Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Unpatched Fortinet Bug Allows Firewall Takeovers

https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Unpatched Fortinet Bug Allows Firewall TakeoversPost Views: 92
Reading Time: 1 Minute
The OS command-injection bug, in the web application firewall (WAF) platform known as FortiWeb, will get a patch this week.
An unpatched OS command-injection security vulnerability has been disclosed in Fortinet’s web application firewall (WAF) platform, known as FortiWeb. It could allow privilege escalation and full device takeover, researchers said.

FortiWeb is a cybersecurity defense platform, aimed at protecting business-critical web applications from attacks that target known and unknown vulnerabilities. The firewall has been to keep up with the deployment of new or updated features, or the addition of new web APIs, according to Fortinet.

The bug (CVE pending) exists in FortiWeb’s management interface (version 6.3.11 and prior), and carries a CVSSv3 base score of 8.7 out of 10, making it high-severity. It can allow a remote, authenticated attacker to execute arbitrary commands on the system, via the SAML server configuration page, according to Rapid7 researcher William Vu who discovered the bug.
See Also: Critical Valve Bug Lets Gamers Add Unlimited Funds to Steam Wallets
“Note that while authentication is a prerequisite for this exploit, this vulnerability could be combined with another authentication-bypass issue, such as CVE-2020-29015,” according to a Tuesday writeup on the issue.

Once attackers are authenticated to the management interface of the FortiWeb device, they can smuggle commands using backticks in the “Name” field of the SAML Server configuration page. These commands are then executed as the root user of the underlying operating system.

“An attacker can leverage this vulnerability to take complete control of the affected device, with the highest possible privileges,” according to the writeup. “They might install a persistent shell, crypto mining software, or other malicious software.”

The damage could be worse if the management interface is exposed to the internet: Rapid7 noted that attackers could pivot to the wider network in that case. However, Rapid7 researchers identified less than three hundred appliances that appeared to be doing so.

In the analysis, Vu provided a proof-of-concept exploit code, which uses an HTTP POST request and response.

In light of the disclosure, Fortinet has sped up plans to release a fix for the problem with FortiWeb 6.4.1 — originally planned for the end of August, it will now be available by the end of the week.

“We are working to deliver immediate notification of a workaround to customers and a patch released by the end of the week,” it said in a statement provided to Threatpost.

The firm also noted that Rapid7’s disclosure was a bit of a surprise given vulnerability-disclosure norms in the industry.
See Also: Offensive Security Tool: Warcannon
“The security of our customers is always our first priority. Fortinet recognizes the important role of independent security researchers who work closely with vendors to protect the cybersecurity ecosystem in alignment with their responsible disclosure policies. In addition to directly communicating with researchers, our disclosure policy is clearly outlined on the Fortinet PSIRT Policy page, which includes asking incident submitters to maintain strict confidentiality until complete resolutions are available for customers. As such, we had expected that Rapid7 hold any findings prior to the end of the our 90-day Responsible disclosure window.  We regret that in this instance, individual research was fully disclosed witho[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Unpatched Fortinet Bug Allows Firewall Takeovers https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Unpatched Fortinet Bug Allows Firewall TakeoversPost Views: 92 Reading Time:…
ut adequate notification prior to the 90-day window.”

For now, Rapid7 offered straightforward advice:

“In the absence of a patch, users are advised to disable the FortiWeb device’s management interface from untrusted networks, which would include the internet,” according to Rapid7. “Generally speaking, management interfaces for devices like FortiWeb should not be exposed directly to the internet anyway — instead, they should be reachable only via trusted, internal networks, or over a secure VPN connection.”

The Rapid7 researchers said that the vulnerability appears to be related to CVE-2021-22123, which was patched in June. See Also: Hacking Stories: Andrian Lamo – The ‘homeless’ HackerFortinet: Popular for ExploitThe vendor is no stranger to cybersecurity bugs in its platforms, and Fortinet’s cybersecurity products are popular as exploitation avenues with cyberattackers, including nation-state actors. Users should prepare to patch quickly.

In April, the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) warned that various advanced persistent threats (APTs) were actively exploiting three security vulnerabilities in the Fortinet SSL VPN for espionage. Exploits for CVE-2018-13379, CVE-2019-5591 and CVE-2020-12812 were being used for to gain a foothold within networks before moving laterally and carrying out recon, they warned.

One of those bugs, a Fortinet vulnerability in FortiOS, was also seen being used to deliver a new ransomware strain, dubbed Cring, that is targeting industrial enterprises across Europe.
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-1-90x90.png Bug in Millions of Flawed IoT Devices Lets Attackers Eavesdrop1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Steam-logo-90x90.jpg Critical Valve Bug Lets Gamers Add Unlimited Funds to Steam Wallets2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/tmobile-header-90x90.webp Hacker claims to steal data of 100 million T-mobile customers3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/depositphotos_40325161-stock-photo-microsoft-building-90x90.jpg Microsoft Warns: Another Unpatched PrintNightmare Zero-Day6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/crypto-hack-90x90.jpg Crypto Hack Earned Crooks $600 Million1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/msft-microsoft-logo-2-3-90x90.webp Actively Exploited Windows Zero-Day Gets a Patch1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/botnet-90x90.jpg Auth Bypass Bug Exploited, Affecting Millions of Routers1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/cisco-patch-90x90.png Critical Cisco Bug in VPN Routers Allows Remote Takeover1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/delete-telegram-message-e1628177080885-90x90.jpg MacOS Flaw in Telegram Retrieves Deleted Messages2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/spam-call-90x90.jpg Black Hat: ‘I’m Calling About Your Car Warranty’, aka PII Hijinx2 weeks ago
style="display:block; text-align:center;"
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post Unpatched Fortinet Bug Allows Firewall Takeovers first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
MSSQL Penetration Testing:Nmap

To obtain basic information such as database names, usernames, names of tables, etc from the SQL servers on the Windows operating system, we will execute penetration testing using Nmap scripts. MSSQL is Microsoft SQL Server for database management in the network. By default, it runs on port 1433. In our previousarticle, we had set up a Microsoft SQL Server in Windows 10. Table of Content· RequirementRequirementAttacker:Kali Linux (NMAP)Target:Windows 10 (MS SQL Server)locate *.nse | grep ms-sqlhttps://1.bp.blogspot.com/-4dYTFUFC-Xg/YR4qfU4QL3I/AAAAAAAAyNE/teNjU5BPa-8E8W3ctp5S47j9_eqmNfV3QCLcBGAsYHQ/s16000/0.png Enumerating versionThis Script will attempt to determine configuration and version information for Microsoft SQL Server instances.Credential Brute ForcePerforms brute-force password auditing against Ms-SQL servers and connection timeout (default: “5s”). All we need are dictionaries for usernames and passwords, which will be passed as arguments.Execute SQL QueryOnce you have retrieved the login credential use these credentials in the NMAP script to execute MS –SQL query. Given below will try to execute certain query “sp_database” against Microsoft SQL Server.NetBIOS EnumerationGiven below NMAP script will enumerate information from remote Microsoft SQL services with NTLM authentication enabled.MS-SQL Password Hash DumpThe following command will dump the password hashes from an MS-SQL server in a format suitable for cracking by tools such as John-the-ripper. To do so, the user needs to have the appropriate DB privileges.___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles|Raj Chandel's Blog MSSQL Penetration Testing:Nmap To obtain basic information such as database names, usernames, names of tables, etc from the SQL servers on the Windows operating system, we will execute penetration testing using Nmap scripts.…
ame=sa,mssql.password=Password@1 192.168.1.146Exploit XP_cmdshell FunctionThe xp_cmdshell is a function of Microsoft SQL Server that allows system administrators to execute an operating system command. By default, the xp_cmdshell option is disabled. NMAP script will attempt to run a command using the command shell of Microsoft SQL Server if found xp_cmdshell is enabled in the targeted serverTest Empty Password LoginIf the administrator of Microsoft-SQL Server left the password blank for login, the attacker can direct login into the database server; as shown in the image below, we are investigating the property of a user's account "sa."Enumerate Database TablesThe following command will attempt to fetch a list of tables from inside the Microsoft SQL server bypassing login credentials as an argument through Nmap script.___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
MSSQL for Pentester: Nmap

To obtain basic information such as database names, usernames, names of tables, etc from the SQL servers on the Windows operating system, we will execute penetration testing using Nmap scripts. MSSQL is Microsoft SQL Server for database management in the network. By default, it runs on port 1433. In our previous article,

The post MSSQL for Pentester: Nmap appeared first on Hacking Articles.

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
NinjaDroid : Ninja Reverse Engineering On Android APK Packages

NinjaDroid is a simple tool to reverse engineering Android APK packages. $ snap install ninjadroid –channel=beta Overview NinjaDroid uses AXMLParser together with a series of Python scripts based on aapt, keytool, string and such to extract a series of information from a given APK package, such as: List of files of the APK: file name, size, MD5, SHA-1, SHA-256 and SHA-512 […]

The post NinjaDroid : Ninja Reverse Engineering On Android APK Packages appeared first on Kali Linux Tutorials.

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Thankyou for your response!

I made a post last week regarding CTF teams. Needless to say the response was amazing! I was shocked to see how many of us are in the same position (struggling to find like minded people to do CTFs with). It's for this reason that I decided to make a discord server where we can do CTFs, talk about tools, methodology and programming. Hope to see you there! :)

I can't include the link because the post will get taken down. Message me and I'll send it right away!

P.s Spread the word!

submitted by /u/bolgz
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Allstar is a GitHub App installed on organizations or repositories (https://www.kitploit.com/search/label/Repositories) to set and enforce security policies. Its goal is to be able to continuously monitor and detect any GitHub setting or repository file contents that may be risky or do not follow security best practices. If Allstar finds a repository to be out of compliance, it will take an action such as create an issue or restore security settings. The specific policies are intended to be highly configurable, to try to meet the needs of different project communities and organizations. Also, developing and contributing new policies is intended to be easy. Allstar is developed under the OpenSSF (https://openssf.org/) organization, as a part of the Securing Critical Projects Working Group (https://github.com/ossf/wg-securing-critical-projects). The OpenSSF runs an instance of Allstar here (https://github.com/apps/allstar-app) for anyone to install and use on their GitHub organizations. However, Allstar can be run by anyone if need be, see the operator docs (https://github.com/ossf/allstar/blob/main/operator.md) for more details.
Quick start
Install Allstar GitHub App (https://github.com/apps/allstar-app) on your organizations and repositories. When installing Allstar, you may review the permissions requested. Allstar asks for read access (https://www.kitploit.com/search/label/Access) to most settings and file contents to detect security compliance. It requests write access to issues to create issues, and to checks to allow the block action. Follow the quick start instructions (https://github.com/ossf/allstar/blob/main/quick-start.md) to setup the configuration files needed to enable Allstar on your repositories. For more details on advanced configuration, see below.
Help! I'm getting issues created by Allstar and I don't want them. (https://github.com/ossf/allstar/blob/main/opt-out.md)

Enable Configuration
Allstar can be enabled on individual repositories at the app level, with the option of enabling or disabling each security policy individually. For organization-level configuration, create a repository named .allstar in your organization. Then create a file called allstar.yaml in that repository. Allstar can either be set to an opt-in or opt-out strategy. In opt-in, only those repositories explicitly listed are enabled. In opt-out, all repositories are enabled, and repositories would need to be explicitly added to opt-out. Allstar is set to opt-in by default, and therefore is not enabled on any repository immediately after installation. To continue with the default opt-in strategy, list the repositories for Allstar to be enabled on in your organization like so: optConfig:
optInRepos:
- repo-one
- repo-two
To switch to the opt-out strategy (recommended), set that option to true: optConfig:
optOutStrategy: true
If you wish to enable Allstar on all but a few repositories, you may use opt-out and list the repositories to disable: optConfig:
optOutStrategy: true
optOutRepos:
- repo-one
- repo-two

Repository Override
Individual repositories can also opt in or out using configuration files inside those repositories. For example, if the organization is configured with the opt-out strategy, a repository may opt itself out by including the file .allstar/allstar.yaml with the contents: optConfig:
optOut: true
Conversely, this allows repositories to opt-in and enable Allstar when the organization is configured with the opt-in strategy. Because opt-in is the default strategy, this is how Allstar works if the .allstar repository doesn't exist. At the organization-level allstar.yaml, repository override (https://www.kitploit.com/search/label/OverRide) may be disabled with the setting: optConfig:
disableRepoOverride: true

___________________________
@hacking_Attack
@Hacking_Video
Each individual policy configuration file (see below) also contains the exact same optConfig configuration object. This allows granularity to enable policies on individual repositories. A policy will not take action unless it is enabled and Allstar is enabled as a whole.
Definition
Organization level enable configuration (https://pkg.go.dev/github.com/ossf/allstar@v0.0.0-20210728182754-005854d69ba7/pkg/config#OrgOptConfig) Repository Override enable configuration (https://pkg.go.dev/github.com/ossf/allstar@v0.0.0-20210728182754-005854d69ba7/pkg/config#RepoOptConfig)
Actions
Each policy can be configured with an action that Allstar will take when it detects a repository to be out of compliance. log: This is the default action, and actually takes place for all actions. All policy run results and details are logged. Logs are currently only visible to the app operator, plans to expose these are under discussion. issue: This action creates a GitHub issue. Only one issue is created per policy, and the text describes the details of the policy violation. If the issue is already open, it is pinged with a comment every 24 hours (not currently user configurable). Once the violation is addressed, the issue will be automatically closed by Allstar within 5-10 minutes. fix: This action is policy specific. The policy will make the changes to the GitHub settings to correct the policy violation. Not all policies will be able to support this (see below). Proposed, but not yet implemented actions. Definitions will be added in the future. block: Allstar can set a GitHub Status Check (https://docs.github.com/en/github/collaborating-with-pull-requests/collaborating-on-repositories-with-code-quality-features/about-status-checks) and block any PR in the repository from being merged if the check fails. email: Allstar would send an email (https://www.kitploit.com/search/label/Email) to the repository administrator(s). rpc: Allstar would send an rpc to some organization-specific system.
Policies
Similar to the Allstar app enable configuration, all policies are enabled and configured with a yaml file in either the organization's .allstar repository, or the repository's .allstar directory. As with the app, policies are opt-in by default, also the default log action won't produce visible results. A simple way to enable all policies is to create a yaml file for each policy with the contents: optConfig:
optOutStrategy: true
action: issue
The fix action is not implemented in any policy yet, but will be implemented in those policies where it is applicable soon.
Branch Protection
This policy's config file is named branch_protection.yaml, and the config definitions are here (https://pkg.go.dev/github.com/ossf/allstar@v0.0.0-20210728182754-005854d69ba7/pkg/policies/branch#OrgConfig). The branch protection (https://www.kitploit.com/search/label/Protection) policy checks that GitHub's branch protection settings (https://docs.github.com/en/github/administering-a-repository/defining-the-mergeability-of-pull-requests/about-protected-branches) are setup correctly according to the specified configuration. The issue text will describe which setting is incorrect. See GitHub's documentation (https://docs.github.com/en/github/administering-a-repository/defining-the-mergeability-of-pull-requests/about-protected-branches) for correcting settings.
Binary Artifacts
This policy's config file is named binary_artifacts.yaml, and the config definitions are here (https://pkg.go.dev/github.com/ossf/allstar@v0.0.0-20210728182754-005854d69ba7/pkg/policies/binary#OrgConfig). This policy incorporates the check from scorecard (https://github.com/ossf/scorecard/#scorecard-checks). Remove the binary artifact from the repository to achieve compliance. As the scorecard results can be verbose, you may need to run scorecard itself (https://github.com/ossf/scorecard) to see all the detailed information.

___________________________
@hacking_Attack
@Hacking_Video
Outside Collaborators
This policy's config file is named outside.yaml, and the config definitions are here (https://pkg.go.dev/github.com/ossf/allstar@v0.0.0-20210728182754-005854d69ba7/pkg/policies/outside#OrgConfig). This policy checks if any Outside Collaborators (https://docs.github.com/en/organizations/managing-access-to-your-organizations-repositories/adding-outside-collaborators-to-repositories-in-your-organization) have either administrator(default) or push(optional) access to the repository. Only organization members should have this access, as otherwise untrusted members can change admin level settings and commit malicious code.
SECURITY.md
This policy's config file is named security.yaml, and the config definitions are here (https://pkg.go.dev/github.com/ossf/allstar@v0.0.0-20210728182754-005854d69ba7/pkg/policies/security#OrgConfig). This policy checks that the repository has a security policy file in SECURITY.md and that it is not empty. The created issue will have a link to the GitHub tab (https://docs.github.com/en/code-security/getting-started/adding-a-security-policy-to-your-repository) that helps you commit a security policy to your repository.
Future Policies
Ensure dependabot is enabled. Check that dependencies are pinned/frozen. More checks from scorecard (https://github.com/ossf/scorecard/#scorecard-checks).
Example Config Repository
See this repo (https://github.com/GoogleContainerTools/.allstar) as an example of Allstar config being used. As the organization administrator, consider a README.md with some information on how Allstar is being used in your organization.
Contribute Policies
Interface definition. (https://github.com/ossf/allstar/blob/main/pkg/policydef/policydef.go) Both the SECURITY.md (https://github.com/ossf/allstar/blob/main/pkg/policies/security/security.go) and Outside Collaborators (https://github.com/ossf/allstar/blob/main/pkg/policies/outside/outside.go) policies are quite simple to understand and good examples to copy.

Download Allstar (https://github.com/ossf/allstar)

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Allstar - GitHub App To Set And Enforce Security Policies

https://1.bp.blogspot.com/-QBp970ROsUE/YRvhZg4c-dI/AAAAAAAAqtU/g9PlFtxjpQQIibsAQYU1g9fF9XSMSNZrwCNcBGAsYHQ/w308-h400/Allstar.png Allstar is a GitHub App installed on organizations or repositories to set and enforce security policies. Its goal is to be able to continuously monitor and detect any GitHub setting or repository file contents that may be risky or do not follow security best practices. If Allstar finds a repository to be out of compliance, it will take an action such as create an issue or restore security settings.

The specific policies are intended to be highly configurable, to try to meet the needs of different project communities and organizations. Also, developing and contributing new policies is intended to be easy.

Allstar is developed under the OpenSSF organization, as a part of the Securing Critical Projects Working Group. The OpenSSF runs an instance of Allstar here for anyone to install and use on their GitHub organizations. However, Allstar can be run by anyone if need be, see the operator docs for more details. Quick startInstall Allstar GitHub App on your organizations and repositories. When installing Allstar, you may review the permissions requested. Allstar asks for read access to most settings and file contents to detect security compliance. It requests write access to issues to create issues, and to checks to allow the blockaction.

Follow the quick start instructions to setup the configuration files needed to enable Allstar on your repositories. For more details on advanced configuration, see below. Help! I'm getting issues created by Allstar and I don't want them.Enable ConfigurationAllstar can be enabled on individual repositories at the app level, with the option of enabling or disabling each security policy individually. For organization-level configuration, create a repository named .allstarin your organization. Then create a file called allstar.yamlin that repository.

Allstar can either be set to an opt-in or opt-out strategy. In opt-in, only those repositories explicitly listed are enabled. In opt-out, all repositories are enabled, and repositories would need to be explicitly added to opt-out. Allstar is set to opt-in by default, and therefore is not enabled on any repository immediately after installation. To continue with the default opt-in strategy, list the repositories for Allstar to be enabled on in your organization like so: optConfig:
optInRepos:
- repo-one
- repo-two
To switch to the opt-out strategy (recommended), set that option to true: optConfig:
optOutStrategy: true
If you wish to enable Allstar on all but a few repositories, you may use opt-out and list the repositories to disable: optConfig:
optOutStrategy: true
optOutRepos:
- repo-one
- repo-two
Repository OverrideIndividual repositories can also opt in or out using configuration files inside those repositories. For example, if the organization is configured with the opt-out strategy, a repository may opt itself out by including the file .allstar/allstar.yamlwith the contents: optConfig:
optOut: true
Conversely, this allows repositories to opt-in and enable Allstar when the organization is configured with the opt-in strategy. Because opt-in is the default strategy, this is how Allstar works if the .allstarrepository doesn't exist.

At the organization-level allstar.yaml, repository override may be disabled with the setting: optConfig:
disableRepoOverride: true
This allows an organization-owner to have a central point of approval for repositories to request an opt-out through a GitHub PR. Understandably, Allsta[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! Allstar - GitHub App To Set And Enforce Security Policies https://1.bp.blogspot.com/-QBp970ROsUE/YRvhZg4c-dI/AAAAAAAAqtU/g9PlFtxjpQQIibsAQYU1g9fF9XSMSNZrwCNcBGAsYHQ/w308-h400/Allstar.png Allstar is a GitHub App installed on organizations…
r or individual policies may not make sense for all repositories. Policy EnableEach individual policy configuration file (see below) also contains the exact same optConfigconfiguration object. This allows granularity to enable policies on individual repositories. A policy will not take action unless it is enabled and Allstar is enabled as a whole. Definition* Organization level enable configuration
* Repository Override enable configuration ActionsEach policy can be configured with an action that Allstar will take when it detects a repository to be out of compliance.

* log: This is the default action, and actually takes place for all actions. All policy run results and details are logged. Logs are currently only visible to the app operator, plans to expose these are under discussion.
* issue: This action creates a GitHub issue. Only one issue is created per policy, and the text describes the details of the policy violation. If the issue is already open, it is pinged with a comment every 24 hours (not currently user configurable). Once the violation is addressed, the issue will be automatically closed by Allstar within 5-10 minutes.
* fix: This action is policy specific. The policy will make the changes to the GitHub settings to correct the policy violation. Not all policies will be able to support this (see below).

Proposed, but not yet implemented actions. Definitions will be added in the future.

* block: Allstar can set a GitHub Status Check and block any PR in the repository from being merged if the check fails.
* email: Allstar would send an email to the repository administrator(s).
* rpc: Allstar would send an rpc to some organization-specific system. PoliciesSimilar to the Allstar app enable configuration, all policies are enabled and configured with a yaml file in either the organization's .allstarrepository, or the repository's .allstardirectory. As with the app, policies are opt-in by default, also the default logaction won't produce visible results. A simple way to enable all policies is to create a yaml file for each policy with the contents: optConfig:
optOutStrategy: true
action: issue
The fixaction is not implemented in any policy yet, but will be implemented in those policies where it is applicable soon. Branch ProtectionThis policy's config file is named branch_protection.yaml, and the config definitions are here.

The branch protection policy checks that GitHub's branch protection settings are setup correctly according to the specified configuration. The issue text will describe which setting is incorrect. See GitHub's documentation for correcting settings. Binary ArtifactsThis policy's config file is named binary_artifacts.yaml, and the config definitions are here.

This policy incorporates the check from scorecard. Remove the binary artifact from the repository to achieve compliance. As the scorecard results can be verbose, you may need to run scorecard itself to see all the detailed information. Outside CollaboratorsThis policy's config file is named outside.yaml, and the config definitions are here.

This policy checks if any Outside Collaborators have either administrator(default) or push(optional) access to the repository. Only organization members should have this access, as otherwise untrusted members can change admin level settings and commit malicious code. SECURITY.mdThis policy's config file is named security.yaml, and the config definitions are here.

This policy checks that the repository has a security policy file in SECURITY.mdand that it is not empty. The created issue will have a link to the GitHub tab that helps you commit a security policy [...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
r or individual policies may not make sense for all repositories. Policy EnableEach individual policy configuration file (see below) also contains the exact same optConfigconfiguration object. This allows granularity to enable policies on individual repositories.…
to your repository. Future Policies* Ensure dependabot is enabled.
* Check that dependencies are pinned/frozen.
* More checks from scorecard. Example Config RepositorySee this repo as an example of Allstar config being used. As the organization administrator, consider a README.md with some information on how Allstar is being used in your organization. Contribute PoliciesInterface definition.

Both the SECURITY.md and Outside Collaborators policies are quite simple to understand and good examples to copy. Download Allstar

___________________________
@hacking_Attack
@Hacking_Video