Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Scan4All - Vuls Scan: 15000+PoCs; 21 Kinds Of Application Password Crack; 7000+Web Fingerprints; 146 Protocols And 90000+ Rules Port Scanning; Fuzz, HW, Awesome BugBounty...

https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEisTJxJ4U78kCBktVvucfEIDh57XmKW1q6sBmDzUOpTpKc8MJ-Cn1Hxzu4dBdCO86QZ2nWnmkzV_Pw8OkuBxyTJ28khyAkBnUeaBU8VHPHemkCET7Zps8erD1mh0n7aLwSm0kLSqxmLKtBTSRS_f8VFXlb6ZfoxUPrXkEERIJG_ngKJvbx_CqzTpbzZ2g/w640-h500/scan4all_4.png * What is scan4all: integrated vscan, nuclei, ksubdomain, subfinder, etc., fully automated and intelligent。red team tools Code-level optimization, parameter optimization, and individual modules, such as vscan filefuzz, have been rewritten for these integrated projects. In principle, do not repeat the wheel, unless there are bugs, problems
* Cross-platform: based on golang implementation, lightweight, highly customizable, open source, supports Linux, windows, mac os, etc.
* Support [21] password blasting, support custom dictionary, open by "priorityNmap": true
* RDP
* SSH
* rsh-spx
* Mysql
* MsSql
* Oracle
* Postgresql
* Redis
* FTP
* Mongodb
* SMB, also detect MS17-010 (CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, CVE-2017-0147, CVE-2017-0148), SmbGhost (CVE- 2020-0796)
* Telnet
* Snmp
* Wap-wsp (Elasticsearch)
* RouterOs
* HTTP BasicAuth
* Weblogic, enable nuclei through enableNuclei=true at the same time, support T3, IIOP and other detection
* Tomcat
* Jboss
* Winrm(wsman)
* POP3

* By default, http password intelligent blasting is enabled, and it will be automatically activated when an HTTP password is required, without manual intervention
* Detect whether there is nmap in the system, and enable nmap for fast scanning through priorityNmap=true, which is enabled by default, and the optimized nmap parameters are faster than masscan Disadvantages of using nmap: Is the network bad, because the traffic network packet is too large, which may lead to incomplete results Using nmap additionally requires setting the root password to an environment variable export PPSSWWDD=yourRootPswd More references: config/doNmapScan.sh By default, naabu is used to complete port scanning -stats=true to view the scanning progress Can I not scan ports? noScan=true ./scan4all -l list.txt -v
# nmap result default noScan=true
./scan4all -l nmapRssuilt.xml -v
* Fast 15000+ POC detection capabilities, PoCs include:
* nuclei POC Nuclei Templates Top 10 statisticsTAGCOUNTAUTHORCOUNTDIRECTORYCOUNTSEVERITYCOUNTTYPECOUNTcve1294daffainfo605cves1277info1352http3554panel591dhiyaneshdk503exposed-panels600high938file76lfi486pikpikcu321vulnerabilities493medium766network50xss439pdteam269technologies266critical436dns17wordpress401geeknik187exposures254low211exposure355dwisiswant0169misconfiguration207unknown7cve20213220x_akoko154token-spray206rce313princechaddha147workflows187wp-plugin297pussycat0x128default-logins101tech282gy741126file76
281 directories, 3922 files.

* vscan POC
* vscan POC includes: xray 2.0 300+ POC, go POC, etc.

* scan4all POC

*
Support 7000+ web fingerprint scanning, identification:

* httpx fingerprint
* vscan fingerprint
* vscan fingerprint: including eHoleFinger, localFinger, etc.

* scan4all fingerprint

*
Support 146 protocols and 90000+ rule port scanning

* Depends on protocols and fingerprints supported by nmap

*
Fast HTTP sensitive file detection, can customize dictionary

*
Landing page detection

*
Supports multiple types of input - STDIN/HOST/IP/CIDR/URL/TXT

*
Supports multiple output types - JSON/TXT/CSV/STDOUT

*
Highly integratable: Configurable unified storage of results to Elasticsearch [strongly recommended]

*
Smart SSL Analysis:

* In-depth analysis, automatically correlate the scanning of domain names in SSL information, such as *.xxx.com, and complete subdomain traversal according [...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! Scan4All - Vuls Scan: 15000+PoCs; 21 Kinds Of Application Password Crack; 7000+Web Fingerprints; 146 Protocols And 90000+ Rules Port Scanning; Fuzz, HW, Awesome BugBounty... https://blogger.googleusercontent.com/img/b/R29vZ2xl/A…
to the configuration, and the result will automatically add the target to the scanning list
* Support to enable *.xx.com subdomain traversal function in smart SSL information, export EnableSubfinder=true, or adjust in the configuration file

*
Automatically identify the case of multiple IPs associated with a domain (DNS), and automatically scan the associated multiple IPs

*
Smart processing:

*
1. When the IPs of multiple domain names in the list are the same, merge port scans to improve efficiency

*
1. Intelligently handle http abnormal pages, and fingerprint calculation and learning
*
Automated supply chain identification, analysis and scanning

*
Link python3 log4j-scan

* This version blocks the bug that your target information is passed to the DNS Log Server to avoid exposing vulnerabilities
* Added the ability to send results to Elasticsearch for batch, touch typing
* There will be time in the future to implement the golang version how to use? mkdir ~/MyWork/;cd ~/MyWork/;git clone https://github.com/hktalent/log4j-scan*
Intelligently identify honeypots and skip targets. This function is disabled by default. You can set EnableHoneyportDetection=true to enable

*
Highly customizable: allow to define your own dictionary through config/config.json configuration, or control more details, including but not limited to: nuclei, httpx, naabu, etc.

*
support HTTP Request Smuggling: CL-TE、TE-CL、TE-TE、CL_CL、BaseErr https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhZVBr5mB-81add0R_jYDFS3DoG6-LqIH-yf_TNL3GDQ7Fa1SvL2WQg7FlOx3sKngftpPENspqEfbH6RHtp1XpuQ1EbQGdoq535hFyQc4ZQeJFRX1UyiAk2m5UbdSwsGZdEIfe0z6uLWYPexY4GhjHSlDp-PRQ7fobAnFQgx4BGwmOdmkIkdVYBtIbZAw/w640-h484/scan4all_5.png *
Support via parameter Cookie='PHPSession=xxxx' ./scan4all -host xxxx.com, compatible with nuclei, httpx, go-poc, x-ray POC, filefuzz, http Smuggling work processhttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_K6RURLfwpi_9Pv9y5F0u4eRgBjrt_UunLJB72vLweBPpbA_mPMurpM6U4cz4vuFyZfx8vldg4LnueHqSVVXiAnXxbOCWLByoOyJdLN1NLI2GEH_exnjPvN4Hkvm6TFQ2D1Gn-0gwGIcpXCUqdaAeCvaNyecpNsr4YBy9rNepINgNlF-jZUJ7wowO0g/w640-h358/workflow.jpg how to installdownload from Releases go install github.com/hktalent/scan4all@2.6.9
scan4all -h
how to use*
1. Start Elasticsearch, of course you can use the traditional way to output, results mkdir -p logs data
docker run --restart=always --ulimit nofile=65536:65536 -p 9200:9200 -p 9300:9300 -d --name es -v $PWD/logs:/usr/share/elasticsearch/logs -v $PWD /config/elasticsearch.yml:/usr/share/elasticsearch/config/elasticsearch.yml -v $PWD/config/jvm.options:/usr/share/elasticsearch/config/jvm.options -v $PWD/data:/ usr/share/elasticsearch/data hktalent/elasticsearch:7.16.2
# Initialize the es index, the result structure of each tool is different, and it is stored separately
./config/initEs.sh

# Search syntax, more query methods, learn Elasticsearch by yourself
http://127.0.0.1:9200/nmap_index/_doc/_search?q=_id:192.168.0.111
where 92.168.0.111 is the target to query
* Please install nmap by yourself before use Using Help go build
# Precise scan url list UrlPrecise=true
UrlPrecise=true ./scan4all -l xx.txt
# Disable adaptation to nmap and use naabu port to scan its internally defined http-related ports
priorityNmap=false ./scan4all -tp http -list allOut.txt -v
Work Plan* Integrate web-cache-vulnerability-scanner to realize HTTP smuggling smuggling and cache poisoning detection
* Linkage with metasploit-framework, on the premise that the system has been installed, cooperate with tmux, and complete the linkage with the macos environment as the best practice
* Integrate more fuzzers , such as linking sqlmap
* Integrate chromedp to achieve screenshots of landing pages, detection of front-end landing pages with pure js and js architecture, and corresponding crawlers (sensitive information detection, page crawling)
* Integrate nmap-go to improve ex[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
to the configuration, and the result will automatically add the target to the scanning list * Support to enable *.xx.com subdomain traversal function in smart SSL information, export EnableSubfinder=true, or adjust in the configuration file * Automatically…
ecution efficiency, dynamically parse the result stream, and integrate it into the current task waterfall
* Integrate ksubdomain to achieve faster subdomain blasting
* Integrate spider to find more bugs
* Semi-automatic fingerprint learning to improve accuracy; specify fingerprint name, configure Q & A* how use Cookie?
* libpcap related question

more see: discussions Changelog* 2022-07-20 fix and PR nuclei #2301 并发多实例的bug
* 2022-07-20 add web cache vulnerability scanner
* 2022-07-19 PR nuclei #2308 add dsl function: substr aes_cbc
* 2022-07-19 添加dcom Protocol enumeration network interfaces
* 2022-06-30 嵌入式集成私人版本nuclei-templates 共3744个YAML POC; 1、集成Elasticsearch存储中间结果 2、嵌入整个config目录到程序中
* 2022-06-27 优化模糊匹配,提高正确率、鲁棒性;集成ksubdomain进度
* 2022-06-24 优化指纹算法;增加工作流程图
* 2022-06-23 添加参数ParseSSl,控制默认不深度分析SSL中的DNS信息,默认不对SSL中dns进行扫描;优化:nmap未自动加.exe的bug;优化windows下缓存文件未优化体积的bug
* 2022-06-22 集成11种协议弱口令检测、密码爆破:ftp、mongodb、mssql、mysql、oracle、postgresql、rdp、redis、smb、ssh、telnet,同时优化支持外挂密码字典
* 2022-06-20 集成Subfinder,域名爆破,启动参数导出EnableSubfinder=true,注意启动后很慢; ssl证书中域名信息的自动深度钻取 允许通过 config/config.json 配置定义自己的字典,或设置相关开关
* 2022-06-17 优化一个域名多个IP的情况,所有IP都会被端口扫描,然后按照后续的扫描流程
* 2022-06-15 此版本增加了过去实战中获得的几个weblogic密码字典和webshell字典
* 2022-06-10 完成核的整合,当然包括核模板的整合
* 2022-06-07 添加相似度算法来检测 404
* 2022-06-07 增加http url列表精准扫描参数,根据环境变量UrlPrecise=true开启 Download Scan4All

___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
SCodeScanner : Stands For Source Code Scanner Where The User Can Scans The Source Code For Finding The Critical Vulnerabilities

SCodeScanner stands for Source Code scanner where the user can scans the source code for finding the Critical Vulnerabilities. The main objective for this scanner is to find the vulnerabilities inside the source code before code gets published in Prod.

Features

* Supported PHP Language
* Supported YAML Language
* Pass results to bug tracking services like Jira also Slack (Sending files to group to multiple people at once).
* Gives results in JSON format, which can easily be used to any other program.
* Works with Rules. We only need to create some rules which the target rule is not present in php/yaml directory.
* Rules that can scan advance patterns

Achievements

SCodeScanner received 5 CVEs for finding vulnerabilities in multiple CMS plugins.

* CVE-2022-1465
* CVE-2022-1474
* CVE-2022-1527
* CVE-2022-1532
* CVE-2022-1604

How to run?

* Download the repository –
* Run pip3 install -r requirements.txt
* And run python3 scscanner.py --help
Download

___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Cyber Security And Mental Health

It is no secret that the internet can be a dark and dangerous place. Whether you’re just spending some leisure time on social media or gambling online, it is important to be vigilant. Every day we read stories in the news about cyber attacks and cyber bullying. These stories usually involve young people who have been the victim of some kind of online harassment. But what many people don’t realize is that these attacks can have a serious impact on the mental health of those involved.

Cyber attacks can take many forms. They can be anything from someone hacking into your personal accounts and posting embarrassing information, to sending threatening or abusive messages. In some cases, the effects of a cyber attack can be so severe that the victim is left feeling suicidal.

Cyber bullying is one of the most common forms of cyber attack. It usually involves someone sending hurtful or mean messages to another person. In some cases, it can also involve posting humiliating photos or videos of the victim online. The effects of cyber bullying can be devastating. Victims of cyber bullying often suffer from anxiety, depression, and low self-esteem. They may also struggle with sleep problems, eating disorders, and substance abuse. In extreme cases, cyber bullying can lead to thoughts of suicide.

And, as more and more people suffer from mental health issues, the internet can be a trigger for those conditions. It’s not just the act of being online that can be harmful, but also the content that people are exposed to.

Cyber security and mental health are two very important issues that are often overlooked. But they are both connected.

Mental health and cyber security are both about protecting yourself from harm. Mental health is about protecting your mind from things that can hurt it. This can include things like anxiety, depression, stress, and trauma. And Cyber security is about protecting your computer and your online information from being hacked or stolen. Both mental health and cyber security are important for your well-being.

Here are some tips to help you stay mindful of both cyber security and mental health.

1. Create strong passwords and keep them secure. Make sure your passwords are strong and difficult to guess. Avoid using easily guessed words like your name, birthdate, or favorite sports team. Use a combination of uppercase and lowercase letters, numbers, and special characters. And never use the same password at more than one site.

2. Be aware of phishing scams. Phishing scams are designed to trick you into giving up personal information, like your passwords or credit card numbers. Be suspicious of any email or text message that asks you to click on a link or provide personal information.

3. Keep your software up to date. That includes your operating system, web browser, and any apps you have installed. Most software updates include security enhancements, so it’s important to install them as soon as they’re available.

4. Use a secure connection. Any time you’re using a public Wi-Fi network, be sure to use a secure connection. That means using a Virtual Private Network (VPN) if one is available, or connecting to a secure HTTPS site.

5. Be mindful of what you post online. Think carefully about what you share on social media and other online platforms. Once something is posted, it’s often difficult to remove it completely.

___________________________
@hacking_Attack
@Hacking_Video