Posts

Djangohunter - Tool Designed To Attention Pose Incorrectly Configured Django Applications That Are Exposing Sensitive Information

Image
Tool designed to attention position incorrectly configured Django applications that are exposing sensitive information. https://www.reddit.com/r/django/comments/87qcf4/28165_thousand_django_running_servers_are_exposed/ https://twitter.com/6ix7ine/status/978598496658960384?lang=en Usage Usage: python3 djangohunter.py --key {shodan} Dorks: 'DisallowedHost', 'KeyError', 'OperationalError', 'Page non industrial plant life at /' Requirements Shodan Pyfiglet Requests BeautifulSoup pip -r install requirements Demo Disclaimer Code samples are provided for educational purposes. Adequate defenses tin move solely survive built yesteryear researching assail techniques available to malicious actors. Using this code against target systems without prior permission is illegal inwards almost jurisdictions. The authors are non liable for whatever damages from misuse of this information or code. Download Djangohunter

Novahot - A Webshell Framework For Penetration Testers

Image
novahot is a webshell framework for penetration testers. It implements a JSON-based API that tin communicate alongside trojans written inwards whatsoever language. By default, it ships alongside trojans written inwards PHP, ruby, together with python. Beyond executing organization commands, novahot is able to emulate interactive terminals, including mysql , sqlite3 , together with psql . It additionally implements "virtual commands" that cash inwards one's chips inwards possible to upload, download, edit, together with thought remote files locallly using your preferred applications. Installation Install the executable require from npm: [sudo] npm install -g novahot Then seed a config file: novahot config > /.novahotrc Usage View the available trojans alongside novahot trojan list . Select a trojan inwards a linguistic communication that is appropriate for your target, therefore re-create its source to a novel file. (Ex: novahot trojan though...

Hackertarget - Tools As Well As Network Word To Help Organizations Alongside Ready On Surface Discovery

Image
Use opened upwards source tools as well as network intelligence to attention organizations alongside assail surface discovery as well as identification of safety vulnerabilities. Identification of an organizations vulnerabilities is an impossible chore without tactical word on the network footprint. By combining opened upwards source word alongside the worlds best opened upwards source safety scanning tools, nosotros enable your assail surface discovery. With the mightiness for Internet assets to hold out deployed inward seconds, the assail surface is to a greater extent than dynamic as well as e'er growing. This real fact makes mapping your external network footprint a difficult problem. We aim to supply solutions to solve this problem. Start alongside our tools for domain as well as IP address data, as well as therefore pin to mapping the exposure alongside hosted opened upwards source scanners. We accept developed a linux final tool using python programming linguistic ...

Dirhunt V0.6.0 - Uncovering Spider Web Directories Without Bruteforce

Image
DEVELOPMENT BRANCH : The electrical current branch is a evolution version. Go to the stable issue past times clicking on the principal branch . Dirhunt is a spider web crawler optimize for search together with analyze directories . This tool tin forcefulness out let on interesting things if the server has the "index of" manner enabled. Dirhunt is also useful if the directory listing is non enabled. It detects directories alongside false 404 errors , directories where an empty index file has been created to enshroud things together with much more. $ dirhunt http://website.com/ Dirhunt does non operate beast force. But neither is it only a crawler . This tool is faster than others because it minimizes requests to the server. Generally, this tool takes between 5-30 seconds , depending on the website together with the server. Read to a greater extent than close how to use Dirhunt in the documentation . Features Process one or multiple sites at a time. P...

Webmap - Nmap Spider Web Dashboard Together With Reporting

Image
Influenza A virus subtype H5N1 Web Dashbord for Nmap XML Report Usage You should role this alongside docker, merely past times sending this command: $ mkdir /tmp/webmap $ docker run -d \ --name webmap \ -h webmap \ -p 8000:8000 \ -v /tmp/webmap:/opt/xml \ rev3rse/webmap $ # right away y'all tin run Nmap in addition to relieve the XML Report on /tmp/webmap $ nmap -sT -A -T4 -oX /tmp/webmap/myscan.xml 192.168.1.0/24 Now request your browser to http://localhost:8000 Quick in addition to Dirty $ roll -sL http://bit.ly/webmapsetup | bash Upgrade from previous release $ # halt running webmap container $ docker halt webmap $ # take away webmap container $ docker rm webmap $ # push clitoris novel ikon from dockerhub $ docker push clitoris rev3rse/webmap $ # run WebMap $ roll -sL http://bit.ly/webmapsetup | bash Run without Docker This projection is designed to run on a Docker container. IMHO it isn't a ade...