encrypted from the client to the onion host, no need to trust CAs which are a fallible model.
* NAT punching - On a firewalled network, no need to open ports

For a deeper understanding, read the Rendezvous Specification and Tor design.

Onion Routing tries to solve most of these problems but it is still centralized by the Directory Authorities, and referencing Matt Traudt's blog post: replacing it for something more distributed is not a trivial task.

On the Tor echosystem, from TPO metrics, comparing only Free and Open Source Operating Systems, Linuxdominates on relays by platform and Tor Browser downloads by platform over BSD. Data regarding which operating system the onion service operator can not be easily acquired for obvious reasons. That was on the network level, but know on the user system, even if one chooses a Free and Open Source Operating System, GNU/Linux dominates a big share over *BSD, having a huge impact on the main software used for the kernel (Linux), shell (bash), service manager (systemd). GoalThe goal of this project is:

* facilitates onion service management, from activating a service to adding client authorization to it, giving the full capabilities of editing files manually would have but with less tipying.
* show the that managing the onion service is much more than just using a webserver with your pages.
* distribution, from the source code level (FOSS) to the effect it takes when it allows anyone to run the code on any operating system, shell or service manager. Mitigation from a single point of failure

Descentralization from a single point of failure:

* Kernel from predominant Linuxto also BSD.
* Shell from predominant bashto also any POSIX shell such as ksh, (y,d)ashand zsh(emulating sh).
* Service manager from predominant systemdto also OpenRC.

Editing the tor configuration file (torrc) is not difficult, but automation solves problem of misconfiguration and ha[...]