Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Bug Bounty Progress Disclosure

Bug Bounties — Another Key Step to Strengthen the Security of the Balancer ProtocolContinue reading on Balancer Protocol »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Zphisher-GUI-Back_office : A Zphisher GUI Back-Office Plugin

Zphisher-GUI-Back_office is a plugin where you can see in real time the victims of your phishing campaign, you just have to change the Zphisher files for these. Easy!

This tool creates a graphical back office for the zphish tool (although it is not 100% necessary to use this tool, you can use these files by hosting it on a localhost).

Instructions

* You need to deploy the server with a template, identify in the “login.html” file the name of the two post parameters.
* Modify the post parameters of the “login.php” file of the plugin with the original identifier of Zphisher (line 7 and 8).
* Replace all deployed http server files with plugin files (except login.html).
* Set “chmod 777 -R in parental directory of phishing”.

If you have an api key from haveibeenpwned.com you have to insert it in the file “api_key.txt” in the directory “programa interprete”, in this way the back-office will tell you which accounts are exposed on the internet.

No need 100% Zphisher

You can also use this plugin by hard sharing the project by Ngrok from your LocalHost without using Zphisher.

This plugin comes with a sample login page, in this case from Office 365, you can use any Zphisher template for this plugin, using Ngrok to share your localhost.

Back office properties

You can see if the inserted account is exposed on the internet:
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgJXAUUbQOSBrcqUGiz4l6BL7lLbdDsJqFLZoCCBgAMYhZzriUyvQ9J4dGlUhaVSEaARw4WBKgY5rrZou1KzlURfwPbbNqfHl-SEVx7ZSyYVirK6fgjFbk8JC-qR7jI9ICGTviAEzw2VnuggFhU5QvJTHuPZ_MV125nSVgrCRsQ8RPRMSrxCOnJxEdQ/s648/168440897-6e70af86-a744-4776-a9de-3c54439a730d.png
-Total number of accounts and “Pwned” accounts:
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjAZnwMSgbBcpGIfhUIzQWd7EeMbBKu3XS6QETwk4gb44GGCG6slg4IMY0yqcKYr-UCTKAd_n1soTorUVYdQfTjhs_LrDdTl_EYwYvJEAK6vjnPia8UbFabLZa0kAWKi6I4K1ur3_Z5GcdByBU6moE7YZnCBVED-8tSstEem65ptAvgDXUTFsA84Nfv/s907/168440952-a4453be2-97df-4bf1-953d-7e00ad40d519.png
-Evaluation of security in the passwords of all the inserted accounts:
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi6hHbb_pku3txC1Cn7gv9XWmDZNY_4LIz4xNWpwl-aseF0JXtJWxDJaBQBDcvthhhlIlxP-qqSPI0l32Wvq9AS-l5_O5sjARf_kFMzziAlMl-YT5uDOyuIjrZWhqoYMyQllxDMZwr2oJt95ERZ67E2AfSE0gUEjj8xXwYnaItZNMqGJYogw9KlkMjR/s907/168440970-7fdd6df1-decc-4a6c-97c4-bd06b51a65e2.png

Download

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Fb_Friend_List_Scraper : OSINT Tool To Scrape Names And Usernames From Large Friend Lists

Fb_Friend_List_Scraper is a OSINT tool to scrape names and usernames from large friend lists on Facebook, without being rate limited.

Getting started

* Install using pip: python -m pip install fb-friend-list-scraper
* Script is now installed as fbfriendlistscraper
* Run with -hor --helpto show usage information.

Usage

usage: fbfriendlistscraper [-h] -e EMAIL [-p PASSWORD] -u USERNAME [-o OUTFILE] [-w] [-q] [-x] [-s SLEEPMULTIPLIER] [-i PROXY] [-c CMD]
Tool to scrape names and usernames from large friend lists on Facebook, without being rate limited
options:
-h, –help show this help message and exit
-e EMAIL, –email EMAIL
Email address or phone number to login with.
-p PASSWORD, –password PASSWORD
Password to login with. If not supplied you will be prompted. You really shouldn’t use this for security reasons.
-u USERNAME, –username USERNAME
Username of the user to scrape.
-o OUTFILE, –outfile OUTFILE
Path of the output file. (Default: ./scraped_friends.txt)
-w, –headless Run webdriver in headless mode.
-q, –quiet Do not print scraped users to screen.
-x, –onlyusernames Only the usernames/IDs will be written to the output file.
-s SLEEPMULTIPLIER, –sleepmultiplier SLEEPMULTIPLIER
Multiply sleep time between each page scrape by n. Useful when being easily rate-limited.
-i PROXY, –proxy PROXY
Proxy server to use for connecting. Username/password can be supplied like: socks5://user:pass@host:port
-c CMD, –cmd CMD Shell command to run after each page scrape. Useful for changing proxy/VPN exit.
examples:
fbfriendlistscraper -e your@email.com -p YourPassword123 -u someusername.123 -o my_file.txt
fbfriendlistscraper –email your@email.com –username another.user –headless -s 2 -x
fbfriendlistscraper -e your@email.com -u username.johnson -w –proxy socks5://127.0.0.1:9050
fbfriendlistscraper -e your@email.com -u xxuserxx –headless –cmd “mullvad relay set provider Quadranet”
fbfriendlistscraper -e your@email.com -u markzuckerburger -w -o ./test.txt –cmd “killall -HUP tor”
Download

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Shifting the Cybersecurity Paradigm From Severity-Focused to Risk-Centric

Embrace cyber-risk modeling and ask security teams to pinpoint the risks that matter and prioritize remediation efforts.
Dark Reading: Attacks/Breaches
5 Surprising Cyberattacks AI Stopped This Year

See how these novel, sophisticated, or creative threats used techniques such as living off the land to evade detection from traditional defensive measures — but were busted by AI.

___________________________
@hacking_Attack
@Hacking_Video