Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
PartyLoud - A Simple Tool To Generate Fake Web Browsing And Mitigate Tracking

https://blogger.googleusercontent.com/img/a/AVvXsEgfik1VBgFBYXx3Jijkq7L26Znz8PyZqaUpokPqDSK7smln8HsMyWgynYJX_uHxHcyeDDwSP3pmFRiXxaEu20bDje5OSVyX2k_Kr4MgLhcoe2TvE54OUR0zqF4PSm_vj2UOGVpGnjp3B-2Z8DgmjZdRYe3IO7LfS3aLHYV9Hjkt1ZtbJXNkbvvCSfbOWg=w640-h434 PartyLoud is a highly configurable and straightforward free tool that helps you prevent tracking directly from your linux terminal, no special skills required. Once started, you can forget it is running. It provides several flags; each flag lets you customize your experience and change PartyLoud behaviour according to your needs.
* Simple. 3 files only, no installation required, just clone this repo an you're ready to go.
* Powerful. Thread-based navigation.
* Stealthy. Optimized to emulate user navigation.
* Portable. You can use this script on every unix-based OS.

This project was inspired by noisy.py How It Works 1. URLs and keywords are loaded (either from partyloud.conf and badwords or from user-defined files)
2. If proxy flag has been used, proxy config will be tested
3. For each URL in ULR-list a thread is started, each thread as an user agent associated
4. Each thread will start by sending an HTTP request to the given URL
5. The response if filtered using the keywords in order to prevent 404s and malformed URLs
6. A new URL is choosen from the list generated after filering
7. Current thread sleeps for a random time
8. Actions from 4 to 7 are repeated using the new URL until user send kill signal (CTRL-C or enter key) Features * Configurable urls list and blocklist
* Random DNS Mode : each request is done on a different DNS Server
* Multi-threaded request engine (# of thread are equal to # of urls in partyloud.conf)
* Error recovery mechanism to protect Engines from failures
* Spoofed User Agent prevent from fingerprinting (each engine has a different user agent)
* Dynamic UI Setup Clone the repository: git clone https://github.com/realtho/PartyLoud.gitNavigate to the directory and make the script executable: cd PartyLoud
chmod +x partyloud.sh
Run 'partyloud': ./partyloud.shUsage Usage: ./partyloud.sh [options...]

-d --dns
To stop the script press either enter or CRTL-CFile Specifications In current release there is no input-validation on files.If you find bugs or have suggestions on how to improve this features please help me by opening issues on GitHub IntroIf you don’t have special needs , default config files are just fine to get you started.
Default files are located in:

* badwords
* partyloud.conf
* DNSList

Please note that file name and extension are not important, just content of files matter badwords - Keywords-based blocklistbadwords is a keywords-based blocklist used to filter non-HTML content, images, document and so on.
The default config as been created after several weeks of testing. If you really think you need a custom blocklist, my suggestion is to start by copy and modifying default config according to your needs.
Here are some hints on how to create a great blocklist file:
DO DONT

Use only ASCII chars Define one-site-only rules Try to keep the rules as general as possible Define case-sensitive rules Prefer relative p[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! PartyLoud - A Simple Tool To Generate Fake Web Browsing And Mitigate Tracking https://blogger.googleusercontent.com/img/a/AVvXsEgfik1VBgFBYXx3Jijkq7L26Znz8PyZqaUpokPqDSK7smln8HsMyWgynYJX_uHxHcyeDDwSP3pmFRiXxaEu20bDje5OSVyX2k_Kr4…
ath Place more than one rule per line partyloud.conf - ULR Listpartyloud.conf is a ULR List used as starting point for fake navigation generators.
The goal here is to create a good list of sites containing a lot of URLs.
Aside suggesting you not to use google, youtube and social networks related links, I've really no hints for you.
Note #1 - To work properly the URLs must be well-formed Note #2 - Even if the file contains 1000 lines only 10 are used (first 10, working on randomness) Note #3 - Only one URL per line is allowed DNSList - DNS ListDNSList is a List of DNS used as argument for random DNS feature. Random DNS is not enable by default, so the “default file” is really just a guide line and a test used while developing the function to se if everything was working as expected.
The only suggestion here is to add as much address as possible to increase randomness.
Note #1 - Only one address per line is allowed Download PartyLoud

___________________________
@hacking_Attack
@Hacking_Video
Finding P1 Vulnerabilities: Tools & Resources

The second, more in-depth part of ‘Finding P1 Vulnerabilities: A Step by Step Guide’.Continue reading on The Gray Area »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Cisco Jabber XMPP Stanza Smuggling

https://1.bp.blogspot.com/-ASAiGIAsbZo/WWlu3lcAbmI/AAAAAAAAII0/K9TarDW1B-wz0w-5-5rrjX8jWsow7QyegCLcBGAs/s1600/h100.png
There is a vulnerability in Cisco Jabber that allows an attacker to send arbitrary XMPP stanzas (XMPP control messages) to another Cisco Jabber client, including XMPP stanzas that are normally sent only by the trusted server.

SHA-256 | ed2115ba91caeae4b0245ae0141359b56fa7d27077ea7a8cb6d34c1aa2ad914c

Download
Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
New Vault Alert: Welcome PhononDAO

We are excited to welcome PhononDAO to the Hats ecosystem! This unique partnership will take part in two steps; starting with a short term…Continue reading on Medium »
Read more...
Dark Reading: Attacks/Breaches
Name That Toon: Witching Hour

Feeling creative? Submit your caption and our panel of experts will reward the winner with a $25 Amazon gift card.