CRLFMap – A Tool To Find HTTP Splitting Vulnerabilities

KitPloit - PenTest Tools!-- CRLFMap is a tool to find HTTP Splitting vulnerabilitiesWhy? I wanted to write a tool in Golang for concurrency I wanted to be able to fuzz both parameters and paths Installation go get github.com/ryandamour/crlfmap Help Available Commands: help Help about any command scan A scanner for all your CRLF needsFlags: -h, … Continue reading CRLFMap – A Tool To Find HTTP Splitting Vulnerabilities

U.S. Treasury Sanctions Hacking Group Backed by Iranian Intelligence

The Hacker News-- The U.S. government on Thursday imposed sweeping sanctions against an Iranian threat actor backed by the country's Ministry of Intelligence and Security (MOIS) for carrying out malware campaigns targeting Iranian dissidents, journalists, and international companies in the telecom and travel sectors. According to the U.S. Treasury and the Federal Bureau of Investigation (FBI), the … Continue reading U.S. Treasury Sanctions Hacking Group Backed by Iranian Intelligence

Android 11 — 5 New Security and Privacy Features You Need to Know

The Hacker News-- After a long wait and months of beta testing, Google last week finally released Android 11, the latest version of the Android mobile operating system—with features offering billions of its users more control over their data security and privacy. Android security is always a hot topic and almost always for the wrong … Continue reading Android 11 — 5 New Security and Privacy Features You Need to Know

Zin – A Payload Injector For Bugbounties Written In Go

KitPloit - PenTest Tools!-- A Payload Injector for bugbounties written in go Features Inject multiple payloads into all parameters Inject single payloads into all parameters Saves responses into output folder Displays Status Code & Response Length Can grep for patterns in the response Really fast Easy to setup Install $ go get -u github.com/ethicalhackingplayground/Zin New … Continue reading Zin – A Payload Injector For Bugbounties Written In Go

Charities and the advertising industry: data ecosystems and privacy risks

Malwarebytes Labs-- Data makes the world go round, more often than not via advertising and its tracking mechanisms. Whether you think making money from large volumes of PII to keep the web ticking over is a good thing, or a sleazy data-grab often encouraging terrible ad practices, it’s not going to go away anytime soon. … Continue reading Charities and the advertising industry: data ecosystems and privacy risks

Zenscrape: A Simple Web Scraping Solution for Penetration Testers

The Hacker News-- Did you ever try extracting any information from any website? Well, if you have then you have surely enacted web scraping functions without even knowing it! To put in simpler terms, Web scraping, or also known as web data extraction, is the process of recouping or sweeping data from web-pages. It is … Continue reading Zenscrape: A Simple Web Scraping Solution for Penetration Testers

dorkX – Pipe Different Tools With Google Dork Scanner

KitPloit - PenTest Tools!-- Pipe different tools with google dork Scanner Install zoid@MSI ~/dorkX> git clone https://github.com/ethicalhackingplayground/dorkX zoid@MSI ~/dorkX> cd dorkX zoid@MSI ~/dorkX> go build dorkx.go zoid@MSI ~/dorkX> go build corsx.go zoid@MSI ~/dorkX> go build csrfx.go zoid@MSI ~/dorkX> go build zin.go Usage: Blind XSS zoid@MSI ~/dorkX> ./dorkX -dorks dorks.txt -concurrency 100 | dalfox pipe -b … Continue reading dorkX – Pipe Different Tools With Google Dork Scanner