Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
A fast tool to scan (https://www.kitploit.com/search/label/Scan) SAAS,PAAS App written in Go SAAS App Support : salesforce contentful (next version) Note flag -o output not working install : golang 1.18Ver go install -v github.com/Ph33rr/cirrusgo/cmd/cirrusgo@latest
or
go install -v github.com/Ph33rr/CirrusGo/cmd/cirrusgo@latest
Help: cirrusgo --help Define single URL to fuzz -l, --list Show App List -c, --check only check endpoint -V, --version Show current version -h, --help Display its help [cirrusgo [app] [options] ..] cirrusgo salesforce --help -u, --url Define single URL -c, --check only check endpoint -lobj, --listobj pull the object list. -gobj --getobj pull the object. -obj --objects set the object name. Default value is "User" object. Juicy Objects: Case,Account,User,Contact,Document,Cont entDocument,ContentVersion,ContentBody,CaseComment,Not e,Employee,Attachment,EmailMessage,CaseExternalDocumen t,Attachment,Lead,Name,EmailTemplate,EmailMessageRelation -gre --getrecord pull the Record id. -re --recordid set the recode id to dump the record -cw --chkWritable check all Writable objects -f, --full dump all pages of objects. --dump -H, --header Pass custom header (https://www.kitploit.com/search/label/Custom%20Header) to target -proxy, --proxy Use proxy to fuzz -o, --output File to save results [flags payload] [command: cirrusgo salesforce --payload options] -payload, --payload Generator (https://www.kitploit.com/search/label/Generator) payload (https://www.kitploit.com/search/label/Payload) for test manual Default "ObjectList" GetItems -obj set object -page set page -pages set pageSize GetRecord -re set recoder id WritableOBJ -obj set object SearchObj -obj set object -page set page -pages set pageSize AuraContext -fwuid set UID -App set AppName -markup set markup ObjectList no options Dump no options -h, --help Display its help '> ______ _ ______
/ ____/(_)_____ _____ __ __ _____ / ____/____
/ / / // ___// ___// / / // ___// / __ / __ \
/ /___ / // / / / / /_/ /(__ )/ /_/ // /_/ /
\____//_//_/ /_/ \__,_//____/ \____/ \____/ v0.0.1

cirrusgo --help

-u, --url Define single URL to fuzz
-l, --list Show App List
-c, --check only check endpoint
-V, --version Show current version
-h, --help Display its help

[cirrusgo [app] [options] ..]
cirrusgo salesforce --help

-u, --url Define single URL
-c, --check only check endpoint
-lobj, --listobj pull the object list.
-gobj --getobj pull the object.
-obj --objects set the object name. Default value is "User" object.
Juicy Objects: Case,Account,User,Contact,Document,Cont
entDocument,ContentVersion,ContentBody,CaseComment,Not
e,Employee,Attachment,EmailMessage,CaseExternalDocumen
t,Attachment,Lead,Name,EmailTemplate,EmailMessageRelation
-gre --getrecord pull the Record id.
-re --recordid set the recode id to dump the record
-cw --chkWritable check all Writable objects
-f, --full dump all pages of objects.
--dump
-H, --header Pass custom header to target
-proxy, --proxy Use proxy to fuzz

-o, --output File to save results

[flags payload]
[command: cirrusgo salesforce --payload options]
-payload, --payload Generator payload for test manual Default "ObjectList"

GetItems -obj set object
-page set page
-pages set pageSize
GetRecord -re set recoder id
WritableOBJ -obj set object
SearchObj -obj set object
-page set page
-pages set pageSize
AuraContext -fwuid set UID
-App set AppName
-markup set markup
ObjectList no options
Dump no options
-h, --help Display its help
Example : cirrusgo salesforce -u https://loclhost -gobj dump: cirrusgo salesforce -u https://localhost/ -f check Writable Objects: cirusgo salesforce -u https://localhost/ -cw

Download Cirrusgo (https://github.com/Ph33rr/cirrusgo)
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Cirrusgo - A Fast Tool To Scan SAAS, PAAS App Written In Go

https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi86EhCFbOLT-YRbgxWvkf_H9XLy0Bzmk7RoA_a2c45PQ55r8qEXWB5fhnwxpNuxMG4hHDjwR_rTd4up9H-cmVsEI6RGKijUGnS-uV7bmXG0Ni2-jT5agL2vp8yXI1BLG0arI-ZWzbqsk6GcpdttpP3aXHWBJX9ENQuVFoyOcxLXJkdv3wRNQ2Yyh4T/w640-h482/cirrusgo.png A fast tool to scan SAAS,PAAS App written in Go

SAAS App Support :

* salesforce
* contentful (next version)

Note flag -o output not working

install : golang 1.18Ver go install -v github.com/Ph33rr/cirrusgo/cmd/cirrusgo@latest
or
go install -v github.com/Ph33rr/CirrusGo/cmd/cirrusgo@latest
Help: cirrusgo --helpPass custom header to target -proxy, --proxy <urlUse proxy to fuzz -o, --output <fileFile to save results [flags payload] [command: cirrusgo salesforce --payload options] -payload, --payload Generator payload for test manual Default "ObjectList" GetItems -obj set object -page set page -pages set pageSize GetRecord -re set recoder id WritableOBJ -obj set object SearchObj -obj set object -page set page -pages set pageSize AuraContext -fwuid set UID -App set AppName -markup set markup ObjectList no options Dump no options -h, --help Display its help ">______ _ ______
/ ____/(_)_____ _____ __ __ _____ / ____/____
/ / / // ___// ___// / / // ___// / __ / __ \
/ /___ / // / / / / /_/ /(__ )/ /_/ // /_/ /
\____//_//_/ /_/ \__,_//____/ \____/ \____/ v0.0.1

cirrusgo --help

-u, --url <urlDefine single URL to fuzz
-l, --list Show App List
-c, --check only check endpoint
-V, --version Show current version
-h, --help Display its help

[cirrusgo [app] [options] ..]
cirrusgo salesforce --help

-u, --url <urlDefine single URL
-c, --check only check endpoint
-lobj, --listobj pull the object list.
-gobj --getobj pull the object.
-obj --objects set the object name. Default value is "User" object.
Juicy Objects: Case,Account,User,Contact,Document,Cont
entDocument,ContentVersion,ContentBody,CaseComment,Not
e,Employee,Attachment,EmailMessage,CaseExternalDocumen
t,Attachment,Lead,Name,EmailTemplate,EmailMessageRelation
-gre --getrecord pull the Record id.
-re --recordid set the recode id to dump the record
-cw --chkWritable check all Writable objects
-f, --full dump all pages of objects.
--dump
-H, --header
Pass custom header to target
-proxy, --proxy <urlUse proxy to fuzz

-o, --output <fileFile to save results

[flags payload]
[command: cirrusgo salesforce --payload options]
-payload, --payload Generator payload for test manual Default "ObjectList"

GetItems -obj set object
-page set page
-pages set pageSize
GetRecord -re set recoder id
WritableOBJ -obj set object
SearchObj -obj set object
-page set page
-pages set pageSize
AuraContext -fwuid set UID
-App set AppName
-markup set markup
ObjectList no options
Dump no options
-h, --help Display its help

Example : cirrusgo salesforce -u https://loclhost -gobjdump: cirrusgo salesforce -u https://localhost/ -fcheck Writable Objects: cirusgo salesforce -u https://localhost/ -cwDownload Cirrusgo
Dark Reading: Attacks/Breaches
Ping Identity to Go Private After $2.8B Acquisition

The identity-services company is being acquired by Thoma Bravo software investment for cash, before being delisted.
Moonbeam Team släpper en brådskande säkerhetspatch för felet med trunkning av heltal

Aug 1, 2022Continue reading on Medium »
Read more...
Certified Ethical Hacking V11 & Counter Measures By Pentester Club

Pentester Club Pvt Ltd CEH certification training course provides you the hands-on training required to master the techniques hackers use…Continue reading on Medium »
Read more...
what is footprinting in hacking || types of footprinting || Pentester Club

Footprinting is an ethical hacking technique used to gather as much data as possible about a specific targeted computer system, an…Continue reading on Medium »
Read more...
SS7 Practical Video From Pentester Club

Signaling System 7 (SS7) is an architecture for performing out-of-band signaling in support of the call-establishment, billing, routing…Continue reading on Medium »
Read more...
Finding SQL Injection Manually

SQL injection is a code injection technique used to hack websites, attack data applications, destroy databases by inserting malicious SQL…Continue reading on Medium »
Read more...
Protection Strategies Sql Injection

SQL injections are one of the most utilized web attack vectors used with the goal of retrieving sensitive data from organizations.Continue reading on Medium »
Read more...
DBMS Detection Of Sql Injection

In this article, we will learn about DBMS Injection.Continue reading on Medium »
Read more...
Authentication Bypass

When performing a penetration test of an application, tests against the authentication mechanism are always an important check. While a…Continue reading on Medium »
Read more...
hacking: security in practice
How to tell which continent/zone Amazon is hosting a web application?

We have a supplier who is supposed to be hosting our SaaS application on Amazon Europe due to data privacy etc. However, we have a suspicion they are hosting it in the US. Are there any online tools which when given a URL can determine the host location?

submitted by /u/erolbrown
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video