Hello Bitcoin talk users!
I have been involved in website / network security for around 5 years now. I spend most of my time working on friends sites and lurking on security forums giving out advice to website owners and security enthusiast. I have recently become interested in crypto and started accepting the currency from clients for coding projects or penetration testing.
One of my customers pointed me to this forum and thought there might be some demand here for my services seeing there seems to be a lot of websites popping up here on a daily basis it made me think "I wonder how many put security at the top of there agenda" So I have come here to offer my services be that website testing, Penetration testing, Data security, PHP, SQL, Frontend/backend work.
I'm also here to sell some of my latest website testing tools!
Perfect for the security aware website owner!
as all website owners know 2016 has been a year of hell for site administrators, with new threats popping up daily its a task to keep on top of latest vulnerability and attack methods!
I also offer a First alert service for website owners. How this works is website owner gives us all the version numbers of software / plugins being used on there site or we can scan there site for this information and to show exactly whats running on your server, We then add this to our database and when updates or upgrades or exploits for those versions become available we alert the owners to either update or remove services until a patch is successfully released.
This gives website owners a little piece of mind that there is someone else keeping a eye out for web nasties and updates to there software or hardware.
Now onto the tools
At the moment I have 2 tools I am selling on the open market.
Everyone knows about cloudflare! and how they are "supposed" to protect the sites real IP from being leaked to hackers.
I have developed a script that can be run to test your website to make sure CF is working correctly and protecting your site. this includes all sub-domains which get looked over and can be the one point of attack for hackers!
The tools can scan in multiple modes.
Mode 1 - DNS Brute-force
This method attempts to Brute-Force the hostnames and all sub-domains on the server. then output's the results to a results.txt file. It is very effective and works on over 70% of CF activated sites I have tested it on.
Mode 2 - Nmap Scan
Attempts to enumerate DNS hostnames by brute force guessing of common subdomains. With the dns-brute.srv argument, dns-brute will also try to enumerate common DNS SRV records.
Mode 3 - Netcraft Toolbar
This mode will check the domain against netcraft records and show hosting history. If a site has been hosted without CF active then the Original IP address sometimes is shown in the hosting history (see example.com record below)
NETBLK-03-EU-93-184-216-0-24 93.184.216.34 unknown ECS iad/182A 23-Dec-2016
NETBLK-03-EU-93-184-216-0-24 93.184.216.34 unknown ECS ewr/15BD 16-Oct-2016
NETBLK-03-EU-93-184-216-0-24 93.184.216.34 Linux ECS ewr/15BD 10-Oct-2016
NETBLK-03-EU-93-184-216-0-24 93.184.216.34 unknown ECS ewr/15BD 12-Sep-2016
NETBLK-03-EU-93-184-216-0-24 93.184.216.34 Linux ECS ewr/15BD 2-Sep-2016
NETBLK-03-EU-93-184-216-0-24 93.184.216.34 unknown ECS ewr/15BD 20-Aug-2016
NETBLK-03-EU-93-184-216-0-24 93.184.216.34 Linux ECS ewr/15BD 18-Aug-2016
NETBLK-03-EU-93-184-216-0-24 93.184.216.34 unknown ECS ewr/15BD 3-Aug-2016
NETBLK-03-EU-93-184-216-0-24 93.184.216.34 Linux ECS ewr/15BD 2-Aug-2016
NETBLK-03-EU-93-184-216-0-24 93.184.216.34 unknown ECS ewr/15BD 1-Aug-2016
Price for this tool is $20 with lifetime update (as methods change so will the script)
SQLMAP GUI Web Interface!
Before anything, this project wouldn't even be possible without the awesome development team behind SQLMAP - hats off to them!
This is a PHP Frontend I made to work with the SQLMAP JSON API Server (sqlmapapi.py) to allow for a Web GUI to drive near full functionality of SQLMAP!
all of your usual SQLMAP command line functionality is still possible via this Web GUI.
Requirements:
Linux, Apache, PHP
PHP 5.3+ is suggested
Python and any SQLMAP dependencies
Price is $25 with lifetime updates as new features are developed.
Below is a screen shot of the GUI
http://postimg.org/image/umtfmfqr5/I am also available for penetration testing work and coding work with very reasonable rates.
Website scanning with XSS / SQLI Testing / Front end only scanning - $60
Website scanning with XSS / SQLI Testing / Front & Back End - $90
Server Protection tuition $20
Other services, Code/Python/C++/PHP/HTML5/HTML/MYSQL/RUBY/JAVA
Virus Removal, Home Network Security, Web Server assistance, Penetration testing,
If you require something that is not listed then please do just ask!
I wish you all a very merry Xmas and I hope you all have a great new year!
Thanks
UGMZ