Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Common Nginx Misconfiguration leads to Path Traversal
https://cdn-images-1.medium.com/max/2600/0*eA1ZnHCtDmUPuMMA
Recently, I have been invited by my friend to participate into a private pentest project. The target has been using Nginx as its Reverse…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Common Nginx Misconfiguration leads to Path Traversal
https://cdn-images-1.medium.com/max/2600/0*eA1ZnHCtDmUPuMMA
Recently, I have been invited by my friend to participate into a private pentest project. The target has been using Nginx as its Reverse…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Common Nginx Misconfiguration leads to Path Traversal
Recently, I have been invited by my friend to participate into a private pentest project. The target has been using Nginx as its Reverse…
hacking: security in practice
Crossposted from r/HowtoHack, any advice here?
submitted by /u/N1tingale
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Crossposted from r/HowtoHack, any advice here?
submitted by /u/N1tingale
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Crossposted from r/HowtoHack, any advice here?
Posted in r/hacking by u/N1tingale • 1 point and 0 comments
snovvcrash/NimHollow: Nim implementation of Process Hollowing using syscalls (PoC)
https://www.reddit.com/r/redteamsec/comments/rpj4fn/snovvcrashnimhollow_nim_implementation_of_process/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://github.com/snovvcrash/NimHollow) [comments] (https://www.reddit.com/r/redteamsec/comments/rpj4fn/snovvcrashnimhollow_nim_implementation_of_process/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/rpj4fn/snovvcrashnimhollow_nim_implementation_of_process/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://github.com/snovvcrash/NimHollow) [comments] (https://www.reddit.com/r/redteamsec/comments/rpj4fn/snovvcrashnimhollow_nim_implementation_of_process/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
snovvcrash/NimHollow: Nim implementation of Process Hollowing...
Posted in r/redteamsec by u/dmchell • 5 points and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Neovim for Beginners — init.lua
https://cdn-images-1.medium.com/max/1427/1*KL99cTPElu7zUp07BtQvGA.png
Let’s start our journey to customize Neovim.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Neovim for Beginners — init.lua
https://cdn-images-1.medium.com/max/1427/1*KL99cTPElu7zUp07BtQvGA.png
Let’s start our journey to customize Neovim.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Neovim for Beginners — init.lua
Let’s start our journey to customize Neovim.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Common Nginx Misconfiguration leads to Path Traversal
https://cdn-images-1.medium.com/max/2600/0*eA1ZnHCtDmUPuMMA
Recently, I have been invited by my friend to participate into a private pentest project. The target has been using Nginx as its Reverse…
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Common Nginx Misconfiguration leads to Path Traversal
https://cdn-images-1.medium.com/max/2600/0*eA1ZnHCtDmUPuMMA
Recently, I have been invited by my friend to participate into a private pentest project. The target has been using Nginx as its Reverse…
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Common Nginx Misconfiguration leads to Path Traversal
Recently, I have been invited by my friend to participate into a private pentest project. The target has been using Nginx as its Reverse…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Grim Finance Loses $30 Million From Smart Contract Bug
https://cdn-images-1.medium.com/max/1600/0*D-AOveVM4O0-c8gF
Grim Finance became the latest victim of a crypto hack as an attacker stole $30 million in funds. Grim Finance is a decentralized finance…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Grim Finance Loses $30 Million From Smart Contract Bug
https://cdn-images-1.medium.com/max/1600/0*D-AOveVM4O0-c8gF
Grim Finance became the latest victim of a crypto hack as an attacker stole $30 million in funds. Grim Finance is a decentralized finance…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Grim Finance Loses $30 Million From Smart Contract Bug
Grim Finance became the latest victim of a crypto hack as an attacker stole $30 million in funds. Grim Finance is a decentralized finance…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackme LFI Writeup
https://cdn-images-1.medium.com/max/2600/0*wTxj_b5XveVEicfi
How to find and exploit LFI
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
TryHackme LFI Writeup
https://cdn-images-1.medium.com/max/2600/0*wTxj_b5XveVEicfi
How to find and exploit LFI
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackme LFI Writeup
How to find and exploit LFI
SourceLeakHacker - A Multi Threads Web Application Source Leak Scanner
SourceLeakHacker is a muilt-threads web directories scanner.Installationpip install -r requirements.txtUsage dictionary scale --output OUTPUT output folder, default: result/YYYY-MM-DD hh:mm:ss --threads THREADS, -t THREADS threads numbers, default: 4 --timeout TIMEOUT HTTP request timeout --level {CRITICAL,ERROR,WARNING,INFO,DEBUG}, -v {CRITICAL,ERROR,WARNING,INFO,DEBUG} log level --version, -V show program's version number and exit ">usage: SourceLeakHacker.py optionsoptional arguments: -h, --help show this help message and exit --url URL url to scan, eg: 'http://127.0.0.1/' --urls URLS file contains urls to scan, one line one url. --scale {full,tiny} build-in dictionary scale --output OUTPUT output folder, default: result/YYYY-MM-DD hh:mm:ss --threads THREADS, -t THREADS threads numbers, default: 4 --timeout TIMEOUT HTTP request timeout --level {CRITICAL,ERROR,WARNING,INFO,DEBUG}, -v {CRITICAL,ERROR,WARNING,INFO,DEBUG} log level --version, -V show program's version number and exitExample$ python SourceLeakHacker.py --url=http://baidu.com --threads=4 --timeout=8302 0 3.035766 text/html; charset=iso-8859-1 http://baidu.com/_/_index.php302 0 3.038096 text/html; charset=iso-8859-1 http://baidu.com/_/_index.php.bak...302 0 0.063973 text/html; charset=iso-8859-1 http://baidu.com/_adm/_index.php302 0 0.081672 text/html; charset=iso-8859-1 http://baidu.com/_adm/_index.php.bakResult save in file: result/2020-02-27 07:07:47.csv$ cat url.txt http://baidu.com/http://google.com/$ python SourceLeakHacker.py --urls=url.txt --threads=4 --timeout=8302 0 2.363600 text/html; charset=iso-8859-1 http://baidu.com/_/_index.php.bak302 0 0.098417 text/html; charset=iso-8859-1 http://baidu.com/_adm/_index.php.bak...302 0 0.060524 text/html; charset=iso-8859-1 http://google.com/_adm/_index.php.bak302 0 0.075042 text/html; charset=iso-8859-1 http://baidu.com/_adm/_index.php.backResult save in file: result/2020-02-27 07:08:54.csvDemoTODOs Arguments parser. Store scan result into csv file. Support for multiple urls (from file). Add help comments for every params. Update Usage. Adjust dictionary elements order systematically. Change logger in order to suite for both windows and linux. Add log level. Update Screenshots. Retry and avoid dead lock Store scan result into sqlite database. Download small url contents, then store them into sqlite database.Known Bugs CTRL C does not works on windows platformDownload SourceLeakHacker
Read more...
___________________________
@hacking_Attack
@Hacking_Video
SourceLeakHacker is a muilt-threads web directories scanner.Installationpip install -r requirements.txtUsage dictionary scale --output OUTPUT output folder, default: result/YYYY-MM-DD hh:mm:ss --threads THREADS, -t THREADS threads numbers, default: 4 --timeout TIMEOUT HTTP request timeout --level {CRITICAL,ERROR,WARNING,INFO,DEBUG}, -v {CRITICAL,ERROR,WARNING,INFO,DEBUG} log level --version, -V show program's version number and exit ">usage: SourceLeakHacker.py optionsoptional arguments: -h, --help show this help message and exit --url URL url to scan, eg: 'http://127.0.0.1/' --urls URLS file contains urls to scan, one line one url. --scale {full,tiny} build-in dictionary scale --output OUTPUT output folder, default: result/YYYY-MM-DD hh:mm:ss --threads THREADS, -t THREADS threads numbers, default: 4 --timeout TIMEOUT HTTP request timeout --level {CRITICAL,ERROR,WARNING,INFO,DEBUG}, -v {CRITICAL,ERROR,WARNING,INFO,DEBUG} log level --version, -V show program's version number and exitExample$ python SourceLeakHacker.py --url=http://baidu.com --threads=4 --timeout=8302 0 3.035766 text/html; charset=iso-8859-1 http://baidu.com/_/_index.php302 0 3.038096 text/html; charset=iso-8859-1 http://baidu.com/_/_index.php.bak...302 0 0.063973 text/html; charset=iso-8859-1 http://baidu.com/_adm/_index.php302 0 0.081672 text/html; charset=iso-8859-1 http://baidu.com/_adm/_index.php.bakResult save in file: result/2020-02-27 07:07:47.csv$ cat url.txt http://baidu.com/http://google.com/$ python SourceLeakHacker.py --urls=url.txt --threads=4 --timeout=8302 0 2.363600 text/html; charset=iso-8859-1 http://baidu.com/_/_index.php.bak302 0 0.098417 text/html; charset=iso-8859-1 http://baidu.com/_adm/_index.php.bak...302 0 0.060524 text/html; charset=iso-8859-1 http://google.com/_adm/_index.php.bak302 0 0.075042 text/html; charset=iso-8859-1 http://baidu.com/_adm/_index.php.backResult save in file: result/2020-02-27 07:08:54.csvDemoTODOs Arguments parser. Store scan result into csv file. Support for multiple urls (from file). Add help comments for every params. Update Usage. Adjust dictionary elements order systematically. Change logger in order to suite for both windows and linux. Add log level. Update Screenshots. Retry and avoid dead lock Store scan result into sqlite database. Download small url contents, then store them into sqlite database.Known Bugs CTRL C does not works on windows platformDownload SourceLeakHacker
Read more...
___________________________
@hacking_Attack
@Hacking_Video
Baidu
百度一下,你就知道
全球领先的中文搜索引擎、致力于让网民更便捷地获取信息,找到所求。百度超过千亿的中文网页数据库,可以瞬间找到相关的搜索结果。
Snap-Scraper - Snap Scraper Enables Users To Download Media Uploaded To Snapchat's Snap Map Using A Set Of Latitude And Longitude Coordinates
http://www.kitploit.com/2021/12/snap-scraper-snap-scraper-enables-users.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/12/snap-scraper-snap-scraper-enables-users.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Snap-Scraper - Snap Scraper Enables Users To Download Media Uploaded To Snapchat's Snap Map Using A Set Of Latitude And Longitude…
Snap Scraper is an open source intelligence (https://www.kitploit.com/search/label/Intelligence) tool which enables users to download media uploaded to Snapchat's Snap Map using a set of latitude and longitiude co-ordinates. This project is in no way affiliated with, authorized, maintained, sponsored or endorsed by Snap inc. or any of its affiliates or subsidiaries. This program is for education, forensic and bug reporting purposes only and is provided without warranty.When using this tool please cite the following publication:Richard Matthews, Kieren Lovell, Matthew Sorell, Ghost protocol – Snapchat as a method of surveillance, Forensic Science International: Digital Investigation, Volume 36, Supplement, 2021, 301112, ISSN 2666-2817, https://doi.org/10.1016/j.fsidi.2021.301112.
Screenshots
___________________________
@hacking_Attack
@Hacking_Video
Screenshots
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.