UNDERCODE TESTING
312 subscribers
311 photos
24 videos
173 files
29.6K links
๐Ÿฆ‘ World first platform which Collect & Analyzes every New hacking method.

+ Free AI Practice.

(New Bug Bounty Methods, Tools Updates, AI & Courses).

โœจ Services: Undercode.help/services

โœจyoutube.com/undercode

@Undercode_Testing
Download Telegram
Forwarded from Exploiting Crew (Pr1vAt3)
๐Ÿฆ‘ Dark Web Online sites List:

Email Providers
Cock.li xdkriz6cn2avvcr2vks5lvvtmfojz2ohjzj4fhyuka55mvljeso2ztqd.onion

Elude.in eludemailxhnqzfmxehy3bk5guyhlxbunfyhkcksv4gvx6d3wcf6smad.onion

Sonar Tor Messenger sonarmsng5vzwqezlvtu2iiwwdn3dxkhotftikhowpfjuzg7p3ca5eid.onion

ProtonMail protonmailrmez3lotccipshtkleegetolb73fuirgj7r4o4vfu7ozyd.onion

RiseUp Email 5gdvpfoh6kb2iqbizb37lzk2ddzrwa47m6rpdueg2m656fovmbhoptqd.onion

Blogs And Personal Sites
qorg11.net lainwir3s4y5r7mqm3kurzpljyf77vty2hrrfkps6wm4nnnqzest4lqd.onion

Course Enigma cgjzkysxa4ru5rhrtr6rafckhexbisbtxwg2fg743cjumioysmirhdad.onion

Kill-9 killnod2s77o3axkktdu52aqmmy4acisz2gicbhjm4xbvxa2zfftteyd.onion

Digdeeper digdeep4orxw6psc33yxa2dgmuycj74zi6334xhxjlgppw6odvkzkiad.onion

Spware Watchdog spywaredrcdg5krvjnukp3vbdwiqcv3zwbrcg6qh27kiwecm4qyfphid.onion

MayVaneDay Studios meynethaffeecapsvfphrcnfrx44w2nskgls2juwitibvqctk2plvhqd.onion

Shadow Wiki zsxjtsgzborzdllyp64c6pwnjz5eic76bsksbxzqefzogwcydnkjy3yd.onion

Outer Space reycdxyc24gf7jrnwutzdn3smmweizedy7uojsa7ols6sflwu25ijoyd.onion

Tech Learning Collective lpiyu33yusoalp5kh3f4hak2so2sjjvjw5ykyvu2dulzosgvuffq6sad.onion

Fuwa Fuwa fwfwqtpi2ofmehzdxe3e2htqfmhwfciwivpnsztv7dvpuamhr72ktlqd.onion

S-Config xjfbpuj56rdazx4iolylxplbvyft2onuerjeimlcqwaihp3s6r4xebqd.onion
 
Hacking
Defcon g7ejphhubv5idbbu3hb3wawrs5adw7tkx7yjabnf65xtzztgg4hcsqqd.onion

InfoCon w27irt6ldaydjoacyovepuzlethuoypazhhbot6tljuywy52emetn7qd.onion
 
News Sites
ProPublica p53lf57qovyuvwsc6xnrppyply3vtqm7l6pcobkmyqsiofyeznfu5uqd.onion
Darknetlive darkzzx4avcsuofgfez5zq75cqc4mprjvfqywo45dfcaxrwqg6qrlfid.onion
 
Open Source Software
OnionShare lldan5gahapx5k7iafb3s4ikijc4ni7gx5iywdflkba5y2ezyg6sjgyd.onion

Whonix dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion

Qubes OS www.qubesosfasa4zl44o4tws22di6kepyzfeqv3tg4e3ztknltfxqrymdad.onion

Keybase.IO keybase5wmilwokqirssclfnsqrjdsi7jdir5wy7y7iu3tanwmtp6oid.onion

Bitcoin Core 6hasakffvppilxgehrswmffqurlcjjjhd76jgvaqmsg6ul25s7t3rzyd.onion

Wasabi Wallet wasabiukrxmkdgve5kynjztuovbg43uxcbcxn6y2okcrsg7gb6jdmbad.onion

The Tor Project 2gzyxa5ihm7nsggfxnu52rck2vv4rvmdlkiu3zzui5du4xyclen53wid.onion
 
Others
CIA.gov ciadotgov4sjwlzihbbgxnqg3xiyrg7so2r2o3lt5wz5ypk4sxyjstad.onion

Internet Archive archivebyd3rzt3ehjpm4c3bjkyxv3hjleiytnvxcn7x32psn2kxcuid.onion

Bible4u bible4u2lvhacg4b3to2e2veqpwmrc2c3tjf2wuuqiz332vlwmr4xbad.onion

Imperial Library kx5thpx2olielkihfyo4jgjqfb7zx7wxr3sd4xzt26ochei4m6f7tayd.onion

Comic Book Library nv3x2jozywh63fkohn5mwp2d73vasusjixn3im3ueof52fmbjsigw6ad.onion

Tor Paste torpastezr7464pevuvdjisbvaf4yqi4n7sgz7lkwgqwxznwy5duj4ad.onion

Fuck Facebook 4wbwa6vcpvcr3vvf4qkhppgy56urmjcj2vagu2iqgp3z656xcmfdbiqd.onion

Just Another Library libraryfyuybp7oyidyya3ah5xvwgyix6weauoini7zyz555litmmumad.onion

Google Feud lkqx6qn7whctpdjhcoohpoyi6ahtrveuii7kq2m647ssvo5skqp7ioad.onion

NCIDE Police Task Force ncidetfs7banpz2d7vpndev5somwoki5vwdpfty2k7javniujekit6ad.onion
Forwarded from Exploiting Crew (Pr1vAt3)
๐Ÿฆ‘Ethereum Hacking:

Mythril for Smart Contracts (Ethereum)
If you want to explore Mythril's use cases (Ethereum-focused):
1. Install Mythril:

   pip install mythril

2. Run Mythril to analyze a smart contract:

   myth analyze contract.sol

3. Detect vulnerabilities in bytecode:

   myth analyze --rpc http://127.0.0.1:8545 -a <CONTRACT_ADDRESS>

---

### Commands for Bitcoin Pentesting
Bitcoin pentesting would rely on tools and methods such as analyzing P2SH scripts, transaction structures, and wallet vulnerabilities. Below are specific actionable commands/tools:

#### 1. Bitcoin Script Analysis
Use bitcoin-cli to decode and analyze scripts:

   bitcoin-cli decodescript <HEX_SCRIPT>

#### 2. Transaction Vulnerability Analysis
Decode raw transactions:

   bitcoin-cli decoderawtransaction <RAW_TX>

#### 3. Wallet Testing
Test wallets using libraries like btcpy:

   from btcpy.structs.transaction import Transaction
tx = Transaction.deserialize(<RAW_TX>)
print(tx)

#### 4. Cross-Site Blockchain Vulnerabilities
Automate REST API pentesting for wallets or blockchain explorers:

   sqlmap -u "http://blockchainexplorer.com/api?query=*" --dbs

#### 5. Custom Scripts for Exploits
Create Bitcoin raw transactions with custom scripts:

   bitcoin-cli createrawtransaction '[{"txid":"<TXID>","vout":<INDEX>}]' '{"<ADDRESS>":<AMOUNT>}'

---

### Mythril-like Analysis for Bitcoin Alternatives
1. Analyze multisig transactions for bugs:

   bitcoin-cli validateaddress <ADDRESS>

2. Debug SegWit scripts:

   bitcoin-cli decodescript <HEX_SCRIPT>

3. Use btcd or other libraries to craft transactions:
`bash
go run btcd_tx_tool.go

This post is made for educational purposes
๐Ÿฆ‘ AI models and tools for cybersecurity and hacking research

1. Code Analysis and Security Tools
- CodeBERT: AI model for secure code analysis.
URL: [https://huggingface.co/microsoft/codebert-base](https://huggingface.co/microsoft/codebert-base)
- DeepCode by Snyk: Detects vulnerabilities in codebases.
URL: [https://www.deepcode.ai/](https://www.deepcode.ai/)
- Joern: Open-source code analysis tool designed for vulnerability discovery.
URL: [https://joern.io/](https://joern.io/)

2. Adversarial Models and Simulations
- DeepExploit: Automates penetration testing with AI-driven attacks.
URL: [https://github.com/13o-bbr-bbq/machine_learning_security](https://github.com/13o-bbr-bbq/machine_learning_security)
- TextAttack: Framework for generating adversarial text for NLP systems.
URL: [https://github.com/QData/TextAttack](https://github.com/QData/TextAttack)
- Foolbox: Test the robustness of AI models with adversarial inputs.
URL: [https://foolbox.readthedocs.io/](https://foolbox.readthedocs.io/)

3. Malware Detection and Threat Intelligence
- MalConv: Neural network for malware detection from raw binaries.
URL: [https://github.com/Endermanch/MalwareDatabase](https://github.com/Endermanch/MalwareDatabase)
- Cuckoo Sandbox AI: Analyze malware behavior with AI integration.
URL: [https://cuckoosandbox.org/](https://cuckoosandbox.org/)
- Viper Framework: Malware and binary analysis toolset.
URL: [https://github.com/viper-framework/viper](https://github.com/viper-framework/viper)

4. Image and Data Analysis Tools
- YOLO (You Only Look Once): Detect anomalies or objects in visual data.
URL: [https://github.com/ultralytics/yolov5](https://github.com/ultralytics/yolov5)
- AutoML Vision by Google: Train custom vision models for detecting tampering.
URL: [https://cloud.google.com/automl](https://cloud.google.com/automl)

5. Network and System Monitoring Tools
- SnortAI: Intrusion detection with machine learning enhancements.
URL: [https://www.snort.org/](https://www.snort.org/)
- Zeek AI (Bro): Network analysis framework extended with AI.
URL: [https://zeek.org/](https://zeek.org/)
- DeepPacket: AI-driven analysis of network packet data.
URL: [https://github.com/xiaokexiang/DeepPacket](https://github.com/xiaokexiang/DeepPacket)

6. General Security Tools with AI Features
- TriageML: Machine learning for automating malware triage.
URL: [https://github.com/fireeye/Triage](https://github.com/fireeye/Triage)
- AI-Hunter: AI-driven platform for detecting and investigating cyber threats.
URL: [https://www.criticalstart.com/ai-hunter/](https://www.criticalstart.com/ai-hunter/)
- ELK Stack with AI: Integrate AI plugins with the ELK Stack for advanced threat detection.
URL: [https://www.elastic.co/](https://www.elastic.co/)
Forwarded from Exploiting Crew (Pr1vAt3)
๐Ÿฆ‘ Email Tracking:


### ๐Ÿ” About Zehef
Zehef specializes in:
- Locating public data associated with a specific email address.
- Providing insights into email breaches, pastes, and social media accounts.

---

### ๐ŸŒ  Key Features
1. Breached Data Check:
- Identify if the email has appeared in any public data breaches using sources like Pastebin or others.
2. HudsonRock Integration:
- Leverage HudsonRock to analyze leaks and identify potential compromises.
3. Social Media Account Discovery:
- Check for linked accounts across platforms such as:
- Instagram
- Spotify
- Deezer
- Adobe
- ๐• (formerly Twitter), etc.
4. Email Combination Generation:
- Create possible variations of the target email for further testing or OSINT purposes.

---

### ๐Ÿ“ฆ Installation
#### Prerequisites
- Python: Version 3.10 or later.
- Git: Installed and configured.

#### Steps:
1. Clone the Zehef repository:
   git clone https://github.com/N0rz3/Zehef.git
cd Zehef

2. Install the dependencies:
   pip3 install -r requirements.txt


---

### ๐ŸŽฒ Usage
Run the tool with the following syntax:
python3 zehef.py [email]


#### Example:
python3 zehef.py target@example.com


#### Available Options:
- email: The email address for which you want to retrieve information.
- -h, --help: Displays help information.

---

### ๐Ÿ’ก Notes
Zehef is an advanced tool for ethical OSINT practices and should only be used with proper authorization. Misuse could violate laws or terms of service on various platforms.

๐Ÿ”— GitHub Repository: [Zehef on GitHub](https://github.com/N0rz3/Zehef)
Forwarded from Exploiting Crew (Pr1vAt3)
๐Ÿฆ‘ To "run a script" on a quantum computer, you typically use a quantum programming language like Qiskit (for IBM Quantum), Cirq (for Google's quantum devices), or others like Braket (Amazon)

Quantum Script Using Qiskit

# Import necessary libraries
from qiskit import QuantumCircuit, Aer, execute

# Step 1: Create a quantum circuit with one qubit and one classical bit
qc = QuantumCircuit(1, 1)

# Step 2: Apply a Hadamard gate to put the qubit in superposition
qc.h(0)

# Step 3: Measure the qubit
qc.measure(0, 0)

# Step 4: Simulate the quantum circuit
simulator = Aer.get_backend('qasm_simulator') # Classical simulation of a quantum computer
result = execute(qc, simulator, shots=1024).result()

# Step 5: Retrieve and display results
counts = result.get_counts()
print("Measurement Results:", counts)

# Optional: Visualize the circuit
print(qc)


---

### What It Does:
1. Hadamard Gate (H): Places the qubit in a superposition, meaning it's in a mix of |0โŸฉ and |1โŸฉ.
2. Measurement: Collapses the qubit to either |0โŸฉ or |1โŸฉ probabilistically upon measurement.
3. Simulation: Runs the quantum program multiple times (e.g., 1024 shots) on a classical simulator to emulate quantum results.

---

### Output Example:
After running, you might see:
Measurement Results: {'0': 511, '1': 513}
โ”Œโ”€โ”€โ”€โ” โ–‘ โ”Œโ”€โ”
q_0: โ”ค H โ”œโ”€โ–‘โ”€โ”คMโ”œ
โ””โ”€โ”€โ”€โ”˜ โ–‘ โ””โ•ฅโ”˜
c_0: โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ•จโ”€


---

### Running on a Real Quantum Computer:
If you have access to IBM Quantum or a similar quantum platform:
1. Replace the simulator with an actual quantum backend:
   from qiskit import IBMQ
IBMQ.load_account()
provider = IBMQ.get_provider(hub='ibm-q')
backend = provider.get_backend('ibmq_qasm_simulator') # Use an actual quantum device here
result = execute(qc, backend, shots=1024).result()


Quantum computing is still in its infancy, and scripts generally focus on demonstrating concepts or solving specific problems (e.g., optimization or quantum chemistry simulations). Let me know if you'd like to explore further!
๐Ÿฆ‘ Reverse engineering:

๐Ÿ–ฅ๏ธ Static Analysis Tools
1. IDA Pro
- Industry-standard disassembler and debugger for analyzing binaries.
- Includes a powerful scripting engine.
- Website: [Hex-Rays](https://hex-rays.com/)

2. Ghidra
- Open-source reverse engineering suite developed by the NSA.
- Features include decompilation and support for various architectures.
- GitHub: [Ghidra](https://github.com/NationalSecurityAgency/ghidra)

3. Radare2
- Advanced open-source framework for analyzing binaries, debugging, and patching.
- Command-line focused but has GUI support via Cutter.
- GitHub: [Radare2](https://github.com/radareorg/radare2)

4. Binary Ninja
- Lightweight reverse engineering platform with an emphasis on automation.
- Features include powerful APIs for custom analysis.
- Website: [Binary Ninja](https://binary.ninja/)

5. Capstone
- A lightweight disassembly framework supporting multiple architectures.
- Often used as a backend for other tools.
- GitHub: [Capstone](https://github.com/capstone-engine/capstone)

---

### ๐Ÿ” Dynamic Analysis Tools
1. OllyDbg
- Classic debugger for Windows binaries.
- Focused on malware and exploit analysis.

2. WinDbg
- A powerful Windows debugger.
- Commonly used for debugging Windows kernel and drivers.

3. x64dbg
- Open-source debugger for Windows applications.
- Provides a user-friendly GUI and scripting capabilities.
- GitHub: [x64dbg](https://github.com/x64dbg/x64dbg)

4. Frida
- Dynamic instrumentation toolkit.
- Ideal for analyzing mobile apps and binaries during runtime.
- GitHub: [Frida](https://github.com/frida/frida)

5. Qiling Framework
- Advanced binary emulation framework for testing and debugging.
- Supports multiple architectures.
- GitHub: [Qiling Framework](https://github.com/qilingframework/qiling)

---

### ๐Ÿ“ฑ Mobile App Reverse Engineering Tools
1. APKTool
- Decompiles Android APK files to view the source code and resources.
- Ideal for analyzing Android malware or app vulnerabilities.
- GitHub: [APKTool](https://github.com/iBotPeaches/Apktool)

2. Jadx
- Decompiler for Android DEX and APK files.
- Converts binary code into readable Java code.
- GitHub: [Jadx](https://github.com/skylot/jadx)

3. Hopper Disassembler
- User-friendly disassembler and debugger for macOS and iOS binaries.
- Website: [Hopper](https://www.hopperapp.com/)

---

### โš™๏ธ Firmware Reverse Engineering Tools
1. Binwalk
- Tool for extracting and analyzing firmware images.
- Frequently used in IoT and embedded system analysis.
- GitHub: [Binwalk](https://github.com/ReFirmLabs/binwalk)

2. GHIDRA Firmware Analyzer
- Part of Ghidra; supports firmware disassembly and analysis.

3. Firmadyne
- Emulation and analysis of Linux-based firmware.
- GitHub: [Firmadyne](https://github.com/firmadyne/firmadyne)

---

### ๐Ÿ” Encryption and Obfuscation Tools
1. Uncompyle6
- Decompiler for Python bytecode back into readable Python source code.
- GitHub: [Uncompyle6](https://github.com/rocky/python-uncompyle6)

2. Procyon
- Java decompiler that supports modern Java features.
- GitHub: [Procyon](https://github.com/mstrobel/procyon)

3. Snowman Decompiler
- Lightweight decompiler for C/C++ binaries.
- GitHub: [Snowman](https://github.com/yegord/snowman)

---

### ๐Ÿ’ก Other Useful Tools
1. YARA
- Helps identify and classify malware through pattern matching.
- GitHub: [YARA](https://github.com/VirusTotal/yara)

2. RETool
- Web-based reverse engineering toolkit.
- Ideal for quick analysis without heavy installations.
- Website: [RETool](https://reverseengineeringtool.com/)

3. DiE (Detect It Easy)
- Identifies obfuscation, packers, and encryption in binaries.
- GitHub: [Detect It Easy](https://github.com/horsicq/Detect-It-Easy)
Forwarded from Exploiting Crew (Pr1vAt3)
๐Ÿฆ‘ New Working list of Google Dorks :

### Files Containing Passwords
1. site:github.com "BEGIN OPENSSH PRIVATE KEY"
2. ext:nix "BEGIN OPENSSH PRIVATE KEY"
3. intext:"aws_access_key_id" | intext:"aws_secret_access_key" filetype:json | filetype:yaml
4. intitle:index of /etc/ssh

### Various Online Devices
5. inurl:home.htm intitle:1766

### Vulnerable Servers
6. intitle:"SSL Network Extender Login" -checkpoint.com
7. intext:"siemens" & inurl:"/portal/portal.mwsl"
8. Google Dork Submisson For GlobalProtect Portal
9. inurl:"cgi-bin/koha"

### Files Containing Juicy Info
10. intext:"proftpd.conf" "index of"
11. site:.edu filetype:xls "root" database
12. intext:"dhcpd.conf" "index of"
13. site:uat.* * inurl:login

### Files Containing Usernames
14. "START test_database" ext:log
15. "Header for logs at time" ext:log
Forwarded from Exploiting Crew (Pr1vAt3)
Forwarded from Exploiting Crew (Pr1vAt3)
๐Ÿฆ‘ Top Ai Image Generators:

General AI Art Tools
1. DALLยทE
7 [https://openai.com/dall-e](https://openai.com/dall-e)

2. MidJourney
[https://www.midjourney.com](https://www.midjourney.com)

3. Stable Diffusion (DreamStudio)
[https://dreamstudio.ai](https://dreamstudio.ai)

4. DeepAI Image Generator
[https://deepai.org/machine-learning-model/text2img](https://deepai.org/machine-learning-model/text2img)

5. Runway ML
[https://runwayml.com](https://runwayml.com)

### Free and Easy-to-Use Generators
6. Craiyon (formerly DALLยทE Mini)
[https://craiyon.com](https://craiyon.com)

7. Artbreeder
[https://www.artbreeder.com](https://www.artbreeder.com)

8. Fotor AI Art Generator
[https://www.fotor.com/features/ai-image-generator](https://www.fotor.com/features/ai-image-generator)

9. Picsart AI Generator
[https://picsart.com/ai-image-generator](https://picsart.com/ai-image-generator)

10. NightCafe Studio
[https://creator.nightcafe.studio](https://creator.nightcafe.studio)

### Specialized AI Tools
11. Avatarify AI (For Portraits)
[https://www.avatarify.ai](https://www.avatarify.ai)

12. Deep Dream Generator (Surreal Images)
[https://deepdreamgenerator.com](https://deepdreamgenerator.com)

13. Deep Nostalgia (Photo Animation)
[https://www.myheritage.com/deep-nostalgia](https://www.myheritage.com/deep-nostalgia)

14. ArtSmart.ai
[https://artsmart.ai](https://artsmart.ai)

15. RunDiffusion (Customizable)
[https://www.rundiffusion.com](https://www.rundiffusion.com)