Posts

Showing posts with the label Exploits

Webmap - Nmap Spider Web Dashboard Together With Reporting

Image
Influenza A virus subtype H5N1 Web Dashbord for Nmap XML Report Usage You should role this alongside docker, merely past times sending this command: $ mkdir /tmp/webmap $ docker run -d \ --name webmap \ -h webmap \ -p 8000:8000 \ -v /tmp/webmap:/opt/xml \ rev3rse/webmap $ # right away y'all tin run Nmap in addition to relieve the XML Report on /tmp/webmap $ nmap -sT -A -T4 -oX /tmp/webmap/myscan.xml 192.168.1.0/24 Now request your browser to http://localhost:8000 Quick in addition to Dirty $ roll -sL http://bit.ly/webmapsetup | bash Upgrade from previous release $ # halt running webmap container $ docker halt webmap $ # take away webmap container $ docker rm webmap $ # push clitoris novel ikon from dockerhub $ docker push clitoris rev3rse/webmap $ # run WebMap $ roll -sL http://bit.ly/webmapsetup | bash Run without Docker This projection is designed to run on a Docker container. IMHO it isn't a ade...

Infection Monkey V1.6 - An Automated Pentest Tool

Image
The Infection Monkey is an opened upward source safety tool for testing a information center's resiliency to perimeter breaches in addition to internal server infection. The Monkey uses diverse methods to self-propagate across a information oculus in addition to reports success to a centralized Monkey Island server. The Infection Monkey is comprised of 2 parts: Monkey - H5N1 tool which infects other machines in addition to propagates to them Monkey Island - H5N1 dedicated server to command in addition to visualize the Infection Monkey's progress within the information center To read to a greater extent than almost the Monkey, see http://infectionmonkey.com Main Features The Infection Monkey uses the next techniques in addition to exploits to propagate to other machines. Multiple propagation techniques: Predefined passwords Common logical exploits Password stealing using Mimikatz Multiple exploit methods: SSH SMB RDP WMI Shellshock Conficker Sam...

Mec V1.4.0 - Majority Exploit Console

Image
massExploitConsole a collection of hacking tools alongside a cli ui. Disclaimer please role this tool exclusively on authorized systems , im non responsible for whatsoever harm caused past times users who ignore my warning exploits are adapted from other sources, delight refer to their writer info please note, due to my express programming sense (it's my kickoff Python project), you lot tin facial expression or hence light-headed bugs Features an easy-to-use cli ui execute whatsoever adpated exploits alongside process-level concurrency some built-in exploits (automated) hide your ip addr using proxychains4 in addition to ss-proxy (built-in) zoomeye host scan (10 threads) a elementary baidu crawler (multi-threaded) censys host scan Getting started git clone https://github.com/jm33-m0/massExpConsole.git && cd massExpConsole && ./install.py when installing pypi deps, apt-get install libncurses5-dev (for Debian-based distros) mightin...

Rootos - Macos Origin Helper

Image
Tries to purpose diverse CVEs to hit sudo or root access. All exploits accept an halt destination of adding ALL ALL=(ALL) NOPASSWD: ALL to /etc/sudoers allowing whatever user to hold out sudo commands. Exploits CVE-2008-2830 CVE-2015-3760 CVE-2015-5889 CVE-2017-13872 AppleScript Dynamic Phishing Sudo Piggyback Link Run python root.py Download rootOS

Mad-Metasploit - Metasploit Custom Modules, Plugins & Resources Scripts

Image
Metasploit custom modules, plugins, resources script and.. awesome metasploit collection https://www.hahwul.com/p/mad-metasploit.html Awesome opened upwards awesome.md Add mad-metasploit to metasploit framework config your metasploit-framework directory $ vim config/config.rb $metasploit_path = '/opt/metasploit-framework/embedded/framework/' # /usr/share/metasploit-framework 2-A. Interactive Mode $ ./mad-metasploit 2-B. Commandline Mode(preset all) $ ./mad-metasploit [-a/-y/--all/--yes] Use custom modules search auxiliary/exploits, other.. HAHWUL > search springboot Matching Modules ================ Name Disclosure Date Rank Check Description ---- --------------- ---- ----- ----------- auxiliary/mad_metasploit/springboot_actuator normal No Springboot actuator cheque Use custom plugins charge mad-metaspl...

Ffm (Freedom Fighting Mode) - Opened Upward Rootage Hacking Harness

Image
FFM is a hacking harness that y'all tin occupation during the post-exploitation stage of a red-teaming engagement. The see of the tool was derived from a 2007 conference from @thegrugq. It was presented at SSTIC 2018 as well as the accompanying slide deck is available at this url . If you're non familiar amongst this flat of tools, it is strongly advised to conduct maintain a seem at them to empathise what a hacking harness' role is. All the comments are included inwards the slides. Usage The goal of a hacking harness is to deed equally a helper that automates mutual tasks during the post-exploitation phase, but also safeguards the user against mistakes they may make. It is an instrumentation of the shell. Run ./ffm.py to activate it as well as y'all tin start working immediately. There are 2 commands y'all demand to know about: Type !list to display the commands provided past times the harness. Type SHIFT+TAB to perform tab completion on the loca...

Isf - Industrial Command Arrangement Exploitation Framework

Image
ISF(Industrial Exploitation Framework) is a exploitation framework based on Python, it's similar to metasploit framework. ISF is based on opened upwards source projection routersploit . Read this inward other languages: English , 简体中文 , ICS Protocol Clients Name Path Description modbus_tcp_client icssploit/clients/modbus_tcp_client.py Modbus-TCP Client wdb2_client icssploit/clients/wdb2_client.py WdbRPC Version two Client(Vxworks 6.x) s7_client icssploit/clients/s7_client.py s7comm Client(S7 300/400 PLC) Exploit Module Name Path Description s7_300_400_plc_control exploits/plcs/siemens/s7_300_400_plc_control.py S7-300/400 PLC start/stop s7_1200_plc_control exploits/plcs/siemens/s7_1200_plc_control.py S7-1200 PLC start/stop/reset vxworks_rpc_dos exploits/plcs/vxworks/vxworks_rpc_dos.py Vxworks RPC remote dos(CVE-2015-7599) quantum_140_plc_control exploits/plcs/schneider/quantum_140_plc_control....