Pentesting: Security Checks (automation)
https://www.reddit.com/r/Pentesting/comments/r78xom/pentesting_security_checks_automation/
Hello, I am looking for some feedback and resources in Designing Penetration Security Checks (automation).
In our SDLC we have the standard SAST\DAST, Dependency Checks, Vuln scanners, etc.. However, we struggle when going GA for an offering, when performing either Internal or External (independent) Penetration test finding issues at the end of the SDLC; delaying GA Besides, including continuing education among developers, our thought is to continue to shift left and place some Security Checks, preferably automated in the hands of the developers and in the SDLC pipeline. However, I'm not too keen on providing developers with actual exploitation tools, but maybe some automated scripts that perform, e.g.; jwt validation, UI redress attack, Improper Error Handling, etc.. I think it's known that security scanners tend to have their own pros and cons, and these "lower-level" security checks would be just another input for an Internal pentest. So, when you do have an external (independent) pentest, it would help reduce any additional findings. Does anyone have any feedback, resources, and possible playbooks (scripts, etc) that would help in identifying issues earlier in the SDLC? Thank you submitted by /u/Semperfi4000 (https://www.reddit.com/user/Semperfi4000)
[link] (https://www.reddit.com/r/Pentesting/comments/r78xom/pentesting_security_checks_automation/) [comments] (https://www.reddit.com/r/Pentesting/comments/r78xom/pentesting_security_checks_automation/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/r78xom/pentesting_security_checks_automation/
Hello, I am looking for some feedback and resources in Designing Penetration Security Checks (automation).
In our SDLC we have the standard SAST\DAST, Dependency Checks, Vuln scanners, etc.. However, we struggle when going GA for an offering, when performing either Internal or External (independent) Penetration test finding issues at the end of the SDLC; delaying GA Besides, including continuing education among developers, our thought is to continue to shift left and place some Security Checks, preferably automated in the hands of the developers and in the SDLC pipeline. However, I'm not too keen on providing developers with actual exploitation tools, but maybe some automated scripts that perform, e.g.; jwt validation, UI redress attack, Improper Error Handling, etc.. I think it's known that security scanners tend to have their own pros and cons, and these "lower-level" security checks would be just another input for an Internal pentest. So, when you do have an external (independent) pentest, it would help reduce any additional findings. Does anyone have any feedback, resources, and possible playbooks (scripts, etc) that would help in identifying issues earlier in the SDLC? Thank you submitted by /u/Semperfi4000 (https://www.reddit.com/user/Semperfi4000)
[link] (https://www.reddit.com/r/Pentesting/comments/r78xom/pentesting_security_checks_automation/) [comments] (https://www.reddit.com/r/Pentesting/comments/r78xom/pentesting_security_checks_automation/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Pentesting: Security Checks (automation)
Hello, I am looking for some feedback and resources in Designing Penetration Security Checks (automation). In our SDLC we have the standard...
Arbswap Announces Testnet Launch and Bug Bounty Event
https://medium.com/@arbswap/arbswap-announces-testnet-launch-and-bug-bounty-event-e323f450a88a?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@arbswap/arbswap-announces-testnet-launch-and-bug-bounty-event-e323f450a88a?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Arbswap Announces Testnet Launch and Bug Bounty Event
Arbswap is launching its testnet platform on the Arbitrum Network. This marks a huge milestone for the team and the community, who’ll be…
Arbswap is launching its testnet platform on the Arbitrum Network. This marks a huge milestone for the team and the community, who’ll be…Continue reading on Medium » (https://medium.com/@arbswap/arbswap-announces-testnet-launch-and-bug-bounty-event-e323f450a88a?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Arbswap Announces Testnet Launch and Bug Bounty Event
Arbswap is launching its testnet platform on the Arbitrum Network. This marks a huge milestone for the team and the community, who’ll be…
What is an IDOR Vulnerability?
https://medium.com/@kaorrosi/what-is-an-idor-vulnerability-7af668b6a0a6?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@kaorrosi/what-is-an-idor-vulnerability-7af668b6a0a6?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is an IDOR Vulnerability?
And How to Find One!
And How to Find One!Continue reading on Medium » (https://medium.com/@kaorrosi/what-is-an-idor-vulnerability-7af668b6a0a6?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is an IDOR Vulnerability?
And How to Find One!
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Review on eLearnSecurity Certified Professional Penetration Tester! (eCPPTv2)
https://cdn-images-1.medium.com/max/600/0*jHo7yIvLFTWv27vI.png
eCPPTv2 - eLearnSecurity Certified Professional Penetration Tester version 2
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Review on eLearnSecurity Certified Professional Penetration Tester! (eCPPTv2)
https://cdn-images-1.medium.com/max/600/0*jHo7yIvLFTWv27vI.png
eCPPTv2 - eLearnSecurity Certified Professional Penetration Tester version 2
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Review on eLearnSecurity Certified Professional Penetration Tester! (eCPPTv2)
eCPPTv2 - eLearnSecurity Certified Professional Penetration Tester version 2
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to track anyone Currect Location with the use of Image metadata..
https://cdn-images-1.medium.com/max/1280/1*pY_2IKzRxHaRotaFIDHcuQ.jpeg
Warning:
This post is being given by us only for the purpose of cyber security education to you, if you use it for any illegal work, only…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to track anyone Currect Location with the use of Image metadata..
https://cdn-images-1.medium.com/max/1280/1*pY_2IKzRxHaRotaFIDHcuQ.jpeg
Warning:
This post is being given by us only for the purpose of cyber security education to you, if you use it for any illegal work, only…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to track anyone currect Loction with the use of Image metadata..
Warning: This post is being given by us only for the purpose of cyber security education to you, if you use it for any illegal work, only…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Keeping the wrench out of the gears: 5 tips for achieving compliance in the era of DevSecOps
https://cdn-images-1.medium.com/max/2600/0*fW8To7F5x5XSjo9O
We answer some common questions about compliance and provide tips for making it work for high-performing Dev teams.
Continue reading on ShiftLeft Blog »
___________________________
@hacking_Attack
@Hacking_Video
Keeping the wrench out of the gears: 5 tips for achieving compliance in the era of DevSecOps
https://cdn-images-1.medium.com/max/2600/0*fW8To7F5x5XSjo9O
We answer some common questions about compliance and provide tips for making it work for high-performing Dev teams.
Continue reading on ShiftLeft Blog »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Keeping the wrench out of the gears: 5 tips for achieving compliance in the era of DevSecOps
We answer some common questions about compliance and provide tips for making it work for high-performing Dev teams.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is an IDOR Vulnerability?
https://cdn-images-1.medium.com/max/2600/0*R9h9lelJvArkw5L4
And How to Find One!
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
What is an IDOR Vulnerability?
https://cdn-images-1.medium.com/max/2600/0*R9h9lelJvArkw5L4
And How to Find One!
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is an IDOR Vulnerability?
And How to Find One!
hacking: security in practice
Blockchain Agent Dev Workshop today with the white hats of Arbitrary Execution. Great chance to get in on the next billion dollar opp. 11am EST.
submitted by /u/theregenerates
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Blockchain Agent Dev Workshop today with the white hats of Arbitrary Execution. Great chance to get in on the next billion dollar opp. 11am EST.
submitted by /u/theregenerates
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Blockchain Agent Dev Workshop today with the white hats of...
Posted in r/hacking by u/theregenerates • 1 point and 1 comment
hacking: security in practice
nmap scan showing ssh-hostkeys
I've been instructed for an assignment to pentest a VM, during an NMAP scan on an open SSH port, it's showing me 3 ssh host keys. 2048 and two 256, is there anything I can do with these to help me use an ssh vulnerability?
submitted by /u/fgtethancx
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
nmap scan showing ssh-hostkeys
I've been instructed for an assignment to pentest a VM, during an NMAP scan on an open SSH port, it's showing me 3 ssh host keys. 2048 and two 256, is there anything I can do with these to help me use an ssh vulnerability?
submitted by /u/fgtethancx
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
nmap scan showing ssh-hostkeys
I've been instructed for an assignment to pentest a VM, during an NMAP scan on an open SSH port, it's showing me 3 ssh host keys. 2048 and two...
hacking: security in practice
JTR can't show Cracked password
When i type :
john --show hash.txt /or john hash.txt --show
it says
1 password hash cracked, 0 left
How to show cracked password?
submitted by /u/DnD_Junichiro
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
JTR can't show Cracked password
When i type :
john --show hash.txt /or john hash.txt --show
it says
1 password hash cracked, 0 left
How to show cracked password?
submitted by /u/DnD_Junichiro
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
JTR can't show Cracked password
When i type : john --show hash.txt /or john hash.txt --show it says 1 password hash cracked, 0 left How to show cracked password?
hacking: security in practice
How is that possible ?
I was wondering. Why books about hacking are legal if with that knowledge you can do lots of harm ? Is that possible that books about hacking that are on the market are bullshit ? And real knowledge is prohibited ? Plz answer
submitted by /u/Iproman
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How is that possible ?
I was wondering. Why books about hacking are legal if with that knowledge you can do lots of harm ? Is that possible that books about hacking that are on the market are bullshit ? And real knowledge is prohibited ? Plz answer
submitted by /u/Iproman
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How is that possible ?
I was wondering. Why books about hacking are legal if with that knowledge you can do lots of harm ? Is that possible that books about hacking that...
Arbswap Announces Testnet Launch and Bug Bounty Event
Arbswap is launching its testnet platform on the Arbitrum Network. This marks a huge milestone for the team and the community, who’ll be…Continue reading on Medium »
Read more...
Arbswap is launching its testnet platform on the Arbitrum Network. This marks a huge milestone for the team and the community, who’ll be…Continue reading on Medium »
Read more...