Link for Understand to Hacking and Defence
Link for Understand to Hacking and Defence
➖https://www.guerrillamail.com/en/
➖https://10minutemail.com
➖https://www.trash-mail.com/inbox/
➖https://www.mailinator.com
➖http://www.yopmail.com/en
➖https://generator.email
➖https://en.getairmail.com
➖http://www.throwawaymail.com/en
➖https://maildrop.cc
➖https://owlymail.com/en
➖https://www.moakt.com
➖https://tempail.com
➖http://www.yopmail.com
➖https://temp-mail.org/en
➖https://www.mohmal.com Best options
➖http://od.obagg.com Best options
➖http://onedrive.readmail.net Best options
➖http://xkx.me Best options
➖ https://www.emailondeck.com
➖ https://smailpro.com
➖ https://anonbox.net
➖ https://M.kuku.lu
https://www.yougetsignal.com/
DNS MAP
https://github.com/makefu/dnsmap/
Windows grep Software to Search (and Replace) through Files and Folders on Your PC and
Network
https://www.powergrep.com/
Reflected XSS on http://microsoft.com subdomains
https://medium.com/bugbountywriteup/reflected-xss-on-microsoft-com-subdomains-
4bdfc2c716df
Mapping-Injection
https://github.com/antonioCoco/Mapping-Injection
Rapid7_OSINT
All the tools you need to make your own mind up from the Open Data Sets
https://github.com/tg12/rapid7_OSINT
++Networking
- Wireshark, tshark
- tcpdump
- netcat, telnet
- nmap
++ Forensics
- dd
- strings
- scalpel
- TrID
- binwalk
- foremost
- ExifTool
- Any hex editor
- DFF
- CAINE
- The Sleuth kit
- Volatility
++Crypto
- Cryptool
- hashpump
- Sage
- John the Ripper
- hashcat
- Online tools(web)
- Modules for python
++Stegano
- OpenStego
- OutGuess
- Steghide
- StegFS
- pngcheck
- Gimp
- Audacity
- Mp3Stego
- ffmpeg
- Own tools
++Reverse
- GDB
- IDA Pro
- Immunity Debugger
- OllyDbg
- Radare2
- nm
- objdump
- strace
- ILSPy(.NET)
- JD-GUI(Java)
- FFDec(Flash)
- dex2jar(Android)
- uncomplye2(Python)
- Any hex editor
- Exe unpackers
- Resource unpackers
- Compilers
1.Hacking: How to Hack Computers, Basic Security and Penetration Testing Ebook
Download Link : https://drive.google.com/file/d/0B4CdA3JV_23OSW5BTVlNU1RlaW8/view
Here are few links ( Ebooks) that you guys might be interested.
Metasploit, NMAP, Wireshark, Aircrack, Nessus, Social Engineering Toolkit, W3AF, Burp Suite,
BeEF, SQLmap
https://cybersecuritynews.com/penetration-testing-tools/
https://drive.google.com/drive/folders/1Tv_tLTeotyMcJz6mR0cOba1FaEnqaNbQ
Hacking-Security-Ebooks
Top 100 Hacking & Security E-Books (Free Download) - Powered by Yeahhub.com
https://github.com/yeahhub/Hacking-Security-Ebooks
Hacker Ebook
•Car Hacker Handbook
•The hacker playbook 1,2,3
•Grey hat Hacking
•Advanced Penetration testing
•Black hat python
•Defensive security
•Hacking-the art of exploitation
•Kali revealed
•Advanced pentesting by Cybrary
Many more go check it out
Drive Link
https://drive.google.com/drive/folders/1qhLjmXvzxxkhgZoXoGsXhNm8KjOrtGCT
Metasploit course:
Google drive:
https://drive.google.com/drive/folders/1YLPpd9RhdbW3Icrfz4HM147C0y_IGPhE
Complete Kali Linux Tutorial, Complete Penetration Testing Training, Learn Hacking
Download : https://drive.google.com/drive/u/0/folders/1NFG4Li5Q7uulp7Hpn8t3ZkWvviGVg-fJ
#Computer_Forensics
Full course just for you :
https://drive.google.com/drive/folders/1luUwu4kyZ0YgBAPL_F5CZ6aDX6grETw0
This Video Tutorial Will Help You To Learn Different Types Of Network Attacks And Secure
Yourself From It
https://drive.google.com/drive/u/0/mobile/folders/1PPv133qe42Tzhxu9BNitLM8lzTWylZxy
CTF/Wargames
https://overthewire.org/wargames
https://www.pentesterlab.com
http://www.itsecgames.com
https://exploit-exercises.com
https://www.enigmagroup.org
http://smashthestack.org
http://3564020356.org
https://www.hackthissite.org
http://www.hackertest.net
http://0x0539.net
https://vulnhub.com
https://ringzer0team.com
https://root-me.org
https://microcorruption.com
http://abctf.xyz
http://pwnable.kr
https://ctftime.org
https://www.vulnhub.com
https://w3challs.com/challenges/hacking
http://forensicscontest.com/puzzles
https://xss-game.appspot.com
http://pwnable.tw
https://io.netgarage.org
https://www.mavensecurity.com/resources/web-security-dojo
https://www.owasp.org/index.php/OWASP_Wordpress_Security_Implementation_Guideline
OWASP API Security Top 10
https://github.com/OWASP/API-Security/blob/develop/2019/en/dist/owasp-api-security-top-
10.pdf
WARNING! All versions of #Microsoft Windows (7, 8.1, 10, Server 2008, 2012, 2016, 2019)
operating systems contain 2 new font parsing library RCE vulnerabilities that are:
—CRITICAL
—UNPATCHED
—Under active ZERO-DAY attacks
No patch available, so all Windows users are highly recommended to immediately apply
workarounds (mentioned in the article) to reduce the risk of getting hacked.
Details ➤ https://thehackernews.com/2020/03/windows-adobe-font-vulnerability.html
VulnSpy privides materials allowing anyone to gain practical hands-on experience with cyber
security.
https://www.vulnspy.com/
Security-cheatsheets
A collection of useful cheatsheets for cheat that focuses on aiding security-type people with
either security tools or popular UNIX programs.
https://github.com/andrewjkerr/security-cheatsheets
“Google Dorks List 2018 — Fresh Google Dorks 2018 For SQLi” by Waziristani Haxor
https://link.medium.com/3T1WmO5VJ2
The Kostebek is a reconnaissance tool which uses firms' trademark information to discover
their domains.
https://github.com/esecuritylab/kostebek
Open-AudIT is an application to tell you exactly what is on your network, how it is configured
and when it changes
https://www.open-audit.org/index.php
Inspire women to fall in love with programming
https://djangogirls.org
Reversing and exploiting books
https://github.com/hdbreaker/ExploitingBooks
Dirilis kerentanan cve-2020-0796. Anda bisa mendapatkan tambalan dengan pergi ke alamat di
bawah ini dan menginstalnya di sistem Anda.
https: //portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0796
1- Tekan tombol windows + R untuk membuka RUN dan masukkan perintah Winver untuk
menampilkan versi OS.
2- Unduh dan instal pembaruan sesuai dengan versi Windows Anda.
3- Mulai ulang Windows Anda.
Anda dapat bertindak dalam dua cara untuk memastikan tambalan diinstal.
CM Menggunakan CMD
Salin dan jalankan perintah berikut dalam CMD.
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200005
Peringatan serius
Dalam tambalan keamanan Microsoft yang dirilis pada 10 Maret 2020, Microsoft menerapkan
kesadaran kerentanan pada SMBv3 yang memungkinkan eksekusi kode jarak jauh dan distribusi
seperti cacing pada sistem yang rentan.
Meskipun belum jelas kapan Microsoft akan berusaha untuk memperbaiki tambalan,
perusahaan menginginkan penggunanya untuk menonaktifkan SMBv3 sebagai solusi dan
memblokir koneksi TCP port 2 pada firewall dan komputer pengguna.
Researchers discovered a new ransomware strain dubbed Pxj that encrypts users’ files appends
“.pxj” extension to the encrypted files. The new ransomware strain was discovered by IBM’s X-
Force Incident Response team, and the ransomware malware is all known as “XVFXGW”. PXJ
Ransomware The PXJ Ransomware code appears to be a new one, it doesn’t share […]
The post New PXJ Ransomware Delete’s Backup Copies and Disable’s User Ability to Recover
any Files (https://gbhackers.com/new-pxj-ransomware/) appeared first on GBHackers On
Security (https://gbhackers.com/).
Memhunter is an Automated Memory Resident Malware Detection tool for the hunting of
memory resident malware at scale, improving the threat hunter analysis process and
remediation times.
It’s a self contained binary that can be deployed and managed at scale, does not use memory
dumps and relies purely on memory inspection to do its work. It also does not require any
complex infrastructure to deploy.
The tool was designed as a replacement of memory forensic volatility plugins such as malfind
and hollowfind.
Read the rest of Memhunter – Automated Memory Resident Malware Detection now! Only
available at Darknet. (https://www.darknet.org.uk/2020/03/memhunter-automated-memory-
resident-malware-detection/)
Reverse Engineering Resource Collection. 3000+ open source tools, ~600 blog post
https://github.com/alphaSeclab/awesome-reverse-engineering/blob/master/Readme_en.md
GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes.
https://github.com/swisskyrepo/GraphQLmap
EXIST is a web application for aggregating and analyzing cyber threat intelligence.
https://github.com/nict-csl/exist
Toolkit to detect and keep track on Blind XSS, XXE & SSRF
https://github.com/SpiderMate/B-XSSRF
Wordlists for creating statistically likely username lists for use in password attacks and security
testing
- http://weakpass.com
- http://hashes.org
- http://github.com/danielmiessler/SecLists
- http://github.com/berzerk0/Probable-Wordlists
- http://github.com/insidetrust/statistically-likely-usernames
HeapViewer
An IDA Pro plugin to examine the heap, focused on exploit development.
https://github.com/danigargu/heap-viewer
http://telegram.org/blog/ton-gram-notice
https://relayto.com/relayto/telegram-open-network-ton-ico-whitepaper-6kf4rycn/pdf
BurpSuite
https://github.com/alphaSeclab/awesome-burp-suite/blob/master/Readme_en.md
OnionScan is a free and open source tool for investigating the Dark Web. For all the amazing
technological innovations in the anonymity and privacy space, there is always a constant threat
that has no effective technological patch - human error. [OnionScan]
https://github.com/s-rah/onionscan
Sudomy is a subdomain enumeration tool, created using a bash script, to analyze domains and
collect subdomains in fast and comprehensive way . Report output in HTML or CSV format
https://github.com/Screetsec/Sudomy
Moloch is an open source, large scale, full packet capturing, indexing, and database system.
http://molo.ch
Red-Teaming-Toolkit
A collection of open source and commercial tools that aid in red team operations.
https://github.com/infosecn1nja/Red-Teaming-Toolkit
RedGhost
Linux post exploitation framework designed to assist red teams in gaining persistence,
reconnaissance and leaving no trace.
https://github.com/d4rk007/RedGhost
DEEPWARE SCANNER
https://www.deepware.ai
Flan Scan is a lightweight network vulnerability scanner. With Flan Scan you can easily find
open ports on your network, identify services and their version, and get a list of relevant CVEs
affecting your network.
A pretty sweet vulnerability scanner
https://github.com/cloudflare/flan
SSRF_Vulnerable_Lab
EE | SSRF Vulnerable LAB | https://github.com/incredibleindishell/
hundreds of ethical hacking & penetration testing & red team & cyber security & computer
science resources.
https://github.com/blaCCkHatHacEEkr/PENTESTING-BIBLE
M0nkeyShell:
How to prepare for OSCP complete guide
Below are 5 skills which you have to improve before registering for OSCP
> Learn basic of Computer Network, Web application, and Linux
> Learn Bash and Python scripting
> Enumeration is key in OSCP lab, I repeat Enumeration is key in OSCP Lab and in real world too
> Download vulnerable VM machines from vulnhub
> Buffer Overflow (BOF) exploitation
Below are the reference for Buffer overflow and exploit developmet for OSCP
> http://www.fuzzysecurity.com/tutorials/expDev/1.html
> https://www.corelan.be/index.php/2009/07/19/exploit-writing-tutorial-part-1-stack-based-
overflows/
Privilege Escalation:
> http://www.greyhathacker.net/?p=738
> http://www.fuzzysecurity.com/tutorials/16.html
> https://github.com/GDSSecurity/Windows-Exploit-Suggester
> http://pwnwiki.io/#!privesc/windows/index.md
> https://blog.g0tmi1k.com/2011/08/basic-linux-privilege-escalation/
> https://github.com/rebootuser/LinEnum
> https://www.youtube.com/watch?v=PC_iMqiuIRQ
> https://www.adampalmer.me/iodigitalsec/2013/08/13/mysql-root-to-system-root-with-udf-
for-windows-and-linux/
Port redirection/tunneling
> https://chamibuddhika.wordpress.com/2012/03/21/ssh-tunnelling-explained/
> http://www.abatchy.com/search/label/Networking
Practise Lab online & offline --- Most of this lab help you to understand different attack and
(privilege escaltion very very important for OSCP )
> http://overthewire.org/wargames/bandit/
> https://www.explainshell.com/
> https://www.vulnhub.com/?q=kioptrix&sort=date-asc&type=vm
> https://www.vulnhub.com/entry/fristileaks-13,133/
> https://www.vulnhub.com/entry/brainpan-1,51/ (Buffer overflow vm)
> https://www.vulnhub.com/entry/mr-robot-1,151/
> https://www.vulnhub.com/entry/hacklab-vulnix,48/
> https://www.vulnhub.com/entry/vulnos-2,147/
> https://www.vulnhub.com/entry/sickos-12,144/
> https://www.vulnhub.com/entry/devrandom-scream,47/
> https://www.vulnhub.com/entry/skytower-1,96/
> https://github.com/rapid7/metasploitable3/wiki
Awesome
https://github.com/sindresorhus/awesome
Bypassing-Web-Application-Firewalls-And-XSS-Filters
https://github.com/frizb/Bypassing-Web-Application-Firewalls
Adama
Searches For Threat Hunting and Security Analytics
https://github.com/randomuserid/Adama
Hacker Roadmap
https://github.com/sundowndev/hacker-roadmap
Critical Security Flaw Found in WhatsApp Desktop Platform Allowing Cybercriminals Read
From The File System Access
https://www.perimeterx.com/tech-blog/2020/whatsapp-fs-read-vuln-disclosure/
1. https://www.scanmyserver.com/
2. http://sucuri.7eer.net/c/245992/212721/3713?u=https%3A%2F%2Fptop.only.wip.la%3A443%2Fhttps%2Fsitecheck.sucuri.net%2F
3. http://www.quttera.com/
4. https://www.acunetix.com/vulnerability-scanner/register-online-vulnerability-
scanner/https://www.siteguarding.com/en/affiliate?partner_id=3662Acunetix
5. https://detectify.com/
6. https://www.siteguarding.com/en/affiliate?partner_id=3662
7. https://app.webinspector.com/UpGuard
8. https://www.netsparker.com/online-web-application-security-scanner/Observatory
9. https://app.upguard.com/webscan
10. https://observatory.mozilla.org/
11. https://www.tinfoilsecurity.com/
Kali ini kami ingin memperkenalkan 40 situs bagus kepada teman-teman. Beberapa di
antaranya mungkin bermanfaat bagi Anda.
1. Situs Lynda adalah situs web tempat lebih dari 4 juta orang berlatih (Lynda.com sekarang
adalah LinkedIn Learning).
2. Cari tau 101 Free Online Journal and Research Databases.
3. Situs Creative Life: Bawalah kreativitas Anda dengan kelas online gratis.
4. Situs Hackaday: Kembangkan keterampilan Anda dengan rekomendasi harian dari situs
web ini.
5. Situs MindTools: Tempat untuk mempelajari keterampilan manajemen
6. Situs Codecademy: Di sekolah online ini Anda dapat belajar bekerja dengan Java, PHP,
Python, dan banyak lagi.
7. Situs EdX: Situs web ini menawarkan banyak kursus online termasuk pemrograman.
8. Situs Platzi: Dapatkan pelatihan profesional dalam pemasaran, coding, pengembangan
aplikasi dan desain dengan situs web ini.
9. Situs Big Think: Temukan artikel dan video tentang pemikir hebat di situs ini.
10. Situs kerajinan: Pelajari melalui tutorial menyenangkan oleh para ahli di bidang seni seperti
memasak, merajut, menjahit, menghias kue dan banyak lagi.
11. Situs: Sumber lengkap kiat dan saran tentang topik apa pun yang mungkin Anda pikirkan.
12. Situs Lifehacker: Tips untuk kehidupan sehari-hari
13. Situs LitLovers: Pecinta sastra memiliki akses ke kursus online gratis di area ini.
14. Situs Udacity: Pelajari Pengodean Gratis di Kursus Online Gratis bersama Sebastian Tran.
15. Situs Zidbits: Tempat untuk mengakses artikel dan berita menarik dan fakta aneh
16. Situs TED Ed: Kumpulan tutorial berharga tentang berbagai topik
17. Situs Scitable: Jika Anda tertarik pada genetika, Anda dapat mempelajari tentang situs ini.
18. Situs ITunes U: Universitas ternama seperti Harvard dan Yale berbagi podcast di sini.
19. Situs Livemocha: Terhubung dengan 190 bahasa untuk mempelajari bahasa baru.
20. Situs MIT Open Courseware: Bergabunglah dengan Universitas MIT untuk mempelajari
dasar-dasar pengkodean.
21. Situs WonderHowTo: Situs ini menawarkan video baru setiap hari untuk mempelajari cara
melakukan berbagai hal.
22. Situs FutureLearn: Bergabung dengan tiga juta pengguna situs ini dan berpartisipasi dalam
kursus tentang belajar dari kesehatan hingga sejarah.
23. Situs One Month: Pelajari keterampilan baru dalam sebulan.
24. Situs Khan Academy: Salah satu Platform Pendidikan Online Paling Populer dengan Tema
Game
25. Situs Yousician: Bagaimana Anda belajar musik?
26. Situs Duolingo: Situs pembelajaran bahasa gratis
27. Situs Squareknot: Kreativitas juga bisa dipelajari.
28. Situs Web Highbrow: Layanan berlangganan yang mengirimi Anda tutorial lima menit
setiap hari ke email Anda.
29. Situs Spreeder: Pelajari cara membaca di situs ini
30. Situs Memrise: Tingkatkan pengetahuan kosakata Anda.
31. Situs HTML5Rocks: Google profesional berbagi pembaruan terbaru, kiat sumber daya dan
informasi terkait HTML5 lainnya dengan Anda.
32. Situs Daftar Artikel Wikipedia Daily: Dapatkan artikel Wikipedia di email Anda setiap hari.
33. Situs DataMonkey: Pelajari SQL dan Excel di situs ini.
34. Situs Saylor Academy: Belajar untuk mempresentasikan dan memberi kuliah dengan kursus
online di situs ini.
35. Situs Cook Smarts: Pelajari memasak dasar dan profesional di situs ini.
36. Situs The Happiness: Belajar Menjadi Bahagia.
37. Situs: Kursus konten khusus dari fotografi hingga blogging
38. Situs Surface Languages: Jika Anda perlu belajar hanya beberapa kata dalam bahasa baru
untuk perjalanan, jangan lewatkan situs ini.
39. Situs Academic Earth: Kursus akademik lanjutan tersedia dari 2009 hingga sekarang.
40. Situs Make: Pelajari cara melakukan hal-hal sederhana di rumah dan jadilah tukang reparasi
Anda sendiri.