Please do not believe everyone, do your own research before switching. Look around for genuine people , don’t take advice from those who…Continue reading on Medium » (https://vsr13.medium.com/chapter-1-my-journey-in-the-field-of-pentesting-bug-hunting-597cb71ca5f7?source=rss------bug_bounty-5)
Chapter 1 — My journey in the field of Pentesting & Bug hunting.
Please do not believe everyone, do your own research before switching. Look around for genuine people , don’t take advice from those who…Continue reading on Medium »
Read more...
Please do not believe everyone, do your own research before switching. Look around for genuine people , don’t take advice from those who…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Chrome Zero-Day Exploit Posted on Twitter
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Chrome Zero-Day Exploit Posted on TwitterPost Views: 120
style="display:block"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="8337846400"
data-ad-format="auto"
data-full-width-responsive="true">
Reading Time: 1 Minute
A researcher has dropped working exploit code for a zero-day remote code execution (RCE) vulnerability on Twitter, which he said affects the current versions of Google Chrome and potentially other browsers, like Microsoft Edge, that use the Chromium framework.
Security researcher Rajvardhan Agarwal tweeted a GitHub link to the exploit code — the result of the Pwn2Own ethical hacking contest held online last week — on Monday.
“Just here to drop a chrome 0day,” Agarwal wrote in his tweet. “Yes you read that right.” Pwn2Own contest rules require that the Chrome security team receive details of the code so they could patch the vulnerability as soon as possible, which they did; the latest version of the Chrome V8 JavaScript engine patches the flaw, Agarwal said in a comment posted in response to his own tweet.
However, that patch has not yet been integrated into official releases of downstream Chromium-based browsers such as Chrome, Edge and others, leaving them potentially vulnerable to attacks. Google is expected to release a new Chrome version —including security fixes— sometime on Tuesday, though it’s unclear if patches for the bug will be included.
See Also: 1.3M Clubhouse Users’ Data Dumped in Hacker Forum for Free As of the time of publication, a Chrome update had not yet been released and Google had not yet replied to an email by Threatpost requesting comment about the flaw and the update. Not Fully WeaponizedSecurity researchers Bruno Keith and Niklas Baumstark of Dataflow Security developed the exploit code for a type mismatch bug during last’s week’s contest, and used it to successfully exploit the Chromium vulnerability to run malicious code inside Chrome and Edge. They received $100,000 for their work.
The exploit includes a PoC HTML file that, with its corresponding JavaScript file, can be loaded into a Chromium-based browser in order to launch the Windows calculator (calc.exe) program. Attackers would still need to escape the Chrome browser “sandbox,” a security container preventing browser-specific code from reaching the underlying OS, to complete full remote code execution, according to a published report from Recorded Future.
The researchers seemed surprised that Agarwal posted the exploit on Twitter, with Baumstark tweeting a response to Agarwal’s post on Monday. “Getting popped with our own bugs wasn’t on my bingo card for 2021,” he tweeted.
getting popped with our own bugs wasn't on my bingo card for 2021. not sure it was too smart of Google to add that regression test right away… https://t.co/e0RUlmbxRK
— Niklas B (@_niklasb) April 12, 2021
See Also: Offensive Security Tool: CVE Binary Tool by Intel While the exploit code that Agarwal posted does indeed allow an attacker to run malicious code on a user’s operating system, he apparently was not unscrupulous enough to post a fully weaponized version of the code, according to The Record — he did not post a full exploit chain that would allow sandbox escape.
Still, the exploit as posted could still attack services that run embedded/headless versions of Chromium, where sandbox protections aren’t usually enabled, Agarwal told The Record.
The 2021 Pwn2Own spring edition, sponsored by Trend Micro’s Zero Day Initiative, was held online last week after organizers published a list of eligible targets for the contest in Janua[...]
Chrome Zero-Day Exploit Posted on Twitter
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Chrome Zero-Day Exploit Posted on TwitterPost Views: 120
style="display:block"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="8337846400"
data-ad-format="auto"
data-full-width-responsive="true">
Reading Time: 1 Minute
A researcher has dropped working exploit code for a zero-day remote code execution (RCE) vulnerability on Twitter, which he said affects the current versions of Google Chrome and potentially other browsers, like Microsoft Edge, that use the Chromium framework.
Security researcher Rajvardhan Agarwal tweeted a GitHub link to the exploit code — the result of the Pwn2Own ethical hacking contest held online last week — on Monday.
“Just here to drop a chrome 0day,” Agarwal wrote in his tweet. “Yes you read that right.” Pwn2Own contest rules require that the Chrome security team receive details of the code so they could patch the vulnerability as soon as possible, which they did; the latest version of the Chrome V8 JavaScript engine patches the flaw, Agarwal said in a comment posted in response to his own tweet.
However, that patch has not yet been integrated into official releases of downstream Chromium-based browsers such as Chrome, Edge and others, leaving them potentially vulnerable to attacks. Google is expected to release a new Chrome version —including security fixes— sometime on Tuesday, though it’s unclear if patches for the bug will be included.
See Also: 1.3M Clubhouse Users’ Data Dumped in Hacker Forum for Free As of the time of publication, a Chrome update had not yet been released and Google had not yet replied to an email by Threatpost requesting comment about the flaw and the update. Not Fully WeaponizedSecurity researchers Bruno Keith and Niklas Baumstark of Dataflow Security developed the exploit code for a type mismatch bug during last’s week’s contest, and used it to successfully exploit the Chromium vulnerability to run malicious code inside Chrome and Edge. They received $100,000 for their work.
The exploit includes a PoC HTML file that, with its corresponding JavaScript file, can be loaded into a Chromium-based browser in order to launch the Windows calculator (calc.exe) program. Attackers would still need to escape the Chrome browser “sandbox,” a security container preventing browser-specific code from reaching the underlying OS, to complete full remote code execution, according to a published report from Recorded Future.
The researchers seemed surprised that Agarwal posted the exploit on Twitter, with Baumstark tweeting a response to Agarwal’s post on Monday. “Getting popped with our own bugs wasn’t on my bingo card for 2021,” he tweeted.
getting popped with our own bugs wasn't on my bingo card for 2021. not sure it was too smart of Google to add that regression test right away… https://t.co/e0RUlmbxRK
— Niklas B (@_niklasb) April 12, 2021
See Also: Offensive Security Tool: CVE Binary Tool by Intel While the exploit code that Agarwal posted does indeed allow an attacker to run malicious code on a user’s operating system, he apparently was not unscrupulous enough to post a fully weaponized version of the code, according to The Record — he did not post a full exploit chain that would allow sandbox escape.
Still, the exploit as posted could still attack services that run embedded/headless versions of Chromium, where sandbox protections aren’t usually enabled, Agarwal told The Record.
The 2021 Pwn2Own spring edition, sponsored by Trend Micro’s Zero Day Initiative, was held online last week after organizers published a list of eligible targets for the contest in Janua[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Chrome Zero-Day Exploit Posted on Twitter https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Chrome Zero-Day Exploit Posted on TwitterPost Views: 120 style="display:block" data…
ry. The contest drew multiple teams and included 23 hacking sessions against 10 different products from the list of predefined targets. See Also: Hacking Stories: When two young hackers played war games with PentagonThe teams had 15 minutes to run their exploit code and achieve RCE inside the targeted app, receiving various monetary awards — with $1.5 million in total prize money at stake — for each successful exploit from the contest’s sponsors as well as points towards the overall ranking. Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Clubhouse2-e1618258606781-90x90.png 1.3M Clubhouse Users’ Data Dumped in Hacker Forum for Free1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/linkedin-90x90.png Data from 500M LinkedIn Users Posted for Sale Online2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/cisco-patch-90x90.png Zero-Day Bug Impacts Problem-Plagued Cisco SOHO Routers5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/google-play-90x90.jpg Fake Netflix App on Google Play Spreads Malware Via WhatsApp6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/vmware-patch-90x90.jpg Critical Cloud Bug in VMWare Carbon Black Allows Takeover1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/eggs-chickens-e1617650984482-90x90.jpg LinkedIn Spear-Phishing Campaign Targets Job Hunters1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/pf9bzNs3hHRgAcgDQTPPa3-1200-80-90x90.jpg Facebook data on 533 million users posted online1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/NAS-Bug-90x90.jpg Legacy QNAP NAS Devices Vulnerable to Zero-Day Attack2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/iphone-privacy-90x90.jpg Apple, Google Both Track Mobile Telemetry Data, Despite Users Opting Out2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Monero-Mining-90x90.png Malicious Docker Cryptomining Images Rack Up 20M Downloads2 weeks ago
The post Chrome Zero-Day Exploit Posted on Twitter first appeared on Black Hat Ethical Hacking.
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/linkedin-90x90.png Data from 500M LinkedIn Users Posted for Sale Online2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/cisco-patch-90x90.png Zero-Day Bug Impacts Problem-Plagued Cisco SOHO Routers5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/google-play-90x90.jpg Fake Netflix App on Google Play Spreads Malware Via WhatsApp6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/vmware-patch-90x90.jpg Critical Cloud Bug in VMWare Carbon Black Allows Takeover1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/eggs-chickens-e1617650984482-90x90.jpg LinkedIn Spear-Phishing Campaign Targets Job Hunters1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/pf9bzNs3hHRgAcgDQTPPa3-1200-80-90x90.jpg Facebook data on 533 million users posted online1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/NAS-Bug-90x90.jpg Legacy QNAP NAS Devices Vulnerable to Zero-Day Attack2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/iphone-privacy-90x90.jpg Apple, Google Both Track Mobile Telemetry Data, Despite Users Opting Out2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Monero-Mining-90x90.png Malicious Docker Cryptomining Images Rack Up 20M Downloads2 weeks ago
The post Chrome Zero-Day Exploit Posted on Twitter first appeared on Black Hat Ethical Hacking.
hacking: security in practice
How
I made an Instagram page with a friend, I've been using it for personal use for some time now after changing the password to the gmail and the instagram, it turn out my friend still has access even after I changed the password again removed his device from logged in devices and even 2FA. How is this possible? He has access to the Google account and his device isn't even showing in logged in devices.
submitted by /u/KhoobNoob
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
How
I made an Instagram page with a friend, I've been using it for personal use for some time now after changing the password to the gmail and the instagram, it turn out my friend still has access even after I changed the password again removed his device from logged in devices and even 2FA. How is this possible? He has access to the Google account and his device isn't even showing in logged in devices.
submitted by /u/KhoobNoob
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
reddit
How
I made an Instagram page with a friend, I've been using it for personal use for some time now after changing the password to the gmail and the...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
NSA says it found new critical vulnerabilities in Microsoft Exchange Server
https://external-preview.redd.it/3nSBkgg1hlmJNpn3Q4GHxQUfKY0H3rkCjJUNoL5CZPM.jpg?width=640&crop=smart&auto=webp&s=49b2dac468b5def6a3e4b85c2dff60e96921e0ba submitted by /u/_P4TR10T
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
NSA says it found new critical vulnerabilities in Microsoft Exchange Server
https://external-preview.redd.it/3nSBkgg1hlmJNpn3Q4GHxQUfKY0H3rkCjJUNoL5CZPM.jpg?width=640&crop=smart&auto=webp&s=49b2dac468b5def6a3e4b85c2dff60e96921e0ba submitted by /u/_P4TR10T
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
Forwarded from HACK EVERYTHING (Sourabh Mishra)
*Bug Bounty Notes*
======>
Finding all subdomains -> amass + assetfinder + findomain + subfinder + github-subdomain
Sort and Unique mean merge them to all-subdomains.txt
Resolve those subdomains - is ip/domain live?
check for alive subdomains -> httpx or httprobe -> prefer httpx
got https subdomains -> arrange with status code like 200,302,403,404,500
visual recon on these subdomains -> gowitness, eyewitness, aquatone
Port scans on these subdomains
content discovery on them -> ffuf, wfuzz, dirsearch, gobuster
google dorks + shodan dorks on interesting subdomains + GHDB + Github Dorks
get to know what technologies the target using -> whatweb or builtwith or wappalyzer
what server?
what libraries
what lang -> php, asp
also check cookies and session to know tech and infrastructure
what cms using?
Grab all JS Files and enumerate it for juicy information ->
interesting url
intersting js library
interesting subdomain
interesting api
internal ports or portals and their creds -> port scan on internal domains
default test user creds
db creds
hardcoded secrets
hidden paths
and lots of
Tool -> jsscanner , linkfinder, jsfinder, relative-url-extractor and lots of one liner commands , getjs
Understand JS Code -> can get -> dom xss , Postmessage vulns, Logical Bugs, check for outdated frameworks and components
extract js stuff ->
echo "https://target.com | gau | grep -iE '\.js$' | httpx -status-code -mc 200 -content-type | grep 'application/javascript'
extract API Stuff ->
cat file.js | grep -aoP "(?<=(\"|\'|\'))\\/[a-zA-Z0-9_?&=\\/\\-\\#\\.]*(?=(\\"|\\'|\\'))" | sort -u
Deobfuscate Javascript
If see -> var test=" or var page=" in JS File or page source , try to append these as GET Parameters and check for bugs there
Monitor JS Changes regularly
Fetching URLs ->
Time to get all URLs and parameters from those web file that is alive-hosts and do enumeration on them for vulns or other things
waybackurls
gau
gf
gospider
hakcawler - here idea to grep things like, subdomain,url,form,javascript,robots etc
Fetching URLs -> Might Lead to -> SSTI, XSS, SQLi, SSRF, Open Redirect, IDOR etc
Now use github to more recon for juciy info - gwen github tools , gitrob, git-hound
ALL SET NOW MASS HUNT FOR XSS (step by step) =>
=========
echo "yourtarget.com" | waybackurls | tee target.txt
cat target.txt | gf xss | sed 's/=.*/=/' | sed 's/URL: //' | tee targetxss.txt
dalfox file targetxss.txt pipe
# nuclei ->
# find all the urls of your target & save them in a .txt file
echo "yourtarget.com" | waybackurls | tee target.txt
# run the .txt file with nuclei for find bugs
nuclei -l target.txt -t /root/nuclei-templates/ -v {for use all the templats at once}
nuclei -l target.txt -t /root/nuclei-templates/vulnerabilities -v {for finding vulnerabilities}
nuclei -l target.txt -t /root/nuclei-templates/cves -v {for all the new cve bugs}
# Update nuclei-templates/
nuclei -update-templates
Burp Collaborator Alternative - https://pingb.in
Quickly find ssrf/open redirect ->
gau target website -s | head -n 5000> target.txt; cat target.txt | sort -u | grep -a -i =http> redirects.txt
One Liner Commands and other commands =>
=============>
# Create Custom Wordlist
gau $1| unfurl -u keys | tee -a wordlist.txt ; gau $1 | unfurl -u paths|tee -a ends.txt; sed 's#/#\n#g' ends.txt | sort -u | tee -a wordlist.txt | sort -u ;rm ends.txt | sed -i -e 's/\.css\|\.png\|\.jpeg\|\.jpg\|\.svg\|\.gif\|\.wolf\|\.bmp//g' wordlist.txt
#cat domains.txt | httprobe | xargs curl | tok | tr '[:upper:]' '[:lower:]' | sort -u | tee -a words.txt
# CORS Misconfiguration
site="https://example.com"; gau "$site" | while read url;do target=$(curl -s -I -H "Origin: https://evil.com" -X GET $url) | if grep 'https://evil.com'; then [Potentional CORS Found]echo $url;else echo Nothing on "$url";fi;done
# Extract Endpoint Form Js Files
cat main.js | grep -oh "\"\/[a-zA-Z0-9_/?=&]*\"" | sed -e 's/^"//' -e 's/"$//' | sort -u
# Get Ip's From Text File
grep -E -o '(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2
======>
Finding all subdomains -> amass + assetfinder + findomain + subfinder + github-subdomain
Sort and Unique mean merge them to all-subdomains.txt
Resolve those subdomains - is ip/domain live?
check for alive subdomains -> httpx or httprobe -> prefer httpx
got https subdomains -> arrange with status code like 200,302,403,404,500
visual recon on these subdomains -> gowitness, eyewitness, aquatone
Port scans on these subdomains
content discovery on them -> ffuf, wfuzz, dirsearch, gobuster
google dorks + shodan dorks on interesting subdomains + GHDB + Github Dorks
get to know what technologies the target using -> whatweb or builtwith or wappalyzer
what server?
what libraries
what lang -> php, asp
also check cookies and session to know tech and infrastructure
what cms using?
Grab all JS Files and enumerate it for juicy information ->
interesting url
intersting js library
interesting subdomain
interesting api
internal ports or portals and their creds -> port scan on internal domains
default test user creds
db creds
hardcoded secrets
hidden paths
and lots of
Tool -> jsscanner , linkfinder, jsfinder, relative-url-extractor and lots of one liner commands , getjs
Understand JS Code -> can get -> dom xss , Postmessage vulns, Logical Bugs, check for outdated frameworks and components
extract js stuff ->
echo "https://target.com | gau | grep -iE '\.js$' | httpx -status-code -mc 200 -content-type | grep 'application/javascript'
extract API Stuff ->
cat file.js | grep -aoP "(?<=(\"|\'|\'))\\/[a-zA-Z0-9_?&=\\/\\-\\#\\.]*(?=(\\"|\\'|\\'))" | sort -u
Deobfuscate Javascript
If see -> var test=" or var page=" in JS File or page source , try to append these as GET Parameters and check for bugs there
Monitor JS Changes regularly
Fetching URLs ->
Time to get all URLs and parameters from those web file that is alive-hosts and do enumeration on them for vulns or other things
waybackurls
gau
gf
gospider
hakcawler - here idea to grep things like, subdomain,url,form,javascript,robots etc
Fetching URLs -> Might Lead to -> SSTI, XSS, SQLi, SSRF, Open Redirect, IDOR etc
Now use github to more recon for juciy info - gwen github tools , gitrob, git-hound
ALL SET NOW MASS HUNT FOR XSS (step by step) =>
=========
echo "yourtarget.com" | waybackurls | tee target.txt
cat target.txt | gf xss | sed 's/=.*/=/' | sed 's/URL: //' | tee targetxss.txt
dalfox file targetxss.txt pipe
# nuclei ->
# find all the urls of your target & save them in a .txt file
echo "yourtarget.com" | waybackurls | tee target.txt
# run the .txt file with nuclei for find bugs
nuclei -l target.txt -t /root/nuclei-templates/ -v {for use all the templats at once}
nuclei -l target.txt -t /root/nuclei-templates/vulnerabilities -v {for finding vulnerabilities}
nuclei -l target.txt -t /root/nuclei-templates/cves -v {for all the new cve bugs}
# Update nuclei-templates/
nuclei -update-templates
Burp Collaborator Alternative - https://pingb.in
Quickly find ssrf/open redirect ->
gau target website -s | head -n 5000> target.txt; cat target.txt | sort -u | grep -a -i =http> redirects.txt
One Liner Commands and other commands =>
=============>
# Create Custom Wordlist
gau $1| unfurl -u keys | tee -a wordlist.txt ; gau $1 | unfurl -u paths|tee -a ends.txt; sed 's#/#\n#g' ends.txt | sort -u | tee -a wordlist.txt | sort -u ;rm ends.txt | sed -i -e 's/\.css\|\.png\|\.jpeg\|\.jpg\|\.svg\|\.gif\|\.wolf\|\.bmp//g' wordlist.txt
#cat domains.txt | httprobe | xargs curl | tok | tr '[:upper:]' '[:lower:]' | sort -u | tee -a words.txt
# CORS Misconfiguration
site="https://example.com"; gau "$site" | while read url;do target=$(curl -s -I -H "Origin: https://evil.com" -X GET $url) | if grep 'https://evil.com'; then [Potentional CORS Found]echo $url;else echo Nothing on "$url";fi;done
# Extract Endpoint Form Js Files
cat main.js | grep -oh "\"\/[a-zA-Z0-9_/?=&]*\"" | sed -e 's/^"//' -e 's/"$//' | sort -u
# Get Ip's From Text File
grep -E -o '(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2
Target
Target : Expect More. Pay Less.
Shop Target online and in-store for everything from groceries and essentials to clothing and electronics. Choose contactless pickup or delivery today.
Forwarded from HACK EVERYTHING (Sourabh Mishra)
4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)' $1
# Subdomain Bruteforcer with FFUF
ffuf -u https://FUZZ.$1 -w $2 -v | grep "| URL |" | awk '{print $4}'
# Get Subdomains from Archive
curl -s "http://web.archive.org/cdx/search/cdx?url=*.$1/*&output=text&fl=original&collapse=urlkey" | gsed -e 's_https*://__' -e "s/\/.*//" | sort -u
# Get Subdomains from BufferOver.run
curl -s https://dns.bufferover.run/dns?q=.$1 |jq -r .FDNS_A[]|cut -d',' -f2|sort -u
# Get Subdomains from JLDC
curl -s "https://jldc.me/anubis/subdomains/$1" | grep -Po "((http|https):\/\/)?(([\w.-]*)\.([\w]*)\.([A-z]))\w+" | sort -u
# Extract Subdomains Form riddler.io
curl -s "https://riddler.io/search/exportcsv?q=pld:$1" | grep -Po "(([\w.-]*)\.([\w]*)\.([A-z]))\w+" | sort -u
# Get Subdomains from VirusTotal
curl -s "https://www.virustotal.com/ui/domains/domain.com/subdomains?limit=40" | grep -Po "((http|https):\/\/)?(([\w.-]*)\.([\w]*)\.([A-z]))\w+" | sort -u
# Get Subdomains from certpostter
curl -s "https://certspotter.com/api/v0/certs?domain=$1" | grep -Po "((http|https):\/\/)?(([\w.-]*)\.([\w]*)\.([A-z]))\w+" | sort -u
# Get Subdomains from crt.sh
curl -s "https://crt.sh/?q=%25.$1&output=json" | jq -r '.[].name_value' | sed 's/\*\.//g' | sort -u
# Sort & Tested Domains from Recon.dev
curl "https://recon.dev/api/search?key=apikey&domain=$1" |jq -r '.[].rawDomains[]' | sed 's/ //g' | sort -u |httpx -silent
# Get Subdomains rapiddns.io
curl -s "https://rapiddns.io/subdomain/$1?full=1#result" | grep "<td><a" | cut -d '"' -f 2 | grep http | cut -d '/' -f3 | sed 's/#results//g' | sort -u
# JS Files Finder
assetfinder $1 | gau|egrep -v '(.css|.png|.jpeg|.jpg|.svg|.gif|.wolf)'|while read url; do vars=$(curl -s $url | grep -Eo "var [a-zA-Zo-9_]+" |sed -e 's, 'var','"$url"?',g' -e 's/ //g'|grep -v '.js'|sed 's/.*/&=xss/g'):echo -e "\e[1;33m$url\n" "\e[1;32m$vars";done
# Link Finder
curl -s $1 | grep -Eo "(http|https)://[a-zA-Z0-9./?=_-]*" | sort | uniq | grep ".js" > jslinks.txt; while IFS= read link; do python linkfinder.py -i "$link" -o cli; done < jslinks.txt | grep $2 | grep -v $3 | sort -n | uniq; rm -rf jslinks.txt
# domain-check.sh
chaos -d domain -o dm -silent | httpx -silent | xargs -P100 -I@ gospider -c 30 -t 15 -d 4 -a -H "x-forwarded-for: 127.0.0.1" -H "User-Agent: Mozilla/5.0 (Linux; U; Android 2.2) AppleWebKit/533.1 (KHTML, like Gecko) Version/4.0 Mobile Safari/533.1" -s @
===========================================================
# Subdomain enumeration using all.txt ->
$ ffuf -w JHADDIX-ALL/all.txt -u "https://FUZZ.target.com/" -v | grep "| URL |" | awk '{print $4}'
# Search subdomain using gospider ->
$ gospider -d 0 -s "https://target.com" -c 5 -t 100 -d 5 --blacklist jpg,jpeg,gif,css,tif,tiff,png,ttf,woff,woff2,ico,pdf,svg,txt | grep -Eo '(http|https)://[^/"]+' | anew
# Filter the valid subdomains found ->
$ while read i; do digout=$(dig +short ${i//[$'\t\r\n ']}); if [[ ! -z $digout ]]; then echo ${i//[$'\t\r\n ']}; fi; done < target.com.txt > target.com_valid.txt
# python sub3num.py target.com
python
#!/usr/bin/python
from subprocess import Popen, PIPE
import sys
domain = sys.argv[1]
commands = ['findomain -t '+domain+' -o;subfinder -d '+domain+' -o '+domain+'_subfinder.txt ;assetfinder --subs-only '+domain+' >> '+domain+'_assetfinder.txt;amass enum -d '+domain+' -o '+domain+'_amass.txt ;python ~/Bug-Tools/subbrute/subbrute.py '+domain+' -o '+domain+'_subbrute.txt ;python ~/Bug-Tools/Sublist3r/sublist3r.py -d '+domain+' -o '+domain+'_sublist3r.txt ;cat *.txt | sort -u >> '+domain+'_final_domains.txt ;cat '+domain+'_final_domains.txt | httpx | sort -u >> valid_subs.txt;']
count = 0
processes = []
for com in commands:
print "Start execute commands.."
processes.append(Popen(com, shell=True))
count += 1
print "[OK] command "+str(count)+" running successfully."
else:
print "Finish.."
for i, process in enumerate(processes):
process.wait()
print "Command #{} finished".format(i)
========================================
Resources =>
https://exploitway[.]com/github-dork
# Subdomain Bruteforcer with FFUF
ffuf -u https://FUZZ.$1 -w $2 -v | grep "| URL |" | awk '{print $4}'
# Get Subdomains from Archive
curl -s "http://web.archive.org/cdx/search/cdx?url=*.$1/*&output=text&fl=original&collapse=urlkey" | gsed -e 's_https*://__' -e "s/\/.*//" | sort -u
# Get Subdomains from BufferOver.run
curl -s https://dns.bufferover.run/dns?q=.$1 |jq -r .FDNS_A[]|cut -d',' -f2|sort -u
# Get Subdomains from JLDC
curl -s "https://jldc.me/anubis/subdomains/$1" | grep -Po "((http|https):\/\/)?(([\w.-]*)\.([\w]*)\.([A-z]))\w+" | sort -u
# Extract Subdomains Form riddler.io
curl -s "https://riddler.io/search/exportcsv?q=pld:$1" | grep -Po "(([\w.-]*)\.([\w]*)\.([A-z]))\w+" | sort -u
# Get Subdomains from VirusTotal
curl -s "https://www.virustotal.com/ui/domains/domain.com/subdomains?limit=40" | grep -Po "((http|https):\/\/)?(([\w.-]*)\.([\w]*)\.([A-z]))\w+" | sort -u
# Get Subdomains from certpostter
curl -s "https://certspotter.com/api/v0/certs?domain=$1" | grep -Po "((http|https):\/\/)?(([\w.-]*)\.([\w]*)\.([A-z]))\w+" | sort -u
# Get Subdomains from crt.sh
curl -s "https://crt.sh/?q=%25.$1&output=json" | jq -r '.[].name_value' | sed 's/\*\.//g' | sort -u
# Sort & Tested Domains from Recon.dev
curl "https://recon.dev/api/search?key=apikey&domain=$1" |jq -r '.[].rawDomains[]' | sed 's/ //g' | sort -u |httpx -silent
# Get Subdomains rapiddns.io
curl -s "https://rapiddns.io/subdomain/$1?full=1#result" | grep "<td><a" | cut -d '"' -f 2 | grep http | cut -d '/' -f3 | sed 's/#results//g' | sort -u
# JS Files Finder
assetfinder $1 | gau|egrep -v '(.css|.png|.jpeg|.jpg|.svg|.gif|.wolf)'|while read url; do vars=$(curl -s $url | grep -Eo "var [a-zA-Zo-9_]+" |sed -e 's, 'var','"$url"?',g' -e 's/ //g'|grep -v '.js'|sed 's/.*/&=xss/g'):echo -e "\e[1;33m$url\n" "\e[1;32m$vars";done
# Link Finder
curl -s $1 | grep -Eo "(http|https)://[a-zA-Z0-9./?=_-]*" | sort | uniq | grep ".js" > jslinks.txt; while IFS= read link; do python linkfinder.py -i "$link" -o cli; done < jslinks.txt | grep $2 | grep -v $3 | sort -n | uniq; rm -rf jslinks.txt
# domain-check.sh
chaos -d domain -o dm -silent | httpx -silent | xargs -P100 -I@ gospider -c 30 -t 15 -d 4 -a -H "x-forwarded-for: 127.0.0.1" -H "User-Agent: Mozilla/5.0 (Linux; U; Android 2.2) AppleWebKit/533.1 (KHTML, like Gecko) Version/4.0 Mobile Safari/533.1" -s @
===========================================================
# Subdomain enumeration using all.txt ->
$ ffuf -w JHADDIX-ALL/all.txt -u "https://FUZZ.target.com/" -v | grep "| URL |" | awk '{print $4}'
# Search subdomain using gospider ->
$ gospider -d 0 -s "https://target.com" -c 5 -t 100 -d 5 --blacklist jpg,jpeg,gif,css,tif,tiff,png,ttf,woff,woff2,ico,pdf,svg,txt | grep -Eo '(http|https)://[^/"]+' | anew
# Filter the valid subdomains found ->
$ while read i; do digout=$(dig +short ${i//[$'\t\r\n ']}); if [[ ! -z $digout ]]; then echo ${i//[$'\t\r\n ']}; fi; done < target.com.txt > target.com_valid.txt
# python sub3num.py target.com
python
#!/usr/bin/python
from subprocess import Popen, PIPE
import sys
domain = sys.argv[1]
commands = ['findomain -t '+domain+' -o;subfinder -d '+domain+' -o '+domain+'_subfinder.txt ;assetfinder --subs-only '+domain+' >> '+domain+'_assetfinder.txt;amass enum -d '+domain+' -o '+domain+'_amass.txt ;python ~/Bug-Tools/subbrute/subbrute.py '+domain+' -o '+domain+'_subbrute.txt ;python ~/Bug-Tools/Sublist3r/sublist3r.py -d '+domain+' -o '+domain+'_sublist3r.txt ;cat *.txt | sort -u >> '+domain+'_final_domains.txt ;cat '+domain+'_final_domains.txt | httpx | sort -u >> valid_subs.txt;']
count = 0
processes = []
for com in commands:
print "Start execute commands.."
processes.append(Popen(com, shell=True))
count += 1
print "[OK] command "+str(count)+" running successfully."
else:
print "Finish.."
for i, process in enumerate(processes):
process.wait()
print "Command #{} finished".format(i)
========================================
Resources =>
https://exploitway[.]com/github-dork
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe — Ninja Skills
https://cdn-images-1.medium.com/max/1280/0*DyDTxgOQlA-i79l9.png
Having fun with TryHackMe again. So, here is the write up and guideline to pass this Bounty Hacker challenge.
Continue reading on Medium »
TryHackMe — Ninja Skills
https://cdn-images-1.medium.com/max/1280/0*DyDTxgOQlA-i79l9.png
Having fun with TryHackMe again. So, here is the write up and guideline to pass this Bounty Hacker challenge.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Backdoor
https://cdn-images-1.medium.com/max/953/1*LhRmw3ZSy22AfuFlwCF9Tw.png
Hackfreaks Official. Author’s content.
Continue reading on Medium »
Backdoor
https://cdn-images-1.medium.com/max/953/1*LhRmw3ZSy22AfuFlwCF9Tw.png
Hackfreaks Official. Author’s content.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
These are the Dangers of Social Media Hacking
https://cdn-images-1.medium.com/max/2000/1*bblC8aOmsNydyeAle8KttQ.jpeg
People are losing more than money.
Continue reading on Medium »
These are the Dangers of Social Media Hacking
https://cdn-images-1.medium.com/max/2000/1*bblC8aOmsNydyeAle8KttQ.jpeg
People are losing more than money.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Why Application Security is the Key to Your App’s Safety
https://cdn-images-1.medium.com/max/2600/0*PzycBFIYM2J9hR2B
Stepping into new era of vulnerabilities & possibilities
Continue reading on Brandlitic »
Why Application Security is the Key to Your App’s Safety
https://cdn-images-1.medium.com/max/2600/0*PzycBFIYM2J9hR2B
Stepping into new era of vulnerabilities & possibilities
Continue reading on Brandlitic »
Cross Site Scripting (XSS) in Webmail Calender in IceWarp WebClient (CVE-2020–25925)
https://ashketchum.medium.com/cross-site-scripting-xss-in-webmail-calender-in-icewarp-webclient-cve-2020-25925-67e1cbc40bd9?source=rss------bug_bounty-5
https://ashketchum.medium.com/cross-site-scripting-xss-in-webmail-calender-in-icewarp-webclient-cve-2020-25925-67e1cbc40bd9?source=rss------bug_bounty-5