en
Feedback
Ethical Hackers Vol. 2

Ethical Hackers Vol. 2

Open in Telegram

Acquire Content-Rich Courses and Tutorials here For Free. Strictly for Educational purposes onlyπŸ’―

Show more
6 865
Subscribers
No data24 hours
No data7 days
-1030 days

Data loading in progress...

Similar Channels
No data
Any problems? Please refresh the page or contact our support manager.
Tags Cloud
No data
Any problems? Please refresh the page or contact our support manager.
Incoming and Outgoing Mentions
---
---
---
---
---
---
Attracting Subscribers
March '25
March '25
+3
in 0 channels
February '25
+78
in 0 channels
Get PRO
January '25
+62
in 0 channels
Get PRO
December '24
+76
in 0 channels
Get PRO
November '24
+44
in 0 channels
Get PRO
October '24
+83
in 1 channels
Get PRO
September '24
+129
in 1 channels
Get PRO
August '24
+99
in 0 channels
Get PRO
July '24
+113
in 0 channels
Get PRO
June '24
+90
in 0 channels
Get PRO
May '24
+103
in 0 channels
Get PRO
April '24
+73
in 0 channels
Get PRO
March '24
+103
in 0 channels
Get PRO
February '24
+100
in 0 channels
Get PRO
January '24
+142
in 0 channels
Get PRO
December '23
+101
in 0 channels
Get PRO
November '23
+144
in 0 channels
Get PRO
October '23
+119
in 0 channels
Get PRO
September '23
+214
in 0 channels
Get PRO
August '23
+235
in 0 channels
Get PRO
July '23
+169
in 0 channels
Get PRO
June '23
+79
in 0 channels
Get PRO
May '23
+122
in 0 channels
Get PRO
April '23
+268
in 0 channels
Get PRO
March '23
+117
in 0 channels
Get PRO
February '23
+107
in 0 channels
Get PRO
January '23
+89
in 0 channels
Get PRO
December '22
+195
in 0 channels
Get PRO
November '22
+138
in 0 channels
Get PRO
October '22
+454
in 0 channels
Get PRO
September '22
+558
in 0 channels
Get PRO
August '22
+314
in 0 channels
Get PRO
July '22
+339
in 0 channels
Get PRO
June '22
+330
in 0 channels
Get PRO
May '22
+423
in 0 channels
Get PRO
April '22
+94
in 0 channels
Get PRO
March '22
+109
in 0 channels
Get PRO
February '22
+84
in 0 channels
Get PRO
January '22
+121
in 0 channels
Get PRO
December '21
+124
in 0 channels
Get PRO
November '21
+94
in 0 channels
Get PRO
October '21
+334
in 0 channels
Get PRO
September '21
+218
in 0 channels
Get PRO
August '21
+273
in 0 channels
Get PRO
July '21
+298
in 0 channels
Get PRO
June '21
+188
in 0 channels
Get PRO
May '21
+245
in 0 channels
Get PRO
April '21
+204
in 0 channels
Get PRO
March '21
+168
in 0 channels
Get PRO
February '21
+160
in 0 channels
Get PRO
January '21
+209
in 0 channels
Get PRO
December '20
+3 838
in 0 channels
Date
Subscriber Growth
Mentions
Channels
02 March+2
01 March+1
Channel Posts
2
https://t.me/Ethical_Hackers_Giveaway
0
3
https://t.me/ETHICALHACKERSC
0
4
Get Live Demo (https://demo.waf.chaitin.com:9443/) FEATURES List of the main features as follows: Block Web Attacks It defenses for all of web attacks, such as SQL injection, XSS, code injection, os command injection, CRLF injection, XXE, SSRF, path traversal and so on. Rate Limiting Defend your web apps against DoS attacks, bruteforce attempts, traffic surges, and other types of abuse by throttling traffic that exceeds defined limits. Anti-Bot Challenge Anti-Bot challenges to protect your website from bot attacks, humen users will be allowed, crawlers and bots will be blocked. Authentication Challenge When authentication challenge turned on, visitors need to enter the password, otherwise they will be blocked. Dynamic Protection When dynamic protection turned on, html and js codes in your web server will be dynamically encrypted by each time you visit. Download SafeLine (https://github.com/chaitin/SafeLine)
0
5
No text...
0
6
No text...
0
7
No text...
0
8
No text...
0
9
By deploying a WAF in front of a web application, a shield is placed between the web application and the Internet. While a proxy server protects a client machine's identity by using an intermediary, a WAF is a type of reverse-proxy, protecting the server from exposure by having clients pass through the WAF before reaching the server. A WAF protects your web apps by filtering, monitoring, and blocking any malicious HTTP/S traffic traveling to the web application, and prevents any unauthorized data from leaving the app. It does this by adhering to a set of policies that help determine what traffic is malicious and what traffic is safe. Just as a proxy server acts as an intermediary to protect the identity of a client, a WAF operates in similar fashion but acting as an reverse proxy intermediary that protects the web app server from a potentially malicious client. its core capabilities include: Defenses for web attacks Proactive bot abused defense HTML & JS code encryption IP-based rate limiting Web Access Control List Screenshots
0
10
No text...
0
11
SafeLine is a self-hosted WAF(Web Application Firewall) to protect your web apps from attacks and exploits. A web application firewall helps protect web apps by filtering and monitoring HTTP traffic between a web application and the Internet. It typically protects web apps from attacks such as SQL injection (https://www.kitploit.com/search/label/Injection), XSS, code injection (https://www.kitploit.com/search/label/Injection), os command injection (https://www.kitploit.com/search/label/Injection), CRLF injection (https://www.kitploit.com/search/label/Injection), ldap injection (https://www.kitploit.com/search/label/Injection), xpath injection (https://www.kitploit.com/search/label/Injection), RCE, XXE, SSRF, path traversal, backdoor (https://www.kitploit.com/search/label/Backdoor), bruteforce (https://www.kitploit.com/search/label/Bruteforce), http-flood (https://www.kitploit.com/search/label/HTTP-flood), bot abused, among others. How It Works
0
12
No text...
0
13
SafeLine - Serve As A Reverse Proxy To Protect Your Web Services From Attacks And Exploits http://www.kitploit.com/2024/09/safeline-serve-as-reverse-proxy-to.html
0
14
BYOSI - Bring-Your-Own-Script-Interpreter - Leveraging the abuse of trusted applications, one is able to deliver a compatible script interpreter for a Windows, Mac, or Linux system as well as malicious source code in the form of the specific script interpreter of choice. Once both the malicious source code and the trusted script interpeter are safely written to the target system, one could simply execute said source code via the trusted script interpreter. PolyDrop - Leverages thirteen scripting languages to perform the above attack. The following langues are wholly ignored by AV vendors including MS-Defender: - tcl - php - crystal (https://www.kitploit.com/search/label/Crystal) - julia - golang - dart - dlang - vlang - nodejs (https://www.kitploit.com/search/label/NodeJS) - bun - python - fsharp (https://www.kitploit.com/search/label/Fsharp) - deno All of these languages were allowed to completely execute, and establish a reverse shell by MS-Defender. We assume the list is even longer, given that languages such as PHP are considered "dead" languages. - Currently undetectable by most mainstream Endpoint-Detection & Response vendors. The total number of vendors that are unable to scan or process just PHP file types is 14, and they are listed below: Alibaba Avast-Mobile BitDefenderFalx Cylance DeepInstinct Elastic McAfee Scanner Palo Alto Networks SecureAge SentinelOne (Static ML) Symantec Mobile Insight Trapmine Trustlook Webroot And the total number of vendors that are unable to accurately identify malicious PHP scripts (https://www.kitploit.com/search/label/Scripts) is 54, and they are listed below: Acronis (Static ML) AhnLab-V3 ALYac Antiy-AVL Arcabit Avira (no cloud) Baidu BitDefender BitDefenderTheta ClamAV CMC CrowdStrike Falcon Cybereason Cynet DrWeb Emsisoft eScan ESET-NOD32 Fortinet GData Gridinsoft (no cloud) Jiangmin K7AntiVirus K7GW Kaspersky Lionic Malwarebytes MAX MaxSecure NANO-Antivirus Panda QuickHeal Sangfor Engine Zero Skyhigh (SWG) Sophos SUPERAntiSpyware Symantec TACHYON TEHTRIS Tencent Trellix (ENS) Trellix (HX) TrendMicro TrendMicro-HouseCall Varist VBA32 VIPRE VirIT ViRobot WithSecure Xcitium Yandex Zillya ZoneAlarm by Check Point Zoner With this in mind, and the absolute shortcomings on identifying PHP based malware (https://www.kitploit.com/search/label/Malware) we came up with the theory that the 13 identified languages are also an oversight by these vendors, including CrowdStrike, Sentinel1, Palo Alto, Fortinet, etc. We have been able to identify that at the very least Defender considers these obviously malicious payloads as plaintext. Disclaimer We as the maintainers, are in no way responsible for the misuse or abuse of this product. This was published for legitimate penetration testing/red teaming purposes, and for educational value. Know the applicable laws in your country of residence before using this script, and do not break the law whilst using this. Thank you and have a nice day. EDIT In case you are seeing all of the default declarations, and wondering wtf guys. There is a reason; this was built to be more moduler for later versions. For now, enjoy the tool and feel free to post issues. They'll be addressed as quickly as possible. Download PolyDrop (https://github.com/MalwareSupportGroup/PolyDrop)
0
15
No text...
0
16
PolyDrop - A BYOSI (Bring-Your-Own-Script-Interpreter) Rapid Payload Deployment Toolkit http://www.kitploit.com/2024/09/polydrop-byosi-bring-your-own-script.html
0
17
Usage examples Run a fuzzing (https://www.kitploit.com/search/label/Fuzzing) task (ffuf): secator x ffuf http://testphp.vulnweb.com/FUZZ Run a url crawl workflow: secator w url_crawl http://testphp.vulnweb.com Run a host scan: secator s host mydomain.com and more... to list all tasks / workflows / scans that you can use: secator x --help secator w --help secator s --help Learn more To go deeper with secator, check out: * Our complete documentation (https://docs.freelabz.com/) * Our getting started tutorial video (https://youtu.be/-JmUTNWQDTQ?si=qpAClDWMXo2zwUK7) * Our Medium post (https://medium.com/p/09333f3d3682) * Follow us on social media: @freelabz (https://twitter.com/freelabz) on Twitter and @FreeLabz (https://youtube.com/@FreeLabz) on YouTube Download Secator (https://github.com/freelabz/secator)
0
18
No text...
0
19
The volume mount -v is necessary to save all secator reports to your host machine, and--net=host is recommended to grant full access to the host network. You can alias this command to run it easier: alias secator="docker run -it --rm --net=host -v ~/.secator:/root/.secator freelabz/secator" Now you can run secator like if it was installed on baremetal: secator --help Docker Compose git clone https://github.com/freelabz/secator cd secator docker-compose up -d docker-compose exec secator secator --help Note: If you chose the Bash, Docker or Docker Compose installation methods, you can skip the next sections and go straight to Usage (https://github.com/freelabz/secator#usage). Installing languages secator uses external tools, so you might need to install languages used by those tools assuming they are not already installed on your system. We provide utilities to install required languages if you don't manage them externally: Go secator install langs go Ruby secator install langs ruby Installing tools secator does not install any of the external tools it supports by default. We provide utilities to install or update each supported tool which should work on all systems supporting apt: All tools secator install tools Specific tools secator install tools For instance, to install `httpx`, use: secator install tools httpx Please make sure you are using the latest available versions for each tool before you run secator or you might run into parsing / formatting issues. Installing addons secator comes installed with the minimum amount of dependencies. There are several addons available for secator: worker Add support for Celery workers (see [Distributed runs with Celery](https://docs.freelabz.com/in-depth/distributed-runs-with-celery)). secator install addons worker google Add support for Google Drive exporter (`-o gdrive`). secator install addons google mongodb Add support for MongoDB driver (`-driver mongodb`). secator install addons mongodb redis Add support for Redis backend (Celery). secator install addons redis dev Add development tools like `coverage` and `flake8` required for running tests. secator install addons dev trace Add tracing tools like `memray` and `pyinstrument` required for tracing functions. secator install addons trace build Add `hatch` for building and publishing the PyPI package. secator install addons build Install CVEs secator makes remote API calls to https://cve.circl.lu/ to get in-depth information about the CVEs it encounters. We provide a subcommand to download all known CVEs locally so that future lookups are made from disk instead: secator install cves Checking installation health To figure out which languages or tools are installed on your system (along with their version): secator health Usage secator --help
0
20
secator is a task and workflow runner used for security assessments. It supports dozens of well-known security tools and it is designed to improve productivity (https://www.kitploit.com/search/label/Productivity) for pentesters (https://www.kitploit.com/search/label/Pentesters) and security researchers. Features Curated list of commands Unified input options Unified output schema CLI and library usage Distributed (https://www.kitploit.com/search/label/Distributed) options with Celery Complexity from simple tasks to complex workflows Customizable (https://www.kitploit.com/search/label/Customizable) Supported tools secator integrates the following tools: Name Description Category httpx (https://github.com/projectdiscovery/httpx) Fast HTTP prober. http cariddi (https://github.com/edoardottt/cariddi) Fast crawler and endpoint secrets / api keys / tokens matcher. http/crawler gau (https://github.com/lc/gau) Offline URL crawler (Alien Vault, The Wayback Machine, Common Crawl, URLScan). http/crawler gospider (https://github.com/jaeles-project/gospider) Fast web spider written in Go. http/crawler katana (https://github.com/projectdiscovery/katana) Next-generation crawling and spidering framework. http/crawler dirsearch (https://github.com/maurosoria/dirsearch) Web path discovery. http/fuzzer feroxbuster (https://github.com/epi052/feroxbuster) Simple, fast, recursive content discovery tool written in Rust. http/fuzzer ffuf (https://github.com/ffuf/ffuf) Fast web fuzzer written in Go. http/fuzzer h8mail (https://github.com/khast3x/h8mail) Email OSINT and breach hunting tool. osint dnsx (https://github.com/projectdiscovery/dnsx) Fast and multi-purpose DNS toolkit designed for running DNS queries. recon/dns dnsxbrute (https://github.com/projectdiscovery/dnsx) Fast and multi-purpose DNS toolkit designed for running DNS queries (bruteforce mode). recon/dns subfinder (https://github.com/projectdiscovery/subfinder) Fast subdomain finder. recon/dns fping (https://fping.org/) Find alive hosts on local networks. recon/ip mapcidr (https://github.com/projectdiscovery/mapcidr) Expand CIDR ranges into IPs. recon/ip naabu (https://github.com/projectdiscovery/naabu) Fast port discovery tool. recon/port maigret (https://github.com/soxoj/maigret) Hunt for user accounts across many websites. recon/user gf (https://github.com/tomnomnom/gf) A wrapper around grep to avoid typing common patterns. tagger grype (https://github.com/anchore/grype) A vulnerability scanner for container images and filesystems. vuln/code dalfox (https://github.com/hahwul/dalfox) Powerful XSS scanning tool and parameter analyzer. vuln/http msfconsole (https://docs.rapid7.com/metasploit/msf-overview) CLI to access and work with the Metasploit Framework. vuln/http wpscan (https://github.com/wpscanteam/wpscan) WordPress Security Scanner vuln/multi nmap (https://github.com/nmap/nmap) Vulnerability scanner using NSE scripts. vuln/multi nuclei (https://github.com/projectdiscovery/nuclei) Fast and customisable vulnerability scanner based on simple YAML based DSL. vuln/multi searchsploit (https://gitlab.com/exploit-database/exploitdb) Exploit searcher. exploit/search Feel free to request new tools to be added by opening an issue, but please check that the tool complies with our selection criterias before doing so. If it doesn't but you still want to integrate it into secator, you can plug it in (see the dev guide (https://docs.freelabz.com/for-developers/writing-custom-tasks)). Installation Installing secator Pipx pipx install secator Pip pip install secator Bash wget -O - https://raw.githubusercontent.com/freelabz/secator/main/scripts/install.sh | sh Docker docker run -it --rm --net=host -v ~/.secator:/root/.secator freelabz/secator --help
0