Hacking on Medium
Investigating DLL logs with Python
https://cdn-images-1.medium.com/max/800/0*OpWTu1q9TLvGOeSG.jpg
Dynamic Link Libraries (aka DLL) are code snippets in files that make up programs on your Windows computer.
Continue reading on Python in Plain English »
___________________________
@hacking_Attack
@Hacking_Video
Investigating DLL logs with Python
https://cdn-images-1.medium.com/max/800/0*OpWTu1q9TLvGOeSG.jpg
Dynamic Link Libraries (aka DLL) are code snippets in files that make up programs on your Windows computer.
Continue reading on Python in Plain English »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Investigating DLL logs with Python
Dynamic Link Libraries (aka DLL) are code snippets in files that make up programs on your Windows computer. They help maintain organization…
Hacking on Medium
Relevant — THM Walkthrough
https://cdn-images-1.medium.com/max/1457/1*6g9hWzhwbCDhqmInrRUVXA.png
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Relevant — THM Walkthrough
https://cdn-images-1.medium.com/max/1457/1*6g9hWzhwbCDhqmInrRUVXA.png
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Relevant — THM Walkthrough
Introduction
Hacking on Medium
HTB: Conceal Writeup w/o Metasploit
https://cdn-images-1.medium.com/max/600/0*9jLiGwTSSt8ztMWS.png
Introduction
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
HTB: Conceal Writeup w/o Metasploit
https://cdn-images-1.medium.com/max/600/0*9jLiGwTSSt8ztMWS.png
Introduction
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Medium
HTB: Conceal Writeup w/o Metasploit
Introduction
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Read it and weep, my children. -Pad
https://external-preview.redd.it/UvA0EauPA6wspB9rKrrMxSBl3kwLS1-38rudwF2GQwk.jpg?width=108&crop=smart&auto=webp&s=8d8f3fc2becc6c542519e096f66c27d8e903f054 submitted by /u/endless
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Read it and weep, my children. -Pad
https://external-preview.redd.it/UvA0EauPA6wspB9rKrrMxSBl3kwLS1-38rudwF2GQwk.jpg?width=108&crop=smart&auto=webp&s=8d8f3fc2becc6c542519e096f66c27d8e903f054 submitted by /u/endless
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Read it and weep, my children. -Pad
Posted in r/hacking by u/endless • 1 point and 0 comments
hacking: security in practice
what can somebody actually do with an ip address?
i keep seeing very conflicting stuff regarding this
some people are like "If somebody has your ip they can connect to your network!! they can hack you and install malware!!! find where you live! They could steal ALL your info and ruin your life!!!!11!1!"
and others say "they could find your internet provider and city, thats basically it"
and some say "lol literally nothing"
so im honestly kinda really confused, what can somebody actually do with an ip?
submitted by /u/fumosquared
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
what can somebody actually do with an ip address?
i keep seeing very conflicting stuff regarding this
some people are like "If somebody has your ip they can connect to your network!! they can hack you and install malware!!! find where you live! They could steal ALL your info and ruin your life!!!!11!1!"
and others say "they could find your internet provider and city, thats basically it"
and some say "lol literally nothing"
so im honestly kinda really confused, what can somebody actually do with an ip?
submitted by /u/fumosquared
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
Hacking on Medium
How to Secure Your WordPress
There are a variety of ways to secure your WordPress site, from using strong passwords and security plugins to adding extra layers of…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to Secure Your WordPress
There are a variety of ways to secure your WordPress site, from using strong passwords and security plugins to adding extra layers of…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to Secure Your WordPress
There are a variety of ways to secure your WordPress site, from using strong passwords and security plugins to adding extra layers of…
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Reverse engineered the Bookman3 CD-key scheme and published a post on the technical process. Check it out! 🔓💿🖥️
https://external-preview.redd.it/qI1Ga7E1Ot6sb3S5x21PQp48YUKHQfZ194JWL5GYIIw.jpg?width=640&crop=smart&auto=webp&s=2a5ff514351b3708ae7b4ac70dd5b121358ad8fd submitted by /u/jsyang
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reverse engineered the Bookman3 CD-key scheme and published a post on the technical process. Check it out! 🔓💿🖥️
https://external-preview.redd.it/qI1Ga7E1Ot6sb3S5x21PQp48YUKHQfZ194JWL5GYIIw.jpg?width=640&crop=smart&auto=webp&s=2a5ff514351b3708ae7b4ac70dd5b121358ad8fd submitted by /u/jsyang
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Reverse engineered the Bookman3 CD-key scheme and published a post...
Posted in r/hacking by u/jsyang • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
An old tool I made, but never shared here and just recently updated...
A while back I wrote a wifi brute-forcer at https://github.com/flancast90/wifi-bf, but I realized I never shared here. I would love some feedback on it, and maybe it can help some other beginner n00bs (like me) learn some basics.
It's all open-source and has a few contributors so far, but more are appreciated! Feel free to take a look at the code, too (not only because of the nice header for the tool, but also to make sure I'm not installing malware on your computer lol)
submitted by /u/Muted_Original
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
An old tool I made, but never shared here and just recently updated...
A while back I wrote a wifi brute-forcer at https://github.com/flancast90/wifi-bf, but I realized I never shared here. I would love some feedback on it, and maybe it can help some other beginner n00bs (like me) learn some basics.
It's all open-source and has a few contributors so far, but more are appreciated! Feel free to take a look at the code, too (not only because of the nice header for the tool, but also to make sure I'm not installing malware on your computer lol)
submitted by /u/Muted_Original
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
An old tool I made, but never shared here and just recently updated...
A while back I wrote a wifi brute-forcer at [https://github.com/flancast90/wifi-bf](https://github.com/flancast90/wifi-bf), but I realized I never...
Hacking on Medium
[THM] Dav Writeup
https://cdn-images-1.medium.com/max/778/1*54y7tEExRsDPFX9PUQQ1aA.png
Dav is an easy machine in TryHackMe in which we’ll use basic enumeration, learn more about WebDAV and how to explore it to gain access to…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
[THM] Dav Writeup
https://cdn-images-1.medium.com/max/778/1*54y7tEExRsDPFX9PUQQ1aA.png
Dav is an easy machine in TryHackMe in which we’ll use basic enumeration, learn more about WebDAV and how to explore it to gain access to…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
[THM] Dav Writeup
Dav is an easy machine in TryHackMe in which we’ll use basic enumeration, learn more about WebDAV and how to explore it to gain access to…
Hacking on Medium
Plotted-TMS
https://cdn-images-1.medium.com/max/778/1*t39LcMGA45DUtbhxEHrsqA.png
A beginner-friendly CTF hosted on Tryhackme.com Created by
sa.infinity8888. Gole of this machine is boot to root, get user flag and root…
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Plotted-TMS
https://cdn-images-1.medium.com/max/778/1*t39LcMGA45DUtbhxEHrsqA.png
A beginner-friendly CTF hosted on Tryhackme.com Created by
sa.infinity8888. Gole of this machine is boot to root, get user flag and root…
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Plotted-TMS
A beginner-friendly CTF hosted on Tryhackme.com Created by sa.infinity8888. Gole of this machine is boot to root, get user flag and root…
BugBounty: Algolia key disclosure vulnerability
https://medium.com/@Hacker_Yogi/bugbounty-algolia-key-disclosure-vulnerability-be18a1cb3535?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@Hacker_Yogi/bugbounty-algolia-key-disclosure-vulnerability-be18a1cb3535?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
BugBounty: Algolia key disclosure vulnerability
What is Algolia?
What is Algolia?Continue reading on Medium » (https://medium.com/@Hacker_Yogi/bugbounty-algolia-key-disclosure-vulnerability-be18a1cb3535?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
BugBounty: Algolia key disclosure vulnerability
What is Algolia?
BugBounty: Algolia key disclosure vulnerability
What is Algolia?Continue reading on Medium »
Read more...
What is Algolia?Continue reading on Medium »
Read more...
SSRFire - An Automated SSRF Finder. Just Give The Domain Name And Your Server And Chill! Also Has Options To Find XSS And Open Redirects
http://www.kitploit.com/2022/02/ssrfire-automated-ssrf-finder-just-give.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/02/ssrfire-automated-ssrf-finder-just-give.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
SSRFire - An Automated SSRF Finder. Just Give The Domain Name And Your Server And Chill! Also Has Options To Find XSS And Open…
Syntax ./ssrfire.sh -d domain.com -s yourserver.com -f custom_file.txt -c cookies domain.com ---> The domain for which you want to test yourserver.com ---> Your server which detects SSRF. Eg. Burp collaborator custom_file.txt ---> Optional argument. You give your own custom URLs instead of using gau cookies ---> Optional argument. To send requests as an authenticated user If you don't have burpsuite (https://www.kitploit.com/search/label/Burpsuite) professional, you can use interact sh (https://interact.projectdiscovery.io/) by the awesome projectdiscovery team as your server. Requirements Since this uses GAU, FFUF, qsreplace and OpenRedirex, you need GO and python 3.7+. You need not have the tools installed, as the script setup.sh will install everything. You just need to install python and GO. Even if you have the tools installed I would highly recommend you to install them again so that there no conflicts while setting the paths. If you don't want to install the tools again, paste this code in your .profile in your home directory (https://www.kitploit.com/search/label/Directory) and source .profile them. Also, you have to make a small change in the ssrfire.sh on line 10, where you have to replace source /home/hari/.profile without your .profile path. (Only if you are not installing tools through setup.sh) #Replace /path/to/ with the specific directory where the tool is installed
#If you already have configured paths for any of the tools, replace that code with the below one.
ffuf(){
echo "Usage: ffuf https://www.domain.com/FUZZ payloads.txt"
/path/to/ffuf/./main -u $1 -w $2 -b $3 -c -t 100
}
gau(){
echo "Usage: gau domain.com"
/path/to/gau/./main $1
}
gau_s(){
/path/to/gau/./main --subs $1
}
openredirex(){
echo "Usage: openredirex urls.txt payloads.txt"
python3 /path/to/OpenRedireX/openredirex.py -l $1 -p $2 --keyword FUZZ
}
qsreplace(){
/path/to/qsreplace/./main $1
}
Usage **highly recommended**) ./ssrfire.sh -d domain.com -s yourserver.com">chmod +x setup.sh
./setup.sh (preferably yes for all ---> **highly recommended**)
./ssrfire.sh -d domain.com -s yourserver.com
Finding SSRF Now, gau gets into action by fetching all the URLs of the domain. This may take a lot of time. You can check the output generated till now at output/domain.com/raw_urls.txt Let it run for at least 10-15 minutes, and then if you want to continue, you can. But if you want to test the URLs fetched till now, quit the process. Copy the raw_urls.txt inside of output/domain.com and place it outside the domain.com folder Now run ./ssrfire.sh -d domain.com -s yourserver.com -f /path/to/copied_raw_urls.txt
Select yes when asked whether to delete the existing folder. This will skip the process of GAU fetching URLs. Now all the URLs with parameters will be filtered and yourserver.com will be placed into their parameter values.(final_urls.txt) The next step is to fire requests to all the final URLs. Finding XSS Warning: This generates a lot of traffic. Do not use this against sites which you are not authorized to test This tests all the URLs fetched, and based on how the input is reflected in the response, it adds that particular URL to the output/domain.com/xss-suspects.txt (This may contain false positives) For further testing this, you can input this list to the XSS detection tools like XSStrike to find XSS. Finding open redirects Just enter the path to a payload file or use the default payload. I personally prefer openredirex, as it is specifically designed to check for open redirects by loading the URLs from the list and it looks a lot cleaner, and doesn't flood your terminal. Tools used: GAU - https://github.com/lc/gau ffuf - https://github.com/ffuf/ffuf qspreplace - https://github.com/tomnomnom/qsreplace OpenRedireX - https://github.com/devanshbatham/OpenRedireX Thanks to all the authors of the tools.
___________________________
@hacking_Attack
@Hacking_Video
#If you already have configured paths for any of the tools, replace that code with the below one.
ffuf(){
echo "Usage: ffuf https://www.domain.com/FUZZ payloads.txt"
/path/to/ffuf/./main -u $1 -w $2 -b $3 -c -t 100
}
gau(){
echo "Usage: gau domain.com"
/path/to/gau/./main $1
}
gau_s(){
/path/to/gau/./main --subs $1
}
openredirex(){
echo "Usage: openredirex urls.txt payloads.txt"
python3 /path/to/OpenRedireX/openredirex.py -l $1 -p $2 --keyword FUZZ
}
qsreplace(){
/path/to/qsreplace/./main $1
}
Usage **highly recommended**) ./ssrfire.sh -d domain.com -s yourserver.com">chmod +x setup.sh
./setup.sh (preferably yes for all ---> **highly recommended**)
./ssrfire.sh -d domain.com -s yourserver.com
Finding SSRF Now, gau gets into action by fetching all the URLs of the domain. This may take a lot of time. You can check the output generated till now at output/domain.com/raw_urls.txt Let it run for at least 10-15 minutes, and then if you want to continue, you can. But if you want to test the URLs fetched till now, quit the process. Copy the raw_urls.txt inside of output/domain.com and place it outside the domain.com folder Now run ./ssrfire.sh -d domain.com -s yourserver.com -f /path/to/copied_raw_urls.txt
Select yes when asked whether to delete the existing folder. This will skip the process of GAU fetching URLs. Now all the URLs with parameters will be filtered and yourserver.com will be placed into their parameter values.(final_urls.txt) The next step is to fire requests to all the final URLs. Finding XSS Warning: This generates a lot of traffic. Do not use this against sites which you are not authorized to test This tests all the URLs fetched, and based on how the input is reflected in the response, it adds that particular URL to the output/domain.com/xss-suspects.txt (This may contain false positives) For further testing this, you can input this list to the XSS detection tools like XSStrike to find XSS. Finding open redirects Just enter the path to a payload file or use the default payload. I personally prefer openredirex, as it is specifically designed to check for open redirects by loading the URLs from the list and it looks a lot cleaner, and doesn't flood your terminal. Tools used: GAU - https://github.com/lc/gau ffuf - https://github.com/ffuf/ffuf qspreplace - https://github.com/tomnomnom/qsreplace OpenRedireX - https://github.com/devanshbatham/OpenRedireX Thanks to all the authors of the tools.
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
Download SSRFire (https://github.com/ksharinarayanan/SSRFire)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - ksharinarayanan/SSRFire: An automated SSRF finder. Just give the domain name and your server and chill! ;) Also has options…
An automated SSRF finder. Just give the domain name and your server and chill! ;) Also has options to find XSS and open redirects - ksharinarayanan/SSRFire