domingo, 30 de agosto de 2020

ezEmu - Simple Execution Of Commands For Defensive Tuning/Research

Related news

Hack-Tools - The All-In-One Red Team Extension For Web Pentester


The all-in-one Red Team browser extension for Web Pentesters
HackTools, is a web extension facilitating your web application penetration tests, it includes cheat sheets as well as all the tools used during a test such as XSS payloads, Reverse shells and much more.
With the extension you no longer need to search for payloads in different websites or in your local storage space, most of the tools are accessible in one click. HackTools is accessible either in pop up mode or in a whole tab in the Devtools part of the browser with F12.

Current functions:
  • Dynamic Reverse Shell generator (PHP, Bash, Ruby, Python, Perl, Netcat)
  • Shell Spawning (TTY Shell Spawning)
  • XSS Payloads
  • Basic SQLi payloads
  • Local file inclusion payloads (LFI)
  • Base64 Encoder / Decoder
  • Hash Generator (MD5, SHA1, SHA256, SHA512)
  • Useful Linux commands (Port Forwarding, SUID)

Preview



Install the application

Chromium based browser
All the available releases are here..
Otherwise, if you want to build the project yourself from the source code

Mozilla Firefox
You can download HackTools on the Firefox browser add-ons here.

Build from source code
yarn install && yarn build
Once the build is done correctly, webpack will create a new folder called dist
After that you need to go to the extension tab on your chrome based navigator and turn on the

developer mode

Then click on the load unpacked button in the top left corner

Once you clicked on the button you just need to select the dist folder and that's it !

Authors
Ludovic COULON & Riadh BOUCHAHOUA




via KitPloit

Continue reading


  1. Hacking Tools Kit
  2. Pentest Tools Find Subdomains
  3. Hacker Tools For Windows
  4. Pentest Tools Review
  5. Hack App
  6. Blackhat Hacker Tools
  7. Hacker Tool Kit
  8. Hacker Tools For Windows
  9. Pentest Reporting Tools
  10. Hacker Tools Mac
  11. Hacker Tools For Windows
  12. Hack Tools For Games
  13. Pentest Tools Website Vulnerability
  14. How To Hack
  15. Pentest Tools
  16. Hacker Tools For Windows
  17. Hacking Tools For Games
  18. Hacks And Tools
  19. Tools For Hacker
  20. Pentest Tools Tcp Port Scanner
  21. Usb Pentest Tools
  22. World No 1 Hacker Software
  23. Pentest Tools Website Vulnerability
  24. Hack Tools Github
  25. Hacking Tools For Windows
  26. Tools 4 Hack
  27. Hacking Tools Download
  28. Kik Hack Tools
  29. Game Hacking
  30. Hacking Tools For Kali Linux
  31. Hacker Tools Linux
  32. Hacking Tools 2019
  33. Hacker Tools Online
  34. Install Pentest Tools Ubuntu
  35. Computer Hacker
  36. Hack Tools For Windows
  37. Hack Tools Download
  38. Pentest Tools Framework
  39. Hack Tools Download
  40. Pentest Tools Website Vulnerability
  41. Hacking Tools Usb
  42. How To Hack
  43. Hacking Tools
  44. Growth Hacker Tools
  45. Computer Hacker
  46. Underground Hacker Sites
  47. Hak5 Tools
  48. Pentest Tools Framework
  49. Hacking Tools Windows
  50. Hacker Tools 2019
  51. Pentest Tools Tcp Port Scanner
  52. Nsa Hacker Tools
  53. Hacking Tools Mac
  54. Growth Hacker Tools
  55. Hacker
  56. Hacker Tools Free
  57. Hacker Tools Online
  58. Hacker Tools Free
  59. Best Pentesting Tools 2018
  60. New Hacker Tools
  61. Hack App
  62. Hacker Tools For Ios
  63. Github Hacking Tools
  64. Wifi Hacker Tools For Windows
  65. Hacker Tools For Ios
  66. Hacking Tools Usb
  67. Hacking Tools For Windows Free Download
  68. Hacker Tools Software
  69. Usb Pentest Tools
  70. Pentest Tools Tcp Port Scanner
  71. Pentest Tools Tcp Port Scanner
  72. How To Install Pentest Tools In Ubuntu
  73. Game Hacking
  74. Top Pentest Tools
  75. Physical Pentest Tools
  76. Tools For Hacker
  77. Hack Tools For Windows

sábado, 29 de agosto de 2020

SubOver - A Powerful Subdomain Takeover Tool


Subover is a Hostile Subdomain Takeover tool designed in Python. From start, it has been aimed with speed and efficiency in mind. Till date, SubOver detects 36 services which is much more than any other tool out there. The tool is multithreaded and hence delivers good speed. It can easily detect and report potential subdomain takeovers that exist. The list of potentially hijackable services is very comprehensive and it is what makes this tool so powerful.

Installing
You need to have Python 2.7 installed on your machine. The following additional requirements are required -
  • dnspython
  • colorama
git clone https://github.com/Ice3man543/SubOver.git .
cd SubOver
# consider installing virtualenv
pip install -r requirements.txt
python subover.py -h

Usage
python subover.py -l subdomains.txt -o output_takeovers.txt
  • -l subdomains.txt is the list of target subdomains. These can be discovered using various tool such as sublist3r or others.
  • -o output_takeovers.txtis the name of the output file. (Optional & Currently not very well formatted)
  • -t 20 is the default number of threads that SubOver will use. (Optional)
  • -V is the switch for showing verbose output. (Optional, Default=False)

Currently Checked Services
  • Github
  • Heroku
  • Unbounce
  • Tumblr
  • Shopify
  • Instapage
  • Desk
  • Tictail
  • Campaignmonitor
  • Cargocollective
  • Statuspage
  • Amazonaws
  • Cloudfront
  • Bitbucket
  • Squarespace
  • Smartling
  • Acquia
  • Fastly
  • Pantheon
  • Zendesk
  • Uservoice
  • WPEngine
  • Ghost
  • Freshdesk
  • Pingdom
  • Tilda
  • Wordpress
  • Teamwork
  • Helpjuice
  • Helpscout
  • Cargo
  • Feedpress
  • Freshdesk
  • Surge
  • Surveygizmo
  • Mashery
Count : 36

FAQ
Q: What should my wordlist look like?
A: Your wordlist should include a list of subdomains you're checking and should look something like:
backend.example.com
something.someone.com
apo-setup.fxc.something.com

Your tool sucks!
Yes, you're probably correct. Feel free to:
  • Not use it.
  • Show me how to do it better.

Contact
Twitter: @Ice3man543

Credits


Related word

Linux.Agent Malware Sample - Data Stealer



Research: SentinelOne, Tim Strazzere Hiding in plain sight?
Sample credit: Tim Strazzere


List of files

9f7ead4a7e9412225be540c30e04bf98dbd69f62b8910877f0f33057ca153b65  malware
d507119f6684c2d978129542f632346774fa2e96cf76fa77f377d130463e9c2c  malware
fddb36800fbd0a9c9bfffb22ce7eacbccecd1c26b0d3fb3560da5e9ed97ec14c  script.decompiled-pretty
ec5d4f90c91273b3794814be6b6257523d5300c28a492093e4fa1743291858dc  script.decompiled-raw
4d46893167464852455fce9829d4f9fcf3cce171c6f1a9c70ee133f225444d37  script.dumped

malware_a3dad000efa7d14c236c8018ad110144
malware fcbfb234b912c84e052a4a393c516c78
script.decompiled-pretty aab8ea012eafddabcdeee115ecc0e9b5
script.decompiled-raw ae0ea319de60dae6d3e0e58265e0cfcc
script.dumped b30df2e63bd4f35a32f9ea9b23a6f9e7


Download


Download. Email me if you need the password


More info