Halo teman teman, Perkenalkan nama saya Mohammad Alfin Hidayatullah dan saya adalah seorang bug bounty hunter. Kali ini saya ingjn berbagi…Continue reading on Medium » (https://alpinnnnnn13.medium.com/stored-xss-in-app-gitbook-com-6349f42661f7?source=rss------bug_bounty-5)
What Is JWT 🤔?Continue reading on Medium » (https://antwanemil.medium.com/jwt-common-attacks-b41de384113e?source=rss------bug_bounty-5)
Hey guys, hope you all are doing well. I am Bharat Singh a Security Researcher and bug hunter from India. In this writeup I am going to…Continue reading on Medium » (https://medium.com/@bharatsingh070601/stored-xss-using-svg-file-2e3608248fae?source=rss------bug_bounty-5)
Solace Partners with Hats Finance to Sponsor Bug Bounties
https://medium.com/solace-fi/solace-partners-with-hats-finance-to-sponsor-bug-bounties-7532c20622ae?source=rss------bug_bounty-5
https://medium.com/solace-fi/solace-partners-with-hats-finance-to-sponsor-bug-bounties-7532c20622ae?source=rss------bug_bounty-5
Solace, the decentralized insurance provider, is partnering with Hats Finance to sponsor bug bounties for Solace-insured DApps. This…Continue reading on Solace.Fi » (https://medium.com/solace-fi/solace-partners-with-hats-finance-to-sponsor-bug-bounties-7532c20622ae?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
RESim : Reverse Engineering Software Using A Full System Simulator
RESim is a dynamic system analysis tool that provides detailed insight into processes, programs and data flow within networked computers. RESim simulates networks of computers through use of the Simics'[1] platform’s high fidelity models of processors, peripheral devices (e.g., network interface cards), and disks. The networked simulated computers load and run targeted software copied from images extracted from the physical systems being modeled.
Broadly, RESim aids reverse engineering and vulnerability analysis of networks of Linux-based systems by inventorying processes in terms of the programs they execute and the data they consume. Data sources include files, device interfaces and inter-process communication mechanisms. Process execution and data consumption is documented through dynamic analysis of a running simulated system without installation or injection of software into the simulated system, and without detailed knowledge of the kernel hosting the processes.
RESim also provides interactive visibility into individual executing programs through use of a custom plug-in to the IDA Pro disassembler/debugger. Plugins for the Ghidra Debugger are also available. The disassembler/debugger allows setting breakpoints to pause the simulation at selected events in either future time, or past time. For example, RESim can direct the simulation state to reverse until the most recent modification of a selected memory address.
Reloadable checkpoints may be generated at any point during system execution.
A RESim simulation can be paused for inspection, e.g., when a specified process is scheduled for execution, and subsequently continued, potentially with altered memory or register state. The analyst can explicitly modify memory or register content, and can also dynamically augment memory based on system events, e.g., change a password file entry when read by the su program.
Analysis is performed entirely through observation of the simulated target system’s memory and processor state, without need for shells, software injection, or kernel symbol tables. The analysis is said to be external because the analysis observation functions have no effect on the state of the simulated system.
RESim has been integrated with the American Fuzzing Lop (AFL) fuzzer. This fuzzing system injects fuzzed data directly into the application read buffer, simplifying the fuzzing setup and workflow. RESim automatically replays and analyzes any detected crashes, identifying the causes of crashes, e.g., corruption of execution control.
Please refer to the RESim User’s Guide for additional information. A brief demonstration of RESim can be seen here: (https://nps.box.com/s/rf3n104ualg38pon6b7fm6m6wqk9zz50)
RESim is based on a software vetting and forensic analysis platform created for the DARPA Cyber Grand Challenge. That repo is here: https://github.com/mfthomps/cgc-monitor. A paper describing that work is at https://www.sciencedirect.com/science/article/pii/S1742287618301920 And a fine summary of the use of Simics in the CGC Monitor is at https://software.intel.com/content/www/us/en/develop/blogs/simics-software-automates-cyber-grand-challenge-validation.html
[1]Simics is a full system simulator sold by Wind River, which holds all relevant trademarks.
Download
RESim : Reverse Engineering Software Using A Full System Simulator
RESim is a dynamic system analysis tool that provides detailed insight into processes, programs and data flow within networked computers. RESim simulates networks of computers through use of the Simics'[1] platform’s high fidelity models of processors, peripheral devices (e.g., network interface cards), and disks. The networked simulated computers load and run targeted software copied from images extracted from the physical systems being modeled.
Broadly, RESim aids reverse engineering and vulnerability analysis of networks of Linux-based systems by inventorying processes in terms of the programs they execute and the data they consume. Data sources include files, device interfaces and inter-process communication mechanisms. Process execution and data consumption is documented through dynamic analysis of a running simulated system without installation or injection of software into the simulated system, and without detailed knowledge of the kernel hosting the processes.
RESim also provides interactive visibility into individual executing programs through use of a custom plug-in to the IDA Pro disassembler/debugger. Plugins for the Ghidra Debugger are also available. The disassembler/debugger allows setting breakpoints to pause the simulation at selected events in either future time, or past time. For example, RESim can direct the simulation state to reverse until the most recent modification of a selected memory address.
Reloadable checkpoints may be generated at any point during system execution.
A RESim simulation can be paused for inspection, e.g., when a specified process is scheduled for execution, and subsequently continued, potentially with altered memory or register state. The analyst can explicitly modify memory or register content, and can also dynamically augment memory based on system events, e.g., change a password file entry when read by the su program.
Analysis is performed entirely through observation of the simulated target system’s memory and processor state, without need for shells, software injection, or kernel symbol tables. The analysis is said to be external because the analysis observation functions have no effect on the state of the simulated system.
RESim has been integrated with the American Fuzzing Lop (AFL) fuzzer. This fuzzing system injects fuzzed data directly into the application read buffer, simplifying the fuzzing setup and workflow. RESim automatically replays and analyzes any detected crashes, identifying the causes of crashes, e.g., corruption of execution control.
Please refer to the RESim User’s Guide for additional information. A brief demonstration of RESim can be seen here: (https://nps.box.com/s/rf3n104ualg38pon6b7fm6m6wqk9zz50)
RESim is based on a software vetting and forensic analysis platform created for the DARPA Cyber Grand Challenge. That repo is here: https://github.com/mfthomps/cgc-monitor. A paper describing that work is at https://www.sciencedirect.com/science/article/pii/S1742287618301920 And a fine summary of the use of Simics in the CGC Monitor is at https://software.intel.com/content/www/us/en/develop/blogs/simics-software-automates-cyber-grand-challenge-validation.html
[1]Simics is a full system simulator sold by Wind River, which holds all relevant trademarks.
Download
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
LiveTargetsFinder : Generates Lists Of Live Hosts And URLs For Targeting, Automating The Usage Of MassDNS
LiveTargetsFinder, Generates lists of live hosts and URLs for targeting, automating the usage of Massdns, Masscan and nmap to filter out unreachable hosts
Given an input file of domain names, this script will automate the usage of MassDNS to filter out unresolvable hosts, and then pass the results on to Masscan to confirm that the hosts are reachable and on which ports. The script will then generate a list of full URLs to be used for further targeting (passing into tools like gobuster or dirsearch, or making HTTP requests), a list of reachable domain names, and a list of reachable IP addresses. As an optional last step, you can run an nmap version scan on this reduced host list, verifying that the earlier reachable hosts are up, and gathering service information from their open ports. OverviewThis script is especially useful for large domain sets, such as subdomain enumerations gathered from an apex domain with thousands of subdomains. With these large lists, an nmap scan would simply take too long. The goal here is to first use the less accurate, but much faster, MassDNS to quickly reduce the size of your input list by removing unresolvable domains. Then, Masscan will be able to take the output from MassDNS, and further confirm that the hosts are reachable, and on which ports. The script will then parse these results and generate lists of the live hosts discovered.
Now, the list of hosts should be reduced enough to be suitable for further scanning/testing. If you want to go a step further, you can tell the script to run an nmap scan on the list of reachable hosts, which should take more reasonable amount of time with the shorter list of hosts. After running nmap, any false positives given from Masscan will be filtered out. Raw nmap output will be stored in the regular nmap XML format, and additional information from the version detection will be added to a SQLite database. InstallationIf using the nmap scan option, this tool assumes that you already have nmap installed
Note: Running the install script is only needed if you do not already have MassDNS and Masscan installed, or if you would like to reinstall them inside this repo. If you do not run the script, you can provide the paths to the respective executables as arguments. The script additionally expects that the resolvers list included with MassDNS be located at
git clone https://github.com/allyomalley/LiveTargetsFinder.git
cd LiveTargetsFinder
sudo pip3 install -r requirements.txt
(OPTIONAL)
chmod +x install_deps.sh
./install_deps.sh
If you do not already have MassDNS and Masscan installed, and would prefer to install them yourself, see the documentation for instructions: Usagepython3 liveTargetsFinder.py [domainList] [options]
FlagDescriptionDefaultRequired
* Note that the Masscan and MassDNS settings are hardcoded inside liveTargetsFinder.py. Feel free to edit them (lines 87 + 97).
* Since this tool was designed with very large lists in mind, I tweaked many of the settings to try to balance speed, accuracy, and network constraints – these can all be adjusted to suit your needs and bandwith.
* Default settings for Masscan only scans ports 80 and 443.
*
LiveTargetsFinder : Generates Lists Of Live Hosts And URLs For Targeting, Automating The Usage Of MassDNS
LiveTargetsFinder, Generates lists of live hosts and URLs for targeting, automating the usage of Massdns, Masscan and nmap to filter out unreachable hosts
Given an input file of domain names, this script will automate the usage of MassDNS to filter out unresolvable hosts, and then pass the results on to Masscan to confirm that the hosts are reachable and on which ports. The script will then generate a list of full URLs to be used for further targeting (passing into tools like gobuster or dirsearch, or making HTTP requests), a list of reachable domain names, and a list of reachable IP addresses. As an optional last step, you can run an nmap version scan on this reduced host list, verifying that the earlier reachable hosts are up, and gathering service information from their open ports. OverviewThis script is especially useful for large domain sets, such as subdomain enumerations gathered from an apex domain with thousands of subdomains. With these large lists, an nmap scan would simply take too long. The goal here is to first use the less accurate, but much faster, MassDNS to quickly reduce the size of your input list by removing unresolvable domains. Then, Masscan will be able to take the output from MassDNS, and further confirm that the hosts are reachable, and on which ports. The script will then parse these results and generate lists of the live hosts discovered.
Now, the list of hosts should be reduced enough to be suitable for further scanning/testing. If you want to go a step further, you can tell the script to run an nmap scan on the list of reachable hosts, which should take more reasonable amount of time with the shorter list of hosts. After running nmap, any false positives given from Masscan will be filtered out. Raw nmap output will be stored in the regular nmap XML format, and additional information from the version detection will be added to a SQLite database. InstallationIf using the nmap scan option, this tool assumes that you already have nmap installed
Note: Running the install script is only needed if you do not already have MassDNS and Masscan installed, or if you would like to reinstall them inside this repo. If you do not run the script, you can provide the paths to the respective executables as arguments. The script additionally expects that the resolvers list included with MassDNS be located at
{massDNS_directory}/lists/resolvers.txt.git clone https://github.com/allyomalley/LiveTargetsFinder.git
cd LiveTargetsFinder
sudo pip3 install -r requirements.txt
(OPTIONAL)
chmod +x install_deps.sh
./install_deps.sh
If you do not already have MassDNS and Masscan installed, and would prefer to install them yourself, see the documentation for instructions: Usagepython3 liveTargetsFinder.py [domainList] [options]
FlagDescriptionDefaultRequired
--target-listInput file containing list of domains, e.g google.comYes --massdns-pathPath to the MassDNS executable, if non-default./massdns/bin/massdnsNo --masscan-pathPath to the Masscan executable, if non-default./masscan/bin/masscanNo --nmapRun an nmap version detection scan on the gathered live hostsDisabledNo --db-pathIf using the –nmap option, supply the path to the database you would like to append to (will be created if does not exist)output/liveTargetsFinder.sqlite3No * Note that the Masscan and MassDNS settings are hardcoded inside liveTargetsFinder.py. Feel free to edit them (lines 87 + 97).
* Since this tool was designed with very large lists in mind, I tweaked many of the settings to try to balance speed, accuracy, and network constraints – these can all be adjusted to suit your needs and bandwith.
* Default settings for Masscan only scans ports 80 and 443.
*
-s[...]
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials LiveTargetsFinder : Generates Lists Of Live Hosts And URLs For Targeting, Automating The Usage Of MassDNS LiveTargetsFinder, Generates lists of live hosts and URLs for targeting, automating the usage of Massdns, Masscan and nmap to filter…
, (
* Full MassDNS arguments:
*
* Another setting of note is the
* Full Masscan arguments:
*
* Default nmap settings only scans ports 80 and 443, with timing -T4 and a few NSE scripts.
* Full nmap arguments:
*
python3 liveTargetsFinder.py –target-list victim_domains.txt
Did NOT run the install script:
python3 liveTargetsFinder.py –target-list victim_domains.txt –massdns-path ../massdns/bin/massdns –masscan-path ../masscan/bin/masscan OutputInput: victimDomains.txt
FileDescriptionExamplesoutput/victimDomains_targetUrls.txtList of reachable, live URLshttps://github.com, http://github.comoutput/victimDomains_domains_alive.txtList of live domain namesgithub.com, google.comoutput/victimDomains_ips_alive.txtList of live IP addresses10.1.0.200, 52.3.1.166Supplied or default DB PathSQLite database storing live hosts and information about their services runningoutput/victimDomains_massdns.txtThe raw output from MassDNS, in ndjson formatoutput/victimDomains_masscan.txtThe raw output from Masscan, in ndjson formatoutput/victimDomains_nmap.txtThe raw output from nmap, in XML format Download
--hashmap-size) in particular was chosen for performance reasons – you will likely be able to increase this.* Full MassDNS arguments:
*
-c 25 -o J -r ./massdns/lists/resolvers.txt -s 100 -w massdnsOutput -t A targetHosts* Documentation* Another setting of note is the
--max-rateargument for Masscan – you will likely want to adjust this.* Full Masscan arguments:
*
-iL ipFile -oD masscanOutput --open-only --max-rate 5000 -p80,443 --max-retries 10* Documentation* Default nmap settings only scans ports 80 and 443, with timing -T4 and a few NSE scripts.
* Full nmap arguments:
*
--script http-server-header.nse,http-devframework.nse,http-headers -sV -T4 -p80,443 -oX {output.xml}ExampleDid run install script:python3 liveTargetsFinder.py –target-list victim_domains.txt
Did NOT run the install script:
python3 liveTargetsFinder.py –target-list victim_domains.txt –massdns-path ../massdns/bin/massdns –masscan-path ../masscan/bin/masscan OutputInput: victimDomains.txt
FileDescriptionExamplesoutput/victimDomains_targetUrls.txtList of reachable, live URLshttps://github.com, http://github.comoutput/victimDomains_domains_alive.txtList of live domain namesgithub.com, google.comoutput/victimDomains_ips_alive.txtList of live IP addresses10.1.0.200, 52.3.1.166Supplied or default DB PathSQLite database storing live hosts and information about their services runningoutput/victimDomains_massdns.txtThe raw output from MassDNS, in ndjson formatoutput/victimDomains_masscan.txtThe raw output from Masscan, in ndjson formatoutput/victimDomains_nmap.txtThe raw output from nmap, in XML format Download
Exploit SQL Injection and bypass captcha with SQLMAP
https://4bdoz.medium.com/exploit-sql-injection-and-bypass-captcha-with-sqlmap-81e6fa1d4cd8?source=rss------bug_bounty-5
https://4bdoz.medium.com/exploit-sql-injection-and-bypass-captcha-with-sqlmap-81e6fa1d4cd8?source=rss------bug_bounty-5
Kenzy challenge (Cyber wargames 2022)Continue reading on Medium » (https://4bdoz.medium.com/exploit-sql-injection-and-bypass-captcha-with-sqlmap-81e6fa1d4cd8?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Smap - A Drop-In Replacement For Nmap Powered By Shodan.Io
https://blogger.googleusercontent.com/img/a/AVvXsEjTp46z-nQDLPd9k8m95mz1ojUtMfyM5cYUE4H5Z5U6EHhWQsNZfy1ZmCB_6vepViTQwzsIrhJG9gYrIbp_uUJEpY_8ecWISPJcEcxJClqFT6gNE3SRYU2R1iXliKZoC0gSrp9iagvMRQEnKKLMPY6dmCKzXNhzRE3r6LCx1yTOQizU0lfJ9UDaO8Hi=w640-h278 Smap is a replica of Nmap which uses shodan.io's free API for port scanning. It takes same command line arguments as Nmap and produces the same output which makes it a drop-in replacament for Nmap. Features* Scans 200 hosts per second
* Doesn't require any account/api key
* Vulnerability detection
* Supports all nmap's output formats
* Service and version fingerprinting
* Makes no contact to the targets InstallationBinariesYou can download a pre-built binary from here and use it right away. Manual
Supported formats
* a super fast port scanner
* results for most common ports (top 1237)
* no connections to be made to the targets You are okay with* not being able to scan IPv6 addresses
* results being up to 7 days old
* a few false negatives Download Smap
Smap - A Drop-In Replacement For Nmap Powered By Shodan.Io
https://blogger.googleusercontent.com/img/a/AVvXsEjTp46z-nQDLPd9k8m95mz1ojUtMfyM5cYUE4H5Z5U6EHhWQsNZfy1ZmCB_6vepViTQwzsIrhJG9gYrIbp_uUJEpY_8ecWISPJcEcxJClqFT6gNE3SRYU2R1iXliKZoC0gSrp9iagvMRQEnKKLMPY6dmCKzXNhzRE3r6LCx1yTOQizU0lfJ9UDaO8Hi=w640-h278 Smap is a replica of Nmap which uses shodan.io's free API for port scanning. It takes same command line arguments as Nmap and produces the same output which makes it a drop-in replacament for Nmap. Features* Scans 200 hosts per second
* Doesn't require any account/api key
* Vulnerability detection
* Supports all nmap's output formats
* Service and version fingerprinting
* Makes no contact to the targets InstallationBinariesYou can download a pre-built binary from here and use it right away. Manual
go install -v github.com/s0md3v/smap/cmd/smap@latestConfused or something not working? For more detailed instructions, click here AUR pacakgeSmap is available on AUR as smap-git (builds from source) and smap-bin (pre-built binary). Homebrew/MacSmap is also avaible on Homebrew. brew update
brew install smap UsageSmap takes the same arguments as Nmap but options other than -p, -h, -o*, -iLare ignored. If you are unfamiliar with Nmap, here's how to use Smap. Specifying targetssmap 127.0.0.1 127.0.0.2 You can also use a list of targets, seperated by newlines. smap -iL targets.txt Supported formats 1.1.1.1 // IPv4 address
example.com // hostname
178.23.56.0/8 // CIDR OutputSmap supports 6 output formats which can be used with the -o* as follows smap example.com -oX output.xml If you want to print the output to terminal, use hyphen (-) as filename.Supported formats
oX // nmap's xml format
oG // nmap's greppable format
oN // nmap's default format
oA // output in all 3 formats above at once
oP // IP:PORT pairs seperated by newlines
oS // custom smap format
oJ // json Note: Since Nmap doesn't scan/display vulnerabilities and tags, that data is not available in nmap's formats. Use -oSto view that info. Specifying portsSmap scans these 1237 ports by default. If you want to display results for certain ports, use the -poption. smap -p21-30,80,443 -iL targets.txt ConsiderationsSince Smap simply fetches existent port data from shodan.io, it is super fast but there's more to it. You should use Smap if: You want* vulnerability detection* a super fast port scanner
* results for most common ports (top 1237)
* no connections to be made to the targets You are okay with* not being able to scan IPv6 addresses
* results being up to 7 days old
* a few false negatives Download Smap