ghidra-scripts
SecLists
Our great sponsors
ghidra-scripts | SecLists | |
---|---|---|
49 | 177 | |
210 | 53,392 | |
- | - | |
7.0 | 9.6 | |
3 months ago | 4 days ago | |
Java | PHP | |
MIT License | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
ghidra-scripts
- The Hiew Hex Editor
- Okus obratnega inženiringa - naloga 2
-
I've figured out what 13 of the 16 enemy flags mean in Ultima V. Help me figure out the last three.
I've got no experience with reverse-engineering executables, but I got a bunch of code-like stuff showing up when I fed ULTIMA.EXE to Ghidra and told it to analyze it with all the flags set.
- Ask HN: What's the best open source alternative to IDA Pro?
-
I found an old floppy disk, what does this mean/what should I do?
It's likely a binary file that's improperly being interpreted as Unicode by the text editor. If it's an executable file, you can use Ghidra to disassemble and analyze it. There may also be some interesting ASCII strings that would reveal its purpose. My guess is that it's a Windows version of Unix "tee" program which will write stdin to a file and stdout simultaneously.
-
Free Hex Editor
On the other hand, this slick "Ghidra" webpage looks suspicious. It's probably written in Typescript on Electron!
-
Disabling a pointless hardware check in an old DOS EXE
A free, open source alternative: https://ghidra-sre.org
In case you decide to reverse engineer the .exe you might want to check out Ghidra. It runs on both Windows and Linux and is similar to IDA.
-
What are some good resources to learn about reverse engineering and computer architecture?
Ghidra
- Is IDA-deblugger availabe on the Void linux platform?
SecLists
-
What's the problem with my API?
Maybe swagger.txt
-
I had a machine running for two weeks on the public cloud. Every few seconds there was an automated SSH login attempt. Here is the full list of usernames - some of which are quite curious.
Typical of the sorts of information a tester/attacker might be using from: Daniel Miessler's SecLists
-
[OC] I updated our famous password table for 2023
Oh, and then you have this.
-
Join Celebrations! Appwrite 1.3 Ships Relationships
You can now also enable a rule for password dictionary. Appwrite knows what are the most common passwords, and with this rule enabled, it will not allow you users to set any of those passwords. It prevents your users from having passwords like password, 123456678, or qwertyui. Appwrite currently knows the 10,000 most commonly used passwords thanks to the same list used by other industry-leading auth providers. You can check out the dictionary list on GitHub.
-
Generating Passphrases Using Nonsense Words?
You could even take a list of the 100,000 most common passwords, and create a virtually uncrackable passphrase simply by combining 3 words that have been randomly selected from that list.
- cómo empezar en seguridad informática
-
The new type of SQL injection
Pro tip: just compound like 30 ashley madison leaked passwords for a super password.
-
Bruteforcing Firefox logins.json key4.db
If you need larger password lists ---> https://github.com/danielmiessler/SecLists
-
i created a cpanel bruteforce tool
Then add in a few default lists from SecLists Passwords dir and Usernames dir
-
word lists
Just out of curiosity... Isn't the directory titled "/seclists/", within the directory /use/share/wordlists/ the same as what's at danielmiessler / SecLists?
What are some alternatives?
Probable-Wordlists - Version 2 is live! Wordlists sorted by probability originally created for password generation and testing - make sure your passwords aren't popular!
gobuster - Directory/File, DNS and VHost busting tool written in Go
big-list-of-naughty-strings - The Big List of Naughty Strings is a list of strings which have a high probability of causing issues when used as user-input data.
wpscan - WPScan WordPress security scanner. Written for security professionals and blog maintainers to test the security of their WordPress websites. Contact us via [email protected]
btcrecover - An open source Bitcoin wallet password and seed recovery tool designed for the case where you already know most of your password/seed, but need assistance in trying different possible combinations.
english-words - :memo: A text file containing 479k English words for all your dictionary/word-based projects e.g: auto-completion / autosuggestion
naive-hashcat - Crack password hashes without the fuss :cat2:
rockyou2021
403fuzzer - Fuzz 403/401ing endpoints for bypasses
passfault - OWASP Passfault evaluates passwords and enforces password policy in a completely different way.
zxcvbn - Low-Budget Password Strength Estimation
SQLMap - Automatic SQL injection and database takeover tool