docker run -v $(pwd)/credentials.json:/socialpwned/credentials.json -v $(pwd)/output:/socialpwned/output -it mrtuxx/socialpwned socialpwned.py --credentials credentials.json --ghunt --email-gh "email@example.com"
NOTE: Whenever you add the --ghunt flag this module will be executed. If you do it in a bulk search it may fail due to the amount of requests. Dehashed
___________________________
@hacking_Attack
@Hacking_Video
NOTE: Whenever you add the --ghunt flag this module will be executed. If you do it in a bulk search it may fail due to the amount of requests. Dehashed
___________________________
@hacking_Attack
@Hacking_Video
docker run -v $(pwd)/credentials.json:/socialpwned/credentials.json -v $(pwd)/output:/socialpwned/output -it mrtuxx/socialpwned socialpwned.py --credentials credentials.json --dehashed --email-dh "email@example.com"
NOTE: Adding the --dehashed flag at the end of each search will make an API request for each email. Combos docker run -v $(pwd)/credentials.json:/socialpwned/credentials.json -v $(pwd)/output:/socialpwned/output -it mrtuxx/socialpwned socialpwned.py --credentials credentials.json --instagram --target-ig username --followers-ig --followings-ig --linkedin --company 123456789 --employees --twitter --target-tw username --all-tw --pwndb --ghunt --dehashed
docker run -v $(pwd)/credentials.json:/socialpwned/credentials.json -v $(pwd)/output:/socialpwned/output -it mrtuxx/socialpwned socialpwned.py --credentials credentials.json --instagram --target-ig username --linkedin --target-in username --twitter --target-tw username --all-tw --pwndb --ghunt --dehashed
References Instagram API (https://github.com/LevPasha/Instagram-API-python). Author: LevPasha Linkedin API (https://github.com/tomquirk/linkedin-api). Author: tomquirk Twint (https://github.com/twintproject/twint). Author: twintproject PwnDB (https://github.com/davidtavarez/pwndb). Author: davidtavarez GHunt (https://github.com/mxrch/GHunt). Author: mxrch Disclaimer The usage of SocialPwned to attack targets without prior mutual consent is illegal. In addition, it makes use of different modules that violate Linkedin and Instagram rules, therefore, you will be banned temporarily or permanently. It is the responsibility of the end user to use SocialPwned. The developers are not responsible and are not liable for any misuse or damage caused.
Download SocialPwned (https://github.com/MrTuxx/SocialPwned)
___________________________
@hacking_Attack
@Hacking_Video
NOTE: Adding the --dehashed flag at the end of each search will make an API request for each email. Combos docker run -v $(pwd)/credentials.json:/socialpwned/credentials.json -v $(pwd)/output:/socialpwned/output -it mrtuxx/socialpwned socialpwned.py --credentials credentials.json --instagram --target-ig username --followers-ig --followings-ig --linkedin --company 123456789 --employees --twitter --target-tw username --all-tw --pwndb --ghunt --dehashed
docker run -v $(pwd)/credentials.json:/socialpwned/credentials.json -v $(pwd)/output:/socialpwned/output -it mrtuxx/socialpwned socialpwned.py --credentials credentials.json --instagram --target-ig username --linkedin --target-in username --twitter --target-tw username --all-tw --pwndb --ghunt --dehashed
References Instagram API (https://github.com/LevPasha/Instagram-API-python). Author: LevPasha Linkedin API (https://github.com/tomquirk/linkedin-api). Author: tomquirk Twint (https://github.com/twintproject/twint). Author: twintproject PwnDB (https://github.com/davidtavarez/pwndb). Author: davidtavarez GHunt (https://github.com/mxrch/GHunt). Author: mxrch Disclaimer The usage of SocialPwned to attack targets without prior mutual consent is illegal. In addition, it makes use of different modules that violate Linkedin and Instagram rules, therefore, you will be banned temporarily or permanently. It is the responsibility of the end user to use SocialPwned. The developers are not responsible and are not liable for any misuse or damage caused.
Download SocialPwned (https://github.com/MrTuxx/SocialPwned)
___________________________
@hacking_Attack
@Hacking_Video
Hello lads, it’s me again. Let’s discuss different techniques about bypassing 2FA.Continue reading on Medium » (https://aaryanapex.medium.com/2fa-bypass-techniques-dcdb19d29f11?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
2FA Bypass Techniques
Hello lads, it’s me again. Let’s discuss different techniques about bypassing 2FA.
APWine Incorrect Check of Delegations Bugfix Review
https://medium.com/immunefi/apwine-incorrect-check-of-delegations-bugfix-review-7e401a49c04f?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/immunefi/apwine-incorrect-check-of-delegations-bugfix-review-7e401a49c04f?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
APWine Incorrect Check of Delegations Bugfix Review
In the Web2 world, a simple oversight in the code doesn’t always result in a huge breach of data (of course, sometimes they do). In Web3…
In the Web2 world, a simple oversight in the code doesn’t always result in a huge breach of data (of course, sometimes they do). In Web3…Continue reading on Immunefi » (https://medium.com/immunefi/apwine-incorrect-check-of-delegations-bugfix-review-7e401a49c04f?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
APWine Incorrect Check of Delegations Bugfix Review
In the Web2 world, a simple oversight in the code doesn’t always result in a huge breach of data (of course, sometimes they do). In Web3…
Registrations Open for IWCON 2022 — the Online International Cybersecurity Conference
https://infosecwriteups.com/registrations-open-for-iwcon-2022-the-online-international-cybersecurity-conference-6890fbd37474?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://infosecwriteups.com/registrations-open-for-iwcon-2022-the-online-international-cybersecurity-conference-6890fbd37474?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Registrations Open for IWCON 2022 — the Online International Cybersecurity Conference
Book your seats today!
Book your seats today!Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/registrations-open-for-iwcon-2022-the-online-international-cybersecurity-conference-6890fbd37474?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Registrations Open for IWCON 2022 — the Online International Cybersecurity Conference
Book your seats today!
Privilege Escalation Using Wildcard Injection | Tar Wildcard Injection |
https://systemweakness.com/privilege-escalation-using-wildcard-injection-tar-wildcard-injection-a57bc81df61c?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://systemweakness.com/privilege-escalation-using-wildcard-injection-tar-wildcard-injection-a57bc81df61c?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Privilege Escalation Using Wildcard Injection | Tar Wildcard Injection |
This blog is about how to use Wildcard Injection to escalate privileges to root in Unix-like OS.
This blog is about how to use Wildcard Injection to escalate privileges to root in Unix-like OS.Continue reading on System Weakness » (https://systemweakness.com/privilege-escalation-using-wildcard-injection-tar-wildcard-injection-a57bc81df61c?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Privilege Escalation Using Wildcard Injection | Tar Wildcard Injection |
This blog is about how to use Wildcard Injection to escalate privileges to root in Unix-like OS.
Full Account takeover (ATO) — a tale of two bugs
https://medium.com/@kojodaprogrammer/full-account-takeover-ato-a-tale-of-two-bugs-d1b3765ff1de?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@kojodaprogrammer/full-account-takeover-ato-a-tale-of-two-bugs-d1b3765ff1de?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Full Account takeover (ATO) — a tale of two bugs 🐛
Hi everyone, I hope we’re all having a swell day. Before I jump into today's bug report, I’d like to express my sincerest gratitude for…
Hi everyone, I hope we’re all having a swell day. Before I jump into today's bug report, I’d like to express my sincerest gratitude for…Continue reading on Medium » (https://medium.com/@kojodaprogrammer/full-account-takeover-ato-a-tale-of-two-bugs-d1b3765ff1de?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Full Account takeover (ATO) — a tale of two bugs 🐛
Hi everyone, I hope we’re all having a swell day. Before I jump into today's bug report, I’d like to express my sincerest gratitude for…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
AFLTriage : Tool To Triage Crashing Input Files Using A Debugger
AFLTriage is a tool to triage crashing input files using a debugger. It is designed to be portable and not require any run-time dependencies, besides libc and an external debugger. It supports triaging crashes generated by any program, not just AFL, but recognizes AFL directories specially, hence the name.
Some notable features include:
* Multiple report formats: text, JSON, and raw debugger JSON
* Parallel crash triage
* Crash deduplication
* Sanitizer report parsing
* Supports binary targets with or without symbols/debugging information
* Source code and variables will be annotated in reports for context
Currently AFLTriage only supports GDB and has only been tested on Linux C/C++ targets. Note that AFLTriage does not classify crashes by potential exploitablity. Accurate exploitability classification is very target and scenario specific and is best left to specialized tools and expert analysts. Usage
Usage of AFLTriage is quite straightforward. You need your inputs to triage, an output directory for reports, and the binary and its arguments to triage.
Example:
$ afltriage -i fuzzing_directory –o reports ./target_binary –option-one @@
AFLTriage v1.0.0
[+] GDB is working (GNU gdb (Ubuntu 8.1.1-0ubuntu1) 8.1.1 – Python 3.6.9 (default, Jan 26 2021, 15:33:00))
[+] Image triage cmdline: “./target_binary –option-one @@”
[+] Reports will be output to directory “reports”
[+] Triaging AFL directory fuzzing_directory/ (41 files)
[+] Triaging 41 testcases
[+] Using 24 threads to triage
[+] Triaging [41/41 00:00:02] [####################] CRASH: ASAN detected heap-buffer-overflow in buggy_function after a READ leading to SIGABRT (si_signo=6) / SI_TKILL (si_code=-6)
[+] Triage stats [Crashes: 25 (unique 12), No crash: 16, Errored: 0]
Similar to AFL the
You will need a working Rust build environment. Once you have cargo and rust installed, building and running is simple:
cd afltriage-rs/
cargo run –help
<compilation
Finished dev [unoptimized + debuginfo] target(s) in 0.33s
Running
Extended Usage
afltriage 1.0.0
Quickly triage and summarize crashing testcases
USAGE:
afltriage -i … -o …
OPTIONS:
-i …
A list of paths to a testcase, directory of testcases, AFL directory, and/or directory of AFL directories to
be triaged. Note that this arg takes multiple inputs in a row (e.g. -i input1 input2…) so it cannot be the
last argument passed to AFLTriage — this is reserved for the command.
-o
The output directory for triage report files. Use ‘-‘ to print entire reports to console.
-t, –timeout
The timeout in milliseconds for each testcase to triage. [default: 60000]
-j, –jobs
How many threads to use during triage.
–report-formats …
The triage report output formats. Multiple values allowed: e.g. text,json. [default: text] [possible
values: text, json, rawjson]
–bucket-strategy
The crash deduplication strategy to use. [default: afltriage] [possible values: none, afltriage,
first_frame, first_frame_raw, first_5_frames, function_names, first_function_name]
–child-output
Include child output in triage reports.
–child-output-lines
How many lines of program output from the target to include in reports. Use 0 to mean unlimited lines (not
recommended). [default: 25]
–stdin
Provide testcase input to the target via stdin instead of a file.
–profile-only
Perform environment checks, describe the inputs to be triaged, and profile the target binary.
–skip-profile
Skip target profiling before input processing.
–debug
Enable low-level debugging output of triage operations.
-h, –help
Prints help information
-V, –version
Prints version i[...]
AFLTriage : Tool To Triage Crashing Input Files Using A Debugger
AFLTriage is a tool to triage crashing input files using a debugger. It is designed to be portable and not require any run-time dependencies, besides libc and an external debugger. It supports triaging crashes generated by any program, not just AFL, but recognizes AFL directories specially, hence the name.
Some notable features include:
* Multiple report formats: text, JSON, and raw debugger JSON
* Parallel crash triage
* Crash deduplication
* Sanitizer report parsing
* Supports binary targets with or without symbols/debugging information
* Source code and variables will be annotated in reports for context
Currently AFLTriage only supports GDB and has only been tested on Linux C/C++ targets. Note that AFLTriage does not classify crashes by potential exploitablity. Accurate exploitability classification is very target and scenario specific and is best left to specialized tools and expert analysts. Usage
Usage of AFLTriage is quite straightforward. You need your inputs to triage, an output directory for reports, and the binary and its arguments to triage.
Example:
$ afltriage -i fuzzing_directory –o reports ./target_binary –option-one @@
AFLTriage v1.0.0
[+] GDB is working (GNU gdb (Ubuntu 8.1.1-0ubuntu1) 8.1.1 – Python 3.6.9 (default, Jan 26 2021, 15:33:00))
[+] Image triage cmdline: “./target_binary –option-one @@”
[+] Reports will be output to directory “reports”
[+] Triaging AFL directory fuzzing_directory/ (41 files)
[+] Triaging 41 testcases
[+] Using 24 threads to triage
[+] Triaging [41/41 00:00:02] [####################] CRASH: ASAN detected heap-buffer-overflow in buggy_function after a READ leading to SIGABRT (si_signo=6) / SI_TKILL (si_code=-6)
[+] Triage stats [Crashes: 25 (unique 12), No crash: 16, Errored: 0]
Similar to AFL the
@@is replaced with the path of the file to be triaged. AFLTriage will take care of the rest. Building and RunningYou will need a working Rust build environment. Once you have cargo and rust installed, building and running is simple:
cd afltriage-rs/
cargo run –help
<compilation
Finished dev [unoptimized + debuginfo] target(s) in 0.33s
Running
target/debug/afltriage --helpAFLTriage usage>Extended Usage
afltriage 1.0.0
Quickly triage and summarize crashing testcases
USAGE:
afltriage -i … -o …
OPTIONS:
-i …
A list of paths to a testcase, directory of testcases, AFL directory, and/or directory of AFL directories to
be triaged. Note that this arg takes multiple inputs in a row (e.g. -i input1 input2…) so it cannot be the
last argument passed to AFLTriage — this is reserved for the command.
-o
The output directory for triage report files. Use ‘-‘ to print entire reports to console.
-t, –timeout
The timeout in milliseconds for each testcase to triage. [default: 60000]
-j, –jobs
How many threads to use during triage.
–report-formats …
The triage report output formats. Multiple values allowed: e.g. text,json. [default: text] [possible
values: text, json, rawjson]
–bucket-strategy
The crash deduplication strategy to use. [default: afltriage] [possible values: none, afltriage,
first_frame, first_frame_raw, first_5_frames, function_names, first_function_name]
–child-output
Include child output in triage reports.
–child-output-lines
How many lines of program output from the target to include in reports. Use 0 to mean unlimited lines (not
recommended). [default: 25]
–stdin
Provide testcase input to the target via stdin instead of a file.
–profile-only
Perform environment checks, describe the inputs to be triaged, and profile the target binary.
–skip-profile
Skip target profiling before input processing.
–debug
Enable low-level debugging output of triage operations.
-h, –help
Prints help information
-V, –version
Prints version i[...]