Networking Security
1.16K subscribers
131 photos
88 videos
39 files
91 links
🌐 Networking Security!

πŸ“‹ IT & Cyber Security & Blog's

πŸ–‡Channel link: t.me/+kbSQJSsjzoc2YWYx

For @Networking_Security

Contact: @Muhammedov
Download Telegram
πŸ—£ IPSEC IKE

⏺ IPSec xavfsiz tarmoq protokollari to'plami bo'lib, asosan xavfsiz bo'lmagan tarmoqlar orqali virtual xususiy tarmoq (VPN) ulanishlarini o'rnatish uchun ishlatiladi. IPSec xavfsiz ulanishlarni ta'minlash uchun Internet Key Exchange (IKE) protokolidan foydalanadi va tarmoq orqali yuborilgan ma'lumotlar paketlarini autentifikatsiya qiladi va shifrlaydi.

⏺ IPSEC IKE Flood - bu DDoS hujumining bir turi bo'lib, hujum qiluvchi ko'pincha soxta chiquvchi IP-manzillar bilan katta miqdordagi trafikni yuboradi va bu VPN serverining IKE trafigiga javob berishiga sabab bo'ladi. Natijada, VPN server resurslarining haddan tashqari iste'moli qayd etiladi, bu esa uning qonuniy mijozlarga (foydalanuvchilarga) kirishni rad etadi.

For @Networking_Security β˜‘οΈ
Please open Telegram to view this post
VIEW IN TELEGRAM
⚑5πŸ”₯5πŸ‘4πŸ‘¨β€πŸ’»3πŸ•Š11
🎯DDoS Attack qanday ishlaydi?

ℹ️Example: TCP => SYN/ACK

For @Networking_Security β˜‘οΈ
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘12πŸ‘¨β€πŸ’»8⚑4πŸ•Š11
This media is not supported in your browser
VIEW IN TELEGRAM
🌐Tarmoq hujumlari qaysi darajada va qanday ishlaydi❕

For @Networking_Security β˜‘οΈ
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘3πŸ’―3πŸ”₯2πŸ•Š1πŸ‘¨β€πŸ’»11
πŸ—£ Web Application Firewall

WAF yoki Web Application Firewall web-ilova va Internet o'rtasidagi HTTP trafigini filtrlash va nazorat qilish orqali web-ilovalarni himoya qilishga yordam beradi. U odatda web-ilovalarni Cross-Site Scripting (XSS), SQL injection va boshqalar kabi hujumlardan himoya qiladi.

WAF - bu 7-qavat xavfsizligi (OSI modelida) va barcha turdagi hujumlardan himoyalanish uchun mo'ljallanmagan. Ushbu hujumga qarshi mudofaa usuli odatda bir qator hujum vektorlariga qarshi yaxlit mudofaa yaratadigan vositalar to'plamining bir qismidir.

WAF - teskari proksi-serverning bir turi bo'lib, u mijozlar serverga yetib borishdan oldin WAF orqali o'tayotganda serverni ta'sir qilishdan himoya qiladi.

DDoS hujumi paytida WAF oxirgi himoya qatlami bo'lib, bloklangan manzillarni trafikni filtrlash markaziga uzatadi. Bu sizga provayder tarmog'iga yaqinlashganda, boshqa tarmoq qurilmalarining resurslarini bo'shatib, zararli trafikni darhol to'xtatishga imkon beradi.

DDoS hujumlaridan himoya qilish uchun faqat WAF-dan foydalanish tavsiya etilmaydi , chunki u keng ko'lamli hujumda muvaffaqiyatsizlikka uchragan birinchi elementlardan biridir. Web-ilovani DDoS hujumlaridan himoya qilish uchun maxsus service lardan (Cloudflare va boshqalar) dan foydalanish ancha samaralidir.

For @Networking_Security β˜‘οΈ
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘6πŸ’―4πŸ†’2❀1πŸ‘¨β€πŸ’»11
#rasman

πŸ€‘ Endi Telegramda rasman pul topsak bo'ladi

β€’ Telegramning bugungi yangilanishida endi agar sizni 1000 tadan oshiq obunachilik kanalingiz bo'lsa Telegram sizda chiqadigan reklamalar uchun 50% pulini sizga TON orqali tushurib berishni boshladi.

Manbaa: ITva KOMPYUTER


For @Networking_Security β˜‘οΈ
πŸ”₯55πŸ‘¨β€πŸ’»2😎2❀1πŸ‘Œ1
This media is not supported in your browser
VIEW IN TELEGRAM
For @Networking_Security β˜‘οΈ
🀣123❀‍πŸ”₯2πŸ’―2πŸ‘¨β€πŸ’»2
❔ Node.js va libuv-dagi zaifliklar

Node.js 21.6.2, 20.11.1 va 18.19.1 yangilanishlari bizga 8 ta zaiflikni tuzatishni olib keldi, shu jumladan 4 tasi yuqori darajadagi xavf bilan.

❕ Ulardan ba'zi zaifliklar: Imtiyozsiz foydalanuvchi tomonidan kodni almashtirish imkoniyati (CVE- 2024-21892 ) ; HTTP so'rovlarini qayta ishlashda resurslarning tugashi sababli xizmat ko'rsatishni rad etish (CVE- 2024-22019 ); Asosiy katalog fayl yoΚ»llari chegarasidan tashqarida (CVE- 2024-21896 ) : Parametrlarda niqoblarni notoΚ»gΚ»ri ishlatish (CVE -2024-21890 ) .

For @Networking_Security πŸ”
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘4πŸ‘¨β€πŸ’»3❀‍πŸ”₯1😁1
DNS orqali DDoS hujum (DNS Amplification Attack)

Hacker sizning qaysidir qurilmangizni (Asosan router yoki Server) ni ishdan chiqarmoqchi bo'lsa u sizga juda ko'plab paket jo'natishi kerak va (Qurilma, Website, Server) uni ko'rib chiqolmay o'z ishini bajarmay qo'yishi kerak. demak maqsad shu.
Buning uchun u virus tarqatib zombi kompyuterlardan foydalanadi yoki kattaroq DNS serverda bir qator narsani o'zgartirsa kifoya. qanday deysizmi?
tasaavvur qiling...
Butun dunyo www.google.com dan foydalanadi va sekundiga milliardlab so'rovlar kelib tushadi Google ga.
Agar hacker google domaini ostiga sizning (Qurilma, Website, Server) ipsini biriktirib qo'ysa bormi...
sekundiga millionlab paketlar sizni qurilmangizga keladi. Juda katta ehtimollik bilan uncha so'rovga sizning (Qurilma, Website, Server) javob berolmaydi va xizmat ko'rsatishni rad etadi (DDoS) va shu bilan hacker o'zi hohlaganiga erishishi mumkin.


Bunday hujumlardan qanday himoyalanish mumkin?

Trafikni filtrlash: Tarmoq qurilmalarida trafikni filtrlashni sozlash, DNS serverlarga faqat ruxsat berilgan manbalardan tashqari kirishni cheklash.
DNS ni sozlash: O'z serveringizni hujum uchun ishlatishni oldini olish uchun, refleksiv so'rovlarni cheklash.
Trafikni monitoring qilish: Oddiy ravishda DNS serverlarga ko'p so'rovlarni qilish mumkinligini aniqlash uchun trafikni doimiy ravishda kuzatish.
CDN va DDoS himoyasi xizmatlaridan foydalanish: Hujumni aniqlash va bartaraf etishga yordam berishi mumkin bo'lgan CDN va DDoS himoyasi xizmatlaridan foydalanish.


For @Networking_Security πŸ”
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘¨β€πŸ’»4πŸ”₯2πŸ’―2πŸ†’1
#YouTube dan video/audio yuklovchi API

function download($url, $quality, $option) {
$api = "https://x.wwi.su/x/download/";
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => $api."?option=download&url=$url&quality=$quality",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_USERAGENT => "PHPiB",
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
]);
$response = curl_exec($curl);
curl_close($curl);
return $response;
}
header('Content-Type: application/json');

echo download($_GET["url"], $_GET["quality"], $_GET["option"]);
πŸ‘6πŸ‘Œ3πŸ‘¨β€πŸ’»3πŸ”₯2
This media is not supported in your browser
VIEW IN TELEGRAM
Kayfiyatni ko'taramiz😁

For @Networking_Security β˜‘οΈ
🀣9⚑3😁2❀1
This media is not supported in your browser
VIEW IN TELEGRAM
πŸ˜…Kiberxavfsizlik sohasiga ga o'qishga topshirgan men...

P.S tushungan tushundi πŸ˜‚

For @Networking_Security β˜‘οΈ
Please open Telegram to view this post
VIEW IN TELEGRAM
🀣23πŸ‘¨β€πŸ’»5πŸ”₯3😁2πŸ‘1
πŸ‘ Kurs: axloqiy hackerlik - NMAP bilan.

Nmap - har qanday miqdordagi ob'ektlar bilan IP-tarmoqlarni turli xil maxsus skanerlash , shuningdek skanerlangan tarmoq ob'ektlari holatini aniqlash uchun mo'ljallangan bepul yordamchi dastur.

❗️ Bu kuchli va murakkab vosita bo'lib, uning kodi o'nlab yillar davomida sayqallangan. Bu tez, ishonchli va nihoyatda funktsionaldir.

β†˜οΈ YouTube

For @Networking_Security β˜‘οΈ
Please open Telegram to view this post
VIEW IN TELEGRAM
❀3πŸ‘¨β€πŸ’»3πŸ’―2
Muborak Ramazon Hayiti qutlug' bo'lsin!

πŸ•Œ Barchangizni Ramazon oyida qilgan ibodatlaringiz, ehsonlaringiz va tutgan ro'zalaringiz qabul bo'lishini tilagan holda Iyd ul-Fitr bilan tabriklaymiz.

✨ Doimo ilm talabida bo'lish, uni o'zgalar bilan baham ko'rish va u orqali halol rizq topish, shuningdek, o'z sohangiz bo'yicha professional kadr bo'lishingizga tilakdoshmiz!

For @Networking_Security β˜‘οΈ
πŸ•Š5❀‍πŸ”₯4πŸ‘4πŸ”₯2πŸ‘Œ1πŸ’―1
Kiberxavfsizlik asoslari.pdf
16.8 MB
Kiberxavfsizlik asoslariπŸ“š

Kiberhavfsizlikka qiziqqanlar va shu sohada oΚ»qiyotganlar uchun yaxshi qoΚ»llanmaπŸ“„

For @Networking_Security β˜‘οΈ
❀4πŸ‘2❀‍πŸ”₯1πŸ‘Œ1πŸ‘¨β€πŸ’»1πŸ†’1
πŸ’» Kali Linux-da Nikto Scanner-dan foydalanish

Nikto - bu Kali Linuxda o'rnatilgan ochiq manbali web-ilovalar skaneri. Ushbu vosita pentesterlarga web-serverdagi web-ilovada mavjud bo'lgan xavfsizlik zaifliklarini topish jarayonini osongina avtomatlashtirish imkonini beradi.

Foydalanish:

nikto -h 172.30.1.49
-h opsiyasidan foydalanish maqsadning host nomi yoki IP manzilini belgilash imkonini beradi. Turli hil skanerlash imkoniyatlari haqida ko'proq ma'lumot olish uchun buyruqdan foydalaning:
nikto --help

πŸ–₯ GitHub

@Networking_Security πŸ”
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ’―6πŸ‘3πŸ‘¨β€πŸ’»3⚑1❀1πŸ‘Œ1
Hacking.with.Kali.Linux.Wireless.Penetration.pdf
242 KB
πŸ“‚ Hacking with Kali Linux Wireless Penetration

Eddie Arnold 2024


For @Networking_Security β˜‘οΈ
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘¨β€πŸ’»4❀2πŸ‘2
Hacking-books | Hacking kitoblar | News: 2022 Crack Update.

Android Security Fundamentals

Attacking Network Protocols

Black Hat Python (newest edition)

Gray Hat C#

Hacking The Art of Exploitation Second Edition

iOS Application Security

Metasploit - A Penetration Tester's Guide

Penetration Testing by Georgia Weidmann

Pentesting Azure Applications

Practical Forensic Imaging

Practical Malware Analysis

Serious Cryptography

Silence On The Wire

The Car Hacker's Handbook

The Tangled Web



πŸ§‘β€πŸ’»Githubdan yuklab olish:
https://github.com/tanc7/hacking-books

For @Networking_Security πŸ”
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘4❀3πŸ‘¨β€πŸ’»2
DDoS uchun bepul stresser sayt⚑️

Free: 300 sec va HTTP SPAM method βœ…

❗️DISCLAIMER❗️

Website: https://stresser.su 🌎

For @Networking_Security πŸ”
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘5⚑3❀2πŸ‘¨β€πŸ’»1
HTTP javob kodlari

Asosiy kategoriyalar:

1xx. Ma'lumot 100 - 199
2xx. Muvaffaqiyatli 200 - 299
3xx. Qayta yo'naltirishlar 300 - 399
4xx. Mijoz xatolari 400 - 499
5xx. Server xatolari 500 - 599

Eng mashhurlari:

β–ͺ️ 200 – OK. Server soβ€˜rovni muvaffaqiyatli qayta ishladi.
β–ͺ️ 201 – Created. Server so'rovni qayta ishladi va yangi resurs yaratdi.
β–ͺ️ 204 – No content. Server soβ€˜rovni qayta ishladi, ammo kontent yoβ€˜q.
β–ͺ️ 301 – Moved Permanently. SoΚ»ralgan maΚΌlumotlar butunlay boshqa manzilga koΚ»chirildi.
β–ͺ️ 304 – Not Modified. So'ralgan manba o'zgarmaganligini, shuning uchun keshlangan versiyadan foydalanishi mumkinligini ko'rsatadi.
β–ͺ️ 400 – Bad Request. Server qayta ishlay olmaydigan so'rov yuborildi (masalan, so'rov noto'g'ri ma'lumotlar formatini yubordi)
β–ͺ️ 401 – Unauthorized. Avtorizatsiya yo'qligi sababli kirish taqiqlandi.
β–ͺ️ 404 – Not Found. Serverga ulanish o'rnatildi, ammo so'rov bo'yicha hech qanday ma'lumot yo'q.
β–ͺ️ 500 – Internal Server Error. Ichki server xatosi; xatoning sabablari ko'p bo'lishi mumkin.
❀5πŸ‘5πŸ•Š1
Type of Hackersℹ️

For @Networking_Security πŸ”
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘3❀2πŸ’―2
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘2πŸ”₯2🐳2