Wapiti –Web Applications Security Auditing Framework

Wapiti – Web Applications Security Auditing Framework

Wapiti is a vulnerability assessment framework that performs black box security auditing of the web applications. The vulnerabilities that can be assessed with Wapiti include database injections, Local File Inclusion (LFI), Remote File Inclusion (RFI), command execution, CRLF injection, Server Side Request Forgery (SSRF), XML External Entity (XXE) injection, Shellshock bugs, .htaccess attacks, and source…

Read More
pureblood tool

Pureblood Tool – web Application Penetration Testing

Pureblood  Information Gathering and Security Auditing Tool Pureblood is a Python tool that can be used during the information gathering and gaining access phases of penetration testing. Pureblood can collect useful information about target web applications, such as Banner grabbing, WHOIS record, DNS data, reverse DNS lookup, reverse IP lookup, CMS information, ports information, admin panel paths, subdomain scan…

Read More
CVE-2021-44228-Log4j-Log4Shell

Multiple Nation-State actors are exploiting Log4Shell flaw

China, Iran, North Korea and Turkey’s nation-state actors are trying to exploit log4shell vulnerability in the attacks. Microsoft researchers said that the nation-state actor of China, Iran, North Korea and Turkey are now misusing Log4shell (CVE-2021-44228) in the Log4J Library in their campaigns. Some groups who exploited vulnerability are phosphorus related to China and Iran,…

Read More
Magecart group

New Magecart group uses an e-Skimmer that avoids VMs and sandboxes

A new Magecart group leverages a browser script to evade virtualized environments and sandboxes used by researchers. Malwarebytes researchers have spotted a new Magecart group that uses a browser script to evade detection and the execution in virtualized environments used by security researchers for threat analysis. Hacker groups under the Magecart umbrella continue to target e-stores to steal payment…

Read More
Super Stealthy Backdoor Spreads To Hit Hundreds Of Thousands Of Web Users

Super Stealthy Backdoor Spreads To Hit Hundreds Of Thousands Of Web Users

Backdoor Spreads To Hit Hundreds Of Thousands Of Web Users || One of the most sophisticated web server backdoors ever seen has spread fast and is now sitting on hundreds of webservers running some of the most popular websites in the world, researchers have warned. One expert told TechWeekEurope the Cdorked backdoor, brought to light in April, is almost…

Read More
8 Things That Anonymous, The Hacker 'Terrorist' Group, Has Done For Good

8 Things That Anonymous, The Hacker ‘Terrorist’ Group, Has Done For Good

It’s easy to think of the hacking group  Anonymous  as a group of punk troublemakers, raising hell online. Some have even debated  whether their extra-legal protests should be labeled terrorist acts . But that would overlook some of the genuinely good deeds the group – whose members identify themselves with the  Vendetta mask  – has done. Whether it’s retaliating against kiddie…

Read More