Black Hat Ethical Hacking
New version of Clop ransomware targets Linux servers
New version of Clop ransomware targets Linux servers
Black Hat Ethical Hacking
New version of Clop ransomware targets Linux servers | Black Hat Ethical Hacking
The Clop ransomware gang is using a new malware variant that targets Linux servers, but the encryption scheme is flawed, allowing victims to retrieve their files for free.
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Darkdump2 - Search The Deep Web Straight From Your Terminal
https://blogger.googleusercontent.com/img/a/AVvXsEgdAo6TFEdFheZEcmpZVGC0r9BoIjvvLSvfvSFj4iBJBoDC2vesDDRPfEJ6Unh3yLppU00ldWSPA4obp0vVEU0yGJUqb9NGVnbIMmcrzFuCba_S52ts8bko5H9KiL0gERmOCSm2yk04wFHPtG9T6CQHP6zoV6UOxYSdsYG4XW3dzAGF86w_mLvjLHVmvA=w386-h400
About Darkdump (Recent Notice - 12/27/22)
Darkdump is a simple script written in Python3.11 in which it allows users to enter a search term (query) in the command line and darkdump will pull all the deep web sites relating to that query. Darkdump2.0 is here, enjoy!
Installation
1.
2.
3.
4.
Usage
Example 1:
Example 2:
Example 3:
* Note: The 'amount' argument filters the number of results outputted
Usage With Increased Anonymity
Darkdump Proxy:
Menu
Visual
https://blogger.googleusercontent.com/img/a/AVvXsEh1rxzBtWIn9C9vBOvCqq4MvHIAuD28RZNIPUT5bmdMJCbwbCFhEiJ0gU_UeeGRZ3iMy7ekrynWduG6MM95J16ZVMGNsA9kwXBZZKMPq2M4wznFH5b2CcG7002AT91DxwBcDmxOhgqMNBXLfdmz_HZMec7tANb2QINCxQwPM43ojeYqhNBzO9trf2FDPw=w640-h440
Ethical Notice
The developer of this program, Josh Schiavone, is not resposible for misuse of this data gathering tool. Do not use darkdump to navigate websites that take part in any activity that is identified as illegal under the laws and regulations of your government. May God bless you all.
License
MIT License
Copyright (c) Josh Schiavone
Download Darkdump
Darkdump2 - Search The Deep Web Straight From Your Terminal
https://blogger.googleusercontent.com/img/a/AVvXsEgdAo6TFEdFheZEcmpZVGC0r9BoIjvvLSvfvSFj4iBJBoDC2vesDDRPfEJ6Unh3yLppU00ldWSPA4obp0vVEU0yGJUqb9NGVnbIMmcrzFuCba_S52ts8bko5H9KiL0gERmOCSm2yk04wFHPtG9T6CQHP6zoV6UOxYSdsYG4XW3dzAGF86w_mLvjLHVmvA=w386-h400
About Darkdump (Recent Notice - 12/27/22)
Darkdump is a simple script written in Python3.11 in which it allows users to enter a search term (query) in the command line and darkdump will pull all the deep web sites relating to that query. Darkdump2.0 is here, enjoy!
Installation
1.
git clone https://github.com/josh0xA/darkdump2.
cd darkdump3.
python3 -m pip install -r requirements.txt4.
python3 darkdump.py --helpUsage
Example 1:
python3 darkdump.py --query programmingExample 2:
python3 darkdump.py --query="chat rooms"Example 3:
python3 darkdump.py --query hackers --amount 12* Note: The 'amount' argument filters the number of results outputted
Usage With Increased Anonymity
Darkdump Proxy:
python3 darkdump.py --query bitcoin -pMenu
____ _ _
| \ ___ ___| |_ _| |_ _ _____ ___
| | | .'| _| '_| . | | | | . |
|____/|__,|_| |_,_|___|___|_|_|_| _|
|_|
Developed By: Josh Schiavone
https://github.com/josh0xA
joshschiavone.com
Version 2.0
usage: darkdump.py [-h] [-v] [-q QUERY] [-a AMOUNT] [-p]
options:
-h, --help show this help message and exit
-v, --version returns darkdump's version
-q QUERY, --query QUERY
the keyword or string you want to search on the deepweb
-a AMOUNT, --amount AMOUNT
the amount of results you want to retrieve (default: 10)
-p, --proxy use darkdump proxy to increase anonymity
Visual
https://blogger.googleusercontent.com/img/a/AVvXsEh1rxzBtWIn9C9vBOvCqq4MvHIAuD28RZNIPUT5bmdMJCbwbCFhEiJ0gU_UeeGRZ3iMy7ekrynWduG6MM95J16ZVMGNsA9kwXBZZKMPq2M4wznFH5b2CcG7002AT91DxwBcDmxOhgqMNBXLfdmz_HZMec7tANb2QINCxQwPM43ojeYqhNBzO9trf2FDPw=w640-h440
Ethical Notice
The developer of this program, Josh Schiavone, is not resposible for misuse of this data gathering tool. Do not use darkdump to navigate websites that take part in any activity that is identified as illegal under the laws and regulations of your government. May God bless you all.
License
MIT License
Copyright (c) Josh Schiavone
Download Darkdump
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Installing Kali Linux: A Step-by-Step Guide
https://cdn-images-1.medium.com/max/2600/0*2Cj4_nmTrmUOPSM-
Kali Linux is a popular open-source operating system used by ethical hackers and penetration testers. Installing Kali Linux is not much…
Continue reading on Medium »
Installing Kali Linux: A Step-by-Step Guide
https://cdn-images-1.medium.com/max/2600/0*2Cj4_nmTrmUOPSM-
Kali Linux is a popular open-source operating system used by ethical hackers and penetration testers. Installing Kali Linux is not much…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe: Phishing Analysis Tools
https://cdn-images-1.medium.com/max/1267/1*xq0pZ8NRkW5SWuIQ_6QS3Q.jpeg
Please note: I am not going to post any flags from the TryHackMe (THM) platform on my walkthroughs. I feel I would be violating the…
Continue reading on Medium »
TryHackMe: Phishing Analysis Tools
https://cdn-images-1.medium.com/max/1267/1*xq0pZ8NRkW5SWuIQ_6QS3Q.jpeg
Please note: I am not going to post any flags from the TryHackMe (THM) platform on my walkthroughs. I feel I would be violating the…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The popping history of XSS
https://cdn-images-1.medium.com/max/2600/1*3coUI8c54rvDSfiRtW3d0Q.png
Cross-Site Scripting (XSS) is a type of security vulnerability that has been around since the early days of the World Wide Web. XSS allows…
Continue reading on Medium »
The popping history of XSS
https://cdn-images-1.medium.com/max/2600/1*3coUI8c54rvDSfiRtW3d0Q.png
Cross-Site Scripting (XSS) is a type of security vulnerability that has been around since the early days of the World Wide Web. XSS allows…
Continue reading on Medium »
Reflected XSS on Target with tough WAF ( WAF Bypass )
I was doing web pentesting on a private program. The program had a very tough WAF even typing alert as a payload would block be blocked by…Continue reading on Medium »
Read more...
I was doing web pentesting on a private program. The program had a very tough WAF even typing alert as a payload would block be blocked by…Continue reading on Medium »
Read more...
How could I exploit OpenID "request object" with none algorithm ?
https://www.reddit.com/r/Pentesting/comments/10wsa12/how_could_i_exploit_openid_request_object_with/
https://www.reddit.com/r/Pentesting/comments/10wsa12/how_could_i_exploit_openid_request_object_with/
submitted by /u/tomatediabolik (https://www.reddit.com/user/tomatediabolik)
[link] (https://i.redd.it/k55ufv37nxga1.png) [comments] (https://www.reddit.com/r/Pentesting/comments/10wsa12/how_could_i_exploit_openid_request_object_with/)
[link] (https://i.redd.it/k55ufv37nxga1.png) [comments] (https://www.reddit.com/r/Pentesting/comments/10wsa12/how_could_i_exploit_openid_request_object_with/)
Prospective Employer sent me a Project
https://www.reddit.com/r/Pentesting/comments/10wsqm7/prospective_employer_sent_me_a_project/
<!-- SC_OFF -->Hey guys, I recently interviewed for a junior PT position and was given a project to do at home to test my self-learning capabilities. I am completely out of my comfort zone as this project is beyond my skills at the moment, but I'm doing my best. If y'all don't mind, what steps should I take in testing a website once I have done basic reconnaissance? I did some vulnerability scanning and tinkered around with Burp but I'm coming up blank. Thank you! <!-- SC_ON --> submitted by /u/Yrsal (https://www.reddit.com/user/Yrsal)
[link] (https://www.reddit.com/r/Pentesting/comments/10wsqm7/prospective_employer_sent_me_a_project/) [comments] (https://www.reddit.com/r/Pentesting/comments/10wsqm7/prospective_employer_sent_me_a_project/)
https://www.reddit.com/r/Pentesting/comments/10wsqm7/prospective_employer_sent_me_a_project/
<!-- SC_OFF -->Hey guys, I recently interviewed for a junior PT position and was given a project to do at home to test my self-learning capabilities. I am completely out of my comfort zone as this project is beyond my skills at the moment, but I'm doing my best. If y'all don't mind, what steps should I take in testing a website once I have done basic reconnaissance? I did some vulnerability scanning and tinkered around with Burp but I'm coming up blank. Thank you! <!-- SC_ON --> submitted by /u/Yrsal (https://www.reddit.com/user/Yrsal)
[link] (https://www.reddit.com/r/Pentesting/comments/10wsqm7/prospective_employer_sent_me_a_project/) [comments] (https://www.reddit.com/r/Pentesting/comments/10wsqm7/prospective_employer_sent_me_a_project/)