Posts

Missing spf record

Hey friends how are you hope you are doing well. Today we are discussing about really interesting topic that is missing spf record in simple way how you can send Gmail from website Gmail to anyone. This kind of vulnerabilities are very useful in social engineering. This website are very easy to exploit want to know how to find and exploit this vulnerabilities  do follow the following steps : First you have to check whether website have a Valid SPF record or not . For checking SPF record do visit this website : https://www.dmarcanalyzer.com/spf/checker/ Once you found website with no valid SPF record You have to use any fake mailer service to send Gmail from target website to the victim . And boom you are successfully exploited this vulnerabilitie. If you have any doubts do watch this video : https://youtu.be/BSZGkpAZXaI And also don't forget to follow us on Instagram and GitHub and do like our content on Instagram: https://instagram.com/__pytools__ https://GitHub.com/pytools786

Parameter tampering

  Hey guys how are you hope you are doing well. Today we are discussing about really interesting topic that is Parameter tampering. When you hear about website hacking you might be thinking about how hacker's alter the price of products and many more questions you are might be thinking about. So don't worry I am going to explain you everything pls do read this article completely . As name implies tampering the parameter is called Parameter tampering .   Parameter tampering is a simple attack targeting the application business logic. This attack takes advantage of the fact that many programmers rely on hidden or fixed fields (such as a hidden tag in a form or a parameter in a URL) as the only security measure for certain operations. Attackers can easily modify these parameters to bypass the security mechanisms that rely on them. Want to know how to exploit this vulnerabilitie do watch this video: https://youtu.be/9KmzSk5O8U8 And also don't forget to follow us on Instagram an...

Scanning

Hey friends, how are you today we are going to discuss about scanning so let's get started. After gathering information about target website next step is to scan the website for the vulnerability.  In this article we are Going to scan the website using tool called rapid scan Rapid scan is Multi-Tool Web Vulnerability Scanner. Rapid scan automatically runs multiple tools such as nikto, dnsscan, wafw00f, and fierce against the host. It currently supports 80 vulnerability tests. In this recipe, we will learn the usage of RapidScan to save time and automate vulnerability discovery. This tool is open source and available on GitHub at the link: https://github.com/skavngr/rapidscan After cloning the given tool change the directory at location of tool and then type the following command: python rapidscan.py http://example.com And then hit enter after sometime the tool will list all the Vulnerability. That's all for today's guys and don't forget to follow us on Instagram and Git...

INFORMATION GATHERING

Hey guys how are you today we are going to discuss about information gathering.   Information gathering is the first step of Ethical Hacking, where the penetration tester or even hackers gather information on their target victims. To increase your chances of a “successful” hacking . Back to website hacking, there are three approaches that one can take when planning to perform a hack on a website/web app. These approaches include:- Server-side Attack Client-side Attack Web Application Pen testing . As mentioned earlier, every attack begins with information gathering. There is a couple of information that one can gather during the process. These include but are not limited to: 1] Victim IP addresses 2] Domain Name Information 3] Technologies used by the website/web applications 4] Other websites on the same server DNS records This information could help you perform a successful hack on a website/ web app. In this article, I will be showing you how to use some tools to gather informat...

Hunting down social media accounts with beef-xss

  Hey guys how are you today I am going to tell you another way of hunting social media accounts, that's is by using beef-xss. Want to know what is beef-xss do visit this article: https://pytools786.blogspot.com/2021/03/hack-windows-10-using-link.html This way is pretty much similar as phishing but this way gives us remote control on the browser so we can do lots of cool things with this method and it is less suspicious as compare to phishing because we are going to embed our beef Payload into website. Want to know how to hunt social media accounts using beef-xss pls do watch this video: https://youtu.be/HIYcqZqqpS4 Also don't forget to follow us on Instagram and GitHub and do like our content on Instagram: https://instagram.com/__pytools__ https://GitHub.com/pytools786

Recovering all the saved passwords from target system using lazagne

  Hey friends how are you hope you are doing well. Today I am going to tell you how you can recover all the saved passwords from target system with the help of tool called lazange . The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext, APIs, custom algorithms, databases, etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software Basically lazange is a post exploitation tool, but with the help of simple python script we can used it directly without actually gaining the access over victim. Want to how to used lazange with python script pls do watch this video: https://youtu.be/rAgaIokaufA That's all for today Thx guy's Also don't forget to follow us on Instagram and GitHub and do like our content on Instagram: http://instagram.com/__pytools__ https://github.com/Pytools786/

Hunting social media accounts with phishing

Hey friends how are you, Today I am going to tell you most popular and comman way to hack any social media account. And that is phishing Phishing is a cyber attack that uses disguised email as a weapon. The goal is to trick the email recipient into believing that the message is something they want or need — a request from their bank, for instance, or a note from someone in their company — and to click a link or download an attachment. You can generate your own phishing pages or phishing website with the help of tools like socialfish and SEToolkit. Want to know how to generate phishing pages using socialfish and SEToolkit pls do watch this video's: https://youtu.be/u9dBGWVwMMA https://youtu.be/Jjulz-xHwEo That's all for today's . Thx  Also don't forget to follow us on Instagram and GitHub and do like our content on Instagram: http://instagram.com/__pytools__ https://github.com/Pytools786/