Pown CDB is a Chrome Debug Protocol utility. The main goal of the tool is to automate common tasks to help debug web applications from the command-line and actively monitor and intercept (https://www.kitploit.com/search/label/Intercept) HTTP requests and responses. This is particularly useful during penetration tests and other types of security assessments and investigations.
Credits This tool is part of secapps.com (https://secapps.com/) open-source initiative. ___ ___ ___ _ ___ ___ ___
/ __| __/ __| /_\ | _ \ _ \/ __|
\__ \ _| (__ / _ \| _/ _/\__ \
|___/___\___/_/ \_\_| |_| |___/
https://secapps.com
Authors @pdp (https://twitter.com/pdp) - https://pdparchitect.github.io/www/ Quickstart This tool is meant to be used as part of Pown.js (https://github.com/pownjs/pown) but it can be invoked separately as an independent tool. Install Pown first as usual: $ npm install -g pown@latest Invoke directly from Pown: $ pown cdb Library Use Install this module locally from the root of your project: $ npm install @pown/cdb --save Once done, invoke pown cli: $ POWN_ROOT=. ./node_modules/.bin/pown-cli cdb You can also use the global pown to invoke the tool locally: $ POWN_ROOT=. pown cdb Usage WARNING: This pown command is currently under development and as a result will be subject to breaking changes. pown cdb
Chrome Debug Protocol Tool
Commands:
pown cdb launch Launch server application such as chrome, firefox, opera and edge [aliases: start]
pown cdb navigate Go to the specified url [aliases: goto, go]
pown cdb network Chrome Debug Protocol Network Monitor [aliases: net, sniff, proxy, mon, monitor]
pown cdb cookies Dump current page cookies [aliases: cookie]
pown cdb screenshot Screenshot (https://www.kitploit.com/search/label/Screenshot) the current page [aliases: capture, shoot, shot]
Options:
--version Show version number [boolean]
--help Show help [boolean]
pown cdb launch pown cdb launch
Launch server application such as chrome, firefox, opera and edge
Options:
--version Show version number [boolean]
--help Show help [boolean]
--port, -p Remote debugging (https://www.kitploit.com/search/label/Debugging) port [number] [default: 9222]
--xss-auditor, -x Turn on/off XSS auditor [boolean] [default: true]
--certificate-errors, -c Turn on/off certificate errors [boolean] [default: true]
--pentest, -t Start with prefered settings for pentesting (https://www.kitploit.com/search/label/Pentesting) [boolean] [default: false]
pown cdb navigate pown cdb network pown cdb cookies pown cdb screenshot Tutorials Web Application Security Assessment Let's explore how to use Pown CDB during a typical web app security engagments. First, ensure that you have the latest pown installed: $ npm install -g pown If you have pown installed, make sure you have the latest version: $ pown update To get started with Pown CDB we need a Chrome browser instance (other browsers (https://www.kitploit.com/search/label/Browsers) are also supported) with chrome debug remote interface enabled and listening on localhost: $ pown cdb launch --port 9333 Once the chrome browser instance is running, hook it with pown cdb network utility: $ pown cdb network --port 9333 -b The -b flag is used to start Pown CDB with a curses-based user interface:
___________________________
@hacking_Attack
@Hacking_Video
Credits This tool is part of secapps.com (https://secapps.com/) open-source initiative. ___ ___ ___ _ ___ ___ ___
/ __| __/ __| /_\ | _ \ _ \/ __|
\__ \ _| (__ / _ \| _/ _/\__ \
|___/___\___/_/ \_\_| |_| |___/
https://secapps.com
Authors @pdp (https://twitter.com/pdp) - https://pdparchitect.github.io/www/ Quickstart This tool is meant to be used as part of Pown.js (https://github.com/pownjs/pown) but it can be invoked separately as an independent tool. Install Pown first as usual: $ npm install -g pown@latest Invoke directly from Pown: $ pown cdb Library Use Install this module locally from the root of your project: $ npm install @pown/cdb --save Once done, invoke pown cli: $ POWN_ROOT=. ./node_modules/.bin/pown-cli cdb You can also use the global pown to invoke the tool locally: $ POWN_ROOT=. pown cdb Usage WARNING: This pown command is currently under development and as a result will be subject to breaking changes. pown cdb
Chrome Debug Protocol Tool
Commands:
pown cdb launch Launch server application such as chrome, firefox, opera and edge [aliases: start]
pown cdb navigate Go to the specified url [aliases: goto, go]
pown cdb network Chrome Debug Protocol Network Monitor [aliases: net, sniff, proxy, mon, monitor]
pown cdb cookies Dump current page cookies [aliases: cookie]
pown cdb screenshot Screenshot (https://www.kitploit.com/search/label/Screenshot) the current page [aliases: capture, shoot, shot]
Options:
--version Show version number [boolean]
--help Show help [boolean]
pown cdb launch pown cdb launch
Launch server application such as chrome, firefox, opera and edge
Options:
--version Show version number [boolean]
--help Show help [boolean]
--port, -p Remote debugging (https://www.kitploit.com/search/label/Debugging) port [number] [default: 9222]
--xss-auditor, -x Turn on/off XSS auditor [boolean] [default: true]
--certificate-errors, -c Turn on/off certificate errors [boolean] [default: true]
--pentest, -t Start with prefered settings for pentesting (https://www.kitploit.com/search/label/Pentesting) [boolean] [default: false]
pown cdb navigate pown cdb network pown cdb cookies pown cdb screenshot Tutorials Web Application Security Assessment Let's explore how to use Pown CDB during a typical web app security engagments. First, ensure that you have the latest pown installed: $ npm install -g pown If you have pown installed, make sure you have the latest version: $ pown update To get started with Pown CDB we need a Chrome browser instance (other browsers (https://www.kitploit.com/search/label/Browsers) are also supported) with chrome debug remote interface enabled and listening on localhost: $ pown cdb launch --port 9333 Once the chrome browser instance is running, hook it with pown cdb network utility: $ pown cdb network --port 9333 -b The -b flag is used to start Pown CDB with a curses-based user interface:
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
Use key-combo shift + ? to get a list of available shortcuts:
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
As soon as you start using the browser, Pown CDB will record and display the traffic in the user interface. To intercept requests use key-combo ctrl + t.
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Requests are captured and opened in your default shell editor ($EDITOR). Make the desired changes, save and quit. The original request will be replaced with your changes.
Download Cdb (https://github.com/pownjs/cdb)
___________________________
@hacking_Attack
@Hacking_Video
Download Cdb (https://github.com/pownjs/cdb)
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - pownjs/cdb: Automate common Chrome Debug Protocol tasks to help debug web applications from the command-line and actively…
Automate common Chrome Debug Protocol tasks to help debug web applications from the command-line and actively monitor and intercept HTTP requests and responses. - pownjs/cdb
Instalasi Genymotion dan pemasangan Burpsuite certificate pada emulator Genymotion
https://medium.com/@bedvuln/instalasi-genymotion-dan-pemasangan-burpsuite-certificate-pada-emulator-genymotion-a252e8187ded?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@bedvuln/instalasi-genymotion-dan-pemasangan-burpsuite-certificate-pada-emulator-genymotion-a252e8187ded?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Instalasi Genymotion dan pemasangan Burpsuite certificate pada emulator Genymotion
Halo teman-teman, selamat datang di post medium pertama saya. Pada post ini saya akan membagikan tutorial bagaimana cara instalasi…
Halo teman-teman, selamat datang di post medium pertama saya. Pada post ini saya akan membagikan tutorial bagaimana cara instalasi…Continue reading on Medium » (https://medium.com/@bedvuln/instalasi-genymotion-dan-pemasangan-burpsuite-certificate-pada-emulator-genymotion-a252e8187ded?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Instalasi Genymotion dan pemasangan Burpsuite certificate pada emulator Genymotion
Halo teman-teman, selamat datang di post medium pertama saya. Pada post ini saya akan membagikan tutorial bagaimana cara instalasi…
Initial Setup Genymotion & Burpsuite for Android Mobile App Pentest(Bahasa)
https://medium.com/@wicaksonoindra/initial-setup-genymotion-burpsuite-for-android-mobile-app-pentest-bahasa-f65b4c1f0760?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@wicaksonoindra/initial-setup-genymotion-burpsuite-for-android-mobile-app-pentest-bahasa-f65b4c1f0760?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Initial Setup Genymotion & Burpsuite for Android Mobile App Pentest(Bahasa)
Pada kesempatan kali ini, saya menulis artikel mengenai instalasi genymotion dan burpsuite yang akan digunakan untuk melakukan penetrasi…
Pada kesempatan kali ini, saya menulis artikel mengenai instalasi genymotion dan burpsuite yang akan digunakan untuk melakukan penetrasi…Continue reading on Medium » (https://medium.com/@wicaksonoindra/initial-setup-genymotion-burpsuite-for-android-mobile-app-pentest-bahasa-f65b4c1f0760?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Initial Setup Genymotion & Burpsuite for Android Mobile App Pentest(Bahasa)
Pada kesempatan kali ini, saya menulis artikel mengenai instalasi genymotion dan burpsuite yang akan digunakan untuk melakukan penetrasi…
hacking: security in practice
hi
Can anybody type my ip address im curious to know what it is
submitted by /u/No_Claim1826
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
hi
Can anybody type my ip address im curious to know what it is
submitted by /u/No_Claim1826
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
hi
Can anybody type my ip address im curious to know what it is
Server Side Request Forgery (SSRF) Attacks & Cara Mencegahnya / Patched #Episode_SSRF1
https://orangmuda.medium.com/server-side-request-forgery-ssrf-attacks-how-to-prevent-them-2a6fbe3a281f?source=rss------bug_bounty-5
Serangan Server-Side Request Forgery (SSRF) memungkinkan penyerang membuat permintaan ke domain apa pun melalui server yang rentan…Continue reading on Medium » (https://orangmuda.medium.com/server-side-request-forgery-ssrf-attacks-how-to-prevent-them-2a6fbe3a281f?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://orangmuda.medium.com/server-side-request-forgery-ssrf-attacks-how-to-prevent-them-2a6fbe3a281f?source=rss------bug_bounty-5
Serangan Server-Side Request Forgery (SSRF) memungkinkan penyerang membuat permintaan ke domain apa pun melalui server yang rentan…Continue reading on Medium » (https://orangmuda.medium.com/server-side-request-forgery-ssrf-attacks-how-to-prevent-them-2a6fbe3a281f?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Server Side Request Forgery (SSRF) Attacks & Cara Mencegahnya / Patched #Episode_SSRF1
Serangan Server-Side Request Forgery (SSRF) memungkinkan penyerang membuat permintaan ke domain apa pun melalui server yang rentan…
Server Side Request Forgery (SSRF) Attacks & Cara Mencegahnya / Patched #Episode\_SSRF1
Serangan Server-Side Request Forgery (SSRF) memungkinkan penyerang membuat permintaan ke domain apa pun melalui server yang rentan…Continue reading on Medium »
Read more...
Serangan Server-Side Request Forgery (SSRF) memungkinkan penyerang membuat permintaan ke domain apa pun melalui server yang rentan…Continue reading on Medium »
Read more...
Any discord servers for CRTP students ?
https://www.reddit.com/r/Pentesting/comments/w3pcbi/any_discord_servers_for_crtp_students/
i contacted the support about a discord server so that students could help each other and they said its only for bootcamp users to share bootcamp details not for regular CRTP labs, are there any unofficial discord labs for CRTP takers ? just want a community where i can ask questions and stuff. submitted by /u/watermelonSoundsNice (https://www.reddit.com/user/watermelonSoundsNice)
[link] (https://www.reddit.com/r/Pentesting/comments/w3pcbi/any_discord_servers_for_crtp_students/) [comments] (https://www.reddit.com/r/Pentesting/comments/w3pcbi/any_discord_servers_for_crtp_students/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/w3pcbi/any_discord_servers_for_crtp_students/
i contacted the support about a discord server so that students could help each other and they said its only for bootcamp users to share bootcamp details not for regular CRTP labs, are there any unofficial discord labs for CRTP takers ? just want a community where i can ask questions and stuff. submitted by /u/watermelonSoundsNice (https://www.reddit.com/user/watermelonSoundsNice)
[link] (https://www.reddit.com/r/Pentesting/comments/w3pcbi/any_discord_servers_for_crtp_students/) [comments] (https://www.reddit.com/r/Pentesting/comments/w3pcbi/any_discord_servers_for_crtp_students/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Any discord servers for CRTP students ?
i contacted the support about a discord server so that students could help each other and they said its only for bootcamp users to share bootcamp...