[Pntst] [https://t.me/pntsts/2500] | 21.09.2020 14:08:15: I've never come across that at all. Only test ones... We're dumping different databases. [Pntst] [https://t.me/pntsts/2496] | 21.09.2020 14:06:54: + because the latest users have identical passwords [Pntst] [https://t.me/pntsts/2446] | 18.09.2020 16:09:06: The main thing is that it's not group ib ))) [Pntst] [https://t.me/pntsts/2445] | 18.09.2020 16:08:42: Congratulations! [Pntst] [https://t.me/pntsts/2026] | 04.09.2020 11:53:46: Looks like it, actually [Pntst] [https://t.me/pntsts/2022] | 04.09.2020 11:52:14: It seems the parameter was set... [Pntst] [https://t.me/pntsts/2021] | 04.09.2020 11:51:51: I think map looks for asterisks first... and asks if it should inject there. But I could be wrong. [Pntst] [https://t.me/pntsts/2011] | 04.09.2020 11:49:09: Turnstile at the entrance [Pntst] [https://t.me/pntsts/2009] | 04.09.2020 11:48:35: )))))))))))) [Pntst] [https://t.me/pntsts/2006] | 04.09.2020 11:47:19: Hello, please type cmd.exe [Pntst] [https://t.me/pntsts/1997] | 04.09.2020 11:45:16: Scatter flash drives near offices [Pntst] [https://t.me/pntsts/1994] | 04.09.2020 11:44:52: I think it'll work ) but not with Acunetix or sqlmap. Need to send viruses to corporate email addresses [Pntst] [https://t.me/pntsts/1962] | 04.09.2020 11:26:26: Dbms [Pntst] [https://t.me/pntsts/1956] | 04.09.2020 11:24:29: No [Pntst] [https://t.me/pntsts/1951] | 04.09.2020 11:23:25: [Image] [Pntst] [https://t.me/pntsts/1946] | 04.09.2020 11:22:03: Need to see which request actually causes this error; it can't connect [Pntst] [https://t.me/pntsts/1936] | 04.09.2020 11:20:55: I’d shove a gem like that—where MySQL is actually showing through—into the scanner [Pntst] [https://t.me/pntsts/1932] | 04.09.2020 11:19:57: The site is broken and can't connect to MySQL [Pntst] [https://t.me/pntsts/1929] | 04.09.2020 11:18:59: Maybe if we tweak something, the right response will pop up [Pntst] [https://t.me/pntsts/1928] | 04.09.2020 11:18:44: It is hitting the database, but the response... is pretty meh—nothing impressive [Pntst] [https://t.me/pntsts/1927] | 04.09.2020 11:17:56: Can't connect to MySQL server [Pntst] [https://t.me/pntsts/1922] | 04.09.2020 11:16:21: Handing in our homework logins and passwords [Pntst] [https://t.me/pntsts/1921] | 04.09.2020 11:16:12: )))) [Pntst] [https://t.me/pntsts/1918] | 04.09.2020 11:15:24: Pick a tamper script for kremlin.ru? ) [Pntst] [https://t.me/pntsts/1905] | 04.09.2020 11:10:21: https://hackware.ru/?p=1928 [Pntst] [https://t.me/pntsts/1723] | 04.09.2020 09:58:21: Yes [Pntst] [https://t.me/pntsts/1598] | 03.09.2020 15:37:02: well, that obviously won't happen... but where do such ideas come from in those wild little heads? [Pntst] [https://t.me/pntsts/1597] | 03.09.2020 15:36:36: [Web link] [Pntst] [https://t.me/pntsts/1537] | 03.09.2020 12:40:42: not surprised. the Japanese are crazy [Pntst] [https://t.me/pntsts/1536] | 03.09.2020 12:40:17: -_- in that case, I see one option: sending a map there via a POST method [Pntst] [https://t.me/pntsts/1533] | 03.09.2020 12:39:05: you'd go crazy trying to insert all those quotes by hand [Pntst] [https://t.me/pntsts/1532] | 03.09.2020 12:38:51: Burp? [Pntst] [https://t.me/pntsts/1530] | 03.09.2020 12:38:32: if it's not a secret [Pntst] [https://t.me/pntsts/1529] | 03.09.2020 12:38:26: and how did you get in there [Pntst] [https://t.me/pntsts/1524] | 03.09.2020 12:32:54: ))) [Pntst] [https://t.me/pntsts/1522] | 03.09.2020 12:32:09: [Web link] [Pntst] [https://t.me/pntsts/1521] | 03.09.2020 12:30:40: this thing is pure evil (or good, really)—it doesn't even respond to scanners; maybe try changing the user agents... [Pntst] [https://t.me/pntsts/1518] | 03.09.2020 12:29:30: Host? Or do such shenanigans not fly here... [Pntst] [https://t.me/pntsts/1517] | 03.09.2020 12:28:49: how do you scan it? 0_О [Pntst] [https://t.me/pntsts/1516] | 03.09.2020 12:28:41: I'm shocked [Pntst] [https://t.me/pntsts/1514] | 03.09.2020 12:28:32: [Web link] [Pntst] [https://t.me/pntsts/1513] | 03.09.2020 12:27:47: Sparker just throws an error and crashes... never seen anything like it. [Pntst] [https://t.me/pntsts/1512] | 03.09.2020 12:27:19: Does Akamai protect against scanning? No scanner can pick it up... Site is unreachable... [Pntst] [https://t.me/pntsts/1464] | 27.08.2020 22:36:48: Chardetect says it's ASCII :))) Teacher knew that from the start :)) [Pntst] [https://t.me/pntsts/1463] | 27.08.2020 22:18:49: [DEBUG] declared web page charset 'iso-8859-1' [DEBUG] declared web page charset 'utf-8' Two charsets, too... damn Japanese. [Pntst] [https://t.me/pntsts/1462] | 27.08.2020 22:02:43: [Web link] [Pntst] [https://t.me/pntsts/1461] | 27.08.2020 22:01:09: Anyway, on Kali, map told me "invalid character" once, but then apparently changed its mind and started spitting out hieroglyphs. BUT SO SLOWLY. I've never seen such a sluggish SQLi in my life. Need to fire up v5 and think. [Pntst] [https://t.me/pntsts/1460] | 27.08.2020 20:04:25: It's a bit different here; there is a solution method, but Stamparm himself says to run it on Linux... ( [Pntst] [https://t.me/pntsts/1458] | 27.08.2020 18:26:49: With hex, the DBs would dump in a way that made them unopenable, but maybe it'll help now with the tables [Pntst] [https://t.me/pntsts/1453] | 27.08.2020 18:22:01: having to open the laptop, press the power button—what a nightmare [Pntst] [https://t.me/pntsts/1451] | 27.08.2020 18:21:23: Or it's honestly easier to just boot up Linux already)))) [Pntst] [https://t.me/pntsts/1446] | 27.08.2020 18:21:16: Hex\ncalling all tamperers? [Pntst] [https://t.me/pntsts/1449] | 27.08.2020 18:20:54: [WARNING] cannot properly display (some) Unicode characters inside your terminal ('cp866') environment. All unhandled occurrences will result in replacement with '?' character. Please, find proper character representation inside corresponding output files nasty garbled characters —-> ???? [Pntst] [https://t.me/pntsts/1447] | 27.08.2020 16:21:25: saw it, thanks. I wouldn't say no to a couple of accounts [Pntst] [https://t.me/pntsts/1444] | 27.08.2020 15:05:58: I'd like to express my gratitude to Comrade Teacher @Pentest_IT for helping me get that nasty SQLi exploit running. By the way, Union is available there too now, so no need to suffer. Also, I wanted to ask the rest of you: what VPN do you use besides Nord? It's been really disappointing me lately—I had to install some wild thing called Time-Sec. [Pntst] [https://t.me/pntsts/1438] | 27.08.2020 09:51:05: Definitely, though I need to get some sleep first ) [Pntst] [https://t.me/pntsts/1436] | 27.08.2020 09:48:49: Sparker outputted it in his mini-exploit, so there is an SQLi [Pntst] [https://t.me/pntsts/1435] | 27.08.2020 09:48:07: Acunetix and Sparker [Pntst] [https://t.me/pntsts/1433] | 27.08.2020 09:47:11: Or maybe it's some kind of WAF that's filtering... [Pntst] [https://t.me/pntsts/1431] | 27.08.2020 09:46:39: From Windows; maybe there won't be such issues on Kali [Pntst] [https://t.me/pntsts/1429] | 27.08.2020 03:27:58: Telegram displayed it correctly here... [Pntst] [https://t.me/pntsts/1428] | 27.08.2020 03:27:50: -p "ロクインID" [Pntst] [https://t.me/pntsts/1427] | 27.08.2020 03:27:20: [CRITICAL] all testable parameters you provided are not present within the given request data It's not accepting the command directly from Sparker [Pntst] [https://t.me/pntsts/1426] | 27.08.2020 03:18:32: And Windows suggests saving the text file in Unicode... Oh, those Asians. [Pntst] [https://t.me/pntsts/1425] | 27.08.2020 03:17:16: Sparker just shoved the data into UTF-8 for sqlmap. [Pntst] [https://t.me/pntsts/1424] | 27.08.2020 03:15:44: Has anyone run into this? What else can I try, or is something redundant? With the first two SQLi cases, sqlmap just suggested a 302 redirect. Now an SQLi has popped up with actual proof, and the response is large—a substantial one. [Pntst] [https://t.me/pntsts/1423] | 27.08.2020 03:14:53: Asian-style encoding issues: UTF-8 + sqlmap mistakes it for a WAF—I'm running it with `encode utf-8` and `--tamper=overlongutf8more`. [Pntst] [https://t.me/pntsts/1422] | 27.08.2020 03:14:07: [Web link] [Pntst] [https://t.me/pntsts/1397] | 25.08.2020 12:38:08: Medium – yes – tomorrow. [Pntst] [https://t.me/pntsts/1393] | 24.08.2020 15:55:42: 0_o [Pntst] [https://t.me/pntsts/1392] | 24.08.2020 15:55:39: So, when is the training actually happening? [Pntst] [https://t.me/pntsts/1384] | 21.08.2020 13:17:33: I figured nothing is ever simple [Pntst] [https://t.me/pntsts/1383] | 21.08.2020 13:17:24: basically, you have to go through it both ways... [Pntst] [https://t.me/pntsts/1380] | 21.08.2020 13:16:05: I wonder if the map will leak stuff based purely on cookies... [Pntst] [https://t.me/pntsts/1379] | 21.08.2020 13:14:59: Authorization is actually a really interesting topic. How necessary is it? Of course, a lot is hidden behind logins, directories, fields, etc. But I was once thrown off by a case where I didn't find a vulnerability with authorization, but I did find one without it. [Pntst] [https://t.me/pntsts/1373] | 21.08.2020 13:10:31: I really need to finish configuring AppSpider... [Pntst] [https://t.me/pntsts/1372] | 21.08.2020 13:10:15: Maybe someone in the group will find this useful [Pntst] [https://t.me/pntsts/1370] | 21.08.2020 13:08:38: [Web link] [Pntst] [https://t.me/pntsts/1369] | 21.08.2020 13:04:55: sneaky corporations [Pntst] [https://t.me/pntsts/1368] | 21.08.2020 13:04:33: You have to egg the hackers on so there's a reason to sell the product later))) [Pntst] [https://t.me/pntsts/1367] | 21.08.2020 13:04:11: never knew that [Pntst] [https://t.me/pntsts/1366] | 21.08.2020 13:04:06: and it really is sponsored by Netsparker – cool. [Pntst] [https://t.me/pntsts/1363] | 21.08.2020 13:01:10: you have to modify Java classes there; I don't really get along with Java editors—I started a thread on BHF and XSS with all the keygens, license files, and the reverser's comments, but no one took it on. [Pntst] [https://t.me/pntsts/1361] | 21.08.2020 12:59:18: Regarding the news – https://www.invicti.com/#brands Netsparker and Acunetix are under the same roof now; looks like the former bought the latter [Pntst] [https://t.me/pntsts/1358] | 21.08.2020 12:55:43: Yeah, it is strange—why would they need two almost identical scanners? They must have given it some thought. [Pntst] [https://t.me/pntsts/1356] | 08/21/2020 12:54:39: [Web link] [Pntst] [https://t.me/pntsts/1355] | 08/21/2020 12:53:41: [Web link] [Pntst] [https://t.me/pntsts/1354] | 08/21/2020 12:53:10: [Web link] [Pntst] [https://t.me/pntsts/1353] | 08/21/2020 12:52:54: [Web link] [Pntst] [https://t.me/pntsts/1351] | 21.08.2020 12:51:42: Still apparently old school [Pntst] [https://t.me/pntsts/135] 0] | 21.08.2020 12:51:18: [Web link] [Pntst] [https://t.me/pntsts/1349] | 21.08.2020 12:50:52: I wonder how long it's been like that? I downloaded it just a month or month-and-a-half ago... maybe I'm getting Insight now too [Pntst] [https://t.me/pntsts/1348] | 21.08.2020 12:50:24: yeah [Pntst] [https://t.me/pntsts/1345] | 21.08.2020 12:49:08: keys are easy, sessions even get saved [Pntst] [https://t.me/pntsts/1344] | 21.08.2020 12:48:53: Got it, we'll save up [Pntst] [https://t.me/pntsts/1343] | 21.08.2020 12:48:45: 1. yeah, mine is called Rapid7 Security Console too; on their site, it's still called Nexpose [Pntst] [https://t.me/pntsts/1340] | 21.08.2020 12:29:39: Off-topic – anyone with experience in DDoS attacks against WAF-protected applications using stressers or botnets, please PM me [Pntst] [https://t.me/pntsts/1339] | 21.08.2020 12:25:10: The generator's author is Egyptian (apparently, some part of Meta has Egyptian roots too—though the author seems to be English, there's an "I love Egypt" inscription in the console); he knows his way around Python—we've chatted. They seem to love all kinds of malware, apparently) [Pntst] [https://t.me/pntsts/1338] | 21.08.2020 12:14:45: [Web link] [Pntst] [https://t.me/pntsts/1337] | 21.08.2020 12:14:35: There's also this piece of software for payloads; it bypasses many AVs—though I haven't actually tested it yet, nor have I tested it for file binding/joining. [Pntst] [https://t.me/pntsts/1336] | 21.08.2020 12:13:42: [Web link] [Pntst] [https://t.me/pntsts/1335] | 21.08.2020 12:08:46: There is a working crack for 6.6.28–29 (I managed to get it running eventually); for Meta, I only have the installer and a couple of old articles on how it used to be cracked. [Pntst] [https://t.me/pntsts/1334] | 21.08.2020 12:07:47: Thanks for the info. I might be repeating myself, but I'd still love to see an updatable crack for Nexpose and any version of Metasploit Pro. [Pntst] [https://t.me/pntsts/1292] | 15.08.2020 20:11:43: )))) [Pntst] [https://t.me/pntsts/1281] | 15.08.2020 20:04:10: Everything here is strictly for educational purposes. So it's all good. [Pntst] [https://t.me/pntsts/1280] | 15.08.2020 20:03:42: And often, behind the barbed wire, I dream of my Aerocool chair... [Pntst] [https://t.me/pntsts/1276] | 15.08.2020 20:02:54: My number is 245... a stamp on my padded jacket... [Pntst] [https://t.me/pntsts/1272] | 15.08.2020 20:01:32: Instant sentence buff [Pntst] [https://t.me/pntsts/1271] | 15.08.2020 20:01:24: Out of mercenary motives (and who dumps databases for free...) [Pntst] [https://t.me/pntsts/1270] | 15.08.2020 20:01:05: There's also a fun Part 2 [Pntst] [https://t.me/pntsts/1269] | 15.08.2020 20:01:00: Found it [Pntst] [https://t.me/pntsts/1267] | 15.08.2020 19:59:58: Ooo [Pntst] [https://t.me/pntsts/1266] | 15.08.2020 19:59:56: And what is the wording? [Pntst] [https://t.me/pntsts/1261] | 15.08.2020 19:59:09: I'm a breeding agronomist [Pntst] [https://t.me/pntsts/1257] | 15.08.2020 19:58:14: Sequel map — 100% [Pntst] [https://t.me/pntsts/1256] | 15.08.2020 19:58:07: Scanners get equated to them all the time [Pntst] [https://t.me/pntsts/1255] | 15.08.2020 19:58:00: Any malicious software [Pntst] [https://t.me/pntsts/1254] | 15.08.2020 19:57:52: Or 237... (Hope I don't mix it up with the sExual ones) [Pntst] [https://t.me/pntsts/1251] | 15.08.2020 19:57:10: Who's been caught yet? [Pntst] [https://t.me/pntsts/1249] | 15.08.2020 19:57:06: Let's talk about 273 instead [Pntst] [https://t.me/pntsts/1248] | 15.08.2020 19:56:43: Gr [Pntst] [https://t.me/pntsts/1247] | 15.08.2020 19:56:41: Just over 6 [Pntst] [https://t.me/pntsts/1245] | 15.08.2020 19:56:14: Article 228 Part 1—depending on the region, the judge, and your background—you can easily get up to 3 years [Pntst] [https://t.me/pntsts/1244] | 15.08.2020 19:55:50: Anyway, this isn't about Russia at all [Pntst] [https://t.me/pntsts/1243] | 15.08.2020 19:55:44: Distribution. Welcome to Parts 3 and 4 [Pntst] [https://t.me/pntsts/1242] | 15.08.2020 19:55:30: Starts at 6 years for Article 228 Part 1 [Pntst] [https://t.me/pntsts/1235] | 15.08.2020 19:52:31: Only in our CIS countries can you get 3+ years for absolutely nothing [Pntst] [https://t.me/pntsts/1234] | 15.08.2020 19:52:00: They have everything there—honey, THC, and CBD [Pntst] [https://t.me/pntsts/1232] | 15.08.2020 19:51:01: At the FDA office in Bangkok [Pntst] [https://t.me/pntsts/1231] | 15.08.2020 19:50:46: For some, a high; for others, medicine [Pntst] [https://t.me/pntsts/1230] | 15.08.2020 19:50:34: In Thailand, I saw it being prescribed for medicinal purposes to grandmothers and families with seriously ill children [Pntst] [https://t.me/pntsts/1226] | 15.08.2020 19:49:55: The admin's gonna show up any minute and ban us all (((( [Pntst] [https://t.me/pntsts/1218] | 15.08.2020 19:46:29: 😭 [Pntst] [https://t.me/pntsts/1217] | 15.08.2020 19:46:22: I haven't smoked for six months now ((( [Pntst] [https://t.me/pntsts/1215] | 15.08.2020 19:43:39: Thanks, but no thanks [Pntst] [https://t.me/pntsts/1214] | 15.08.2020 19:43:27: I posted the latest one on bhf [Pntst] [https://t.me/pntsts/1210] | 15.08.2020 19:42:47: I've never tried pulling the database manually via the browser. [Pntst] [https://t.me/pntsts/1209] | 15.08.2020 19:42:25: I think "no cast" serves a different purpose [Pntst] [https://t.me/pntsts/1208] | 15.08.2020 19:42:16: The map has its own payloads anyway. And only a tamper or hex editor can fix them [Pntst] [https://t.me/pntsts/1205] | 15.08.2020 19:41:13: You can do it with skip the little box, but it's also in the *wrong encoding* [Pntst] [https://t.me/pntsts/1204] | 15.08.2020 19:40:55: Screw it, we need solutions for people [Pntst] [https://t.me/pntsts/1201] | 15.08.2020 19:39:03: Sex ( [Pntst] [https://t.me/pntsts/1198] | 15.08.2020 19:36:19: That makes more sense now. And like, you just watch until the response hits... Honestly, it's easier to just shove the payload in using Burp Intruder. [Pntst] [https://t.me/pntsts/1192] | 15.08.2020 19:34:49: Not clear. Maybe an example when you have time? [Pntst] [https://t.me/pntsts/1191] | 15.08.2020 19:34:39: There are three versions on the new one too. [Pntst] [https://t.me/pntsts/1188] | 15.08.2020 19:33:20: Burp is clear, but what about HackBar for Firefox? [Pntst] [https://t.me/pntsts/1187] | 15.08.2020 19:33:00: Or maybe it's the encoding. [Pntst] [https://t.me/pntsts/1186] | 15.08.2020 19:32:44: Or "or", "and", or something else. [Pntst] [https://t.me/pntsts/1185] | 15.08.2020 19:32:34: And how do you tell manually in the browser that the quotes aren't working? [Pntst] [https://t.me/pntsts/1184] | 15.08.2020 19:32:19: Nah, nah, well... various Python tools/detectors are fine [Pntst] [https://t.me/pntsts/1154] | 15.08.2020 19:04:23: But thanks [Pntst] [https://t.me/pntsts/1153] | 15.08.2020 19:04:21: Even more confusing [Pntst] [https://t.me/pntsts/1151] | 15.08.2020 19:03:03: Don't get it [Pntst] [https://t.me/pntsts/1149] | 15.08.2020 19:02:42: Browser?) [Pntst] [https://t.me/pntsts/1148] | 15.08.2020 19:02:37: What should I open? [Pntst] [https://t.me/pntsts/1146] | 15.08.2020 18:59:32: Fellow experts [Pntst] [https://t.me/pntsts/1145] | 15.08.2020 18:59:20: Teach me how to manually check what's being filtered [Pntst] [https://t.me/pntsts/1094] | 06.08.2020 18:48:34: Thanks, but is changing the DNS actually necessary then? Do they work together somehow? Or can I just write the hosts and be done with it... [Pntst] [https://t.me/pntsts/1091] | 06.08.2020 18:27:24: apparently, just changing the DNS isn't enough to gain the WAF's trust [Pntst] [https://t.me/pntsts/1090] | 06.08.2020 18:27:08: [Web link] [Pntst] [https://t.me/pntsts/1089] | 06.08.2020 18:26:55: [File] [Pntst] [https://t.me/pntsts/1088] | 06.08.2020 18:26:27: Hey there [Pntst] [https://t.me/pntsts/1087] | 06.08.2020 18:26:21: I don't know how I'm staying on my feet ) sometimes wobbling, sometimes steady, but I'm trying to figure things out, basically [Pntst] [https://t.me/pntsts/1085] | 06.08.2020 00:07:14: or I need to dig into it—though sleeping would be better) [Pntst] [https://t.me/pntsts/1084] | 06.08.2020 00:06:14: and there's no proper lookup to blend in right away [Pntst] [https://t.me/pntsts/1083] | 05.08.2020 23:53:27: and it gets updated; it's not abandoned [Pntst] [https://t.me/pntsts/1080] | 05.08.2020 23:53:13: anyway, here's the utility I was looking for [Pntst] [https://t.me/pntsts/1079] | 05.08.2020 23:53:05: forgot [Pntst] [https://t.me/pntsts/1076] | 05.08.2020 23:52:52: [File] [Pntst] [https://t.me/pntsts/1075] | 05.08.2020 23:52:37: [Web link] [Pntst] [https://t.me/pntsts/1016] | 05.08.2020 23:25:43: 🙄 [Pntst] [https://t.me/pntsts/1014] | 05.08.2020 23:24:49: I want it in one click ) [Pntst] [https://t.me/pntsts/1013] | 05.08.2020 23:24:40: that's how we live((( STABILITY [Pntst] [https://t.me/pntsts/1010] | 05.08.2020 23:23:40: what a dreamer I am [Pntst] [https://t.me/pntsts/1009] | 05.08.2020 23:23:29: does anyone have some proven software like that to change DNS settings with a single click? preferably with DNS lookup too) [Pntst] [https://t.me/pntsts/1008] | 05.08.2020 23:22:26: [Web link] [Pntst] [https://t.me/pntsts/1006] | 05.08.2020 23:15:29: but that one has a really handy mini-GUI [Pntst] [https://t.me/pntsts/1005] | 05.08.2020 23:15:05: for some reason, I'm afraid of Guron's software. because of that crazy obfuscation—even the text-based utilities [Pntst] [https://t.me/pntsts/1004] | 05.08.2020 23:14:38: official [Pntst] [https://t.me/pntsts/1003] | 05.08.2020 23:14:29: C: cd C:\`````\sqlmap-master cls sqlmap.py --gui [Pntst] [https://t.me/pntsts/1000] | 05.08.2020 23:13:17: ..not necessarily [Pntst] [https://t.me/pntsts/999] | 05.08.2020 23:10:33: actually, I was wrong—they did something 4 months ago. Probably Python 3. [Pntst] [https://t.me/pntsts/997] | 05.08.2020 23:09:48: I've got a bunch of them too, haven't even run them yet. Curious about them as well. [Pntst] [https://t.me/pntsts/996] | 05.08.2020 23:09:28: NoSQL [tool] that hasn't been updated in a couple of years [Pntst] [https://t.me/pntsts/991] | 05.08.2020 23:08:05: I fired up Burp recently—did a race condition—felt like magic; need to work my way up to that level. First comes Metasploit, Nexpose, Nmap, Zmap, and a whole lot more ahead. [Pntst] [https://t.me/pntsts/988] | 05.08.2020 23:06:58: Wonder if this will help with painless scanning. Anyway, gotta master Cloud bypassing, since it's everywhere. [Pntst] [https://t.me/pntsts/986] | 05.08.2020 23:06:26: Can't do it that way—gotta go through the pain. [Pntst] [https://t.me/pntsts/985] | 05.08.2020 23:06:05: [Web link] [Pntst] [https://t.me/pntsts/982] | 05.08.2020 23:04:26: only in my dreams, maybe) [Pntst] [https://t.me/pntsts/981] | 05.08.2020 23:04:15: and another really interesting topic involves tokens and the cloud zone—specifically for getting Netsparker to play nice with the WAF; there are scrapers for this data on GitHub [Pntst] [https://t.me/pntsts/976] | 05.08.2020 23:03:19: alright, that’s a long story, and I need to get some sleep at least once in a while—I imagine that’s covered in detail during the training we'll look into it [Pntst] [https://t.me/pntsts/975] | 05.08.2020 23:02:39: picked one of these at random [Pntst] [https://t.me/pntsts/974] | 05.08.2020 23:02:33: [Web link] [Pntst] [https://t.me/pntsts/971] | 05.08.2020 23:01:45: nope [Pntst] [https://t.me/pntsts/969] | 05.08.2020 23:01:31: did you set a bad DNS? [Pntst] [https://t.me/pntsts/968] | 05.08.2020 23:01:20: Quick question: I found the IP behind Cloudflare – set the DNS in NordVPN – direct IP not allowed – what do I do now? [Pntst] [https://t.me/pntsts/961] | 05.08.2020 22:59:53: let's get some more details on that, please [Pntst] [https://t.me/pntsts/959] | 05.08.2020 22:59:37: then it takes a long time to treat the fractures( [Pntst] [https://t.me/pntsts/955] | 05.08.2020 22:59:08: 😃😃😃 [Pntst] [https://t.me/pntsts/951] | 05.08.2020 22:58:04: Did they find [him] via IP? A friendly request to the ISP? [Pntst] [https://t.me/pntsts/950] | 05.08.2020 22:57:47: 😳 [Pntst] [https://t.me/pntsts/948] | 05.08.2020 22:56:32: blue team blue team [Pntst] [https://t.me/pntsts/946] | 05.08.2020 22:56:20: I JUST PNTST-ED! [Pntst] [https://t.me/pntsts/944] | 05.08.2020 22:55:48: spun it up first, then took a look. ((( [Pntst] [https://t.me/pntsts/943] | 05.08.2020 22:55:19: I once foolishly helped spin up a crappy bank—Quick—and didn't sleep well afterwards [Pntst] [https://t.me/pntsts/892] | 05.08.2020 19:35:45: I tried more than once to uncheck boxes in the default XML config and change the scan speed—but it still... ...it stays at default (. So, a Python guy then))) [Pntst] [https://t.me/pntsts/890] | 05.08.2020 19:34:30: so a reverse engineer will be found [Pntst] [https://t.me/pntsts/888] | 05.08.2020 19:33:56: I had a Sibka once = I've never encountered anything worse than that piece of crap, sorry to say) [Pntst] [https://t.me/pntsts/867] | 05.08.2020 19:10:06: because time is money, after all [Pntst] [https://t.me/pntsts/866] | 05.08.2020 19:09:27: Having to go into the web interface every time is a total nightmare—unchecking those boxes, dragging the bar around... I dream of a tool that simplifies all that; if I could also hook up a remote server with a different localhost... well, I don't know, what else could a person want? [Pntst] [https://t.me/pntsts/865] | 05.08.2020 19:07:23: [Web link] [Pntst] [https://t.me/pntsts/753] | 27.07.2020 20:51:46: need to enable -v and take a look [Pntst] [https://t.me/pntsts/751] | 27.07.2020 20:51:32: 403 - forbidden, reasons unknown [Pntst] [https://t.me/pntsts/748] | 27.07.2020 20:50:59: Pyatikhatki — it crashed, or the connection is bad [Pntst] [https://t.me/pntsts/718] | 27.07.2020 20:24:47: I'm a total boomer [Pntst] [https://t.me/pntsts/717] | 27.07.2020 20:24:41: Sure ) [Pntst] [https://t.me/pntsts/715] | 27.07.2020 20:23:33: You write it in data or headers (if that's where it goes) — but sqlmap starts cycling through everything anyway, instead of targeting it precisely [Pntst] [https://t.me/pntsts/713] | 27.07.2020 20:22:07: That question has been on my mind for a long time too. I know you can define payloads in sqlmap's payload files. You can use suffix, prefix, string... and so on. But I'd really love to see a real-world example of how to take a working "true" payload value from Burp or Spider and hit the jackpot in one go (which also reduces the risk of triggering the WAF)... [Pntst] [https://t.me/pntsts/696] | 27.07.2020 20:14:38: To me, it's top-notch [Pntst] [https://t.me/pntsts/689] | 27.07.2020 20:04:35: [Web link] [Pntst] [https://t.me/pntsts/688] | 27.07.2020 20:03:51: Also... the official GUI for MAP has been released; I'm currently trying to get kxcode to work on it, since he has the best GUI skills. [Pntst] [https://t.me/pntsts/685] | 27.07.2020 20:03:17: Telegram is a small world. [Pntst] [https://t.me/pntsts/682] | 27.07.2020 20:02:35: Hi everyone. [Pntst] [https://t.me/pntsts/681] | 27.07.2020 20:02:29: They say "DNS infiltrate" helps, though I've never managed to get it to work myself—maybe it'll work for someone else. [Pntst] [https://t.me/pntsts/665] | 25.07.2020 22:00:24: [Web link] [Pntst] [https://t.me/pntsts/664] | 25.07.2020 21:50:28: Only the VT from Raid—but it likely originates from the Chinese, as is usually the case. [Pntst] [https://t.me/pntsts/662] | 25.07.2020 20:59:40: [Web link] [Pntst] [https://t.me/pntsts/660] | 25.07.2020 20:51:05: What about tampers? I saw "tamperchains" on GitHub, but I haven't had a chance to use them yet—plus there's Atlas. [Pntst] [https://t.me/pntsts/659] | 25.07.2020 20:50:26: [Web link] [Pntst] [https://t.me/pntsts/657] | 25.07.2020 20:47:26: good luck! [Pntst] [https://t.me/pntsts/652] | 25.07.2020 20:46:12: you're breaking the Chinese stuff ) [Pntst] [https://t.me/pntsts/651] | 25.07.2020 20:45:49: dunno [Pntst] [https://t.me/pntsts/650] | 25.07.2020 20:45:42: Safedog is Amazon too. Maybe it's just detecting it like that—double hosting, like WAF + WAF [Pntst] [https://t.me/pntsts/648] | 25.07.2020 20:42:34: they aren't sitting behind two proxies (like Cloudflare), surely? IMHO [Pntst] [https://t.me/pntsts/647] | 25.07.2020 20:42:03: are they hardware-based ones? Norton, etc.? [Pntst] [https://t.me/pntsts/644] | 25.07.2020 20:36:01: thanks [Pntst] [https://t.me/pntsts/643] | 25.07.2020 20:35:54: [Web link] [Pntst] [https://t.me/pntsts/641] | 25.07.2020 20:31:47: not clear ( [Pntst] [https://t.me/pntsts/639] | 25.07.2020 20:31:08: how does that work [Pntst] [https://t.me/pntsts/637] | 25.07.2020 20:29:49: if it's not too much trouble and you have the time, whip up a mini-guide on how to... ...use it)) I mean, I have Burp—well, I have no brains [Pntst] [https://t.me/pntsts/635] | 25.07.2020 20:27:52: https://href.li/?https://anonfiles.com/39E5K5H2oe/Burpsuite_Pro_2020.7_rar [Pntst] [https://t.me/pntsts/632] | 25.07.2020 20:18:42: there's a URL there too [Pntst] [https://t.me/pntsts/631] | 25.07.2020 20:18:35: and sometimes there's a Referer too [Pntst] [https://t.me/pntsts/630] | 25.07.2020 20:17:24: I just haven't happened to do it that way—but I'm curious [Pntst] [https://t.me/pntsts/629] | 25.07.2020 20:17:12: and how do you edit the -r file once you've found the IP? sometimes there's just a 'Host' line... do you just change that? [Pntst] [https://t.me/pntsts/628] | 25.07.2020 20:16:50: that's if you do it manually via -u [Pntst] [https://t.me/pntsts/627] | 25.07.2020 20:16:39: sqlmap -u "ip.ip.ip.ip/index.php?id=1" -p id --host="site.com" [Pntst] [https://t.me/pntsts/625] | 25.07.2020 20:11:58: and what's this wafbypass thing? [Pntst] [https://t.me/pntsts/624] | 25.07.2020 20:11:40: well, and things like Censys, DNS history, etc., etc., etc. [Pntst] [https://t.me/pntsts/623] | 25.07.2020 20:11:26: [Web link] [Pntst] [https://t.me/pntsts/621] | 25.07.2020 20:08:13: maybe the config can be exported directly from the GUI somehow [Pntst] [https://t.me/pntsts/620] | 25.07.2020 20:07:43: I don't know where it's located in version 10. In version 13, it's at C:\ProgramData\Acunetix\shared\general\settings.xml; I think a folder gets created in ProgramData for version 10 too [Pntst] [https://t.me/pntsts/615] | 25.07.2020 19:59:37: could you share the config? if you don't mind. I'd save it to my pack—who knows, I might actually need to roll back to it someday [Pntst] [https://t.me/pntsts/611] | 25.07.2020 19:55:55: If you have time, check out aiduspay.com just for the sake of it; it's an ICO site with at least three SQLi vulnerabilities, even after the fixes. I worked with them legitimately [Pntst] [https://t.me/pntsts/609] | 25.07.2020 19:54:39: It's all a bit strange ( [Pntst] [https://t.me/pntsts/606] | 25.07.2020 19:53:42: @_@ [Pntst] [https://t.me/pntsts/604] | 25.07.2020 19:52:50: Yeah, I posted it on BHF in the "Acunetix collection" thread (Buterbrod shared it, by the way). But why version 10? I've also heard and seen that it finds more stuff. Is it really that much better—and without false positives? Have there been comparisons with the latest versions? Maybe the newer ones find things the old one misses. They don't mention "improved SQLi detection" in the changelogs for nothing, after all. [Pntst] [https://t.me/pntsts/592] | 24.07.2020 08:29:37: There are links in the reverse engineering section on BHF. [Pntst] [https://t.me/pntsts/591] | 24.07.2020 08:29:22: But you can apparently send the exploits it finds straight to Metasploit; it's all very convenient and professional. [Pntst] [https://t.me/pntsts/589] | 24.07.2020 08:28:42: There might be other Java-related bugs somewhere; need to test it. [Pntst] [https://t.me/pntsts/588] | 24.07.2020 08:28:24: And I just have to share this with you guys—I got Nexpose up and running. It took blood, sweat, and tears... but... it works [Pntst] [https://t.me/pntsts/587] | 24.07.2020 08:27:43: 13.0.200715107(15 July 2020) [Pntst] [https://t.me/pntsts/585] | 24.07.2020 08:27:24: No changelog for this version yet; the site only has one with that build number for macOS. I posted the described changes that were available over on BHF. [Pntst] [https://t.me/pntsts/584] | 24.07.2020 08:26:52: life, the walk, the smile) [Pntst] [https://t.me/pntsts/581] | 24.07.2020 08:26:24: latest Acunetix from July 15 [Pntst] [https://t.me/pntsts/580] | 24.07.2020 08:26:18: https://href.li/?https://anonfiles.com/TcafP3H7o6/awslatest_rar [Pntst] [https://t.me/pntsts/571] | 20.07.2020 19:12:24: I have a rough idea of ​​how to finish the crack, but I lack the technical skill. [Pntst] [https://t.me/pntsts/570] | 20.07.2020 19:12:13: I'll provide the installer, a semi-functional crack, and license keys. [Pntst] [https://t.me/pntsts/569] | 20.07.2020 19:12:02: Can we send them Nexpose? [Pntst] [https://t.me/pntsts/567] | 20.07.2020 19:10:51: Thanks [Pntst] [https://t.me/pntsts/566] | 20.07.2020 19:10:47: Ooh, cool ) [Pntst] [https://t.me/pntsts/563] | 20.07.2020 19:09:22: + , do you happen to have an installer? [Pntst] [https://t.me/pntsts/561] | 16.07.2020 12:39:35: https://anonfiles.com/J4N9o7G8o0/Metasploit_Pro_pdf [Pntst] [https://t.me/pntsts/560] | 16.07.2020 12:35:26: Might be useful to someone: a guide to Metasploit Pro in Russian [Pntst] [https://t.me/pntsts/559] | 15.07.2020 23:35:21: here's the thing. the crack had malware in it too; my Windows crashed completely... yeah, he "obfuscated" it, sure... [Pntst] [https://t.me/pntsts/558] | 15.07.2020 23:34:55: https://raidforums.com/Thread-Cracked-Rapid7-Nexpose-6-6-28-29-Enterprise?page=13&highlight=nexpose [Pntst] [https://t.me/pntsts/557] | 15.07.2020 23:34:35: Everyone there was writing "THANKS THANKS GREAT"—they hadn't even run it, the idiots. I told him, "It doesn't work," and he called me a cocksucker... and all that sort of thing. The cocaine they've got there is bad stuff. [Pntst] [https://t.me/pntsts/556] | 15.07.2020 23:33:54: latest Nexpose [Pntst] [https://t.me/pntsts/554] | 15.07.2020 23:20:17: I spent two weeks arguing with "Dark Lord" over there because he posted a broken Nexpose crack and called me a moron for pointing out that it didn't work—plus, there was malware in it too. In the end, he fixed it and released it to the "chosen few." (The crack was actually broken.) ((((( [Pntst] [https://t.me/pntsts/552] | 15.07.2020 2 3:19:21: Guys, does anyone have an old Raid account? Maybe one that's been leveled up a bit? [Pntst] [https://t.me/pntsts/551] | 15.07.2020 22:51:30: @_@ [Pntst] [https://t.me/pntsts/549] | 15.07.2020 22:50:50: I wonder how long it would take to actually get the hang of all this. [Pntst] [https://t.me/pntsts/548] | 15.07.2020 22:50:17: Figured it out) Sonar is their high-speed project that quietly scans the whole internet on its own, and you can import data from sooo many scanners https://docs.rapid7.com/metasploit/importing-data/#supported-third-party-scan-reports — even from Nessus XML. [Pntst] [https://t.me/pntsts/547] | 15.07.2020 22:19:13: Not really clear. [Pntst] [https://t.me/pntsts/546] | 15.07.2020 22:19:09: I see it also ingests Sonar reports; I checked—it's some kind of open-source scanner in the Community Edition. [Pntst] [https://t.me/pntsts/544] | 15.07.2020 22:09:20: But there are no exploits. [Pntst] [https://t.me/pntsts/543] | 15.07.2020 22:09:17: so there might be SQLi [Pntst] [https://t.me/pntsts/541] | 15.07.2020 22:08:56: which means all sorts of XSS and other nastiness too [Pntst] [https://t.me/pntsts/539] | 15.07.2020 22:08:42: although there are 20 SQLi issues on the web app [Pntst] [https://t.me/pntsts/538] | 15.07.2020 22:08:35: it's just strange that the Metasploit web scan didn't find anything on its own [Pntst] [https://t.me/pntsts/533] | 15.07.2020 22:06:32: oh man, still so much to dig through... [Pntst] [https://t.me/pntsts/532] | 15.07.2020 22:06:15: Can the spider generate reports in Nexpose format for Metasploit? Nessus definitely can, by the looks of it [Pntst] [https://t.me/pntsts/527] | 15.07.2020 22:05:25: is that from IBM? [Pntst] [https://t.me/pntsts/521] | 15.07.2020 22:02:48: hope they don't shut the whole thing down [Pntst] [https://t.me/pntsts/520] | 15.07.2020 22:02:35: Oh boy ((( [Pntst] [https://t.me/pntsts/518] | 15.07.2020 22:02:03: Nice, gotta churn out keys for years to come [Pntst] [https://t.me/pntsts/514] | 15.07.2020 21:56:57: Started figuring out Meta; it's a really interesting tool—seems like the best one I've ever handled. And thank God they made a Pro version for button-mashers like me) [Pntst] [https://t.me/pntsts/513] | 15.07.2020 21:56:13: Do I understand correctly that Metasploit itself (the trial version—and are there differences between the trial and full versions?) scans pretty poorly, and it's better to feed it reports from Nessus or Nexpose (damn that thing)? [Pntst] [https://t.me/pntsts/512] | 15.07.2020 03:14:39: https://anonfiles.com/5au3X9F9o8/ASR721241_rar I want to share the latest "Spider" with you; the crack is probably the same, but I uploaded the whole thing for convenience. It scans perfectly. On the test site http://testphp.vulnweb.com/, it found 32 SQLi—better than "Perch" itself) [Pntst] [https://t.me/pntsts/508] | 13.07.2020 17:28:49: Thanks [Pntst] [https://t.me/pntsts/505] | 13.07.2020 14:26:53: Also, a question for @Pentest_IT: could you share the course outline or syllabus, even just roughly? What to expect? I'm really interested. I remember the general idea, but I'd like more details if possible. [Pntst] [https://t.me/pntsts/503] | 13.07.2020 14:25:09: As far as I know, it consumes Burp requests. Surely they aren't any different from the ones used by sqlmap or Burp Spider... [Pntst] [https://t.me/pntsts/502] | 13.07.2020 14:24:38: So, did you ever manage to feed it into nosqlmap? [Pntst] [https://t.me/pntsts/500] | 13.07.2020 14:18:10: I'm no expert, but in my opinion, it's easier to fuzz the parameter manually; if the payload shows up in the attack traffic, then you can specify the technique to save time. Still, it's an interesting feature—I saw something similar in Burp Spider. [Pntst] [https://t.me/pntsts/490] | 10.07.2020 23:50:20: I still don't get what the hell is going on with that "host not exist" error... [Pntst] [https://t.me/pntsts/489] | 10.07.2020 23:50:01: You've got some interesting challenges. [Pntst] [https://t.me/pntsts/487] | 10.07.2020 23:49:44: It's also weird—like, it was running fine with Atlas, but now it won't run, and it's throwing Python errors... shows [Pntst] [https://t.me/pntsts/485] | 10.07.2020 23:49:23: Very, very unlikely [Pntst] [https://t.me/pntsts/483] | 10.07.2020 23:48:42: For everything to work properly [Pntst] [https://t.me/pntsts/482] | 10.07.2020 23:48:32: Maybe the default `python -v` (--v/version) is using something like 2.7. Python on Linux is a total pain in the ass... [Pntst] [https://t.me/pntsts/481] | 10.07.2020 23:47:51: How are you running it? / `python3 atlas.py -commands`? [Pntst] [https://t.me/pntsts/480] | 10.07.2020 23:47:27: Definitely Python [Pntst] [https://t.me/pntsts/478] | 10.07.2020 23:42:31: And the errors look like Python errors [Pntst] [https://t.me/pntsts/477] | 10.07.2020 23:40:04: [Web link] [Pntst] [https://t.me/pntsts/476] | 10.07.2020 23:38:38: Whatwaf, cloudfail, cloudflair for identifying the WAF type; some of these tools also try out tampers [Pntst] [https://t.me/pntsts/472] | 09.07.2020 14:27:08: So, here's a similar issue. I haven't found anything else like it anywhere on the internet. [Pntst] [https://t.me/pntsts/471] | 09.07.2020 14:26:52: https://sourceforge.net/p/sqlmap/mailman/sqlmap-users/thread/4DFD2500.3000405@gmail.com/ [Pntst] [https://t.me/pntsts/470] | 09.07.2020 14:26:15: I sent it to him via private message. [Pntst] [https://t.me/pntsts/469] | 09.07.2020 14:26:10: It exists. [Pntst] [https://t.me/pntsts/467] | 09.07.2020 14:25:06: [Web link] [Pntst ] [https://t.me/pntsts/466] | 09.07.2020 14:22:35: I keep getting this exact error consistently—with a VPN, with any location, even without a VPN )) —whether using `-u` or `-r`. [Pntst] [https://t.me/pntsts/451] | 09.07.2020 14:06:12: Right off the bat o_o? Without payloads? I didn't try it immediately like that... @nomoretrust, I thought you said it was running for you... [Pntst] [https://t.me/pntsts/448] | 09.07.2020 14:05:18: It's the same error on both Windows and Linux; first time I've encountered this. It's mentioned a couple of times in the sqlmap issues, but even stampart can't really explain it there. [Pntst] [https://t.me/pntsts/447] | 09.07.2020 14:04:29: Good day. What's the reason for the host error—something like "host not found"...? [Pntst] [https://t.me/pntsts/443] | 07.07.2020 21:25:38: That's the guy I invited here ) it's more fun to run it together. [Pntst] [https://t.me/pntsts/440] | 07.07.2020 21:24:50: ))) I just wanted to help a friend, but then I ended up needing help myself) [Pntst] [https://t.me/pntsts/438] | 07.07.2020 21:22:00: I'm helping a buddy out; it's running fine for him, but not for me))) [Pntst] [https://t.me/pntsts/436] | 07.07.2020 21:21:52: seems like everything's okay [Pntst] [https://t.me/pntsts/434] | 07.07.2020 21:19:38: that's what I thought too—checked in the browser—it exists [Pntst] [https://t.me/pntsts/433] | 07.07.2020 21:19:28: I'm pulling the file from the desktop using -r [Pntst] [https://t.me/pntsts/431] | 07.07.2020 21:19:13: changed VPN locations, but it didn't help [Pntst] [https://t.me/pntsts/430] | 07.07.2020 21:19:01: Any ideas what the issue might be? It runs on other SQL targets... the host is alive... I can access it manually... but nmap doesn't see it [Pntst] [https://t.me/pntsts/429] | 07.07.2020 21:18:39: [17:14:58] [CRITICAL] host '***.****.**' does not exist [Pntst] [https://t.me/pntsts/408] | 07.07.2020 15:56:14: That's really a shame; honestly, I thought for sure this would be covered in the course. (( How to manipulate it using suffix, prefix, string, or query. [Pntst] [https://t.me/pntsts/234] | 03.07.2020 23:28:48: OK. There's no rush on this. [Pntst] [https://t.me/pntsts/233] | 03.07.2020 23:28:41: Nexpose Enterprise [Pntst] [https://t.me/pntsts/231] | 03.07.2020 23:27:25: By the way, there is a working crack for Nexpose, but it's likely riddled with malware. Who could I turn to for unpacking—and possibly deobfuscation—to get a clean crack? If it's not a secret. [Pntst] [https://t.me/pntsts/229] | 03.07.2020 23:26:01: Need to get Windows back up and running ASAP, thanks. [Pntst] [https://t.me/pntsts/227] | 03.07.2020 23:24:39: The one that gets detected [Pntst] [https://t.me/pntsts/226] | 03.07.2020 23:24:32: Corporate email only [Pntst] [https://t.me/pntsts/225] | 03.07.2020 23:24:28: That's how I tried to get Nexpose [Pntst] [https://t.me/pntsts/221] | 03.07.2020 23:15:09: Oh vei [Pntst] [https://t.me/pntsts/219] | 03.07.2020 23:15:01: That's the one with the web panel [Pntst] [https://t.me/pntsts/218] | 03.07.2020 23:14:48: @_@ [Pntst] [https://t.me/pntsts/215] | 03.07.2020 23:12:51: Meta Pro... that's cool. I've never seen the Pro version shared anywhere [Pntst] [https://t.me/pntsts/214] | 03.07.2020 23:08:07: I tried doing a bulk upload too; it doesn't handle everything—assuming we're talking about version 13. It eats about 50 scans at a time, then I had to add the rest manually. Maybe I was doing something wrong [Pntst] [https://t.me/pntsts/210] | 03.07.2020 23:05:29: Yeah, even with manual authorization, Cloud sometimes blocks Okun... well, I guess that's something that needs a detailed look [Pntst] [https://t.me/pntsts/206] | 03.07.2020 23:03:06: What do you mean by "customized for yourself," if it's not a secret? [Pntst] [https://t.me/pntsts/204] | 03.07.2020 23:01:34: I'm actually more concerned with the reverse question: how to scan in order to find things. Take Okun, for instance—even after getting a 500 error or a Cloud block a billion times, it'll still say everything's fine without batting an eye ...won't even blink. AppSpider might handle it differently. Sparker will likely slow the scan down significantly. [Pntst] [https://t.me/pntsts/201] | 03.07.2020 22:58:11: So the scanner finds it, but nmap can't? O_o [Pntst] [https://t.me/pntsts/182] | 03.07.2020 21:29:02: Spider sometimes finds NoSQL, which raises the question: are they actually connecting MongoDB alongside the main database? Judging by *some studies or other*, NoSQL DBs are being used increasingly often. The question is what they're storing there... and if it's even necessary. I'd be interested to know if NoSQLMap is aware of this—or if it's even needed at all. [Pntst] [https://t.me/pntsts/177] | 03.07.2020 21:23:23: +++ [Pntst] [https://t.me/pntsts/167] | 03.07.2020 19:18:02: Checked out the OSCP prices from Kali/OffSec today—they start at $1k @_@ [Pntst] [https://t.me/pntsts/150] | 02.07.2020 18:11:44: Thanks a ton!! [Pntst] [https://t.me/pntsts/141] | 02.07.2020 08:51:55: I really want to switch to Linux right now. But AppSpider, Nexpose... (if I clear them out)... they seem to be keeping me tied to Windows. On the other hand, I do have dedicated servers available. [Pntst] [https://t.me/pntsts/138] | 02.07.2020 08:47:56: Last night was like exterminating cockroaches; then the locker showed up, it seems... and crushed them [Pntst] [https://t.me/pntsts/137] | 02.07.2020 08:47:12: Pants full of malware [Pntst] [https://t.me/pntsts/136] | 02.07.2020 08:47:06: From Darkside [Pntst] [https://t.me/pntsts/135] | 02.07.2020 08:47:01: So I leaked it [Pntst] [https://t.me/pntsts/133] | 02.07.2020 08:45:34: But just like everywhere else, sometimes it missed something, and sometimes the perch spotted it [Pntst] [https://t.me/pntsts/132] | 02.07.2020 08:44:54: IMHO, it's a top-notch scanner when it comes to bypassing WAFs. (I wish I could find info on its advanced settings—I've scoured the entire internet.) It's a shame I didn't get a chance to try out nexpose yet... ((((((( [Pntst] [https://t.me/pntsts/129] | 02.07.2020 08:36:29: Thanks [Pntst] [https://t.me/pntsts/127] | 02.07.2020 08:36:06: Bumped the PM [Pntst] [https://t.me/pntsts/123] | 02.07.2020 08:33:02: I'll definitely be ready in about a week. I picked up some "Enterprise" Trojans while using Nexpose; I battled them for 6 hours, but they won. Payment structure: 200-100 (may the strongest win). I'd like to get an idea of ​​the course details. And I'm really looking forward to an answer regarding the previous question. [Pntst] [https://t.me/pntsts/111] | 19.06.2020 12:51:36: Thanks [Pntst] [https://t.me/pntsts/100] | 18.06.2020 19:06:33: That's strange—neither Wappalyzer nor Cloud Detect picked up the cloud for me 0_O [Pntst] [https://t.me/pntsts/98] | 18.06.2020 18:50:34: OK, I'll prepare a report [Pntst] [https://t.me/pntsts/97] | 18.06.2020 18:50:25: WAF gets detected without POST data and cookies... [Pntst] [https://t.me/pntsts/94] | 18.06.2020 18:48:19: Online [Pntst] [https://t.me/pntsts/91] | 18.06.2020 18:46:08: If it's not too much trouble—could you take a look? [Pntst] [https://t.me/pntsts/90] | 18.06.2020 18:45:35: But sqlmap is outputting a command that isn't being accepted... Maybe I'm just messing it up, though. [Pntst] [https://t.me/pntsts/89] | 18.06.2020 18:44:36: But again, it's the syntax... Error message found: You have an error in your SQL syntax [Pntst] [https://t.me/pntsts/88] | 18.06.2020 18:44:19: So Acunetix spotted it too. [Pntst] [https://t.me/pntsts/87] | 18.06.2020 18:44:15: Acunetix sees it as well. I'm going to run it through there again now. But I just can't get it to exploit—it says the POST parameter *might* be injectable, but nothing more. [Pntst] [https://t.me/pntsts/84] | 18.06.2020 18:41:59: The attack vector using Single Quote encoding (UCS-2 Encoding)—`111%u0027`—is the only one yielding a somewhat interesting response. No idea how to encode payloads into that format... [Pntst] [https://t.me/pntsts/83] | 18.06.2020 18:39:40: Good evening. Hi there. If Netsparker reports "probable," and AppSpider finds 4 attack vectors—3 resulting in syntax errors and the 4th in an "Unknown column 'c0' in 'where clause'" error—and sqlmap just won't work when I run it manually (and even flagged it once as a non-exploitable false positive), is that the end of the road? [Pntst] [https://t.me/pntsts/75] | 17.06.2020 19:09:11: That’s a really interesting angle too, since you could find yourself some legitimate extra work that way. [Pntst] [https://t.me/pntsts/73] | 17.06.2020 19:05:24: I hope a diploma from this university will carry some weight on hh.ru)) [Pntst] [https://t.me/pntsts/65] | 17.06.2020 18:56:15: Will Cobalt Strike and Metasploit be included? [Pntst] [https://t.me/pntsts/63] | 17.06.2020 18:54:13: I was just discussing the issue of darknet scanning with a colleague; we considered routing traffic through Privoxy or Proxifier, or maybe finding an old Tor Browser bundle. [Pntst] [https://t.me/pntsts/62] | 17.06.2020 18:53:39: Thanks, I have a feeling this is going to be interesting. [Pntst] [https://t.me/pntsts/56] | 17.06.2020 18:43:33: [Web link] [Pntst] [https://t.me/pntsts/55] | 17.06.2020 18:41:32: I'm really interested in the question of exploiting a discovered vulnerability; the scanner outputs both the raw data and the data that triggers the error, but sqlmap doesn't handle that kind of data very well when you just dump it into a .txt file. I've Googled a lot and asked Stamp—he says to just shove the raw data into a .txt file and use a marker—but what if I want to save time and just use a specific payload to test it with sqlmap for GET, POST, or headers (which is actually pretty tricky for me)? [Pntst] [https://t.me/pntsts/27] | 13.06.2020 11:19:32: Question: why AppSpider instead of Acunetix, Sparker, or some other scanner? [Pntst] [https://t.me/pntsts/16] | 12.06.2020 10:11:47: Thanks, I hope we get enough people soon. [Pntst] [https://t.me/pntsts/13] | 12.06.2020 10:03:13: From bhf — hastalamuerte [Pntst] [https://t.me/pntsts/12] | 12.06.2020 10:03:00: Good day. I'm waiting for the start; I recall there was mention of an introductory lesson. I'd also like to know if there's a training syllabus I could look at? I'm really keen to learn about exploiting XSS vulnerabilities and hooking into BeEF. [KRD_chat] [https://t.me/c/1383479642/11527] | 20.03.2020 04:43:38: Can a newbie get a tip on services—maybe somewhere to buy Bitcoin or crypto using a credit card? ...buy? [KRD_chat] [https://t.me/c/1383479642/11526] | 20.03.2020 04:43:00: There are Turkish ones with 2FA; I have no fucking clue how to bypass it [KRD_chat] [https://t.me/c/1383479642/11525] | 20.03.2020 04:42:47: From the US to Brazil and the Emirates [KRD_chat] [https://t.me/c/1383479642/11524] | 20.03.2020 04:42:39: The cards vary a lot [KRD_chat] [https://t.me/c/1383479642/11521] | 20.03.2020 04:41:58: Tried to load rubles via Unipay into some shitty service; the approval takes forever [KRD_chat] [https://t.me/c/1383479642/11520] | 20.03.2020 04:41:30: Honestly, I haven't got a fucking clue [KRD_chat] [https://t.me/c/1383479642/11519] | 20.03.2020 04:41:16: There's a bunch of checked, valid ones [KRD_chat] [https://t.me/c/1383479642/11518] | 20.03.2020 04:41:09: Where should I hit the CC? ?)) [KRD_chat] [https://t.me/c/1383479642/11517] | 03/20/2020 04:40:52: Guys [The Darknet, which we deserve] [https://t.me/c/1077626075/594193] | 27.04.2017 21:49:16: /help@banofbot [The Darknet We Deserve] [https://t.me/c/1077626075/591295] | 24.04.2017 21:12:49: Here on a business trip [The Darknet We Deserve] [https://t.me/c/1077626075/591294] | 24.04.2017 21:12:40: I can put you up [The Darknet We Deserve] [https://t.me/c/1077626075/591293] | 24.04.2017 21:12:38: As a brother or sister would) [The Darknet We Deserve] [https://t.me/c/1077626075/591292] | 24.04.2017 21:12:30: Who in Kazan can show me around? [The Darknet We Deserve] [https://t.me/c/1077626075/591091] | 24.04.2017 10:30:09: Anyone from Kazan? I'm here for work until Friday—let's have some fun [The Darknet We Deserve] [https://t.me/c/1077626075/587907] | 21.04.2017 14:37:11: I'm heading there for a week, looking for company ) [The Darknet We Deserve] [https://t.me/c/1077626075/587906] | 21.04.2017 14:36:56: Any girls here from Kazan? [The Darknet We Deserve] [https://t.me/c/1077626075/585731] | 20.04.2017 21:25:04: I can send it to you via PM [The Darknet We Deserve] [https://t.me/c/1077626075/577391] | 17.04.2017 13:48:50: Should I take the cork out, or are we sitting on it as is? [The Darknet We Deserve] [https://t.me/c/1077626075/577389] | 17.04.2017 13:47:46: Who said "bottle" here? [The Darknet We Deserve] [https://t.me/c/1077626075/577388] | 17.04.2017 13:47:39: [Image] [The Darknet We Deserve] [https://t.me/c/1077626075/574761] | 14.04.2017 22:15:12: You look like Tom Hardy. I'm not like... you [The Darknet We Deserve] [https://t.me/c/1077626075/574757] | 14.04.2017 22:14:31: [Sticker] [The Darknet We Deserve] [https://t.me/c/1077626075/574756] | 14.04.2017 22:14:28: Any kitties here?) [The Darknet We Deserve] [https://t.me/c/1077626075/574746] | 14.04.2017 22:12:41: Nice try, Comrade Major [The Darknet We Deserve] [https://t.me/c/1077626075/574744] | 14.04.2017 22:12:06: Wha [The Darknet We Deserve] [https://t.me/c/1077626075/572802] | 12.04.2017 01:11:16: Nein [The Darknet We Deserve] [https://t.me/c/1077626075/572800] | 12.04.2017 01:10:32: )) [The Darknet We Deserve] [https://t.me/c/1077626075/572799] | 12.04.2017 01:10:31: But I did manage to get in somehow [The Darknet We Deserve] [https://t.me/c/1077626075/572797] | 12.04.2017 01:10:12: Address hidden [The Darknet We Deserve] [https://t.me/c/1077626075/572796] | 12.04.2017 01:10:03: Here was the link [The Darknet We Deserve] [https://t.me/c/1077626075/572795] | 12.04.2017 01:09:59: https://t.me/joinchat/AAAAAEA7RNtb_E9ZjRrCjg [The Darknet We Deserve] [https://t.me/c/1077626075/572792] | 12.04.2017 01:09:24: I don't have that user in my contacts [The Darknet We Deserve] [https://t.me/c/1077626075/572791] | 12.04.2017 01:09:10: Piper invited me via the link [The Darknet We Deserve] [https://t.me/c/1077626075/572789] | 12.04.2017 01:09:00: How do you get an invite to this place? [The Darknet We Deserve] [https://t.me/c/1077626075/572787] | 12.04.2017 01:08:24: Give me an invite link pls [The Darknet We Deserve] [https://t.me/c/1077626075/572639] | 11.04.2017 22:48:02: Guys, which section is PCP in on RAMP? [The Darknet We Deserve] [https://t.me/c/1077626075/572636] | 11.04.2017 22:10:25: People have different levels of susceptibility. To everything. [The Darknet We Deserve] [https://t.me/c/1077626075/572634] | 11.04.2017 21:48:58: Or real coffee [The Darknet We Deserve] [https://t.me/c/1077626075/572633] | 11.04.2017 21:48:48: Red Bull gives me almost the same buzz [The Darknet We Deserve] [https://t.me/c/1077626075/572628] | 11.04.2017 21:33:22: suum cuique [The Darknet We Deserve] [https://t.me/c/1077626075/572622] | 11.04.2017 21:32:26: That actually helped, even [The Darknet We Deserve] [https://t.me/c/1077626075/572620] | 11.04.2017 21:32:20: But I quit because I lost my mind back then [The Darknet We Deserve] [https://t.me/c/1077626075/572619] | 11.04.2017 21:32:07: Speed ​​is a poor man's drug, IMHO [The Darknet We Deserve] [https://t.me/c/1077626075/572617] | 11.04.2017 21:31:56: Maybe [The Darknet We Deserve] [https://t.me/c/1077626075/572615] | 11.04.2017 21:31:36: And then *I* quit... The others, not so much [The Darknet We Deserve] [https://t.me/c/1077626075/572614] | 11.04.2017 21:31:28: Well, that just makes you a weakling. Back in '07, we used to thrash the hell out of the wheels [The Darknet We Deserve] [https://t.me/c/1077626075/572611] | 11.04.2017 21:31:14: )))))) [The Darknet We Deserve] [https://t.me/c/1077626075/572607] | 11.04.2017 21:30:59: I think the engine's gonna blow [The Darknet We Deserve] [https://t.me/c/1077626075/572606] | 11.04.2017 21:30:55: Yeah, even three of 'em [The Darknet We Deserve] [https://t.me/c/1077626075/572602] | 11.04.2017 21:30:47: Well [The Darknet We Deserve] [https://t.me/c/1077626075/572599] | 11.04.2017 21:30:35: Give it a test [The Darknet We Deserve] [https://t.me/c/1077626075/572598] | 11.04.2017 21:30:33: Rip a donut [The Darknet, ...we deserve] [https://t.me/c/1077626075/572596] | 11.04.2017 21:30:25: Sure [The Darknet we deserve] [https://t.me/c/1077626075/572586] | 11.04.2017 21:28:37: On DMT [The Darknet we deserve] [https://t.me/c/1077626075/572582] | 11.04.2017 21:28:27: They'll tell you you won't die, it's all good [The Darknet we deserve] [https://t.me/c/1077626075/572581] | 11.04.2017 21:28:19: Imagine they cut it with heroin [The Darknet we deserve] [https://t.me/c/1077626075/572580] | 11.04.2017 21:28:10: IMHO [The Darknet we deserve] [https://t.me/c/1077626075/572579] | 11.04.2017 21:28:08: Idiot [The Darknet we deserve] [https://t.me/c/1077626075/572574] | 11.04.2017 21:17:43: God forbid you ever get stuck with that kind of bullshit [The Darknet We Deserve] [https://t.me/c/1077626075/572573] | 11.04.2017 21:17:34: Fuck, there are morons everywhere, but I hope there are some decent people here [The Darknet We Deserve] [https://t.me/c/1077626075/572571] | 11.04.2017 21:16:29: Hey guys, anyone growing mushrooms? Give me some advice—a friend of mine has cluster headaches and knows psilocybin helps (a damn good doctor told him so). Where can I find full grow kits with manuals and all that? [The Darknet We Deserve] [https://t.me/c/1077626075/566080] | 07.04.2017 20:40:14: Ban for MMORPG [The Darknet We Deserve] [https://t.me/c/1077626075/559605] | 03.04.2017 19:44:20: Nastya on H [The Darknet We Deserve] [https://t.me/c/1077626075/559387] | 03.04.2017 16:17:01: Either it's those fucking scumbags from ISIS [The Darknet We Deserve] [https://t.me/c/1077626075/559386] | 03.04.2017 16:16:51: The people around the leader [The Darknet We Deserve] [https://t.me/c/1077626075/559385] | 03.04.2017 16:16:43: To rally everyone together [The Darknet We Deserve] [https://t.me/c/1077626075/559384] | 03.04.2017 16:16:33: Like Pyatigorsk, Ryazan, or wherever that 'sugar' incident was [The Darknet We Deserve] [https://t.me/c/1077626075/559382] | 03.04.2017 16:16:20: Just hope it’s not... our own people [The Darknet We Deserve] [https://t.me/c/1077626075/559381] | 03.04.2017 16:16:11: Fuck, this is a nightmare [The Darknet We Deserve] [https://t.me/c/1077626075/559379] | 03.04.2017 16:16:08: Tell me about it [The Darknet We Deserve] [https://t.me/c/1077626075/521727] | 20.03.2017 15:20:20: Google is your friend [The Darknet We Deserve] [https://t.me/c/1077626075/521722] | 20.03.2017 15:19:40: Actually, it sure as hell isn't you. Too bad there's no banning here ( [The Darknet We Deserve] [https://t.me/c/1077626075/521719] | 20.03.2017 15:19:05: For her voice messages [The Darknet We Deserve] [https://t.me/c/1077626075/521718] | 20.03.2017 15:18:59: That cunt’s already been banned from a second chat [The Darknet We Deserve] [https://t.me/c/1077626075/521713] | 20.03.2017 15:18:25: Yeah, Japanese drops. Fucking great effect. Haven't seen better. Okumetil is good too, but I think you're not supposed to use it too often—correct me if I'm wrong [The Darknet We Deserve] [https://t.me/c/1077626075/521705] | 20.03.2017 15:13:22: The absolute best drops are Santa FX Neo [The Darknet We Deserve] [https://t.me/c/1077626075/521056] | 20.03.2017 10:46:00: It's a sort of initiation rite for newbies [The Darknet We Deserve] [https://t.me/c/1077626075/521054] | 20.03.2017 10:45:48: Silk Road, man nipples [The Darknet We Deserve] [https://t.me/c/1077626075/514528] | 17.03.2017 21:29:40: You could also knock out an eye and put in a prosthetic one with a secret compartment [The Darknet We Deserve] [https://t.me/c/1077626075/514527] | 17.03.2017 21:29:30: Clever [The Darknet We Deserve] [https://t.me/c/1077626075/514449] | 17.03.2017 21:21:16: Greetings to the house