GithubHelp home page GithubHelp logo

wh1t3-e4gl3 / white-deface Goto Github PK

View Code? Open in Web Editor NEW
130.0 3.0 43.0 93 KB

This is a simple python tool to automatically deface webdav vulnerable websites.

License: Apache License 2.0

Python 100.00%
deface deface-tools deface-website defacement defacer hacking web-deface web-hacking website-defacement website-hack

white-deface's Introduction

Typing SVG

"I will not post any high level/complicated and explict programs or content here because all the contents in my account is intended simply for educational purpose only and the aim is every one will understand the scripts i post so i tried to keep it simple as much as i can and provide explanation of each code. each of them will be simple implementations, so that everyone can understand the aspects."

WH1T3-E4GL3 TryHackMe


GitHub Streak

 WH1T3-E4GL3

  • 👋 Hi, I’m Sethu Satheesh
  • 👀 I’m interested in ethical hacking
  • 🌱 I’m currently learning a lot of things🥵
  • 💞️ I’m looking to collaborate on google🤭
  • 📫 How to reach me : https://www.instagram.com/whxitte (Instagram me [Not for any hacking services])

white-deface's People

Contributors

arvindshivanshu avatar wh1t3-e4gl3 avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar

white-deface's Issues

Deleted dependency detected

I'm a Cyber Security researcher and developer of PackjGuard [1] to address open-source software supply chain attacks.

Issue

During my research, I found that this repo is vulnerable to attack due to missing deleted dependency from the public PyPI registry.

Details

Specifically, file https://github.com/WH1T3-E4GL3/white-deface/blob/97c47d6f4cf7c00abe4e446b80446e626f6f3b7f/requirements.txt lists crackmapexec as one of the dependencies. However, it has been deleted from public PyPI. As such, an external bad actor can claim that name and register a malicious package, which will be then installed with pip install command, resulting in arbitrary remote code execution.

Impact

Not only your apps/services using https://github.com/WH1T3-E4GL3/white-deface repo code are vulnerable to this attack, but the users of your open-source Github repo could also fall victim.

You could read more about such attacks here: https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610

Remediation

Please manually register a placeholder crackmapexec package on PyPI immediately or remove crackmapexec dependency from https://github.com/WH1T3-E4GL3/white-deface/blob/97c47d6f4cf7c00abe4e446b80446e626f6f3b7f/requirements.txt to fix this vulnerability.

To automatically fix such issues in future, please install PackjGuard Github app [1].

Thanks!

  1. PackjGuard is a Github app that monitors your repos 24x7, detects vulnerable/malicious/risky open-source dependencies, and creates pull requests for auto remediation: https://github.com/marketplace/packjguard

i appreciate your message for script kiddies :)

Great to see your contribution! It's important to remember that the original creator put in a lot of effort to make this project. So, let's give credit where it's due and ensure our contributions benefit the entire community. You can add your improvements to the original repository as a pull request: Original link . Please, let's avoid simply copying and pasting. Thanks for understanding! 😊

Deface issue

Hey brother please help me the tool white deface is not working please answer

Deleted dependency detected

I'm a Cyber Security researcher and developer of PackjGuard [1] to address open-source software supply chain attacks.

Issue

During my research, I found that this repo is vulnerable to attack due to deleted dependency from the public PyPI registry.

Details

Specifically, file https://github.com/WH1T3-E4GL3/white-deface/blob/e112d87d290f18eee83dc4425c9b5f02178ec61e/requirements.txt lists sinchsms as one of the dependencies. However, it has been deleted from public PyPI. As such, an external bad actor can claim that name and register a malicious package, which will be then installed with pip install command, resulting in arbitrary remote code execution.

Impact

Not only your apps/services using https://github.com/WH1T3-E4GL3/white-deface repo code are vulnerable to this attack, but the users of your open-source Github repo could also fall victim.

You could read more about such attacks here: https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610

Remediation

Please manually register a placeholder sinchsms package on PyPI immediately or remove sinchsms dependency from https://github.com/WH1T3-E4GL3/white-deface/blob/e112d87d290f18eee83dc4425c9b5f02178ec61e/requirements.txt to fix this vulnerability.

To automatically fix such issues in future, please install PackjGuard Github app [1].

Thanks!

  1. PackjGuard is a Github app that monitors your repos 24x7, detects vulnerable/malicious/risky open-source dependencies, and creates pull requests for auto remediation: https://github.com/marketplace/packjguard

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.