C R O S S - S I T E S SCRIPTINGContinue reading on Medium » (https://medium.com/@Diegoeducacao404.../vulnerabilidades-web-748d81182b25?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
VULNERABILIDADES WEB 7.0
C R O S S - S I T E S SCRIPTING
hacking: security in practice
What is your best password management and why?
I am diving into a better password manager and was looking into some alternatives.
I was wondering if you guys did some research about it and know more.
I am also looking for some research on why this password manager is secure, etc.
submitted by /u/andreolf
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
What is your best password management and why?
I am diving into a better password manager and was looking into some alternatives.
I was wondering if you guys did some research about it and know more.
I am also looking for some research on why this password manager is secure, etc.
submitted by /u/andreolf
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
What is your best password management and why?
I am diving into a better password manager and was looking into some alternatives. I was wondering if you guys did some research about it and...
Ethical Hacking Roadmap and Resources
https://rashahacks.medium.com/ethical-hacking-roadmap-and-resources-395d4f29d2b6?source=rss------bug_bounty-5
Checklist for the things that one has to learn while learning Linux: Shell, Navigation, File System, Redirection, Permissions, Processes…Continue reading on Medium » (https://rashahacks.medium.com/ethical-hacking-roadmap-and-resources-395d4f29d2b6?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://rashahacks.medium.com/ethical-hacking-roadmap-and-resources-395d4f29d2b6?source=rss------bug_bounty-5
Checklist for the things that one has to learn while learning Linux: Shell, Navigation, File System, Redirection, Permissions, Processes…Continue reading on Medium » (https://rashahacks.medium.com/ethical-hacking-roadmap-and-resources-395d4f29d2b6?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Ethical Hacking Roadmap and Resources
Checklist for the things that one has to learn while learning Linux: Shell, Navigation, File System, Redirection, Permissions, Processes…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Dispositivos NAS de QNAP afectados por el aumento de ataques de ransomware ech0raix
https://cdn-images-1.medium.com/max/930/0*DdbDUU70tO4vxSpD.jpg
PUBLICADO EN 27 DICIEMBRE, 2021POR DPAB
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Dispositivos NAS de QNAP afectados por el aumento de ataques de ransomware ech0raix
https://cdn-images-1.medium.com/max/930/0*DdbDUU70tO4vxSpD.jpg
PUBLICADO EN 27 DICIEMBRE, 2021POR DPAB
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Dispositivos NAS de QNAP afectados por el aumento de ataques de ransomware ech0raix
PUBLICADO EN 27 DICIEMBRE, 2021POR DPAB
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Ethical Hacking Roadmap and Resources
Checklist for the things that one has to learn while learning Linux: Shell, Navigation, File System, Redirection, Permissions, Processes…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Ethical Hacking Roadmap and Resources
Checklist for the things that one has to learn while learning Linux: Shell, Navigation, File System, Redirection, Permissions, Processes…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Ethical Hacking Roadmap and Resources
Checklist for the things that one has to learn while learning Linux: Shell, Navigation, File System, Redirection, Permissions, Processes…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
BrainPAN VM Walkthroguh
https://cdn-images-1.medium.com/max/830/0*r01vdFPP8V51R9Yq.png
Makineyi indirebilirsiniz.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
BrainPAN VM Walkthroguh
https://cdn-images-1.medium.com/max/830/0*r01vdFPP8V51R9Yq.png
Makineyi indirebilirsiniz.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
BrainPAN VM Walkthroguh
Makineyi indirebilirsiniz.
Dumping LSASS with Duplicated Handles
https://www.reddit.com/r/redteamsec/comments/rpxe0u/dumping_lsass_with_duplicated_handles/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://rastamouse.me/dumping-lsass-with-duplicated-handles/) [comments] (https://www.reddit.com/r/redteamsec/comments/rpxe0u/dumping_lsass_with_duplicated_handles/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/rpxe0u/dumping_lsass_with_duplicated_handles/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://rastamouse.me/dumping-lsass-with-duplicated-handles/) [comments] (https://www.reddit.com/r/redteamsec/comments/rpxe0u/dumping_lsass_with_duplicated_handles/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Dumping LSASS with Duplicated Handles
Posted in r/redteamsec by u/dmchell • 2 points and 0 comments
hacking: security in practice
scanning for proxies
so i just started looking into 0.0.0.0/0 scanning and it has shown a lot of potential so far with application like zmap and zgrab, had a lot of fun joining random minecraft server, but i would like to explore a more practical, usefull you might say, approach. when i think of scanning the internet other than vulnerable DNS servers, i think about those looooong ass free proxy lists sitting there in the open. I know, i know those are not anonymous, but i was wondering, how the duck do they get those lists, they are obviously not their servers, and to add to that proxies often have random ports, how do you scan for a service that has random ports, even then if you find a server with a port 80 or 8080 it could just be an http server out there, how do you identify it is an actual proxy, banner perhaps?
ps: pls do not point out proprietary software or any if you can, i'm trying to learn here not skid, if you have a good open source project i will gladly look into it but only has a last resort
(TL;DR) i want a free proxy list, made by me, and im struggling, pls help
submitted by /u/filippobob
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
scanning for proxies
so i just started looking into 0.0.0.0/0 scanning and it has shown a lot of potential so far with application like zmap and zgrab, had a lot of fun joining random minecraft server, but i would like to explore a more practical, usefull you might say, approach. when i think of scanning the internet other than vulnerable DNS servers, i think about those looooong ass free proxy lists sitting there in the open. I know, i know those are not anonymous, but i was wondering, how the duck do they get those lists, they are obviously not their servers, and to add to that proxies often have random ports, how do you scan for a service that has random ports, even then if you find a server with a port 80 or 8080 it could just be an http server out there, how do you identify it is an actual proxy, banner perhaps?
ps: pls do not point out proprietary software or any if you can, i'm trying to learn here not skid, if you have a good open source project i will gladly look into it but only has a last resort
(TL;DR) i want a free proxy list, made by me, and im struggling, pls help
submitted by /u/filippobob
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
hacking: security in practice
Is there any mobile tracking software?
I don't care if the software is free or not, i just need it, please tell me a legit one
submitted by /u/uglyassfacegeek
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is there any mobile tracking software?
I don't care if the software is free or not, i just need it, please tell me a legit one
submitted by /u/uglyassfacegeek
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is there any mobile tracking software?
I don't care if the software is free or not, i just need it, please tell me a legit one
KitPloit - PenTest Tools!
ShonyDanza - A Customizable, Easy-To-Navigate Tool For Researching, Pen Testing, And Defending With The Power Of Shodan
___________________________
@hacking_Attack
@Hacking_Video
ShonyDanza - A Customizable, Easy-To-Navigate Tool For Researching, Pen Testing, And Defending With The Power Of Shodan
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
ShonyDanza - A Customizable, Easy-To-Navigate Tool For Researching, Pen Testing, And Defending With The Power Of Shodan
ShonyDanza - A Customizable, Easy-To-Navigate Tool For Researching, Pen Testing, And Defending With The Power Of Shodan
http://www.kitploit.com/2021/12/shonydanza-customizable-easy-to_01477721372.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/12/shonydanza-customizable-easy-to_01477721372.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
ShonyDanza - A Customizable, Easy-To-Navigate Tool For Researching, Pen Testing, And Defending With The Power Of Shodan
A customizable, easy-to-navigate tool for researching, pen testing, and defending with the power of Shodan.
With ShonyDanza, you can:Obtain IPs based on search criteriaAutomatically exclude honeypots from the results based on your pre-configured thresholdsPre-configure all IP searches to filter on your specified net range(s)Pre-configure search limitsUse build-a-search to craft searches with easy building blocksUse stock searches and pre-configure your own stock searchesCheck if IPs are known malware (https://www.kitploit.com/search/label/Malware) C2sGet host and domain profilesScan on-demandFind exploitsGet total counts for searches and exploitsAutomatically save exploit code, IP lists, host profiles, domain profiles, and scan results to directories within ShonyDanzaInstallationgit clone https://github.com/fierceoj/ShonyDanza.git
Requirementspython3shodan librarycd ShonyDanza
pip3 install -r requirements.txtUsageEdit config.py to include your desired configurations
cd configs
sudo nano config.py
dictionary below to add it to your shonydanza stock searches menu #see https://github.com/jakejarvis/awesome-shodan-queries for a great source of queries #check into "vuln:" filter if you have Small Business Plan or higher (e.g., vuln:cve-2019-11510) STOCK_SEARCHES = { 'ANONYMOUS_FTP':'ftp anonymous ok', 'RDP':'port:3389 has_screenshot:true', 'OPEN_TELNET':'port:23 console (https://www.kitploit.com/search/label/Console) gateway (https://www.kitploit.com/search/label/Gateway) -password', 'APACHE_DIR_LIST':'http.title:"Index of /"', 'SPRING_BOOT':'http.favicon.hash:116323821', 'HP_PRINTERS':'"Serial Number:" "Built:" "Server: HP HTTP"', 'DOCKER_API':'"Docker Containers:" port:2375', 'ANDROID_ROOT_BRIDGE':'"Android Debug Bridge" "Device" port:5555', 'MONGO_EXPRESS_GUI':'"Set-Cookie: mongo-express=" "200 OK"', 'CVE-2019-11510_PULSE_VPN':'http.html:/dana-na/', 'CVE-2019-19781_CITRIX_NETSCALER':'http.waf:"Citrix NetScaler"', 'CVE-2020-5902_F5_BIGIP':'http.favicon.hash:-335242539 "3992"', 'CVE-2020-3452_CISCO_ASA_FTD':'200 "Set-Cookie: webvpn;"' } #OPTIONAL #IP or cidr range constraint for searches that return list of IP addresses #use comma-separated list to designate multiple (e.g. 1.1.1.1,2.2.0.0/16,3.3.3.3,3.3.3.4) #NET_RANGE = '0.0.0.0/0' ">#config file for shonydanza searches
#REQUIRED
#maximum number of results that will be returned per search
#default is 100
SEARCH_LIMIT = 100
#REQUIRED
#IPs exceeding the honeyscore limit will not show up in IP results
#scale is 0.0 to 1.0
#adjust to desired probability to restrict results by threshold, or keep at 1.0 to include all results
HONEYSCORE_LIMIT = 1.0
#REQUIRED - at least one key: value pair
#add a shodan dork to the dictionary below to add it to your shonydanza stock searches menu
#see https://github.com/jakejarvis/awesome-shodan-queries for a great source of queries
#check into "vuln:" filter if you have Small Business Plan or higher (e.g., vuln:cve-2019-11510)
STOCK_SEARCHES = {
'ANONYMOUS_FTP':'ftp anonymous ok',
'RDP':'port:3389 has_screenshot:true',
'OPEN_TELNET':'port:23 console gateway -password',
'APACHE_DIR_LIST':'http.title:"Index of /"',
'SPRING_BOOT':'http.favicon.hash:116323821',
'HP_PRINTERS':'"Serial Number:" "Built:" "Server: HP HTTP"',
'DOCKER_API':'"Docker Containers:" port:2375',
'ANDROID_ROOT_BRIDGE':'"Android Debug Bridge" "Device" port:5555',
'MONGO_EXPRESS_GUI':'"Set-Cookie: mongo-express=" "200 OK"',
'CVE-2019-11510_PULSE_VPN':'http.html:/dana-na/',
'CVE-2019-19781_CITRIX_NETSCALER':'http.waf:"Citrix NetScaler"',
'CVE-2020-5902_F5_BIGIP':'http.favicon.hash:-335242539 "3992"',
'CVE-2020-3452_CISCO_ASA_FTD':'200 "Set-Cookie: webvpn;"'
}
#OPTIONAL
#IP or cidr range constraint for searches that return list of IP addresses
#use comma-separated list to designate multiple (e.g. 1.1.1.1,2.2.0.0/16,3.3.3.3,3.3.3.4)
#NET_RANGE = '0.0.0.0/0'
Run
cd ../
python3 shonydanza.py
___________________________
@hacking_Attack
@Hacking_Video
With ShonyDanza, you can:Obtain IPs based on search criteriaAutomatically exclude honeypots from the results based on your pre-configured thresholdsPre-configure all IP searches to filter on your specified net range(s)Pre-configure search limitsUse build-a-search to craft searches with easy building blocksUse stock searches and pre-configure your own stock searchesCheck if IPs are known malware (https://www.kitploit.com/search/label/Malware) C2sGet host and domain profilesScan on-demandFind exploitsGet total counts for searches and exploitsAutomatically save exploit code, IP lists, host profiles, domain profiles, and scan results to directories within ShonyDanzaInstallationgit clone https://github.com/fierceoj/ShonyDanza.git
Requirementspython3shodan librarycd ShonyDanza
pip3 install -r requirements.txtUsageEdit config.py to include your desired configurations
cd configs
sudo nano config.py
dictionary below to add it to your shonydanza stock searches menu #see https://github.com/jakejarvis/awesome-shodan-queries for a great source of queries #check into "vuln:" filter if you have Small Business Plan or higher (e.g., vuln:cve-2019-11510) STOCK_SEARCHES = { 'ANONYMOUS_FTP':'ftp anonymous ok', 'RDP':'port:3389 has_screenshot:true', 'OPEN_TELNET':'port:23 console (https://www.kitploit.com/search/label/Console) gateway (https://www.kitploit.com/search/label/Gateway) -password', 'APACHE_DIR_LIST':'http.title:"Index of /"', 'SPRING_BOOT':'http.favicon.hash:116323821', 'HP_PRINTERS':'"Serial Number:" "Built:" "Server: HP HTTP"', 'DOCKER_API':'"Docker Containers:" port:2375', 'ANDROID_ROOT_BRIDGE':'"Android Debug Bridge" "Device" port:5555', 'MONGO_EXPRESS_GUI':'"Set-Cookie: mongo-express=" "200 OK"', 'CVE-2019-11510_PULSE_VPN':'http.html:/dana-na/', 'CVE-2019-19781_CITRIX_NETSCALER':'http.waf:"Citrix NetScaler"', 'CVE-2020-5902_F5_BIGIP':'http.favicon.hash:-335242539 "3992"', 'CVE-2020-3452_CISCO_ASA_FTD':'200 "Set-Cookie: webvpn;"' } #OPTIONAL #IP or cidr range constraint for searches that return list of IP addresses #use comma-separated list to designate multiple (e.g. 1.1.1.1,2.2.0.0/16,3.3.3.3,3.3.3.4) #NET_RANGE = '0.0.0.0/0' ">#config file for shonydanza searches
#REQUIRED
#maximum number of results that will be returned per search
#default is 100
SEARCH_LIMIT = 100
#REQUIRED
#IPs exceeding the honeyscore limit will not show up in IP results
#scale is 0.0 to 1.0
#adjust to desired probability to restrict results by threshold, or keep at 1.0 to include all results
HONEYSCORE_LIMIT = 1.0
#REQUIRED - at least one key: value pair
#add a shodan dork to the dictionary below to add it to your shonydanza stock searches menu
#see https://github.com/jakejarvis/awesome-shodan-queries for a great source of queries
#check into "vuln:" filter if you have Small Business Plan or higher (e.g., vuln:cve-2019-11510)
STOCK_SEARCHES = {
'ANONYMOUS_FTP':'ftp anonymous ok',
'RDP':'port:3389 has_screenshot:true',
'OPEN_TELNET':'port:23 console gateway -password',
'APACHE_DIR_LIST':'http.title:"Index of /"',
'SPRING_BOOT':'http.favicon.hash:116323821',
'HP_PRINTERS':'"Serial Number:" "Built:" "Server: HP HTTP"',
'DOCKER_API':'"Docker Containers:" port:2375',
'ANDROID_ROOT_BRIDGE':'"Android Debug Bridge" "Device" port:5555',
'MONGO_EXPRESS_GUI':'"Set-Cookie: mongo-express=" "200 OK"',
'CVE-2019-11510_PULSE_VPN':'http.html:/dana-na/',
'CVE-2019-19781_CITRIX_NETSCALER':'http.waf:"Citrix NetScaler"',
'CVE-2020-5902_F5_BIGIP':'http.favicon.hash:-335242539 "3992"',
'CVE-2020-3452_CISCO_ASA_FTD':'200 "Set-Cookie: webvpn;"'
}
#OPTIONAL
#IP or cidr range constraint for searches that return list of IP addresses
#use comma-separated list to designate multiple (e.g. 1.1.1.1,2.2.0.0/16,3.3.3.3,3.3.3.4)
#NET_RANGE = '0.0.0.0/0'
Run
cd ../
python3 shonydanza.py
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
See this how-to article (https://null-byte.wonderhowto.com/forum/to-use-shonydanza-find-target-and-exploit-0318883/) for additional usage instruction.Legal DisclaimerThis project is made for educational and ethical testing (https://www.kitploit.com/search/label/Testing) purposes only. Usage of ShonyDanza for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program.
Download ShonyDanza (https://github.com/fierceoj/ShonyDanza)
___________________________
@hacking_Attack
@Hacking_Video
Download ShonyDanza (https://github.com/fierceoj/ShonyDanza)
___________________________
@hacking_Attack
@Hacking_Video
WonderHowTo
How to: Use ShonyDanza to Find a Target and an Exploit
Shodan is a search engine that collects information on internet-connected devices. It is an incredibly powerful tool for security researchers, penetration testers, hackers, and network defenders. T...
Unlucky Story, Judge Duplicate, and Only Get a Thank You. But It makes Me smile.
This is from my local bounty program in my country, Indonesia. I found some vulnerabilities in an e-commerce website and I think it would…Continue reading on Medium »
Read more...
This is from my local bounty program in my country, Indonesia. I found some vulnerabilities in an e-commerce website and I think it would…Continue reading on Medium »
Read more...