1year anniversary of BugBountyHunter & our second Hackevent
https://zseano.medium.com/catching-up-with-zseano-our-1year-anniversary-of-bugbountyhunter-our-second-hackevent-fc15e3d2d594?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://zseano.medium.com/catching-up-with-zseano-our-1year-anniversary-of-bugbountyhunter-our-second-hackevent-fc15e3d2d594?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
1year anniversary of BugBountyHunter & our second Hackevent
Sorry for the silence from me lately with regards to any new writeups or anything interesting! The new dad life has been something…
Sorry for the silence from me lately with regards to any new writeups or anything interesting! The new dad life has been something…Continue reading on Medium » (https://zseano.medium.com/catching-up-with-zseano-our-1year-anniversary-of-bugbountyhunter-our-second-hackevent-fc15e3d2d594?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
1year anniversary of BugBountyHunter & our second Hackevent
Sorry for the silence from me lately with regards to any new writeups or anything interesting! The new dad life has been something…
Kubernetes-Goat - Is A "Vulnerable By Design" Kubernetes Cluster. Designed To Be An Intentionally Vulnerable Cluster Environment To Learn And Practice Kubernetes Security
The Kubernetes Goat is designed to be an intentionally vulnerable cluster environment to learn and practice Kubernetes security.Refer to https://madhuakula.com/kubernetes-goat for the guide.Show us somePlease feel free to send us a PR and show some Upcoming Training's and SessionsDEFCON DEMO Labshttps://forum.defcon.org/node/237237Cloud Village - DEFCONhttps://cloud-village.org/#talks?collapseMadhuAkulaRecent Kubernetes Goat PresentationsOWASP Bay Area Meetup DEFCON Red Team VillageJust click and Play in the browser for free using Katacoda Playground - Try nowhttps://katacoda.com/madhuakula/scenarios/kubernetes-goatSetting up Kubernetes GoatBefore we set up the Kubernetes Goat, ensure that you have created and have admin access to the Kubernetes clusterkubectl version --shortSet up the helm version 2 in your path as helm2. Refer to helm releases for more information about setuphelm2 --helpThen finally setup Kubernetes Goat by running the following commandgit clone https://github.com/madhuakula/kubernetes-goat.gitcd kubernetes-goatbash setup-kubernetes-goat.shTo export the ports/services locally to start learning, run the following commandbash access-kubernetes-goat.shThen navigate to http://127.0.0.1:1234Kubernetes Goat - KIND setupIf you want to setup Kubernetes Goat using KIND, refer to kind-setupScenariosSensitive keys in code-basesDIND (docker-in-docker) exploitationSSRF in K8S worldContainer escape to access host systemDocker CIS Benchmarks analysisKubernetes CIS Benchmarks analysisAttacking private registryNodePort exposed servicesHelm v2 tiller to PwN the clusterAnalysing crypto miner containerKubernetes Namespaces bypassGaining environment informationDoS the memory/CPU resourcesHacker Container previewHidden in layersRBAC Least Privileges MisconfigurationKubeAudit - Audit Kubernetes ClustersSysdig Falco - Runtime Security Monitoring & DetectionPopeye - A Kubernetes Cluster SanitizerSecure network boundaries using NSPShowcasePresented at OWASP Bay Area Meetup at https://youtu.be/DQllxpb46YwPresented at DEF CON RED Team Village https://youtu.be/aEaSZJRbnToPresented at OWASP San Diego at https://www.meetup.com/Open-Web-Application-Security-Project-San-Diego-OWASP-SD/events/hmbbkrybckbvb/Featured in the official Kubernetes Podcast at https://kubernetespodcast.com/episode/109-kubermaticFeatured in tl;dr sec https://tldrsec.com/blog/tldr-sec-039Featured in CloudSecList https://cloudseclist.com/issues/issue-42Presented at EkoParty 2020 DevSecOps https://youtu.be/XqwbVU-gtngPresented at c0c0cn 2020 https://india.c0c0n.org/2020/speakers#madhu_akulaFeatured in Info Ck YouTube channel https://youtu.be/5ojho4L6XfoPresented in Cloud Native Indonesia Meetup https://youtu.be/pf5jOGWoWU0Presented in USENIX LISA 2021 Closing NotePresented in SANS CloudSecNext Summit 2021DisclaimerKubernetes Goat creates intentionally vulnerable resources into your cluster. DO NOT deploy Kubernetes Goat in a production environment or alongside any sensitive cluster resources.Kubernetes Goat comes with absolutely no warranties whatsoever. By using Kubernetes Goat, you take full responsibility for all outcomes that result.Download Kubernetes-Goat
Read more...
___________________________
@hacking_Attack
@Hacking_Video
The Kubernetes Goat is designed to be an intentionally vulnerable cluster environment to learn and practice Kubernetes security.Refer to https://madhuakula.com/kubernetes-goat for the guide.Show us somePlease feel free to send us a PR and show some Upcoming Training's and SessionsDEFCON DEMO Labshttps://forum.defcon.org/node/237237Cloud Village - DEFCONhttps://cloud-village.org/#talks?collapseMadhuAkulaRecent Kubernetes Goat PresentationsOWASP Bay Area Meetup DEFCON Red Team VillageJust click and Play in the browser for free using Katacoda Playground - Try nowhttps://katacoda.com/madhuakula/scenarios/kubernetes-goatSetting up Kubernetes GoatBefore we set up the Kubernetes Goat, ensure that you have created and have admin access to the Kubernetes clusterkubectl version --shortSet up the helm version 2 in your path as helm2. Refer to helm releases for more information about setuphelm2 --helpThen finally setup Kubernetes Goat by running the following commandgit clone https://github.com/madhuakula/kubernetes-goat.gitcd kubernetes-goatbash setup-kubernetes-goat.shTo export the ports/services locally to start learning, run the following commandbash access-kubernetes-goat.shThen navigate to http://127.0.0.1:1234Kubernetes Goat - KIND setupIf you want to setup Kubernetes Goat using KIND, refer to kind-setupScenariosSensitive keys in code-basesDIND (docker-in-docker) exploitationSSRF in K8S worldContainer escape to access host systemDocker CIS Benchmarks analysisKubernetes CIS Benchmarks analysisAttacking private registryNodePort exposed servicesHelm v2 tiller to PwN the clusterAnalysing crypto miner containerKubernetes Namespaces bypassGaining environment informationDoS the memory/CPU resourcesHacker Container previewHidden in layersRBAC Least Privileges MisconfigurationKubeAudit - Audit Kubernetes ClustersSysdig Falco - Runtime Security Monitoring & DetectionPopeye - A Kubernetes Cluster SanitizerSecure network boundaries using NSPShowcasePresented at OWASP Bay Area Meetup at https://youtu.be/DQllxpb46YwPresented at DEF CON RED Team Village https://youtu.be/aEaSZJRbnToPresented at OWASP San Diego at https://www.meetup.com/Open-Web-Application-Security-Project-San-Diego-OWASP-SD/events/hmbbkrybckbvb/Featured in the official Kubernetes Podcast at https://kubernetespodcast.com/episode/109-kubermaticFeatured in tl;dr sec https://tldrsec.com/blog/tldr-sec-039Featured in CloudSecList https://cloudseclist.com/issues/issue-42Presented at EkoParty 2020 DevSecOps https://youtu.be/XqwbVU-gtngPresented at c0c0cn 2020 https://india.c0c0n.org/2020/speakers#madhu_akulaFeatured in Info Ck YouTube channel https://youtu.be/5ojho4L6XfoPresented in Cloud Native Indonesia Meetup https://youtu.be/pf5jOGWoWU0Presented in USENIX LISA 2021 Closing NotePresented in SANS CloudSecNext Summit 2021DisclaimerKubernetes Goat creates intentionally vulnerable resources into your cluster. DO NOT deploy Kubernetes Goat in a production environment or alongside any sensitive cluster resources.Kubernetes Goat comes with absolutely no warranties whatsoever. By using Kubernetes Goat, you take full responsibility for all outcomes that result.Download Kubernetes-Goat
Read more...
___________________________
@hacking_Attack
@Hacking_Video
Madhuakula
Welcome to Kubernetes Goat | Kubernetes Goat
Interactive Kubernetes Security Learning Playground
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Two Iranian Nationals Charged for Cyber-Enabled Disinformation and Threat Campaign Designed to Influence the 2020 US Presidential Election
An indictment was unsealed charging two Iranian nationals for their involvement in a cyber-enabled campaign to intimidate and influence American voters, and otherwise undermine voter confidence and sow discord, in connection with the 2020 US presidential election.
___________________________
@hacking_Attack
@Hacking_Video
Two Iranian Nationals Charged for Cyber-Enabled Disinformation and Threat Campaign Designed to Influence the 2020 US Presidential Election
An indictment was unsealed charging two Iranian nationals for their involvement in a cyber-enabled campaign to intimidate and influence American voters, and otherwise undermine voter confidence and sow discord, in connection with the 2020 US presidential election.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Two Iranian Nationals Charged for Cyber-Enabled Disinformation and Threat Campaign Designed to Influence the 2020 US Presidential…
An indictment was unsealed charging two Iranian nationals for their involvement in a cyber-enabled campaign to intimidate and influence American voters, and otherwise undermine voter confidence and sow discord, in connection with the 2020 US presidential…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Beginner’s Tutorial: Offsec: How to upload a backdoor into a Vulnerable Web Application (DVWA)
On this topic I would like to discuss and show you a little bit about DVWA (Damn Vulnerable Web Application). This is an environment in…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Beginner’s Tutorial: Offsec: How to upload a backdoor into a Vulnerable Web Application (DVWA)
On this topic I would like to discuss and show you a little bit about DVWA (Damn Vulnerable Web Application). This is an environment in…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Beginner’s Tutorial: Offsec: How to upload a backdoor into a Vulnerable Web Application (DVWA)
On this topic I would like to discuss and show you a little bit about DVWA (Damn Vulnerable Web Application). This is an environment in…
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
US indicts Iranian hackers for Proud Boys voter intimidation emails
https://external-preview.redd.it/4VwEAcTYYwogCtNlOhtsJtfm5mjk_jqItOJWiVpaxZA.jpg?width=640&crop=smart&auto=webp&s=7a39887c52d3133452589740f586ce9064e6c0f8 submitted by /u/DrinkMoreCodeMore
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
US indicts Iranian hackers for Proud Boys voter intimidation emails
https://external-preview.redd.it/4VwEAcTYYwogCtNlOhtsJtfm5mjk_jqItOJWiVpaxZA.jpg?width=640&crop=smart&auto=webp&s=7a39887c52d3133452589740f586ce9064e6c0f8 submitted by /u/DrinkMoreCodeMore
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
US indicts Iranian hackers for Proud Boys voter intimidation emails
Posted in r/hacking by u/DrinkMoreCodeMore • 1 point and 0 comments
Mizar Bug Bounty Program Extended Until 18th of December
Ever since the launch of our closed beta bounty program on the 18th of October we’ve received a lot of feedback from the community to…Continue reading on Mizar_ai »
Read more...
Ever since the launch of our closed beta bounty program on the 18th of October we’ve received a lot of feedback from the community to…Continue reading on Mizar_ai »
Read more...
CleanTalk ADVISORY and SCAM Secure your Accounts/ Remove the Plugin until Patch Out
Scammer#1 Owner and CoFounderContinue reading on Medium »
Read more...
Scammer#1 Owner and CoFounderContinue reading on Medium »
Read more...
1year anniversary of BugBountyHunter & our second Hackevent
Sorry for the silence from me lately with regards to any new writeups or anything interesting! The new dad life has been something…Continue reading on Medium »
Read more...
Sorry for the silence from me lately with regards to any new writeups or anything interesting! The new dad life has been something…Continue reading on Medium »
Read more...
Pre-Authentication Account Take-Over
Hello Hunters, Today I’m going to tell about one of my interesting and rare finding which is Pre-Authentication Account Take-Over.Continue reading on Medium »
Read more...
Hello Hunters, Today I’m going to tell about one of my interesting and rare finding which is Pre-Authentication Account Take-Over.Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Bazarloader Malware
https://cdn-images-1.medium.com/max/1042/0*AaFaDMdzmbH-bEau
A Study on a recent malware
Continue reading on rootissh »
___________________________
@hacking_Attack
@Hacking_Video
Bazarloader Malware
https://cdn-images-1.medium.com/max/1042/0*AaFaDMdzmbH-bEau
A Study on a recent malware
Continue reading on rootissh »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bazarloader Malware
A Study on a recent malware