Finding SSL Certificates:
Certdomainfinder https://github.com/amar-
myana/certdomainfinder/blob/master/README.md
Certgraph https://github.com/lanrat/certgraph
Certificate Search https://crt.sh
CERT Spotter https://sslmate.com/certspotter/api
Google Transparency Report:
Certificates
https://transparencyreport.google.com/https/certific
ates
Internet-Wide Scan Data
Repository
https://scans.io
OpenData Rapid7 https://opendata.rapid7.com
Purplepee.com https://purplepee.co
spyse_ SSL Lookup https://spyse.com/tools/ssl-lookup
Certdomainfinder https://github.com/amar-
myana/certdomainfinder/blob/master/README.md
Certgraph https://github.com/lanrat/certgraph
Certificate Search https://crt.sh
CERT Spotter https://sslmate.com/certspotter/api
Google Transparency Report:
Certificates
https://transparencyreport.google.com/https/certific
ates
Internet-Wide Scan Data
Repository
https://scans.io
OpenData Rapid7 https://opendata.rapid7.com
Purplepee.com https://purplepee.co
spyse_ SSL Lookup https://spyse.com/tools/ssl-lookup
Exploit Search Engines:
CVE Circl.lu https://cve.circl.lu
CVE Details https://www.cvedetails.com
CVE Mitre https://cve.mitre.org
Exploit-db https://www.exploit-db.com
Exploit Search https://exploitsearch.com
NMMapper https://www.nmmapper.com
Rapid7 https://www.rapid7.com/db
Shodan Exploits https://exploits.shodan.io
Sploitus https://sploitus.com
Vulmon https://vulmon.com
Vulnerability Assessment
Platform
https://vulners.com/landing
WPScan Wordpress
Vulnerability Database
https://wpvulndb.com
CVE Circl.lu https://cve.circl.lu
CVE Details https://www.cvedetails.com
CVE Mitre https://cve.mitre.org
Exploit-db https://www.exploit-db.com
Exploit Search https://exploitsearch.com
NMMapper https://www.nmmapper.com
Rapid7 https://www.rapid7.com/db
Shodan Exploits https://exploits.shodan.io
Sploitus https://sploitus.com
Vulmon https://vulmon.com
Vulnerability Assessment
Platform
https://vulners.com/landing
WPScan Wordpress
Vulnerability Database
https://wpvulndb.com
cve.circl.lu
Vulnerability-Lookup
Vulnerability-Lookup - Fast vulnerability lookup correlation from different sources.
clawhub.py
29.1 KB
Claw Guard — ClawHub Skill Security Scanner v2
v2 improvements:
▶️ Context-aware analysis: distinguishes "uses .env" vs "steals .env"
▶️ Well-known application ports whitelisted (Radarr, Sonarr, Plex, etc.)
▶️ Self-scan exclusion (scanner ignores its own detection patterns)
▶️ Smarter risk scoring: only counts real threats, not documentation
▶️ False positive tags: findings can be marked as likely FP with explanation
▶️ VT threshold: 1 detection on 90+ engines = not CRITICAL
Usage:
Scans OpenClaw skill directories for malware, prompt injection, data exfiltration, and other security threats.
v2 improvements:
Usage:
python3 scan_skill.py <skill_path>
python3 scan_skill.py --batch <path1> <path2> ...
python3 scan_skill.py --json <skill_path>
python3 scan_skill.py --vt <skill_path>
python3 scan_skill.py --vt --vt-key <api_key> <skill_path>
python3 scan_skill.py --vt --no-upload <skill_path>
Please open Telegram to view this post
VIEW IN TELEGRAM
👍1
telegraph malware.py
6.3 KB
What this malware is doing
In this case, the malware fetches a fixed URL:
https://telegra.ph/3657468-10-13
It then parses the HTML and looks specifically for this tag:
<meta property="og:description" content="...">
The value of
og:description is expected to contain Base64-encoded data, which is then XOR-decrypted to produce the actual C2 host (IP or domain).How it works step by step
The malware performs a normal HTTPS GET request to telegra.ph, a domain that is:
Rather than parsing the visible page body, the malware reads the Open Graph metadata (
og:description), which is usually ignored by scanners.HOSTcontent="1"), the resolver breaksWhy attackers use Telegraph for this
This technique is intentionally designed for resilience and stealth:
This malware component functions as:
Please open Telegram to view this post
VIEW IN TELEGRAM
👍1
Echidna — это инструмент для проведения фаззинга смарт контрактов, который предоставляет возможность автоматического тестирования контрактов на наличие уязвимостей и ошибок.
— Данный инструмент создает и запускает тестовые смарт контракты, которые позволяют исследовать различные пути выполнения смарт контракта и выявить потенциальные уязвимости.
#Vulnerability #Fuzzing #Web3
Please open Telegram to view this post
VIEW IN TELEGRAM
❤2
Делаем из YouTube файлоПомойку + encrypt --password
*
файлы до 256 GB
*
download SOFT
*
Дальше пишем бота для MAX который как CI/CD зальет артефакты на rutube
*
файлы до 256 GB
*
download SOFT
*
Дальше пишем бота для MAX который как CI/CD зальет артефакты на rutube
AURA
=> https://github.com/Oxule/Aura
AURA is a decentralized messenger leveraging Nearby Connections technology to create robust mesh networks. It thrives where the internet fails, bypassing censorship and eliminating central points of failure.
✨ Key Features
🌐 Offline Mesh: Powered by Bluetooth and Wi-Fi Direct. Messages hop from device to device seamlessly.
🎭 The Aura: A unique digital identity concept. Your specific color, icon, and behavior patterns form your "Aura" within the network.
🔐 Total Privacy: End-to-End (E2E) encryption for all data. Complete anonymity: messages are injected into a shared distributed ledger without sender or recipient metadata.
🛡 Flood Protection: Smart architecture designed to mitigate "Blackhole" and flood-based attacks.
🎨 Modern UI/UX: A smooth, intuitive interface that bridges the gap between high security and everyday usability.
=> https://github.com/Oxule/Aura
AURA is a decentralized messenger leveraging Nearby Connections technology to create robust mesh networks. It thrives where the internet fails, bypassing censorship and eliminating central points of failure.
✨ Key Features
🌐 Offline Mesh: Powered by Bluetooth and Wi-Fi Direct. Messages hop from device to device seamlessly.
🎭 The Aura: A unique digital identity concept. Your specific color, icon, and behavior patterns form your "Aura" within the network.
🔐 Total Privacy: End-to-End (E2E) encryption for all data. Complete anonymity: messages are injected into a shared distributed ledger without sender or recipient metadata.
🛡 Flood Protection: Smart architecture designed to mitigate "Blackhole" and flood-based attacks.
🎨 Modern UI/UX: A smooth, intuitive interface that bridges the gap between high security and everyday usability.
Please open Telegram to view this post
VIEW IN TELEGRAM
Ceno Browser v2.8.2
=> https://censorship.no/ru/index.html
=> https://github.com/censorship-no/ceno-browser/releases
CENO (сокращенно от Censorship.no!) — это мобильный веб-браузер, использующий новый способ обхода цензуры в интернете, что позволяет пользователям, живущим в зоне цензуры, обмениваться полученным контентом друг с другом в пиринговой (p2p) сети.
Changelog:
=> https://github.com/ceno-app/ceno-android/releases/tag/v2.8.2
=> https://censorship.no/ru/index.html
=> https://github.com/censorship-no/ceno-browser/releases
CENO (сокращенно от Censorship.no!) — это мобильный веб-браузер, использующий новый способ обхода цензуры в интернете, что позволяет пользователям, живущим в зоне цензуры, обмениваться полученным контентом друг с другом в пиринговой (p2p) сети.
Changelog:
=> https://github.com/ceno-app/ceno-android/releases/tag/v2.8.2
GitHub
Releases · ceno-app/ceno-android
A full-featured CENO browser reference implementation using Mozilla Android Components + Ouinet - ceno-app/ceno-android
This media is not supported in your browser
VIEW IN TELEGRAM
Alt-sendme — отправляйте файлы и папки в любую точку мира без хранения в облаке — любой размер, любой формат, без аккаунтов и ограничений.
Бесплатный инструмент для передачи файлов с открытым исходным кодом, использующий возможности передовой одноранговой сети, позволяет передавать файлы напрямую, не сохраняя их на облачных серверах.
🐱 GitHub
Бесплатный инструмент для передачи файлов с открытым исходным кодом, использующий возможности передовой одноранговой сети, позволяет передавать файлы напрямую, не сохраняя их на облачных серверах.
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
👍3❤1🥰1 1
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
Скачать данные сервиса можно отсюда https://ip.thc.org/docs/bulk-data-access. Они обновляются в конце каждого месяца.
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM