SourceLeakHacker - A Multi Threads Web Application Source Leak Scanner
http://www.kitploit.com/2021/12/sourceleakhacker-multi-threads-web.html
http://www.kitploit.com/2021/12/sourceleakhacker-multi-threads-web.html
SourceLeakHacker is a muilt-threads web directories scanner.Installationpip install -r requirements.txt
Usage dictionary scale --output OUTPUT output folder, default: result/YYYY-MM-DD hh:mm:ss --threads THREADS, -t THREADS threads numbers, default: 4 --timeout TIMEOUT HTTP request timeout --level {CRITICAL,ERROR,WARNING,INFO,DEBUG}, -v {CRITICAL,ERROR,WARNING,INFO,DEBUG} log level --version, -V show program's version number and exit ">usage: SourceLeakHacker.py [options]
optional arguments:
-h, --help show this help message and exit
--url URL url to scan, eg: 'http://127.0.0.1/'
--urls URLS file contains urls to scan, one line one url.
--scale {full,tiny} build-in dictionary scale
--output OUTPUT output folder, default: result/YYYY-MM-DD hh:mm:ss
--threads THREADS, -t THREADS
threads numbers, default: 4
--timeout TIMEOUT HTTP request timeout
--level {CRITICAL,ERROR,WARNING,INFO,DEBUG}, -v {CRITICAL,ERROR,WARNING,INFO,DEBUG}
log level
--version, -V show program's version number and exit
Example$ python SourceLeakHacker.py --url=http://baidu.com --threads=4 --timeout=8
[302] 0 3.035766 text/html; charset=iso-8859-1 http://baidu.com/_/_index.php
[302] 0 3.038096 text/html; charset=iso-8859-1 http://baidu.com/_/__index.php.bak
...
[302] 0 0.063973 text/html; charset=iso-8859-1 http://baidu.com/_adm/_index.php
[302] 0 0.081672 text/html; charset=iso-8859-1 http://baidu.com/_adm/_index.php.bak
Result save in file: result/2020-02-27 07:07:47.csv
$ cat url.txt
http://baidu.com/
http://google.com/
$ python SourceLeakHacker.py --urls=url.txt --threads=4 --timeout=8
[302] 0 2.363600 text/html; charset=iso-8859-1 http://baidu.com/_/__index.php.bak
[302] 0 0.098417 text/html; charset=iso-8859-1 http://baidu.com/_adm/__index.php.bak
...
[302] 0 0.060524 text/html; charset=iso-8859-1 http://google.com/_adm/_index.php.bak
[302] 0 0.075042 text/html; charset=iso-8859-1 http://baidu.com/_adm/_index.php.back
Result save in file: result/2020-02-27 07:08:54.csv
Demo
Usage dictionary scale --output OUTPUT output folder, default: result/YYYY-MM-DD hh:mm:ss --threads THREADS, -t THREADS threads numbers, default: 4 --timeout TIMEOUT HTTP request timeout --level {CRITICAL,ERROR,WARNING,INFO,DEBUG}, -v {CRITICAL,ERROR,WARNING,INFO,DEBUG} log level --version, -V show program's version number and exit ">usage: SourceLeakHacker.py [options]
optional arguments:
-h, --help show this help message and exit
--url URL url to scan, eg: 'http://127.0.0.1/'
--urls URLS file contains urls to scan, one line one url.
--scale {full,tiny} build-in dictionary scale
--output OUTPUT output folder, default: result/YYYY-MM-DD hh:mm:ss
--threads THREADS, -t THREADS
threads numbers, default: 4
--timeout TIMEOUT HTTP request timeout
--level {CRITICAL,ERROR,WARNING,INFO,DEBUG}, -v {CRITICAL,ERROR,WARNING,INFO,DEBUG}
log level
--version, -V show program's version number and exit
Example$ python SourceLeakHacker.py --url=http://baidu.com --threads=4 --timeout=8
[302] 0 3.035766 text/html; charset=iso-8859-1 http://baidu.com/_/_index.php
[302] 0 3.038096 text/html; charset=iso-8859-1 http://baidu.com/_/__index.php.bak
...
[302] 0 0.063973 text/html; charset=iso-8859-1 http://baidu.com/_adm/_index.php
[302] 0 0.081672 text/html; charset=iso-8859-1 http://baidu.com/_adm/_index.php.bak
Result save in file: result/2020-02-27 07:07:47.csv
$ cat url.txt
http://baidu.com/
http://google.com/
$ python SourceLeakHacker.py --urls=url.txt --threads=4 --timeout=8
[302] 0 2.363600 text/html; charset=iso-8859-1 http://baidu.com/_/__index.php.bak
[302] 0 0.098417 text/html; charset=iso-8859-1 http://baidu.com/_adm/__index.php.bak
...
[302] 0 0.060524 text/html; charset=iso-8859-1 http://google.com/_adm/_index.php.bak
[302] 0 0.075042 text/html; charset=iso-8859-1 http://baidu.com/_adm/_index.php.back
Result save in file: result/2020-02-27 07:08:54.csv
Demo
TODOs Arguments parser. Store scan (https://www.kitploit.com/search/label/Scan) result into csv file. Support for multiple urls (from file). Add help comments for every params. Update Usage. Adjust dictionary elements order systematically. Change logger in order to suite for both windows (https://www.kitploit.com/search/label/Windows) and linux. Add log level. Update Screenshots. Retry and avoid dead lock Store scan result into sqlite (https://www.kitploit.com/search/label/SQLite) database. Download small url contents, then store them into sqlite database.Known Bugs CTRL C does not works on windows platform
Download SourceLeakHacker (https://github.com/WangYihang/SourceLeakHacker)
Download SourceLeakHacker (https://github.com/WangYihang/SourceLeakHacker)
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
SourceLeakHacker - A Multi Threads Web Application Source Leak Scanner
https://blogger.googleusercontent.com/img/a/AVvXsEgUOdDFx17sXG1CMjHy7O4iwGy8vmT8hDgdA9vKZdPw1Of6KmjIo_MGjGWzcRtPtg5V814r-RICiL1TxRG-QNUnL0IhfQjLu-KTZraIUfut3ks9Nj1SCJqa00_bo5Ujpenh0Mh9JorJVg6e8I2OLoJQsuTtuWhwJPrVibRNacVtvFEiFNu_RGgSsGU76g=w640-h250 SourceLeakHacker is a muilt-threads web directories scanner. Installation
* Store scan result into csv file.
* Support for multiple urls (from file).
* Add help comments for every params.
* Update Usage.
* Adjust dictionary elements order systematically.
* Change logger in order to suite for both windows and linux.
* Add log level.
* Update Screenshots.
* Retry and avoid dead lock
* Store scan result into sqlite database.
* Download small url contents, then store them[...]
SourceLeakHacker - A Multi Threads Web Application Source Leak Scanner
https://blogger.googleusercontent.com/img/a/AVvXsEgUOdDFx17sXG1CMjHy7O4iwGy8vmT8hDgdA9vKZdPw1Of6KmjIo_MGjGWzcRtPtg5V814r-RICiL1TxRG-QNUnL0IhfQjLu-KTZraIUfut3ks9Nj1SCJqa00_bo5Ujpenh0Mh9JorJVg6e8I2OLoJQsuTtuWhwJPrVibRNacVtvFEiFNu_RGgSsGU76g=w640-h250 SourceLeakHacker is a muilt-threads web directories scanner. Installation
pip install -r requirements.txt Usage dictionary scale --output OUTPUT output folder, default: result/YYYY-MM-DD hh:mm:ss --threads THREADS, -t THREADS threads numbers, default: 4 --timeout TIMEOUT HTTP request timeout --level {CRITICAL,ERROR,WARNING,INFO,DEBUG}, -v {CRITICAL,ERROR,WARNING,INFO,DEBUG} log level --version, -V show program's version number and exit ">usage: SourceLeakHacker.py [options]
optional arguments:
-h, --help show this help message and exit
--url URL url to scan, eg: 'http://127.0.0.1/'
--urls URLS file contains urls to scan, one line one url.
--scale {full,tiny} build-in dictionary scale
--output OUTPUT output folder, default: result/YYYY-MM-DD hh:mm:ss
--threads THREADS, -t THREADS
threads numbers, default: 4
--timeout TIMEOUT HTTP request timeout
--level {CRITICAL,ERROR,WARNING,INFO,DEBUG}, -v {CRITICAL,ERROR,WARNING,INFO,DEBUG}
log level
--version, -V show program's version number and exit Example$ python SourceLeakHacker.py --url=http://baidu.com --threads=4 --timeout=8
[302] 0 3.035766 text/html; charset=iso-8859-1 http://baidu.com/_/_index.php
[302] 0 3.038096 text/html; charset=iso-8859-1 http://baidu.com/_/__index.php.bak
...
[302] 0 0.063973 text/html; charset=iso-8859-1 http://baidu.com/_adm/_index.php
[302] 0 0.081672 text/html; charset=iso-8859-1 http://baidu.com/_adm/_index.php.bak
Result save in file: result/2020-02-27 07:07:47.csv $ cat url.txt
http://baidu.com/
http://google.com/
$ python SourceLeakHacker.py --urls=url.txt --threads=4 --timeout=8
[302] 0 2.363600 text/html; charset=iso-8859-1 http://baidu.com/_/__index.php.bak
[302] 0 0.098417 text/html; charset=iso-8859-1 http://baidu.com/_adm/__index.php.bak
...
[302] 0 0.060524 text/html; charset=iso-8859-1 http://google.com/_adm/_index.php.bak
[302] 0 0.075042 text/html; charset=iso-8859-1 http://baidu.com/_adm/_index.php.back
Result save in file: result/2020-02-27 07:08:54.csv Demohttps://blogger.googleusercontent.com/img/a/AVvXsEhrTF16-jNo9Xpd8fvdoSzH2dvJ5fX-VeHuKpgzTGp15v8SyvheK4vUxeI0Eo0s1-5bSD5-SEhct4uiRfYjxetMSsBMQXRMsYxsY2qmmK0calYLLOr_oxPlxPNSitl9An7ky_ZSS5-QyT47pohwFv07znx3uZnSd9WBuBUJb9H1ERMnCU0PfpB7Y_ZDFA=w640-h250 https://blogger.googleusercontent.com/img/a/AVvXsEg2ZSBj_e0bT-VQ2EdQl5hGNK94aT47vYz8Tvyhy2xL9GpPIZKmCyAw4Mb28h0V22uPiyb8TJ9nBT7THVO_l5WeTXg56hv43ExxkmpSfJkAJWtat_p_7C4LaR6LvgumpEWQv5j8Cr28dGkue9wxl_a5lP1YtTAQkIHNwdv1tqtdTAsSku4OBnW2rZ5_ag=w640-h238 https://blogger.googleusercontent.com/img/a/AVvXsEiOGCv00CrdyqNnX7VDqoyoUbGM9cCVpa4-ZnMb2opuddiHOFcmawhZuYieo_50TVvBO-jyCFCPr_vkwroLiFPt_mBWNofx4bUIb5KQoW05yVTJRDicxKrklIbmY0H_2uUDoaUMYgQaewrOZ2LHTfrDPD8smZ-bNnWOFjVGuuJL60jKl6HCu-aDGJsOaQ=w640-h338 TODOs* Arguments parser.* Store scan result into csv file.
* Support for multiple urls (from file).
* Add help comments for every params.
* Update Usage.
* Adjust dictionary elements order systematically.
* Change logger in order to suite for both windows and linux.
* Add log level.
* Update Screenshots.
* Retry and avoid dead lock
* Store scan result into sqlite database.
* Download small url contents, then store them[...]
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! SourceLeakHacker - A Multi Threads Web Application Source Leak Scanner https://blogger.googleusercontent.com/img/a/AVvXsEgUOdDFx17sXG1CMjHy7O4iwGy8vmT8hDgdA9vKZdPw1Of6KmjIo_MGjGWzcRtPtg5V814r-RICiL1TxRG-QNUnL0IhfQjLu-KTZraIUfut3…
into sqlite database. Known Bugs* CTRL C does not works on windows platform Download SourceLeakHacker
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Mr. Robot VM Walkthrough
https://cdn-images-1.medium.com/max/792/0*Wgs8ADDi2shsCU0E.png
Makineyi indirebilirsiniz.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Mr. Robot VM Walkthrough
https://cdn-images-1.medium.com/max/792/0*Wgs8ADDi2shsCU0E.png
Makineyi indirebilirsiniz.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Mr. Robot VM Walkthrough
Makineyi indirebilirsiniz.
hacking: security in practice
Rant: Hacking Nigerian Politicians
Idk who is going to read this but i really can’t stand Nigerian politicians and their corruption. Millions of people are living below the poverty line meanwhile politicians and their families are becoming stinky wealthy. I wish that hackers who hack accounts and data would target these politicians. 😡
submitted by /u/Twist_Material
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Rant: Hacking Nigerian Politicians
Idk who is going to read this but i really can’t stand Nigerian politicians and their corruption. Millions of people are living below the poverty line meanwhile politicians and their families are becoming stinky wealthy. I wish that hackers who hack accounts and data would target these politicians. 😡
submitted by /u/Twist_Material
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Rant: Hacking Nigerian Politicians
Idk who is going to read this but i really can’t stand Nigerian politicians and their corruption. Millions of people are living below the poverty...
https://b.thumbs.redditmedia.com/WqA-iNvAUo8DGvFkVUyP9o1itqRz6nRI4J5TmdLSzyU.jpg https://preview.redd.it/gofjcclf1z781.jpg?width=699&format=pjpg&auto=webp&s=1687e5f17fdcac987812a2a1005767ab41b19fee
(first published on a blog forum nov 24, 2021)
computer chipset device fingerprinting via bluetooth net, apparently this non bluetooth device can have its data collected on mesh network with terminal commands for netstat related to listening, message; wireless
-Intel Me soe
-hardware (wifi radio)
-me ≠ physicality
-me ≅ Intel /ssd MPN/3LA (rfid?)
submitted by /u/scryblackwren
[link] [comments]
(first published on a blog forum nov 24, 2021)
computer chipset device fingerprinting via bluetooth net, apparently this non bluetooth device can have its data collected on mesh network with terminal commands for netstat related to listening, message; wireless
-Intel Me soe
-hardware (wifi radio)
-me ≠ physicality
-me ≅ Intel /ssd MPN/3LA (rfid?)
submitted by /u/scryblackwren
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
MIT xPRO Professional Certificate in Coding
Hey guys and gals,
I just wanted to take a moment to let you know that the xPRO Department of MIT will be offering a Professional Certificate in Coding(Full Time) starting on February 9th, 2022. It's a 4 month online program covering Front and Back End Development.
There are several payment options and loans available. There is also a $950 Tuition Assistance right now with code: MOPCCOFTTA that you can enter on the payment portal. However, if you are using an Ascent or Sallie Mae loan, you will need to call them so the Admissions Department can deduct this tuition assistance from your loan.
You can also get an additional $500 off just by using the link below to apply:
$500 OFF using this link
I look forward to seeing some of you there.
Thank you and good luck!!!
submitted by /u/AwesomenessPie
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
MIT xPRO Professional Certificate in Coding
Hey guys and gals,
I just wanted to take a moment to let you know that the xPRO Department of MIT will be offering a Professional Certificate in Coding(Full Time) starting on February 9th, 2022. It's a 4 month online program covering Front and Back End Development.
There are several payment options and loans available. There is also a $950 Tuition Assistance right now with code: MOPCCOFTTA that you can enter on the payment portal. However, if you are using an Ascent or Sallie Mae loan, you will need to call them so the Admissions Department can deduct this tuition assistance from your loan.
You can also get an additional $500 off just by using the link below to apply:
$500 OFF using this link
I look forward to seeing some of you there.
Thank you and good luck!!!
submitted by /u/AwesomenessPie
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
MIT xPRO Professional Certificate in Coding
Hey guys and gals, I just wanted to take a moment to let you know that the xPRO Department of MIT will be offering a **Professional Certificate...
Weapons in my quiver: Tools and extension I use in bounties
https://manasharsh.medium.com/weapons-in-my-quiver-tools-and-extension-i-use-in-bounties-d8e2e0265fb?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://manasharsh.medium.com/weapons-in-my-quiver-tools-and-extension-i-use-in-bounties-d8e2e0265fb?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Weapons in my quiver: Tools and extension I use in bounties
As this blog already describes, I will be putting some info about tools and extensions which I use daily in my bounties. For an early…
As this blog already describes, I will be putting some info about tools and extensions which I use daily in my bounties. For an early…Continue reading on Medium » (https://manasharsh.medium.com/weapons-in-my-quiver-tools-and-extension-i-use-in-bounties-d8e2e0265fb?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Weapons in my quiver: Tools and extension I use in bounties
As this blog already describes, I will be putting some info about tools and extensions which I use daily in my bounties. For an early…
Legit or not so much
https://www.reddit.com/r/Pentesting/comments/rpdml6/legit_or_not_so_much/
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/rpdml6/legit_or_not_so_much/
___________________________
@hacking_Attack
@Hacking_Video
reddit
Legit or not so much
Posted in r/Pentesting by u/stewtech3 • 5 points and 2 comments