fa
Feedback
BlackLineGroup

BlackLineGroup

رفتن به کانال در Telegram

🚩 Channel was restricted by Telegram

نمایش بیشتر
اطلاعاتی وجود ندارد
مشترکین
اطلاعاتی وجود ندارد24 ساعت
-6017 روز
-1 41030 روز
آرشیو پست ها
📌 Directory Listing 🔎 Here are some examples of directory listings found on Indonesian websites. Directory listing can expose sensitive files that shouldn’t be publicly accessible. 🚀 BLScanner Scan Results 🚀 Total found: 300+ vulnerabilities on *.id domains 📂 Example Directory Listings:
1. https://sinergi.bpsdm.sultengprov.go.id/lib/ajax/ 2. https://simataku.dinkopumkm.sultengprov.go.id/ 3. https://layananoperasional.transjakarta.co.id/images/ 4. https://layanan.diskominfo.sultengprov.go.id/pma/js/ 5. https://klg.transjakarta.co.id/admin/static/ 6. https://jurnalbrida.sultengprov.go.id/wp-admin/css/ 7. https://inputbus.transjakarta.co.id/manual/style/ 8. https://e-mep.sultengprov.go.id/assets/ 9. https://dispusarda.sultengprov.go.id/upload_files/ 10. https://disnakertrans.sultengprov.go.id//wp-content/plugins/ml-slider/ 11. https://dishut.sultengprov.go.id/upload/ 12. https://disdukcapil.bandarlampungkota.go.id/assets/font-awesome/ 13. https://disdikbud.bandarlampungkota.go.id/temhome/css/ 14. http://siakip.sultengprov.go.id/manual/style/ 15. https://analitik.transjakarta.co.id/manual/style/ 16. http://agenda.magelangkota.go.id/assets/ 17. https://databaseperkimtan.sultengprov.go.id/api/
📌 And many more... These directory listings can be exploited further, potentially exposing configuration files, backups, or sensitive scripts that could lead to data leaks. 🛠 Recommended Fixes: ✅ Disable directory listing in .htaccess or nginx.conf. ✅ Ensure only necessary files are publicly accessible. ✅ Apply proper file permissions to prevent unauthorized access. ⚡️ _This is just a small part of BLScanner’s findings, which detected over 300 directory listings on Indonesian websites._ 🚨

photo content

In this new bot you can access the admin page on any website😶‍🌫️

photo content

new bot❤️
new bot❤️

Gg sekali scanning dapet SQL 12 biji
Gg sekali scanning dapet SQL 12 biji

free account on private group🤣
free account on private group🤣

no joke, This is really really very bad LOL

photo content
+8

photo content

Is anyone playing this game? I just found a critical vulnerability that allows me to take over any account as long as it does
Is anyone playing this game? I just found a critical vulnerability that allows me to take over any account as long as it doesn’t have two-factor authentication enabled😎😛

🎆 Prototype Pollution Vulnerability Yo, *Prototype Pollution* is a sneaky JavaScript flaw! It lets attackers slap random stuff onto an object’s prototype (aka the big boss object). This way, they can mess with properties that should be off-limits. But heads-up—it’s not always a one-shot kill. To make it nasty, attackers usually pair it with tricks like *XSS* to drop some evil moves. --- 💻 JavaScript Object Prototypes 101 In JS, everything’s an object, fam! Think of it as a bag of key-value goodies—values can be booleans, strings, numbers, whatever. Making an object? Easy peasy:
let userInfo = {
    "username": "admin",
    "password": "1qaz2wsx3edc",
    "email": "admin@victim.com"
};
Wanna grab stuff from it? Two vibes: - Dot style: userInfo.username - Bracket style: userInfo["username"] One of these is the key to polluting prototypes—guess which! --- 🔍 How Prototype Pollution Works When you call an object’s property, JS checks the object first. No dice? It climbs the *prototype chain* to the parent prototype. Try this in your browser console:
var name = "Udin";
console.log(name.__proto__);
Boom—“Udin”’s a string, so it grabs all the cool stuff from the *String prototype*. Dot or bracket it, and you’ll see inherited goodies you didn’t even add! Wanna peek at the prototype manually? Just hit: a.__proto__. Exploit Time: If an attacker rewrites a prototype property used in your app’s frontend or backend, it’s game over—security chaos incoming! --- 🛠 Testing for Prototype Pollution Time to poke around! Tweak the URL and fire it off: 1️⃣ Dot Notation Vibes
http://target.com/?__proto__.udin=udin
2️⃣ Bracket Notation Vibes
http://target.com/?__proto__[udin]=udin
WAF Dodging If the firewall’s being a buzzkill and blocks __proto__, switch it up:
/?constructor.prototype.udin=udin
/?constructor[prototype][udin]=udin
Still blocked? Get sneaky with nested chaos:
/?proprototo[udin]=udin
/?proprototo.udin=udin
/?constconstructorructor[protoprototypetype][udin]=udin
/?constconstructorructor.protoprototypetype.udin=udin
Check If It Worked Pop this in the console:
let test = {};
console.log(test.udin); // "udin" pops up? You’re in!
If it shows, the target’s got a *Prototype Pollution* hole! --- 🎯 Wrap-Up Prototype Pollution is a beast—mix it with other exploits, and it’s a security nightmare. Knowing how JS prototypes roll is clutch for both hacking and defending. Stay sharp, fam!

Bootcamp batch 1 isn’t finished yet, but even without promotion or an official announcement, many people are already waiting
Bootcamp batch 1 isn’t finished yet, but even without promotion or an official announcement, many people are already waiting for the next one. What does this mean guys?😅😶

Mantab dapet lagi dari botnya 2 sql injection mas wkwk
Mantab dapet lagi dari botnya 2 sql injection mas wkwk

💻 Buat Windows User: 1️⃣ Download *install.ps1* dari repo. 2️⃣ Buka PowerShell as Admin:
Set-ExecutionPolicy -ExecutionPolicy bypass -Scope process
3️⃣ Jalankan:
.\install.ps1
4️⃣ Ikutin langkah aktivasi manual sama kayak di atas. Lisensi pake nama custom juga bisa (contoh: license to BlackLineGroup). 5️⃣ Shortcut dibikin otomatis di *Burp-Suite-Pro.vbs*, tinggal double-click buat jalanin. --- ⚠️⚠️⚠️⚠️⚠️⚠️ - Kalo *Chromium Browser* di Burp ga jalan, coba buka tanpa *sudo*. Edit *install.sh*, hapus baris sudo cp ke /bin, trus jalanin manual dari folder lokal. - Versi terbaru selalu di-update di repo, cek aja commit terakhir. ✅Done! Sekarang *Burp Suite Pro* udah aktif pake nama lisensi kamu sendiri. Happy hacking bro, tapi ingat, buat edukasi aja ya! 😎 Gimana, jelas ga? Kalo ada yang bingung, tanya lagi aja di sini! 🔥

🛠 Cara Install Burp Suite Professional dengan Lisensi nama sendiri 07 Maret 2025 Prasyarat: - Pastikan udah install *Git*, *Wget*, sama *OpenJDK* (versi 21, 22, atau 23 recomended). - Koneksi internet harus stabil, biar ga putus pas download. --- 😀 Langkah-langkah Instalasi (Linux): 1️⃣ Clone Repo-nya Dulu
cd && git clone https://github.com/xiv3r/Burpsuite-Professional.git
cd Burpsuite-Professional
- Ini bakal ngambil semua file dari repo ke folder lokalmu. 2️⃣Update Dependencies
sudo apt update && sudo apt install git wget openjdk-21-jre openjdk-22-jre openjdk-23-jre -y
- Pastikan semua dependensi ke-install, biar *Burp* jalan mulus. 3️⃣ Download Burp Suite Pro - File *install.sh* di repo udah otomatis ngambil versi terbaru (contoh: v2025.1.1). Langsung aja jalankan:
sudo sh install.sh
- Tunggu bentar, dia bakal download *burpsuite_pro_v2025.1.1.jar* sama *loader.jar*. 4️⃣Jalankan Keygen & Burp - Setelah download selesai, *loader.jar* bakal kebuka otomatis buat generate lisensi. - Di jendela *loader*: - Ubah string lisensi jadi pake nama kamu, misal:
    license to BlackLineGroup
    
- Copy lisensi yang di-generate. 5️⃣Aktivasi Manual di Burp - Buka *Burp Suite Pro*-nya (otomatis ke-launch abis install). - Klik *Manual Activation*: - Paste lisensi dari *loader* tadi ke kolom pertama. - Copy *License Request*-nya dari Burp, trus paste ke *loader*. - *Loader* bakal kasih *License Response*, copy lagi ke Burp, klik *Next*, trus *Done*. 6️⃣Bikin Shortcut (Opsional) - Biar gampang buka lagi, file *burpsuitepro* udah dibikin di /bin. Tinggal ketik:
burpsuitepro
- Atau bikin launcher di desktop pake command:
java -javaagent:/path/to/loader.jar -noverify -jar /path/to/burpsuite_pro_v2025.1.1.jar

Alhamdulillah, being a white hat is truly enjoyable😚
Alhamdulillah, being a white hat is truly enjoyable😚

🤫
🤫

GeoSpy is a Python tool that uses AI from Graylark to track locations from photos. Features: ✅ Extracts country, city, and coordinates from an image. ✅ Generates a Google Maps link based on coordinates. GeoSpy AI can detect your location from photos taken at home. The developers claim that no metadata is needed at all. The neural network simply analyzes the scenery in your photo to guess where you are. So, maybe it's best to avoid sharing home photos from now on. 😬

bri.co.id My bot got a vulnerability with High severity there😨
bri.co.id My bot got a vulnerability with High severity there😨