Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
GATOR – A Comprehensive GCP Attack Toolkit For Offensive Research
GATOR – GCP Attack Toolkit for Offensive Research, a tool designed to aid in research and exploiting Google Cloud Environments.
It offers a comprehensive range of modules tailored to support users in various attack stages, spanning from Reconnaissance to Impact.
Modules
Resource CategoryPrimary ModuleCommand GroupOperationDescriptionUser Authenticationauth–activateActivate a Specific Authentication Method–addAdd a New Authentication Method–deleteRemove a Specific Authentication Method–listList All Available Authentication MethodsCloud Functionsfunctions–listList All Deployed Cloud Functions–permissionsDisplay Permissions for a Specific Cloud Function–triggersList All Triggers for a Specific Cloud FunctionCloud StoragestoragebucketslistList All Storage BucketspermissionsDisplay Permissions for Storage BucketsCompute Enginecomputeinstancesadd-ssh-keyAdd SSH Key to Compute Instances
Installation
Python 3.11 or newer should be installed. You can verify your Python version with the following command:
Manual Installation via setup.py
Automated Installation via pip
Documentation
Have a look at the GATOR Documentation for an explained guide on using GATOR and it’s module!
Issues
Reporting An Issue
If you encounter any problems with this tool, I encourage you to let me know. Here are the steps to report an issue:
1. Check Existing Issues: Before reporting a new issue, please check the existing issues in this repository. Your issue might have already been reported and possibly even resolved.
2. Create a New Issue: If your problem hasn’t been reported, please create a new issue in the GitHub repository. Click the Issues tab and then click New Issue.
3. Describe the Issue: When creating a new issue, please provide as much information as possible. Include a clear and descriptive title, explain the problem in detail, and provide steps to reproduce the issue if possible. Including the version of the tool you’re using and your operating system can also be helpful.
4. Submit the Issue: After you’ve filled out all the necessary information, click Submit new issue.
Your feedback is important, and will help improve the tool. I appreciate your contribution!
Resolving An Issue
I’ll be reviewing reported issues on a regular basis and try to reproduce the issue based on your description and will communicate with you for further information if necessary. Once I understand the issue, I’ll work on a fix.
Please note that resolving an issue may take some time depending on its complexity. I appreciate your patience and understanding.
GATOR – A Comprehensive GCP Attack Toolkit For Offensive Research
GATOR – GCP Attack Toolkit for Offensive Research, a tool designed to aid in research and exploiting Google Cloud Environments.
It offers a comprehensive range of modules tailored to support users in various attack stages, spanning from Reconnaissance to Impact.
Modules
Resource CategoryPrimary ModuleCommand GroupOperationDescriptionUser Authenticationauth–activateActivate a Specific Authentication Method–addAdd a New Authentication Method–deleteRemove a Specific Authentication Method–listList All Available Authentication MethodsCloud Functionsfunctions–listList All Deployed Cloud Functions–permissionsDisplay Permissions for a Specific Cloud Function–triggersList All Triggers for a Specific Cloud FunctionCloud StoragestoragebucketslistList All Storage BucketspermissionsDisplay Permissions for Storage BucketsCompute Enginecomputeinstancesadd-ssh-keyAdd SSH Key to Compute Instances
Installation
Python 3.11 or newer should be installed. You can verify your Python version with the following command:
python --version Manual Installation via setup.py
git clone https://github.com/anrbn/GATOR.git
cd GATOR
python setup.py install Automated Installation via pip
pip install gator-red Documentation
Have a look at the GATOR Documentation for an explained guide on using GATOR and it’s module!
Issues
Reporting An Issue
If you encounter any problems with this tool, I encourage you to let me know. Here are the steps to report an issue:
1. Check Existing Issues: Before reporting a new issue, please check the existing issues in this repository. Your issue might have already been reported and possibly even resolved.
2. Create a New Issue: If your problem hasn’t been reported, please create a new issue in the GitHub repository. Click the Issues tab and then click New Issue.
3. Describe the Issue: When creating a new issue, please provide as much information as possible. Include a clear and descriptive title, explain the problem in detail, and provide steps to reproduce the issue if possible. Including the version of the tool you’re using and your operating system can also be helpful.
4. Submit the Issue: After you’ve filled out all the necessary information, click Submit new issue.
Your feedback is important, and will help improve the tool. I appreciate your contribution!
Resolving An Issue
I’ll be reviewing reported issues on a regular basis and try to reproduce the issue based on your description and will communicate with you for further information if necessary. Once I understand the issue, I’ll work on a fix.
Please note that resolving an issue may take some time depending on its complexity. I appreciate your patience and understanding.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
SecuSphere – Revolutionizing DevSecOps For Secure Software Development
Welcome to SecuSphere, your one-stop solution for all DevSecOps needs. Our centralized platform is expertly designed to manage and optimize your vulnerability management, CI/CD pipeline integration, security assessments, and DevSecOps practices.
SecuSphere is a comprehensive DevSecOps platform designed to streamline and enhance your organization’s security posture throughout the software development life cycle.
Our platform serves as a centralized hub for vulnerability management, security assessments, CI/CD pipeline integration, and fostering DevSecOps practices and culture. Centralized Vulnerability Management
At the heart of SecuSphere is a powerful vulnerability management system. Our platform collects, processes, and prioritizes vulnerabilities, integrating with a wide array of vulnerability scanners and security testing tools.
Risk-based prioritization and automated assignment of vulnerabilities streamline the remediation process, ensuring that your teams tackle the most critical issues first.
Additionally, our platform offers robust dashboards and reporting capabilities, allowing you to track and monitor vulnerability status in real-time. Seamless CI/CD Pipeline Integration
SecuSphere integrates seamlessly with your existing CI/CD pipelines, providing real-time security feedback throughout your development process.
Our platform enables automated triggering of security scans and assessments at various stages of your pipeline.
Furthermore, SecuSphere enforces security gates to prevent vulnerable code from progressing to production, ensuring that security is built into your applications from the ground up.
This continuous feedback loop empowers developers to identify and fix vulnerabilities early in the development cycle. Comprehensive Security Assessment
SecuSphere offers a robust framework for consuming and analyzing security assessment reports from various CI/CD pipeline stages.
Our platform automates the aggregation, normalization, and correlation of security findings, providing a holistic view of your application’s security landscape.
Intelligent deduplication and false-positive elimination reduce noise in the vulnerability data, ensuring that your teams focus on real threats.
Furthermore, SecuSphere integrates with ticketing systems to facilitate the creation and management of remediation tasks. Cultivating DevSecOps Practices
SecuSphere goes beyond tools and technology to help you drive and accelerate the adoption of DevSecOps principles and practices within your organization.
Our platform provides security training and awareness for developers, security, and operations teams, helping to embed security within your development and operations processes.
SecuSphere aids in establishing secure coding guidelines and best practices and fosters collaboration and communication between security, development, and operations teams.
With SecuSphere, you’ll create a culture of shared responsibility for security, enabling you to build more secure, reliable software.
Embrace the power of integrated DevSecOps with SecuSphere – secure your software development, from code to cloud. Features
* Vulnerability Management: Collect, process, prioritize, and remediate vulnerabilities from a centralized platform, integrating with various vulnerability scanners and security testing tools.
* CI/CD Pipeline Integration: Provide real-time security feedback with seamless CI/CD pipeline integration, including automated security scans, security gates, and a continuous feedback loop for developers.
* Security Assessment: Analyze security assessment reports from various CI/CD pipeline stages with automated aggregation, normalization, correlation of security findings, and intelligent deduplication.
* DevSecOps Practices: Drive and acceler[...]
SecuSphere – Revolutionizing DevSecOps For Secure Software Development
Welcome to SecuSphere, your one-stop solution for all DevSecOps needs. Our centralized platform is expertly designed to manage and optimize your vulnerability management, CI/CD pipeline integration, security assessments, and DevSecOps practices.
SecuSphere is a comprehensive DevSecOps platform designed to streamline and enhance your organization’s security posture throughout the software development life cycle.
Our platform serves as a centralized hub for vulnerability management, security assessments, CI/CD pipeline integration, and fostering DevSecOps practices and culture. Centralized Vulnerability Management
At the heart of SecuSphere is a powerful vulnerability management system. Our platform collects, processes, and prioritizes vulnerabilities, integrating with a wide array of vulnerability scanners and security testing tools.
Risk-based prioritization and automated assignment of vulnerabilities streamline the remediation process, ensuring that your teams tackle the most critical issues first.
Additionally, our platform offers robust dashboards and reporting capabilities, allowing you to track and monitor vulnerability status in real-time. Seamless CI/CD Pipeline Integration
SecuSphere integrates seamlessly with your existing CI/CD pipelines, providing real-time security feedback throughout your development process.
Our platform enables automated triggering of security scans and assessments at various stages of your pipeline.
Furthermore, SecuSphere enforces security gates to prevent vulnerable code from progressing to production, ensuring that security is built into your applications from the ground up.
This continuous feedback loop empowers developers to identify and fix vulnerabilities early in the development cycle. Comprehensive Security Assessment
SecuSphere offers a robust framework for consuming and analyzing security assessment reports from various CI/CD pipeline stages.
Our platform automates the aggregation, normalization, and correlation of security findings, providing a holistic view of your application’s security landscape.
Intelligent deduplication and false-positive elimination reduce noise in the vulnerability data, ensuring that your teams focus on real threats.
Furthermore, SecuSphere integrates with ticketing systems to facilitate the creation and management of remediation tasks. Cultivating DevSecOps Practices
SecuSphere goes beyond tools and technology to help you drive and accelerate the adoption of DevSecOps principles and practices within your organization.
Our platform provides security training and awareness for developers, security, and operations teams, helping to embed security within your development and operations processes.
SecuSphere aids in establishing secure coding guidelines and best practices and fosters collaboration and communication between security, development, and operations teams.
With SecuSphere, you’ll create a culture of shared responsibility for security, enabling you to build more secure, reliable software.
Embrace the power of integrated DevSecOps with SecuSphere – secure your software development, from code to cloud. Features
* Vulnerability Management: Collect, process, prioritize, and remediate vulnerabilities from a centralized platform, integrating with various vulnerability scanners and security testing tools.
* CI/CD Pipeline Integration: Provide real-time security feedback with seamless CI/CD pipeline integration, including automated security scans, security gates, and a continuous feedback loop for developers.
* Security Assessment: Analyze security assessment reports from various CI/CD pipeline stages with automated aggregation, normalization, correlation of security findings, and intelligent deduplication.
* DevSecOps Practices: Drive and acceler[...]
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials SecuSphere – Revolutionizing DevSecOps For Secure Software Development Welcome to SecuSphere, your one-stop solution for all DevSecOps needs. Our centralized platform is expertly designed to manage and optimize your vulnerability management…
ate the adoption of DevSecOps principles and practices within your team. Benefit from our security training, secure coding guidelines, and collaboration tools. Dashboard And Reporting
SecuSphere offers built-in dashboards and reporting capabilities that allow you to easily track and monitor the status of vulnerabilities.
With our risk-based prioritization and automated assignment features, vulnerabilities are efficiently managed and sent to the relevant teams for remediation. API And Web Console
SecuSphere provides a comprehensive REST API and Web Console.
This allows for greater flexibility and control over your security operations, ensuring you can automate and integrate SecuSphere into your existing systems and workflows as seamlessly as possible.
For more information please refer to our Official Rest API Documentation Integration With Ticketing Systems
SecuSphere integrates with popular ticketing systems, enabling the creation and management of remediation tasks directly within the platform.
This helps streamline your security operations and ensure faster resolution of identified vulnerabilities. Security Training And Awareness
SecuSphere is not just a tool, it’s a comprehensive solution that drives and accelerates the adoption of DevSecOps principles and practices.
We provide security training and awareness for developers, security, and operations teams, and aid in establishing secure coding guidelines and best practices. User Guide
Get started with SecuSphere using our comprehensive user guide. Installation
You can install SecuSphere by cloning the repository, setting up locally, or using Docker. Clone The Repository "$ git clone https://github.com/SecurityUniversalOrg/SecuSphere.git" Setup Local Setup
Navigate to the source directory and run the Python file: "$ cd src/
$ python run.py" Dockerfile Setup
Build and run the Dockerfile in the cicd directory: "$ # From repository root
$ docker build -t secusphere:latest .
$ docker run secusphere:latest" Docker Compose
Use Docker Compose in the "ci_cd/iac/" directory: "$ cd ci_cd/iac/
$ docker-compose -f secusphere.yml up" Pull From Docker Hub
Pull the latest version of SecuSphere from Docker Hub and run it: "$ docker pull securityuniversal/secusphere:latest
$ docker run -p 8081:80 -d secusphere:latest"
SecuSphere offers built-in dashboards and reporting capabilities that allow you to easily track and monitor the status of vulnerabilities.
With our risk-based prioritization and automated assignment features, vulnerabilities are efficiently managed and sent to the relevant teams for remediation. API And Web Console
SecuSphere provides a comprehensive REST API and Web Console.
This allows for greater flexibility and control over your security operations, ensuring you can automate and integrate SecuSphere into your existing systems and workflows as seamlessly as possible.
For more information please refer to our Official Rest API Documentation Integration With Ticketing Systems
SecuSphere integrates with popular ticketing systems, enabling the creation and management of remediation tasks directly within the platform.
This helps streamline your security operations and ensure faster resolution of identified vulnerabilities. Security Training And Awareness
SecuSphere is not just a tool, it’s a comprehensive solution that drives and accelerates the adoption of DevSecOps principles and practices.
We provide security training and awareness for developers, security, and operations teams, and aid in establishing secure coding guidelines and best practices. User Guide
Get started with SecuSphere using our comprehensive user guide. Installation
You can install SecuSphere by cloning the repository, setting up locally, or using Docker. Clone The Repository "$ git clone https://github.com/SecurityUniversalOrg/SecuSphere.git" Setup Local Setup
Navigate to the source directory and run the Python file: "$ cd src/
$ python run.py" Dockerfile Setup
Build and run the Dockerfile in the cicd directory: "$ # From repository root
$ docker build -t secusphere:latest .
$ docker run secusphere:latest" Docker Compose
Use Docker Compose in the "ci_cd/iac/" directory: "$ cd ci_cd/iac/
$ docker-compose -f secusphere.yml up" Pull From Docker Hub
Pull the latest version of SecuSphere from Docker Hub and run it: "$ docker pull securityuniversal/secusphere:latest
$ docker run -p 8081:80 -d secusphere:latest"
Uncovering hidden XSS vulnerabilities through advanced payload injection
Cross-Site Scripting (XSS) vulnerabilities continue to be a significant threat to web applications. Even with improved security practices…Continue reading on Medium »
Read more...
Cross-Site Scripting (XSS) vulnerabilities continue to be a significant threat to web applications. Even with improved security practices…Continue reading on Medium »
Read more...
Medium
Uncovering hidden XSS vulnerabilities through advanced payload injection
Cross-Site Scripting (XSS) vulnerabilities continue to be a significant threat to web applications. Even with improved security practices…
Top 10 XSS techniques that every bug bounty hunter should know”
Cross-Site Scripting (XSS) is a common and potentially dangerous security vulnerability that continues to plague web applications.Continue reading on Medium »
Read more...
Cross-Site Scripting (XSS) is a common and potentially dangerous security vulnerability that continues to plague web applications.Continue reading on Medium »
Read more...
Medium
Top 10 XSS techniques that every bug bounty hunter should know”
Cross-Site Scripting (XSS) is a common and potentially dangerous security vulnerability that continues to plague web applications. As a bug…
Bug Hunting: An Extension that Makes the Job Easier
Bismillah (in the name of Allah, the Merciful) #FreepalestineContinue reading on Medium »
Read more...
Bismillah (in the name of Allah, the Merciful) #FreepalestineContinue reading on Medium »
Read more...
Medium
Bug Hunting: An Extension that Makes the Job Easier
Hidden treasure JS
Open redirect & rXSS via profile image
Hello hackers, In this article, I will demonstrate how I found an open redirect by uploading an SVG image as a profile avatar.Continue reading on Medium »
Read more...
Hello hackers, In this article, I will demonstrate how I found an open redirect by uploading an SVG image as a profile avatar.Continue reading on Medium »
Read more...
Medium
Open redirect & rXSS via profile image
Hello hackers,
In this article, I will demonstrate how I found an open redirect by uploading an SVG image as a profile avatar.
In this article, I will demonstrate how I found an open redirect by uploading an SVG image as a profile avatar.
LooneyPwner - Exploit Tool For CVE-2023-4911, Targeting The 'Looney Tunables' Glibc Vulnerability In Various Linux Distributions
http://www.kitploit.com/2023/10/looneypwner-exploit-tool-for-cve-2023.html
http://www.kitploit.com/2023/10/looneypwner-exploit-tool-for-cve-2023.html
Exploit tool for CVE-2023-4911, targeting the 'Looney Tunables' glibc vulnerability (https://www.kitploit.com/search/label/Vulnerability) in various Linux distributions. LooneyPwner is a proof-of-concept (PoC) exploit tool targeting the critical buffer overflow (https://www.kitploit.com/search/label/Buffer%20Overflow) vulnerability, nicknamed "Looney Tunables," found in the GNU C Library (glibc). This flaw, officially tracked as CVE-2023-4911, is present in various Linux distributions, posing significant risks, including unauthorized data access and system alterations.
The vulnerability in the GNU C Library (glibc) was disclosed last week, with notable security researchers and analysts releasing PoC exploits, indicating the potential for widespread attacks. The flaw, discovered by Qualys researchers, can grant attackers root privileges on various Linux distributions including Fedora, Ubuntu, and Debian. Unauthorized root access provides attackers unrestricted authority, enabling them to: Modify, delete, or steal sensitive data. Install malicious software or backdoors. Facilitate ongoing attacks that may remain undetected (https://www.kitploit.com/search/label/Undetected) for extended periods. Cause data breaches, accessing customer data, intellectual property, and financial records. Disrupt critical system operations, potentially causing service outages and harming an organization's reputation. LooneyPwner exploits (https://www.kitploit.com/search/label/Exploits) the "Looney Tunables" flaw, targeting affected glibc versions. The tool: Detects the installed glibc version. Checks for vulnerability status. Offers an option for exploitation (https://www.kitploit.com/search/label/Exploitation) if vulnerable. chmod +x looneypwner.sh
./looneypwner.sh
This tool is intended for educational purposes and security research only. The user assumes all responsibility for any damages or misuse resulting from its use. This exploit code is based on the work of leesh3288 (https://github.com/leesh3288/CVE-2023-4911). A big thanks to him for the foundational work on the exploit.
Download LooneyPwner (https://github.com/chaudharyarjun/LooneyPwner)
The vulnerability in the GNU C Library (glibc) was disclosed last week, with notable security researchers and analysts releasing PoC exploits, indicating the potential for widespread attacks. The flaw, discovered by Qualys researchers, can grant attackers root privileges on various Linux distributions including Fedora, Ubuntu, and Debian. Unauthorized root access provides attackers unrestricted authority, enabling them to: Modify, delete, or steal sensitive data. Install malicious software or backdoors. Facilitate ongoing attacks that may remain undetected (https://www.kitploit.com/search/label/Undetected) for extended periods. Cause data breaches, accessing customer data, intellectual property, and financial records. Disrupt critical system operations, potentially causing service outages and harming an organization's reputation. LooneyPwner exploits (https://www.kitploit.com/search/label/Exploits) the "Looney Tunables" flaw, targeting affected glibc versions. The tool: Detects the installed glibc version. Checks for vulnerability status. Offers an option for exploitation (https://www.kitploit.com/search/label/Exploitation) if vulnerable. chmod +x looneypwner.sh
./looneypwner.sh
This tool is intended for educational purposes and security research only. The user assumes all responsibility for any damages or misuse resulting from its use. This exploit code is based on the work of leesh3288 (https://github.com/leesh3288/CVE-2023-4911). A big thanks to him for the foundational work on the exploit.
Download LooneyPwner (https://github.com/chaudharyarjun/LooneyPwner)
16.2 Lab: Clickjacking with form input data prefilled from a URL parameter | 2023
The goal of the lab is to change the email address of the user by prepopulating a form using a URL parameter and enticing the user to…Continue reading on Medium »
Read more...
The goal of the lab is to change the email address of the user by prepopulating a form using a URL parameter and enticing the user to…Continue reading on Medium »
Read more...
Medium
16.2 Lab: Clickjacking with form input data prefilled from a URL parameter | 2023
The goal of the lab is to change the email address of the user by prepopulating a form using a URL parameter and enticing the user to…
Exploring the use of XSS in newer technologies such as WebSockets and WebRTC
https://medium.com/@Land2Cyber/exploring-the-use-of-xss-in-newer-technologies-such-as-websockets-and-webrtc-649f72bbb160?source=rss------bug_bounty-5
https://medium.com/@Land2Cyber/exploring-the-use-of-xss-in-newer-technologies-such-as-websockets-and-webrtc-649f72bbb160?source=rss------bug_bounty-5
Cross-Site Scripting (XSS) is a well-known web security vulnerability that has plagued web applications for years. While it typically…Continue reading on Medium » (https://medium.com/@Land2Cyber/exploring-the-use-of-xss-in-newer-technologies-such-as-websockets-and-webrtc-649f72bbb160?source=rss------bug_bounty-5)
Uncovering hidden XSS vulnerabilities through advanced payload injection
https://medium.com/@Land2Cyber/uncovering-hidden-xss-vulnerabilities-through-advanced-payload-injection-3e93f53f4301?source=rss------bug_bounty-5
https://medium.com/@Land2Cyber/uncovering-hidden-xss-vulnerabilities-through-advanced-payload-injection-3e93f53f4301?source=rss------bug_bounty-5
Cross-Site Scripting (XSS) vulnerabilities continue to be a significant threat to web applications. Even with improved security practices…Continue reading on Medium » (https://medium.com/@Land2Cyber/uncovering-hidden-xss-vulnerabilities-through-advanced-payload-injection-3e93f53f4301?source=rss------bug_bounty-5)
“Unraveling the Data Maze A Beginner’s Guide to Data Science”
In the age of information, data has become the new currency. It is the driving force behind decision-making, innovation, and progress in…Continue reading on Medium »
Read more...
In the age of information, data has become the new currency. It is the driving force behind decision-making, innovation, and progress in…Continue reading on Medium »
Read more...
Medium
“Unraveling the Data Maze A Beginner’s Guide to Data Science”
In the age of information, data has become the new currency. It is the driving force behind decision-making, innovation, and progress in…
“Beyond Numbers The Art and Science of Data Analysis”
In the age of information, data has become the lifeblood of decision-making, innovation, and progress. But data analysis is not just about…Continue reading on Medium »
Read more...
In the age of information, data has become the lifeblood of decision-making, innovation, and progress. But data analysis is not just about…Continue reading on Medium »
Read more...
Medium
“Beyond Numbers The Art and Science of Data Analysis”
In the age of information, data has become the lifeblood of decision-making, innovation, and progress. But data analysis is not just about…