Unblob - Extract Files From Any Kind Of Container Formats
unblob is an accurate, fast, and easy-to-use extraction suite. It parses unknown binary blobs for more than 30 different archive, compression, and file-system formats, extracts their content recursively, and carves out unknown chunks that have not been accounted for. Unblob is free to use, licensed with the MIT license. It has a Command Line Interface and can be used as a Python library. This turns unblob into the perfect companion for extracting, analyzing, and reverse engineering firmware images. See more at https://unblob.org. Demo Download Unblob
Read more...
unblob is an accurate, fast, and easy-to-use extraction suite. It parses unknown binary blobs for more than 30 different archive, compression, and file-system formats, extracts their content recursively, and carves out unknown chunks that have not been accounted for. Unblob is free to use, licensed with the MIT license. It has a Command Line Interface and can be used as a Python library. This turns unblob into the perfect companion for extracting, analyzing, and reverse engineering firmware images. See more at https://unblob.org. Demo Download Unblob
Read more...
Unblob - Extract Files From Any Kind Of Container Formats
http://www.kitploit.com/2022/11/unblob-extract-files-from-any-kind-of.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/11/unblob-extract-files-from-any-kind-of.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Unblob - Extract Files From Any Kind Of Container Formats
unblob is an accurate, fast, and easy-to-use extraction suite. It parses unknown binary (https://www.kitploit.com/search/label/Binary) blobs for more than 30 different archive, compression, and file-system formats, extracts their content recursively, and carves out unknown chunks that have not been accounted for. Unblob is free to use, licensed with the MIT license. It has a Command Line Interface and can be used as a Python library.
This turns unblob into the perfect companion for extracting, analyzing, and reverse engineering firmware (https://www.kitploit.com/search/label/Firmware) images. See more at https://unblob.org (https://unblob.org/). Demo
___________________________
@hacking_Attack
@Hacking_Video
This turns unblob into the perfect companion for extracting, analyzing, and reverse engineering firmware (https://www.kitploit.com/search/label/Firmware) images. See more at https://unblob.org (https://unblob.org/). Demo
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
Download Unblob (https://github.com/onekey-sec/unblob)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - onekey-sec/unblob: Extract files from any kind of container formats
Extract files from any kind of container formats. Contribute to onekey-sec/unblob development by creating an account on GitHub.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is Vulnerability Scanning?
https://cdn-images-1.medium.com/max/2600/1*v3e99FSix-1wPdjqWC0Vbg.jpeg
Discover Weaknesses Automatically
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
What is Vulnerability Scanning?
https://cdn-images-1.medium.com/max/2600/1*v3e99FSix-1wPdjqWC0Vbg.jpeg
Discover Weaknesses Automatically
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is Vulnerability Scanning?
Discover Weaknesses Automatically
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to protect your dApps from crypto hacks in 2022
https://cdn-images-1.medium.com/max/2600/1*Yr5y4lt6G5GP6zt7uoGcbw.jpeg
Users losing crypto funds due to malicious activity is not uncommon. Indeed, it is for this reason that researchers recently proposed…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to protect your dApps from crypto hacks in 2022
https://cdn-images-1.medium.com/max/2600/1*Yr5y4lt6G5GP6zt7uoGcbw.jpeg
Users losing crypto funds due to malicious activity is not uncommon. Indeed, it is for this reason that researchers recently proposed…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to protect your dApps from crypto hacks in 2022
Users losing crypto funds due to malicious activity is not uncommon. Indeed, it is for this reason that researchers recently proposed…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How I bypassed Cloudflare WAF to get my First Bug
https://cdn-images-1.medium.com/max/720/1*MIdUG107hR7anBU0gyKi_w.jpeg
This blog is about how I found my first XSS vulnerability.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How I bypassed Cloudflare WAF to get my First Bug
https://cdn-images-1.medium.com/max/720/1*MIdUG107hR7anBU0gyKi_w.jpeg
This blog is about how I found my first XSS vulnerability.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I bypassed Cloudflare WAF to get my First Bug
This blog is about how I found my first XSS vulnerability.
XSS using a username
XSS triggered by exploiting a vulnerable input field of a signup page.Continue reading on Medium »
Read more...
XSS triggered by exploiting a vulnerable input field of a signup page.Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Unblob - Extract Files From Any Kind Of Container Formats
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgQo8GWKOqEwwmOWVLXlzGYJAXDOFEJicyV5EaBPfz0GgXCFEXwHZ1A4EspjjHseTOHZQUI99K-DHEhsq3ovBUy6jhtMSXShUO8AoxHAvDOpN43emqgRNTTW-51ZeELA0FT_Z_EoM7YHG-NflhjsNliQ2u389CFyRl5Xth_hEnQFUfA_WOBAfmWd6Oiww/w640-h180/unblob.png
unblob is an accurate, fast, and easy-to-use extraction suite. It parses unknown binary blobs for more than 30 different archive, compression, and file-system formats, extracts their content recursively, and carves out unknown chunks that have not been accounted for.
Unblob is free to use, licensed with the MIT license. It has a Command Line Interface and can be used as a Python library.
This turns unblob into the perfect companion for extracting, analyzing, and reverse engineering firmware images.
See more at https://unblob.org.
Demo
https://github.com/onekey-sec/unblob/raw/main/docs/demo.svg
Download Unblob
___________________________
@hacking_Attack
@Hacking_Video
Unblob - Extract Files From Any Kind Of Container Formats
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgQo8GWKOqEwwmOWVLXlzGYJAXDOFEJicyV5EaBPfz0GgXCFEXwHZ1A4EspjjHseTOHZQUI99K-DHEhsq3ovBUy6jhtMSXShUO8AoxHAvDOpN43emqgRNTTW-51ZeELA0FT_Z_EoM7YHG-NflhjsNliQ2u389CFyRl5Xth_hEnQFUfA_WOBAfmWd6Oiww/w640-h180/unblob.png
unblob is an accurate, fast, and easy-to-use extraction suite. It parses unknown binary blobs for more than 30 different archive, compression, and file-system formats, extracts their content recursively, and carves out unknown chunks that have not been accounted for.
Unblob is free to use, licensed with the MIT license. It has a Command Line Interface and can be used as a Python library.
This turns unblob into the perfect companion for extracting, analyzing, and reverse engineering firmware images.
See more at https://unblob.org.
Demo
https://github.com/onekey-sec/unblob/raw/main/docs/demo.svg
Download Unblob
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Unblob - Extract Files From Any Kind Of Container Formats
XSS triggered by exploiting a vulnerable input field of a signup page.Continue reading on Medium » (https://sagarsajeev.medium.com/xss-using-a-username-8a8ab1b79a77?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
XSS using a username
XSS triggered by exploiting a vulnerable input field of a signup page.
Attack Simulator for SolarWinds, Codecov, and ua-parser-js breaches
https://www.reddit.com/r/redteamsec/comments/yv140a/attack_simulator_for_solarwinds_codecov_and/
The SUNSPOT (http://crowdstrike.com/blog/sunspot-malware-technical-analysis/) malware, Codecov breach (https://about.codecov.io/security-update/), and lot of compromised open-source packages (like was the case with ua-parser-js (https://github.com/advisories/GHSA-pjwm-rvh2-c87w)) target the CI/ CD pipeline to modify release build or exfiltrate credentials. As part of writing tests for Harden Runner GitHub Action (https://github.com/step-security/harden-runner), which prevents such attacks, there was a need to write attack simulator for these attacks. You can check out the attack simulator here: https://github.com/step-security/attack-simulator It has information and relevant links about these attacks at one place. There are a set of GitHub Actions workflows that simulate the steps from these attacks. There is also a malware simulator npm package which simulates behavior of typical compromised npm packages using preinstall step. Wanted to share in case one is looking for similar attack simulator for attacks on CI/ CD pipelines. submitted by /u/varunsh-coder (https://www.reddit.com/user/varunsh-coder)
[link] (https://www.reddit.com/r/redteamsec/comments/yv140a/attack_simulator_for_solarwinds_codecov_and/) [comments] (https://www.reddit.com/r/redteamsec/comments/yv140a/attack_simulator_for_solarwinds_codecov_and/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/yv140a/attack_simulator_for_solarwinds_codecov_and/
The SUNSPOT (http://crowdstrike.com/blog/sunspot-malware-technical-analysis/) malware, Codecov breach (https://about.codecov.io/security-update/), and lot of compromised open-source packages (like was the case with ua-parser-js (https://github.com/advisories/GHSA-pjwm-rvh2-c87w)) target the CI/ CD pipeline to modify release build or exfiltrate credentials. As part of writing tests for Harden Runner GitHub Action (https://github.com/step-security/harden-runner), which prevents such attacks, there was a need to write attack simulator for these attacks. You can check out the attack simulator here: https://github.com/step-security/attack-simulator It has information and relevant links about these attacks at one place. There are a set of GitHub Actions workflows that simulate the steps from these attacks. There is also a malware simulator npm package which simulates behavior of typical compromised npm packages using preinstall step. Wanted to share in case one is looking for similar attack simulator for attacks on CI/ CD pipelines. submitted by /u/varunsh-coder (https://www.reddit.com/user/varunsh-coder)
[link] (https://www.reddit.com/r/redteamsec/comments/yv140a/attack_simulator_for_solarwinds_codecov_and/) [comments] (https://www.reddit.com/r/redteamsec/comments/yv140a/attack_simulator_for_solarwinds_codecov_and/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
r/redteamsec - Attack Simulator for SolarWinds, Codecov, and ua-parser-js breaches
21 votes and 1 comment so far on Reddit
P1 Bounties: Cross-Site Scripting (XSS) Tips And Tricks
https://medium.com/the-gray-area/p1-bounties-cross-site-scripting-xss-tips-and-tricks-10bf84daff38?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/the-gray-area/p1-bounties-cross-site-scripting-xss-tips-and-tricks-10bf84daff38?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
P1 Bug Hunting: Cross-Site Scripting (XSS) Tips And Tricks
TL;DR- A guide on what XSS is, how to find it, how to exploit it, and then how to make the most money off of it.
TL;DR- A guide on what XSS is, how to find it, how to exploit it, and then how to make the most money off of it.Continue reading on The Gray Area » (https://medium.com/the-gray-area/p1-bounties-cross-site-scripting-xss-tips-and-tricks-10bf84daff38?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
P1 Bug Hunting: Cross-Site Scripting (XSS) Tips And Tricks
TL;DR- A guide on what XSS is, how to find it, how to exploit it, and then how to make the most money off of it.