What's new

Closed How to hunt payload (hard, normal, and easy way)

Status
Not open for further replies.

Kaidus

Forum Guru
Joined
Jul 16, 2017
Posts
4,112
Reaction
4,459
Points
1,248
Hi guys I put my tutorial here for those anyone who did not see my post and also to my teamates.

First of all I know that maybe or almost don't know how to hunt payload on their own, so I make this tutorial to let others hunt payload (free sites/bug sites) on their own.

I have here hard, normal and easy way to hunt payload


HARD WAY
What you need?
•tPacketCapture
•Pcap app or any app that can open the file
•Download the app on playstore


HARD way to hunt payload, before you're going to hunt payload you need first an app called (tPacketCapture) this app lets you record your local traffic between your Android device and the connected network.

How to use this app, first you need free sites that you know before you need to use this app (e.g facebook(.)com, freebasics and more)

So let's start, first ON your data and search any free sites to surf on, see the picture below;
View attachment 277068
Then open tPacketCapture and click CAPTURE;
View attachment 277069
View attachment 277070
After you click capture, click and click and click the refresh button on the upper right side, just click it then.
View attachment 277072
When you done clicking the refresh button you can see the current file or file in the middle of the app. Let the file reach 100kb,
Then disable the VPN key above.
View attachment 277071
After you disable the VPN key, open the file by clicking the file list. Open the file with pcap app or any app that can open the file.
View attachment 277074
Open the file and scroll, then you see this (refer the picture below) there is host get that host.
View attachment 277075
View attachment 277076

Host (ui.ff.avast.com)
Try to see if that host is working or not by using it on injector as a payload or try to use this site (check-host.net) to know if its working or not.


NORMAL WAY
What you need?
Internet data to surf or just use injector
•Open this site or search it (yougetsignal.com)

You do not have permission to view the full content of this post. Log in or register now.
You Get Signal is a reverse IP domain checker, it let you know what are other/same web server that hosting that site. Just click the remote address and put anything you want (e.g google.com, phcorner.net, freebasics.com, etc).

•Not almost in this site can get what you want to search or to search with the same domian be aware of that, if you didn't get what you want results there will be always alternative WAY
View attachment 277077
Then you can see this (refer the picture below), just pick any domain or site
View attachment 277078
Check if that domain/site is working by using it on injector as a payload or use this site (check-host.net) to check.



EASY WAY
What you need?

•Internet data to surf or just use injector
•Open this site (Configinter.com)

You do not have permission to view the full content of this post. Log in or register now.
After you click that site you can see already payloads that have status, see the picture below
View attachment 277079
 
Last edited:
most easiest way is ask someone if my update ng proxy or payload whatsoever mas easiestest to
 
yeah but its depends on what did you put :)

Kung sabagay. Paki include mo na din ts sa thread mo na may limit para atleast maging aware yung iba. Suggestion lang naman. :)
 
Last edited by a moderator:
Kung sabagay. Paki include mo na din ts sa thread mo na may limit para atleast maging aware yung iba. Suggestion lang naman. :)
That's why there will be always an alternative just like the other WAY i was just put. Ok I will put for them to let know
 
Last edited by a moderator:
Status
Not open for further replies.

Similar threads

Back
Top