Hacking Articles Tips Tricks Videos Tutorials
Hashcat from the TrustedSec team. * Naive hashcat - Naive hashcat is a plug-and-play script that is pre-configured with naive, emperically-tested, "good enough" parameters/attack types. Distributed cracking* CrackLord - Queue and resource system for cracking…
cking).
* Gorilla - Tool for generating wordlists or extending an existing one using mutations.
* Keyboard-Walk-Generators - Generate Keyboard Walk Dictionaries for cracking.
* kwprocessor - Advanced keyboard-walk generator with configureable basechars, keymap and routes.
* maskprocessor - High-performance word generator with a per-position configureable charset.
* maskuni - A standalone fast word generator in the spirit of hashcat's mask generator with unicode support.
* Mentalist - Mentalist is a graphical tool for custom wordlist generation. It utilizes common human paradigms for constructing passwords and can output the full wordlist as well as rules compatible with Hashcat and John the Ripper.
* Phraser - Phraser is a phrase generator using n-grams and Markov chains to generate phrases for passphrase cracking.
* princeprocessor - Standalone password candidate generator using the PRINCE algorithm.
* Rephraser - A Python-based reimagining of Phraser using Markov-chains for linguistically-correct password cracking.
* Rling - RLI Next Gen (Rling), a faster multi-threaded, feature rich alternative to rli found in hashcat utilities.
* statsprocessor - Word generator based on per-position markov-chains.
* TTPassGen - Flexible and scriptable password dictionary generator which supportss brute-force, combination, complex rule modes etc.
* token-reverser - Words list generator to crack security tokens.
* WikiRaider - WikiRaider enables you to generate wordlists based on country specific databases of Wikipedia. WordlistsLaguage specific* Albanian wordlist - A mix of names, last names and some albanian literature.
* Danish Phone Wordlist Generator - This tool can generate wordlists of Danish phone numbers by area and/or usage (Mobile, landline etc.) Useful for password cracking or fuzzing Danish targets.
* Danish Wordlists - Collection of danish wordlists for cracking danish passwords.
* French Wordlists - This project aim to provide french word list about everything a person could use as a base password. Other* Packet Storm Wordlists - A substantial collection of different wordlists in multiple languages.
* Rocktastic - Includes many permutations of passwords and patterns that have been observed in the wild.
* RockYou2021 - RockYou2021.txt is a MASSIVE WORDLIST compiled of various other wordlists.
* WeakPass - Collection of large wordlists. Specific file formatsPDF* pdfrip - A multi-threaded PDF password cracking utility equipped with commonly encountered password format builders and dictionary attacks. PEM* pemcracker - Tool to crack encrypted PEM files. JKS* JKS private key cracker - Cracking passwords of private key entries in a JKS fileCracking passwords of private key entries in a JKS file. ZIP* bkcrack - Crack legacy zip encryption with Biham and Kocher's known plaintext attack.
* frackzip - Small tool for cracking encrypted ZIP archives. Artificial Intelligence* adams - Reducing Bias in Modeling Real-world Password Strength via Deep Learning and Dynamic Dictionaries. - Code for cracking passwords with neural networks.
* RNN-Passwords - Using the char-rnn to learn and guess passwords.
* rulesfinder - This tool finds efficient password mangling rules (for John the Ripper or Hashcat) for a given dictionary and a list of passwords. ResearchPapers* Generating Optimized Guessing Candidates toward Better Password Cracking from Multi-Dictionaries Using Relativistic GAN (2020)
* GENPass: A General Deep Learning Model for Password Guessing with PCFG Rules and Adversarial Generation (2018)
* Password Cracking Using Probabilistic Context-Free Grammars (2009)
* Reducing Bias in Modeling Real-world Password Strength via Deep Learning and Dynamic Dictionaries (2020)
* Fast, Lean, and Accurate: Modeling Password Guessability Using Neural Networks (2016)
* PassGAN: A Deep Learning Approach for Password Guessing (2017) Talks* DEF CON Safe Mode Password Village - Getting Started wit[...]
___________________________
@hacking_Attack
@Hacking_Video
* Gorilla - Tool for generating wordlists or extending an existing one using mutations.
* Keyboard-Walk-Generators - Generate Keyboard Walk Dictionaries for cracking.
* kwprocessor - Advanced keyboard-walk generator with configureable basechars, keymap and routes.
* maskprocessor - High-performance word generator with a per-position configureable charset.
* maskuni - A standalone fast word generator in the spirit of hashcat's mask generator with unicode support.
* Mentalist - Mentalist is a graphical tool for custom wordlist generation. It utilizes common human paradigms for constructing passwords and can output the full wordlist as well as rules compatible with Hashcat and John the Ripper.
* Phraser - Phraser is a phrase generator using n-grams and Markov chains to generate phrases for passphrase cracking.
* princeprocessor - Standalone password candidate generator using the PRINCE algorithm.
* Rephraser - A Python-based reimagining of Phraser using Markov-chains for linguistically-correct password cracking.
* Rling - RLI Next Gen (Rling), a faster multi-threaded, feature rich alternative to rli found in hashcat utilities.
* statsprocessor - Word generator based on per-position markov-chains.
* TTPassGen - Flexible and scriptable password dictionary generator which supportss brute-force, combination, complex rule modes etc.
* token-reverser - Words list generator to crack security tokens.
* WikiRaider - WikiRaider enables you to generate wordlists based on country specific databases of Wikipedia. WordlistsLaguage specific* Albanian wordlist - A mix of names, last names and some albanian literature.
* Danish Phone Wordlist Generator - This tool can generate wordlists of Danish phone numbers by area and/or usage (Mobile, landline etc.) Useful for password cracking or fuzzing Danish targets.
* Danish Wordlists - Collection of danish wordlists for cracking danish passwords.
* French Wordlists - This project aim to provide french word list about everything a person could use as a base password. Other* Packet Storm Wordlists - A substantial collection of different wordlists in multiple languages.
* Rocktastic - Includes many permutations of passwords and patterns that have been observed in the wild.
* RockYou2021 - RockYou2021.txt is a MASSIVE WORDLIST compiled of various other wordlists.
* WeakPass - Collection of large wordlists. Specific file formatsPDF* pdfrip - A multi-threaded PDF password cracking utility equipped with commonly encountered password format builders and dictionary attacks. PEM* pemcracker - Tool to crack encrypted PEM files. JKS* JKS private key cracker - Cracking passwords of private key entries in a JKS fileCracking passwords of private key entries in a JKS file. ZIP* bkcrack - Crack legacy zip encryption with Biham and Kocher's known plaintext attack.
* frackzip - Small tool for cracking encrypted ZIP archives. Artificial Intelligence* adams - Reducing Bias in Modeling Real-world Password Strength via Deep Learning and Dynamic Dictionaries. - Code for cracking passwords with neural networks.
* RNN-Passwords - Using the char-rnn to learn and guess passwords.
* rulesfinder - This tool finds efficient password mangling rules (for John the Ripper or Hashcat) for a given dictionary and a list of passwords. ResearchPapers* Generating Optimized Guessing Candidates toward Better Password Cracking from Multi-Dictionaries Using Relativistic GAN (2020)
* GENPass: A General Deep Learning Model for Password Guessing with PCFG Rules and Adversarial Generation (2018)
* Password Cracking Using Probabilistic Context-Free Grammars (2009)
* Reducing Bias in Modeling Real-world Password Strength via Deep Learning and Dynamic Dictionaries (2020)
* Fast, Lean, and Accurate: Modeling Password Guessability Using Neural Networks (2016)
* PassGAN: A Deep Learning Approach for Password Guessing (2017) Talks* DEF CON Safe Mode Password Village - Getting Started wit[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
cking). * Gorilla - Tool for generating wordlists or extending an existing one using mutations. * Keyboard-Walk-Generators - Generate Keyboard Walk Dictionaries for cracking. * kwprocessor - Advanced keyboard-walk generator with configureable basechars, keymap…
h Hashcat
* DEF CON Safe Mode Password Village - Jeremi Gosney - Cracking at Extreme Scale
* Tailored, Machine Learning-driven Password Guessing Attacks and Mitigation at DefCamp
* UNHash - Methods for better password cracking
* USENIX Security '21 - Reducing Bias in Modeling Real-world Password Strength via Deep Learning and Dynamic Dictionaries
* USENIX Security '16 - Fast, Lean, and Accurate: Modeling Password Guessability Using Neural Networks Awesome-Password-Cracking
___________________________
@hacking_Attack
@Hacking_Video
* DEF CON Safe Mode Password Village - Jeremi Gosney - Cracking at Extreme Scale
* Tailored, Machine Learning-driven Password Guessing Attacks and Mitigation at DefCamp
* UNHash - Methods for better password cracking
* USENIX Security '21 - Reducing Bias in Modeling Real-world Password Strength via Deep Learning and Dynamic Dictionaries
* USENIX Security '16 - Fast, Lean, and Accurate: Modeling Password Guessability Using Neural Networks Awesome-Password-Cracking
___________________________
@hacking_Attack
@Hacking_Video
Saving more than 100,000 website from a Watering Hole attack
https://med-mahmoudi26.medium.com/saving-more-than-100-000-website-from-a-watering-hole-attack-a22f63a37f94?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://med-mahmoudi26.medium.com/saving-more-than-100-000-website-from-a-watering-hole-attack-a22f63a37f94?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Saving more than 100,000 website from a Watering Hole attack
Watering hole is a computer attack strategy in which an attacker guesses or observes which websites an organization often uses and infects…
Watering hole is a computer attack strategy in which an attacker guesses or observes which websites an organization often uses and infects…Continue reading on Medium » (https://med-mahmoudi26.medium.com/saving-more-than-100-000-website-from-a-watering-hole-attack-a22f63a37f94?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Saving more than 100,000 website from a Watering Hole attack
Watering hole is a computer attack strategy in which an attacker guesses or observes which websites an organization often uses and infects…
Pentesting/bug bounty and not leaving vulnerabilities behind
https://www.reddit.com/r/Pentesting/comments/x2dr8a/pentestingbug_bounty_and_not_leaving/
submitted by /u/DerekFoReal777 (https://www.reddit.com/user/DerekFoReal777)
[link] (https://www.reddit.com/r/Hacking_Tutorials/comments/wz2go8/pentestingbug_bounty_and_not_leaving/) [comments] (https://www.reddit.com/r/Pentesting/comments/x2dr8a/pentestingbug_bounty_and_not_leaving/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/x2dr8a/pentestingbug_bounty_and_not_leaving/
submitted by /u/DerekFoReal777 (https://www.reddit.com/user/DerekFoReal777)
[link] (https://www.reddit.com/r/Hacking_Tutorials/comments/wz2go8/pentestingbug_bounty_and_not_leaving/) [comments] (https://www.reddit.com/r/Pentesting/comments/x2dr8a/pentestingbug_bounty_and_not_leaving/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Pentesting/bug bounty and not leaving vulnerabilities behind
Posted in r/Pentesting by u/DerekFoReal777 • 1 point and 0 comments
‘PTN’ infosec monthly #3— InfoSec Updates
https://medium.com/pentesternepal/ptn-infosec-monthly-3-infosec-updates-c28273328f78?source=rss------bug_bounty-5
Namaste everyone,
Welcome to ‘PTN’ infosec monthly #3. We are back with the third newsletter with infosec updates. We started ‘PTN infosec…Continue reading on Pentester Nepal » (https://medium.com/pentesternepal/ptn-infosec-monthly-3-infosec-updates-c28273328f78?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/pentesternepal/ptn-infosec-monthly-3-infosec-updates-c28273328f78?source=rss------bug_bounty-5
Namaste everyone,
Welcome to ‘PTN’ infosec monthly #3. We are back with the third newsletter with infosec updates. We started ‘PTN infosec…Continue reading on Pentester Nepal » (https://medium.com/pentesternepal/ptn-infosec-monthly-3-infosec-updates-c28273328f78?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
‘PTN’ infosec monthly #3— InfoSec Updates
Namaste everyone, Welcome to ‘PTN’ infosec monthly #3. We are back with the third newsletter with infosec updates. We started ‘PTN infosec…
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
I made an UDP packet analysis tool in Node.JS
https://external-preview.redd.it/ZquPAU8cZhn0mo04ZhRduLjfjWqLtXZZPPqxxp1O98E.jpg?width=640&crop=smart&auto=webp&s=850372ef18372a4dd28079ffd6f4b3bbda3c82c7 submitted by /u/PANCHO7532
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
I made an UDP packet analysis tool in Node.JS
https://external-preview.redd.it/ZquPAU8cZhn0mo04ZhRduLjfjWqLtXZZPPqxxp1O98E.jpg?width=640&crop=smart&auto=webp&s=850372ef18372a4dd28079ffd6f4b3bbda3c82c7 submitted by /u/PANCHO7532
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
I made an UDP packet analysis tool in Node.JS
Posted in r/hacking by u/PANCHO7532 • 0 points and 0 comments
‘PTN’ infosec monthly #3— InfoSec Updates
Namaste everyone, Welcome to ‘PTN’ infosec monthly #3. We are back with the third newsletter with infosec updates. We started ‘PTN infosec…Continue reading on Pentester Nepal »
Read more...
Namaste everyone, Welcome to ‘PTN’ infosec monthly #3. We are back with the third newsletter with infosec updates. We started ‘PTN infosec…Continue reading on Pentester Nepal »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
My CyberSecurity journey — What I am doing now ?
https://cdn-images-1.medium.com/max/600/0*_OsvQovdQiAjN5x8.png
Since I want to find a way to CyberSecurity and Ethical Hacking, i have noted that having 24 hours in a day is REALLY, REALLY short !
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
My CyberSecurity journey — What I am doing now ?
https://cdn-images-1.medium.com/max/600/0*_OsvQovdQiAjN5x8.png
Since I want to find a way to CyberSecurity and Ethical Hacking, i have noted that having 24 hours in a day is REALLY, REALLY short !
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
My CyberSecurity journey — What I am doing now ?
Since I want to find a way to CyberSecurity and Ethical Hacking, i have noted that having 24 hours in a day is REALLY, REALLY short !
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Blood (CTF Challenges)
https://cdn-images-1.medium.com/max/600/1*ci0xL3MMGpvwkj-rgNsSuQ.png
Hi everyone,
This is my first post on medium
Here I want to share my journey in CTF Challenges.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Blood (CTF Challenges)
https://cdn-images-1.medium.com/max/600/1*ci0xL3MMGpvwkj-rgNsSuQ.png
Hi everyone,
This is my first post on medium
Here I want to share my journey in CTF Challenges.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Blood (CTF Challenges)
Hi everyone, This is my first post on medium Here I want to share my journey in CTF Challenges.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
dBmonster : Track WiFi Devices With Their Recieved Signal Strength
dBmonster you are able to scan for nearby WiFi devices and track them trough the signal strength (dBm) of their sent packets (sniffed with TShark). These dBm values will be plotted to a graph with matplotlib. It can help you to identify the exact location of nearby WiFi devices (use a directional WiFi antenna for the best results) or to find out how your self made antenna works the best (antenna radiation patterns).
Features on Linux and MacOS
FeatureLinuxMacOSListing WiFi interfaceshttps://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png Track & scan on 2.4GHzhttps://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png Track & scan on 5GHzhttps://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png Scanning for APhttps://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png Scanning for STAhttps://s.w.org/images/core/emoji/14.0.0/72x72/2705.png Beep when device foundhttps://s.w.org/images/core/emoji/14.0.0/72x72/2753.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png
Installation
git clone https://github.com/90N45-d3v/dBmonster
cd dBmonster
Install required tools (On MacOS without sudo)
sudo python requirements.py
Start dBmonster
sudo python dBmonster.py
Has been successfully tested on
Platform https://s.w.org/images/core/emoji/14.0.0/72x72/1f4bb.png WiFi Adapter https://s.w.org/images/core/emoji/14.0.0/72x72/1f4e1.png Kali LinuxALFA AWUS036NHA, DIY Bi-Quad WiFi AntennaMacOS MontereyInternal card 802.11 a/b/g/n/ac (MBP 2019) * should work on any MacOS or Debian based system and with every WiFi card that supports monitor-mode
Download
___________________________
@hacking_Attack
@Hacking_Video
dBmonster : Track WiFi Devices With Their Recieved Signal Strength
dBmonster you are able to scan for nearby WiFi devices and track them trough the signal strength (dBm) of their sent packets (sniffed with TShark). These dBm values will be plotted to a graph with matplotlib. It can help you to identify the exact location of nearby WiFi devices (use a directional WiFi antenna for the best results) or to find out how your self made antenna works the best (antenna radiation patterns).
Features on Linux and MacOS
FeatureLinuxMacOSListing WiFi interfaceshttps://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png Track & scan on 2.4GHzhttps://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png Track & scan on 5GHzhttps://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png Scanning for APhttps://s.w.org/images/core/emoji/14.0.0/72x72/2705.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png Scanning for STAhttps://s.w.org/images/core/emoji/14.0.0/72x72/2705.png Beep when device foundhttps://s.w.org/images/core/emoji/14.0.0/72x72/2753.png https://s.w.org/images/core/emoji/14.0.0/72x72/2705.png
Installation
git clone https://github.com/90N45-d3v/dBmonster
cd dBmonster
Install required tools (On MacOS without sudo)
sudo python requirements.py
Start dBmonster
sudo python dBmonster.py
Has been successfully tested on
Platform https://s.w.org/images/core/emoji/14.0.0/72x72/1f4bb.png WiFi Adapter https://s.w.org/images/core/emoji/14.0.0/72x72/1f4e1.png Kali LinuxALFA AWUS036NHA, DIY Bi-Quad WiFi AntennaMacOS MontereyInternal card 802.11 a/b/g/n/ac (MBP 2019) * should work on any MacOS or Debian based system and with every WiFi card that supports monitor-mode
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
dBmonster : Track WiFi Devices With Their Recieved Signal Strength
dBmonster you are able to scan for nearby WiFi devices and track them trough the signal strength (dBm) of their sent packets.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
System Informer : A Free, Powerful, Multi-Purpose Tool That Helps You Monitor System Resources, Debug Software And Detect Malware
System Informer, A free, powerful, multi-purpose tool that helps you monitor system resources, debug software and detect malware. Brought to you by Winsider Seminars & Solutions, Inc.
System requirements
Windows 7 or higher, 32-bit or 64-bit.
Features
* A detailed overview of system activity with highlighting.
* Graphs and statistics allow you quickly to track down resource hogs and runaway processes.
* Can’t edit or delete a file? Discover which processes are using that file.
* See what programs have active network connections, and close them if necessary.
* Get real-time information on disk access.
* View detailed stack traces with kernel-mode, WOW64 and .NET support.
* Go beyond services.msc: create, edit and control services.
* Small, portable and no installation required.
* 100% Free Software (MIT)
Building the project
Requires Visual Studio (2022 or later).
Execute
You can download the free Visual Studio Community Edition to build the System Informer source code.
See the build readme for more information or if you’re having trouble building.
Enhancements/Bugs
Please use the GitHub issue tracker for reporting problems or suggesting new features.
Settings
If you are running System Informer from a USB drive, you may want to save System Informer’s settings there as well. To do this, create a blank file named “SystemInformer.exe.settings.xml” in the same directory as SystemInformer.exe. You can do this using Windows Explorer:
* Make sure “Hide extensions for known file types” is unticked in Tools > Folder options > View.
* Right-click in the folder and choose New > Text Document.
* Rename the file to SystemInformer.exe.settings.xml (delete the “.txt” extension).
Download
___________________________
@hacking_Attack
@Hacking_Video
System Informer : A Free, Powerful, Multi-Purpose Tool That Helps You Monitor System Resources, Debug Software And Detect Malware
System Informer, A free, powerful, multi-purpose tool that helps you monitor system resources, debug software and detect malware. Brought to you by Winsider Seminars & Solutions, Inc.
System requirements
Windows 7 or higher, 32-bit or 64-bit.
Features
* A detailed overview of system activity with highlighting.
* Graphs and statistics allow you quickly to track down resource hogs and runaway processes.
* Can’t edit or delete a file? Discover which processes are using that file.
* See what programs have active network connections, and close them if necessary.
* Get real-time information on disk access.
* View detailed stack traces with kernel-mode, WOW64 and .NET support.
* Go beyond services.msc: create, edit and control services.
* Small, portable and no installation required.
* 100% Free Software (MIT)
Building the project
Requires Visual Studio (2022 or later).
Execute
build_release.cmdlocated in the builddirectory to compile the project or load the SystemInformer.slnand Plugins.slnsolutions if you prefer building the project using Visual Studio.You can download the free Visual Studio Community Edition to build the System Informer source code.
See the build readme for more information or if you’re having trouble building.
Enhancements/Bugs
Please use the GitHub issue tracker for reporting problems or suggesting new features.
Settings
If you are running System Informer from a USB drive, you may want to save System Informer’s settings there as well. To do this, create a blank file named “SystemInformer.exe.settings.xml” in the same directory as SystemInformer.exe. You can do this using Windows Explorer:
* Make sure “Hide extensions for known file types” is unticked in Tools > Folder options > View.
* Right-click in the folder and choose New > Text Document.
* Rename the file to SystemInformer.exe.settings.xml (delete the “.txt” extension).
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
System Informer : A Free, Powerful, Multi-Purpose Tool
System Informer, A free, powerful, multi-purpose tool that helps you monitor system resources, debug software and detect malware.
Burp Suite + Quickbooks
https://www.reddit.com/r/Pentesting/comments/x2jxey/burp_suite_quickbooks/
Hello! Question for any who have any ideas: is there a way to intercept and view traffic from QuickBooks to a banking website in a tool like Burp Suite or similar? Some background: I am reviewing a banking website, and it offers the option to link QuickBooks and other such software to the account using a person's normal online banking creds. I have a hypothesis that there may be some portions of the website this uses that might be vulnerable to attack (as they are not intended to be seen by users and instead are just passthroughs for QuickBooks). So I would like to map them out, sample the typical requests, and manipulate them. I have added the Burp Suite CA and set my system proxy to a listening Burp Suite proxy, and confirmed I can intercept browser traffic as normal. However, when I download the trial version of QuickBooks and try to connect it to the bank account, the connection fails. It succeeds if I stop trying to proxy through Burp Suite. It seems likely that QuickBooks isn't trusting the burp Suite CA I installed (it probably has its own CAs it trusts). But I'm not sure if I'm neglecting something, or if anyone has encountered a similar issue. Any thoughts? Any other tools/approaches that might be good for exploring this avenue of attack further? Thank you very much! submitted by /u/helmutye (https://www.reddit.com/user/helmutye)
[link] (https://www.reddit.com/r/Pentesting/comments/x2jxey/burp_suite_quickbooks/) [comments] (https://www.reddit.com/r/Pentesting/comments/x2jxey/burp_suite_quickbooks/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/x2jxey/burp_suite_quickbooks/
Hello! Question for any who have any ideas: is there a way to intercept and view traffic from QuickBooks to a banking website in a tool like Burp Suite or similar? Some background: I am reviewing a banking website, and it offers the option to link QuickBooks and other such software to the account using a person's normal online banking creds. I have a hypothesis that there may be some portions of the website this uses that might be vulnerable to attack (as they are not intended to be seen by users and instead are just passthroughs for QuickBooks). So I would like to map them out, sample the typical requests, and manipulate them. I have added the Burp Suite CA and set my system proxy to a listening Burp Suite proxy, and confirmed I can intercept browser traffic as normal. However, when I download the trial version of QuickBooks and try to connect it to the bank account, the connection fails. It succeeds if I stop trying to proxy through Burp Suite. It seems likely that QuickBooks isn't trusting the burp Suite CA I installed (it probably has its own CAs it trusts). But I'm not sure if I'm neglecting something, or if anyone has encountered a similar issue. Any thoughts? Any other tools/approaches that might be good for exploring this avenue of attack further? Thank you very much! submitted by /u/helmutye (https://www.reddit.com/user/helmutye)
[link] (https://www.reddit.com/r/Pentesting/comments/x2jxey/burp_suite_quickbooks/) [comments] (https://www.reddit.com/r/Pentesting/comments/x2jxey/burp_suite_quickbooks/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Burp Suite + Quickbooks
UPDATE: Figured it out--you have to install the Burp Suite / Portswigger CA as a Trusted Root CA on the local machine (doing it through a browser...
Rotation IP Address with Burpsuite
https://medium.com/@mil3anism/rotation-ip-address-with-burpsuite-24b315bbc4a5?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@mil3anism/rotation-ip-address-with-burpsuite-24b315bbc4a5?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Rotation IP Address with Burpsuite
Hi, For those of you who are unfamiliar with what IP Rotation is, I’m going to share a quick tip and trick with you all on how to use…