Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
My own review of SMS verification services 2022
I have been reading a lot in this community and I would like to bring something useful for you, I know that some of you will find it very useful and even save money and time looking for the right service.
Normally this type of service is very useful for websites that when we are going to register asks us to put a phone number to verify our account (As is the case of PayPal, Gmail, eBay, Google Voice, Tinder, etc....).
With this post the only thing I want to do is to share my experience and I want to make clear that I will only leave reviews on sites that are paid (because the free ones you can try on your own), but I will leave a link where you can find many free services.
In all 2021 I spent more than 500$ in sms verification for websites like Google Voice, eBay and Moneylion mainly, but also for other services like Survey Sites, Social Networks sites among others. So I have enough experience to give you my point of view.
I calculated the score based on the following criterio
* Real and high quality non-voip numbers
* Price
* Support
* Payment methods
* Trustpilot reviews
* Availability
* Diversity of countries
* Long and short term numbers
Without further ado, let's get started:
VerifyWithSMS – verifywithsms.com – Score: 6.5/10
Well, they usually offer non voip numbers of average quality, for services with little security and demand it works really well, almost always works on the first try, but the panorama changes drastically with very demanded services as is the case of Google Voice. Lately none of them work, even Google tells you: "We can not accept this phone number, try another one" fortunately they give you a ref--un if the text message does not arrive so all is not lost. For cases like PayPal let's say that out of every 10 numbers you request, 5 work and 5 don't, so you have to be patient.
The price is affordable but not cheap (compared to other providers). Most of their numbers cost between $1.14 and $1.5, but if you are going to buy in large quantities, you should consider it.
Support is a bit slow. They take 1-2 days to respond, sometimes less, but that's the average. They usually solve the problems in most cases and this is a relief, especially when a service is not working properly.
Payment methods are varied but they lack the important stuff: Pay pal, among others. Currently they have Perfectmoney, Coinpayments and Payeer. Not bad, but for me it is not enough, it is not always easy to get cryptocurrencies and it is a bit frustrating when I am in a hurry and need a virtual number.
On Trustpilot they leave a lot to be desired with a lot of negative reviews recently, they currently have a rating of 2.6 with 117 reviews. Their percentage of negative reviews is 49% and their percentage of positive reviews is 38%.
You can check the reviews here: https://www.trustpilot.com/review/verifywithsms.com
In terms of availability, they replenish their stock very quickly when they run out of simcar every 24 hours they add new phone numbers which is a great help for services in high demand and with little security such as Gmail, they offer US and UK virtual numbers, although their catalog for UK is quite limited compared to US, however at least they offer both options, but unfortunately they do not offer Long-term numbers. According to official information, their platform will soon be offering this feature.
In conclusion, it is not a bad provider as long as you want to verify simple services with little security, but definitely do not try it with Google Voice.
Major Phones – majorphones.com – Scores: 9.5/10
Their website is very intuitive and clear, the quality of the numbers is exceptionally good, out of 10 numbers I request, 9 work perfectly, even on sites like [...]
___________________________
@hacking_Attack
@Hacking_Video
My own review of SMS verification services 2022
I have been reading a lot in this community and I would like to bring something useful for you, I know that some of you will find it very useful and even save money and time looking for the right service.
Normally this type of service is very useful for websites that when we are going to register asks us to put a phone number to verify our account (As is the case of PayPal, Gmail, eBay, Google Voice, Tinder, etc....).
With this post the only thing I want to do is to share my experience and I want to make clear that I will only leave reviews on sites that are paid (because the free ones you can try on your own), but I will leave a link where you can find many free services.
In all 2021 I spent more than 500$ in sms verification for websites like Google Voice, eBay and Moneylion mainly, but also for other services like Survey Sites, Social Networks sites among others. So I have enough experience to give you my point of view.
I calculated the score based on the following criterio
* Real and high quality non-voip numbers
* Price
* Support
* Payment methods
* Trustpilot reviews
* Availability
* Diversity of countries
* Long and short term numbers
Without further ado, let's get started:
VerifyWithSMS – verifywithsms.com – Score: 6.5/10
Well, they usually offer non voip numbers of average quality, for services with little security and demand it works really well, almost always works on the first try, but the panorama changes drastically with very demanded services as is the case of Google Voice. Lately none of them work, even Google tells you: "We can not accept this phone number, try another one" fortunately they give you a ref--un if the text message does not arrive so all is not lost. For cases like PayPal let's say that out of every 10 numbers you request, 5 work and 5 don't, so you have to be patient.
The price is affordable but not cheap (compared to other providers). Most of their numbers cost between $1.14 and $1.5, but if you are going to buy in large quantities, you should consider it.
Support is a bit slow. They take 1-2 days to respond, sometimes less, but that's the average. They usually solve the problems in most cases and this is a relief, especially when a service is not working properly.
Payment methods are varied but they lack the important stuff: Pay pal, among others. Currently they have Perfectmoney, Coinpayments and Payeer. Not bad, but for me it is not enough, it is not always easy to get cryptocurrencies and it is a bit frustrating when I am in a hurry and need a virtual number.
On Trustpilot they leave a lot to be desired with a lot of negative reviews recently, they currently have a rating of 2.6 with 117 reviews. Their percentage of negative reviews is 49% and their percentage of positive reviews is 38%.
You can check the reviews here: https://www.trustpilot.com/review/verifywithsms.com
In terms of availability, they replenish their stock very quickly when they run out of simcar every 24 hours they add new phone numbers which is a great help for services in high demand and with little security such as Gmail, they offer US and UK virtual numbers, although their catalog for UK is quite limited compared to US, however at least they offer both options, but unfortunately they do not offer Long-term numbers. According to official information, their platform will soon be offering this feature.
In conclusion, it is not a bad provider as long as you want to verify simple services with little security, but definitely do not try it with Google Voice.
Major Phones – majorphones.com – Scores: 9.5/10
Their website is very intuitive and clear, the quality of the numbers is exceptionally good, out of 10 numbers I request, 9 work perfectly, even on sites like [...]
___________________________
@hacking_Attack
@Hacking_Video
reddit
My own review of SMS verification services 2022
I have been reading a lot in this community and I would like to bring something useful for you, I know that some of you will find it very useful...
Hacking Articles Tips Tricks Videos Tutorials
hacking: security in practice My own review of SMS verification services 2022 I have been reading a lot in this community and I would like to bring something useful for you, I know that some of you will find it very useful and even save money and time looking…
PayPal, eBay and Amazon that sometimes give problems when verifying the account. The support is really very fast, they respond in less than 20 minutes and have always given me a solution to the problems. They give re--fun if the text message never arrives, although sometimes I have had to go to support because it doesn't give me the refun automatically and this is sometimes problematic. They don't offer as many payment methods, and again they are missing the important ones: Pay pal, the ones they currently have are Perfectmoney, Coinpayment, Payeer.
On trustpilot they have a rating of 4.2 with 9 reviews so far, 78% of them with 5 stars and the rest with 4 stars, which says a lot about the company. https://www.trustpilot.com/review/majorphones.com ,
Most people agree that the support is fast and the cost of the service is cheap, and it's true! Most of their virtual numbers cost from $0.5 to $1 which is really very affordable. They offer US and UK non voip numbers, plus they offer Short term and Long term numbers. This is a great advantage mainly for services like Twitter, Facebook, Whatsapp that sometimes ask for several verifications.
Normally they always have stock, except sometimes with services like Uber and when this happens, they usually replenish them in 24-48 hours (something that sometimes makes me desperate).
Overall, I highly recommend them, but I think if you don't have the payment methods they offer, you will have to look for other options.
You can check their Telegram Channel in: https://t.me/s/majorphonesllc
Textverified – textverified.com – Rating: 8/10
The quality of their numbers is very solid. I have only had occasional problems and most of them were (my fault for requesting too many codes or using proxy hosting). Very easy to use, convenient, and their support is fast (4-5 hours to respond). Like Major Phones and Verifywithsms, I really like the fact that if the text message doesn't arrive they do an automatic refu--n. I don't have to deal with asking for manual refu. The site is very simple and intuitive which makes it easy to use. Lately I've had a few problems verifying Tinder with them, mainly because the text message doesn't arrive. They accept alipay and wechat
On trustpilot they have a rating of 3.4 out of 5 with 10 reviews. You can check them out here: https://www.trustpilot.com/review/www.textverified.com
As for their services, they are affordable, with prices ranging from $0.75 to $1.5 but unfortunately they only offer US virtual numbers and only Short-term numbers which is a big drawback.
Note: They recently developed a feature to offer US (long-term) numbers but not under their name (which I find strange) I have never used it but you can check more information about this feature on their official website. https://www.textverified.com/blog/?p=502
You can check their blog in: https://www.textverified.com/blog/
SMSPVA – SMSPVA.COM – Rating: 2/10
This site is a piece of crap. Their numbers are very cheap but also of very bad quality. Out of 10 numbers 3 work and the worst thing is that sometimes they don't even give you a refu, when you go to complain in their chat, they block you and that's it.
On trustpilot they have a rating of 1.9, most of them insulting the company. You can check the reviews at https://www.trustpilot.com/review/smspva.com
My recommendation: Stay away from this company.
Reddit phoneverification – r/phoneverification – Rating: 5/10
Generally a positive experience with the sellers (I think that’s sellers are resellers) on r/phoneverification. But it's really inconvenient because the seller has to be online. Good prices can be found though. Can't really review it on the whole since you have bad sellers and good sellers. Lately, there's been a lot of spam from low quality sellers selling overly expensive/bad verifications. A good option if you're very patient.
I hope you find this useful. See you in a future post
subm[...]
___________________________
@hacking_Attack
@Hacking_Video
On trustpilot they have a rating of 4.2 with 9 reviews so far, 78% of them with 5 stars and the rest with 4 stars, which says a lot about the company. https://www.trustpilot.com/review/majorphones.com ,
Most people agree that the support is fast and the cost of the service is cheap, and it's true! Most of their virtual numbers cost from $0.5 to $1 which is really very affordable. They offer US and UK non voip numbers, plus they offer Short term and Long term numbers. This is a great advantage mainly for services like Twitter, Facebook, Whatsapp that sometimes ask for several verifications.
Normally they always have stock, except sometimes with services like Uber and when this happens, they usually replenish them in 24-48 hours (something that sometimes makes me desperate).
Overall, I highly recommend them, but I think if you don't have the payment methods they offer, you will have to look for other options.
You can check their Telegram Channel in: https://t.me/s/majorphonesllc
Textverified – textverified.com – Rating: 8/10
The quality of their numbers is very solid. I have only had occasional problems and most of them were (my fault for requesting too many codes or using proxy hosting). Very easy to use, convenient, and their support is fast (4-5 hours to respond). Like Major Phones and Verifywithsms, I really like the fact that if the text message doesn't arrive they do an automatic refu--n. I don't have to deal with asking for manual refu. The site is very simple and intuitive which makes it easy to use. Lately I've had a few problems verifying Tinder with them, mainly because the text message doesn't arrive. They accept alipay and wechat
On trustpilot they have a rating of 3.4 out of 5 with 10 reviews. You can check them out here: https://www.trustpilot.com/review/www.textverified.com
As for their services, they are affordable, with prices ranging from $0.75 to $1.5 but unfortunately they only offer US virtual numbers and only Short-term numbers which is a big drawback.
Note: They recently developed a feature to offer US (long-term) numbers but not under their name (which I find strange) I have never used it but you can check more information about this feature on their official website. https://www.textverified.com/blog/?p=502
You can check their blog in: https://www.textverified.com/blog/
SMSPVA – SMSPVA.COM – Rating: 2/10
This site is a piece of crap. Their numbers are very cheap but also of very bad quality. Out of 10 numbers 3 work and the worst thing is that sometimes they don't even give you a refu, when you go to complain in their chat, they block you and that's it.
On trustpilot they have a rating of 1.9, most of them insulting the company. You can check the reviews at https://www.trustpilot.com/review/smspva.com
My recommendation: Stay away from this company.
Reddit phoneverification – r/phoneverification – Rating: 5/10
Generally a positive experience with the sellers (I think that’s sellers are resellers) on r/phoneverification. But it's really inconvenient because the seller has to be online. Good prices can be found though. Can't really review it on the whole since you have bad sellers and good sellers. Lately, there's been a lot of spam from low quality sellers selling overly expensive/bad verifications. A good option if you're very patient.
I hope you find this useful. See you in a future post
subm[...]
___________________________
@hacking_Attack
@Hacking_Video
Trustpilot
Major Phones LLC is rated "Poor" with 2.7 / 5 on Trustpilot
Do you agree with Major Phones LLC's TrustScore? Voice your opinion today and hear what 50 customers have already said.
Hacking Articles Tips Tricks Videos Tutorials
PayPal, eBay and Amazon that sometimes give problems when verifying the account. The support is really very fast, they respond in less than 20 minutes and have always given me a solution to the problems. They give re--fun if the text message never arrives…
itted by /u/Mundane-Parsnip [link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Kenobi Walkthrough | TryHackMe | Explained | Part 1
https://medium.com/@Medusa0xf/kenobi-walkthrough-tryhackme-explained-part-1-8183d63db80b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@Medusa0xf/kenobi-walkthrough-tryhackme-explained-part-1-8183d63db80b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Kenobi Walkthrough|TryHackMe | Explained| Part 1
Goals: Enumerate Samba for shares, manipulate a vulnerable version of proftpd
Goals: Enumerate Samba for shares, manipulate a vulnerable version of proftpdContinue reading on Medium » (https://medium.com/@Medusa0xf/kenobi-walkthrough-tryhackme-explained-part-1-8183d63db80b?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Kenobi Walkthrough|TryHackMe | Explained| Part 1
Goals: Enumerate Samba for shares, manipulate a vulnerable version of proftpd
LAPTOPS
https://www.reddit.com/r/Pentesting/comments/sa5rtc/laptops/
Hello , I want a help in choosing a laptop , what laptop i should go for a gaming (asus rog zephyrus g14 base model ) or 2 in 1 laptop cuz i like them and use full too (HP envy / HP pavillion ) or go for mac air [21:33]is there going to be any limitation on mac or i should go for gaming one [21:33]looking as a cllg student and maybe some casual gamings , Whats most useful for me? submitted by /u/Revolutionary-Play59 (https://www.reddit.com/user/Revolutionary-Play59)
[link] (https://www.reddit.com/r/Pentesting/comments/sa5rtc/laptops/) [comments] (https://www.reddit.com/r/Pentesting/comments/sa5rtc/laptops/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/sa5rtc/laptops/
Hello , I want a help in choosing a laptop , what laptop i should go for a gaming (asus rog zephyrus g14 base model ) or 2 in 1 laptop cuz i like them and use full too (HP envy / HP pavillion ) or go for mac air [21:33]is there going to be any limitation on mac or i should go for gaming one [21:33]looking as a cllg student and maybe some casual gamings , Whats most useful for me? submitted by /u/Revolutionary-Play59 (https://www.reddit.com/user/Revolutionary-Play59)
[link] (https://www.reddit.com/r/Pentesting/comments/sa5rtc/laptops/) [comments] (https://www.reddit.com/r/Pentesting/comments/sa5rtc/laptops/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
LAPTOPS
1. Hello , I want a help in choosing a laptop , what laptop i should go for a gaming (asus rog zephyrus g14 base model ) or 2 in 1 laptop cuz i...
Kenobi Walkthrough | TryHackMe | Explained | Part 1
Goals: Enumerate Samba for shares, manipulate a vulnerable version of proftpdContinue reading on Medium »
Read more...
Goals: Enumerate Samba for shares, manipulate a vulnerable version of proftpdContinue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
OffensiveRust : Rust Weaponization For Red Team Engagements
OffensiveRust, my experiments in weaponizing Rust for implant development and general offensive operations.
Why Rust?
* It is faster than languages like C/C++
* It is multi-purpose language, bearing excellent communities
* It has an amazing inbuilt dependency build management called Cargo
* It is LLVM based which makes it a very good candidate for bypassing static AV detection
* Super easy cross compilation to Windows from *nix/MacOS, only requires you to install the
FileDescriptionAllocate_With_SyscallsIt uses NTDLL functions directly with the ntapi LibraryCreate_DLLCreates DLL and pops up a msgbox, Rust does not fully support this so things might get weird since Rust DLL do not have a main functionDeviceIoControlOpens driver handle and executing DeviceIoControlEnableDebugPrivilegesEnable SeDebugPrivilege in the current processShellcode_Local_injectExecutes shellcode directly in local process by casting pointerExecute_With_CMDExecutes cmd by passing a command via RustImportedFunctionCallIt imports minidump from dbghelp and executes itKernel_Driver_ExploitKernel Driver exploit for a simple buffer overflowNamed_Pipe_ClientNamed Pipe ClientNamed_Pipe_ServerNamed Pipe ServerProcess_Injection_CreateThreadProcess Injection in remote process with CreateRemoteThreadUnhookingUnhooking callsasm_syscallObtaining PEB address via asmbase64_system_enumBase64 encoding/decoding stringshttp-https-requestsHTTP/S requests by ignoring cert check for GET/POSTpatch_etwPatch ETWppid_spoofSpoof parent process for created processtcp_ssl_clientTCP client with SSL that ignores cert check (Requires openssl and perl to be installed for compiling)tcp_ssl_serverTCP Server, with port parameter(Requires openssl and perl to be installed for compiling)wmi_executeExecutes WMI query to obtain the AV/EDRs in the hostWindows.h+ BindingsThis file contains structures of Windows.h plus complete customized LDR,PEB,etc.. that are undocumented officially by Microsoft, add at the top of your file include!(“../bindings.rs”);UUID_Shellcode_ExecutionPlants shellcode from UUID array into heap space and uses
This repository does not provide binaries, you’re gonna have to compile them yourself.
Install Rust
Simply download the binary and install.
This repo was compiled in Windows 10 so I would stick to it. As mentioned OpenSSL binaries will have depencency issues that will require OpenSSL and perl to be installed. For the TCP SSL client/server I recommend static build due to dependencies on the hosts you will execute the binaries. For creating a project, execute: cargo new This will automatically create the structured project folders with:
project
├── Cargo.toml
└── src
└── main.rs
Cargo.toml is the file that contains the dependencies and the configuration for the compilation. main.rs is the main file that will be compiled along with any potential directories that contain libraries.
For compiling the project, go into the project directory and execute:
you can also you the below command inside the project directory to format it in a better way
___________________________
@hacking_Attack
@Hacking_Video
OffensiveRust : Rust Weaponization For Red Team Engagements
OffensiveRust, my experiments in weaponizing Rust for implant development and general offensive operations.
Why Rust?
* It is faster than languages like C/C++
* It is multi-purpose language, bearing excellent communities
* It has an amazing inbuilt dependency build management called Cargo
* It is LLVM based which makes it a very good candidate for bypassing static AV detection
* Super easy cross compilation to Windows from *nix/MacOS, only requires you to install the
mingwtoolchain, although certain libraries cannot be compiled successfully in other OSes. Examples in this repoFileDescriptionAllocate_With_SyscallsIt uses NTDLL functions directly with the ntapi LibraryCreate_DLLCreates DLL and pops up a msgbox, Rust does not fully support this so things might get weird since Rust DLL do not have a main functionDeviceIoControlOpens driver handle and executing DeviceIoControlEnableDebugPrivilegesEnable SeDebugPrivilege in the current processShellcode_Local_injectExecutes shellcode directly in local process by casting pointerExecute_With_CMDExecutes cmd by passing a command via RustImportedFunctionCallIt imports minidump from dbghelp and executes itKernel_Driver_ExploitKernel Driver exploit for a simple buffer overflowNamed_Pipe_ClientNamed Pipe ClientNamed_Pipe_ServerNamed Pipe ServerProcess_Injection_CreateThreadProcess Injection in remote process with CreateRemoteThreadUnhookingUnhooking callsasm_syscallObtaining PEB address via asmbase64_system_enumBase64 encoding/decoding stringshttp-https-requestsHTTP/S requests by ignoring cert check for GET/POSTpatch_etwPatch ETWppid_spoofSpoof parent process for created processtcp_ssl_clientTCP client with SSL that ignores cert check (Requires openssl and perl to be installed for compiling)tcp_ssl_serverTCP Server, with port parameter(Requires openssl and perl to be installed for compiling)wmi_executeExecutes WMI query to obtain the AV/EDRs in the hostWindows.h+ BindingsThis file contains structures of Windows.h plus complete customized LDR,PEB,etc.. that are undocumented officially by Microsoft, add at the top of your file include!(“../bindings.rs”);UUID_Shellcode_ExecutionPlants shellcode from UUID array into heap space and uses
EnumSystemLocalesACallback in order to execute the shellcode. Compiling the examples in this repoThis repository does not provide binaries, you’re gonna have to compile them yourself.
Install Rust
Simply download the binary and install.
This repo was compiled in Windows 10 so I would stick to it. As mentioned OpenSSL binaries will have depencency issues that will require OpenSSL and perl to be installed. For the TCP SSL client/server I recommend static build due to dependencies on the hosts you will execute the binaries. For creating a project, execute: cargo new This will automatically create the structured project folders with:
project
├── Cargo.toml
└── src
└── main.rs
Cargo.toml is the file that contains the dependencies and the configuration for the compilation. main.rs is the main file that will be compiled along with any potential directories that contain libraries.
For compiling the project, go into the project directory and execute:
cargo buildThis will use your default toolchain. If you want to build the final “release” version execute: cargo build --releaseFor static binaries, in terminal before the build command execute: "C:\Program Files (x86)\Microsoft Visual Studio\2019\Community\VC\Auxiliary\Build\vcvars64.bat"set RUSTFLAGS=-C target-feature=+crt-staticIn case it does not feel easy for you to read my code the way it is written,you can also you the below command inside the project directory to format it in a better way
cargo fmtCertain ex[...]___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
OffensiveRust : Rust Weaponization For Red Team Engagements
OffensiveRust, my experiments in weaponizing Rust for implant development and general offensive operations.
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials OffensiveRust : Rust Weaponization For Red Team Engagements OffensiveRust, my experiments in weaponizing Rust for implant development and general offensive operations. Why Rust? * It is faster than languages like C/C++ * It is multi…
amples might not compile and give you some error, since it might require a nightly
build of Rust with the latest features. To install it just do:
Cross-Compiling requires to follow the instructions here By installing different toolchains, you can cross compile with the below command cargo build --target To see the installed toolchains on your system do:
This repo contains a lot of configuration options and ideas about reducing the file size. Static binaries are usually quite big. Pitfalls I found myself falling into
Careful of \0 bytes, do not forget them for strings in memory, I spent a lot of my time but windbg always helped resolving it. Interesting Rust libraries
* WINAPI
* WINAPI2
* Windows – This is the official Microsoft one that I have not played much with OPSEC
* Even though Rust has good advantages it is quite difficult to get used to it and it ain’t very intuitive.
* Shellcode generation is another issue due to LLVM. I have found a few ways to approach this.
Donut sometimes does generate shellcode that works but depending on how the project is made, it might not.
In general, for shellcode generation the tools that are made should be made to host all code in .text segment, which leads to this amazing repo. There is a shellcode sample in this project that can show you how to structure your code for successfull shellcode generation.
In addition, this project also has a shellcode generator that grabs the .text segment of a binary and and dumps the shellcode after executing some patches.
This project grabs from a specific location the binary so I made a fork that receives the path of the binary as an argument here.
* Even if you remove all debug symbols, rust can still keep references to your home directory in the binary. The only way I’ve found to remove this is to pass the following flag:
* Although for the above there is another way to remove info about the home directory by adding at the top of Cargo.toml
* Since Rust by default leaves a lot of things as strings in the binary, I mostly use this cargo.toml to avoid them and also reduce size
with build command
___________________________
@hacking_Attack
@Hacking_Video
build of Rust with the latest features. To install it just do:
rustup default nightlyThe easiest place to find the dependencies or Crates as they are called. Cross CompilingCross-Compiling requires to follow the instructions here By installing different toolchains, you can cross compile with the below command cargo build --target To see the installed toolchains on your system do:
rustup toolchain listFor checking all the available toolchains you can install in your system do: rustup target listFor installing a new toolchain do: rustup target add Optimizing executables for sizeThis repo contains a lot of configuration options and ideas about reducing the file size. Static binaries are usually quite big. Pitfalls I found myself falling into
Careful of \0 bytes, do not forget them for strings in memory, I spent a lot of my time but windbg always helped resolving it. Interesting Rust libraries
* WINAPI
* WINAPI2
* Windows – This is the official Microsoft one that I have not played much with OPSEC
* Even though Rust has good advantages it is quite difficult to get used to it and it ain’t very intuitive.
* Shellcode generation is another issue due to LLVM. I have found a few ways to approach this.
Donut sometimes does generate shellcode that works but depending on how the project is made, it might not.
In general, for shellcode generation the tools that are made should be made to host all code in .text segment, which leads to this amazing repo. There is a shellcode sample in this project that can show you how to structure your code for successfull shellcode generation.
In addition, this project also has a shellcode generator that grabs the .text segment of a binary and and dumps the shellcode after executing some patches.
This project grabs from a specific location the binary so I made a fork that receives the path of the binary as an argument here.
* Even if you remove all debug symbols, rust can still keep references to your home directory in the binary. The only way I’ve found to remove this is to pass the following flag:
--remap-path-prefix {your home directory}={some random identifier}. You can use bash variables to get your home directory and generate a random placeholder: --remap-path-prefix "$HOME"="$RANDOM". (By Yamakadi)* Although for the above there is another way to remove info about the home directory by adding at the top of Cargo.toml
cargo-features = ["strip"].* Since Rust by default leaves a lot of things as strings in the binary, I mostly use this cargo.toml to avoid them and also reduce size
with build command
cargo build --release -Z build-std=std,panic_abort -Z build-std-features=panic_immediate_abort --target x86_64-pc-windows-msvcDownload___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
4-ZERO-3 : 403/401 Bypass Methods + Bash Automation
4-ZERO-3 Tool to bypass 403/401. This script contain all the possible techniques to do the same.
* NOTE : If you see multiple [200 Ok]/bypasses as output, you must check the Content-Length. If the content-length is same for multiple [200 Ok]/bypasses means false positive. Reason can be “301/302” or “../” [Payload] DON’T PANIC.
* Script will print
Preview
https://blogger.googleusercontent.com/img/a/AVvXsEh-Azb5dLefZw7DoFtDQnobEZMUybDoJ-J1gugTm6IAIv6dsGDnJPUOSq28t0y-9wyWP9nqZKLfSIjRVsDlJzIYfE2EyAnic9KxXl_x4pxrCFHvnLNCcCABmamILH4UbGCcxMnQMXBFUynok73jOWaWz5UKU-XaGIwQ974OAuWEskg4NAmxVi-nfxPO=s1880
Help
root@me_dheeraj:$ bash 403-bypass.sh -h
https://blogger.googleusercontent.com/img/a/AVvXsEiRoCOl4w8pr--iR6lDUoGLH7gwXmVBMjQqhNFrLZCo5XHK41Wb7KZdJ_zBWhzR0T8yaEj7H55cK88Jc2hivE1Z7uodcqS4g03gdeLfkDqUKYAogtrbxcIgEkBCMaser7seoEkILZc9oXZUSjjRO94FVCFm5M0xqryPRSw3-mCbOB8wHZjcGZXdEcI7=s886
Usage / Modes
* Scan with specific payloads:
[
root@me_dheeraj:$ bash 403-bypass.sh -u https://target.com/secret –header
[
root@me_dheeraj:$ bash 403-bypass.sh -u https://target.com/secret –protocol
root@me_dheeraj:$ bash 403-bypass.sh -u https://target.com/secret –port
root@me_dheeraj:$ bash 403-bypass.sh -u https://target.com/secret –HTTPmethod
[
root@me_dheeraj:$ bash 403-bypass.sh -u https://target.com/secret –encode
root@me_dheeraj:$ bash 403-bypass.sh -u https://target.com/secret –SQLi
* Complete Scan {includes all exploits/payloads} for an endpoint [ –exploit ]
root@me_dheeraj:$ bash 403-bypass.sh -u https://target.com/secret –exploit
Download
___________________________
@hacking_Attack
@Hacking_Video
4-ZERO-3 : 403/401 Bypass Methods + Bash Automation
4-ZERO-3 Tool to bypass 403/401. This script contain all the possible techniques to do the same.
* NOTE : If you see multiple [200 Ok]/bypasses as output, you must check the Content-Length. If the content-length is same for multiple [200 Ok]/bypasses means false positive. Reason can be “301/302” or “../” [Payload] DON’T PANIC.
* Script will print
cURLPAYLOAD if possible bypass found.Preview
https://blogger.googleusercontent.com/img/a/AVvXsEh-Azb5dLefZw7DoFtDQnobEZMUybDoJ-J1gugTm6IAIv6dsGDnJPUOSq28t0y-9wyWP9nqZKLfSIjRVsDlJzIYfE2EyAnic9KxXl_x4pxrCFHvnLNCcCABmamILH4UbGCcxMnQMXBFUynok73jOWaWz5UKU-XaGIwQ974OAuWEskg4NAmxVi-nfxPO=s1880
Help
root@me_dheeraj:$ bash 403-bypass.sh -h
https://blogger.googleusercontent.com/img/a/AVvXsEiRoCOl4w8pr--iR6lDUoGLH7gwXmVBMjQqhNFrLZCo5XHK41Wb7KZdJ_zBWhzR0T8yaEj7H55cK88Jc2hivE1Z7uodcqS4g03gdeLfkDqUKYAogtrbxcIgEkBCMaser7seoEkILZc9oXZUSjjRO94FVCFm5M0xqryPRSw3-mCbOB8wHZjcGZXdEcI7=s886
Usage / Modes
* Scan with specific payloads:
[
--header] Support HEADER based bypasses/payloadsroot@me_dheeraj:$ bash 403-bypass.sh -u https://target.com/secret –header
[
--protocol] Support PROTOCOL based bypasses/payloadsroot@me_dheeraj:$ bash 403-bypass.sh -u https://target.com/secret –protocol
--port] Support PORT based bypasses/payloadroot@me_dheeraj:$ bash 403-bypass.sh -u https://target.com/secret –port
--HTTPmethod] Support HTTP Method based bypasses/payloadroot@me_dheeraj:$ bash 403-bypass.sh -u https://target.com/secret –HTTPmethod
[
--encode] Support URL Encoded bypasses/payloadroot@me_dheeraj:$ bash 403-bypass.sh -u https://target.com/secret –encode
--SQLi] Support MySQL mod_Security & libinjection bypasses/payloads [** New **]root@me_dheeraj:$ bash 403-bypass.sh -u https://target.com/secret –SQLi
* Complete Scan {includes all exploits/payloads} for an endpoint [ –exploit ]
root@me_dheeraj:$ bash 403-bypass.sh -u https://target.com/secret –exploit
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
4-ZERO-3 : 403/401 Bypass Methods + Bash Automation
4-ZERO-3 Tool to bypass 403/401. This script contain all the possible techniques to do the same. If you see multiple [200 Ok]/bypasses .
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Neovim for Beginner — Auto Pairs
https://cdn-images-1.medium.com/max/859/1*iKnnKICOb4Nht9Dhh3Tw5g.png
Configure treesitter-based auto-pairing, auto-tagging, and end-wise completion.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Neovim for Beginner — Auto Pairs
https://cdn-images-1.medium.com/max/859/1*iKnnKICOb4Nht9Dhh3Tw5g.png
Configure treesitter-based auto-pairing, auto-tagging, and end-wise completion.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Neovim for Beginner — Auto Pairs
Configure treesitter-based auto-pairing, auto-tagging, and end-wise completion.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to Protect Yourself From Camera and Microphone Hacking
https://cdn-images-1.medium.com/max/860/1*woCCi1VymPcUH7FmGmgJlg.jpeg
Write down the steps to protect your camera and microphone from being hacked
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to Protect Yourself From Camera and Microphone Hacking
https://cdn-images-1.medium.com/max/860/1*woCCi1VymPcUH7FmGmgJlg.jpeg
Write down the steps to protect your camera and microphone from being hacked
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to Protect Yourself From Camera and Microphone Hacking
Write down the steps to protect your camera and microphone from being hacked
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Termux:Widget — User Termux Widget Like a Pro in 2022
https://cdn-images-1.medium.com/max/600/0*mjyBQwb7Us-KOo7h.png
Hey guys 🙋♂️, Termux is one of the best tool when it comes to android Hacking and Scripting and the one measure issue that we face with…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Termux:Widget — User Termux Widget Like a Pro in 2022
https://cdn-images-1.medium.com/max/600/0*mjyBQwb7Us-KOo7h.png
Hey guys 🙋♂️, Termux is one of the best tool when it comes to android Hacking and Scripting and the one measure issue that we face with…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Termux:Widget — User Termux Widget Like a Pro in 2022
Hey guys 🙋♂️, Termux is one of the best tool when it comes to android Hacking and Scripting and the one measure issue that we face with…