Tampilkan postingan dengan label Vulnerability. Tampilkan semua postingan
Tampilkan postingan dengan label Vulnerability. Tampilkan semua postingan

Hack Windows using HTA Method


HTA Method ?

HTA Method adalah suatu metode yang digunakan unutk mengirim dan menjalankan exploit dengan menyisipkan exploit tersebut kedalam file yang telah ditanam di fake website.

Langkah-langkah


1. Pastikan sudah memepunya setoolkit. Buka tool tersebut, lalu pilih Social-Engineering Attacks.


2. Selanjutnya pilih Website Attack Vectors.


3. Selanjutnya kita pilih jenis method yang akan digunakan, sesuai judul kita gunakan HTA Method.


4. Nah, disini kita pilih site cloner saja karena paling mudah tanpa perlu upload file web yang akan dibuat fake website.


5. Selanjutnya isi url website yang akan kita clone. Disini saya menggunakan google.


6. Untuk Lhostnya disesuaikan dengan ip masing-masing. ip pc saya adalah 192.168.1.6.


7. nah untuk reverse port payloadnya biarkan default 433


8. Untuk type port yang digunakan pilih TCP.


9. Kita tunggu sampai metasploit siap menjalankan exploitnya. Contoh metasploit sudah siap.


10. Langsung saja eksekusi shellnya yang berada di pc target. Ketik ip lhost yang telah diset tadi yaitu 192.168.1.6 (tergantung ip masing-masing). Tunggu sebentar nanti akan ada pop-up download file (exploit), silahkan di download dan dijalankan dan tunggu saja beberapa saat, dan liat di terminal metasploit menunjukkan bahwa sessions dari pc target telah terbuka. Berikut gambarannya :


[NOTE]
Sebagai manusia yang masih mempunyai akal yg sehat gunakan dengan hal yang bermanfaat. Ingat etika itu penting, meskipun anda seorang underground.

Apabila masih bingung bisa dilihat video tutorial disini




Tulpar - Web Scanner Vulnerability


What is Tulpar ?

Tulpar adalah sebuah tool open source yang diciptakan untuk melakukan pengecekan terhadap kerentanan (vulnerability) suatu web.

Features

      -Sql Injection (GET Method)
      -XSS (GET Method)
      -Crawl
      -E-mail Disclosure
      -Credit Card Disclosure
      -Whois
      -Command Injection (GET Method)
      -Directory Traversal (GET Method)
      -File Include (GET Method)
      -Server Information
      -Technology Information
      -X-Content-Type Check
      -X-XSS-Protection Check
      -TCP Port Scanner
      -robots.txt Check
      -URL Encode
      -Certification Information
      -Available Methods
      -Cyber Threat Intelligence
      -IP2Location
      -File Input Available Check

Installation

git clone https://github.com/anilbaranyelken/tulpar.git
cd tulpar
pip install -r requirements

Usage

python tulpar.py action web_URL
Action: full xss sql fuzzing e-mail credit-card whois links portscanner urlEncode cyberthreatintelligence commandInjection directoryTraversal fileInclude headerCheck certificate method IP2Location FileInputAvailable

Example

Kita coba lakukan pengumpulan informasi dns dengan method whois :


Untuk lainnya bisa di coba sendiri.

[NOTE]
Sebagai manusia yang masih mempunyai akal yg sehat gunakan dengan hal yang bermanfaat. Ingat etika itu penting, meskipun anda seorang underground.

Source : https://github.com/tulpar/tulpar

Scan SSL Vulnerability using A2SV


1. Apa itu A2SV ?
A2SV (auto scanning ssl vulnerability) adalah sebuah tool yang dirancang khusus dengan tujuan mencari vulnerability dari ssl.

2. Support Vulnerability

      [CVE-2007-1858] Anonymous Cipher
      [CVE-2012-4929] CRIME(SPDY)
      [CVE-2014-0160] CCS Injection
      [CVE-2014-0224] HeartBleed
      [CVE-2014-3566] SSLv3 POODLE
      [CVE-2015-0204] FREAK Attack
      [CVE-2015-4000] LOGJAM Attack
      [CVE-2016-0800] SSLv2 DROWN

2. How to Install?

A. Download(clone) & Unpack A2SV
#git clone https://github.com/hahwul/a2sv.git
#cd a2sv

B. Install Python Package / OpenSSL
#pip install argparse
#pip install netaddr
#apt-get install openssl

C. Run A2SV
#python a2sv.py -h

or

#./install.sh ======= and then open in your terminal "a2sv"

3. How to Use ?


Trying on website [sensor] :
1. a2sv -t bing.com
ini adalah contoh hasil scan menggunakan a2sv :


Bisa dilihat website [sensor] mempunyai vuln seperti di hasil scan.

[NOTE]
Sebagai manusia yang masih mempunyai akal yg sehat gunakan dengan hal yang bermanfaat. Ingat etika itu penting, meskipun anda seorang underground.

[Update A2SV]
#python a2sv.py -u
#python a2sv.py --update

Source : https://github.com/hahwul/a2sv

Fsociety Hacking Tools Pack - Kumpulan Tools Pentetrasi Framework


Kumpulan tools yang dipack menjadi satu untuk keperluan Pentrasi testing Framework. Fsociety Berisi Semua Alat yang Digunakan Dalam Serial film mr.Robot.


Menu

  • Information Gathering
  • Password Attacks
  • Wireless Testing
  • Exploitation Tools
  • Sniffing & Spoofing
  • Web Hacking
  • Private Web Hacking
  • Post Exploitation
  • INSTALL & UPDATE

Daftar Tools


Information Gathering :
  • Nmap
  • Setoolkit
  • Port Scanning
  • Host To IP
  • wordpress user
  • CMS scanner
  • XSStracer
  • Dork - Google Dorks Passive Vulnerability Auditor
  • Scan A server's Users

Password Attacks :
  • Cupp
  • Ncrack

Wireless Testing :
  • reaver
  • pixiewps

Exploitation Tools :
  • Venom
  • sqlmap
  • Shellnoob
  • commix
  • FTP Auto Bypass
  • jboss-autopwn

Sniffing & Spoofing :
  • Setoolkit
  • SSLtrip
  • pyPISHER
  • SMTP Mailer

Web Hacking :
  • Drupal Hacking
  • Inurlbr
  • Wordpress & Joomla Scanner
  • Gravity Form Scanner
  • File Upload Checker
  • Wordpress Exploit Scanner
  • Wordpress Plugins Scanner
  • Shell and Directory Finder
  • Joomla! 1.5 - 3.4.5 remote code execution
  • Vbulletin 5.X remote code execution
  • BruteX - Automatically brute force all services running on a target
  • Arachni - Web Application Security Scanner Framework

Private Web Hacking
  • Get all websites
  • Get joomla websites
  • Get wordpress websites
  • Control Panel Finder
  • Zip Files Finder
  • Upload File Finder
  • Get server users
  • SQli Scanner
  • Ports Scan (range of ports)
  • ports Scan (common ports)
  • Get server Info
  • Bypass Cloudflare

Post Exploitation
  • Shell Checker
  • POET
  • Phishing Framework

Installation


1. Download

# git clone https://github.com/Manisso/fsociety.git
# cd fsociety && python fsociety.py

2. Install and Upate (pilih 0)

0 : INSTALL & UPDATE

3. Congratulation Fsociety is Installed !

Contoh Pemakaian :




Referensi :

https://www.kitploit.com/2017/12/fsociety-hacking-tools-pack-penetration.html
https://github.com/Manisso/fsociety

Crips - Tools Untuk mendapatkan informasi Alamat IP, Web Pages dan DNS dengan cepat.


Crips adalah kumpulan tool IP online yang dapat digunakan untuk mendapatkan informasi tentang Alamat IP, Web Pages, dan catatan DNS dengan cepat secara online.

Menu

  • Whois lookup
  • Traceroute
  • DNS Lookup
  • Reverse DNS Lookup
  • GeoIP Lookup
  • Port Scan
  • Reverse IP Lookup
  • INSTALL & UPDATE
  • Exit

Whois lookup
Mengetahui identitias pemilik ip atau domain name system.

Traceroute
Pelacakan jalur koneksi internet menggunakan mtr sebuah alat traceroute terbaru untuk melacak jalur koneksi Internet.

DNS Lookup
Menemukan data DNS dari sebuah domain, hasilnya ditentukan dengan menggunakan alat penggali DNS di tools Crips.

Reverse DNS Lookup
Menemukan catatan Reverse DNS untuk suatu alamat IP.

GeoIP Lookup
Mencari sebuah lokasi dari alamat IP menggunakan GeoIP location tool.

Port Scan
Mendeteksi port yang berada pada firewall.

Reverse IP Lookup
Temukan host web yang terintergrasi dengan alamat IP dengan reverse IP lookup.

INSTALL & UPDATE


1. Download

# git clone https://github.com/Manisso/Crips.git
# cd Crips && python Crips.py

2. Install and Upate (pilih 0)

0 : INSTALL & UPDATE

3. Congratulation Crips is Installed !

Referensi

https://www.kitploit.com/2017/12/crips-ip-tools-to-quickly-get.html
https://github.com/Manisso/Crips



XAttacker - Website Vulnerability Scanner & Auto Exploiter


XAttacker adalah sebuah Website Vulnerability Scanner & Auto Exploiter buatan Mohamed Riahi.

Intallasi


# git clone https://github.com/Moham3dRiahi/XAttacker.git

Fitur-Fitur


[1] WordPress :
  • Adblock Blocker
  • WP All Import
  • Blaze
  • Catpro
  • Cherry Plugin
  • Download Manager
  • Formcraft
  • levoslideshow
  • Power Zoomer
  • Gravity Forms
  • Revslider Upload Shell
  • Revslider Dafece Ajax
  • Revslider Get Config
  • Showbiz
  • Simple Ads Manager
  • Slide Show Pro
  • WP Mobile Detector
  • Wysija
  • InBoundio Marketing
  • dzs-zoomsounds
  • Reflex Gallery
  • Creative Contact Form
  • Work The Flow File Upload
  • WP Job Manger
  • PHP Event Calendar
  • Synoptic
  • Wp Shop
  • Content Injection

[2] Joomla
  • Com Jce
  • Com Media
  • Com Jdownloads
  • Com Fabrik
  • Com Jdownloads Index
  • Com Foxcontact
  • Com Ads Manager
  • Com Blog
  • Com Users
  • Com Weblinks
  • mod_simplefileupload

[3] DruPal
  • Add Admin

[4] PrestaShop
  • columnadverts
  • soopamobile
  • soopabanners
  • Vtermslideshow
  • simpleslideshow
  • productpageadverts
  • homepageadvertise
  • homepageadvertise2
  • jro_homepageadvertise
  • attributewizardpro
  • 1attributewizardpro
  • AttributewizardproOLD
  • attributewizardpro_x
  • advancedslider
  • cartabandonmentpro
  • cartabandonmentproOld
  • videostab
  • wg24themeadministration
  • fieldvmegamenu
  • wdoptionpanel
  • pk_flexmenu
  • pk_vertflexmenu
  • nvn_export_orders
  • megamenu
  • tdpsthemeoptionpanel
  • psmodthemeoptionpanel
  • masseditproduct

[5] Lokomedia
  • SQL injection

Video




Contoh Penggunaan


1. Jika sudah memiliki daftar website kalian bisa menjalankan tool ini dengan perintah :

# perl XAttacker.pl -l list.txt

list.txt = berisi daftar websites

2. Jika kalian hanya ingin melakukanya pada 1 website saja bisa dengan perintah :

# perl XAttacker.pl

3. Jika ingin memberi warna pada baris yang berbeda tambahkan script ini di file XAttacker.pl.

use Win32::Console::ANSI;


Referensi


https://www.kitploit.com/2017/12/xattacker-website-vulnerability-scanner.html
https://github.com/Moham3dRiahi/XAttacker