hacking: security in practice
I created another OSINT tool to find Instagram places and posts based on their locaiton
Hi Everyone,
I hope you are doing well. Last week I created a tool for finding tweets based on locations (https://birdhunt.co/) and I have created an app that does the same for Instagram places/posts. It's completely free to use again, It is desktop only but would love to make it mobile-friendly in the future.
the new tool can be found here: https://instahunt.co/
It would be great to hear your thoughts and feedback!
submitted by /u/LibertyProgram
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
I created another OSINT tool to find Instagram places and posts based on their locaiton
Hi Everyone,
I hope you are doing well. Last week I created a tool for finding tweets based on locations (https://birdhunt.co/) and I have created an app that does the same for Instagram places/posts. It's completely free to use again, It is desktop only but would love to make it mobile-friendly in the future.
the new tool can be found here: https://instahunt.co/
It would be great to hear your thoughts and feedback!
submitted by /u/LibertyProgram
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
I created another OSINT tool to find Instagram places and posts...
Hi Everyone, I hope you are doing well. Last week I created a tool for finding tweets based on locations...
https://external-preview.redd.it/XgKCLfVCBI9E5iWKPvzE9yEVWbK32k_iDwn4g2_qjMw.jpg?width=640&crop=smart&auto=webp&s=647acfb76dc4b9fb247006b2dca58f96627e4509 Started down this rabbit hole to try and make a dumb remote smart. Anything to spoof button presses and also has a web interface takes too much power since it runs on 3XAAA, so I started trying to clone the dumb state signals. Picked up an RTLSDR dongle and confirmed that the transmissions are at 417.9 Mhz. Pic below of what one of the signals looks like in URH. Even if I could identify the proper code, I have no idea how to transmit at that frequency. The controller has a custom programmed RFM110 transmitter. Thoughts on how I could proceed?
https://preview.redd.it/jfca9ixupth81.png?width=1023&format=png&auto=webp&s=eaaa9207f34504fe81bcaafa0a1ec774efdcfad9
submitted by /u/moose09876
[link] [comments]
https://preview.redd.it/jfca9ixupth81.png?width=1023&format=png&auto=webp&s=eaaa9207f34504fe81bcaafa0a1ec774efdcfad9
submitted by /u/moose09876
[link] [comments]
hacking: security in practice
is it illegal to make a virus that reminds people not to run strange files?
my plan is to make a virus that spreads itself but the only thing it open is a window with the text "please dont run random/strange .exe files on your pc what you've ran now couldve been malware this virus didnt do anything to your pc stay safe"?
EDIT: thx for the fast answers thought to make it as a small project to remind people to not run random stuff from the internet but as you may know i cant do it in prison
submitted by /u/TheHolyTachankaYT
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
is it illegal to make a virus that reminds people not to run strange files?
my plan is to make a virus that spreads itself but the only thing it open is a window with the text "please dont run random/strange .exe files on your pc what you've ran now couldve been malware this virus didnt do anything to your pc stay safe"?
EDIT: thx for the fast answers thought to make it as a small project to remind people to not run random stuff from the internet but as you may know i cant do it in prison
submitted by /u/TheHolyTachankaYT
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
is it illegal to make a virus that reminds people not to run...
my plan is to make a virus that spreads itself but the only thing it open is a window with the text "please dont run random/strange .exe files on...
hacking: security in practice
How to clear apps data without any exceptions using shell or by meterpreter session?
I want to do it through shell or through meterpreter session!
I just want to clear app data or to reinstall the app..
I tried uninstalling app using meterpreter:-
I tried using "app_uninstall package_name" but shows uninstall dialog option on the screen to do it manually...
Is there a way to clear app data or to uninstall an app without any exception and without accessing root?
(The phone is not rooted)
(For educational purpose)
submitted by /u/QinnStar
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to clear apps data without any exceptions using shell or by meterpreter session?
I want to do it through shell or through meterpreter session!
I just want to clear app data or to reinstall the app..
I tried uninstalling app using meterpreter:-
I tried using "app_uninstall package_name" but shows uninstall dialog option on the screen to do it manually...
Is there a way to clear app data or to uninstall an app without any exception and without accessing root?
(The phone is not rooted)
(For educational purpose)
submitted by /u/QinnStar
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to clear apps data without any exceptions using shell or by...
I want to do it through shell or through meterpreter session! I just want to clear app data or to reinstall the app.. I tried uninstalling app...
hacking: security in practice
Can we clear any app data using a shell script?
If so then can someone give me the script?
submitted by /u/QinnStar
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Can we clear any app data using a shell script?
If so then can someone give me the script?
submitted by /u/QinnStar
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Can we clear any app data using a shell script?
If so then can someone give me the script?
hacking: security in practice
Does anyone know how to get into an old Microsoft account??
ok so i have an old Microsoft account that i need to regain access too but no longer have the password and its so old there are no security systems in place like a phone or backup Email linked to it. . i have tried going through Microsofts shitty password recovery system but I never had an Xbox account, an Outlook or Hotmail and i do have an old skype but i don't think it was ever linked to the account as it was made before they acquired Skype. . .
i have tried going through their support but its shit and they just did the stupid password recovery system I tried and told them failed. .
Does anyone know a way different way I can recover this account? to be clear I'm not asking to hire anyone. . as I am not tech-savvy enough for that and dont want to get my other information compromised. .
all I want is to know if there is another way I can maybe contact Microsoft or some other way I can regain access to this account??
submitted by /u/V7I_TheSeventhSector
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Does anyone know how to get into an old Microsoft account??
ok so i have an old Microsoft account that i need to regain access too but no longer have the password and its so old there are no security systems in place like a phone or backup Email linked to it. . i have tried going through Microsofts shitty password recovery system but I never had an Xbox account, an Outlook or Hotmail and i do have an old skype but i don't think it was ever linked to the account as it was made before they acquired Skype. . .
i have tried going through their support but its shit and they just did the stupid password recovery system I tried and told them failed. .
Does anyone know a way different way I can recover this account? to be clear I'm not asking to hire anyone. . as I am not tech-savvy enough for that and dont want to get my other information compromised. .
all I want is to know if there is another way I can maybe contact Microsoft or some other way I can regain access to this account??
submitted by /u/V7I_TheSeventhSector
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Does anyone know how to get into an old Microsoft account??
ok so i have an old Microsoft account that i need to regain access too but no longer have the password and its so old there are no security...
Hacking on Medium
Gmail user enumeration
A couple of years ago I stumbled across this article. The person who authored the page found an API end point that if a valid Gmail email…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Gmail user enumeration
A couple of years ago I stumbled across this article. The person who authored the page found an API end point that if a valid Gmail email…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Gmail user enumeration
A couple of years ago I stumbled across this article. The person who authored the page found an API end point that if a valid Gmail email…
Hacking on Medium
Coinbase invierte millones en mostrar un QR durante la Super Bowl y le sale el tiro por la culata…
https://cdn-images-1.medium.com/max/1275/0*zkjIQvSteB7Ywuwb
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Coinbase invierte millones en mostrar un QR durante la Super Bowl y le sale el tiro por la culata…
https://cdn-images-1.medium.com/max/1275/0*zkjIQvSteB7Ywuwb
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Coinbase invierte millones en mostrar un QR durante la Super Bowl y le sale el tiro por la culata: la web se cae en segundos
Coinbase, uno de los mayores mercados de criptomonedas del mundo, se ha convertido esta pasada noche en uno de las grandes sensaciones de la pausa publicitaria de la Super Bowl. Esto es, de los…
Hacking on Medium
Noticias cripto de la semana: Colombia, Super Bowl y recuperan BTC robados
https://cdn-images-1.medium.com/max/1500/1*zohqifvH05XYR8oryRCgXw.png
La industria cripto continúa su evolución. Conoce las noticias de criptomonedas más relevantes de la segunda semana de febrero.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Noticias cripto de la semana: Colombia, Super Bowl y recuperan BTC robados
https://cdn-images-1.medium.com/max/1500/1*zohqifvH05XYR8oryRCgXw.png
La industria cripto continúa su evolución. Conoce las noticias de criptomonedas más relevantes de la segunda semana de febrero.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Noticias cripto de la semana: Colombia, Super Bowl y recuperan BTC robados
La industria cripto continúa su evolución. Conoce las noticias de criptomonedas más relevantes de la segunda semana de febrero.
Hacking on Medium
Pandora — HTB Write Up
https://cdn-images-1.medium.com/max/700/1*trxa__MZUAw8vtUjHghD9Q.png
Walkthrough of a easy Hack The Box Machine
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Pandora — HTB Write Up
https://cdn-images-1.medium.com/max/700/1*trxa__MZUAw8vtUjHghD9Q.png
Walkthrough of a easy Hack The Box Machine
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Pandora — HTB Write Up
Walkthrough of a easy Hack The Box Machine
Hacking on Medium
NFL’s San Francisco 49ers suffer a ransomware attack just before the Superbowl | #malware |…
https://cdn-images-1.medium.com/max/1085/1*kV1Tzw5ayQ8AQFZxC488Jw.png
Just hours before Superbowl LVI (56), the San Francisco 49ers became victim of a ransomware attack. At this time, the team is stating they…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
NFL’s San Francisco 49ers suffer a ransomware attack just before the Superbowl | #malware |…
https://cdn-images-1.medium.com/max/1085/1*kV1Tzw5ayQ8AQFZxC488Jw.png
Just hours before Superbowl LVI (56), the San Francisco 49ers became victim of a ransomware attack. At this time, the team is stating they…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
NFL’s San Francisco 49ers suffer a ransomware attack just before the Superbowl | #malware | #ransomware
Just hours before Superbowl LVI (56), the San Francisco 49ers became victim of a ransomware attack. At this time, the team is stating they…
Hacking on Medium
Uploading malicious files
https://cdn-images-1.medium.com/max/600/1*X-O16R3Fk4s1zqxS6bRWvw.png
Guys! I’m back with a new blog and I’m so excited because with this room from hacker101ctf you can learn a lot about file upload…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Uploading malicious files
https://cdn-images-1.medium.com/max/600/1*X-O16R3Fk4s1zqxS6bRWvw.png
Guys! I’m back with a new blog and I’m so excited because with this room from hacker101ctf you can learn a lot about file upload…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Uploading malicious files
Guys! I’m back with a new blog and I’m so excited because with this room from hacker101ctf you can learn a lot about file upload…
Hacking on Medium
Vulnerabilidades de los enrutadores de la serie RV de Cisco Small Business
https://cdn-images-1.medium.com/max/1571/0*no_9MML0kjta1g89
PUBLICADO EN 14 FEBRERO, 2022 POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Vulnerabilidades de los enrutadores de la serie RV de Cisco Small Business
https://cdn-images-1.medium.com/max/1571/0*no_9MML0kjta1g89
PUBLICADO EN 14 FEBRERO, 2022 POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Vulnerabilidades de los enrutadores de la serie RV de Cisco Small Business
PUBLICADO EN 14 FEBRERO, 2022 POR EHACKING
Hacking on Medium
Check Out The Full Speaker Line-Up of IWCON 2022
https://cdn-images-1.medium.com/max/1440/1*85rTWfkKDYRlEaDA4_4EYQ.png
Book your seats for the coolest, most value-packed cybersecurity event of 2022!
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Check Out The Full Speaker Line-Up of IWCON 2022
https://cdn-images-1.medium.com/max/1440/1*85rTWfkKDYRlEaDA4_4EYQ.png
Book your seats for the coolest, most value-packed cybersecurity event of 2022!
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Check Out The Full Speaker Line-Up of IWCON 2022
Book your seats for the coolest, most value-packed cybersecurity event of 2022!
KitPloit - PenTest Tools!
Droopescan - A Plugin-Based Scanner That Aids Security Researchers In Identifying Issues With Several CMSs, Mainly Drupal And Silverstripe
___________________________
@hacking_Attack
@Hacking_Video
Droopescan - A Plugin-Based Scanner That Aids Security Researchers In Identifying Issues With Several CMSs, Mainly Drupal And Silverstripe
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Droopescan - A Plugin-Based Scanner That Aids Security Researchers In Identifying Issues With Several CMSs, Mainly Drupal And Silverstripe
Droopescan - A Plugin-Based Scanner That Aids Security Researchers In Identifying Issues With Several CMSs, Mainly Drupal And Silverstripe
http://www.kitploit.com/2022/02/droopescan-plugin-based-scanner-that.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/02/droopescan-plugin-based-scanner-that.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Droopescan - A Plugin-Based Scanner That Aids Security Researchers In Identifying Issues With Several CMSs, Mainly Drupal And Silverstripe
A plugin-based scanner that aids security researchers in identifying issues with several CMS. Usage of droopescan (https://www.kitploit.com/search/label/Droopescan) for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program. Please note that while droopescan outputs the most CMS likely version installed on the remote host, any correlation between version numbers and vulnerabilities (https://www.kitploit.com/search/label/vulnerabilities) must be done manually by the user.
Supported CMS are: SilverStripe Wordpress Drupal Partial functionality for: Joomla (version enumeration (https://www.kitploit.com/search/label/Enumeration) and interesting URLs only) Moodle (plugin & theme very limited, watch out) computer:~/droopescan$ droopescan scan drupal -u http://example.org/ -t 32
[+] No themes found.
[+] Possible interesting urls found:
Default changelog file - https://www.example.org/CHANGELOG.txt
Default admin - https://www.example.org/user/login
[+] Possible version(s):
7.34
[+] Plugins found:
views https://www.example.org/sites/all/modules/views/
https://www.example.org/sites/all/modules/views/README.txt
https://www.example.org/sites/all/modules/views/LICENSE.txt
token https://www.example.org/sites/all/modules/token/
https://www.example.org/sites/all/modules/token/README.txt
https://www.example.org/sites/all/modules/token/LICENSE.txt
pathauto https://www.example.org/sites/all/modules/pathauto/
https://www.example.org/sites/all/modules/pathauto/README.txt
https://www.example.org/s ites/all/modules/pathauto/LICENSE.txt
https://www.example.org/sites/all/modules/pathauto/API.txt
libraries https://www.example.org/sites/all/modules/libraries/
https://www.example.org/sites/all/modules/libraries/CHANGELOG.txt
https://www.example.org/sites/all/modules/libraries/README.txt
https://www.example.org/sites/all/modules/libraries/LICENSE.txt
entity https://www.example.org/sites/all/modules/entity/
https://www.example.org/sites/all/modules/entity/README.txt
https://www.example.org/sites/all/modules/entity/LICENSE.txt
google_analytics https://www.example.org/sites/all/modules/google_analytics/
https://www.example.org/sites/all/modules/google_analytics/README.txt
https://www.example.org/sites/all/modules/google_analytics/LICENSE.txt
ctools https://www.example.org/sites/all/modules/ctools/
https://www.example.org/sites/all/modules/ctools/CH ANGELOG.txt
https://www.example.org/sites/all/modules/ctools/LICENSE.txt
https://www.example.org/sites/all/modules/ctools/API.txt
features https://www.example.org/sites/all/modules/features/
https://www.example.org/sites/all/modules/features/CHANGELOG.txt
https://www.example.org/sites/all/modules/features/README.txt
https://www.example.org/sites/all/modules/features/LICENSE.txt
https://www.example.org/sites/all/modules/features/API.txt
[... snip for README ...]
[+] Scan finished (0:04:59.502427 elapsed)
You can get a full list of options by running: droopescan --help
droopescan scan --help Why not X? Because droopescan: is fast is stable is up to date allows simultaneous scanning of multiple sites is 100% python Installation With pip (recommended) Installation is easy using pip: apt-get install python-pip
pip install droopescan From sources Manual installation is as follows: git clone https://github.com/droope/droopescan.git
cd droopescan
pip install -r requirements.txt
___________________________
@hacking_Attack
@Hacking_Video
Supported CMS are: SilverStripe Wordpress Drupal Partial functionality for: Joomla (version enumeration (https://www.kitploit.com/search/label/Enumeration) and interesting URLs only) Moodle (plugin & theme very limited, watch out) computer:~/droopescan$ droopescan scan drupal -u http://example.org/ -t 32
[+] No themes found.
[+] Possible interesting urls found:
Default changelog file - https://www.example.org/CHANGELOG.txt
Default admin - https://www.example.org/user/login
[+] Possible version(s):
7.34
[+] Plugins found:
views https://www.example.org/sites/all/modules/views/
https://www.example.org/sites/all/modules/views/README.txt
https://www.example.org/sites/all/modules/views/LICENSE.txt
token https://www.example.org/sites/all/modules/token/
https://www.example.org/sites/all/modules/token/README.txt
https://www.example.org/sites/all/modules/token/LICENSE.txt
pathauto https://www.example.org/sites/all/modules/pathauto/
https://www.example.org/sites/all/modules/pathauto/README.txt
https://www.example.org/s ites/all/modules/pathauto/LICENSE.txt
https://www.example.org/sites/all/modules/pathauto/API.txt
libraries https://www.example.org/sites/all/modules/libraries/
https://www.example.org/sites/all/modules/libraries/CHANGELOG.txt
https://www.example.org/sites/all/modules/libraries/README.txt
https://www.example.org/sites/all/modules/libraries/LICENSE.txt
entity https://www.example.org/sites/all/modules/entity/
https://www.example.org/sites/all/modules/entity/README.txt
https://www.example.org/sites/all/modules/entity/LICENSE.txt
google_analytics https://www.example.org/sites/all/modules/google_analytics/
https://www.example.org/sites/all/modules/google_analytics/README.txt
https://www.example.org/sites/all/modules/google_analytics/LICENSE.txt
ctools https://www.example.org/sites/all/modules/ctools/
https://www.example.org/sites/all/modules/ctools/CH ANGELOG.txt
https://www.example.org/sites/all/modules/ctools/LICENSE.txt
https://www.example.org/sites/all/modules/ctools/API.txt
features https://www.example.org/sites/all/modules/features/
https://www.example.org/sites/all/modules/features/CHANGELOG.txt
https://www.example.org/sites/all/modules/features/README.txt
https://www.example.org/sites/all/modules/features/LICENSE.txt
https://www.example.org/sites/all/modules/features/API.txt
[... snip for README ...]
[+] Scan finished (0:04:59.502427 elapsed)
You can get a full list of options by running: droopescan --help
droopescan scan --help Why not X? Because droopescan: is fast is stable is up to date allows simultaneous scanning of multiple sites is 100% python Installation With pip (recommended) Installation is easy using pip: apt-get install python-pip
pip install droopescan From sources Manual installation is as follows: git clone https://github.com/droope/droopescan.git
cd droopescan
pip install -r requirements.txt
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
./droopescan scan --help The master branch corresponds to the latest release (what is in pypi). Development branch is unstable and all pull requests must be made against it. BlackArch BlackArch package (https://github.com/BlackArch/blackarch/blob/master/packages/droopescan/PKGBUILD) installation (maintained by a third party): sudo pacman -S droopescan Docker You can build a docker image and run droopescan from Docker: git clone https://github.com/droope/droopescan.git
cd droopescan
docker build -t droope/droopescan .
# display help
docker run --rm droope/droopescan
# example scanning a drupal site
docker run --rm droope/droopescan scan drupal -u https://drupal.example.com Features Scan types Droopescan aims to be the most accurate by default, while not overloading the target server due to excessive concurrent requests. Due to this, by default, a large number of requests will be made with four threads; change these settings by using the --number and --threads arguments respectively. This tool is able to perform four kinds of tests. By default all tests are ran, but you can specify one of the following with the -e or --enumerate flag: p -- Plugin checks: Performs several thousand HTTP requests and returns a listing of all plugins found to be installed in the target host. t -- Theme checks: As above, but for themes. v -- Version checks: Downloads several files and, based on the checksums of these files, returns a list of all possible versions. i -- Interesting url checks: Checks for interesting urls (admin panels, readme files, etc.) Target specification You can specify a particular host to scan by passing the -u or --url parameter: droopescan scan drupal -u example.org
You can also omit the drupal argument. This will trigger “CMS identification”, like so: droopescan scan -u example.org
Multiple URLs may be scanned utilising the -U or --url-file parameter. This parameter should be set to the path of a file which contains a list of URLs. droopescan scan drupal -U list_of_urls.txt
The drupal parameter may also be ommited in this example. For each site, it will make several GET requests in order to perform CMS identification, and if the site is deemed to be a supported CMS, it is scanned and added to the output list. This can be useful, for example, to run droopescan across all your organisation's sites. droopescan scan -U list_of_urls.txt
The code block below contains an example list of URLs, one per line: http://localhost/drupal/6.0/
http://localhost/drupal/6.1/
http://localhost/drupal/6.10/
http://localhost/drupal/6.11/
http://localhost/drupal/6.12/
A file containing URLs and a value to override the default host header with separated by tabs or spaces is also OK for URL files. This can be handy when conducting a scan through a large range of hosts and you want to prevent unnecessary DNS queries. To clarify, an example below: 192.168.1.1 example.org
http://192.168.1.1/ example.org
http://192.168.1.2/drupal/ example.org
It is quite tempting to test whether the scanner works for a particular CMS by scanning the official site (e.g. wordpress.org for wordpress), but the official sites rarely run vainilla installations of their respective CMS or do unorthodox things. For example, wordpress.org runs the bleeding edge version of wordpress, which will not be identified as wordpress (https://www.kitploit.com/search/label/WordPress) by droopescan at all because the checksums do not match any known wordpress version. Authentication The application fully supports .netrc files and http_proxy environment variables. Use a .netrc file for basic authentication. An example netrc (https://www.gnu.org/software/inetutils/manual/html_node/The-_002enetrc-file.html) (a file named .netrc placed in your root home directory) file could look as follows: machine secret.google.com
login admin@google.com
password Winter01
___________________________
@hacking_Attack
@Hacking_Video
cd droopescan
docker build -t droope/droopescan .
# display help
docker run --rm droope/droopescan
# example scanning a drupal site
docker run --rm droope/droopescan scan drupal -u https://drupal.example.com Features Scan types Droopescan aims to be the most accurate by default, while not overloading the target server due to excessive concurrent requests. Due to this, by default, a large number of requests will be made with four threads; change these settings by using the --number and --threads arguments respectively. This tool is able to perform four kinds of tests. By default all tests are ran, but you can specify one of the following with the -e or --enumerate flag: p -- Plugin checks: Performs several thousand HTTP requests and returns a listing of all plugins found to be installed in the target host. t -- Theme checks: As above, but for themes. v -- Version checks: Downloads several files and, based on the checksums of these files, returns a list of all possible versions. i -- Interesting url checks: Checks for interesting urls (admin panels, readme files, etc.) Target specification You can specify a particular host to scan by passing the -u or --url parameter: droopescan scan drupal -u example.org
You can also omit the drupal argument. This will trigger “CMS identification”, like so: droopescan scan -u example.org
Multiple URLs may be scanned utilising the -U or --url-file parameter. This parameter should be set to the path of a file which contains a list of URLs. droopescan scan drupal -U list_of_urls.txt
The drupal parameter may also be ommited in this example. For each site, it will make several GET requests in order to perform CMS identification, and if the site is deemed to be a supported CMS, it is scanned and added to the output list. This can be useful, for example, to run droopescan across all your organisation's sites. droopescan scan -U list_of_urls.txt
The code block below contains an example list of URLs, one per line: http://localhost/drupal/6.0/
http://localhost/drupal/6.1/
http://localhost/drupal/6.10/
http://localhost/drupal/6.11/
http://localhost/drupal/6.12/
A file containing URLs and a value to override the default host header with separated by tabs or spaces is also OK for URL files. This can be handy when conducting a scan through a large range of hosts and you want to prevent unnecessary DNS queries. To clarify, an example below: 192.168.1.1 example.org
http://192.168.1.1/ example.org
http://192.168.1.2/drupal/ example.org
It is quite tempting to test whether the scanner works for a particular CMS by scanning the official site (e.g. wordpress.org for wordpress), but the official sites rarely run vainilla installations of their respective CMS or do unorthodox things. For example, wordpress.org runs the bleeding edge version of wordpress, which will not be identified as wordpress (https://www.kitploit.com/search/label/WordPress) by droopescan at all because the checksums do not match any known wordpress version. Authentication The application fully supports .netrc files and http_proxy environment variables. Use a .netrc file for basic authentication. An example netrc (https://www.gnu.org/software/inetutils/manual/html_node/The-_002enetrc-file.html) (a file named .netrc placed in your root home directory) file could look as follows: machine secret.google.com
login admin@google.com
password Winter01
___________________________
@hacking_Attack
@Hacking_Video
GitHub
blackarch/PKGBUILD at master · BlackArch/blackarch
An ArchLinux based distribution for penetration testers and security researchers. - blackarch/PKGBUILD at master · BlackArch/blackarch
You can set the http_proxy and https_proxy variables. These allow you to set a parent HTTP proxy, in which you can handle more complex types of authentication (e.g. Fiddler, ZAP, Burp) export http_proxy='user:password@localhost:8080'
export https_proxy='user:password@localhost:8080'
droopescan scan drupal --url http://localhost/drupal
WARNING: By design, to allow intercepting proxies and the testing of applications with bad SSL, droopescan allows self-signed or otherwise invalid certificates. ˙ ͜ʟ˙ Output This application supports both "standard output", meant for human consumption, or JSON, which is more suitable for machine consumption. This output is stable between major versions. This can be controlled with the --output flag. Some sample JSON output would look as follows (minus the excessive whitespace): {
"themes": {
"is_empty": true,
"finds": [
]
},
"interesting urls": {
"is_empty": false,
"finds": [
{
"url": "https:\/\/www.drupal.org\/CHANGELOG.txt",
"description": "Default changelog file."
},
{
"url": "https:\/\/www.drupal.org\/user\/login",
"description": "Default admin."
}
]
},
"version": {
"is_empty": false,
"finds": [
"7.29",
"7.30",
"7.31"
]
},
"plugins": {
"is_empty": false,
"finds": [
{
"url": "https:\/\/www.drupal.org\/sites\/all\/modules\/views\/",
"name": "views"
},
[...snip...]
]
}
}
Some attributes might be missing from the JSON object if parts of the scan are not ran. This is how multi-site output looks like; each line contains a valid JSON object as shown above. $ droopescan scan drupal -U six_and_above.txt -e v
{"host": "http://localhost/drupal-7.6/", "version": {"is_empty": false, "finds": ["7.6"]}}
{"host": "http://localhost/drupal-7.7/", "version": {"is_empty": false, "finds": ["7.7"]}}
{"host": "http://localhost/drupal-7.8/", "version": {"is_empty": false, "finds": ["7.8"]}}
{"host": "http://localhost/drupal-7.9/", "version": {"is_empty": false, "finds": ["7.9"]}}
{"host": "http://localhost/drupal-7.10/", "version": {"is_empty": false, "finds": ["7.10"]}}
{"host": "http://localhost/drupal-7.11/", "version": {"is_empty": false, "finds": ["7.11"]}}
{"host": "http://localhost/drupal-7.12/", "version": {"is_empty": false, "finds": ["7.12"]}}
{"host": "http://localhost/drupal-7.13/", "version": {"is_empty": false, "finds": ["7.13"]}}
{"host": "http://localhost /drupal-7.14/", "version": {"is_empty": false, "finds": ["7.14"]}}
{"host": "http://localhost/drupal-7.15/", "version": {"is_empty": false, "finds": ["7.15"]}}
{"host": "http://localhost/drupal-7.16/", "version": {"is_empty": false, "finds": ["7.16"]}}
{"host": "http://localhost/drupal-7.17/", "version": {"is_empty": false, "finds": ["7.17"]}}
{"host": "http://localhost/drupal-7.18/", "version": {"is_empty": false, "finds": ["7.18"]}}
{"host": "http://localhost/drupal-7.19/", "version": {"is_empty": false, "finds": ["7.19"]}}
{"host": "http://localhost/drupal-7.20/", "version": {"is_empty": false, "finds": ["7.20"]}}
{"host": "http://localhost/drupal-7.21/", "version": {"is_empty": false, "finds": ["7.21"]}}
{"host": "http://localhost/drupal-7.22/", "version": {"is_empty": false, "finds": ["7.22"]}}
{"host": "http://localhost/drupal-7.23/", "version": {"is_empty": false, "finds": ["7.23"]}}
{"host": "htt p://localhost/drupal-7.24/", "version": {"is_empty": false, "finds": ["7.24"]}}
{"host": "http://localhost/drupal-7.25/", "version": {"is_empty": false, "finds": ["7.25"]}}
{"host": "http://localhost/drupal-7.26/", "version": {"is_empty": false, "finds": ["7.26"]}}
{"host": "http://localhost/drupal-7.27/", "version": {"is_empty": false, "finds": ["7.27"]}}
{"host": "http://localhost/drupal-7.28/", "version": {"is_empty": false, "finds": ["7.28"]}}
___________________________
@hacking_Attack
@Hacking_Video
export https_proxy='user:password@localhost:8080'
droopescan scan drupal --url http://localhost/drupal
WARNING: By design, to allow intercepting proxies and the testing of applications with bad SSL, droopescan allows self-signed or otherwise invalid certificates. ˙ ͜ʟ˙ Output This application supports both "standard output", meant for human consumption, or JSON, which is more suitable for machine consumption. This output is stable between major versions. This can be controlled with the --output flag. Some sample JSON output would look as follows (minus the excessive whitespace): {
"themes": {
"is_empty": true,
"finds": [
]
},
"interesting urls": {
"is_empty": false,
"finds": [
{
"url": "https:\/\/www.drupal.org\/CHANGELOG.txt",
"description": "Default changelog file."
},
{
"url": "https:\/\/www.drupal.org\/user\/login",
"description": "Default admin."
}
]
},
"version": {
"is_empty": false,
"finds": [
"7.29",
"7.30",
"7.31"
]
},
"plugins": {
"is_empty": false,
"finds": [
{
"url": "https:\/\/www.drupal.org\/sites\/all\/modules\/views\/",
"name": "views"
},
[...snip...]
]
}
}
Some attributes might be missing from the JSON object if parts of the scan are not ran. This is how multi-site output looks like; each line contains a valid JSON object as shown above. $ droopescan scan drupal -U six_and_above.txt -e v
{"host": "http://localhost/drupal-7.6/", "version": {"is_empty": false, "finds": ["7.6"]}}
{"host": "http://localhost/drupal-7.7/", "version": {"is_empty": false, "finds": ["7.7"]}}
{"host": "http://localhost/drupal-7.8/", "version": {"is_empty": false, "finds": ["7.8"]}}
{"host": "http://localhost/drupal-7.9/", "version": {"is_empty": false, "finds": ["7.9"]}}
{"host": "http://localhost/drupal-7.10/", "version": {"is_empty": false, "finds": ["7.10"]}}
{"host": "http://localhost/drupal-7.11/", "version": {"is_empty": false, "finds": ["7.11"]}}
{"host": "http://localhost/drupal-7.12/", "version": {"is_empty": false, "finds": ["7.12"]}}
{"host": "http://localhost/drupal-7.13/", "version": {"is_empty": false, "finds": ["7.13"]}}
{"host": "http://localhost /drupal-7.14/", "version": {"is_empty": false, "finds": ["7.14"]}}
{"host": "http://localhost/drupal-7.15/", "version": {"is_empty": false, "finds": ["7.15"]}}
{"host": "http://localhost/drupal-7.16/", "version": {"is_empty": false, "finds": ["7.16"]}}
{"host": "http://localhost/drupal-7.17/", "version": {"is_empty": false, "finds": ["7.17"]}}
{"host": "http://localhost/drupal-7.18/", "version": {"is_empty": false, "finds": ["7.18"]}}
{"host": "http://localhost/drupal-7.19/", "version": {"is_empty": false, "finds": ["7.19"]}}
{"host": "http://localhost/drupal-7.20/", "version": {"is_empty": false, "finds": ["7.20"]}}
{"host": "http://localhost/drupal-7.21/", "version": {"is_empty": false, "finds": ["7.21"]}}
{"host": "http://localhost/drupal-7.22/", "version": {"is_empty": false, "finds": ["7.22"]}}
{"host": "http://localhost/drupal-7.23/", "version": {"is_empty": false, "finds": ["7.23"]}}
{"host": "htt p://localhost/drupal-7.24/", "version": {"is_empty": false, "finds": ["7.24"]}}
{"host": "http://localhost/drupal-7.25/", "version": {"is_empty": false, "finds": ["7.25"]}}
{"host": "http://localhost/drupal-7.26/", "version": {"is_empty": false, "finds": ["7.26"]}}
{"host": "http://localhost/drupal-7.27/", "version": {"is_empty": false, "finds": ["7.27"]}}
{"host": "http://localhost/drupal-7.28/", "version": {"is_empty": false, "finds": ["7.28"]}}
___________________________
@hacking_Attack
@Hacking_Video