Welcome to HBH! If you had an account on hellboundhacker.org you will need to reset your password using the Lost Password system before you will be able to login.

Phone number


root72's Avatar
Banned
0 0

Do you know how can i get someone's phone number by knowing his facebook account or his tweet account?


pawnflow's Avatar
Member
0 0

The website gobzi linked to had an XSS vulnerability and redirected you to a malicious site. I copy pasted the blog's content and pasted it onto my website.

Check it out here:

https://goo.gl/q3eybn

TLDR: Basically, there's a really good guide written by some security researchers at Carnegie-Mellon. But to prevent bots from just randomly crawling into their servers, they created a card game which you must reverse engineer and hack to access the guide. To connect, type "nc shell2017.picoctf.com 5194" then you will be directed to the challenge. Once you solved it, type "cd ../../documents/research/results" to get to the folder where the guide is located. Finally, then type "cat ios_cve_427_2008_vuln.pdf" to read it. It's a little complicated to explain the instructions in the document but basically you have to set up a Pineapple to log their IPs then download a few other tools to jailbreak the phone and finally crack their account password. Note that since the guide in from 2008, it may not work on newer Facebook or Twitter anymore. But you can try.


pawnflow's Avatar
Member
0 0

Wait I just realized I used my old XSS website for CTFs. It's still named cookiesteal but I removed the contents. So If you clicked on it, it doesn't steal cookies.