News Feed
  • DrugHub has agreed to fully refund all users who lost money in the SuperMarket exit scam.  
  • Retro Market has gone offline. Circumstances of the closure unknown.  
  • SuperMarket has closed following an exit scam by one of the admins.  
  • The admin of Incognito Market, Pharoah, has been arrested by the FBI several months after exit scamming.  
  • Silk RoadTorhoo mini logo
  • darknet markets list
  • Popular P2P exchange LocalMonero has announced it is closing.  

Drug Hub Market Test Results : Scope | Torhoo darknet markets

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Drug Hub Test Results

I have tested the functionality of this Market to my best Ability, and I took a little longer
on this than Normal just because of how their System Works there.

The thing that made Testing this so Long was that when you send certain types of Data or Malformed Requests towards the WebApp, the .onion link you are logged in with gets Disconnected, and then You need to go back and get another Link and Log In Again.

I could not find anything that would make this "Unsafe", I have looked at the Market from the Buyer Panel, as a Guest and From the Vendor Panels and found No Bugs I could exploit, I Tried different types of Application Layer Attacks towards URLs and they were disconnected, the same thing happened when I am scanning the Market too quickly, I have spoke to the Owner a good Amount of Times and he has actually taught me a thing or too with how some of his Systems Operate, The CAPTCHA for example, I really like this CAPTCHA, but there was a couple of times where the Image had a Solid Background and I was unable to pull it to the correct Marker Position, although this didn't happen too many times It was still easy for me to Solve as a Human and when trying BruteForce on the Range The probability was far too low for me to do anything with.

I have looked for CSRF, XSS, SQLi, Directory Traversal, Race Conditions, Exposed Endpoints, and I have thoroughly tested the Web Application, however I am not a Professional by Any Means, There are people out there that know things I don't know, just like I know things others Might not know, It is always best to get more that one Opinion, but from Everything I have tested this Market has it's security On Point.
-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQSiuw6iPCFk/bzUaqspHmY6RlwQGwUCZURg4QAKCRApHmY6RlwQ
G5NmAP9Vmz4jmwxLRaofTQozF9IpWRKPT7kVgFhacTf/rV9C+gEA+Tvh7CLQGXVJ
am58+aYeeIvP9Us5j7+c/sUaUhD7pAQ=
=3Kka
-----END PGP SIGNATURE-----


I will be Testing Super Market Next
/u/crackheaddom101 P
2 points
1 year ago
can you test crack x m00nkey market?
/u/CodeIsLaw 📢 scope.wtf
2 points
1 year ago
Haha, I was supposed to Pen Test M00nkey but he disappeared, if he comes Back the Offer is still there.
/u/mantspants11
4 points
1 year ago
If it's not reachable, it's not breachable lol
/u/CodeIsLaw 📢 scope.wtf
2 points
1 year ago
Lol, That's a good one.
/u/cuppycake
1 points
1 year ago
This is amazing! How admirable. I could see that you do things that are very helpful and resourceful for others even without the monetary gain. That's highly respectable! I'm a complete noob when it comes to any of this and that but definitely find it intriguing. Thank you for all that you do! (⁠っ⁠.⁠❛⁠ ⁠ᴗ⁠ ⁠❛⁠.⁠)⁠っ