Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Pentesting: Security Checks (automation)
https://www.reddit.com/r/Pentesting/comments/r78xom/pentesting_security_checks_automation/

Hello, I am looking for some feedback and resources in Designing Penetration Security Checks (automation).
In our SDLC we have the standard SAST\DAST, Dependency Checks, Vuln scanners, etc.. However, we struggle when going GA for an offering, when performing either Internal or External (independent) Penetration test finding issues at the end of the SDLC; delaying GA Besides, including continuing education among developers, our thought is to continue to shift left and place some Security Checks, preferably automated in the hands of the developers and in the SDLC pipeline. However, I'm not too keen on providing developers with actual exploitation tools, but maybe some automated scripts that perform, e.g.; jwt validation, UI redress attack, Improper Error Handling, etc.. I think it's known that security scanners tend to have their own pros and cons, and these "lower-level" security checks would be just another input for an Internal pentest. So, when you do have an external (independent) pentest, it would help reduce any additional findings. Does anyone have any feedback, resources, and possible playbooks (scripts, etc) that would help in identifying issues earlier in the SDLC? Thank you submitted by /u/Semperfi4000 (https://www.reddit.com/user/Semperfi4000)
[link] (https://www.reddit.com/r/Pentesting/comments/r78xom/pentesting_security_checks_automation/) [comments] (https://www.reddit.com/r/Pentesting/comments/r78xom/pentesting_security_checks_automation/)

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
nmap scan showing ssh-hostkeys

I've been instructed for an assignment to pentest a VM, during an NMAP scan on an open SSH port, it's showing me 3 ssh host keys. 2048 and two 256, is there anything I can do with these to help me use an ssh vulnerability?

submitted by /u/fgtethancx
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
JTR can't show Cracked password

When i type :

john --show hash.txt /or john hash.txt --show

it says

1 password hash cracked, 0 left

How to show cracked password?

submitted by /u/DnD_Junichiro
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How is that possible ?

I was wondering. Why books about hacking are legal if with that knowledge you can do lots of harm ? Is that possible that books about hacking that are on the market are bullshit ? And real knowledge is prohibited ? Plz answer

submitted by /u/Iproman
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Arbswap Announces Testnet Launch and Bug Bounty Event

Arbswap is launching its testnet platform on the Arbitrum Network. This marks a huge milestone for the team and the community, who’ll be…Continue reading on Medium »
Read more...
What is an IDOR Vulnerability?

And How to Find One!Continue reading on Medium »
Read more...