Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Onionservice : Manage Your Onion Services Via CLI Or TUI On Unix-like Operating System Onionservice is a minimal requirement, portable collection of scripts and documentation to help the service operator juggle (manage) his onion(s).…
d html header attributes.
* Backup – Better be safe.
* Create – Backup of your torrclines containing hidden service configuration, all of your directories of HiddenServiceDirand ClientOnionAuthDir.
* Integrate – Integrate hidden serivces lines configuration from torrcand the directories HiddenServiceDirand ClientOnionAuthDirto your current system. This option should be used after creating a backup and importing to the current host.

* OpSec – Operation Security
* Vanguards – This addon protects against guard discovery and related traffic analysis attacks. A guard discovery attack enables an adversary to determine the guard node(s) that are in use by a Tor client and/or Tor onion service. Once the guard node is known, traffic analysis attacks that can deanonymize an onion service (or onion service user) become easier.
* Unix socket – Support for enabling an onion service over unix socket to avoid localhost bypasses.

* Web server – Serve files with your hidden service using Nginx or Apache2 web server.
* Usability – There are two dialog boxes compatible with the project, dialogand whiptail.
* Bulk – Some commands can be bulked with the argument @allto include all services or clients depending on the option --serviceor --client, list enabled arguments[SERV1,SERV2,...] and [CLIENT1,CLIENT2,...], the command will loop the variables and apply the combination.
* Fool-proof – The script tries its best to filter invalid commands and incorrect syntax. The commands are not difficult but at first sight may scare you. Don’t worry, if it is invalid, it won’t run to avoid tor daemon failing to reload because of invalid configuration. If an invalid command runs, please open an issue. Requirements

* General:
* Unix-like system.
* superuser privileges to call commands as root and the tor user, with doasor sudo.

* Required programs:
* sh – any POSIX shell: dash0.5.4+, bash2.03+, ksh88+, mkshR28+, yash2.29+, busybox ash1.1.3+, zsh3.1.9+ (zsh --emulate sh) etc.
* doas/sudo (must be already configured)
* tor >= 0.3.5.7
* grep >=0.9
* sed
* tar (Backup)
* openssl >= 1.1 (Client Authorization – requires algorithm x25519, so it can’t be LibreSSL)
* basez >= 1.6.2 (Client Authorization)
* git (Vanguards)
* python(3)-stem >=1.8.0 (Vanguards)
* dialog/whiptail (TUI)
* nginx/apache2 (Web server)

* Optional programs:
* (lib)qrencode >= 4.1.1 (List)

* Development programs:
* pandoc (Manual)
* shellcheck (Review)
If using Vanguards, python2.6is the minimal required for Stem, but it is not going to be installed by default. Instructions Clone the repository

git clone https://github.com/nyxnor/onionjuggler.git
cd onionjuggler

et custom variables

You should not modify the default configuration on /etc/onionjuggler/onionjuggler.conf, it will be modified on every update. Your local configurations should be on /etc/onionjuggler/conf.d/*.conf.

To assign values to the variables, yyou can either:

* Open the mentioned configuration file with your favorite editor:
* “${EDITOR:-vi}” /etc/onionjuggler/cond.d/local.conf

or insert configuration to the end of the file with tee:

printf “su_cmd=\”sudo\”\n” | tee -a /etc/onionjuggler/cond.d/local.conf

or edit with sed:

sed -i” “s|^su_cmd=.*|su_cmd=\”doas\”|” /etc/onionjuggler/cond.d/local.conf

Setup the enviroment

Run from inside the cloned repository to create the tor directories, create manual pages and copy scripts to path:

./configure.sh –install

Usage configure.sh

configure.sh setup the environment for OnionJuggler by adding the scripts and manual pages to path and detecting your operating system[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
SourceLeakHacker : A Multi Threads Web Application Source Leak Scanner

SourceLeakHacker is a multi-threads web directories scanner.

Installation

pip install -r requirements.txt

Usage

usage: SourceLeakHacker.py [options]
optional arguments:
-h, –help show this help message and exit
–url URL url to scan, eg: ‘http://127.0.0.1/
–urls URLS file contains urls to scan, one line one url.
–scale {full,tiny} build-in dictionary scale
–output OUTPUT output folder, default: result/YYYY-MM-DD hh:mm:ss
–threads THREADS, -t THREADS
threads numbers, default: 4
–timeout TIMEOUT HTTP request timeout
–level {CRITICAL,ERROR,WARNING,INFO,DEBUG}, -v {CRITICAL,ERROR,WARNING,INFO,DEBUG}
log level
–version, -V show program’s version number and exit

Example

$ python SourceLeakHacker.py –url=http://baidu.com –threads=4 –timeout=8
[302] 0 3.035766 text/html; charset=iso-8859-1 http://baidu.com//_index.php [302] 0 3.038096 text/html; charset=iso-8859-1 http://baidu.com//__index.php.bak

[302] 0 0.063973 text/html; charset=iso-8859-1 http://baidu.com/_adm/_index.php
[302] 0 0.081672 text/html; charset=iso-8859-1 http://baidu.com/_adm/_index.php.bak
Result save in file: result/2020-02-27 07:07:47.csv

$ cat url.txt
http://baidu.com/
http://google.com/
$ python SourceLeakHacker.py –urls=url.txt –threads=4 –timeout=8
[302] 0 2.363600 text/html; charset=iso-8859-1 http://baidu.com/_/__index.php.bak
[302] 0 0.098417 text/html; charset=iso-8859-1 http://baidu.com/_adm/__index.php.bak

[302] 0 0.060524 text/html; charset=iso-8859-1 http://google.com/_adm/_index.php.bak
[302] 0 0.075042 text/html; charset=iso-8859-1 http://baidu.com/_adm/_index.php.back
Result save in file: result/2020-02-27 07:08:54.csv

Demo
https://blogger.googleusercontent.com/img/a/AVvXsEhd9xHc3iuYnE1gfp8QwWl9F8gFnpDETTJm9ltw3UBMC2xhr_PG7GzI1BMDbQSZ72Xklxb5E51hDo9tKN-PHNqBVhhgMfdL4gITWgMPJESc9NRinMSaqHf28zB-g9vgLLSfcqOav3J1rX5CmYOmNOvmVFE8z8EAOFwjcqo9eLMohWdBYAdzExpE38Jc=s1741 https://blogger.googleusercontent.com/img/a/AVvXsEhqm6-NIazQ2rb8KTLT9fq7rsy4g5yBpNNwpqnAPTGjzjWKbECA8tQPbHgyASOOmkniqHYHynU_bLFLYKUTAgnA8kTzrh-vYpsJfJUekJZCVM4g70VUCUbaxdRwKkteR3bz_KZyRzpSxwS8hoHwOrKOxSp_3K2Px12gtvbSpobFtEArkQM_JxWvosiA=s1685 https://blogger.googleusercontent.com/img/a/AVvXsEhh_Zsonh3HGuWx6QfCtI6lB56OwfNpvbBxEnjc7OtudMUMUOVy40WsyQiPKyj301GjZuHkfA7JrWCOS3r9Z3kUWEccdNXqPP7vECsssqMqTpRYpk-QVU9v6IQhfAukanU2Kqu6Rbyavd1X4tQX71C1uZoXanb4JYwl5sr8za6qnGdZzMNHWyUXcN2Q=s1669

Download

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
d html header attributes. * Backup – Better be safe. * Create – Backup of your torrclines containing hidden service configuration, all of your directories of HiddenServiceDirand ClientOnionAuthDir. * Integrate – Integrate hidden serivces lines configuration…
to fit with its default configuration. It can also be used to uninstall. Common development use is to create manual pages, check shell syntax and do all of the aforementioned and give the git status for files to be commited. The update option is raw and only recommended for development as of now.

Install

configure.sh –install ## -i

Uninstall

configure.sh –uninstall ## -d

Update

configure.sh –update ## -u

tui

onionjuggler-tui wraps the CLI in a Terminal User Interface. Some TUI options will let you edit the authorization files, which is recommended to set your favorite text editor to an environment variable that will be tried on the following order: DOAS_EDITOR/SUDO_EDITOR, if empty will try VISUAL, if empty will try EDITOR, if empty WILL fallback to Vi.

Read the tui manual

man onionjuggler-tui

To use the TUI, just run:

onionjuggler-tui

cli

onionjuggler-cli is the main script that manages the HiddenServices. Take a look at the documentation inside docsfolder, there are many other onion services management guides. Read:

Don’t forget the cli manual and the conf manual for advanced usage:

man onionjuggler-cli
man onionjuggler.conf

To create a service named terminator, it is as easy as possible:

onionjuggler-cli activate -s terminator -p 80

But can be as advanced as specifying all the parameters:

onionjuggler-cli activate –service terminator –socket unix –version 3 –port 80,127.0.0.1:80 Download

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Ransomware Trained on Manufacturing Firms Led Cyberattacks in Industrial Sector

Meanwhile, a few "alarming" infiltrations of OT networks by previously unknown threat groups occurred last year as well.
Dark Reading: Attacks/Breaches
Why Passwordless Is at an Impasse

Many widely used business applications aren't built to support passwordless login because identity and authentication remain siloed.
Dark Reading: Attacks/Breaches
Microsoft Debuts Unified Service for Multicloud ID Management

With nine in 10 companies adopting a multicloud strategy, service providers are focused on finding ways to support the management and security efforts of businesses that rely on multiple cloud resources.