{"id":17262208,"url":"https://github.com/elcuervo/tangalanga","last_synced_at":"2025-04-03T03:10:31.433Z","repository":{"id":57567641,"uuid":"267484951","full_name":"elcuervo/tangalanga","owner":"elcuervo","description":"Tangalanga: the Zoom conference scanner hacking tool","archived":false,"fork":false,"pushed_at":"2020-10-20T21:25:19.000Z","size":97,"stargazers_count":288,"open_issues_count":6,"forks_count":42,"subscribers_count":22,"default_branch":"master","last_synced_at":"2025-03-24T08:26:39.913Z","etag":null,"topics":["hacking","hacking-tool","reversing","zoom"],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/elcuervo.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2020-05-28T03:33:50.000Z","updated_at":"2025-02-13T14:28:51.000Z","dependencies_parsed_at":"2022-09-15T05:22:52.163Z","dependency_job_id":null,"html_url":"https://github.com/elcuervo/tangalanga","commit_stats":null,"previous_names":[],"tags_count":2,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elcuervo%2Ftangalanga","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elcuervo%2Ftangalanga/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elcuervo%2Ftangalanga/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elcuervo%2Ftangalanga/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/elcuervo","download_url":"https://codeload.github.com/elcuervo/tangalanga/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":246927835,"owners_count":20856198,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["hacking","hacking-tool","reversing","zoom"],"created_at":"2024-10-15T07:53:15.851Z","updated_at":"2025-04-03T03:10:31.410Z","avatar_url":"https://github.com/elcuervo.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Tangalanga\n\nZoom Conference scanner.\n\nThis scanner will check for a random meeting id and return information if available.\n\n![](http://share.elcuervo.net/screenshot_2020-05-29_213922.png)\n\n## Install\n\nFirst try to see if there's any prebaked version for the date: https://github.com/elcuervo/tangalanga/releases.\n\nThis versions already have a token ready to use.\n\nEither way you can find the Windows, Linux and Mac version on Releases https://github.com/elcuervo/tangalanga/releases.\n\nDownload, uncompress and enjoy.\n\n## Usage\n\nThis are all the possible flags:\n\n```bash\ntangalanga \\\n    -token=user-token \\   # [default: env TOKEN]  user token to use.\n\n    -colors=false \\       # [default: true]    enable/disable colors\n    -censor=true \\        # [default: false]   censors output\n    -output=history \\     # [default: stdout]  write found meetings to file\n    -debug=true \\         # [default: false]   show all the attmpts\n    -tor=true \\           # [default: false]   enable tor connection (will use default socks proxy)\n    -hidden=true \\        # [default: false]   enable embedded tor connection (only linux)\n    -rate=7 \\             # [default: ncpu]    overwrite the default worker pool\n\n    -proxy=socks5://... \\ # [default: socks5://127.0.0.1:9150]   proxy url to use\n```\n\n## Tokens\n\nUnfortunately I couldn't find the way the tokens are being generated but the core concept is that\nthe `zpk` cookie key is being sent during a Join will be usable for ~24 hours before expiring. This\nmakes trivial to join several known meetings, gether some tokens and then use them for the scans.\n\nTokens can be sniffed after a join attempt to a meeting.\nThis means that to \"fish\" a token you'll need a setup that can sniff traffic and also spoof\ncertificates.\n\nUsing Wireshark, Charles or any other of the ssl-proxying-capable tools out there will do the trick.\n\n## TOR (only linux)\n\nTangalanga has a tor runtime embedded so it can connect to the onion network and run the queries\nthere instead of exposing your own ip.\n\n![](http://share.elcuervo.net/tangalanga-find-tor-01.png)\n\nFor any other system I recommend a VPN\n\n## Why the bizarre name?\n\nThis makes reference to a famous 80s/90s personality in the Rio de la Plata. [Doctor Tangalanga](https://en.wikipedia.org/wiki/Dr._Tangalanga)\nwho loved to do phone pranks.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Felcuervo%2Ftangalanga","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Felcuervo%2Ftangalanga","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Felcuervo%2Ftangalanga/lists"}