Login Register






Tutorial Cloning Doxbin.org for Fun and not Profit filter_list
Author
Message
Cloning Doxbin.org for Fun and not Profit #1
For some reason “doxing” people is some kind of new trend among the hacking communities on the internet. Not only do I not like the word “dox” because it just sounds so noobish but the fact that people think they are accomplishing something special also irritates me. I came across a site named doxbin.org a few weeks back or so.

The website allows people to upload text information about someone, with no verification at all for it’s validity. This can work against people trying to “dox” someone. If you simply upload false information about someone over and over again, how do you know the information is correct? I decided I would just clone the website and give it to the masses, maybe a thousand of these dox sites will pop up and people will move away from “doxing” and claiming to have personal information on people.

Initial Cloning
The first thing to do when you clone a website is to just save all the pages. I remember using something called HTTTrack or something like that on Windows a long time ago. However, I do not use Windows anymore and try not to use it, ever. I am currently using Ubuntu (xenial), so let’s use wget to download the whole site.

Code:
wget -r -nc -p --html-extension -k -np -X upload https://doxbin.org/

We don’t need the upload folder with all the entries so the -X argument is telling wget to exclude the upload directories from the website.

So now we have a base to work with. From here it’s not too difficult to add some kind of admin panel to manage the site. We can also guess at what the database is like from simply using the website and what information it has on it.

[Image: screenshot-2019-01-16-at-5.27.20-pm.png]

[Image: workspace-1_001.png]

So now if we look at it in our browser, we can see it’s almost good to go, with barely any work, as you can see below. It all works, but nothing is saving to a database of course.

[Image: screenshot-2019-01-16-at-5.28.35-pm.png]

The links on the front page of our clone is also pointing to the original doxbin.org, but that’s an easy fix.

Creating the Database
Looking at the interface we can get a good feel for the inner workings on the database. Below I circled some of the fields we are going to create. The next image is the phpMyAdmin database I created.

[Image: XcXOJkn.png]

[Image: screenshot-2019-01-16-at-8.05.22-pm.png]

We will be using PDO, since it’s more secure and it’s basically the standard now for interacting with a MySQL database through PHP. We will write a class for our database that will make it easier to pass our data to the template files.

The doxbin site seems to use the titles of the dox's as the ID to view the dox that someone uploaded/added. This is a horrible idea since if you add a new dox with the same title, it won’t even add it to the database. This is a flaw that I think shows the skill level of the coder for doxbin.org, which in my opinion is quite low.

[Image: selection_001-1.png]

Template Engine
I like to use Smarty. If I get complete control over a project, I always opt to use Smarty instead of a heavy frameworks like Symfony. Using a simple template engine and not a huge framework for small projects like this is beneficial for you and the server. Download smarty here.

Code:
unzip -x master.zip rm master.zip mv smarty-master/ smarty/

Above, we unzip the master.zip archive (preserving the directory structure) we downloaded, remove the master.zip file, then rename the directory to something more friendly, named smarty. We need to break apart the sections of the site into a header, body, and footer. The website doesn’t have a footer but ours will.

[Image: selection_001.png]

So basically what we want to do with the template engine is separate our forward facing HTML from our PHP code. This is whole idea behind MVC style programming. This will allow us to update code without breaking other code on the site. We can update classes and then later just plug the data into our templates with ease. As you can see in the image above the body tag is still in the index.php file (the file featured above). I will move it into our nav.tpl file, since that;s where the site starts showing the HTML.

[Image: selection_001-2.png]

Pretty URL’s and Redirects
The site makes use of htaccess rewrites, at least, that’s what it seems like. It may be done with PHP but it’s much easier to just use simple htaccess rewrite rules, which is what we are going to use. The raw view and the upload view pages will be redirected.

[Image: selection_001-3.png]

Installation System
In order to get this thing to the masses so people can easily run and install this clone, we will need some kind of basic installation system. We will need something that a user can input their database details and other settings. To keep things a bit more secure we are going to need to have these settings our of the reach of the internet. This means writing a file and setting permissions for only the web server user.
The permissions on the config file should be

The Captcha
There are a bunch of different captchas out there. Doxbin uses Google’s Recaptcha service. The Google captcha is configured in the installation. If you don’t want the captcha to show, don’t fill out the captcha portion of the install or simply remove the site and secret keys from the config file. If you fail to verify with the captcha you will simply be redirected, no dox entry will be made.

Download
https://anonfile.com/D7wfS5qbba/doxbin_zip
https://realsunjester.wordpress.com/2019...ot-profit/
(This post was last modified: 01-19-2019, 08:21 AM by sunjester.)

Reply

RE: Cloning Doxbin.org for Fun and not Profit #2
This Is quite In depth, that requires time to prepare and execute. It's very well documented, Illustrated and elaborated.

Bookmarked and added to my to-do list.
[Image: AD83g1A.png]

Reply