Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
How did I choose cybersecurity as a career and how am I working on it?

A page from the storybook of my life where I chose to be an ethical hacker instead of a software developer.Continue reading on Medium »
Read more...
如果你不知道什麼是 XSS(Cross-site Scripting),簡單來說就是駭客可以在你的網站上面執行 JavaScript 的程式碼。既然可以執行,那就有可能可以把使用者的 token 偷走,假造使用者的身份登入,就算偷不走…Continue reading on cymetrics » (https://medium.com/cymetrics/prevent-xss-might-be-harder-than-you-thought-ce8c422540b?source=rss------bug_bounty-5)

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Someone i know claims a damning text they sent me was done so by a hacker. Is this case possible?

I need some advise from people who are more familiar with hacking phones and text messages.

Someone sent me a text message earlier this week which is potentially relationship ending. I assume it was sent by mistake, but they are claiming someone else maliciously sent this text to me by hacking their phone somehow. Before completely dismissing this as a possibility, I wanted to verify if this was actually possible or not.

Initially, I sent them a text message, and then received the text in question a couple of minutes later. The text was in response to what I sent them, so the hacker would have needed to be able to monitor our conversation in real time. I'm not too familiar with SMS spoofing apps and tools, but this doesn't sound like something that is possible with typical consumer applications. I might be wrong but from what I can tell SMS spoofers aren't able to see saved conversations and incoming texts. They are just able to send text messages on behalf of another person. Additionally, this text was sent in the same conversation as all of their other legitimate texts. I'm not sure if SMS differentiates spoofed texts from legitimate numbers.

Please let me know if this sounds like something that could realistically occur. I'm kind of in the dark as to what actually happened here, so I'm not even sure if this was a case of SMS spoofing. It could have been done by some other method I'm not aware of. Or it could have just been a mistake or someone else physically sending it from their phone. Any thoughts on this would be appreciated.

submitted by /u/GeeksOasis
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Httpx - A Fast And Multi-Purpose HTTP Toolkit Allows To Run Multiple Probers Using Retryablehttp Library, It Is Designed To Maintain The Result Reliability With Increased Threads
http://www.kitploit.com/2021/05/httpx-fast-and-multi-purpose-http.html

___________________________
@hacking_Attack
@Hacking_Video
From Github
git clone https://github.com/projectdiscovery/httpx.git; cd httpx/cmd/httpx; go build; mv httpx /usr/local/bin/; httpx -version
Usage
httpx -h This will display help for the tool. Here are all the switches it supports. Flag Description Example H Custom Header input httpx -H 'x-bug-bounty: hacker' follow-redirects Follow URL redirects (default false) httpx -follow-redirects follow-host-redirects Follow URL redirects only on same host(default false) httpx -follow-host-redirects http-proxy URL of the proxy server httpx -http-proxy hxxp://proxy-host:80 l File containing HOST/URLs/CIDR to process httpx -l hosts.txt no-color Disable colors in the output. httpx -no-color o File to save output result (optional) httpx -o output.txt json Prints all the probes in JSON format (default false) httpx -json vhost Probes to detect vhost from list of subdomains httpx -vhost threads Number of threads (default 50) httpx -threads 100 http2 HTTP2 probing httpx -http2 pipeline HTTP1.1 Pipeline (https://www.kitploit.com/search/label/Pipeline) probing httpx -pipeline ports Ports ranges to probe (nmap syntax: eg 1,2-10,11) httpx -ports 80,443,100-200 title Prints title of page if available httpx -title path Request path/file httpx -path /api paths Request list of paths from file httpx -paths paths.txt content-length Prints content length in the output httpx -content-length ml Match content length in the output httpx -content-length -ml 125 fl Filter content length in the output httpx -content-length -fl 0,43 status-code Prints status code in the output httpx -status-code mc Match status code in the output httpx -status-code -mc 200,302 fc Filter status code in the output httpx -status-code -fc 404,500 tech-detect Perform wappalyzer based technology detection httpx -tech-detect tls-probe Send HTTP probes on the extracted TLS domains httpx -tls-probe tls-grab Perform TLS data grabbing httpx -tls-grab content-type Prints content-type httpx -content-type location Prints location header httpx -location csp-probe Send HTTP probes on the extracted CSP domains httpx -csp-probe web-server Prints running web sever if available httpx -web-server sr Store responses to file (default false) httpx -sr srd Directory to store response (optional) httpx -srd httpx-output unsafe Send raw requests skipping golang normalization httpx -unsafe request File containing raw request to process httpx -request retries Number of retries httpx -retries random-agent Use randomly selected HTTP User-Agent header value httpx -random-agent silent Prints only results in the output httpx -silent stats Prints statistic every 5 seconds httpx -stats timeout Timeout in seconds (default 5) httpx -timeout 10 verbose Verbose Mode httpx -verbose version Prints current version of the httpx httpx -version x Request Method (default 'GET') httpx -x HEAD method Output requested method httpx -method response-time Output the response time httpx -response-time response-in-json Include response in stdout (only works with -json) httpx -response-in-json websocket Prints if a websocket (https://www.kitploit.com/search/label/WebSocket) is exposed httpx -websocket ip Prints the host IP httpx -ip cname Prints the cname record if available httpx -cname cdn Check if domain's ip belongs to known CDN httpx -cdn filter-string Filter results based on filtered string httpx -filter-string XXX match-string Filter results based on matched string httpx -match-string XXX filter-regex Filter results based on filtered regex httpx -filter-regex XXX match-regex Filter results based on matched regex httpx -match-regex XXX

___________________________
@hacking_Attack
@Hacking_Video
Running httpx with stdin
This will run the tool against all the hosts and subdomains (https://www.kitploit.com/search/label/Subdomains) in hosts.txt and returns URLs running HTTP webserver. cat hosts.txt | httpx

__ __ __ _ __
/ /_ / /_/ /_____ | |/ /
/ __ \/ __/ __/ __ \| /
/ / / / /_/ /_/ /_/ / |
/_/ /_/\__/\__/ .___/_/|_| v1.0
/_/

projectdiscovery.io

[WRN] Use with caution. You are responsible for your actions
[WRN] Developers assume no liability and are not responsible for any misuse or damage.

https://mta-sts.managed.hackerone.com
https://mta-sts.hackerone.com
https://mta-sts.forwarding.hackerone.com
https://docs.hackerone.com
https://www.hackerone.com
https://resources.hackerone.com
https://api.hackerone.com
https://support.hackerone.com
Running httpx with file input
This will run the tool against all the hosts and subdomains in hosts.txt and returns URLs running HTTP webserver. httpx -l hosts.txt -silent

https://docs.hackerone.com
https://mta-sts.hackerone.com
https://mta-sts.managed.hackerone.com
https://mta-sts.forwarding.hackerone.com
https://www.hackerone.com
https://resources.hackerone.com
https://api.hackerone.com
https://support.hackerone.com
Running httpx with CIDR input
echo 173.0.84.0/24 | httpx -silent

https://173.0.84.29
https://173.0.84.43
https://173.0.84.31
https://173.0.84.44
https://173.0.84.12
https://173.0.84.4
https://173.0.84.36
https://173.0.84.45
https://173.0.84.14
https://173.0.84.25
https://173.0.84.46
https://173.0.84.24
https://173.0.84.32
https://173.0.84.9
https://173.0.84.13
https://173.0.84.6
https://173.0.84.16
https://173.0.84.34
Running httpx with subfinder
subfinder (https://www.kitploit.com/search/label/Subfinder) -d hackerone.com -silent | httpx -title -content-length -status-code -silent

https://mta-sts.forwarding.hackerone.com [404] [9339] [Page not found · GitHub Pages]
https://mta-sts.hackerone.com [404] [9339] [Page not found · GitHub Pages]
https://mta-sts.managed.hackerone.com [404] [9339] [Page not found · GitHub Pages]
https://docs.hackerone.com [200] [65444] [HackerOne Platform Documentation]
https://www.hackerone.com [200] [54166] [Bug Bounty - Hacker Powered Security Testing | HackerOne]
https://support.hackerone.com [301] [489] []
https://api.hackerone.com [200] [7791] [HackerOne API]
https://hackerone.com [301] [92] []
https://resources.hackerone.com [301] [0] []
Notes As default, httpx checks for HTTPS probe and fall-back to HTTP only if HTTPS is not reachable. For printing both HTTP/HTTPS results, no-fallback flag can be used. Custom scheme for ports can be defined, for example -ports http:443,http:80,https:8443 vhost, http2, pipeline, ports, csp-probe, tls-probe and path are unique flag with different probes. Unique flags should be used for specific use cases instead of running them as default with other flags. When using json flag, all the information (default probes) included in the JSON output.
Thanks
httpx is made by the projectdiscovery (https://projectdiscovery.io/) team. Community contributions have made the project what it is. See the Thanks.md (https://github.com/projectdiscovery/httpx/blob/master/THANKS.md) file for more details. Do also check out these similar awesome projects that may fit in your workflow:Probing feature is inspired by @tomnomnom/httprobe (https://github.com/tomnomnom/httprobe) work

Download Httpx (https://github.com/projectdiscovery/httpx)

___________________________
@hacking_Attack
@Hacking_Video