Sinisterly
website hacking question. - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking)
+--- Thread: website hacking question. (/Thread-website-hacking-question)

Pages: 1 2 3


RE: website hacking question. - SneakyBit - 01-24-2019

Asking such a question proves you have not the required skills to hack a website, so to start first I would suggest you to learn the basics of web application vulnerabilities and how they are exploited. After that download some vulnerable web applications (DVWA, bWAPP,...) and practice your skills on it. Once you learn all these things and got some practice, only then can you try to hack a web application. BTW I would suggest you not to test web applications for which you have no rights from the admin as it might get you into trouble. Also websites such as CP on the dark net might be set up by the feds to catch pedo's so I would suggest you not to visit such websites and mind your business.

Anyway, wish you good luck!


RE: website hacking question. - mothered - 01-25-2019

Just some advice from someone who's been exploiting for over a couple of decades.

Be "very" careful- It's not a game and depending on the nature of your actions, It can be punishable on a federal level.


RE: website hacking question. - darkninja1980 - 01-25-2019

(01-24-2019, 11:29 PM)SneakyBit Wrote: Asking such a question proves you have not the required skills to hack a website, so to start first I would suggest you to learn the basics of web application vulnerabilities and how they are exploited. After that download some vulnerable web applications (DVWA, bWAPP,...) and practice your skills on it. Once you learn all these things and got some practice, only then can you try to hack a web application. BTW I would suggest you not to test web applications for which you have no rights from the admin as it might get you into trouble. Also websites such as CP on the dark net might be set up by the feds to catch pedo's so I would suggest you not to visit such websites and mind your business.

Anyway, wish you good luck!
It not that I have enough knowledge or skills. I was only confused on the dot onion sites. (.onion) I can figure out the hacking on dot com, etc!
yes, I get your point about the feds to make this site. But the sites do make me sick.
(01-25-2019, 03:53 AM)mothered Wrote: Just some advice from someone who's been exploiting for over a couple of decades.

Be "very" careful- It's not a game and depending on the nature of your actions, It can be punishable on a federal level.
Yes, I understand it no games.


RE: website hacking question. - m3zla - 02-17-2019

Use parrotOS, with anon surf. try
`nping -c 1 --tcp site.onion` you can get a real IP adress.
then read here http://seclists(dot)org/nmap-dev/2015/q2/317 and scan site
you can try some onion scanner like onionscann but it's written no GO and i don't like it so i never used it. probably everything else is like any other clear site.
https://github(dot)com/s-rah/onionscan.git
Or if you want do destroy target site use torkill or any other script for DOS/DDOS.
https://github(dot)com/THSamurai/TorKill


RE: website hacking question. - darkninja1980 - 02-17-2019

(02-17-2019, 03:36 PM)m3zla Wrote: Use parrotOS, with anon surf. try
`nping -c 1 --tcp site.onion` you can get a real IP adress.
then read here http://seclists(dot)org/nmap-dev/2015/q2/317 and scan site
you can try some onion scanner like onionscann but it's written no GO and i don't like it so i never used it. probably everything else is like any other clear site.
https://github(dot)com/s-rah/onionscan.git
Or if you want do destroy target site use torkill or any other script for DOS/DDOS.
https://github(dot)com/THSamurai/TorKill

oh okay, thank you for the input.


RE: website hacking question. - PicoMan - 02-18-2019

do not forget to activate hidden surf in parrot os and start every program with proxychains (it routes the program through tor)
e.g.:Terminal --> proxychains msfconsole
Might be safer Wink


RE: website hacking question. - darkninja1980 - 02-18-2019

(02-18-2019, 11:03 AM)PicoMan Wrote: do not forget to activate hidden surf in parrot os and start every program with proxychains (it routes the program through tor)
e.g.:Terminal --> proxychains msfconsole
Might be safer Wink

thanks for the input.


RE: website hacking question. - m3zla - 02-23-2019

(02-18-2019, 11:03 AM)PicoMan Wrote: do not forget to activate hidden surf in parrot os and start every program with proxychains (it routes the program through tor)
e.g.:Terminal --> proxychains msfconsole
Might be safer ;)

not exactly, it routes tor from the box. The config file find it self in
Code:
/etc/proxychains.conf
in the bottom  you can add some proxy (with space between type ip and port, like 'https 1.1.1.1 8080'). When you just install os or boot liveUSB there is only 'socks4 127.0.0.1 9050' - localhost and tor port, if it dose not start try:
Code:
`sudo tor`
You may try, by the way, to create strict chain tor->proxy, just add one proxy in the bottom, use strict chain, and uncomment chain_lan=2 ( just remove # in front of the line) . And you may also uncomment quite mode, to use proxychain without rubbish ( or just type `2>/dev/null` in the end of line, like
Code:
`proxychains random_script 2>/dev/null`
 )
to test proxy connection you may try
Code:
`proxychains curl ifconfig.io`
just finde that site and use it now.
And finally use proxychains-ng it is new version, i install it every time when i sit on live systemproxychains-ng.
bash script to install:
https://ghostbin.com/paste/fdxvc


RE: website hacking question. - darkninja1980 - 02-24-2019

(02-23-2019, 03:15 AM)m3zla Wrote:
(02-18-2019, 11:03 AM)PicoMan Wrote: do not forget to activate hidden surf in parrot os and start every program with proxychains (it routes the program through tor)
e.g.:Terminal --> proxychains msfconsole
Might be safer Wink

not exactly, it routes tor from the box. The config file find it self in
Code:
/etc/proxychains.conf
in the bottom  you can add some proxy (with space between type ip and port, like 'https 1.1.1.1 8080'). When you just install os or boot liveUSB there is only 'socks4 127.0.0.1 9050' - localhost and tor port, if it dose not start try:
Code:
`sudo tor`
You may try, by the way, to create strict chain tor->proxy, just add one proxy in the bottom, use strict chain, and uncomment chain_lan=2 ( just remove # in front of the line) . And you may also uncomment quite mode, to use proxychain without rubbish ( or just type `2>/dev/null` in the end of line, like
Code:
`proxychains random_script 2>/dev/null`
 )
to test proxy connection you may try
Code:
`proxychains curl ifconfig.io`
just finde that site and use it now.
And finally use proxychains-ng it is new version, i install it every time when i sit on live systemproxychains-ng.
bash script to install:
https://ghostbin.com/paste/fdxvc

thank you Smile


RE: website hacking question. - D0R3K - 04-27-2019

(01-17-2019, 09:51 PM)darkninja1980 Wrote: I want to hack some websites on the darkweb. What methods do I need to do in order hacking an onion site?

Succeeded?