hacking: security in practice
Simple HTML DoS Script for Russian Sites
___________________________
@hacking_Attack
@Hacking_Video
Simple HTML DoS Script for Russian Sites
___________________________
@hacking_Attack
@Hacking_Video
Reddit
Simple HTML DoS Script for Russian Sites : r/hacking
2.2K votes, 362 comments. 2.7M subscribers in the hacking community. A subreddit dedicated to hacking and hackers. Constructive collaboration and…
hacking: security in practice
Support DDOS against russian propoganda websites. Use at your own risk
Someone asked about this recently. Use at your own risk.
Support the DDOS attacks on Russian propaganda websites. All you need to do:
- Open incognito tab in your browser
- Copy this URL: https://stop-russian-desinformation.near.page/
- Leave it open for the time that you can.
Every little step helps!
Page source code: https://pastebin.com/TS90FsFx
Page source code explained:
Requests are sent to the group page using your browser. It's basically the same as printing F5 a lot together. The goal is that the page doesn't load and shuts down. The code does not look malicious to its user, it simply uses computer resources to perform queries, the average user will not even feel it, and the effect on the pages is serious.
Targeted pages:
lenta[.]ru
ria[.]ru
rbc[.]ru
rt[.]com
kremlin[.]ru
smotrim[.]ru
tass[.]ru
tvzvezda[.]ru
vsoloviev[.]ru
1tv[.]ru
vesti[.]ru
sberbank[.]ru
submitted by /u/hypocrite1337
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Support DDOS against russian propoganda websites. Use at your own risk
Someone asked about this recently. Use at your own risk.
Support the DDOS attacks on Russian propaganda websites. All you need to do:
- Open incognito tab in your browser
- Copy this URL: https://stop-russian-desinformation.near.page/
- Leave it open for the time that you can.
Every little step helps!
Page source code: https://pastebin.com/TS90FsFx
Page source code explained:
Requests are sent to the group page using your browser. It's basically the same as printing F5 a lot together. The goal is that the page doesn't load and shuts down. The code does not look malicious to its user, it simply uses computer resources to perform queries, the average user will not even feel it, and the effect on the pages is serious.
Targeted pages:
lenta[.]ru
ria[.]ru
rbc[.]ru
rt[.]com
kremlin[.]ru
smotrim[.]ru
tass[.]ru
tvzvezda[.]ru
vsoloviev[.]ru
1tv[.]ru
vesti[.]ru
sberbank[.]ru
submitted by /u/hypocrite1337
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
reddit.com: over 18?
Reddit gives you the best of the internet in one place. Get a constantly updating feed of breaking news, fun stories, pics, memes, and videos just for you. Passionate about something niche? Reddit has thousands of vibrant communities with people that share…
Readteam-tool: Simple and secure web deployment for pentest and redteam with simwigo
https://www.reddit.com/r/redteamsec/comments/t1c13x/readteamtool_simple_and_secure_web_deployment_for/
Simwigo (https://github.com/8iche/simwigo/) is a cross-plateform tool, written in Go, that allows you to quickly deploy a secure web service (with a nice and neat display:)). It was created to replace the use of tools such as SimpleHTTPServer and http.server from python. It implements additional features allowing easy file exchange. It can be used for a pentest or a redteam, as well as for personal use. An API token authentication, a white list system, and the use of TLS (automatic deployment via Let's Encrypt (https://letsencrypt.org/)) are integrated and increase the security of the service. Check out the latest release: https://github.com/8iche/simwigo/ submitted by /u/B1che (https://www.reddit.com/user/B1che)
[link] (https://www.reddit.com/r/redteamsec/comments/t1c13x/readteamtool_simple_and_secure_web_deployment_for/) [comments] (https://www.reddit.com/r/redteamsec/comments/t1c13x/readteamtool_simple_and_secure_web_deployment_for/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/t1c13x/readteamtool_simple_and_secure_web_deployment_for/
Simwigo (https://github.com/8iche/simwigo/) is a cross-plateform tool, written in Go, that allows you to quickly deploy a secure web service (with a nice and neat display:)). It was created to replace the use of tools such as SimpleHTTPServer and http.server from python. It implements additional features allowing easy file exchange. It can be used for a pentest or a redteam, as well as for personal use. An API token authentication, a white list system, and the use of TLS (automatic deployment via Let's Encrypt (https://letsencrypt.org/)) are integrated and increase the security of the service. Check out the latest release: https://github.com/8iche/simwigo/ submitted by /u/B1che (https://www.reddit.com/user/B1che)
[link] (https://www.reddit.com/r/redteamsec/comments/t1c13x/readteamtool_simple_and_secure_web_deployment_for/) [comments] (https://www.reddit.com/r/redteamsec/comments/t1c13x/readteamtool_simple_and_secure_web_deployment_for/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Readteam-tool: Simple and secure web deployment for pentest and...
[Simwigo](https://github.com/8iche/simwigo/) is a cross-plateform tool, written in **Go**, that allows you to quickly deploy a secure web service...
Hacking on Medium
5 (MUST READ) Cybersecurity books for 2022!
https://cdn-images-1.medium.com/max/600/1*d7AG0TWuXGPbM7rXRDc5-g.png
What are some cybersecurity books that you should read for 2022? To answer this question, I will be discussing with you 5 (MUST READ)…
Continue reading on CodeX »
___________________________
@hacking_Attack
@Hacking_Video
5 (MUST READ) Cybersecurity books for 2022!
https://cdn-images-1.medium.com/max/600/1*d7AG0TWuXGPbM7rXRDc5-g.png
What are some cybersecurity books that you should read for 2022? To answer this question, I will be discussing with you 5 (MUST READ)…
Continue reading on CodeX »
___________________________
@hacking_Attack
@Hacking_Video
Medium
5 (MUST READ) Cybersecurity books for 2022!
What are some cybersecurity books that you should read for 2022? To answer this question, I will be discussing with you 5 (MUST READ)…
Hacking on Medium
What you can do to improve your cybersecurity strategy now
https://cdn-images-1.medium.com/max/2600/1*gNkD3tc-206IoEWS0GHNGg.jpeg
Current cybersecurity landscape and common threats
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
What you can do to improve your cybersecurity strategy now
https://cdn-images-1.medium.com/max/2600/1*gNkD3tc-206IoEWS0GHNGg.jpeg
Current cybersecurity landscape and common threats
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What You Can Do To Improve Your Cybersecurity Strategy Now
Current cybersecurity landscape and common threats
Hacking on Medium
How to create a Vulnerable Box
https://cdn-images-1.medium.com/max/626/0*JFdXoaTc_dPb9SIg.jpg
With this blog, I will teach you how to make an easy vulnerable box from 0
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to create a Vulnerable Box
https://cdn-images-1.medium.com/max/626/0*JFdXoaTc_dPb9SIg.jpg
With this blog, I will teach you how to make an easy vulnerable box from 0
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to create a Vulnerable Box
With this blog, I will teach you how to make an easy vulnerable box from 0
Hacking on Medium
Less than 24 Hours Left For Infosec Writeups Virtual Cybersecurity Conference
https://cdn-images-1.medium.com/max/1568/1*BP4-ZaSKUUcbsjV8iOWQFA.png
Booked your tickets for IWCON2022 yet?
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Less than 24 Hours Left For Infosec Writeups Virtual Cybersecurity Conference
https://cdn-images-1.medium.com/max/1568/1*BP4-ZaSKUUcbsjV8iOWQFA.png
Booked your tickets for IWCON2022 yet?
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Less than 24 Hours Left For Infosec Writeups Virtual Cybersecurity Conference
Booked your tickets for IWCON2022 yet?
Hacking on Medium
The magic of simplicity
https://cdn-images-1.medium.com/max/648/1*yAzx3jkS_0FUVoUTHwxFWQ.jpeg
Today I listened to Indie Hackers podcast where Justin Jackson, a successful podcaster, tinker/maker, and all around great guy shared how…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
The magic of simplicity
https://cdn-images-1.medium.com/max/648/1*yAzx3jkS_0FUVoUTHwxFWQ.jpeg
Today I listened to Indie Hackers podcast where Justin Jackson, a successful podcaster, tinker/maker, and all around great guy shared how…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
The magic of simplicity
Today I listened to Indie Hackers podcast where Justin Jackson, a successful podcaster, tinker/maker, and all around great guy shared how…
Hacking on Medium
APT de Irán explota Log4Shell en VMware Horizon y vulnerabilid en FortiOS
https://cdn-images-1.medium.com/max/1512/0*7M03LdgKqDi9BDDw
PUBLICADO EN 25 FEBRERO, 2022 POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
APT de Irán explota Log4Shell en VMware Horizon y vulnerabilid en FortiOS
https://cdn-images-1.medium.com/max/1512/0*7M03LdgKqDi9BDDw
PUBLICADO EN 25 FEBRERO, 2022 POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
APT de Irán explota Log4Shell en VMware Horizon y vulnerabilid en FortiOS
PUBLICADO EN 25 FEBRERO, 2022 POR EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
openSquat - Detection Of Phishing Domains And Domain Squatting. Supports Permutations Such As Homograph Attack, Typosquatting And Bitsquatting
http://3.bp.blogspot.com/-U9azAjP77Ok/Yd2Ztzy0E6I/AAAAAAAA8v4/J2M6j6u5GGs2ExnqWyQuohFiO78iR15NQCK4BGAYYCw/w640-h221/opensquat_1_openSquat_logo-759121.png What is openSquatopenSquat is an opensource Intelligence (OSINT) security tool to identify cyber squatting threats to specific companies or domains, such as:
* Phishing campaigns
* Domain squatting
* Typo squatting
* Bitsquatting
* IDN homograph attacks
* Doppenganger domains
* Other brand/domain related scams
It does support some key features such as:
* Automatic newly registered domain updating (once a day)
* Levenshtein distance to calculate word similarity
* Fetches active and known phishing domains (Phishing Database project)
* IDN homograph attack detection
* Integration with VirusTotal
* Integration with Quad9 DNS service
* Use different levels of confidence threshold to fine tune
* Save output into different formats (txt, JSON and CSV)
* Can be integrated with other threat intelligence tools and DNS sinkholes
This is an opensource project so everyone's welcomed to contribute. Screenshot / Video Demohttp://1.bp.blogspot.com/-gW6FJifXP3k/Yd2ZuZ2Y9sI/AAAAAAAA8wA/uHlCwmgDTgs5fJibmHlV7aDy0OzYAu1iQCK4BGAYYCw/w640-h514/opensquat_2_openSquat-760624.png Check the 40 seconds Demo Video (v1.95) Demo / Forks* Phishy Domains for a simple web version of the openSquat.
* openSquat Bot for a simple Telegram bot.
Note: Both forks do not contain all openSquat features. How to Install
certificate transparency (ct) hunt python opensquat.py --ct # Period search - registrations from the last month (default: day) python opensquat.py -p month # Tweak confidence level. The lower values bring more false positives # (0: very high, 1: high (default), 2: medium, 3: low, 4: very low python opensquat.py -c 2 # All validations options python opensquat.py --phishing phishing_domains.txt --dns --ct --subdomains --portcheck ">
* Integratration with[...]
___________________________
@hacking_Attack
@Hacking_Video
openSquat - Detection Of Phishing Domains And Domain Squatting. Supports Permutations Such As Homograph Attack, Typosquatting And Bitsquatting
http://3.bp.blogspot.com/-U9azAjP77Ok/Yd2Ztzy0E6I/AAAAAAAA8v4/J2M6j6u5GGs2ExnqWyQuohFiO78iR15NQCK4BGAYYCw/w640-h221/opensquat_1_openSquat_logo-759121.png What is openSquatopenSquat is an opensource Intelligence (OSINT) security tool to identify cyber squatting threats to specific companies or domains, such as:
* Phishing campaigns
* Domain squatting
* Typo squatting
* Bitsquatting
* IDN homograph attacks
* Doppenganger domains
* Other brand/domain related scams
It does support some key features such as:
* Automatic newly registered domain updating (once a day)
* Levenshtein distance to calculate word similarity
* Fetches active and known phishing domains (Phishing Database project)
* IDN homograph attack detection
* Integration with VirusTotal
* Integration with Quad9 DNS service
* Use different levels of confidence threshold to fine tune
* Save output into different formats (txt, JSON and CSV)
* Can be integrated with other threat intelligence tools and DNS sinkholes
This is an opensource project so everyone's welcomed to contribute. Screenshot / Video Demohttp://1.bp.blogspot.com/-gW6FJifXP3k/Yd2ZuZ2Y9sI/AAAAAAAA8wA/uHlCwmgDTgs5fJibmHlV7aDy0OzYAu1iQCK4BGAYYCw/w640-h514/opensquat_2_openSquat-760624.png Check the 40 seconds Demo Video (v1.95) Demo / Forks* Phishy Domains for a simple web version of the openSquat.
* openSquat Bot for a simple Telegram bot.
Note: Both forks do not contain all openSquat features. How to Install
git clone https://github.com/atenreiro/opensquat
pip install -r requirements.txtMake sure you have Python 3.6+ and pip3 in your environment How to UpdateTo update your current version, just type the following commands inside the openSquat directory: git pull
pip install -r requirements.txtThe "pip install" is just to make sure no new libs were added with the new upgrade. Usage ExamplesEdit the "keywords.txt" with your customised keywords to hunt.certificate transparency (ct) hunt python opensquat.py --ct # Period search - registrations from the last month (default: day) python opensquat.py -p month # Tweak confidence level. The lower values bring more false positives # (0: very high, 1: high (default), 2: medium, 3: low, 4: very low python opensquat.py -c 2 # All validations options python opensquat.py --phishing phishing_domains.txt --dns --ct --subdomains --portcheck ">
# Lazy run with default options
python opensquat.py
# for all the options
python opensquat.py -h
# Search for generic terms used in phishing campaigns (can lead to false positives)
python opensquat.py -k generic.txt
# With DNS validation (quad9)
python opensquat.py --dns
# Subdomain search
python opensquat.py --subdomains
# Check for domains with open ports 80/443
python opensquat.py --portcheck
# With Phishing validation (Phishing Database)
python opensquat.py --phishing phish_results.txt
# Save output as JSON
python opensquat.py -o example.json -t json
# Save output as CSV
python opensquat.py -o example.csv -t csv
# Conduct a certificate transparency (ct) hunt
python opensquat.py --ct
# Period search - registrations from the last month (default: day)
python opensquat.py -p month
# Tweak confidence level. The lower values bring more false positives
# (0: very high, 1: high (default), 2: medium, 3: low, 4: very low
python opensquat.py -c 2
# All validations options
python opensquat.py --phishing phishing_domains.txt --dns --ct --subdomains --portcheck To Do / Roadmap* Integration with VirusTotal (VT) for subdomains validation* Integratration with[...]
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
openSquat - Detection Of Phishing Domains And Domain Squatting. Supports Permutations Such As Homograph Attack, Typosquatting And…
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! openSquat - Detection Of Phishing Domains And Domain Squatting. Supports Permutations Such As Homograph Attack, Typosquatting And Bitsquatting http://3.bp.blogspot.com/-U9azAjP77Ok/Yd2Ztzy0E6I/AAAAAAAA8v4/J2M6j6u5GGs2ExnqWyQuohF…
VirusTotal (VT) for malware detection
* Use certificate transparency
* Homograph detection done
* Improve code quality from B to A grade (codacy)
* PEP8 compliance
* AND logical condition for keywords search (e.g: goole+login) - Thanks to Steff T.
* Add documentation Feature RequestTo request for a new feature, create a "new issue" and describe the feature and potential use cases. If something similar already exists, you can upvote the "issue" and contribute to the discussions. Changelog* Check the CHANGELOG file. AuthorsProject founder
* Andre Tenreiro (LinkedInk)
* andre@cert.mz
Contributors
* Please check the contributors page on GitHub How to helpYou can help this project in many ways:
* Providing your time and coding skills to enhance the project
* Build a decent but simple project webpage
* Provide access to OSINT feeds
* Open new issues with new suggestions, ideas, bug report or feature requests
* Spread this project within your network
* Share your story how have you been using the openSquat and what impact it brought to you
* Make a project logo Download Opensquat
___________________________
@hacking_Attack
@Hacking_Video
* Use certificate transparency
* Homograph detection done
* Improve code quality from B to A grade (codacy)
* PEP8 compliance
* AND logical condition for keywords search (e.g: goole+login) - Thanks to Steff T.
* Add documentation Feature RequestTo request for a new feature, create a "new issue" and describe the feature and potential use cases. If something similar already exists, you can upvote the "issue" and contribute to the discussions. Changelog* Check the CHANGELOG file. AuthorsProject founder
* Andre Tenreiro (LinkedInk)
* andre@cert.mz
Contributors
* Please check the contributors page on GitHub How to helpYou can help this project in many ways:
* Providing your time and coding skills to enhance the project
* Build a decent but simple project webpage
* Provide access to OSINT feeds
* Open new issues with new suggestions, ideas, bug report or feature requests
* Spread this project within your network
* Share your story how have you been using the openSquat and what impact it brought to you
* Make a project logo Download Opensquat
___________________________
@hacking_Attack
@Hacking_Video
Pentest-tool: Simple and secure web deployment for pentest and redteam with simwigo
https://www.reddit.com/r/Pentesting/comments/t1bzvd/pentesttool_simple_and_secure_web_deployment_for/
Simwigo (https://github.com/8iche/simwigo/) is a cross-plateform tool, written in Go, that allows you to quickly deploy a secure web service (with a nice and neat display:)). It was created to replace the use of tools such as SimpleHTTPServer and http.server from python. It implements additional features allowing easy file exchange. It can be used for a pentest or a redteam, as well as for personal use. An API token authentication, a white list system, and the use of TLS (automatic deployment via Let's Encrypt (https://letsencrypt.org/)) are integrated and increase the security of the service. Check out the latest release: https://github.com/8iche/simwigo/ submitted by /u/B1che (https://www.reddit.com/user/B1che)
[link] (https://www.reddit.com/r/Pentesting/comments/t1bzvd/pentesttool_simple_and_secure_web_deployment_for/) [comments] (https://www.reddit.com/r/Pentesting/comments/t1bzvd/pentesttool_simple_and_secure_web_deployment_for/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/t1bzvd/pentesttool_simple_and_secure_web_deployment_for/
Simwigo (https://github.com/8iche/simwigo/) is a cross-plateform tool, written in Go, that allows you to quickly deploy a secure web service (with a nice and neat display:)). It was created to replace the use of tools such as SimpleHTTPServer and http.server from python. It implements additional features allowing easy file exchange. It can be used for a pentest or a redteam, as well as for personal use. An API token authentication, a white list system, and the use of TLS (automatic deployment via Let's Encrypt (https://letsencrypt.org/)) are integrated and increase the security of the service. Check out the latest release: https://github.com/8iche/simwigo/ submitted by /u/B1che (https://www.reddit.com/user/B1che)
[link] (https://www.reddit.com/r/Pentesting/comments/t1bzvd/pentesttool_simple_and_secure_web_deployment_for/) [comments] (https://www.reddit.com/r/Pentesting/comments/t1bzvd/pentesttool_simple_and_secure_web_deployment_for/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Pentest-tool: Simple and secure web deployment for pentest and...
[Simwigo](https://github.com/8iche/simwigo/) is a cross-plateform tool, written in **Go**, that allows you to quickly deploy a secure web service...
openSquat - Detection Of Phishing Domains And Domain Squatting. Supports Permutations Such As Homograph Attack, Typosquatting And Bitsquatting
http://www.kitploit.com/2022/02/opensquat-detection-of-phishing-domains.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/02/opensquat-detection-of-phishing-domains.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
openSquat - Detection Of Phishing Domains And Domain Squatting. Supports Permutations Such As Homograph Attack, Typosquatting And…
What is openSquat openSquat is an opensource Intelligence (https://www.kitploit.com/search/label/Intelligence) (OSINT) security tool to identify cyber squatting threats to specific companies or domains, such as: Phishing campaigns Domain squatting Typo squatting Bitsquatting IDN homograph attacks Doppenganger domains Other brand/domain related scams It does support some key features such as: Automatic newly registered domain updating (once a day) Levenshtein distance to calculate word similarity Fetches active and known phishing domains (Phishing Database project) IDN homograph attack detection Integration with VirusTotal Integration with Quad9 DNS service Use different levels of confidence threshold to fine tune Save output into different formats (txt, JSON and CSV) Can be integrated with other threat intelligence (https://www.kitploit.com/search/label/Threat%20Intelligence) tools and DNS sinkholes This is an opensource project so everyone's welcomed to contribute.
Screenshot / Video Demo
___________________________
@hacking_Attack
@Hacking_Video
Screenshot / Video Demo
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
Check the 40 seconds Demo Video (https://asciinema.org/a/361931) (v1.95) Demo / Forks Phishy Domains (https://phishydomains.com/) for a simple web version of the openSquat. openSquat Bot (https://telegram.me/opensquat_bot) for a simple Telegram bot. Note: Both forks do not contain all openSquat features. How to Install git clone https://github.com/atenreiro/opensquat
pip install -r requirements.txt Make sure you have Python 3.6+ and pip3 in your environment How to Update To update your current version, just type the following commands inside the openSquat directory: git pull
pip install -r requirements.txt The "pip install" is just to make sure no new libs were added with the new upgrade. Usage Examples Edit the "keywords.txt" with your customised keywords to hunt. certificate transparency (ct) hunt python opensquat.py --ct # Period search - registrations from the last month (default: day) python opensquat.py -p month # Tweak confidence level. The lower values bring more false positives # (0: very high, 1: high (default), 2: medium, 3: low, 4: very low python opensquat.py -c 2 # All validations options python opensquat.py --phishing phishing_domains.txt --dns --ct --subdomains --portcheck "> # Lazy run with default options
python opensquat.py
# for all the options
python opensquat.py -h
# Search for generic terms used in phishing campaigns (can lead to false positives)
python opensquat.py -k generic.txt
# With DNS validation (quad9)
python opensquat.py --dns
# Subdomain search
python opensquat.py --subdomains
# Check for domains with open ports 80/443
python opensquat.py --portcheck
# With Phishing validation (Phishing Database)
python opensquat.py --phishing phish_results.txt
# Save output as JSON
python opensquat.py -o example.json -t json
# Save output as CSV
python opensquat.py -o example.csv -t csv
# Conduct a certificate transparency (https://www.kitploit.com/sea%20%20%20rch/label/Transparency) (ct) hunt
python opensquat.py --ct
# Period search - registrations from the last month (default: day)
python opensquat.py -p month
# Tweak confidence level. The lower values bring more false positives
# (0: very high, 1: high (default), 2: medium, 3: low, 4: very low
python opensquat.py -c 2
# All validations options
python opensquat.py --phishing phishing_domains.txt --dns --ct --subdomains --portcheck To Do / Roadmap Integration with VirusTotal (VT) for subdomains validation Integratration with VirusTotal (VT) for malware detection Use certificate transparency Homograph detection done Improve code quality (https://www.kitploit.com/search/label/Code%20Quality) from B to A grade (codacy) PEP8 compliance AND logical condition for keywords search (e.g: goole+login) - Thanks to Steff T. Add documentation Feature Request To request for a new feature, create a "new issue" and describe the feature and potential use cases. If something similar already exists, you can upvote the "issue" and contribute to the discussions. Changelog Check the CHANGELOG (https://github.com/atenreiro/opensquat/blob/master/CHANGELOG) file. Authors Project founder Andre Tenreiro (LinkedInk) (https://www.linkedin.com/in/andretenreiro/) andre@cert.mz (mailto:andre@cert.mz) Contributors Please check the contributors page on GitHub How to help You can help this project in many ways: Providing your time and coding skills to enhance the project Build a decent but simple project webpage (https://opensquat.com/) Provide access to OSINT feeds Open new issues with new suggestions, ideas, bug report or feature requests Spread this project within your network Share your story how have you been using the openSquat and what impact it brought to you Make a project logo
___________________________
@hacking_Attack
@Hacking_Video
pip install -r requirements.txt Make sure you have Python 3.6+ and pip3 in your environment How to Update To update your current version, just type the following commands inside the openSquat directory: git pull
pip install -r requirements.txt The "pip install" is just to make sure no new libs were added with the new upgrade. Usage Examples Edit the "keywords.txt" with your customised keywords to hunt. certificate transparency (ct) hunt python opensquat.py --ct # Period search - registrations from the last month (default: day) python opensquat.py -p month # Tweak confidence level. The lower values bring more false positives # (0: very high, 1: high (default), 2: medium, 3: low, 4: very low python opensquat.py -c 2 # All validations options python opensquat.py --phishing phishing_domains.txt --dns --ct --subdomains --portcheck "> # Lazy run with default options
python opensquat.py
# for all the options
python opensquat.py -h
# Search for generic terms used in phishing campaigns (can lead to false positives)
python opensquat.py -k generic.txt
# With DNS validation (quad9)
python opensquat.py --dns
# Subdomain search
python opensquat.py --subdomains
# Check for domains with open ports 80/443
python opensquat.py --portcheck
# With Phishing validation (Phishing Database)
python opensquat.py --phishing phish_results.txt
# Save output as JSON
python opensquat.py -o example.json -t json
# Save output as CSV
python opensquat.py -o example.csv -t csv
# Conduct a certificate transparency (https://www.kitploit.com/sea%20%20%20rch/label/Transparency) (ct) hunt
python opensquat.py --ct
# Period search - registrations from the last month (default: day)
python opensquat.py -p month
# Tweak confidence level. The lower values bring more false positives
# (0: very high, 1: high (default), 2: medium, 3: low, 4: very low
python opensquat.py -c 2
# All validations options
python opensquat.py --phishing phishing_domains.txt --dns --ct --subdomains --portcheck To Do / Roadmap Integration with VirusTotal (VT) for subdomains validation Integratration with VirusTotal (VT) for malware detection Use certificate transparency Homograph detection done Improve code quality (https://www.kitploit.com/search/label/Code%20Quality) from B to A grade (codacy) PEP8 compliance AND logical condition for keywords search (e.g: goole+login) - Thanks to Steff T. Add documentation Feature Request To request for a new feature, create a "new issue" and describe the feature and potential use cases. If something similar already exists, you can upvote the "issue" and contribute to the discussions. Changelog Check the CHANGELOG (https://github.com/atenreiro/opensquat/blob/master/CHANGELOG) file. Authors Project founder Andre Tenreiro (LinkedInk) (https://www.linkedin.com/in/andretenreiro/) andre@cert.mz (mailto:andre@cert.mz) Contributors Please check the contributors page on GitHub How to help You can help this project in many ways: Providing your time and coding skills to enhance the project Build a decent but simple project webpage (https://opensquat.com/) Provide access to OSINT feeds Open new issues with new suggestions, ideas, bug report or feature requests Spread this project within your network Share your story how have you been using the openSquat and what impact it brought to you Make a project logo
___________________________
@hacking_Attack
@Hacking_Video
asciinema.org
openSquat Demo
Searching for domains related to Google, Facebook and Amazon. openSquat Project https://github.com/atenreiro/opensquat
Download Opensquat (https://github.com/atenreiro/opensquat)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - atenreiro/opensquat: openSquat is an open-source tool that detects look-alike domains impersonating your brand, by scanning…
openSquat is an open-source tool that detects look-alike domains impersonating your brand, by scanning newly registered domains daily. - atenreiro/opensquat