Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Smap : A Drop-In Replacement For Nmap Powered By Shodan.Io

Smap is a port scanner built with shodan.io’s free API. It takes same command line arguments as Nmap and produces the same output which makes it a drop-in replacament for Nmap.

Features

* Scans 200 hosts per second
* Doesn’t require any account/api key
* Vulnerability detection
* Supports all nmap’s output formats
* Service and version fingerprinting
* Makes no contact to the targets

Installation

Binaries

You can download a pre-built binary from here and use it right away.

Manual

go install -v github.com/s0md3v/smap/cmd/smap@latest

Confused or something not working? For more detailed instructions, click here

AUR pacakge

Smap is available on AUR as smap-git (builds from source) and smap-bin (pre-built binary).

Homebrew/Mac

Smap is also avaible on Homebrew.

brew update
brew install smap

Usage

Smap takes the same arguments as Nmap but options other than -p, -h, -o*, -iLare ignored. If you are unfamiliar with Nmap, here’s how to use Smap.

Specifying targets

smap 127.0.0.1 127.0.0.2

You can also use a list of targets, seperated by newlines.

smap -iL targets.txt

Supported formats

1.1.1.1 // IPv4 address
example.com // hostname
178.23.56.0/8 // CIDR

Output

Smap supports 6 output formats which can be used with the -o* as follows

smap example.com -oX output.xml

If you want to print the output to terminal, use hyphen (-) as filename.

Supported formats

oX // nmap’s xml format
oG // nmap’s greppable format
oN // nmap’s default format
oA // output in all 3 formats above at once
oP // IP:PORT pairs seperated by newlines
oS // custom smap format
oJ // json

Note: Since Nmap doesn’t scan/display vulnerabilities and tags, that data is not available in nmap’s formats. Use -oSto view that info.

Specifying ports

Smap scans these 1237 ports by default. If you want to display results for certain ports, use the -poption.

smap -p21-30,80,443 -iL targets.txt
Download

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
BlackStone : Pentesting Reporting Tool

BlackStone project or “BlackStone Project” is a tool created in order to automate the work of drafting and submitting a report on audits of ethical hacking or pentesting.

In this tool we can register in the database the vulnerabilities that we find in the audit, classifying them by internal, external audit or wifi, in addition, we can put your description and recommendation, as well as the level of severity and effort for its correction. This information will then help us generate in the report a criticality table as a global summary of the vulnerabilities found.

We can also register a company and, just by adding its web page, the tool will be able to find subdomains, telephone numbers, social networks, employee emails… Docker InstallInstall Docker

/bin/bash -c “$(curl -fsSL https://get.docker.com)”
systemctl enable docker
systemctl start docker

Install docker-compose

sudo curl -L “https://github.com/docker/compose/releases/download/1.29.2/docker-compose-$(uname -s)-$(uname -m)” -o /usr/local/bin/docker-compose
chmod +x /usr/local/bin/docker-compose Install BlackStonegit clone https://github.com/micro-joan/BlackStone
cd BlackStone
docker-compose up -d Manual Install* First we must download an Apache server to host the tool, in my case I use Mamp (I recommend following these steps): https://www.mamp.info/en/downloads/
* We will download the content of this repository and we will have 2 folders (BlackStone and BBDD)
* Once the server starts we will go to c://MAMP/htdocs and paste all the contents of the downloaded folder “BlackStone”
* For the application to work we will have to import the database, we will go to our browser and write “localhost/phpMyAdmin/”, you have the database connection file in the folder BlackStone/conexion.php
* We will create a database called blackstone and import the data from the downloaded BBDD folder
* Log in to BlackStone with the username and password “blackstone” UseFirst you need to go to profile settings and add Hunter.io and haveibeenpwned.com tokens:
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjJCzvYjxykBUCgbyq2MY4Y6nxe2JAtOdRIb0FUfBKlAN_uzY_8YcEOukGspiJ4Rmr7urB9cJ4326Utn6UYvvPnwlkm0PDJaiiQEMmcBeFx-tq5vZFrWH3ozO9iayE_bmUI-daPK40iscaZWFIH_hbp73eFergA6r0GDjJWBQsh7RIrkQRiF4nfjp7B/s900/182502047-36e2b125-de44-463f-8c74-9b8b2cab14e4.gif
After having vulnerabilities in the database, we will go to the audited client and we will register a client along with their web page, once registered we can go to customer details and we can see the following information:

THE USE OF THIS APPLICATION IS FOR PROFESSIONAL USE, THE AUTHOR IS NOT RESPONSIBLE FOR A MISUSE EMPLOYED

* Name of business owner
* Social networks of the company owner
* Email and telephone number of the owner of the company
* Exposed password check on the company owner’s deep web
* Subdomains of the website as well as information of interest found in google
* Emails of company workers
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjrgFCN1NZdZ4fwdsQ_nE9nPXSZ0FNuQX0qooOCfu9X2gbOlcXwBo4qRiYTRy5w9BRINbCoel8GJEMWiNFcx0WMyf-I5RUPO1TuvlIvptUL4PHEmqn1XH80yAEDN9ZaSkBs1yyV9NKd8mFTf-rrCbv4UR4QhCqWYxuO1GIvikpjjGdQzWIYFmpdUUq4/s900/182502564-02929088-2584-4cd9-9d1a-52ce6cb69f17.gif
Once we have the company that we are going to audit registered in the database, we will create a report, adding the date, name of the report and the company to which will be audited. When we register the report, we will give it edit and then we will select the vulnerabilities that we want to appear in the report:
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEglG07CEOD6w097fDIQJ04ACFGxwNRz_GkRlylE0kAT0Nlade3hqquj3gWhWrsULEZl6cDLF0IJH16OlXzTLTTyPdZIXdM2eVpJRmcPYXit89DONac8LZ3Aj4gKOTLBrAiHJAknUtRV0R8eHggGmpRi8tIh6a5JZCPlyuPiDR8Li4hRcmXZQ89NkhvZ/s900/182503343-c1990024-83f2-4c4b-b524-08719d775cac.[...]

___________________________
@hacking_Attack
@Hacking_Video