Hacking Articles Tips Tricks Videos Tutorials
0*pYLfXGkJ6Y2L7Zz-.gif
Hacking on Medium
DHCP Starvation attacks and DHCP spoofing attacks
https://cdn-images-1.medium.com/max/618/0*pYLfXGkJ6Y2L7Zz-.gif
DHCP Starvation attacks and DHCP spoofing attacks
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
DHCP Starvation attacks and DHCP spoofing attacks
https://cdn-images-1.medium.com/max/618/0*pYLfXGkJ6Y2L7Zz-.gif
DHCP Starvation attacks and DHCP spoofing attacks
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
DHCP Starvation attacks and DHCP spoofing attacks
DHCP Starvation attacks and DHCP spoofing attacks
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe: Encryption — Crypto 101 — Walkthrough
https://cdn-images-1.medium.com/max/701/1*TC3tan-799g-X9tahZYPxg.png
Hi! In this walkthrough I will be covering the encryption room at TryHackMe. I am making these walkthroughs to keep myself motivated to…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TryHackMe: Encryption — Crypto 101 — Walkthrough
https://cdn-images-1.medium.com/max/701/1*TC3tan-799g-X9tahZYPxg.png
Hi! In this walkthrough I will be covering the encryption room at TryHackMe. I am making these walkthroughs to keep myself motivated to…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackMe: Encryption — Crypto 101 — Walkthrough
Hi! In this walkthrough I will be covering the encryption room at TryHackMe. I am making these walkthroughs to keep myself motivated to…
Email Injection leads to open redirect
Hii all i have back with new Hacking story !!.so . 3 days Ago i was hunting on vdp program . i found that hacker can redirect user to on…Continue reading on Medium »
Read more...
Hii all i have back with new Hacking story !!.so . 3 days Ago i was hunting on vdp program . i found that hacker can redirect user to on…Continue reading on Medium »
Read more...
Port Finance Logic Error Bugfix Review
https://medium.com/immunefi/port-finance-logic-error-bugfix-review-29767aced446?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/immunefi/port-finance-logic-error-bugfix-review-29767aced446?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Port Finance Logic Error Bugfix Review
Summary
SummaryContinue reading on Immunefi » (https://medium.com/immunefi/port-finance-logic-error-bugfix-review-29767aced446?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Port Finance Logic Error Bugfix Review
Summary
Email Injection leads to open redirect
https://medium.com/@milanjain7906/email-injection-leads-to-open-redirect-631ae473e8d0?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@milanjain7906/email-injection-leads-to-open-redirect-631ae473e8d0?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Email Injection leads to open redirect
Hii all i have back with new Hacking story !!.so . 3 days Ago i was hunting on vdp program . i found that hacker can redirect user to on…
Hii all i have back with new Hacking story !!.so . 3 days Ago i was hunting on vdp program . i found that hacker can redirect user to on…Continue reading on Medium » (https://medium.com/@milanjain7906/email-injection-leads-to-open-redirect-631ae473e8d0?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Email Injection leads to open redirect
Hii all i have back with new Hacking story !!.so . 3 days Ago i was hunting on vdp program . i found that hacker can redirect user to on…
Permanently Access Tools/Directory From Anywhere on Linux
https://medium.com/@imdon2126/permanently-access-tools-directory-from-anywhere-on-linux-f9d465a567b4?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@imdon2126/permanently-access-tools-directory-from-anywhere-on-linux-f9d465a567b4?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Permanently Access Tools/Directory From Anywhere on Linux
When you type a command into a Linux terminal, what’s really happening is that a program is being executed. Normally, to execute a custom…
When you type a command into a Linux terminal, what’s really happening is that a program is being executed. Normally, to execute a custom…Continue reading on Medium » (https://medium.com/@imdon2126/permanently-access-tools-directory-from-anywhere-on-linux-f9d465a567b4?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Permanently Access Tools/Directory From Anywhere on Linux
When you type a command into a Linux terminal, what’s really happening is that a program is being executed. Normally, to execute a custom…
Permanently Access Tools/Directory From Anywhere on Linux
When you type a command into a Linux terminal, what’s really happening is that a program is being executed. Normally, to execute a custom…Continue reading on Medium »
Read more...
When you type a command into a Linux terminal, what’s really happening is that a program is being executed. Normally, to execute a custom…Continue reading on Medium »
Read more...
Intigriti — XSS Challenge — June 2022 — Bug Bounty Hunting — Writeup
Intro:Continue reading on Medium »
Read more...
Intro:Continue reading on Medium »
Read more...
Jwtear - Modular Command-Line Tool To Parse, Create And Manipulate JWT Tokens For Hackers
http://www.kitploit.com/2022/06/jwtear-modular-command-line-tool-to.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/06/jwtear-modular-command-line-tool-to.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Jwtear - Modular Command-Line Tool To Parse, Create And Manipulate JWT Tokens For Hackers
A modular command-line tool to parse, create and manipulate JSON Web Token(JWT) tokens for security testing purposes. Features Complete modularity. All commands are plugins. Easy to add new plugins. Support JWS and JWE tokens. Easy interface for plugins. (follow the template example) Flexible token generation based on production-class libraries (e.g. json-jwt, jwe).
Available plugins Parse: parses jwt tokens. jws: manipulate and generate JWS tokens. jwe: manipulate and generate JWE tokens. bruteforce: brutefocing JWS signing key wiki: contains offline information about JWT, attacks ideas, references. Installation install it yourself as: $ gem install jwtear
Usage Show the main menu 888888 888 888 88888888888
"88b 888 o 888 888
888 888 d8b 888 888
888 888 d888b 888 888 .d88b. 8888b. 888d888
888 888d88888b888 888 d8P Y8b "88b 888P"
888 88888P Y88888 888 88888888 .d888888 888
88P 8888P Y8888 888 Y8b. 888 888 888
888 888P Y888 888 "Y8888 "Y888888 888
.d88P v1.0.0
.d88P"
888P"
NAME
jwtear - Parse, create and manipulate JWT tokens.
SYNOPSIS
jwtear [global options] command [command options] [arguments...]
GLOBAL OPTIONS
-v, --version - Check current and latest version
-h, --help - Show this help message
COMMANDS
help - Shows a list of commands or help for one command
bruteforce, bfs - plugin to offline bruteforce (https://www.kitploit.com/search/label/Brute%20%20%20force) and crack token's signature.
jws, s - Generate signature-based JWT (JWS) token.
jwe, e - Generate encryption-based JWT (JWE) token.
parse - Parse JWT token (accepts JWS and JWE formats).
wiki, w - A JWT wiki for hackers.
Show a subcommand help, use -h COMMAND $jwtear -h jws
NAME
jws - Generate signature-based JWT (JWS) token.
SYNOPSIS
jwtear [global options] jws [command options]
DESCRIPTION
Generate JWS and JWE tokens.
COMMAND OPTIONS
-h, --header=JSON - JWT header (JSON format). eg. {"typ":"JWT","alg":"HS256"}. Run 'jwtear gen -l' for supported algorithms. (required, default: none)
-p, --payload=JSON - JWT payload (JSON format). eg. {"login":"admin"} (required, default: none)
-k, --key=PASSWORD|PUB_KEY_FILE - Key as a password string or a file public key. eg. P@ssw0rd | eg. public_key.pem (default: none)
Use a plugin plugins are defined as subcommands. Each subcommand may have one or more argument and/or switches. $ jwtear parse -t eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.J8SS8VKlI2yV47C4BtfYukWPx_2welF34Mz7l-MNmkE
$ jwtear jws -h '{"alg":"HS256","typ":"JWT"}' -p '{"user":"admin"}' -k p@ss0rd123
$ jwtear jwe -header '{"enc":"A192GCM","typ":"JWT"}' --payload '{"user":"admin"}' --key public.pem
$ jwtear bruteforce -v -t eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJ1c2VyIjpudWxsfQ.Tr0VvdP6rVBGBGuI_luxGCOaz6BbhC6IxRTlKOW8UjM -l ~/tmp/pass.list
Add plugin To add a new plugin, create a new ruby file under plugins directory (https://www.kitploit.com/search/label/Directory) with the following structure module JWTear
module CLI
extend GLI::App
extend JWTear::Helpers::Extensions::Print
extend JWTear::Helpers::Utils
desc "Plugin short description"
long_desc "Plugin long description"
command [:template, :pt] do |c|
c.action do |global, options, arguments|
print_h1 "Plugin template"
print_good "Hi, I'm a template."
template = TemplatePlugin.new
end
end
end
module Plugin
class TemplatePlugin
include JWTear::Helpers::Extensions::Print
include JWTear::Helpers::Utils
def initialize
check_dependencies
# ..code...
end
___________________________
@hacking_Attack
@Hacking_Video
Available plugins Parse: parses jwt tokens. jws: manipulate and generate JWS tokens. jwe: manipulate and generate JWE tokens. bruteforce: brutefocing JWS signing key wiki: contains offline information about JWT, attacks ideas, references. Installation install it yourself as: $ gem install jwtear
Usage Show the main menu 888888 888 888 88888888888
"88b 888 o 888 888
888 888 d8b 888 888
888 888 d888b 888 888 .d88b. 8888b. 888d888
888 888d88888b888 888 d8P Y8b "88b 888P"
888 88888P Y88888 888 88888888 .d888888 888
88P 8888P Y8888 888 Y8b. 888 888 888
888 888P Y888 888 "Y8888 "Y888888 888
.d88P v1.0.0
.d88P"
888P"
NAME
jwtear - Parse, create and manipulate JWT tokens.
SYNOPSIS
jwtear [global options] command [command options] [arguments...]
GLOBAL OPTIONS
-v, --version - Check current and latest version
-h, --help - Show this help message
COMMANDS
help - Shows a list of commands or help for one command
bruteforce, bfs - plugin to offline bruteforce (https://www.kitploit.com/search/label/Brute%20%20%20force) and crack token's signature.
jws, s - Generate signature-based JWT (JWS) token.
jwe, e - Generate encryption-based JWT (JWE) token.
parse - Parse JWT token (accepts JWS and JWE formats).
wiki, w - A JWT wiki for hackers.
Show a subcommand help, use -h COMMAND $jwtear -h jws
NAME
jws - Generate signature-based JWT (JWS) token.
SYNOPSIS
jwtear [global options] jws [command options]
DESCRIPTION
Generate JWS and JWE tokens.
COMMAND OPTIONS
-h, --header=JSON - JWT header (JSON format). eg. {"typ":"JWT","alg":"HS256"}. Run 'jwtear gen -l' for supported algorithms. (required, default: none)
-p, --payload=JSON - JWT payload (JSON format). eg. {"login":"admin"} (required, default: none)
-k, --key=PASSWORD|PUB_KEY_FILE - Key as a password string or a file public key. eg. P@ssw0rd | eg. public_key.pem (default: none)
Use a plugin plugins are defined as subcommands. Each subcommand may have one or more argument and/or switches. $ jwtear parse -t eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.J8SS8VKlI2yV47C4BtfYukWPx_2welF34Mz7l-MNmkE
$ jwtear jws -h '{"alg":"HS256","typ":"JWT"}' -p '{"user":"admin"}' -k p@ss0rd123
$ jwtear jwe -header '{"enc":"A192GCM","typ":"JWT"}' --payload '{"user":"admin"}' --key public.pem
$ jwtear bruteforce -v -t eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJ1c2VyIjpudWxsfQ.Tr0VvdP6rVBGBGuI_luxGCOaz6BbhC6IxRTlKOW8UjM -l ~/tmp/pass.list
Add plugin To add a new plugin, create a new ruby file under plugins directory (https://www.kitploit.com/search/label/Directory) with the following structure module JWTear
module CLI
extend GLI::App
extend JWTear::Helpers::Extensions::Print
extend JWTear::Helpers::Utils
desc "Plugin short description"
long_desc "Plugin long description"
command [:template, :pt] do |c|
c.action do |global, options, arguments|
print_h1 "Plugin template"
print_good "Hi, I'm a template."
template = TemplatePlugin.new
end
end
end
module Plugin
class TemplatePlugin
include JWTear::Helpers::Extensions::Print
include JWTear::Helpers::Utils
def initialize
check_dependencies
# ..code...
end
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.