August 31, 2020

Why (I Believe) WADA Was Not Hacked By The Russians

Disclaimer: This is my personal opinion. I am not an expert in attribution. But as it turns out, not many people in the world are good at attribution. I know this post lacks real evidence and is mostly based on speculation.



Let's start with the main facts we know about the WADA hack, in chronological order:


1. Some point in time (August - September 2016), the WADA database has been hacked and exfiltrated
2. August 15th, "WADA has alerted their stakeholders that email phishing scams are being reported in connection with WADA and therefore asks its recipients to be careful"  https://m.paralympic.org/news/wada-warns-stakeholders-phishing-scams
3. September 1st, the fancybear.net domain has been registered
   Domain Name: FANCYBEAR.NET
...
Updated Date: 18-sep-2016
Creation Date: 01-sep-2016
4. The content of the WADA hack has been published on the website
5. The @FancyBears and @FancyBearsHT Twitter accounts have been created and started to tweet on 12th September, reaching out to journalists
6. 12th September, Western media started headlines "Russia hacked WADA"
7. The leaked documents have been altered, states WADA https://www.wada-ama.org/en/media/news/2016-10/cyber-security-update-wadas-incident-response


The Threatconnect analysis

The only technical analysis on why Russia was behind the hack, can be read here: https://www.threatconnect.com/blog/fancy-bear-anti-doping-agency-phishing/

After reading this, I was able to collect the following main points:

  1. It is Russia because Russian APT groups are capable of phishing
  2. It is Russia because the phishing site "wada-awa[.]org was registered and uses a name server from ITitch[.]com, a domain registrar that FANCY BEAR actors recently used"
  3. It is Russia because "Wada-arna[.]org and tas-cass[.]org were registered through and use name servers from Domains4bitcoins[.]com, a registrar that has also been associated with FANCY BEAR activity."
  4. It is Russia, because "The registration of these domains on August 3rd and 8th, 2016 are consistent with the timeline in which the WADA recommended banning all Russian athletes from the Olympic and Paralympic games."
  5. It is Russia, because "The use of 1&1 mail.com webmail addresses to register domains matches a TTP we previously identified for FANCY BEAR actors."

There is an interesting side-track in the article, the case of the @anpoland account. Let me deal with this at the end of this post.

My problem with the above points is that all five flag was publicly accessible to anyone as TTP's for Fancy Bear. And meanwhile, all five is weak evidence. Any script kittie in the world is capable of both hacking WADA and planting these false-flags.

A stronger than these weak pieces of evidence would be:

  • Malware sharing same code attributed to Fancy Bear (where the code is not publicly available or circulating on hackforums)
  • Private servers sharing the IP address with previous attacks attributed to Fancy Bear (where the server is not a hacked server or a proxy used by multiple parties)
  • E-mail addresses used to register the domain attributed to Fancy Bear
  • Many other things
For me, it is quite strange that after such great analysis on Guccifer 2.0, the Threatconnect guys came up with this low-value post. 


The fancybear website

It is quite unfortunate that the analysis was not updated after the documents have been leaked. But let's just have a look at the fancybear . net website, shall we?

Now the question is, if you are a Russian state-sponsored hacker group, and you are already accused of the hack itself, do you create a website with tons of bears on the website, and do you choose the same name (Fancy Bear) for your "Hack team" that is already used by Crowdstrike to refer to a Russian state-sponsored hacker group? Well, for me, it makes no sense. Now I can hear people screaming: "The Russians changed tactics to confuse us". Again, it makes no sense to change tactics on this, while keeping tactics on the "evidence" found by Threatconnect.

It makes sense that a Russian state-sponsored group creates a fake persona, names it Guccifer 2.0, pretends Guccifer 2.0 is from Romania, but in the end it turns out Guccifer 2.0 isn't a native Romanian speaker. That really makes sense.

What happens when someone creates this fancybear website for leaking the docs, and from the Twitter account reaches out to the media? Journalists check the website, they see it was done by Fancy Bear, they Bing Google this name, and clearly see it is a Russian state-sponsored hacker group. Some journalists also found the Threatconnect report, which seems very convincing for the first read. I mean, it is a work of experts, right? So you can write in the headlines that the hack was done by the Russians.

Just imagine an expert in the USA or Canada writing in report for WADA:
"the hack was done by non-Russian, but state-sponsored actors, who planted a lot of false-flags to accuse the Russians and to destroy confidence in past and future leaks". Well, I am sure this is not a popular opinion, and whoever tries this, risks his career. Experts are human, subject to all kinds of bias.

The Guardian

The only other source I was able to find is from The Guardian, where not just one side (it was Russia) was represented in the article. It is quite unfortunate that both experts are from Russia - so people from USA will call them being not objective on the matter. But the fact that they are Russian experts does not mean they are not true ...

https://www.theguardian.com/sport/2016/sep/15/fancy-bears-hackers--russia-wada-tues-leaks

Sergei Nikitin:
"We don't have this in the case of the DNC and Wada hacks, so it's not clear on what basis conclusions are being drawn that Russian hackers or special services were involved. It's done on the basis of the website design, which is absurd," he said, referring to the depiction of symbolically Russian animals, brown and white bears, on the "Fancy Bears' Hack Team" website.

I don't agree with the DNC part, but this is not the topic of conversation here.

Alexander Baranov:
"the hackers were most likely amateurs who published a "semi-finished product" rather than truly compromising information. "They could have done this more harshly and suddenly," he said. "If it was [state-sponsored] hackers, they would have dug deeper. Since it's enthusiasts, amateurs, they got what they got and went public with it.""

The @anpoland side-track

First please check the tas-cas.org hack https://www.youtube.com/watch?v=day5Aq0bHsA  , I will be here when you finished it. This is a website for "Court of Arbitration for Sport's", and referring to the Threatconnect post, "CAS is the highest international tribunal that was established to settle disputes related to sport through arbitration. Starting in 2016, an anti-doping division of CAS began judging doping cases at the Olympic Games, replacing the IOC disciplinary commission." Now you can see why this attack is also discussed here.


  • My bet is that this machine was set-up for these @anpoland videos only. Whether google.ru is a false flag or it is real, hard to decide. It is interesting to see that there is no google search done via google.ru, it is used only once. 
  • The creator of the video can't double click. Is it because he has a malfunctioning mouse? Is it because he uses a virtualization console, which is near-perfect OPSEC to hide your real identity? My personal experience is that using virtualization consoles remotely (e.g. RDP) has very similar effects to what we can see on the video. 
  • The timeline of the Twitter account is quite strange, registered in 2010
  • I agree with the Threatconnect analysis that this @anpoland account is probably a faketivist, and not an activist. But who is behind it, remains a mystery. 
  • Either the "activist" is using a whonix-like setup for remaining anonymous, or a TOR router (something like this), or does not care about privacy at all. Looking at the response times (SQLmap, web browser), I doubt this "activist" is behind anything related to TOR. Which makes no sense for an activist, who publishes his hack on Youtube. People are stupid for sure, but this does not add up. It makes sense that this was a server (paid by bitcoins or stolen credit cards or whatever) rather than a home computer.
For me, this whole @anpoland thing makes no sense, and I think it is just loosely connected to the WADA hack. 

The mysterious Korean characters in the HTML source

There is another interesting flag in the whole story, which actually makes no sense. When the website was published, there were Korean characters in HTML comments. 



When someone pointed this out on Twitter, these Korean HTML comments disappeared:
These HTML comments look like generated HTML comments, from a WYSIWYG editor, which is using the Korean language. Let me know if you can identify the editor.

The Russians are denying it

Well, what choice they have? It does not matter if they did this or not, they will deny it. And they can't deny this differently. Just imagine a spokesperson: "Previously we have falsely denied the DCC and DNC hacks, but this time please believe us, this wasn't Russia." Sounds plausible ...

Attribution

Let me sum up what we know:

It makes sense that the WADA hack was done by Russia, because:

  1. Russia being almost banned from the Olympics due to doping scandal, it made sense to discredit WADA and US Olympians
  2. There are multiple(weak) pieces of evidence which point to Russia
It makes sense that the WADA hack was not done by  Russia, because: 
  1. By instantly attributing the hack to the Russians, the story was more about to discredit Russia than discrediting WADA or US Olympians.
  2. In reality, there was no gain for Russia for disclosing the documents. Nothing happened, nothing changed, no discredit for WADA. Not a single case turned out to be illegal or unethical.
  3. Altering the leaked documents makes no sense if it was Russia (see update at the end). Altering the leaked documents makes a lot of sense if it was not Russia. Because from now on, people can always state "these leaks cannot be trusted, so it is not true what is written there". It is quite cozy for any US organization, who has been hacked or will be hacked. If you are interested in the "Russians forging leaked documents" debate, I highly recommend to start with this The Intercept article
  4. If the Korean characters were false flags planted by the Russians, why would they remove it? If it had been Russian characters, I would understand removing it.
  5. All evidence against Russia is weak, can be easily forged by even any script kittie.

I don't like guessing, but here is my guess. This WADA hack was an operation of a (non-professional) hackers-for-hire service, paid by an enemy of Russia. The goal was to hack WADA, leak the documents, modify some contents in the documents, and blame it all on the Russians ...

Questions and answers

  • Was Russia capable of doing this WADA hack? Yes.
  • Was Russia hacking WADA? Maybe yes, maybe not.
  • Was this leak done by a Russian state-sponsored hacker group? I highly doubt that.
  • Is it possible to buy an attribution-dice where all six-side is Russia? No, it is sold-out. 

To quote Patrick Gray: "Russia is the new China, and the Russians ate my homework."©

Let me know what you think about this, and please comment. 

Related news
  1. Hacking Tools Software
  2. Hacking Tools Usb
  3. Hacking Tools Online
  4. Pentest Box Tools Download
  5. Blackhat Hacker Tools
  6. Hack Tools Online
  7. Pentest Tools Github
  8. Hacking Tools Mac
  9. Android Hack Tools Github
  10. Pentest Tools Android
  11. Hack Tools For Pc
  12. Bluetooth Hacking Tools Kali
  13. Pentest Tools Android
  14. Hacking Tools For Windows
  15. Pentest Tools Github
  16. Physical Pentest Tools
  17. Hacker Tool Kit
  18. Hacker Tools Online
  19. Ethical Hacker Tools
  20. Pentest Tools Linux
  21. Hacking Apps
  22. How To Make Hacking Tools
  23. Hacking Apps
  24. Pentest Tools Open Source
  25. Beginner Hacker Tools
  26. Bluetooth Hacking Tools Kali
  27. Hacking Tools Hardware
  28. Hack Tools For Pc
  29. Hack App
  30. Tools For Hacker
  31. Hack Tools Download
  32. Nsa Hack Tools Download
  33. Hacking Tools Online
  34. Pentest Tools Port Scanner
  35. Underground Hacker Sites
  36. Pentest Tools Kali Linux
  37. What Are Hacking Tools
  38. Hack Website Online Tool
  39. Pentest Tools For Windows
  40. Hacker Tools Windows
  41. Pentest Tools List
  42. Hacking Tools 2019
  43. Hacking Tools For Windows 7
  44. Pentest Recon Tools
  45. Pentest Tools Website Vulnerability
  46. Pentest Tools Framework
  47. Pentest Tools Website Vulnerability
  48. Nsa Hacker Tools
  49. Wifi Hacker Tools For Windows
  50. Hacking Tools 2019
  51. Hacking Tools Pc
  52. Hacker Tools Free Download
  53. Hacking Apps
  54. Hacker Tools Free
  55. Game Hacking
  56. Underground Hacker Sites
  57. Hacker Tools For Ios
  58. Kik Hack Tools

August 30, 2020

OWASP Web 2.0 Project Update

Some of you likely recall the talk back in 2016 or so of updating the OWASP Foundation website to not appear so much like a...well, a wiki.  That talk was carried forward into 2017 and 2018 and, with each year, the proposal got pushed ahead as there were other, deeper projects to tackle.  With the arrival of 2019 and a firm project plan under the guidance of Mike McCamon, Executive Director, we are finally moving toward a functioning, modern website that will be a whole lot less...wiki-like.  The journey has been circuitous and, while we are not anywhere near complete, we have a set plan in place to bring it to fruition within the calendar year (second quarter of the year, actually).

TLDR: How Can You Help? 

There are certainly ways in which you can get involved now.  For instance, we are looking for a clean way to get wiki pages into GitHub markdown format for archival.  I have done some work here but there are parsing issues with some of the tools.  Do you know a good tool or have you done similar work?  Also, are you or do you know a good designer, someone familiar with GitHub pages that can provide some useful help and feedback along the way?  A Jekyll expert to help code a theme with a handful of templates would be a great addition.  In addition, we could use website server admins who could help with assigning redirects to maintain search integrity.  Finally, there will be a great many pages to move that we will also eventually need community involvement in.  

So, What Have We Done? 

Thus far we have researched various ideas for standing up a new site, including modifying the current wiki, spinning up our own web server, contracting a third party to host and build a new site, and also using existing infrastructure with our own content to launch a new face for OWASP.  Our discussions led us to a familiar place, one that nearly every developer in the OWASP space is familiar with: GitHub.   

In our conversations with GitHub, it became readily apparent that using the platform would be a win for the Foundation as well as GitHub.  Nearly everyone who runs a project at OWASP (documentation or otherwise) uses GitHub.  Because our target audience is also mostly developers we know that they are also very comfortable with the platform.  And while GitHub has a number of high profile companies using their GitHub Pages, the use of the platform as the basis for the entire website of the number one non-profit foundation in the application security sector is a big draw.

We have run with that GitHub Pages idea and have spent internal manpower on a proof of concept.  This proof of concept is less about the UX of the site than the functionality, the ability to utilize the authentication systems, and the ability to utilize automation to push out changes quickly.

Where Are We Now?

We are doing the final stages of website architecture. We are also planning what needs to be in the site, how the pieces will integrate with current projects and chapters, and how we might utilize the community to integrate the pieces so that we have a visually and functionally cohesive website that spans across multiple repositories.

What Is Next?

We will soon be looking for a modern website design that is responsive and clean.  We will begin using the knowledge gained from our proof of concept to build out the internals of the website and then we will start implementing the highest traffic pages and administrative areas into the new platform.  Once we have the big-ticket items moved we will start looking at what is left and moving over those pieces.  The eventual goal would be to have a new, modern website for the future of OWASP while keeping the wiki as an archive of really useful information.


We hope you are as excited as we are about the future of the OWASP Foundation website and will join us as we move toward a modern web presence.  If you have any questions or would like to volunteer your time, experience or knowledge, please contact me at harold.blankenship@owasp.com

More articles


  1. Hacker Tools Free
  2. Pentest Tools Website Vulnerability
  3. Android Hack Tools Github
  4. Hacker Tools For Windows
  5. Pentest Tools For Windows
  6. Termux Hacking Tools 2019
  7. New Hacker Tools
  8. Hacker Tools Apk
  9. Nsa Hack Tools Download
  10. Hacking Tools Name
  11. Hacking Tools For Beginners
  12. Hacking Tools Name
  13. Pentest Tools Alternative
  14. Hackrf Tools
  15. Hacker Tools 2020
  16. Hack Tools Download
  17. Hak5 Tools
  18. Install Pentest Tools Ubuntu
  19. Hack Tool Apk No Root
  20. Computer Hacker
  21. Hack Tool Apk No Root
  22. Hack App
  23. Pentest Tools Url Fuzzer
  24. Pentest Tools For Ubuntu
  25. Pentest Tools Framework
  26. Kik Hack Tools
  27. Hacker Tools 2020
  28. Tools For Hacker
  29. Hacker Hardware Tools
  30. Hack Rom Tools
  31. Hacking Tools Pc
  32. Pentest Tools For Ubuntu
  33. Hacker Tools Free
  34. Easy Hack Tools
  35. Android Hack Tools Github
  36. Pentest Tools Subdomain
  37. Blackhat Hacker Tools
  38. Physical Pentest Tools
  39. Pentest Tools Github
  40. Pentest Recon Tools
  41. Pentest Tools Subdomain
  42. Hacking Tools 2019
  43. Hack Tools
  44. Hacking Tools Name
  45. Best Hacking Tools 2020
  46. Hacker Tools Free
  47. Hack Tools For Windows
  48. Pentest Tools Port Scanner
  49. Physical Pentest Tools
  50. Hacker Tools For Mac
  51. Hacker Tools Hardware
  52. Hacking Tools Usb
  53. Pentest Recon Tools
  54. Hacker Tools List
  55. Hacker Search Tools
  56. Hacking Tools Online
  57. Pentest Recon Tools
  58. Hack Tools Online
  59. Pentest Tools List
  60. New Hack Tools
  61. Hacking Tools Online
  62. Hacking Tools Pc
  63. Hacking Tools Software
  64. Hack Tools
  65. Hack And Tools
  66. Beginner Hacker Tools
  67. Pentest Recon Tools
  68. Tools Used For Hacking
  69. Pentest Tools Url Fuzzer
  70. Hacker Tools 2020
  71. Github Hacking Tools
  72. Nsa Hack Tools Download
  73. Hacking Tools For Games
  74. Best Hacking Tools 2019
  75. Hacking Tools Software
  76. Usb Pentest Tools
  77. Nsa Hacker Tools
  78. Hack Tools Pc
  79. Hacker Tools Free Download
  80. Hacker Security Tools
  81. Tools For Hacker
  82. Hacking Tools Software
  83. Hacker Tools Apk Download
  84. Pentest Tools Github
  85. Pentest Tools Linux
  86. Black Hat Hacker Tools
  87. Best Hacking Tools 2019
  88. Pentest Tools Bluekeep
  89. Hacker Tools For Windows
  90. Hack Tools Pc
  91. Pentest Tools Kali Linux
  92. Hacking Tools For Mac
  93. Hack Tools For Mac
  94. Hacking Tools Windows 10
  95. Hacking Tools
  96. Install Pentest Tools Ubuntu
  97. Ethical Hacker Tools
  98. World No 1 Hacker Software
  99. Hackrf Tools
  100. Bluetooth Hacking Tools Kali
  101. Blackhat Hacker Tools
  102. Tools 4 Hack
  103. Hacker Tools Software
  104. Pentest Box Tools Download
  105. Hacker Tools List
  106. Hack Tool Apk
  107. Nsa Hack Tools
  108. Hacker Tools Windows
  109. Free Pentest Tools For Windows
  110. Hack Tool Apk No Root
  111. Hacking Tools For Windows Free Download
  112. Hacking Tools 2020
  113. Tools Used For Hacking
  114. Hacking Tools
  115. Hack Tools Mac
  116. Kik Hack Tools
  117. Pentest Tools Github
  118. Pentest Tools Website
  119. Hack Apps
  120. Pentest Tools Find Subdomains
  121. Hacker Search Tools
  122. Nsa Hack Tools
  123. Pentest Tools For Windows
  124. Pentest Tools Android
  125. Pentest Tools Kali Linux
  126. World No 1 Hacker Software
  127. Hacker Tools Mac
  128. Hacker Tool Kit
  129. Pentest Tools Framework
  130. Hack Tools 2019
  131. Hacker Tools For Windows
  132. Kik Hack Tools
  133. Pentest Box Tools Download
  134. Free Pentest Tools For Windows
  135. Hacks And Tools
  136. Hacking Tools For Windows
  137. Hacking Tools Pc
  138. Hacking Tools For Beginners
  139. Hacker Tools Hardware
  140. Hacker Tools 2020
  141. Hacking Tools Kit
  142. Hack Tools For Mac
  143. Hacker Techniques Tools And Incident Handling
  144. Hacking Tools Pc
  145. Hacker Hardware Tools
  146. Pentest Tools Download
  147. Hacker Tools For Pc
  148. Ethical Hacker Tools
  149. Hack And Tools
  150. Computer Hacker
  151. Hack Tool Apk
  152. Hack Tools For Mac
  153. Termux Hacking Tools 2019
  154. What Are Hacking Tools
  155. Pentest Tools Framework
  156. Computer Hacker
  157. Pentest Automation Tools
  158. Hack Tools For Games
  159. Pentest Tools Website Vulnerability
  160. Easy Hack Tools
  161. Wifi Hacker Tools For Windows
  162. Pentest Tools Github
  163. Pentest Tools Url Fuzzer
  164. Black Hat Hacker Tools
  165. Hack Tools For Mac
  166. Pentest Box Tools Download
  167. Hackrf Tools
  168. Hacker Search Tools
  169. Hack Tools Pc
  170. Hacker Tools Mac
  171. Hacker Tools Apk
  172. Hacker Techniques Tools And Incident Handling
  173. Hacking Tools For Mac
  174. Best Pentesting Tools 2018
  175. Tools For Hacker
  176. Pentest Tools List
  177. Pentest Reporting Tools
  178. Hackrf Tools

OnionDuke Samples










File attributes

Size: 219136
MD5:  28F96A57FA5FF663926E9BAD51A1D0CB

Size: 126464
MD5:  C8EB6040FD02D77660D19057A38FF769


Size: 316928
MD5:  D1CE79089578DA2D41F1AD901F7B1014


Virustotal info

https://www.virustotal.com/en/file/366affd094cc63e2c19c5d57a6866b487889dab5d1b07c084fff94262d8a390b/analysis/
SHA256: 366affd094cc63e2c19c5d57a6866b487889dab5d1b07c084fff94262d8a390b
File name: 366affd094cc63e2c19c5d57a6866b487889dab5d1b07c084fff94262d8a390b
Detection ratio: 8 / 52
Analysis date: 2014-11-15 18:37:30 UTC ( 8 hours, 44 minutes ago ) 
Antivirus Result Update
Baidu-International Trojan.Win32.Agent.adYf 20141107
F-Secure Backdoor:W32/OnionDuke.B 20141115
Ikarus Trojan.Win32.Agent 20141115
Kaspersky Backdoor.Win32.MiniDuke.x 20141115
Norman OnionDuke.A 20141115
Sophos Troj/Ransom-ALA 20141115
Symantec Backdoor.Miniduke!gen4 20141115
Tencent Win32.Trojan.Agent.Tbsl 20141115

https://www.virustotal.com/en/file/366affd094cc63e2c19c5d57a6866b487889dab5d1b07c084fff94262d8a390b/analysis/


SHA256: 366affd094cc63e2c19c5d57a6866b487889dab5d1b07c084fff94262d8a390b
File name: 366affd094cc63e2c19c5d57a6866b487889dab5d1b07c084fff94262d8a390b
Detection ratio: 8 / 52
Antivirus Result Update
Baidu-International Trojan.Win32.Agent.adYf 20141107
F-Secure Backdoor:W32/OnionDuke.B 20141115
Ikarus Trojan.Win32.Agent 20141115
Kaspersky Backdoor.Win32.MiniDuke.x 20141115
Norman OnionDuke.A 20141115
Sophos Troj/Ransom-ALA 20141115
Symantec Backdoor.Miniduke!gen4 20141115
Tencent Win32.Trojan.Agent.Tbsl 20141115

https://www.virustotal.com/en/file/0102777ec0357655c4313419be3a15c4ca17c4f9cb4a440bfb16195239905ade/analysis/
SHA256: 0102777ec0357655c4313419be3a15c4ca17c4f9cb4a440bfb16195239905ade
File name: 0102777ec0357655c4313419be3a15c4ca17c4f9cb4a440bfb16195239905ade
Detection ratio: 19 / 55
Analysis date: 2014-11-15 18:37:25 UTC ( 8 hours, 47 minutes ago ) 
Antivirus Result Update
AVware Trojan.Win32.Generic!BT 20141115
Ad-Aware Backdoor.Generic.933739 20141115
Baidu-International Trojan.Win32.OnionDuke.BA 20141107
BitDefender Backdoor.Generic.933739 20141115
ESET-NOD32 a variant of Win32/OnionDuke.A 20141115
Emsisoft Backdoor.Generic.933739 (B) 20141115
F-Secure Backdoor:W32/OnionDuke.A 20141115
GData Backdoor.Generic.933739 20141115
Ikarus Trojan.Win32.Onionduke 20141115
Kaspersky Backdoor.Win32.MiniDuke.x 20141115
McAfee RDN/Generic BackDoor!zw 20141115
McAfee-GW-Edition BehavesLike.Win32.Trojan.fh 20141114
MicroWorld-eScan Backdoor.Generic.933739 20141115
Norman OnionDuke.B 20141115
Sophos Troj/Ransom-ANU 20141115
Symantec Backdoor.Miniduke!gen4 20141115
TrendMicro BKDR_ONIONDUKE.AD 20141115
TrendMicro-HouseCall BKDR_ONIONDUKE.AD 20141115
VIPRE Trojan.Win32.Generic!BT 20141115


Related news


  1. How To Install Pentest Tools In Ubuntu
  2. Pentest Tools Nmap
  3. Hack Tools Mac
  4. Best Hacking Tools 2019
  5. Hack Tool Apk No Root
  6. Hacking Tools
  7. Hacker Tools For Windows
  8. Hacking Tools 2020
  9. Pentest Automation Tools
  10. Hacking Tools Github
  11. Hacker Tools 2019
  12. Hack And Tools
  13. Hacker Tools
  14. Hack Tools For Games
  15. Computer Hacker
  16. Hack Tools For Windows
  17. Hackrf Tools
  18. Pentest Tools Website Vulnerability
  19. Hacking Tools For Pc
  20. Computer Hacker
  21. Hacker Techniques Tools And Incident Handling
  22. World No 1 Hacker Software
  23. Pentest Tools Kali Linux
  24. Hacker Tools List
  25. Pentest Tools Review
  26. Hacker Tools Free Download
  27. Top Pentest Tools
  28. Beginner Hacker Tools
  29. Hacker Tools For Mac
  30. Pentest Tools Kali Linux
  31. Hacking Tools Windows
  32. Hacking Tools Online
  33. Hacker Tools Hardware
  34. Hacker Tools Online
  35. Hacking App
  36. Nsa Hack Tools
  37. Pentest Tools Open Source
  38. Hacker Tools For Ios
  39. Pentest Box Tools Download
  40. Hacking Tools For Windows 7
  41. Hack Website Online Tool
  42. Hack Rom Tools
  43. Hacking Tools For Windows
  44. Pentest Tools For Android
  45. Tools 4 Hack
  46. Hacker Tools Online
  47. Hacker Tools For Pc
  48. Hacker Tools List
  49. Bluetooth Hacking Tools Kali
  50. Hacking Tools Name
  51. Hacking Tools Name
  52. What Is Hacking Tools
  53. Hacker Tools 2019
  54. Physical Pentest Tools
  55. Pentest Tools Bluekeep
  56. Hack Tools 2019
  57. Hacker Tools For Ios
  58. Pentest Tools Website
  59. Hacking Tools Hardware
  60. Hacking Tools 2019
  61. Hacking Tools For Windows 7
  62. Hack Tools For Mac
  63. Pentest Tools For Mac
  64. Pentest Tools Website Vulnerability
  65. Top Pentest Tools
  66. Pentest Tools For Windows
  67. Hack Tools For Games
  68. How To Make Hacking Tools
  69. Pentest Tools Linux
  70. Tools Used For Hacking
  71. Pentest Tools Open Source
  72. Hacking Tools Mac
  73. Best Pentesting Tools 2018
  74. Hack Tool Apk
  75. Pentest Tools Port Scanner
  76. Hacking Tools For Windows Free Download
  77. Hacker Tools For Windows
  78. Pentest Tools Bluekeep
  79. Pentest Tools Android
  80. Hack Tools For Ubuntu
  81. Pentest Tools Nmap
  82. Pentest Tools Free
  83. Best Pentesting Tools 2018
  84. Hacker Tools Github
  85. Hack Tools Mac
  86. Nsa Hack Tools Download
  87. Install Pentest Tools Ubuntu
  88. Hacking Tools Free Download
  89. Hacker Tools For Mac
  90. Underground Hacker Sites
  91. Pentest Tools Find Subdomains
  92. Hack Tools For Ubuntu
  93. Pentest Reporting Tools
  94. Hack Tools For Ubuntu
  95. Hacking Tools Hardware
  96. Tools Used For Hacking
  97. Hacking Tools Free Download
  98. Hacker Hardware Tools
  99. Underground Hacker Sites
  100. Hacking Tools Pc
  101. Hack Tools For Games
  102. Hacking Tools Usb
  103. Physical Pentest Tools
  104. Best Hacking Tools 2020
  105. Hacker Tools For Mac
  106. Pentest Tools List
  107. Best Hacking Tools 2020
  108. Easy Hack Tools
  109. Nsa Hack Tools Download
  110. Hacker Tools Linux
  111. Tools 4 Hack
  112. Hack Tools For Pc
  113. Hacking Tools For Windows
  114. Hacker Tools Github
  115. Hacker Tools Apk
  116. Hacking Tools Online
  117. Hack Tools
  118. Pentest Tools Review
  119. Hack Tools
  120. Hacker Hardware Tools
  121. Hacker Tools 2019
  122. Tools Used For Hacking
  123. How To Hack
  124. Hacker Tools Software
  125. Hack And Tools
  126. Underground Hacker Sites