Tor-Native Onion Web Exploitation
"Discover darknet. Fingerprint targets. Bypass auth. Inject SQL. Execute RCE. Exfil config. Persist on .onion infrastructure."
SPECTER PIERCER is a comprehensive Tor-native web exploitation framework targeting .onion hidden services. It discovers and fingerprints darknet applications, bypasses authentication mechanisms, exploits SQL injection, XSS, LFI, and RCE vulnerabilities, exfiltrates configuration and credentials, maintains persistent backdoors within Tor infrastructure, and evades detection at the application and Tor-layer levels. PIERCER operates natively within Tor networks.
Hidden services are not invisible. PIERCER demonstrates that comprehensive web exploitation can target Tor infrastructure at scale, that authentication bypasses work across darknet applications, and that persistence mechanisms can survive across Tor circuit resets and service restarts. Configuration exfiltration reveals the full attack surface of hidden service deployments.
PIERCER operates entirely within Tor circuits, discovering hidden services through darknet enumeration, fingerprinting application stacks, executing classic web exploits (SQLi, XSS, LFI, RCE), and persisting across service restarts through backdoored configuration. Tor-layer evasion prevents detection at the circuit level. Command injection through application interfaces maintains post-exploitation access.
OPEN: Service enumeration and fingerprinting (no authorization)
PIERCE: Authentication bypass and exploitation (ROE + PIERCER_KEY)