Hello hunters,Continue reading on Medium » (https://janmuhammadzaidi.medium.com/how-i-bypassed-403-forbidden-domain-using-a-simple-trick-c2d538de04b8?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I bypassed 403 forbidden domain using a simple trick
Hello hunters,
Hacking on Medium
Cracking Passwords w/ John the Ripper
https://cdn-images-1.medium.com/max/1600/1*F6v-zWxXwKIFUaqtrqqXIQ.png
Today we will be looking at a popular password cracking tool called “John the Ripper“ (JtR).
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Cracking Passwords w/ John the Ripper
https://cdn-images-1.medium.com/max/1600/1*F6v-zWxXwKIFUaqtrqqXIQ.png
Today we will be looking at a popular password cracking tool called “John the Ripper“ (JtR).
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cracking Passwords w/ John the Ripper
Today we will be looking at a popular password cracking tool called “John the Ripper“ (JtR).
Hacking on Medium
abusing Living off the Land binaries (Lolbins) for data exfiltration
https://cdn-images-1.medium.com/max/611/1*Uu9YJ67tfxW66moYJ8RCMg.png
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
abusing Living off the Land binaries (Lolbins) for data exfiltration
https://cdn-images-1.medium.com/max/611/1*Uu9YJ67tfxW66moYJ8RCMg.png
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
abusing Living off the Land binaries (Lolbins) for data exfiltration
Introduction
hacking: security in practice
Where should I start?
I am wondering if I should learn at home, or go to university. I’m book smart, but I can really put my mind to work at home. Did you guys take any courses? If so, what do you recommend I get a degree on? Thanks
submitted by /u/CrispyClout
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Where should I start?
I am wondering if I should learn at home, or go to university. I’m book smart, but I can really put my mind to work at home. Did you guys take any courses? If so, what do you recommend I get a degree on? Thanks
submitted by /u/CrispyClout
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Where should I start?
I am wondering if I should learn at home, or go to university. I’m book smart, but I can really put my mind to work at home. Did you guys take any...
hacking: security in practice
Hey guys, aren't there any ways to protect patent from Russia gov?
By washington post, It says "Russia says its businesses can steal patents from anyone in ‘unfriendly’ countries"
So maybe, there is no problem using McDonald's trademarks without permission. In this regard, aren't there any ways to protect patent from Russia gov?
Blocking IP addresses of Russia will actually helpful for proactive action against Russia's patent theft?
submitted by /u/Late_Ice_9288
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hey guys, aren't there any ways to protect patent from Russia gov?
By washington post, It says "Russia says its businesses can steal patents from anyone in ‘unfriendly’ countries"
So maybe, there is no problem using McDonald's trademarks without permission. In this regard, aren't there any ways to protect patent from Russia gov?
Blocking IP addresses of Russia will actually helpful for proactive action against Russia's patent theft?
submitted by /u/Late_Ice_9288
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Hey guys, aren't there any ways to protect patent from Russia gov?
By washington post, It says "Russia says its businesses can steal patents from anyone in ‘unfriendly’ countries" So maybe, there is no problem...
hacking: security in practice
Is this normal? Ongoing investigation regarding hack.
I am not a hacker, but here is something maybe interesting. Seems like such a high-effort/targeted hack, I'm curious what you hackers think.
This is the story of someone near and dear to me. When saying "I or me", it may be from their POV, just easier.
So, funds were transferred from my bank account to another bank account, but the other bank account was in my name and setup in another state - I never made this account, don't know of the bank, definitely not my account (still waiting to hear back about their investigation). Gmail had filters added to remove "transfer" emails. Gmail did say that my device had a suspicious app detected, which I could not/cannot find (device is my local computer - windows 10). Main bank account that was hacked, said that all activity, including the transfer came from my device (local computer). They didn't say if IP was exact match, but said that IP is same city and that Device ID was my local computer. Around that time, also, Facebooks, Twitter and another Gmail account (not me, but same house) said tried logging in from unrecognized device or what not, I still get these notifications a month later (but these attempts that are blocked, are from IP in my city - I tracert facebook or google, and these IP's are not hop points, they are other ISP owned IP's in the same city I live in - I'm with ATT). Passwords have been changed, 2FA added if it wasn't (it was not before). The initial bank and gmail hack happened a month ago, during span of 5 days. Bank found it odd that my device did it, and also that there is another bank account in my name, meaning my SSN is possibly taken, on top of them knowing security questions, passwords, etc.
I'm the one trying to figure this out with my barely above average IT/Networking experience, and how it was done. Seems like such a high-effort or targeted hack, with the other bank account being created in my name and definitely a person spending some time doing this.
Google account does have user/password logins saved.
I did not find any Firewall exceptions out of the ordinary on local device.
Tasks/Processes seemed normal.
Mbam scan did return PUP.Optional.WinYahoo.Generic located in appdata/../chrome when scanned.
How likely is it that my computer or network is compromised, being that they used my device ID, it seems less likely that they'd spoof my info, more likely that they used my actual device, I'm guessing. Thought has crossed my mind that someone sat outside my house and possibly did this, but that seems absurd. Thinking someone actually breached my computer and really did use it (remotely), invisibly in the background, with me not knowing a thing and me unable to find anything to do all of this and not trigger any alarms. If that's the case, they're probably still connected somehow.
Anyways, I'm looking for insight and thoughts on this, and maybe referrals to another subreddit or site if this is not the right place. I know you hackers are capable of incredible stuff. I'm thinking about setting up Wireshark on a clean PC (been a decade since I touched this stuff), still unable to find anything on that local device, so I could still be compromised after changing all of my passwords and stuff.
submitted by /u/MidiGong
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is this normal? Ongoing investigation regarding hack.
I am not a hacker, but here is something maybe interesting. Seems like such a high-effort/targeted hack, I'm curious what you hackers think.
This is the story of someone near and dear to me. When saying "I or me", it may be from their POV, just easier.
So, funds were transferred from my bank account to another bank account, but the other bank account was in my name and setup in another state - I never made this account, don't know of the bank, definitely not my account (still waiting to hear back about their investigation). Gmail had filters added to remove "transfer" emails. Gmail did say that my device had a suspicious app detected, which I could not/cannot find (device is my local computer - windows 10). Main bank account that was hacked, said that all activity, including the transfer came from my device (local computer). They didn't say if IP was exact match, but said that IP is same city and that Device ID was my local computer. Around that time, also, Facebooks, Twitter and another Gmail account (not me, but same house) said tried logging in from unrecognized device or what not, I still get these notifications a month later (but these attempts that are blocked, are from IP in my city - I tracert facebook or google, and these IP's are not hop points, they are other ISP owned IP's in the same city I live in - I'm with ATT). Passwords have been changed, 2FA added if it wasn't (it was not before). The initial bank and gmail hack happened a month ago, during span of 5 days. Bank found it odd that my device did it, and also that there is another bank account in my name, meaning my SSN is possibly taken, on top of them knowing security questions, passwords, etc.
I'm the one trying to figure this out with my barely above average IT/Networking experience, and how it was done. Seems like such a high-effort or targeted hack, with the other bank account being created in my name and definitely a person spending some time doing this.
Google account does have user/password logins saved.
I did not find any Firewall exceptions out of the ordinary on local device.
Tasks/Processes seemed normal.
Mbam scan did return PUP.Optional.WinYahoo.Generic located in appdata/../chrome when scanned.
How likely is it that my computer or network is compromised, being that they used my device ID, it seems less likely that they'd spoof my info, more likely that they used my actual device, I'm guessing. Thought has crossed my mind that someone sat outside my house and possibly did this, but that seems absurd. Thinking someone actually breached my computer and really did use it (remotely), invisibly in the background, with me not knowing a thing and me unable to find anything to do all of this and not trigger any alarms. If that's the case, they're probably still connected somehow.
Anyways, I'm looking for insight and thoughts on this, and maybe referrals to another subreddit or site if this is not the right place. I know you hackers are capable of incredible stuff. I'm thinking about setting up Wireshark on a clean PC (been a decade since I touched this stuff), still unable to find anything on that local device, so I could still be compromised after changing all of my passwords and stuff.
submitted by /u/MidiGong
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is this normal? Ongoing investigation regarding hack.
I am not a hacker, but here is something maybe interesting. Seems like such a high-effort/targeted hack, I'm curious what you hackers think. This...
Dummy DeHashed data for testing API?
https://www.reddit.com/r/Pentesting/comments/tqwswb/dummy_dehashed_data_for_testing_api/
I'm putting together a desktop app for consuming data from different API's like hunter.io (https://hunter.io/) and DeHashed.
It kinda / sorta works but I've run out of DeHashed credits at the moment and I'm looking for some dummy JSON output in the same format as DeHashed's output so that I can test it. There isn't a complete example in their docs, has anyone found an online resource that can be used for testing the API for free? The alpha version is at https://github.com/cyberfilth/nergal submitted by /u/PascalGeek (https://www.reddit.com/user/PascalGeek)
[link] (https://www.reddit.com/r/Pentesting/comments/tqwswb/dummy_dehashed_data_for_testing_api/) [comments] (https://www.reddit.com/r/Pentesting/comments/tqwswb/dummy_dehashed_data_for_testing_api/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/tqwswb/dummy_dehashed_data_for_testing_api/
I'm putting together a desktop app for consuming data from different API's like hunter.io (https://hunter.io/) and DeHashed.
It kinda / sorta works but I've run out of DeHashed credits at the moment and I'm looking for some dummy JSON output in the same format as DeHashed's output so that I can test it. There isn't a complete example in their docs, has anyone found an online resource that can be used for testing the API for free? The alpha version is at https://github.com/cyberfilth/nergal submitted by /u/PascalGeek (https://www.reddit.com/user/PascalGeek)
[link] (https://www.reddit.com/r/Pentesting/comments/tqwswb/dummy_dehashed_data_for_testing_api/) [comments] (https://www.reddit.com/r/Pentesting/comments/tqwswb/dummy_dehashed_data_for_testing_api/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Dummy DeHashed data for testing API?
I'm putting together a desktop app for consuming data from different API's like [hunter.io](https://hunter.io) and DeHashed. It kinda / sorta...
Analyzing Docker Image for Retrieving Secrets
https://www.reddit.com/r/redteamsec/comments/tqvwe6/analyzing_docker_image_for_retrieving_secrets/
submitted by /u/tbhaxor (https://www.reddit.com/user/tbhaxor)
[link] (https://tbhaxor.com/analyzing-docker-image-for-hunting-secrets/) [comments] (https://www.reddit.com/r/redteamsec/comments/tqvwe6/analyzing_docker_image_for_retrieving_secrets/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/tqvwe6/analyzing_docker_image_for_retrieving_secrets/
submitted by /u/tbhaxor (https://www.reddit.com/user/tbhaxor)
[link] (https://tbhaxor.com/analyzing-docker-image-for-hunting-secrets/) [comments] (https://www.reddit.com/r/redteamsec/comments/tqvwe6/analyzing_docker_image_for_retrieving_secrets/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Analyzing Docker Image for Retrieving Secrets
Posted in r/redteamsec by u/tbhaxor • 4 points and 0 comments
Socid-Extractor - Extract Accounts Info From Personal Pages On Various Sites For OSINT Purpose
http://www.kitploit.com/2022/03/socid-extractor-extract-accounts-info.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/03/socid-extractor-extract-accounts-info.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Socid-Extractor - Extract Accounts Info From Personal Pages On Various Sites For OSINT Purpose
tagline: Nothing worth having is easy...
Without installing: $ ./run.py --url https://www.deviantart.com/muse1908
As a Python library: >> import socid_extractor, requests >>> r = requests.get('https://www.patreon.com/annetlovart') >>> socid_extractor.extract(r.text) {'patreon_id': '33913189', 'patreon_username': 'annetlovart', 'fullname': 'Annet Lovart', 'links': "['https://www.facebook.com/322598031832479', 'https://www.instagram.com/annet_lovart', 'https://twitter.com/annet_lovart', 'https://youtube.com/channel/UClDg4ntlOW_1j73zqSJxHHQ']"}">>>> import socid_extractor, requests
>>> r = requests.get('https://www.patreon.com/annetlovart')
>>> socid_extractor.extract(r.text)
{'patreon_id': '33913189', 'patreon_username': 'annetlovart', 'fullname': 'Annet Lovart', 'links': "['https://www.facebook.com/322598031832479', 'https://www.instagram.com/annet_lovart', 'https://twitter.com/annet_lovart', 'https://youtube.com/channel/UClDg4ntlOW_1j73zqSJxHHQ']"}
Installation $ pip3 install socid-extractor
The latest development version can be installed directly from GitHub: $ pip3 install -U git+https://github.com/soxoj/socid_extractor.git
Sites and methods More than 100 methods (https://github.com/soxoj/socid-extractor/blob/master/METHODS.md) for different sites and platforms are supported! Google (all documents pages, maps contributions), cookies (https://www.kitploit.com/search/label/Cookies) required Yandex (disk, albums, znatoki, music, realty, collections), cookies required to prevent captcha blocks Mail.ru (my.mail.ru user mainpage, photo, video, games, communities) Facebook (user & group pages) VK.com (user page) OK.ru (user page) Instagram Reddit Medium Flickr Tumblr TikTok GitHub ...and many others. You can also check tests file (https://github.com/soxoj/socid-extractor/blob/master/tests/test_e2e.py) for data examples, schemes file (https://github.com/soxoj/socid-extractor/blob/master/socid_extractor/schemes.py) to expore all the methods. When it may be useful Getting all available info by the username (https://www.kitploit.com/search/label/Username) or/and account UID. Examples: Week in OSINT (https://medium.com/week-in-osint/getting-a-grasp-on-googleids-77a8ab707e43), OSINTCurious (https://osintcurio.us/2019/10/01/searching-instagram-part-2/) Users tracking, checking that the account was previously known (by ID) even if all public info has changed. Examples: Aware Online (https://www.aware-online.com/en/importance-of-user-ids-in-social-media-investigations/) Searching by commonly used cross-service UIDs (GAIA ID, Facebook (https://www.kitploit.com/search/label/Facebook) UID, Yandex Public ID, etc.) DB leaks of forums and platforms in SQL format Indexed links that contain target profile ID Searching for tracking (https://www.kitploit.com/search/label/Tracking) data by comparison with other IDs - how it works (https://www.eff.org/wp/behind-the-one-way-mirror), how can it be used (https://www.nytimes.com/interactive/2019/12/19/opinion/location-tracking-cell-phone.html). Law enforcement online requests Tools using socid_extractor Maigret (https://github.com/soxoj/maigret) - powerful namechecker, generate a report with all available info from accounts found. TheScrapper (https://github.com/champmq/TheScrapper) - scrape emails, phone numbers and social media accounts from a website. YaSeeker (https://github.com/HowToFind-bot/YaSeeker) - tool to gather all available information about Yandex account by login/email. Marple (https://github.com/soxoj/marple) - scrape search engines results for a given username. Testing python3 -m pytest tests/test_e2e.py -n 10 -k 'not cookies' -m 'not github_failed and not rate_limited' Contributing Check separate page (https://github.com/soxoj/socid-extractor/blob/master/CONTRIBUTING.md) if you want to add a new methods of fix anything.
___________________________
@hacking_Attack
@Hacking_Video
Without installing: $ ./run.py --url https://www.deviantart.com/muse1908
As a Python library: >> import socid_extractor, requests >>> r = requests.get('https://www.patreon.com/annetlovart') >>> socid_extractor.extract(r.text) {'patreon_id': '33913189', 'patreon_username': 'annetlovart', 'fullname': 'Annet Lovart', 'links': "['https://www.facebook.com/322598031832479', 'https://www.instagram.com/annet_lovart', 'https://twitter.com/annet_lovart', 'https://youtube.com/channel/UClDg4ntlOW_1j73zqSJxHHQ']"}">>>> import socid_extractor, requests
>>> r = requests.get('https://www.patreon.com/annetlovart')
>>> socid_extractor.extract(r.text)
{'patreon_id': '33913189', 'patreon_username': 'annetlovart', 'fullname': 'Annet Lovart', 'links': "['https://www.facebook.com/322598031832479', 'https://www.instagram.com/annet_lovart', 'https://twitter.com/annet_lovart', 'https://youtube.com/channel/UClDg4ntlOW_1j73zqSJxHHQ']"}
Installation $ pip3 install socid-extractor
The latest development version can be installed directly from GitHub: $ pip3 install -U git+https://github.com/soxoj/socid_extractor.git
Sites and methods More than 100 methods (https://github.com/soxoj/socid-extractor/blob/master/METHODS.md) for different sites and platforms are supported! Google (all documents pages, maps contributions), cookies (https://www.kitploit.com/search/label/Cookies) required Yandex (disk, albums, znatoki, music, realty, collections), cookies required to prevent captcha blocks Mail.ru (my.mail.ru user mainpage, photo, video, games, communities) Facebook (user & group pages) VK.com (user page) OK.ru (user page) Instagram Reddit Medium Flickr Tumblr TikTok GitHub ...and many others. You can also check tests file (https://github.com/soxoj/socid-extractor/blob/master/tests/test_e2e.py) for data examples, schemes file (https://github.com/soxoj/socid-extractor/blob/master/socid_extractor/schemes.py) to expore all the methods. When it may be useful Getting all available info by the username (https://www.kitploit.com/search/label/Username) or/and account UID. Examples: Week in OSINT (https://medium.com/week-in-osint/getting-a-grasp-on-googleids-77a8ab707e43), OSINTCurious (https://osintcurio.us/2019/10/01/searching-instagram-part-2/) Users tracking, checking that the account was previously known (by ID) even if all public info has changed. Examples: Aware Online (https://www.aware-online.com/en/importance-of-user-ids-in-social-media-investigations/) Searching by commonly used cross-service UIDs (GAIA ID, Facebook (https://www.kitploit.com/search/label/Facebook) UID, Yandex Public ID, etc.) DB leaks of forums and platforms in SQL format Indexed links that contain target profile ID Searching for tracking (https://www.kitploit.com/search/label/Tracking) data by comparison with other IDs - how it works (https://www.eff.org/wp/behind-the-one-way-mirror), how can it be used (https://www.nytimes.com/interactive/2019/12/19/opinion/location-tracking-cell-phone.html). Law enforcement online requests Tools using socid_extractor Maigret (https://github.com/soxoj/maigret) - powerful namechecker, generate a report with all available info from accounts found. TheScrapper (https://github.com/champmq/TheScrapper) - scrape emails, phone numbers and social media accounts from a website. YaSeeker (https://github.com/HowToFind-bot/YaSeeker) - tool to gather all available information about Yandex account by login/email. Marple (https://github.com/soxoj/marple) - scrape search engines results for a given username. Testing python3 -m pytest tests/test_e2e.py -n 10 -k 'not cookies' -m 'not github_failed and not rate_limited' Contributing Check separate page (https://github.com/soxoj/socid-extractor/blob/master/CONTRIBUTING.md) if you want to add a new methods of fix anything.
___________________________
@hacking_Attack
@Hacking_Video
Deviantart
MuseMercier on DeviantArt
MuseMercier is an artist on DeviantArt. I'm the subject in all my images here. I'm a trained theatre actress and create all sorts of self portraits over on my patreon. Nothing explicit, do not ask me as I get sad. Find out more here: ht... · Artworks: 361…
Download Socid-Extractor (https://github.com/soxoj/socid-extractor)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - soxoj/socid-extractor: ⛏️ The extraction engine behind Maigret: turn any profile URL into a structured OSINT record across…
⛏️ The extraction engine behind Maigret: turn any profile URL into a structured OSINT record across 150+ sites - soxoj/socid-extractor
How to find the computer of a given user on a Windows network?
https://www.reddit.com/r/Pentesting/comments/tqyaot/how_to_find_the_computer_of_a_given_user_on_a/
Hello everybody, I'm new to pentesting and trying to improve my skills :) Recently I pwned a whole domain with more than 200 computers. Next move was to find the computer used by the admin where all passwords where kept. I was lucky enough as machines had an explicit name but that may not be the case everytime. Do you have any tip to share ? How do you find valuable machines on big networks ? Can AD help to identify the computer used by a given user (any PS script or tool to share) ? Regards submitted by /u/fAyf5eQR (https://www.reddit.com/user/fAyf5eQR)
[link] (https://www.reddit.com/r/Pentesting/comments/tqyaot/how_to_find_the_computer_of_a_given_user_on_a/) [comments] (https://www.reddit.com/r/Pentesting/comments/tqyaot/how_to_find_the_computer_of_a_given_user_on_a/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/tqyaot/how_to_find_the_computer_of_a_given_user_on_a/
Hello everybody, I'm new to pentesting and trying to improve my skills :) Recently I pwned a whole domain with more than 200 computers. Next move was to find the computer used by the admin where all passwords where kept. I was lucky enough as machines had an explicit name but that may not be the case everytime. Do you have any tip to share ? How do you find valuable machines on big networks ? Can AD help to identify the computer used by a given user (any PS script or tool to share) ? Regards submitted by /u/fAyf5eQR (https://www.reddit.com/user/fAyf5eQR)
[link] (https://www.reddit.com/r/Pentesting/comments/tqyaot/how_to_find_the_computer_of_a_given_user_on_a/) [comments] (https://www.reddit.com/r/Pentesting/comments/tqyaot/how_to_find_the_computer_of_a_given_user_on_a/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to find the computer of a given user on a Windows network?
Hello everybody, I'm new to pentesting and trying to improve my skills :) Recently I pwned a whole domain with more than 200 computers. Next...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Jatayu : Stealthy Stand Alone PHP Web Shell
JATAYU a Stealthy Stand Alone PHP Web Shell .
FEATURES
* Http Header Based Authentication.
* 100% Undetectable.
* Exec Function Changer.
* Nothing Fancy
USAGE
GET /test/jatayu.php?fn=1&&cmd=whoami
Host : http://test.com
Authtoken : bb3b1a1f-0447-42a6-955a-88681fb88499
FUNCTIONS
PARAMETERFUNCTIONfn=1Calls function shell_exec()fn=2Calls function system()cmd=idExecutes command
GENERATE AUTHTOKEN
php
$r = unpack(‘v*’, fread(fopen(‘/dev/random’, ‘r’),16));
$apiKey = sprintf(‘%04x%04x-%04x-%04x-%04x-%04x%04x%04x’,
$r[1], $r[2], $r[3], $r[4] & 0x0fff | 0x4000,
$r[5] & 0x3fff | 0x8000, $r[6], $r[7], $r[8]);
echo $apiKey;
?>
Download
___________________________
@hacking_Attack
@Hacking_Video
Jatayu : Stealthy Stand Alone PHP Web Shell
JATAYU a Stealthy Stand Alone PHP Web Shell .
FEATURES
* Http Header Based Authentication.
* 100% Undetectable.
* Exec Function Changer.
* Nothing Fancy
USAGE
GET /test/jatayu.php?fn=1&&cmd=whoami
Host : http://test.com
Authtoken : bb3b1a1f-0447-42a6-955a-88681fb88499
FUNCTIONS
PARAMETERFUNCTIONfn=1Calls function shell_exec()fn=2Calls function system()cmd=idExecutes command
GENERATE AUTHTOKEN
php
$r = unpack(‘v*’, fread(fopen(‘/dev/random’, ‘r’),16));
$apiKey = sprintf(‘%04x%04x-%04x-%04x-%04x-%04x%04x%04x’,
$r[1], $r[2], $r[3], $r[4] & 0x0fff | 0x4000,
$r[5] & 0x3fff | 0x8000, $r[6], $r[7], $r[8]);
echo $apiKey;
?>
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Jatayu : Stealthy Stand Alone PHP Web Shell !!! Kali Linux
J ATAYU a Stealthy Stand Alone PHP Web Shell . Http Header Based Authentication. 100% Undetectable. Exec Function Changer. Nothing Fancy
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Scylla : The Simplistic Information Gathering Engine
Scylla is an OSINT tool developed in Python 3.6. Scylla lets users perform advanced searches on Instagram & Twitter accounts, websites/webservers, phone numbers, and names. Scylla also allows users to find all social media profiles (main platforms) assigned to a certain username. In continuation, Scylla has shodan support so you can search for devices all over the internet, it also has in-depth geolocation capabilities. Lastly, Scylla has a finance section which allows users to check if a credit/debit card number has been leaked/pasted in a breach and returns information on the cards IIN/BIN. This is the first version of the tool so please contact the developer if you want to help contribute and add more to Scylla. Installation*
*
*
*
*
A Sample API key is given. I will recommend reading API NOTICE below, for more information.
*
A Sample API key is given. I will recommend reading API NOTICE below, for more information.
*
*
[–info INFO] [-r REVERSE_PHONE_LOOKUP] [-l LOOKUP]
[-s SHODAN_QUERY] [-g GEO] [-c CARD_INFO]
optional arguments:
-h, –help show this help message and exit
-v, –version returns scyla’s version
-ig INSTAGRAM, –instagram INSTAGRAM
return the information associated with specified
instagram account
-tw TW[...]
___________________________
@hacking_Attack
@Hacking_Video
Scylla : The Simplistic Information Gathering Engine
Scylla is an OSINT tool developed in Python 3.6. Scylla lets users perform advanced searches on Instagram & Twitter accounts, websites/webservers, phone numbers, and names. Scylla also allows users to find all social media profiles (main platforms) assigned to a certain username. In continuation, Scylla has shodan support so you can search for devices all over the internet, it also has in-depth geolocation capabilities. Lastly, Scylla has a finance section which allows users to check if a credit/debit card number has been leaked/pasted in a breach and returns information on the cards IIN/BIN. This is the first version of the tool so please contact the developer if you want to help contribute and add more to Scylla. Installation*
git clone https://www.github.com/DoubleThreatSecurity/Scylla* cd Scylla* sudo python3 -m pip install -r requirments.txt* python3 scylla.py --helpUsage* python3 scylla.py --instagram davesmith --twitter davesmithCommand 1 will return account information of that specified Instagram & Twitter account.*
python3 scylla.py --username johndoeCommand 2 will return all the social media (main platforms) profiles associated with that username.*
python3 scylla.py --username johndoe -l="john doe"Command 3 will repeat command 2 but instead it will also perform an in-depth google search for the “-l” argument. NOTE: When searching a query with spaces make sure you add the equal sign followed by the query in quotations. If your query does not have spaces, it will be as such: python3 scylla.py --username johndoe -l query* python3 scylla.py --info google.comCommand 4 will return crucial WHOIS information about the webserver/website.*
python3 scylla.py -r +14167777777Command 5 will dump information on that phone number (Carrier, Location, etc.)*
python3 scylla.py -s apacheCommand 6 will dump all the IP address of apache servers that shodan can grab based on your API key. The query can be anything that shodan can validate.A Sample API key is given. I will recommend reading API NOTICE below, for more information.
*
python3 scylla.py -s webcamxpCommand 7 will dump all the IP addresses and ports of open webcams on the internet that shodan can grab based on your API key. You can also just use the webcamquery but webcamxpreturns better results.A Sample API key is given. I will recommend reading API NOTICE below, for more information.
*
python3 scylla.py -g 1.1.1.1Command 8 will geolocate the specified IP address. It will return the longitude & latitude, city, state/province, country, zip/postal code region and the district.*
python3 scylla.py -c 123456789123456Command 9 will retrieve information on the IIN of the credit/debit card number entered. It will also check if the card number has been leaked/pasted in a breach. Scylla will return the card brand, card scheme, card type, currency, country, and information on the bank of that IIN. NOTE: Enter the full card number if you will like to see if it was leaked. If you just want to check data on the first 6-8 digits (a.k.a the BIN/IIN number) just input the first 6,7 or 8 digits of the credit/debit card number. Lastly, all this information generated is public because this is an OSINT tool, and no revealing details can be generated. This prevents malicous use of this option. Menuusage: scylla.py [-h] [-v] [-ig INSTAGRAM] [-tw TWITTER] [-u USERNAME][–info INFO] [-r REVERSE_PHONE_LOOKUP] [-l LOOKUP]
[-s SHODAN_QUERY] [-g GEO] [-c CARD_INFO]
optional arguments:
-h, –help show this help message and exit
-v, –version returns scyla’s version
-ig INSTAGRAM, –instagram INSTAGRAM
return the information associated with specified
instagram account
-tw TW[...]
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Scylla : The Simplistic Information Gathering Engine
Scylla is an OSINT tool developed in Python 3.6. Scylla lets users perform advanced searches on Instagram & Twitter accounts.
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Scylla : The Simplistic Information Gathering Engine Scylla is an OSINT tool developed in Python 3.6. Scylla lets users perform advanced searches on Instagram & Twitter accounts, websites/webservers, phone numbers, and names. Scylla also…
ITTER, –twitter TWITTER
return the information associated with specified
twitter account
-u USERNAME, –username USERNAME
find social media profiles (main platforms) associated
with given username
–info INFO return information about the specified website(WHOIS)
w/ geolocation
-r REVERSE_PHONE_LOOKUP, –reverse_phone_lookup REVERSE_PHONE_LOOKUP
return information about the specified phone number
(reverse lookup)
-l LOOKUP, –lookup LOOKUP
performs a google search of the 35 top items for the
argument given
-s SHODAN_QUERY, –shodan_query SHODAN_QUERY
performs a an in-depth shodan search on any simple
query (i.e, ‘webcamxp’, ‘voip’, ‘printer’, ‘apache’)
-g GEO, –geo GEO geolocates a given IP address. provides: longitude,
latitude, city, country, zipcode, district, etc.
-c CARD_INFO, –card_info CARD_INFO
check if the credit/debit card number has been pasted
in a breach…dumps sites. Also returns bank
information on the IIN API NOTICEThe API used for the reverse phone number lookup (free package) has maximum 250 requests. The one used in the program right now will most definetely run out of uses in the near future. If you want to keep generating API keys, go to https://www.numverify.com, and select the free plan after creating an account. Then simply go scylla.py and replace the original API key with your new API key found in your account dashboard. Insert your new key into the keys[] array (at the top of the source). For the Shodan API key, it is just a sample key given to the program. The developer recommends creating a shodan account and adding your own API key to the shodan_api[] array at the top of the source (scylla.py). Download
___________________________
@hacking_Attack
@Hacking_Video
return the information associated with specified
twitter account
-u USERNAME, –username USERNAME
find social media profiles (main platforms) associated
with given username
–info INFO return information about the specified website(WHOIS)
w/ geolocation
-r REVERSE_PHONE_LOOKUP, –reverse_phone_lookup REVERSE_PHONE_LOOKUP
return information about the specified phone number
(reverse lookup)
-l LOOKUP, –lookup LOOKUP
performs a google search of the 35 top items for the
argument given
-s SHODAN_QUERY, –shodan_query SHODAN_QUERY
performs a an in-depth shodan search on any simple
query (i.e, ‘webcamxp’, ‘voip’, ‘printer’, ‘apache’)
-g GEO, –geo GEO geolocates a given IP address. provides: longitude,
latitude, city, country, zipcode, district, etc.
-c CARD_INFO, –card_info CARD_INFO
check if the credit/debit card number has been pasted
in a breach…dumps sites. Also returns bank
information on the IIN API NOTICEThe API used for the reverse phone number lookup (free package) has maximum 250 requests. The one used in the program right now will most definetely run out of uses in the near future. If you want to keep generating API keys, go to https://www.numverify.com, and select the free plan after creating an account. Then simply go scylla.py and replace the original API key with your new API key found in your account dashboard. Insert your new key into the keys[] array (at the top of the source). For the Shodan API key, it is just a sample key given to the program. The developer recommends creating a shodan account and adding your own API key to the shodan_api[] array at the top of the source (scylla.py). Download
___________________________
@hacking_Attack
@Hacking_Video
Numverify
Numverify API | Numverify API | Phone Number Validation & Phone Lookup API
Numverify API is a powerful JSON API providing international and national phone number validation, carrier, location, and line type lookup for developers.
Hacking on Medium
Ethical Hacking
What is Ethical Hacking?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Ethical Hacking
What is Ethical Hacking?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Ethical Hacking
What is Ethical Hacking?
Hacking on Medium
TryHackMe: [Day 5] Web Exploitation Pesky Elf Forum
https://cdn-images-1.medium.com/max/1920/1*psaTaSfd9sQyajFeYTLO-w.png
What flag did you get when you disabled the plugin?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TryHackMe: [Day 5] Web Exploitation Pesky Elf Forum
https://cdn-images-1.medium.com/max/1920/1*psaTaSfd9sQyajFeYTLO-w.png
What flag did you get when you disabled the plugin?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackMe: [Day 5] Web Exploitation Pesky Elf Forum
What flag did you get when you disabled the plugin?