Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Vimana - An Experimental Security Framework That Aims To Provide Resources For Auditing Python Web Applications

http://3.bp.blogspot.com/-cczMu4yCVFk/YXsv7pWnVUI/AAAAAAAAzCE/cGHZSTd5C5k33P-DzxX1FjHSATpMz5GwgCK4BGAYYCw/w640-h358/vimana-framework_1_vimana1-743256.png
Vimana is a modular security framework designed to audit Python web applications.
The base of the Vimana is composed of crawlers focused on frameworks (in addition to the generic ones for web), trackers, discovery, fuzzer, parser among other types of modules. The main idea, from where the framework emerged, is to identify, through a blackbox approach, configuration flaws and inadequate and/or insufficient implementations that allow unhandled exceptions to be triggered. Depending on the framework settings (or specific libs even when not using frameworks, for example raw wsgi) this can lead to leakage of sensitive and critical information that can allow to compromising the entire application, server, apis, databases, services and any third part software with tokens, secrets or api keys in current exposed environment variables.
Another important step performed by Vimana is to obtain and reconstruct the source code snippets of the affected modules (leaked by exceptions) that allow the discovery of hardcoded credentials, connection strings to databases, vulnerable libraries, in addition to allowing the analysis of logic of the application of a mixed perspective between the black and whitebox approaches, since the initial analysis starts from a blind test, but ends up allowing access to code snippets.
Content

* Getting Started with Vimana
* About this Version
* Vimana is not
* Use Cases
* Acknowledgment
* Disclaimer
Download Vimana-Framework
Dark Reading: Attacks/Breaches
Free Tool Scans Web Servers for Vulnerability to HTTP Header-Smuggling Attacks

A researcher will release an open source tool at Black Hat Europe next week that roots out server weaknesses to a sneaky type of attack.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
CrowdStrike to Buy Zero-Trust SaaS Provider

SecureCircle provides data-level zero-trust control to endpoints.
Dark Reading: Attacks/Breaches
How AI-Driven Security Analytics Speeds Up Enterprise Defense

Fresh off a $250 million Series E round, Devo Technology plans to expand the core security analytics platform with new features to help enterprise defenders work with security data faster and more effectively.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Zscaler’s 2021 Encrypted Attacks Report Reveals 314% Spike in HTTPS Threats

Massive increase in cyberattacks targeting technology and retail industries confirms immediate need for zero-trust security
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
CISA and Partners Coordinate on Security, Combatting Misinformation for Election Day

CISA will host an election situational awareness room to coordinate with federal partners, state and local election officials, private sector election partners, and political organizations to share real-time information and provide support as needed.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
New 'Trojan Source' Method Lets Attackers Hide Vulns in Source Code

Researchers discover a new technique attackers could use to encode vulnerabilities into software while evading detection.
How I was able to find 4 bugs before getting the RCE in NykaaFashion

Hello everyone, today I will be talking about multiple bugs which I got by a single parameter that lead to RCE. Now, let’s start with the…Continue reading on Medium »
Read more...
hacking: security in practice
data leak lookup services

i'm considering getting a subscription from either snusbase or dehashed, but don't have quite enough experience with either to make a good decision, both seem to have pretty much equal pros and cons. to the people who have used both, which do you prefer and why? if neither, are there any similar ones you recommend? thanks in advance.

submitted by /u/ayammerol
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Understanding AppArmor Kernel Enhancement

AppArmor is the new technology in preventing programs rather than users and file-level access. This is an enhancement in the Linux kernel and can be used to easily mitigate the damage caused by adversaries. In this post, you will learn the basics of the AppArmor and its components

https://tbhaxor.com/understanding-apparmor-kernel-enhancement/

submitted by /u/tbhaxor
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video