THUGS(red) DarkWeb/Monitor_

Black Hat Chat

Alive Hacking Community Tor v3

capture
Blocked: a challenge page was served instead of the siteCHALLENGE PAGE

The only capture we hold is a challenge page, not the service. It is kept for evidence but is not shown here as if it were the site. View the raw capture.

what the page says

Black Hat Chat

A chat community

Black Hat Chat Nickname: Password: Type the characters in the image: Guests, choose a colour: * Random Colour * Beige Blue violet Brown Cyan Sky blue Gold Grey Green Hot pink Light blue Light green Lime green Magenta Olive Orange Orange red Red Royal blue Sea green Sienna Silver Tan Teal Violet White Yellow Yellow green Currently 6 chatter(s) in room: rex bbylover Cappielove Caligula ai cbp Welcome to Black Hat Chat. Try !rules or !help Rules No CP/spam/gore/other illegal activity Manual registration enabled Suggestions, comments and manual registration: blackh4t(at)firemail(dot)cc (encrypted…
reachability history
The 4 most recent checks.
When Status HTTP Response Bytes Via
50m ago Alive content moved 200 197 ms 30,124 chrome-stealth
2h ago Alive content moved 200 584 ms 31,506 chrome-stealth
3h ago Alive content moved 200 743 ms 29,855 chrome-stealth
5h ago Alive 200 529 ms 31,337 chrome-stealth
security headers
Csp
Raw
base-uri 'self'; default-src 'none'; font-src 'self'; form-action 'self'; frame-ancestors 'self'; frame-src 'self'; img-src * data:; media-src * data:; style-src 'self' 'unsafe-inline';
Directives
Base uri
'self'
Default src
'none'
Font src
'self'
Form action
'self'
Frame ancestors
'self'
Frame src
'self'
Img src
*data:
Media src
*data:
Style src
'self''unsafe-inline'
Unsafe inline
yes
Unsafe eval
no
X frame options
sameorigin, SAMEORIGIN
X content type options
nosniff, nosniff
Referrer policy
no-referrer, no-referrer-when-downgrade
Permissions policy
Accelerometer
()
Ambient light sensor
()
Autoplay
()
Battery
()
Camera
()
Cross origin isolated
()
Display capture
()
Document domain
()
Encrypted media
()
Execution while not rendered
()
Execution while out of viewport
()
Fullscreen
()
Geolocation
()
Gyroscope
()
Magnetometer
()
Microphone
()
Midi
()
Navigation override
()
Payment
()
Picture in picture
()
Publickey credentials get
()
Screen wake lock
()
Sync xhr
()
Usb
()
Web share
()
Xr spatial tracking
()
Clipboard read
()
Clipboard write
()
Gamepad
()
Speaker selection
()
Conversion measurement
()
Focus without user activation
()
Hid
()
Idle detection
()
Sync script
()
Vertical scroll
()
Serial
()
Trust token redemption
()
Interest cohort
()
Otp credentials
()
Cross origin
Opener
same-origin
Embedder
require-corp
Resource
same-origin
X xss protection
1; mode=block, 1; mode=block
Cookies
Count
0
Secure
0
Httponly
0
Samesite
0
Score
72
Missing
hsts
technology detected
Server
Raw
nginx
Name
nginx
Family
nginx
Protocol
http/1.1
what blocks us
Detected
yes
Kind
captcha
Vendor
Unknown
Label
Captcha
Confidence
75
Signals
captcha form fieldcaptcha element
Self clearing
no
Waited ms
0
Http code
200
Via
chrome-stealth
contacts published
  • Total0
crypto addresses
  • Total0
forms on the page
Count
1
Kinds
Login
1
Has login
yes
Has search
no
Has upload
no
Forms
  • Kind
    login
    Method
    post
    Action
    http://blkhatjxlrvc5aevqzz5t6kxldayog6jlx5h7glnu44euzongl4fh5ad.onion/index.php
    Inputs
    9
    Types
    hiddentextpasswordsubmit
    Password
    yes
    File
    no
outbound onion links
  • onion_unique not tracked onion_unique
  • onion_total not tracked onion_total
  • clearnet_unique not tracked clearnet_unique 1
  • internal not tracked internal 22
  • external not tracked external 1
  • total not tracked total 23
  • truncated not tracked truncated
response headers
HeaderValue
cache-control no-cache, no-store, must-revalidate, max-age=0, private
connection keep-alive
content-encoding gzip
content-security-policy base-uri 'self'; default-src 'none'; font-src 'self'; form-action 'self'; frame-ancestors 'self'; frame-src 'self'; img-src * data:; media-src * data:; style-src 'self' 'unsafe-inline';
content-type text/html; charset=UTF-8
cross-origin-embedder-policy require-corp
cross-origin-opener-policy same-origin
cross-origin-resource-policy same-origin
date Fri, 21 Aug 2026 16:33:52 GMT
expires 0
permissions-policy accelerometer=(), ambient-light-sensor=(), autoplay=(), battery=(), camera=(), cross-origin-isolated=(), display-capture=(), document-domain=(), encrypted-media=(), execution-while-not-rendered=(), execution-while-out-of-viewport=(), fullscreen=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), navigation-override=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=(), web-share=(), xr-spatial-tracking=(), clipboard-read=(), clipboard-write=(), gamepad=(), speaker-selection=(), conversion-measurement=(), focus-without-user-activation=(), hid=(), idle-detection=(), sync-script=(), vertical-scroll=(), serial=(), trust-token-redemption=(), interest-cohort=(), otp-credentials=()
pragma no-cache
referrer-policy no-referrer, no-referrer-when-downgrade
server nginx
transfer-encoding chunked
x-content-type-options nosniff, nosniff
x-frame-options sameorigin, SAMEORIGIN
x-xss-protection 1; mode=block, 1; mode=block