Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking NitroRansomware Asks for Discord Gift Codes, Steals Access Tokens https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg NitroRansomware Asks for Discord Gift Codes, Steals Access TokensPost…
the cybercriminals behind the cache. The starting bidding price of the stolen gift cards was $10,000, with a “buy now” price of $20,000. The gift cards were bought by another cybercriminal soon after the cards were posted for sale, according to the firm.
“Typically, compromised gift cards sell for 10 percent of the card value in the Dark Web; however, the 895,000 cards offered from the breach were priced at roughly 0.05 percent of the card value,” according to Gemini, in an early April report. This discrepancy likely means the gift cards were potentially carrying low balances, it added.
When it comes to monetization, cybercriminals basically have two options, according to Gemini: Purchase actual goods and resell them; or, sell the cards to a third-party gift card marketplace as in the example above. “In [one] scheme, cybercriminals would use stolen payment cards to purchase gift cards and then sell the gift cards to Cardpool [a carding marketplace],” according to the report. “If a bank were to determine that the gift card had been purchased with a stolen payment card, they could connect with the merchant bank or gift card vendors that issued the gift card and request they void the gift card. Unfortunately, this process can prove cumbersome and time-consuming, making it a rare occurrence and granting cybercriminals a wider time window to pull off their scheme.”
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Untitled-design-10-90x90.png WordPress could treat Google FloC as a security issue1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Crypto_Mining_Bitcoin-90x90.jpg Attackers Target ProxyLogon Exploit to Install Cryptojacker4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/patchtues1-90x90.jpg Microsoft to Patch multiple Zero-Days, 110 vulnerabilities in total5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Google-Chrome-Browser-90x90.jpg Chrome Zero-Day Exploit Posted on Twitter6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Clubhouse2-e1618258606781-90x90.png 1.3M Clubhouse Users’ Data Dumped in Hacker Forum for Free1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/linkedin-90x90.png Data from 500M LinkedIn Users Posted for Sale Online1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/cisco-patch-90x90.png Zero-Day Bug Impacts Problem-Plagued Cisco SOHO Routers2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/google-play-90x90.jpg Fake Netflix App on Google Play Spreads Malware Via WhatsApp2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/vmware-patch-90x90.jpg Critical Cloud Bug in VMWare Carbon Black Allows Takeover2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/eggs-chickens-e1617650984482-90x90.jpg LinkedIn Spear-Phishing Campaign Targets Job Hunters2 weeks ago
The post NitroRansomware Asks for Discord Gift Codes, Steals Access Tokens first appeared on Black Hat Ethical Hacking.
“Typically, compromised gift cards sell for 10 percent of the card value in the Dark Web; however, the 895,000 cards offered from the breach were priced at roughly 0.05 percent of the card value,” according to Gemini, in an early April report. This discrepancy likely means the gift cards were potentially carrying low balances, it added.
When it comes to monetization, cybercriminals basically have two options, according to Gemini: Purchase actual goods and resell them; or, sell the cards to a third-party gift card marketplace as in the example above. “In [one] scheme, cybercriminals would use stolen payment cards to purchase gift cards and then sell the gift cards to Cardpool [a carding marketplace],” according to the report. “If a bank were to determine that the gift card had been purchased with a stolen payment card, they could connect with the merchant bank or gift card vendors that issued the gift card and request they void the gift card. Unfortunately, this process can prove cumbersome and time-consuming, making it a rare occurrence and granting cybercriminals a wider time window to pull off their scheme.”
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Untitled-design-10-90x90.png WordPress could treat Google FloC as a security issue1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Crypto_Mining_Bitcoin-90x90.jpg Attackers Target ProxyLogon Exploit to Install Cryptojacker4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/patchtues1-90x90.jpg Microsoft to Patch multiple Zero-Days, 110 vulnerabilities in total5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Google-Chrome-Browser-90x90.jpg Chrome Zero-Day Exploit Posted on Twitter6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Clubhouse2-e1618258606781-90x90.png 1.3M Clubhouse Users’ Data Dumped in Hacker Forum for Free1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/linkedin-90x90.png Data from 500M LinkedIn Users Posted for Sale Online1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/cisco-patch-90x90.png Zero-Day Bug Impacts Problem-Plagued Cisco SOHO Routers2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/google-play-90x90.jpg Fake Netflix App on Google Play Spreads Malware Via WhatsApp2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/vmware-patch-90x90.jpg Critical Cloud Bug in VMWare Carbon Black Allows Takeover2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/eggs-chickens-e1617650984482-90x90.jpg LinkedIn Spear-Phishing Campaign Targets Job Hunters2 weeks ago
The post NitroRansomware Asks for Discord Gift Codes, Steals Access Tokens first appeared on Black Hat Ethical Hacking.
Reproxy - Simple Edge Server / Reverse Proxy
http://www.kitploit.com/2021/04/reproxy-simple-edge-server-reverse-proxy.html
http://www.kitploit.com/2021/04/reproxy-simple-edge-server-reverse-proxy.html
Reproxy is a simple edge HTTP(s) server / reverse proxy supporting various providers (docker, static, file). One or more providers supply information about requested server, requested url, destination url and health check url. Distributed as a single binary or as a docker container. Automatic SSL termination with Let's Encrypt (https://letsencrypt.org/) Support of user-provided SSL certificates Simple but flexible proxy rules Static, command line (https://www.kitploit.com/search/label/Command%20Line) proxy rules provider Dynamic, file-based proxy rules provider Docker provider with an automatic discovery Optional traffic compression User-defined limits and timeouts Single binary distribution Docker container distribution Built-in static assets server
Server can be set as FQDN, i.e. s.example.com or * (catch all). Requested url can be regex, for example ^/api/(.*) and destination url may have regex matched groups in, i.e. http://d.example.com:8080/$1. For the example above http://s.example.com/api/something?foo=bar will be proxied to http://d.example.com:8080/something?foo=bar. For convenience, requests with the trailing / and without regex groups expanded to /(.*), and destinations in those cases expanded to /$1. I.e. /api/ -> http://127.0.0.1/service will be translated to ^/api/(.*) -> http://127.0.0.1/service/$1 Both HTTP and HTTPS supported. For HTTPS, static certificate can be used as well as automated ACME (Let's Encrypt) certificates. Optional assets server can be used to serve static files. Starting reproxy requires at least one provider defined. The rest of parameters are strictly optional and have sane default. Example with a static provider: reproxy --static.enabled --static.rule="example.com/api/(.*),https://api.example.com/$1" Example with an automatic docker discovery: reproxy --docker.enabled --docker.auto
Install
for a binary distribution pick the proper file in the release section (https://github.com/umputun/reproxy/releases) docker container available on Docker Hub (https://hub.docker.com/r/umputun/reproxy) as well as on Github (https://github.com/umputun/reproxy/blob/master/ghcr.io/umputun/reproxy)Container (https://www.kitploit.com/search/label/Container) Registry. Latest stable version has :vX.Y.Z tag (with :latest alias) and the current master has :master tag.
Providers
Proxy rules supplied by various providers. Currently included file, docker and static. Each provider may define multiple routing rules for both proxied request and static (assets). User can sets multiple providers at the same time. See examples of various providers in examples (https://github.com/umputun/reproxy/tree/master/examples)
Static
This is the simplest provider defining all mapping rules directly in the command line (or environment). Multiple rules supported. Each rule is 3 or 4 comma-separated elements server,sourceurl,destination,[ping-url]. For example: *,^/api/(.*),https://api.example.com/$1, - proxy all request to any host/server with /api prefix to https://api.example.com example.com,/foo/bar,https://api.example.com/zzz,https://api.example.com/ping - proxy all requests to example.com and with /foo/bar url to https://api.example.com/zzz. Uses https://api.example.com/ping for the health check The last (4th) element defines an optional ping url used for health reporting. I.e.*,^/api/(.*),https://api.example.com/$1,https://api.example.com/ping. See Health check (https://github.com/umputun/reproxy#ping-and-health-checks) section for more details.
File
reproxy --file.enabled --file.name=config.yml Example of config.yml: default: # the same as * (catch-all) server
- { route: "^/api/svc1/(.*)", dest: "http://127.0.0.1:8080/blah1/$1" }
- {
route: "/api/svc3/xyz",
dest: "http://127.0.0.3:8080/blah3/xyz",
"ping": "http://127.0.0.3:8080/ping",
}
srv.example.com:
Server can be set as FQDN, i.e. s.example.com or * (catch all). Requested url can be regex, for example ^/api/(.*) and destination url may have regex matched groups in, i.e. http://d.example.com:8080/$1. For the example above http://s.example.com/api/something?foo=bar will be proxied to http://d.example.com:8080/something?foo=bar. For convenience, requests with the trailing / and without regex groups expanded to /(.*), and destinations in those cases expanded to /$1. I.e. /api/ -> http://127.0.0.1/service will be translated to ^/api/(.*) -> http://127.0.0.1/service/$1 Both HTTP and HTTPS supported. For HTTPS, static certificate can be used as well as automated ACME (Let's Encrypt) certificates. Optional assets server can be used to serve static files. Starting reproxy requires at least one provider defined. The rest of parameters are strictly optional and have sane default. Example with a static provider: reproxy --static.enabled --static.rule="example.com/api/(.*),https://api.example.com/$1" Example with an automatic docker discovery: reproxy --docker.enabled --docker.auto
Install
for a binary distribution pick the proper file in the release section (https://github.com/umputun/reproxy/releases) docker container available on Docker Hub (https://hub.docker.com/r/umputun/reproxy) as well as on Github (https://github.com/umputun/reproxy/blob/master/ghcr.io/umputun/reproxy)Container (https://www.kitploit.com/search/label/Container) Registry. Latest stable version has :vX.Y.Z tag (with :latest alias) and the current master has :master tag.
Providers
Proxy rules supplied by various providers. Currently included file, docker and static. Each provider may define multiple routing rules for both proxied request and static (assets). User can sets multiple providers at the same time. See examples of various providers in examples (https://github.com/umputun/reproxy/tree/master/examples)
Static
This is the simplest provider defining all mapping rules directly in the command line (or environment). Multiple rules supported. Each rule is 3 or 4 comma-separated elements server,sourceurl,destination,[ping-url]. For example: *,^/api/(.*),https://api.example.com/$1, - proxy all request to any host/server with /api prefix to https://api.example.com example.com,/foo/bar,https://api.example.com/zzz,https://api.example.com/ping - proxy all requests to example.com and with /foo/bar url to https://api.example.com/zzz. Uses https://api.example.com/ping for the health check The last (4th) element defines an optional ping url used for health reporting. I.e.*,^/api/(.*),https://api.example.com/$1,https://api.example.com/ping. See Health check (https://github.com/umputun/reproxy#ping-and-health-checks) section for more details.
File
reproxy --file.enabled --file.name=config.yml Example of config.yml: default: # the same as * (catch-all) server
- { route: "^/api/svc1/(.*)", dest: "http://127.0.0.1:8080/blah1/$1" }
- {
route: "/api/svc3/xyz",
dest: "http://127.0.0.3:8080/blah3/xyz",
"ping": "http://127.0.0.3:8080/ping",
}
srv.example.com:
- { route: "^/api/svc2/(.*)", dest: "http://127.0.0.2:8080/blah2/$1/abc" } This is a dynamic provider and file change will be applied automatically.
Docker
Docker provider supports a fully automatic discovery (with --docker.auto) with no extra configuration and by default redirects all requests like https://server//(.*) to the internal IP of the given container and the exposed port. Only active (running) containers (https://www.kitploit.com/search/label/Containers) will be detected. This default can be changed with labels: reproxy.server - server (hostname) to match. Also can be a list of comma-separated servers. reproxy.route - source route (location) reproxy.dest - destination path. Note: this is not full url, but just the path which will be appended to container's ip:port reproxy.port - destination port for the discovered container reproxy.ping - ping path for the destination container. reproxy.enabled - enable (yes, true, 1) or disable (no, false, 0) container from reproxy destinations. Pls note: without --docker.auto the destination container has to have at least one of reproxy.* labels to be considered as a potential destination. With --docker.auto, all containers with exposed port will be considered as routing destinations. There are 3 ways to restrict it: Exclude some containers explicitly with --docker.exclude, i.e. --docker.exclude=c1 --docker.exclude=c2 ... Allow only a particular docker network with --docker.network Set the label reproxy.enabled=false or reproxy.enabled=no or reproxy.enabled=0 This is a dynamic provider and any change in container's status will be applied automatically.
SSL support
SSL mode (by default none) can be set to auto (ACME/LE certificates), static (existing certificate) or none. If auto turned on SSL certificate will be issued automatically for all discovered server names. User can override it by setting --ssl.fqdn value(s)
Logging
By default no request log generated. This can be turned on by setting --logger.enabled. The log (auto-rotated) has Apache Combined Log Format (http://httpd.apache.org/docs/2.2/logs.html#combined) User can also turn stdout log on with --logger.stdout. It won't affect the file logging but will output some minimal info about processed requests, something like this: 2021/04/16 01:17:25.601 [INFO] GET - /echo/image.png - xxx.xxx.xxx.xxx - 200 (155400) - 371.661251ms
2021/04/16 01:18:18.959 [INFO] GET - /api/v1/params - xxx.xxx.xxx.xxx - 200 (74) - 1.217669m
Assets Server
User may turn assets server on (off by default) to serve static files. As long as --assets.location set it will treat every non-proxied request under assets.root as a request for static files. Assets server can be used without any proxy providers. In this mode reproxy acts as a simple web server for a static context. In addition to the common assets server multiple custom static servers supported. Each provider has a different way to define such static rule and some providers may not support it at all. For example, multiple static server make sense in case of static (command line provide), file provider and can be even useful with docker provider. static provider - if source element prefixed by assets: it will be treated as file-server. For example *,assets:/web,/var/www, will serve all /web/* request with a file server on top of /var/www directory. file provider - setting optional field assets: true docker provider - reproxy.assets=web-root:location, i.e. reproxy.assets=/web:/var/www.
More options
--gzip enables gizp compression for responses. --max=N allows to set the maximum size of request (default 64k) --header sets extra header(s) added to each proxied request --timeout.* various timeouts for both server and proxy transport. See timeout section in All Application Options (https://github.com/umputun/reproxy#all-application-options)
Ping and health checks
Docker
Docker provider supports a fully automatic discovery (with --docker.auto) with no extra configuration and by default redirects all requests like https://server//(.*) to the internal IP of the given container and the exposed port. Only active (running) containers (https://www.kitploit.com/search/label/Containers) will be detected. This default can be changed with labels: reproxy.server - server (hostname) to match. Also can be a list of comma-separated servers. reproxy.route - source route (location) reproxy.dest - destination path. Note: this is not full url, but just the path which will be appended to container's ip:port reproxy.port - destination port for the discovered container reproxy.ping - ping path for the destination container. reproxy.enabled - enable (yes, true, 1) or disable (no, false, 0) container from reproxy destinations. Pls note: without --docker.auto the destination container has to have at least one of reproxy.* labels to be considered as a potential destination. With --docker.auto, all containers with exposed port will be considered as routing destinations. There are 3 ways to restrict it: Exclude some containers explicitly with --docker.exclude, i.e. --docker.exclude=c1 --docker.exclude=c2 ... Allow only a particular docker network with --docker.network Set the label reproxy.enabled=false or reproxy.enabled=no or reproxy.enabled=0 This is a dynamic provider and any change in container's status will be applied automatically.
SSL support
SSL mode (by default none) can be set to auto (ACME/LE certificates), static (existing certificate) or none. If auto turned on SSL certificate will be issued automatically for all discovered server names. User can override it by setting --ssl.fqdn value(s)
Logging
By default no request log generated. This can be turned on by setting --logger.enabled. The log (auto-rotated) has Apache Combined Log Format (http://httpd.apache.org/docs/2.2/logs.html#combined) User can also turn stdout log on with --logger.stdout. It won't affect the file logging but will output some minimal info about processed requests, something like this: 2021/04/16 01:17:25.601 [INFO] GET - /echo/image.png - xxx.xxx.xxx.xxx - 200 (155400) - 371.661251ms
2021/04/16 01:18:18.959 [INFO] GET - /api/v1/params - xxx.xxx.xxx.xxx - 200 (74) - 1.217669m
Assets Server
User may turn assets server on (off by default) to serve static files. As long as --assets.location set it will treat every non-proxied request under assets.root as a request for static files. Assets server can be used without any proxy providers. In this mode reproxy acts as a simple web server for a static context. In addition to the common assets server multiple custom static servers supported. Each provider has a different way to define such static rule and some providers may not support it at all. For example, multiple static server make sense in case of static (command line provide), file provider and can be even useful with docker provider. static provider - if source element prefixed by assets: it will be treated as file-server. For example *,assets:/web,/var/www, will serve all /web/* request with a file server on top of /var/www directory. file provider - setting optional field assets: true docker provider - reproxy.assets=web-root:location, i.e. reproxy.assets=/web:/var/www.
More options
--gzip enables gizp compression for responses. --max=N allows to set the maximum size of request (default 64k) --header sets extra header(s) added to each proxied request --timeout.* various timeouts for both server and proxy transport. See timeout section in All Application Options (https://github.com/umputun/reproxy#all-application-options)
Ping and health checks
reproxy provides 2 endpoints for this purpose: /ping responds with pong and indicates what reproxy up and running /health returns 200 OK status if all destination servers responded to their ping request with 200 or 417 Expectation Failed if any of servers responded with non-200 code. It also returns json body with details about passed/failed services.
All Application Options
-l, --listen= listen on host:port (default: 127.0.0.1:8080) [$LISTEN]
-m, --max= max response size (default: 64000) [$MAX_SIZE]
-g, --gzip enable gz compression [$GZIP]
-x, --header= proxy headers [$HEADER]
--signature enable reproxy signature headers [$SIGNATURE]
--dbg debug mode [$DEBUG]
ssl:
--ssl.type=[none|static|auto] ssl (auto) support (default: none) [$SSL_TYPE]
--ssl.cert= path to cert.pem file [$SSL_CERT]
--ssl.key= path to key.pem file [$SSL_KEY]
--ssl.acme-location= dir where certificates (https://www.kitploit.com/search/label/Certificates) will be stored by autocert manager (default: ./var/acme) [$SSL_ACME_LOCATION]
--ssl.acme-email= admin email for certificate notifications [$SSL_ACME_EMAIL]
--ssl.http-port= http port for redirect to https and acme challenge test (default: 80) [$SSL_HTTP_PORT]
--ssl.fqdn= FQDN(s) for ACME certificates [$SSL_ACME_FQDN]
assets:
-a, --assets.location= assets location [$ASSETS_LOCATION]
--assets.root= assets web root (default: /) [$ASSETS_ROOT]
logger:
--logger.stdout enable stdout logging [$LOGGER_STDOUT]
--logger.enabled enable access and error rotated logs [$LOGGER_ENABLED]
--logger.file= location of access log (default: access.log) [$LOGGER_FILE]
--logger.max-size= maximum size in megabytes before it gets rotated (default: 100) [$LOGGER_MAX_SIZE]
--logger.max-backups= maximum number of old log files to retain (default: 10) [$LOGGER_MAX_BACKUPS]
dock er:
--docker.enabled enable docker provider [$DOCKER_ENABLED]
--docker.host= docker host (default: unix:///var/run/docker.sock) [$DOCKER_HOST]
--docker.network= docker network [$DOCKER_NETWORK]
--docker.exclude= excluded containers [$DOCKER_EXCLUDE]
--docker.auto enable automatic routing (without labels) [$DOCKER_AUTO]
file:
--file.enabled enable file provider [$FILE_ENABLED]
--file.name= file name (default: reproxy.yml) [$FILE_NAME]
--file.interval= file check interval (default: 3s) [$FILE_INTERVAL]
--file.delay= file event delay (default: 500ms) [$FILE_DELAY]
static:
--static.enabled enable static provider [$STATIC_ENABLED]
--static.rule= routing rules [$STATIC_RULES]
timeout:
--tim eout.read-header= read header server timeout (default: 5s) [$TIMEOUT_READ_HEADER]
--timeout.write= write server timeout (default: 30s) [$TIMEOUT_WRITE]
--timeout.idle= idle server timeout (default: 30s) [$TIMEOUT_IDLE]
--timeout.dial= dial transport timeout (default: 30s) [$TIMEOUT_DIAL]
--timeout.keep-alive= keep-alive transport timeout (default: 30s) [$TIMEOUT_KEEP_ALIVE]
--timeout.resp-header= response header transport timeout (default: 5s) [$TIMEOUT_RESP_HEADER]
--timeout.idle-conn= idle connection transport timeout (default: 90s) [$TIMEOUT_IDLE_CONN]
--timeout.tls= TLS hanshake transport timeout (default: 10s) [$TIMEOUT_TLS]
All Application Options
-l, --listen= listen on host:port (default: 127.0.0.1:8080) [$LISTEN]
-m, --max= max response size (default: 64000) [$MAX_SIZE]
-g, --gzip enable gz compression [$GZIP]
-x, --header= proxy headers [$HEADER]
--signature enable reproxy signature headers [$SIGNATURE]
--dbg debug mode [$DEBUG]
ssl:
--ssl.type=[none|static|auto] ssl (auto) support (default: none) [$SSL_TYPE]
--ssl.cert= path to cert.pem file [$SSL_CERT]
--ssl.key= path to key.pem file [$SSL_KEY]
--ssl.acme-location= dir where certificates (https://www.kitploit.com/search/label/Certificates) will be stored by autocert manager (default: ./var/acme) [$SSL_ACME_LOCATION]
--ssl.acme-email= admin email for certificate notifications [$SSL_ACME_EMAIL]
--ssl.http-port= http port for redirect to https and acme challenge test (default: 80) [$SSL_HTTP_PORT]
--ssl.fqdn= FQDN(s) for ACME certificates [$SSL_ACME_FQDN]
assets:
-a, --assets.location= assets location [$ASSETS_LOCATION]
--assets.root= assets web root (default: /) [$ASSETS_ROOT]
logger:
--logger.stdout enable stdout logging [$LOGGER_STDOUT]
--logger.enabled enable access and error rotated logs [$LOGGER_ENABLED]
--logger.file= location of access log (default: access.log) [$LOGGER_FILE]
--logger.max-size= maximum size in megabytes before it gets rotated (default: 100) [$LOGGER_MAX_SIZE]
--logger.max-backups= maximum number of old log files to retain (default: 10) [$LOGGER_MAX_BACKUPS]
dock er:
--docker.enabled enable docker provider [$DOCKER_ENABLED]
--docker.host= docker host (default: unix:///var/run/docker.sock) [$DOCKER_HOST]
--docker.network= docker network [$DOCKER_NETWORK]
--docker.exclude= excluded containers [$DOCKER_EXCLUDE]
--docker.auto enable automatic routing (without labels) [$DOCKER_AUTO]
file:
--file.enabled enable file provider [$FILE_ENABLED]
--file.name= file name (default: reproxy.yml) [$FILE_NAME]
--file.interval= file check interval (default: 3s) [$FILE_INTERVAL]
--file.delay= file event delay (default: 500ms) [$FILE_DELAY]
static:
--static.enabled enable static provider [$STATIC_ENABLED]
--static.rule= routing rules [$STATIC_RULES]
timeout:
--tim eout.read-header= read header server timeout (default: 5s) [$TIMEOUT_READ_HEADER]
--timeout.write= write server timeout (default: 30s) [$TIMEOUT_WRITE]
--timeout.idle= idle server timeout (default: 30s) [$TIMEOUT_IDLE]
--timeout.dial= dial transport timeout (default: 30s) [$TIMEOUT_DIAL]
--timeout.keep-alive= keep-alive transport timeout (default: 30s) [$TIMEOUT_KEEP_ALIVE]
--timeout.resp-header= response header transport timeout (default: 5s) [$TIMEOUT_RESP_HEADER]
--timeout.idle-conn= idle connection transport timeout (default: 90s) [$TIMEOUT_IDLE_CONN]
--timeout.tls= TLS hanshake transport timeout (default: 10s) [$TIMEOUT_TLS]
--timeout.continue= expect continue transport timeout (default: 1s) [$TIMEOUT_CONTINUE]
Help Options:
-h, --help Show this help message
Status
The project is under active development and may have breaking changes till v1 released.
Download Reproxy (https://github.com/umputun/reproxy)
Help Options:
-h, --help Show this help message
Status
The project is under active development and may have breaking changes till v1 released.
Download Reproxy (https://github.com/umputun/reproxy)
hacking: security in practice
I'd like to pay someone to retrieve a software code
Hi,
I'm a totally incompetent guy in hacking, and don't worry what i'm not going to ask something with bad intentions
Would it be possible to hack a sound software, retrieve the code to be able to apply it to any headphones ?
I have this Logitech Headset that comes with Surround sound treatment on the Windws software, and to my ears it sounds incredible. However my headset is old and dying and I tryed maybe a dozen of headphones (gaming to audiophile ones) and none of them sound the same as my Logitech. It's due to tue "surround" post treatment logitech applies, on honestly it's the best of the market to me, it provides an incredible soundstage and from what i've heard, it's because it deletes several frequencies to trick our brains, creating a virtualy wider soundstage than any other headphones.
That's why I'm thinking about that, would it be possible on the paper ?
submitted by /u/Boutarzi
[link] [comments]
I'd like to pay someone to retrieve a software code
Hi,
I'm a totally incompetent guy in hacking, and don't worry what i'm not going to ask something with bad intentions
Would it be possible to hack a sound software, retrieve the code to be able to apply it to any headphones ?
I have this Logitech Headset that comes with Surround sound treatment on the Windws software, and to my ears it sounds incredible. However my headset is old and dying and I tryed maybe a dozen of headphones (gaming to audiophile ones) and none of them sound the same as my Logitech. It's due to tue "surround" post treatment logitech applies, on honestly it's the best of the market to me, it provides an incredible soundstage and from what i've heard, it's because it deletes several frequencies to trick our brains, creating a virtualy wider soundstage than any other headphones.
That's why I'm thinking about that, would it be possible on the paper ?
submitted by /u/Boutarzi
[link] [comments]
reddit
I'd like to pay someone to retrieve a software code
Hi, I'm a totally incompetent guy in hacking, and don't worry what i'm not going to ask something with bad intentions Would it be possible to...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
SNOWCRASH : A Polyglot Payload Generator
SNOWCRASH creates a script that can be launched on both Linux and Windows machines. Payload selected by the user (in this case combined Bash and Powershell code) is embedded into a single polyglot template, which is platform-agnostic. There are few payloads available, including command execution, reverse shell establishment, binary execution and some more :> Basic […]
The post SNOWCRASH : A Polyglot Payload Generator appeared first on Kali Linux Tutorials.
SNOWCRASH : A Polyglot Payload Generator
SNOWCRASH creates a script that can be launched on both Linux and Windows machines. Payload selected by the user (in this case combined Bash and Powershell code) is embedded into a single polyglot template, which is platform-agnostic. There are few payloads available, including command execution, reverse shell establishment, binary execution and some more :> Basic […]
The post SNOWCRASH : A Polyglot Payload Generator appeared first on Kali Linux Tutorials.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
New attack on SMS and we are still using it for Two-Factor Authentication
https://cdn-images-1.medium.com/max/600/1*HqjJIV6sA_xYR8RItzh5Jg.jpeg
The first and foremost thing to state here, is 80% of the population suffer from what social psychologist call Optimism Bias. Otherwise…
Continue reading on Medium »
New attack on SMS and we are still using it for Two-Factor Authentication
https://cdn-images-1.medium.com/max/600/1*HqjJIV6sA_xYR8RItzh5Jg.jpeg
The first and foremost thing to state here, is 80% of the population suffer from what social psychologist call Optimism Bias. Otherwise…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Creating an undetectable backdoor with Shellter
https://cdn-images-1.medium.com/max/1260/1*TimSBOQm2I9c-MPSav3izA.jpeg
Shellter is equipped for re-encoding any local 32-bit independent Windows application. Since we are endeavoring to stay away from…
Continue reading on Purple TEAM »
Creating an undetectable backdoor with Shellter
https://cdn-images-1.medium.com/max/1260/1*TimSBOQm2I9c-MPSav3izA.jpeg
Shellter is equipped for re-encoding any local 32-bit independent Windows application. Since we are endeavoring to stay away from…
Continue reading on Purple TEAM »
Hacking Articles Tips Tricks Videos Tutorials pinned «Hacking on Medium Advanced Phishing Email — When Protective AI May Harm One popular technique we hear a lot on corporate and college courses on phishing is that there are certain patterns with phishing emails… Continue reading on Medium »»
Hacking Articles Tips Tricks Videos Tutorials pinned «Kali Linux Tutorials SNOWCRASH : A Polyglot Payload Generator SNOWCRASH creates a script that can be launched on both Linux and Windows machines. Payload selected by the user (in this case combined Bash and Powershell code) is embedded into a single polyglot…»
Hacking Articles Tips Tricks Videos Tutorials pinned «Hacking on Medium Creating an undetectable backdoor with Shellter https://cdn-images-1.medium.com/max/1260/1*TimSBOQm2I9c-MPSav3izA.jpeg Shellter is equipped for re-encoding any local 32-bit independent Windows application. Since we are endeavoring to stay…»
Forwarded from Torrent Leaks
Free Course Site
Become a Web Developer from Scratch
https://freecoursesite.com/wp-content/uploads/2019/03/11174_cbb1_116.jpg
This course covers all you need to know about becoming a top skilled web developer even if you never programmed before! What you’ll learn “The Complete Freelancer Guide” e-Book Certificate of Completion 30 Free Responsive Templates Awesome Portfolio Website Make REAL life web apps with our final projects Coding Exercises and Challenges PDF Manuals and […]
The post Become a Web Developer from Scratch appeared first on Free Course Site.
Become a Web Developer from Scratch
https://freecoursesite.com/wp-content/uploads/2019/03/11174_cbb1_116.jpg
This course covers all you need to know about becoming a top skilled web developer even if you never programmed before! What you’ll learn “The Complete Freelancer Guide” e-Book Certificate of Completion 30 Free Responsive Templates Awesome Portfolio Website Make REAL life web apps with our final projects Coding Exercises and Challenges PDF Manuals and […]
The post Become a Web Developer from Scratch appeared first on Free Course Site.
Forwarded from Torrent Leaks
FreeCourseSite – Download Udemy Paid Courses For Free
I2C Communication between Arduino and Raspberry Pi
I2C Communication between Arduino and Raspberry Pi
Arduino and Raspberry Pi Communication with I2C Bus: A step by step guide to Master I2C Protocol and Communicate Easily
What you’ll learn
I2C Communication between Arduino and Raspberry Pi
*
Quick Overview
*
What is I²C and how it works
*
What You Need to Get things done
*
I2C Communication Protocol
*
Device Address Mapping
*
How to code I²C the right way and how to talk to multiple devices easily
*
Code and Circuit Schematics to connect Arduino and Raspberry Pi
*
Communication Protocol between Raspberry Pi and Arduino
*
Tips and Tricks
*
Advantages of I²C and Disadvantages of I²C
*
I²C Operation
*
Main I²C Bus Library Functions
*
How to implement I²C in your project
*
What is the difference between I²C and other communication methods
*
Why using I²C will make your life easier
Requirements
*
Internet Connection
*
Computer, Laptop, Mac, or Chrome device
*
Basic knowledge in C Programming language
Description
I²C (pronounced I-squared-C)
I2C Communication between Arduino and Raspberry Pi: A step by step guide to Master I2C Protocol and Start using it to connect your Arduino and Raspberry Pi
I²C Allows communication of data between I2C devices over two wires. which makes it easier for anyone to exchange information without too much wiring.
In today’s world, every electronics hobbyist works with Arduino and Raspberry Pi to do his projects. With the introduction of Windows 10 IoT Core, Microsoft is also into the embedded world. Today Internet Of Things is a buzzword, but for basic things, we need an Arduino to communicate with a Raspberry Pi. In this course, I will explain how to communicate the Arduino with the Pi using an I2C bus and Windows 10 IoT Core.
I2C communications have become the de facto method of communicating between microcontrollers, microcomputers, and a variety of integrated circuits and sensors. It has been around since 1982 and was originally developed for use in television receivers.
What You Will Learn in This Course:
* What is I²C and how it works
* How to implement I²C in your project
* Why using I²C will make your life easier
* What is the difference between I²C and other communication methods
* Connect to multiple devices easily via I²C the right way
* The advantages and disadvantages of using I²C
* How to code I²C the right way and how to talk to multiple devices easily
* Communication Protocol between Raspberry Pi and Arduino
Who this course is for:
* Anyone Interested in Learning I2C Communication between Arduino and Raspberry Pi
* Anyone Interested in Learning I2C Communication in A Step by Step Manner
* Wo anyone Interested in Learning Arduino I2C Communication
* Anyone Interested in Learning Raspberry Pi I2C Communication
* Anyone interested in talking to multiple devices easily via I²C the right way
* Who anyone Interested in Interfacing Arduino with other ICs or devices via I²C
* Anyone Interested in Controlling different devices using I²C Protocol
* Arduino Lovers
* Raspberry Pi Lovers
* Last updated 3/2021
Content From: https://www.udemy.com/course/i2c-communication-between-arduino-and-raspberry-pi/
Top 5 Awesome Raspberry Pi Projects
Download Now
The post I2C Communication between Arduino and Raspberry Pi appeared first on FreeCourseSite - Download Udemy Paid Courses For Free.
I2C Communication between Arduino and Raspberry Pi
I2C Communication between Arduino and Raspberry Pi
Arduino and Raspberry Pi Communication with I2C Bus: A step by step guide to Master I2C Protocol and Communicate Easily
What you’ll learn
I2C Communication between Arduino and Raspberry Pi
*
Quick Overview
*
What is I²C and how it works
*
What You Need to Get things done
*
I2C Communication Protocol
*
Device Address Mapping
*
How to code I²C the right way and how to talk to multiple devices easily
*
Code and Circuit Schematics to connect Arduino and Raspberry Pi
*
Communication Protocol between Raspberry Pi and Arduino
*
Tips and Tricks
*
Advantages of I²C and Disadvantages of I²C
*
I²C Operation
*
Main I²C Bus Library Functions
*
How to implement I²C in your project
*
What is the difference between I²C and other communication methods
*
Why using I²C will make your life easier
Requirements
*
Internet Connection
*
Computer, Laptop, Mac, or Chrome device
*
Basic knowledge in C Programming language
Description
I²C (pronounced I-squared-C)
I2C Communication between Arduino and Raspberry Pi: A step by step guide to Master I2C Protocol and Start using it to connect your Arduino and Raspberry Pi
I²C Allows communication of data between I2C devices over two wires. which makes it easier for anyone to exchange information without too much wiring.
In today’s world, every electronics hobbyist works with Arduino and Raspberry Pi to do his projects. With the introduction of Windows 10 IoT Core, Microsoft is also into the embedded world. Today Internet Of Things is a buzzword, but for basic things, we need an Arduino to communicate with a Raspberry Pi. In this course, I will explain how to communicate the Arduino with the Pi using an I2C bus and Windows 10 IoT Core.
I2C communications have become the de facto method of communicating between microcontrollers, microcomputers, and a variety of integrated circuits and sensors. It has been around since 1982 and was originally developed for use in television receivers.
What You Will Learn in This Course:
* What is I²C and how it works
* How to implement I²C in your project
* Why using I²C will make your life easier
* What is the difference between I²C and other communication methods
* Connect to multiple devices easily via I²C the right way
* The advantages and disadvantages of using I²C
* How to code I²C the right way and how to talk to multiple devices easily
* Communication Protocol between Raspberry Pi and Arduino
Who this course is for:
* Anyone Interested in Learning I2C Communication between Arduino and Raspberry Pi
* Anyone Interested in Learning I2C Communication in A Step by Step Manner
* Wo anyone Interested in Learning Arduino I2C Communication
* Anyone Interested in Learning Raspberry Pi I2C Communication
* Anyone interested in talking to multiple devices easily via I²C the right way
* Who anyone Interested in Interfacing Arduino with other ICs or devices via I²C
* Anyone Interested in Controlling different devices using I²C Protocol
* Arduino Lovers
* Raspberry Pi Lovers
* Last updated 3/2021
Content From: https://www.udemy.com/course/i2c-communication-between-arduino-and-raspberry-pi/
Top 5 Awesome Raspberry Pi Projects
Download Now
The post I2C Communication between Arduino and Raspberry Pi appeared first on FreeCourseSite - Download Udemy Paid Courses For Free.
Forwarded from Torrent Leaks
Download Free Courses
Tool Building with Windows PowerShell – Advanced
https://s3.eu-central-1.wasabisys.com/courseupload/2021/03/Screen-Shot-2021-03-16-at-2.24.50-PM.png Tool Building with Windows PowerShell – Advanced — Udemy — Last updated 1/2021 — Free download
Learn core scripting skills and many more features of too building in Windows Powershell.
What you’ll learn
*
Tool building to automate administrative tasks
*
Core scripting skills
*
Building advanced functions
*
Creating script modules
*
Writing controller scripts
*
Error handling
*
Debugging
Requirements
*
Experience with Windows client administration, maintenance, and troubleshooting. Experience with Windows networking technologies and implementation. Foundational knowledge of Windows PowerShell, including one-liners, scripting security, and PowerShell scripting constructs.
Description
This Intellezy course, taught by Shawn Stugart, builds on existing PowerShell 5.1 skills and course and focuses on tool building to automate administrative tasks. Students will learn core scripting skills such as building advanced functions, creating script modules, writing controller scripts, and error handling and debugging. Working beyond native PowerShell commands, students will be introduced to technologies and concepts to support custom tool building such as .NET Framework, ReST API, XML and JSON, Desired State Configuration (DSC), Just Enough Administration (JEA), and parallelization.
With nearly 10,000 training videos available for desktop applications, technical concepts, and business skills that comprise hundreds of courses, Intellezy has many of the videos and courses you and your workforce needs to stay relevent and take your skills to the next level. Our video content is engaging and offers assessments that can be used to test knowledge levels pre and/or post course. Our training content is also frequently refreshed to keep current with changes in the software. This ensures you and your employees get the most up-to-date information and techniques for success. And, because our video development is in-house, we can adapt quickly and create custom content for a more exclusive approach to software and computer system roll-outs.
Like most of our courses, closed caption subtitles are available for this course in: Arabic, English, Simplified Chinese, German, Russian, Portuguese (Brazil), Japanese, Spanish (Latin America), Hindi, and French.
Who this course is for:
* Anyone who wishes to learn how to build tools within Windows PowerShell
DOWNLOAD
https://sundryshare.com/themes/flow/images/file_icons/32px/rar.png Tool Building with Windows PowerShell – Advanced.part1.rar (2.93 GB)
sundryshare.com/2iHB https://sundryshare.com/themes/flow/images/group.png https://sundryshare.com/themes/flow/images/download_icon.png https://sundryshare.com/themes/flow/images/file_icons/32px/rar.png Tool Building with Windows PowerShell – Advanced.part2.rar (2.93 GB)
sundryshare.com/2iHC https://sundryshare.com/themes/flow/images/group.png https://sundryshare.com/themes/flow/images/download_icon.png https://sundryshare.com/themes/flow/images/file_icons/32px/rar.png Tool Building with Windows PowerShell – Advanced.part3.rar (1.90 GB)
sundryshare.com/2iHE https://sundryshare.com/themes/flow/images/group.png https://sundryshare.com/themes/flow/images/download_icon.png
Course Content: https://www.udemy.com/course/tool-building[...]
Tool Building with Windows PowerShell – Advanced
https://s3.eu-central-1.wasabisys.com/courseupload/2021/03/Screen-Shot-2021-03-16-at-2.24.50-PM.png Tool Building with Windows PowerShell – Advanced — Udemy — Last updated 1/2021 — Free download
Learn core scripting skills and many more features of too building in Windows Powershell.
What you’ll learn
*
Tool building to automate administrative tasks
*
Core scripting skills
*
Building advanced functions
*
Creating script modules
*
Writing controller scripts
*
Error handling
*
Debugging
Requirements
*
Experience with Windows client administration, maintenance, and troubleshooting. Experience with Windows networking technologies and implementation. Foundational knowledge of Windows PowerShell, including one-liners, scripting security, and PowerShell scripting constructs.
Description
This Intellezy course, taught by Shawn Stugart, builds on existing PowerShell 5.1 skills and course and focuses on tool building to automate administrative tasks. Students will learn core scripting skills such as building advanced functions, creating script modules, writing controller scripts, and error handling and debugging. Working beyond native PowerShell commands, students will be introduced to technologies and concepts to support custom tool building such as .NET Framework, ReST API, XML and JSON, Desired State Configuration (DSC), Just Enough Administration (JEA), and parallelization.
With nearly 10,000 training videos available for desktop applications, technical concepts, and business skills that comprise hundreds of courses, Intellezy has many of the videos and courses you and your workforce needs to stay relevent and take your skills to the next level. Our video content is engaging and offers assessments that can be used to test knowledge levels pre and/or post course. Our training content is also frequently refreshed to keep current with changes in the software. This ensures you and your employees get the most up-to-date information and techniques for success. And, because our video development is in-house, we can adapt quickly and create custom content for a more exclusive approach to software and computer system roll-outs.
Like most of our courses, closed caption subtitles are available for this course in: Arabic, English, Simplified Chinese, German, Russian, Portuguese (Brazil), Japanese, Spanish (Latin America), Hindi, and French.
Who this course is for:
* Anyone who wishes to learn how to build tools within Windows PowerShell
DOWNLOAD
https://sundryshare.com/themes/flow/images/file_icons/32px/rar.png Tool Building with Windows PowerShell – Advanced.part1.rar (2.93 GB)
sundryshare.com/2iHB https://sundryshare.com/themes/flow/images/group.png https://sundryshare.com/themes/flow/images/download_icon.png https://sundryshare.com/themes/flow/images/file_icons/32px/rar.png Tool Building with Windows PowerShell – Advanced.part2.rar (2.93 GB)
sundryshare.com/2iHC https://sundryshare.com/themes/flow/images/group.png https://sundryshare.com/themes/flow/images/download_icon.png https://sundryshare.com/themes/flow/images/file_icons/32px/rar.png Tool Building with Windows PowerShell – Advanced.part3.rar (1.90 GB)
sundryshare.com/2iHE https://sundryshare.com/themes/flow/images/group.png https://sundryshare.com/themes/flow/images/download_icon.png
Course Content: https://www.udemy.com/course/tool-building[...]
Forwarded from Torrent Leaks
Download Free Courses
Best Hacking Tools using Termux on Android Part-1
https://courseupload.com/wp-content/uploads/2021/03/Screen-Shot-2021-03-15-at-9.53.18-AM.png Best Hacking Tools using Termux on Android Part-1 — Udemy — Last updated 3/2021 — Free download
Hacking Tools using Termux on Android For Beginners.
What you’ll learn
*
Hacking with Termux
*
Android Hacking For Beginners
Requirements
*
Should have stable internet connection
*
Should have any Mobile phone to run termux
Description
Best Hacking Tools and Techniques using Termux on Android For Beginners:
In this course you will learn about Hacking with an Android device.
I will teach you how to send fake login in pages using termux and how to get their password, Get IP Address Information, SMS Bombing, Call Bombing..etc.
This is for educational purpose only…..because someone might do this with you so be aware. https://s.w.org/images/core/emoji/13.0.1/72x72/1f642.png
I hope it will be a great and interesting session for all of you.
hacker is a computer expert who uses their technical knowledge to achieve a goal or overcome an obstacle, within a computerized system by non-standard means.
Though the term “hacker” has become associated in popular culture with a “security hacker” – someone who utilizes their technical know-how of bugs or exploits to break into computer systems and access data which would otherwise be unavailable to them – hacking can also be utilized by legitimate figures in legal situations. For example, law enforcement agencies sometimes use hacking techniques in order to collect evidence on criminals and other malicious actors. This could include using anonymity tools (such as a VPN, or the dark web) to mask their identities online, posing as criminals themselves.[1][2] Likewise, covert world agencies can employ hacking techniques in the legal conduct of their work. Oppositely, hacking and cyber-attacks are used extra- and illegally by law enforcement and security agencies (conducting warrantless activities), and employed by State actors as a weapon of both legal and illegal warfare.
Who this course is for:
* Beginner in Hacking
DOWNLOAD
Filename: Best Hacking Tools using Termux on Android Part-1.zip (download) Filesize: 421.28 MB
Course Content: https://www.udemy.com/course/best-hacking-tools-using-termux-on-android-part-1/
Best Hacking Tools using Termux on Android Part-1
https://courseupload.com/wp-content/uploads/2021/03/Screen-Shot-2021-03-15-at-9.53.18-AM.png Best Hacking Tools using Termux on Android Part-1 — Udemy — Last updated 3/2021 — Free download
Hacking Tools using Termux on Android For Beginners.
What you’ll learn
*
Hacking with Termux
*
Android Hacking For Beginners
Requirements
*
Should have stable internet connection
*
Should have any Mobile phone to run termux
Description
Best Hacking Tools and Techniques using Termux on Android For Beginners:
In this course you will learn about Hacking with an Android device.
I will teach you how to send fake login in pages using termux and how to get their password, Get IP Address Information, SMS Bombing, Call Bombing..etc.
This is for educational purpose only…..because someone might do this with you so be aware. https://s.w.org/images/core/emoji/13.0.1/72x72/1f642.png
I hope it will be a great and interesting session for all of you.
hacker is a computer expert who uses their technical knowledge to achieve a goal or overcome an obstacle, within a computerized system by non-standard means.
Though the term “hacker” has become associated in popular culture with a “security hacker” – someone who utilizes their technical know-how of bugs or exploits to break into computer systems and access data which would otherwise be unavailable to them – hacking can also be utilized by legitimate figures in legal situations. For example, law enforcement agencies sometimes use hacking techniques in order to collect evidence on criminals and other malicious actors. This could include using anonymity tools (such as a VPN, or the dark web) to mask their identities online, posing as criminals themselves.[1][2] Likewise, covert world agencies can employ hacking techniques in the legal conduct of their work. Oppositely, hacking and cyber-attacks are used extra- and illegally by law enforcement and security agencies (conducting warrantless activities), and employed by State actors as a weapon of both legal and illegal warfare.
Who this course is for:
* Beginner in Hacking
DOWNLOAD
Filename: Best Hacking Tools using Termux on Android Part-1.zip (download) Filesize: 421.28 MB
Course Content: https://www.udemy.com/course/best-hacking-tools-using-termux-on-android-part-1/