Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
R4Ven : Track IP And GPS Location

Track User’s Smartphone/Pc Ip And Gps Location.

The tool hosts a fake website which uses an iframe to display a legit website and, if the target allows it, it will fetch the Gps location (latitude and longitude)of the target along with IP Addressand Device Information.

This tool is a Proof of Concept and is for Educational Purposes Only.

Using this tool, you can find out what information a malicious website can gather about you and your devices and why you shouldn’t click on random links or grant permissions like Location to them.

On link click
+ it wil automatically fetch ip address and device information
! if location permission allowed, it will fetch exact location of target.
Limitation
- It will not work on laptops or phones that have broken GPS,
# browsers that block javascript,
# or if the user is mocking the GPS location.

- Safari - auto block location permission
- Brave - auto block location permission
- Firefox - after a recent update this browser became very weird it allows location permission but it's not accurate at all.

+ Best work with Chrome browser and location accuracy will be more accurate if you use this on a smartphone.
IP location vs GPS location
- Geographic location based on IP address is NOT accurate,
# Does not provide the location of the target.
# Instead, it provides the approximate location of the ISP (Internet service provider) + GPS fetch almost exact location because it uses longitude and latitude coordinates.
@@ Once location permission is granted @@
# accurate location information is recieved to within 20 to 30 meters of the user's location.
# (it's almost exact location)
Installation

git clone https://github.com/spyboy-productions/r4ven.git
cd r4ven
pip3 install -r requirements.txt
python3 r4ven.py

enter your discord webhook url (set up a channel in your discord server with webhook integration)

https://support.discord.com/hc/en-us/articles/228383668-Intro-to-Webhooks

if not have discord account and sever make one, it’s free.

https://discord.com/

Snapshots
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgkh4jNn-MNqxGPUCnAMhIcrS7ywz5tN2wYyofkwNJwK_9hWmVPi02apvH4_pwqzbZyUzcfO0o2EZe0Jfls6nkyT6rIxhQGMYvsQC7gDKnLG47awkzZXmpyyJBOegeiRxwQ2jXgAoKLcI4iMCb_ca21SAU7XaFjhPR5Ahvwr1ZFurDVgl9hoWej7eBS/s3012/R4Ven1.png https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_sPIM62N57WlFdZz6qmVX-OUn8ePMNWhC-5aArFnLkPfXQrBV2xrdzgraFByxmLkpF_E_FfL8JwMALJdjuPURp9AoJaEJVBbuVmJ_opowtvT_lZI2hhiyE9KNOyaC-fp8DH3rVVeayUd0ezVZeuYFuUJ87I8tOS0rwci2H2Ft0wwK8zSyIbdNpPbJ/s3360/R4Ven2.png https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi2mi1-ptM0D5XEInmFaZ5ynoQ400XGdMCPGcpQzJQfU8OcozRGJ_ONtDa1ShnfGxnkz76MbHwbFmR-IjuzQeEpt94yHYrR0sRM8CIhwodB9mhmhi4qpkSa7XpzHunb5qeqvS10WoSfM0uXAeJohoc5YJBF5Uw1Y_iCPdpu76z6YeRyhHgJo1DThfep/s1732/R4Ven3.png https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhrWsBohPNmlB_-j9eKyaIlDsddivfbUVL497M8o61MWuTG-vF2ye6sJ760KN6QVnv5D3hOS7gH5tVMyI9NGUydgoeQvOMOFgkFzJ5t08SuVJn4E240lU1mlEubD43q9RhNX9UKM1DVHlNYVH3Luq96uUNFZj22xhEURFRw_8jw3PIKU8W3AkHrIcQJ/s2276/R4Ven4.png

Click Here To Download
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Your Right to Internet Privacy: A Tutorial for Beginners

https://cdn-images-1.medium.com/max/2600/0*f750mC-78JnciB6U
There’s an irony to this post. I’m publishing it on Medium using a Mac. A real internet privacy expert would be using Linux and publishing…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to become a hacker in 2023

https://cdn-images-1.medium.com/max/1115/1*T1eTFW7lux9VAUYMRFAHAA.png
It is important to note that the term “hacker” has a negative connotation and is often associated with illegal activities. However, there…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to Hack a Human: Social Engineering

https://cdn-images-1.medium.com/max/832/1*IruWEj3ZlA-DiJqJYRpDZA.png
You must have heard about hacking computer systems or websites etc., but how about Hacking Humans? Hacking a human is not as difficult as…

Continue reading on Medium »
CNA script testing/feedback
https://www.reddit.com/r/redteamsec/comments/zlvdxw/cna_script_testingfeedback/

<!-- SC_OFF -->Hi Teamers, Ive created a Cobalt Strike Aggressor (CNA) Script I've dubbed ipv4guard. As it's my first one ever and Im ever looking for feedback and testers (and contributors!! ;D) to maybe help to improve it. The script is for Cobalt Strike and per the blurb I wrote A Cobalt Strike Aggressor Script that aims to help prevent errant Cobalt Strike commands from being executed on non-whitelisted / off-limit / out-of-scope / unapproved IPv4 addresses. Ive done tested best I can but obviously cant by my lonesome put it into as much of a wider berth testing than the wider community. Cheers <!-- SC_ON --> submitted by /u/savsaintsanta (https://www.reddit.com/user/savsaintsanta)
[link] (https://www.reddit.com/r/redteamsec/comments/zlvdxw/cna_script_testingfeedback/) [comments] (https://www.reddit.com/r/redteamsec/comments/zlvdxw/cna_script_testingfeedback/)
Dark Reading: Attacks/Breaches
CSAF Is the Future of Vulnerability Management

Version 2.0 of the Common Security Advisory Framework will enable organizations to automate vulnerability remediation.
Dark Reading: Attacks/Breaches
Proofpoint Nabs Illusive, Signaling a Sunset for Deception Tech

Former pure-play deception startup Illusive attracts Proofpoint with its repositioned platform focusing on identity threat detection and response (ITDR).
Dark Reading: Attacks/Breaches
Automated Cybercampaign Creates Masses of Bogus Software Building Blocks

The proliferation of automated cyberattacks against npm, NuGet, and PyPI underscores the growing sophistication of threat actors and the threats to open source software supply chains.