SecList for CyberStudents
1.28K subscribers
844 photos
35 videos
225 files
1.1K links
Think outside the box
Download Telegram
Forwarded from Turan Security
🇺🇿 O‘zbekistonda ilk Bug Bounty platformasi — Oq Doppi
Prezidentimiz tomonidan belgilangan 2030-yilgacha kiberxavfsizlikni rivojlantirish strategiyasiga muvofiq, mamlakatimizda axborot tizimlari xavfsizligini ta’minlash va zaifliklarni oldindan aniqlash muhim vazifalardan biridir.
Shu yo‘nalishda TuranSecurity tomonidan O‘zbekistonda birinchi Bug Bounty platformasi — Oq Doppi ishga tushirildi.

🔎 Bug Bounty nima?
Bu kompaniyalarga o‘z tizimlaridagi xavfsizlik zaifliklarini mustaqil va professional ethical (white hat) mutaxassislar yordamida aniqlash imkonini beradigan zamonaviy yondashuvdir. Natijada muammolar erta bosqichda aniqlanadi va xavflar oldi olinadi.

🎩 Nega “Oq Doppi”?
“White hat hacker” — tizimlarni himoya qilish uchun ishlaydigan mutaxassislarni anglatadi.
“Oq Doppi” esa ushbu tushunchaning milliy talqini bo‘lib, ishonch, himoya va mas’uliyat ramzidir.

🤝 Siz uchun qanday foyda beradi?
• Tizimlaringizdagi zaifliklarni real mutaxassislar aniqlaydi
• Xavfsizlik darajasi sezilarli darajada oshadi
• Muammolarni oldindan bartaraf etish imkoniyati
• Qonuniy va nazorat ostidagi test muhiti

🚀 Platforma bugundan ishga tushdi
Birinchi scope doirasida 2 ta dastur ochildi:
TuranSec — *.turansec.uz
Oq Doppi — platformaning o‘zi
🛡 Agar siz kompaniya bo‘lsangiz — tizimlaringizni himoya qiling
🛡 Agar siz mutaxassis bo‘lsangiz — o‘z bilimingizni amalda sinab ko‘ring

Oq Doppi — ishonchli va zamonaviy kiberxavfsizlik yechimi.

Havola: https://oqdoppi.uz

#OqDoppi #CyberSecurity #BugBounty #Uzbekistan #TuranSecurity
🔥52
👩‍💻 Docker Security.

На сайте hacktricks есть очень объемная Wiki по безопасной настройке Docker. Крайне много информации по Socket, Capabilities, Escape from Containers и т.д. Рекомендую к изучению:

Basic Docker Engine Security:
➡️Secure Access to Docker Engine;
➡️Security of Container Images;
➡️Image Scanning;
➡️Docker Image Signing.
Containers Security Features:
➡️Namespaces;
➡️cgroups;
➡️Capabilities;
➡️Seccomp in Docker;
➡️AppArmor in Docker.

#Docker #Security
Forwarded from UzCERT Live
🖥 Apex — sun’iy intellekt asosidagi pentester: tizimlarni haqiqiy xaker kabi sinovdan o‘tkazuvchi yangi texnologiya

Bugungi kunda dasturiy ta’minot ishlab chiqish jarayoni misli ko‘rilmagan darajada tezlashdi. Sun’iy intellekt yordamida yozilayotgan kodlar, avtomatik yangilanishlar va uzluksiz integratsiya (CI/CD) tizimlari sabab xavfsizlikni nazorat qilish tobora murakkablashib bormoqda. Shu sharoitda yangi avlod yechim — Apex paydo bo‘ldi.

⚠️ Bu tizim oddiy skaner emas, balki haqiqiy hujumchi kabi harakat qiladigan sun’iy intellekt agenti hisoblanadi.

📱 Batafsil

#Apex #intellekt #pentester #AI
🚀 UZCERT xizmatining rasmiy telegram sahifasiga a’zo bo‘ling!
Please open Telegram to view this post
VIEW IN TELEGRAM
1👍1🔥1🤔1
TheHive For SOC
Test Case

#SOC #TheHive #BlueTeam #Test
1
Forwarded from 1N73LL1G3NC3
KslKatz

Combining KslDump and GhostKatz to dump LSASS using no-vulnerability KslD.sys memory read to bypass PPL. Extracts MSV1_0 NT hashes and WDigest cleartext passwords (if enabled) from LSASS using a Microsoft-signed driver.
👍1
))
😁6😭6😐5
SecList for CyberStudents
))
From Russia Guys )
1😈1
Forwarded from Cyber Detective
The OSINT Tools Library is new project from Osint Newsletter and Jake Creps

And this isn’t just a simple collection of tools. Each instrument’s page contains the following sections: what does it do, how to use, cost, data processing, use in reporting.

https://tools.osintnewsletter.com/osint-tools/google-lens
Forwarded from Cyber Detective
WindVector

Detailed info on winds and air currents. It features an online map, a 3D model of atmospheric layers, and the ability to view historical data for past dates. It is useful for investigating natural disasters and aviation accidents.

https://windvector.app/

#geoint
Forwarded from Turan Security
Kiberxavfsizlik bo'yicha seminar-trening!

O'zbekiston Respublikasi Prezidentining yoshlar bilan uchrashuvida belgilangan vazifalar doirasida Muhammad al-Xorazmiy nomidagi Toshkent axborot texnologiyalari universiteti talabalarining kiberxavfsizlik sohasidagi amaliy bilim va ko‘nikmalarini oshirish maqsadida sohadagi yetakchi kompaniya mutaxassislari bilan seminar-trening tashkil etildi.

Tadbirda kompaniyamiz vakillari ham o‘zlarining amaliy tajribalari va bilimlari bilan o‘rtoqlashdilar.

Akmaljon Sodiqov - Turan Security asoschisi:
📌 CNA nima? Kiberxavfsizlikda o'qib pul ishlash mumkinmi?
Yoldoshali Esonaliyev - Team Lead:
📌 Web ilovalar xavfsizligi.
Abdumutal Abdumutalov - Team Lead:
📌 Android ilovalari xavfsizligida statik tahlil usullari.

Seminar yakunida universitet professor-o‘qituvchilari va xodimlari bilan hamkorlikni yanada kengaytirish bo‘yicha kelishuvga erishildi.

@turansecurity | www.turansec.uz | info@turansec.uz
👍3🤝2