DOM Based XSS
https://medium.com/@hardeepsinghsandhu537/dom-based-xss-35ad8603232c?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@hardeepsinghsandhu537/dom-based-xss-35ad8603232c?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
DOM Based XSS
DOM based XSS (cross site scripting) is a client side vulnerability that arises when the javascript takes data from user controllable…
DOM based XSS (cross site scripting) is a client side vulnerability that arises when the javascript takes data from user controllable…Continue reading on Medium » (https://medium.com/@hardeepsinghsandhu537/dom-based-xss-35ad8603232c?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
DOM Based XSS
DOM based XSS (cross site scripting) is a client side vulnerability that arises when the javascript takes data from user controllable…
HOW I GOT MY SECOND SWAG
https://faiyazhacks.medium.com/how-i-got-my-second-swag-2fa08a1dfd39?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://faiyazhacks.medium.com/how-i-got-my-second-swag-2fa08a1dfd39?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
HOW I GOT MY SECOND SWAG
Hi everyone! Hope you all are doing good. In this article i am going to show you how i got my second swag from Ivanti by reporting an open…
Hi everyone! Hope you all are doing good. In this article i am going to show you how i got my second swag from Ivanti by reporting an open…Continue reading on Medium » (https://faiyazhacks.medium.com/how-i-got-my-second-swag-2fa08a1dfd39?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
HOW I GOT MY SECOND SWAG
Hi everyone! Hope you all are doing good. In this article i am going to show you how i got my second swag from Ivanti by reporting an open…
How I Bypassed Netflix Profile Lock?
https://infosecwriteups.com/how-i-bypassed-netflix-profile-lock-43901be1307c?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://infosecwriteups.com/how-i-bypassed-netflix-profile-lock-43901be1307c?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I Bypassed Netflix Profile Lock?
Hi hackers,
Hi hackers,Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/how-i-bypassed-netflix-profile-lock-43901be1307c?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I Bypassed Netflix Profile Lock?
Hi hackers,
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Wireless coexistence – New attack technique exploits Bluetooth, WiFi performance features
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Wireless coexistence – New attack technique exploits Bluetooth, WiFi performance featuresPost Views: 172 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 1 Minute
Vulnerabilities in wireless chip designs could allow malicious hackers to steal data and passwords from devices. According to security researchers, attackers could exploit “wireless coexistence” or shared component features on millions of mobile devices.
According to the group, from the Technical University of Darmstadt’s Secure Mobile Networking Group (Germany) and the University of Brescia’s CNIT (Italy), attackers could exploit “wireless coexistence” or shared component features on millions of mobile devices.
Wireless devices often use radio components with shared resources, combination chips or System on a Chip (SoC) designs. These SoCs are responsible for multiple radio interfaces, including Bluetooth, WiFi, LTE (4G) and 5G.
But, as the researchers note, these interfaces typically share components, such as memory, and resources including antennae and wireless spectrum. Designers utilize wireless coexistence to allow resource sharing and maximize network performance. In doing so, they create security flaws that are hard, or even impossible, to patch.
“While SoCs are constantly optimized towards energy efficiency, high throughput, and low latency communication, their security has not always been prioritized,” the researchers warn.
See Also: Complete Offensive Security and Ethical Hacking Course Over-the-air exploitIn tests, researchers built a mobile test rig for under $100, and in an over-the-air exploit made use of a Bluetooth connection to obtain network passwords and manipulate traffic on a WiFi chip. Coexistence attacks enable a novel type of lateral privilege escalation across chip boundaries, they state.
The researchers were able to create a proof-of-concept exploitation of shared resources on technologies from Silicon Labs, Broadcomm, and Cypress. The group found nine CVEs, which they disclosed to the chip companies, as well as the Bluetooth SIG and associated manufacturers that use coexistence interfaces.
Attackers can escalate “privileges laterally from one wireless chip or core into another”. And serial coexistence protocols can leak information across wireless chips, giving away packet types and activity. Malicious hackers could obtain keypress timings from a Bluetooth device “for inferring passwords and password lengths”, they found.
More details on the research can be found in a paper by the researcher entitled ‘Attacks on Wireless Coexistence: Exploiting Cross-Technology Performance Features for Inter-Chip Privilege Escalation‘ (PDF).
More details on the research can be found in a paper by the researcher entitled ‘Attacks on Wireless Coexistence: Exploiting Cross-Technology Performance Features for Inter-Chip Privilege Escalation‘ (PDF).
See Also: Hackers start pushing malware in worldwide Log4Shell attacks Mitigation impossible?The potential attacks are both stealthy and hard to patch. An attack that moves laterally between components is likely to be invisible to the operating system, and so bypass its protection measures, the researchers warned.
Hardware manufacturers should be able to reduce the risks by redesigning chip architectures, and by patching firmware. But not all systems can be patched, and older devic[...]
___________________________
@hacking_Attack
@Hacking_Video
Wireless coexistence – New attack technique exploits Bluetooth, WiFi performance features
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Wireless coexistence – New attack technique exploits Bluetooth, WiFi performance featuresPost Views: 172 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 1 Minute
Vulnerabilities in wireless chip designs could allow malicious hackers to steal data and passwords from devices. According to security researchers, attackers could exploit “wireless coexistence” or shared component features on millions of mobile devices.
According to the group, from the Technical University of Darmstadt’s Secure Mobile Networking Group (Germany) and the University of Brescia’s CNIT (Italy), attackers could exploit “wireless coexistence” or shared component features on millions of mobile devices.
Wireless devices often use radio components with shared resources, combination chips or System on a Chip (SoC) designs. These SoCs are responsible for multiple radio interfaces, including Bluetooth, WiFi, LTE (4G) and 5G.
But, as the researchers note, these interfaces typically share components, such as memory, and resources including antennae and wireless spectrum. Designers utilize wireless coexistence to allow resource sharing and maximize network performance. In doing so, they create security flaws that are hard, or even impossible, to patch.
“While SoCs are constantly optimized towards energy efficiency, high throughput, and low latency communication, their security has not always been prioritized,” the researchers warn.
See Also: Complete Offensive Security and Ethical Hacking Course Over-the-air exploitIn tests, researchers built a mobile test rig for under $100, and in an over-the-air exploit made use of a Bluetooth connection to obtain network passwords and manipulate traffic on a WiFi chip. Coexistence attacks enable a novel type of lateral privilege escalation across chip boundaries, they state.
The researchers were able to create a proof-of-concept exploitation of shared resources on technologies from Silicon Labs, Broadcomm, and Cypress. The group found nine CVEs, which they disclosed to the chip companies, as well as the Bluetooth SIG and associated manufacturers that use coexistence interfaces.
Attackers can escalate “privileges laterally from one wireless chip or core into another”. And serial coexistence protocols can leak information across wireless chips, giving away packet types and activity. Malicious hackers could obtain keypress timings from a Bluetooth device “for inferring passwords and password lengths”, they found.
More details on the research can be found in a paper by the researcher entitled ‘Attacks on Wireless Coexistence: Exploiting Cross-Technology Performance Features for Inter-Chip Privilege Escalation‘ (PDF).
More details on the research can be found in a paper by the researcher entitled ‘Attacks on Wireless Coexistence: Exploiting Cross-Technology Performance Features for Inter-Chip Privilege Escalation‘ (PDF).
See Also: Hackers start pushing malware in worldwide Log4Shell attacks Mitigation impossible?The potential attacks are both stealthy and hard to patch. An attack that moves laterally between components is likely to be invisible to the operating system, and so bypass its protection measures, the researchers warned.
Hardware manufacturers should be able to reduce the risks by redesigning chip architectures, and by patching firmware. But not all systems can be patched, and older devic[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Wireless coexistence – New attack technique exploits Bluetooth, WiFi performance features | Black Hat Ethical Hacking
Vulnerabilities in wireless chip designs could allow malicious hackers to steal data and passwords from devices. According to security researchers, attackers could exploit "wireless coexistence" or shared component features on millions of mobile devices.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Wireless coexistence – New attack technique exploits Bluetooth, WiFi performance features https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Wireless coexistence – New attack technique exploits…
es might no longer receive updates from their makers.
In the meantime, device users are advised to take steps such as deleting unused Bluetooth pairings and using 4G rather than WiFi in public places.
See Also: Offensive Security Tool: log4j Honeypot Flask “This raises an entire new class of attack against devices with multiple RF [radio frequency] interfaces,” UK-based security researcher Andrew Tierney told The Daily Swig. “The most interesting aspect is how stealthy they can be, entirely bypassing protections put in place by the operating system.”
But he added that as the techniques “are very involved” they are most likely to be used by nation states.
See Also: Hacking stories – Rafael Núñez (aka RaFa), hacking NASA with the hacking group: World of Hell
Source: portswigger.net (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Untitled-design.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/apple-store-tower-90x90.jpg Apple fixes macOS security flaw behind Gatekeeper bypass3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/5157-article-201208-ms-team_body_text-90x90.jpg Microsoft Teams bug allowing phishing unpatched since March4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-6-90x90.jpg 800K WordPress sites still impacted by critical SEO plugin flaw5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-5-90x90.jpg Microsoft warns of easy Windows domain takeover via Active Directory bugs6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-4-90x90.jpg TellYouThePass ransomware revived in Linux, Windows Log4j attacks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-3-1-90x90.jpg Log4j attackers switch to injecting Monero miners via RMI1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/Hackers-Using-Malicious-IIS-Server-Module-to-Steal-Microsoft-Exchange-560x380-1-90x90.jpg Hackers steal Microsoft Exchange credentials using IIS module2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/how-ransomware-works-1024x535-1-90x90.png New ransomware now being deployed in Log4Shell attacks2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/0d73-article-201111-ubuntu-90x90.jpg Attackers can get root by crashing Ubuntu’s AccountsService2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/frame_2_delay-0.5s-90x90.jpg Hackers start pushing malware in worldwide Log4Shell attacks2 weeks ago
The post Wireless coexistence – New attack technique exploits Bluetooth, WiFi performance features first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
In the meantime, device users are advised to take steps such as deleting unused Bluetooth pairings and using 4G rather than WiFi in public places.
See Also: Offensive Security Tool: log4j Honeypot Flask “This raises an entire new class of attack against devices with multiple RF [radio frequency] interfaces,” UK-based security researcher Andrew Tierney told The Daily Swig. “The most interesting aspect is how stealthy they can be, entirely bypassing protections put in place by the operating system.”
But he added that as the techniques “are very involved” they are most likely to be used by nation states.
See Also: Hacking stories – Rafael Núñez (aka RaFa), hacking NASA with the hacking group: World of Hell
Source: portswigger.net (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Untitled-design.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/apple-store-tower-90x90.jpg Apple fixes macOS security flaw behind Gatekeeper bypass3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/5157-article-201208-ms-team_body_text-90x90.jpg Microsoft Teams bug allowing phishing unpatched since March4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-6-90x90.jpg 800K WordPress sites still impacted by critical SEO plugin flaw5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-5-90x90.jpg Microsoft warns of easy Windows domain takeover via Active Directory bugs6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-4-90x90.jpg TellYouThePass ransomware revived in Linux, Windows Log4j attacks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-3-1-90x90.jpg Log4j attackers switch to injecting Monero miners via RMI1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/Hackers-Using-Malicious-IIS-Server-Module-to-Steal-Microsoft-Exchange-560x380-1-90x90.jpg Hackers steal Microsoft Exchange credentials using IIS module2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/how-ransomware-works-1024x535-1-90x90.png New ransomware now being deployed in Log4Shell attacks2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/0d73-article-201111-ubuntu-90x90.jpg Attackers can get root by crashing Ubuntu’s AccountsService2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/frame_2_delay-0.5s-90x90.jpg Hackers start pushing malware in worldwide Log4Shell attacks2 weeks ago
The post Wireless coexistence – New attack technique exploits Bluetooth, WiFi performance features first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Creating your own VPN.
How realistic and safe is it that you create your own VPN for complete anonymous browsing?
submitted by /u/Unknown_ZZ
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Creating your own VPN.
How realistic and safe is it that you create your own VPN for complete anonymous browsing?
submitted by /u/Unknown_ZZ
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
hacking: security in practice
Can shell the binary locally but not remotely (CTF)
It's my first ctf and I've spent the better half of december on learning buffer overflows, both via stack execution and Return Oriented Programming. Since the binary is NX protected (but no PIE) I've gone with ROP and using execve (since I couldn't get system working). Works fine with execve on my workstation.
Target is a cgi-bin binary on a remote server where I've gotten ssh shell as a normal user, but need the binary user to access the flag and other files. It leaks via format string since it's a printf() without arguments. However, I'm using puts to give me libc offset. Which works. What doesnt is making the binary stay alive after the first leak chain so I can do the second... It works only locally, while remote segfaults.
I downloaded the libc and binary to my workstation, where I successfully have spawned shell repeatedly (albeit using the workstation libc). I have gathered gadget, /bin/sh, syscall and puts offsets from both the libc I use locally, and the remote one, in identical ways via objdump, string and ROPgadget, also verified all of these by having puts showing me various offsets via its own ROP chain and looking in gdb. Then I just switch libc offsets when attempting the remote shell.
This largely works, as I get the expected puts output from a test ROP chain when trying string offsets etc. But what I cannot figure out is why the binary crashes with segfault right afterwards, when I try to ROP it back to main. This doesn't happen locally, only remote where I've done nc -lk -p 4040 -e /path/to/binary so I can remote() it via pwntools.
payload = buf_junk + POP_RDI + PUTS_GOT + PUTS_PLT + MAIN
Gives me expected offset, and successfully stays alive via MAIN and gives me shell - locally. Segfaults when doing it to remote target via netcat...
I tried doing a pre-RET incase it was a 16 byte alignment issue only on the remote, but didn't help. I need the process to stay alive like it does locally, so the libc offset I gather via puts_plt(puts_got) stays valid for the /bin/sh and syscall offsets to make the final shell chain.
What could make the binary crash with segfault remotely when trying to go back to main, but not locally? Since the main address is in the binary itself, it's not even libc related, which makes it even more curious to me. I've confirmed that PIE is indeed off and it's 0x400000 based both locally and remotely.
submitted by /u/Alternative-Ice-2500
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Can shell the binary locally but not remotely (CTF)
It's my first ctf and I've spent the better half of december on learning buffer overflows, both via stack execution and Return Oriented Programming. Since the binary is NX protected (but no PIE) I've gone with ROP and using execve (since I couldn't get system working). Works fine with execve on my workstation.
Target is a cgi-bin binary on a remote server where I've gotten ssh shell as a normal user, but need the binary user to access the flag and other files. It leaks via format string since it's a printf() without arguments. However, I'm using puts to give me libc offset. Which works. What doesnt is making the binary stay alive after the first leak chain so I can do the second... It works only locally, while remote segfaults.
I downloaded the libc and binary to my workstation, where I successfully have spawned shell repeatedly (albeit using the workstation libc). I have gathered gadget, /bin/sh, syscall and puts offsets from both the libc I use locally, and the remote one, in identical ways via objdump, string and ROPgadget, also verified all of these by having puts showing me various offsets via its own ROP chain and looking in gdb. Then I just switch libc offsets when attempting the remote shell.
This largely works, as I get the expected puts output from a test ROP chain when trying string offsets etc. But what I cannot figure out is why the binary crashes with segfault right afterwards, when I try to ROP it back to main. This doesn't happen locally, only remote where I've done nc -lk -p 4040 -e /path/to/binary so I can remote() it via pwntools.
payload = buf_junk + POP_RDI + PUTS_GOT + PUTS_PLT + MAIN
Gives me expected offset, and successfully stays alive via MAIN and gives me shell - locally. Segfaults when doing it to remote target via netcat...
I tried doing a pre-RET incase it was a 16 byte alignment issue only on the remote, but didn't help. I need the process to stay alive like it does locally, so the libc offset I gather via puts_plt(puts_got) stays valid for the /bin/sh and syscall offsets to make the final shell chain.
What could make the binary crash with segfault remotely when trying to go back to main, but not locally? Since the main address is in the binary itself, it's not even libc related, which makes it even more curious to me. I've confirmed that PIE is indeed off and it's 0x400000 based both locally and remotely.
submitted by /u/Alternative-Ice-2500
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Can shell the binary locally but not remotely (CTF)
It's my first ctf and I've spent the better half of december on learning buffer overflows, both via stack execution and Return Oriented...
DOM Based XSS
DOM based XSS (cross site scripting) is a client side vulnerability that arises when the javascript takes data from user controllable…Continue reading on Medium »
Read more...
DOM based XSS (cross site scripting) is a client side vulnerability that arises when the javascript takes data from user controllable…Continue reading on Medium »
Read more...
HOW I GOT MY SECOND SWAG
Hi everyone! Hope you all are doing good. In this article i am going to show you how i got my second swag from Ivanti by reporting an open…Continue reading on Medium »
Read more...
Hi everyone! Hope you all are doing good. In this article i am going to show you how i got my second swag from Ivanti by reporting an open…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Snap-Scraper - Snap Scraper Enables Users To Download Media Uploaded To Snapchat's Snap Map Using A Set Of Latitude And Longitude Coordinates
https://blogger.googleusercontent.com/img/a/AVvXsEgWG-ekiBrAxg9ExW0j1_o7kODkdKQemFWWPGTaK-6_2oAz2j6EvlzaDnrUHwwZd5YGV3MRs3Ed45frUfspGaiiQY8qmK5PZY3hq56bp-D7jJ23jVUgWxQuZlcSs337Og9m6D15oFcUX4LlVqDXl6do8cBaisliEZHZNEaaoOtyY0JOXcUKAuXCWVu0Pw Snap Scraper is an open source intelligence tool which enables users to download media uploaded to Snapchat's Snap Map using a set of latitude and longitiude co-ordinates. This project is in no way affiliated with, authorized, maintained, sponsored or endorsed by Snap inc. or any of its affiliates or subsidiaries. This program is for education, forensic and bug reporting purposes only and is provided without warranty.
When using this tool please cite the following publication:
1. Richard Matthews, Kieren Lovell, Matthew Sorell, Ghost protocol – Snapchat as a method of surveillance, Forensic Science International: Digital Investigation, Volume 36, Supplement, 2021, 301112, ISSN 2666-2817, https://doi.org/10.1016/j.fsidi.2021.301112. Screenshotshttps://blogger.googleusercontent.com/img/a/AVvXsEhbq_knQyrRWc7ZzlIJXmEb0Hojbxv7jIMYxck2r2bzM7Ie3nbDz4wIjwnveZEeZHnYEWojaQfrj1tpIFnV5d8QuTvbiq5WyZ3xgi00BDXxzDz6RxFe_I7OnZfJlLCXxybhbVLAN9pY41cJ2ABWu7TlK8v2M6jDBWtOHX_vFl9PckXd2HuWBbHmL5McAw=w534-h640 https://blogger.googleusercontent.com/img/a/AVvXsEhQLKsz3-WV274Bw8J9nsSjk6HLgyXXSHXH3ITzziPdpfY5yXs0YiglLwFI18TSNP25DZU_JC2niDub2L4KsayzVZZVaBs0znDmi_piiVxHsUCtG0hdGV_mfuM2rKySZKTop9jUbXcRCQInRsXg3a2agEI3n46hhru6-6GxqLZY1QBK8T_J_gmI-Gl59g=w592-h640 https://blogger.googleusercontent.com/img/a/AVvXsEiq0CMrxmRn8zm8OkWX_Eb-zqaJPzREFE5QGO6HfRQXZvCYIWW_iTiTLHH_iXVmbLisRWeWMv3NSTl9vh3yzEBgnRPQHfhkRhLw6460iL-LqAkdpdXZpaEdGpHWwjS3iaIkT7viFLW41PAOP7uLQaI7GEau0-Qc0DMYc2IQ3owAlSlw6aa7izLQsBTS_g=w570-h640 https://blogger.googleusercontent.com/img/a/AVvXsEgxdPTjSDlIqvw3XBJjvKSwyW56JO3dexM6R2VGNVC0kTM3t2JxOztz2W_hLNE9d8_Ovmy5bL24ZQDH4_KfKNs1gwho0t4R9nFRbVpRAHe79vXtLVQLTFOuFOWTWgYiOGr2UOAJPiZgYHjYVKIiqjnGM5ln0tM6KRS6_J3FfVD_oKmB3Luc8qQGJqEXQQ=w572-h640 https://blogger.googleusercontent.com/img/a/AVvXsEhv0bTi1RgLmjEC7qeoeOjjI1cVgrl09W2O7N91kr-OXIzl5VDVawTTDUt48Ge0vvyFpfD-nS6bPv719KzYlnuDOmjXT73s1uRi2LV_SNO5IwZAt1eJJ_OZ8ctVXC3OT0GZXMd59vwB-PS2aK1gG7lDgB48qAl-L0G4cQ5aaaqnW4F8_D_hwm6-RZ30kw=w640-h340 InstallationMacOSDownload the current linked binary in the most recent release. Using terminal ensure you change permissions to include the executable permission.
You should be presented with the following window: https://blogger.googleusercontent.com/img/a/AVvXsEjMo_QcS8jaD1EjmMpF73bXe-r7QlRWxREvkkKU8XnvU73XT1xQqiOxILArDiRbB4upw-eWi1Fz1_uWpbph8zP5_fFf_Qci1FMnd_TzdOcPhM_-lLSEMWd02flvEqN9Ox_tXvR1OqrSR2jkgk8uff6MMhcEdiOIWo3ddVxjVvd1n1nfMcYsS39ggj61_w=w534-h640 The current options for use are indicated in the command window. Select to option by pressing the required key(s) on the keyboard and pressing enter. CheckThe main option users will select will be the check option to locate snap media on the Snap Map. To select this option type 'c' followed by the enter key.
SnapScraper will then ask you for a set of longitude and lattitude coordinates which can be obtained from map.snapchat.com as discussed in the pub[...]
___________________________
@hacking_Attack
@Hacking_Video
Snap-Scraper - Snap Scraper Enables Users To Download Media Uploaded To Snapchat's Snap Map Using A Set Of Latitude And Longitude Coordinates
https://blogger.googleusercontent.com/img/a/AVvXsEgWG-ekiBrAxg9ExW0j1_o7kODkdKQemFWWPGTaK-6_2oAz2j6EvlzaDnrUHwwZd5YGV3MRs3Ed45frUfspGaiiQY8qmK5PZY3hq56bp-D7jJ23jVUgWxQuZlcSs337Og9m6D15oFcUX4LlVqDXl6do8cBaisliEZHZNEaaoOtyY0JOXcUKAuXCWVu0Pw Snap Scraper is an open source intelligence tool which enables users to download media uploaded to Snapchat's Snap Map using a set of latitude and longitiude co-ordinates. This project is in no way affiliated with, authorized, maintained, sponsored or endorsed by Snap inc. or any of its affiliates or subsidiaries. This program is for education, forensic and bug reporting purposes only and is provided without warranty.
When using this tool please cite the following publication:
1. Richard Matthews, Kieren Lovell, Matthew Sorell, Ghost protocol – Snapchat as a method of surveillance, Forensic Science International: Digital Investigation, Volume 36, Supplement, 2021, 301112, ISSN 2666-2817, https://doi.org/10.1016/j.fsidi.2021.301112. Screenshotshttps://blogger.googleusercontent.com/img/a/AVvXsEhbq_knQyrRWc7ZzlIJXmEb0Hojbxv7jIMYxck2r2bzM7Ie3nbDz4wIjwnveZEeZHnYEWojaQfrj1tpIFnV5d8QuTvbiq5WyZ3xgi00BDXxzDz6RxFe_I7OnZfJlLCXxybhbVLAN9pY41cJ2ABWu7TlK8v2M6jDBWtOHX_vFl9PckXd2HuWBbHmL5McAw=w534-h640 https://blogger.googleusercontent.com/img/a/AVvXsEhQLKsz3-WV274Bw8J9nsSjk6HLgyXXSHXH3ITzziPdpfY5yXs0YiglLwFI18TSNP25DZU_JC2niDub2L4KsayzVZZVaBs0znDmi_piiVxHsUCtG0hdGV_mfuM2rKySZKTop9jUbXcRCQInRsXg3a2agEI3n46hhru6-6GxqLZY1QBK8T_J_gmI-Gl59g=w592-h640 https://blogger.googleusercontent.com/img/a/AVvXsEiq0CMrxmRn8zm8OkWX_Eb-zqaJPzREFE5QGO6HfRQXZvCYIWW_iTiTLHH_iXVmbLisRWeWMv3NSTl9vh3yzEBgnRPQHfhkRhLw6460iL-LqAkdpdXZpaEdGpHWwjS3iaIkT7viFLW41PAOP7uLQaI7GEau0-Qc0DMYc2IQ3owAlSlw6aa7izLQsBTS_g=w570-h640 https://blogger.googleusercontent.com/img/a/AVvXsEgxdPTjSDlIqvw3XBJjvKSwyW56JO3dexM6R2VGNVC0kTM3t2JxOztz2W_hLNE9d8_Ovmy5bL24ZQDH4_KfKNs1gwho0t4R9nFRbVpRAHe79vXtLVQLTFOuFOWTWgYiOGr2UOAJPiZgYHjYVKIiqjnGM5ln0tM6KRS6_J3FfVD_oKmB3Luc8qQGJqEXQQ=w572-h640 https://blogger.googleusercontent.com/img/a/AVvXsEhv0bTi1RgLmjEC7qeoeOjjI1cVgrl09W2O7N91kr-OXIzl5VDVawTTDUt48Ge0vvyFpfD-nS6bPv719KzYlnuDOmjXT73s1uRi2LV_SNO5IwZAt1eJJ_OZ8ctVXC3OT0GZXMd59vwB-PS2aK1gG7lDgB48qAl-L0G4cQ5aaaqnW4F8_D_hwm6-RZ30kw=w640-h340 InstallationMacOSDownload the current linked binary in the most recent release. Using terminal ensure you change permissions to include the executable permission.
chmod 755 SnapScraper Optionally, a icon.png file is included which can be used to change the icon of the downloaded executable. Windows/LinuxAt this point in time, SnapScraper only supports MacOS. However, dependancies have been checked and users should be able to complile the code on their own file system without any issues. Ensure Alamofire has been installed. UsageDouble click SnapScraper to launch the command line tool. SnapScraper works best when the defaul window size is set to 80x50.You should be presented with the following window: https://blogger.googleusercontent.com/img/a/AVvXsEjMo_QcS8jaD1EjmMpF73bXe-r7QlRWxREvkkKU8XnvU73XT1xQqiOxILArDiRbB4upw-eWi1Fz1_uWpbph8zP5_fFf_Qci1FMnd_TzdOcPhM_-lLSEMWd02flvEqN9Ox_tXvR1OqrSR2jkgk8uff6MMhcEdiOIWo3ddVxjVvd1n1nfMcYsS39ggj61_w=w534-h640 The current options for use are indicated in the command window. Select to option by pressing the required key(s) on the keyboard and pressing enter. CheckThe main option users will select will be the check option to locate snap media on the Snap Map. To select this option type 'c' followed by the enter key.
SnapScraper will then ask you for a set of longitude and lattitude coordinates which can be obtained from map.snapchat.com as discussed in the pub[...]
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Snap-Scraper - Snap Scraper Enables Users To Download Media Uploaded To Snapchat's Snap Map Using A Set Of Latitude And Longitude…
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! Snap-Scraper - Snap Scraper Enables Users To Download Media Uploaded To Snapchat's Snap Map Using A Set Of Latitude And Longitude Coordinates https://blogger.googleusercontent.com/img/a/AVvXsEgWG-ekiBrAxg9ExW0j1_o7kODkdKQemFWWPGTaK…
lication "Richard Matthews, Kieren Lovell, Matthew Sorell, Ghost protocol – Snapchat as a method of surveillance, Forensic Science International: Digital Investigation, Volume 36, Supplement, 2021, 301112, ISSN 2666-2817, https://doi.org/10.1016/j.fsidi.2021.301112.". Navigate to map.snapchat.com and note the URL of the location you wish to extract snap media from ie. https://map.snapchat.com/@24.931153,44.873214,6.04z. The coordinates to enter into SnapScraper are located in the URL after the @ symbol. The first number is the lattitude, the second the longitude and the final the zoom level. Lattitude and longitude should be entered into SnapScraper to 6 decimal places while zoom should be entered to 2 decimal places.
When each coordinate is entered into the program SnapScraper will then poll Snap Map for snap media at the desired location. When media is located the meta data of the media will be printed to the command window. https://blogger.googleusercontent.com/img/a/AVvXsEjQVmOtHKc-aQFgneYiRjMEtgIi2ob18oNlDJm7nVjSCiTFPuBu8W5Oftl8E-7UPFg-O7fMRKWBpO9NiSSXu2odpZlbJr8P0PWIH8smNj8Jj9w5k6Cqce8JxFYpH1FJ6XaDmcuSCud1EQPDqbEg8RDaKa1ATGfvEDBdCZuo6fRKLyAoTyOTOdzyE_kaLQ=w592-h640 Users will then be given the option of printing direct links to the media to the command window. Select y to print these links to the command window or n to skip.
Users will then be given the option to save the links to a text file. Select y to save the file n to skip. File will be saved in the users "Downloads" directory in a folder called "Snapchat"(macOS users only). The file is titled with the current date, time and coordiates of extraction prefixed with the word "listing".
Finally, users will be asked if they would like to download the media. This is the extraction step with media being saved directly from the URLs indicated in the previous steps. Select y to download, n to skip. Media will be saved in a folder titled with the current date, time and coordinates of extraction within the "Snapchat" folder previously identified above. Log reportingCurrently log reporting has not been implremented in 0.5.0-b. To save a log of the extraction method use the "export text as" function built in to the terminal.
Finalise the extraction process as above and then quit SnapScraper by selecting "q". The terminal session will end but the window will remain open as shown. https://blogger.googleusercontent.com/img/a/AVvXsEiWxixNfeCP0lleKxJk92CaeA_KbY_JigplIKJ9r8Kg0fWtkIwl7T38QBXbhi-vVRvARK58_ewLJFqzAGi-Ho4ZcjeQQmBottdMT-zMAbib3oTffSBXjsCCSJX1bQs7x_TrCvtQqM9op66rDJ9WYda9wZjiwaCJkljnwtxJBMyc-NHeesL9cxtx3GAtRg=w572-h640 To save a log of activity navigate to Shell-> Export Text as... A save box will open. Navigate to the Snapchat folder within users Downloads folder and find the recent URL listing that has been saved (if used from previous steps). Click on this file and change the save as file name by removing the prefix word listing to log. This will save a text file contianing the contents of the terminal window and show all activity that was contducted while SnapScraper was run. Other optionsSnapScraper has a fully functional menu. Other options include displaying the MIT license, publication information associated with the current release of the tool, information to support the continued development and maintenance and the current development log. To access enter the relevant option keys followed by the enter key. ContributingSnapScraper was born out of a discussion in 2017 while in Tallinn Estonia. In the spirit of that initial collaboration I'd love for you to help bring this project to its full vision. The wiki contains a road map for the codebase including a wishlist of future functionality.
Pull requests are welcome. For major changes, please open an issue first to discuss what you would like to change.
Please make sure to update tests as appropriate. DontationsDontations are appreciated to help support the cont[...]
___________________________
@hacking_Attack
@Hacking_Video
When each coordinate is entered into the program SnapScraper will then poll Snap Map for snap media at the desired location. When media is located the meta data of the media will be printed to the command window. https://blogger.googleusercontent.com/img/a/AVvXsEjQVmOtHKc-aQFgneYiRjMEtgIi2ob18oNlDJm7nVjSCiTFPuBu8W5Oftl8E-7UPFg-O7fMRKWBpO9NiSSXu2odpZlbJr8P0PWIH8smNj8Jj9w5k6Cqce8JxFYpH1FJ6XaDmcuSCud1EQPDqbEg8RDaKa1ATGfvEDBdCZuo6fRKLyAoTyOTOdzyE_kaLQ=w592-h640 Users will then be given the option of printing direct links to the media to the command window. Select y to print these links to the command window or n to skip.
Users will then be given the option to save the links to a text file. Select y to save the file n to skip. File will be saved in the users "Downloads" directory in a folder called "Snapchat"(macOS users only). The file is titled with the current date, time and coordiates of extraction prefixed with the word "listing".
Finally, users will be asked if they would like to download the media. This is the extraction step with media being saved directly from the URLs indicated in the previous steps. Select y to download, n to skip. Media will be saved in a folder titled with the current date, time and coordinates of extraction within the "Snapchat" folder previously identified above. Log reportingCurrently log reporting has not been implremented in 0.5.0-b. To save a log of the extraction method use the "export text as" function built in to the terminal.
Finalise the extraction process as above and then quit SnapScraper by selecting "q". The terminal session will end but the window will remain open as shown. https://blogger.googleusercontent.com/img/a/AVvXsEiWxixNfeCP0lleKxJk92CaeA_KbY_JigplIKJ9r8Kg0fWtkIwl7T38QBXbhi-vVRvARK58_ewLJFqzAGi-Ho4ZcjeQQmBottdMT-zMAbib3oTffSBXjsCCSJX1bQs7x_TrCvtQqM9op66rDJ9WYda9wZjiwaCJkljnwtxJBMyc-NHeesL9cxtx3GAtRg=w572-h640 To save a log of activity navigate to Shell-> Export Text as... A save box will open. Navigate to the Snapchat folder within users Downloads folder and find the recent URL listing that has been saved (if used from previous steps). Click on this file and change the save as file name by removing the prefix word listing to log. This will save a text file contianing the contents of the terminal window and show all activity that was contducted while SnapScraper was run. Other optionsSnapScraper has a fully functional menu. Other options include displaying the MIT license, publication information associated with the current release of the tool, information to support the continued development and maintenance and the current development log. To access enter the relevant option keys followed by the enter key. ContributingSnapScraper was born out of a discussion in 2017 while in Tallinn Estonia. In the spirit of that initial collaboration I'd love for you to help bring this project to its full vision. The wiki contains a road map for the codebase including a wishlist of future functionality.
Pull requests are welcome. For major changes, please open an issue first to discuss what you would like to change.
Please make sure to update tests as appropriate. DontationsDontations are appreciated to help support the cont[...]
___________________________
@hacking_Attack
@Hacking_Video