Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
White Hat, Grey Hat, and Black Hat Hackers, What Are They?
What even is a “hacker”?
Continue reading on Medium »
White Hat, Grey Hat, and Black Hat Hackers, What Are They?
What even is a “hacker”?
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TYPES OF PORTS IN THE NETWORKING.
https://cdn-images-1.medium.com/max/1688/1*2iMZruQL0ubUHxA7ZUN5QQ.png
All H4ckers must know this ports!!
Continue reading on Medium »
TYPES OF PORTS IN THE NETWORKING.
https://cdn-images-1.medium.com/max/1688/1*2iMZruQL0ubUHxA7ZUN5QQ.png
All H4ckers must know this ports!!
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Bitcoin Price Back Above $50,000 | Bent Finances Makes a Stronger Comeback | Bitcoin News
https://cdn-images-1.medium.com/max/961/1*ml3WcUAaBtrgWYMntG2CMg.png
News, YT Videos, Discount Coupons, Technical analysis, and much more are right in your inbox!
Continue reading on Coinmonks »
Bitcoin Price Back Above $50,000 | Bent Finances Makes a Stronger Comeback | Bitcoin News
https://cdn-images-1.medium.com/max/961/1*ml3WcUAaBtrgWYMntG2CMg.png
News, YT Videos, Discount Coupons, Technical analysis, and much more are right in your inbox!
Continue reading on Coinmonks »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
CVE-2021–40579
https://cdn-images-1.medium.com/max/1468/1*T7naSjHYJKUF3glTjIOVZA.png
Insecure direct object references (IDOR)
Continue reading on Medium »
CVE-2021–40579
https://cdn-images-1.medium.com/max/1468/1*T7naSjHYJKUF3glTjIOVZA.png
Insecure direct object references (IDOR)
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Planning Your First Ethical Hack on a Corporate Network
https://cdn-images-1.medium.com/max/600/0*HTjJeczftrC3ihd4
After researching and pitching several potential clients, you landed your first contract as a Penetration Tester.
Continue reading on Medium »
Planning Your First Ethical Hack on a Corporate Network
https://cdn-images-1.medium.com/max/600/0*HTjJeczftrC3ihd4
After researching and pitching several potential clients, you landed your first contract as a Penetration Tester.
Continue reading on Medium »
Passive Information Gathering for Pentesting
Information gathering very important for pentester.Continue reading on Medium »
Read more...
Information gathering very important for pentester.Continue reading on Medium »
Read more...
Abeats Bounty Program
Aiming to test the website's usability, the bounty program is ideal for gathering engagement from the community and finding the necessary…Continue reading on Medium »
Read more...
Aiming to test the website's usability, the bounty program is ideal for gathering engagement from the community and finding the necessary…Continue reading on Medium »
Read more...
SourceLeakHacker - A Multi Threads Web Application Source Leak Scanner
http://www.kitploit.com/2021/12/sourceleakhacker-multi-threads-web.html
http://www.kitploit.com/2021/12/sourceleakhacker-multi-threads-web.html
SourceLeakHacker is a muilt-threads web directories scanner.Installationpip install -r requirements.txt
Usage dictionary scale --output OUTPUT output folder, default: result/YYYY-MM-DD hh:mm:ss --threads THREADS, -t THREADS threads numbers, default: 4 --timeout TIMEOUT HTTP request timeout --level {CRITICAL,ERROR,WARNING,INFO,DEBUG}, -v {CRITICAL,ERROR,WARNING,INFO,DEBUG} log level --version, -V show program's version number and exit ">usage: SourceLeakHacker.py [options]
optional arguments:
-h, --help show this help message and exit
--url URL url to scan, eg: 'http://127.0.0.1/'
--urls URLS file contains urls to scan, one line one url.
--scale {full,tiny} build-in dictionary scale
--output OUTPUT output folder, default: result/YYYY-MM-DD hh:mm:ss
--threads THREADS, -t THREADS
threads numbers, default: 4
--timeout TIMEOUT HTTP request timeout
--level {CRITICAL,ERROR,WARNING,INFO,DEBUG}, -v {CRITICAL,ERROR,WARNING,INFO,DEBUG}
log level
--version, -V show program's version number and exit
Example$ python SourceLeakHacker.py --url=http://baidu.com --threads=4 --timeout=8
[302] 0 3.035766 text/html; charset=iso-8859-1 http://baidu.com/_/_index.php
[302] 0 3.038096 text/html; charset=iso-8859-1 http://baidu.com/_/__index.php.bak
...
[302] 0 0.063973 text/html; charset=iso-8859-1 http://baidu.com/_adm/_index.php
[302] 0 0.081672 text/html; charset=iso-8859-1 http://baidu.com/_adm/_index.php.bak
Result save in file: result/2020-02-27 07:07:47.csv
$ cat url.txt
http://baidu.com/
http://google.com/
$ python SourceLeakHacker.py --urls=url.txt --threads=4 --timeout=8
[302] 0 2.363600 text/html; charset=iso-8859-1 http://baidu.com/_/__index.php.bak
[302] 0 0.098417 text/html; charset=iso-8859-1 http://baidu.com/_adm/__index.php.bak
...
[302] 0 0.060524 text/html; charset=iso-8859-1 http://google.com/_adm/_index.php.bak
[302] 0 0.075042 text/html; charset=iso-8859-1 http://baidu.com/_adm/_index.php.back
Result save in file: result/2020-02-27 07:08:54.csv
Demo
Usage dictionary scale --output OUTPUT output folder, default: result/YYYY-MM-DD hh:mm:ss --threads THREADS, -t THREADS threads numbers, default: 4 --timeout TIMEOUT HTTP request timeout --level {CRITICAL,ERROR,WARNING,INFO,DEBUG}, -v {CRITICAL,ERROR,WARNING,INFO,DEBUG} log level --version, -V show program's version number and exit ">usage: SourceLeakHacker.py [options]
optional arguments:
-h, --help show this help message and exit
--url URL url to scan, eg: 'http://127.0.0.1/'
--urls URLS file contains urls to scan, one line one url.
--scale {full,tiny} build-in dictionary scale
--output OUTPUT output folder, default: result/YYYY-MM-DD hh:mm:ss
--threads THREADS, -t THREADS
threads numbers, default: 4
--timeout TIMEOUT HTTP request timeout
--level {CRITICAL,ERROR,WARNING,INFO,DEBUG}, -v {CRITICAL,ERROR,WARNING,INFO,DEBUG}
log level
--version, -V show program's version number and exit
Example$ python SourceLeakHacker.py --url=http://baidu.com --threads=4 --timeout=8
[302] 0 3.035766 text/html; charset=iso-8859-1 http://baidu.com/_/_index.php
[302] 0 3.038096 text/html; charset=iso-8859-1 http://baidu.com/_/__index.php.bak
...
[302] 0 0.063973 text/html; charset=iso-8859-1 http://baidu.com/_adm/_index.php
[302] 0 0.081672 text/html; charset=iso-8859-1 http://baidu.com/_adm/_index.php.bak
Result save in file: result/2020-02-27 07:07:47.csv
$ cat url.txt
http://baidu.com/
http://google.com/
$ python SourceLeakHacker.py --urls=url.txt --threads=4 --timeout=8
[302] 0 2.363600 text/html; charset=iso-8859-1 http://baidu.com/_/__index.php.bak
[302] 0 0.098417 text/html; charset=iso-8859-1 http://baidu.com/_adm/__index.php.bak
...
[302] 0 0.060524 text/html; charset=iso-8859-1 http://google.com/_adm/_index.php.bak
[302] 0 0.075042 text/html; charset=iso-8859-1 http://baidu.com/_adm/_index.php.back
Result save in file: result/2020-02-27 07:08:54.csv
Demo
TODOs Arguments parser. Store scan (https://www.kitploit.com/search/label/Scan) result into csv file. Support for multiple urls (from file). Add help comments for every params. Update Usage. Adjust dictionary elements order systematically. Change logger in order to suite for both windows (https://www.kitploit.com/search/label/Windows) and linux. Add log level. Update Screenshots. Retry and avoid dead lock Store scan result into sqlite (https://www.kitploit.com/search/label/SQLite) database. Download small url contents, then store them into sqlite database.Known Bugs CTRL C does not works on windows platform
Download SourceLeakHacker (https://github.com/WangYihang/SourceLeakHacker)
Download SourceLeakHacker (https://github.com/WangYihang/SourceLeakHacker)