Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TrojanSourceFinder | Help Find Trojan Source Vulnerability In Code
https://cdn-images-1.medium.com/max/1280/1*JP6vr1oSUPoiNzpa1Pj-Bw.png
TrojanSourceFinder helps developers detect “Trojan Source” vulnerability in source code.
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
TrojanSourceFinder | Help Find Trojan Source Vulnerability In Code
https://cdn-images-1.medium.com/max/1280/1*JP6vr1oSUPoiNzpa1Pj-Bw.png
TrojanSourceFinder helps developers detect “Trojan Source” vulnerability in source code.
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Polygon Fixes the Critical Vulnerability in the Network, Saving Matic Worth of Billions.
https://cdn-images-1.medium.com/max/1024/1*04yEjp-qPjFM-9M9ZTGTZQ.jpeg
Polygon Network, on December 29th, fixed the bug in the system that saved $9 Billion worth of MATIC. Whitehat hacker, Leon Spacewalker…
Continue reading on Geek Culture »
___________________________
@hacking_Attack
@Hacking_Video
Polygon Fixes the Critical Vulnerability in the Network, Saving Matic Worth of Billions.
https://cdn-images-1.medium.com/max/1024/1*04yEjp-qPjFM-9M9ZTGTZQ.jpeg
Polygon Network, on December 29th, fixed the bug in the system that saved $9 Billion worth of MATIC. Whitehat hacker, Leon Spacewalker…
Continue reading on Geek Culture »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Polygon Fixes the Critical Vulnerability in the Network, Saving Matic Worth of Billions.
Polygon Network, on December 29th, fixed the bug in the system that saved $9 Billion worth of MATIC. Whitehat hacker, Leon Spacewalker…
How to freely borrow all the TVL from the Jet Protocol
Recently I discovered a critical vulnerability that could possibly lead to the loss of funds in the smart contract of Jet Protocol, a…Continue reading on Medium »
Read more...
Recently I discovered a critical vulnerability that could possibly lead to the loss of funds in the smart contract of Jet Protocol, a…Continue reading on Medium »
Read more...
Spotlight: Earn Bitcoin While Browsing The Web On Desktop And Mobile
https://medium.com/@daniel.j.hunt/spotlight-earn-bitcoin-while-browsing-the-web-on-desktop-and-mobile-6512636addd3?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@daniel.j.hunt/spotlight-earn-bitcoin-while-browsing-the-web-on-desktop-and-mobile-6512636addd3?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Earn Bitcoin While Browsing The Web On Desktop And Mobile
Is it too good to be true? Well, join me on my quest to find out.
Is it too good to be true? Well, join me on my quest to find out.Continue reading on Medium » (https://medium.com/@daniel.j.hunt/spotlight-earn-bitcoin-while-browsing-the-web-on-desktop-and-mobile-6512636addd3?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Earn Bitcoin While Browsing The Web On Desktop And Mobile
Is it too good to be true? Well, join me on my quest to find out.
SQL Injection - The File Upload Playground
https://shahjerry33.medium.com/sql-injection-the-file-upload-playground-6580b089d013?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://shahjerry33.medium.com/sql-injection-the-file-upload-playground-6580b089d013?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
SQL Injection - The File Upload Playground
Summary :
Summary :Continue reading on Medium » (https://shahjerry33.medium.com/sql-injection-the-file-upload-playground-6580b089d013?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
SQL Injection - The File Upload Playground
Summary :
hacking: security in practice
How do hackers handle the pressure of the day to day?
Lets be real. Name one successful hacker that ISNT paranoid as balls. Shit eats at you no matter how great you think you are.
How are we managing mental health while we work is my question? Any anonymous homies want to share tips on how to manage the stress? What do you do to unwind? How do you find a mentor if you need help?
Appreciate anyone that takes the time to sincerely answer this
submitted by /u/totie01010
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How do hackers handle the pressure of the day to day?
Lets be real. Name one successful hacker that ISNT paranoid as balls. Shit eats at you no matter how great you think you are.
How are we managing mental health while we work is my question? Any anonymous homies want to share tips on how to manage the stress? What do you do to unwind? How do you find a mentor if you need help?
Appreciate anyone that takes the time to sincerely answer this
submitted by /u/totie01010
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How do hackers handle the pressure of the day to day?
Lets be real. Name one successful hacker that ISNT paranoid as balls. Shit eats at you no matter how great you think you are. How are we...
hacking: security in practice
Is it possible to combine Data Science with hacking / IT-security?
Since I was a kid, ~20 years ago, I was interested in IT security. Even though there was not much information out there, I still did simple stuff like scripting, playing with trojans/viruses, wireless wiretap, hacking computer games etc. . But I had no support / help / person to ask, so it got more and more difficult for my 11 year old brain, and I stopped.
Now many years later I study Data Science, which is a lot of statistics (also with many ML topics like (un)supervised learning, reinforcement learning etc.) with a bit of CompSci topics like Data structures, Algorithm, programming, data bases, SW engineering...
My question: Is there any way to combine this Data Science knowledge with hacking/ IT-security? So that I can specialize in a topic Im really interested in? So far, I really miss the technical stuff in Data Science, which inspires me since I was a kid. Finding out gaps, errors and weak points in a system is something that really intrinsically motivates me.
Thanks in advance!
submitted by /u/dongpal
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is it possible to combine Data Science with hacking / IT-security?
Since I was a kid, ~20 years ago, I was interested in IT security. Even though there was not much information out there, I still did simple stuff like scripting, playing with trojans/viruses, wireless wiretap, hacking computer games etc. . But I had no support / help / person to ask, so it got more and more difficult for my 11 year old brain, and I stopped.
Now many years later I study Data Science, which is a lot of statistics (also with many ML topics like (un)supervised learning, reinforcement learning etc.) with a bit of CompSci topics like Data structures, Algorithm, programming, data bases, SW engineering...
My question: Is there any way to combine this Data Science knowledge with hacking/ IT-security? So that I can specialize in a topic Im really interested in? So far, I really miss the technical stuff in Data Science, which inspires me since I was a kid. Finding out gaps, errors and weak points in a system is something that really intrinsically motivates me.
Thanks in advance!
submitted by /u/dongpal
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is it possible to combine Data Science with hacking / IT-security?
Since I was a kid, \~20 years ago, I was interested in IT security. Even though there was not much information out there, I still did simple stuff...
Misconfiguration OAuth Lead Account Takeover
https://human-error.medium.com/misconfiguration-oauth-lead-account-takeover-f695c6f44d6e?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://human-error.medium.com/misconfiguration-oauth-lead-account-takeover-f695c6f44d6e?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Misconfiguration OAuth Lead Account Takeover
Assalamuallaikum Wr.Wb Hello friends I want to explain about the bug bounty that I got in 2020, this vulnerability lies in the weak OAuth
Assalamuallaikum Wr.Wb Hello friends I want to explain about the bug bounty that I got in 2020, this vulnerability lies in the weak OAuthContinue reading on Medium » (https://human-error.medium.com/misconfiguration-oauth-lead-account-takeover-f695c6f44d6e?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Misconfiguration OAuth Lead Account Takeover
Assalamuallaikum Wr.Wb Hello friends I want to explain about the bug bounty that I got in 2020, this vulnerability lies in the weak OAuth
How to freely borrow all the TVL from the Jet Protocol
https://medium.com/@0xjayne/how-to-freely-borrow-all-the-tvl-from-the-jet-protocol-25d40e35920e?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@0xjayne/how-to-freely-borrow-all-the-tvl-from-the-jet-protocol-25d40e35920e?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to freely borrow all the TVL from the Jet Protocol
Recently I discovered a critical vulnerability that could possibly lead to the loss of funds in the smart contract of Jet Protocol, a…
Recently I discovered a critical vulnerability that could possibly lead to the loss of funds in the smart contract of Jet Protocol, a…Continue reading on Medium » (https://medium.com/@0xjayne/how-to-freely-borrow-all-the-tvl-from-the-jet-protocol-25d40e35920e?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to freely borrow all the TVL from the Jet Protocol
Recently I discovered a critical vulnerability that could possibly lead to the loss of funds in the smart contract of Jet Protocol, a…
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
SyntheticSun - A Defense-In-Depth Security Automation And Monitoring Framework Which Utilizes Threat Intelligence, Machine Learning, Managed AWS Security Services And, Serverless Technologies To Continuously Prevent, Detect And Respond To Threats
https://blogger.googleusercontent.com/img/a/AVvXsEjgLAFBqA1vvBC3qBjkrWJIy37GMGEusDvSHALUcuriQXCVkJHKUen75oNZX_EOSmWvD8zQVsQBamtF_jPGPUQCsVa5ni78LfQ7fa2rcOBZ7IsxdS9ipiAit3K_tCqTd3upvU4StW4Xb4G5tdeOgmFQjtAti_Txxe20IixIcPNpArw07-tFOtg3i5L2YQ=w640-h338 SyntheticSun is a defense-in-depth security automation and monitoring framework which utilizes threat intelligence, machine learning, managed AWS security services and, serverless technologies to continuously prevent, detect and respond to threats.
You sleep in fragmented glass
With reflections of you,
But are you feeling alive?
Yeah let me ask you,
Are you feeling alive?
- Norma Jean, 2016 Synopsis* Uses event- and time-based serverless automation (e.g. AWS CodeBuild, AWS Lambda) to collect, normalize, enrich, and correlate security telemetry in Kibana
* Leverages threat intelligence, geolocation data, open-source intelligence, machine learning (ML) backed anomaly detection and AWS APIs to further enrich security telemetry and identify potential threats
* Leverages Random Cut Forests (RCF) and IP Insights unsupervised ML algorithms to identify anomalies in timeseries and IP-entity pair data, respectively. Serverless, container-orchestrated resources are provided to train and deploy new IP Insights endpoints at will.
* Dynamically updates AWS WAFv2 IP Sets and Amazon GuardDuty threat intel sets to bolster protection of your account and infrastructure against known threats DescriptionSyntheticSun is built around the usage of the Malware Information Sharing Platform (MISP) and Anomali's LIMO, which are community driven threat intelligence platforms (TIPs) that provide various types of indicators of compromise (IoC). Normalized and de-duplicated threat intel is looked up against in near-real time to quickly identify known threats in various types of network traffic. To add dynamism to the identification of potential threats IP Insights models are deployed to find anoamlies (and potential threats therein) between the pairing of IP addresses and entities (such as IAM principal ID's, user-agents, etc.), native RCF detectors are also used in Elasticsearch to find anomalies in near real-time security telemetry as it is streamed into Kibana. To democratize the usage and fine-tuning of ML models within security teams, utilities to train IP Insights models are provided as an add-on to the core solution.
To perform the both the orchestration and automation as well as extraction, transformation, and loading (ETL) of security telemetry into Kibana, various AWS serverless technologies such as AWS Lambda, Amazon DynamoDB, and AWS CodeBuild are used. Serverless technologies such as these are used for their scalability, ease of use, relatively cheap costs versus heavy MapReduce or Glue ETL-based solutions. A majority of the solution is deployed via CloudFormation with helper scripts in Python and shell provided throughout the various Stages to promote adoption and the potential deployment in continuous integration pipelines.
To make the "guts" of the solution as lean as possible basic Python modules such as
___________________________
@hacking_Attack
@Hacking_Video
SyntheticSun - A Defense-In-Depth Security Automation And Monitoring Framework Which Utilizes Threat Intelligence, Machine Learning, Managed AWS Security Services And, Serverless Technologies To Continuously Prevent, Detect And Respond To Threats
https://blogger.googleusercontent.com/img/a/AVvXsEjgLAFBqA1vvBC3qBjkrWJIy37GMGEusDvSHALUcuriQXCVkJHKUen75oNZX_EOSmWvD8zQVsQBamtF_jPGPUQCsVa5ni78LfQ7fa2rcOBZ7IsxdS9ipiAit3K_tCqTd3upvU4StW4Xb4G5tdeOgmFQjtAti_Txxe20IixIcPNpArw07-tFOtg3i5L2YQ=w640-h338 SyntheticSun is a defense-in-depth security automation and monitoring framework which utilizes threat intelligence, machine learning, managed AWS security services and, serverless technologies to continuously prevent, detect and respond to threats.
You sleep in fragmented glass
With reflections of you,
But are you feeling alive?
Yeah let me ask you,
Are you feeling alive?
- Norma Jean, 2016 Synopsis* Uses event- and time-based serverless automation (e.g. AWS CodeBuild, AWS Lambda) to collect, normalize, enrich, and correlate security telemetry in Kibana
* Leverages threat intelligence, geolocation data, open-source intelligence, machine learning (ML) backed anomaly detection and AWS APIs to further enrich security telemetry and identify potential threats
* Leverages Random Cut Forests (RCF) and IP Insights unsupervised ML algorithms to identify anomalies in timeseries and IP-entity pair data, respectively. Serverless, container-orchestrated resources are provided to train and deploy new IP Insights endpoints at will.
* Dynamically updates AWS WAFv2 IP Sets and Amazon GuardDuty threat intel sets to bolster protection of your account and infrastructure against known threats DescriptionSyntheticSun is built around the usage of the Malware Information Sharing Platform (MISP) and Anomali's LIMO, which are community driven threat intelligence platforms (TIPs) that provide various types of indicators of compromise (IoC). Normalized and de-duplicated threat intel is looked up against in near-real time to quickly identify known threats in various types of network traffic. To add dynamism to the identification of potential threats IP Insights models are deployed to find anoamlies (and potential threats therein) between the pairing of IP addresses and entities (such as IAM principal ID's, user-agents, etc.), native RCF detectors are also used in Elasticsearch to find anomalies in near real-time security telemetry as it is streamed into Kibana. To democratize the usage and fine-tuning of ML models within security teams, utilities to train IP Insights models are provided as an add-on to the core solution.
To perform the both the orchestration and automation as well as extraction, transformation, and loading (ETL) of security telemetry into Kibana, various AWS serverless technologies such as AWS Lambda, Amazon DynamoDB, and AWS CodeBuild are used. Serverless technologies such as these are used for their scalability, ease of use, relatively cheap costs versus heavy MapReduce or Glue ETL-based solutions. A majority of the solution is deployed via CloudFormation with helper scripts in Python and shell provided throughout the various Stages to promote adoption and the potential deployment in continuous integration pipelines.
To make the "guts" of the solution as lean as possible basic Python modules such as
boto3, requests, json, ipaddress, socketand reperform most of the extraction, transformation, and loading (ETL) into downstream services. Because all geolocation information is provided by ip-api.com, it does not require an account or paid tiers and has a great API which includes throttling information in their response headers. A majority of the Elasticsearch and Kibana dependencies are also provided in code (ind[...]___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
SyntheticSun - A Defense-In-Depth Security Automation And Monitoring Framework Which Utilizes Threat Intelligence, Machine Learning…
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! SyntheticSun - A Defense-In-Depth Security Automation And Monitoring Framework Which Utilizes Threat Intelligence, Machine Learning, Managed AWS Security Services And, Serverless Technologies To Continuously Prevent, Detect And Respond…
icies, mappings, visualizations, etc) to avoid heavy manual configuration. Setting UpSyntheticSun is spread across three Stages due to the size of solution and the required dependencies. All architecture and installation instructions (and FAQs where appropriate) live within their own Stage. Add-ons modules (called an Appendix) are also provided to extend the functionality, which have their own architecture and installation instructions localized. Before you start: Considerations for Production deploymentsSyntheticSun, by virtue of being something you found on GitHub, is a proof-of-concept and therefore I did not go the extra mile for the first release to absolutely harden everything. Provided you are reading this at a point in time where I have not made the necessary changes, consider the following before you deploy this solution into a production environment (or any environment with heightened security needs). I will put these items on a roadmap and update them as appropiate.
1. Train your own IP Insights models using the examples provided in Appendix A. Using your own data, and continually retraining the model, will help accurize findings.
2. Deploy your CodeBuild projects, MISP server, and Elasticsearch Service domain in a VPC in order to harden against internet-borne attacks. Consider using AWS' Client VPN, AWS Site-to-Site VPN, DirectConnect, Amazon Workspaces, and AppStream 2.0 or (if you absolutely have to) a reverse-proxy to access the MISP console and Kibana within a VPC.
3. Consider using Cognito for AuthN into Kibana. Go a step further and federate your User Pool with your corporate IdP.
4. Consider baking your own AMI for MISP or use Fargate to host it. I would also consider pre-baking Suricata and the Amazon CloudWatch Agent into future builds to help scale deployments of agents and HIDPS across your estate.
5. Modify your Suricata configuration to suit the needs of your SecOps teams looking at the logs, since all this solution does is dump them in. You may also consider writing your own rules or importing other sources to harden your hosts against attacks. Prerequisites* Admin access to an AWS Account (if you are using this in a multi-account deployment, you must be in the account where your Masters or Delegated Admin Masters are located)
* Application Load Balancer (ALB) with at least one target instance and access logs enabled
* CloudTrail logging enabled in your account
* One VPC with at least one private subnet (route to NATGW), one public subnet (route to IGW), and VPC Flow Logs enabled as well as published to CloudWatch Logs Stage 1 starts here FAQ1. Why should I use this solution?SyntheticSun is an easy way to start using cyber threat intelligence and machine learning for your edge protection security use cases on the AWS Cloud without having to invest in one or more commercial tools, or hiring a data scientist for your security team (though you should ideally do the latter). This solution, after initial configuration, is fully automated, allowing you to identify and respond to threats at machine speed. Finally, this solution provides basic visualizations for your incident response team to use for threat response, such as allowed inbound or outbound connections or DNS queries to and from IP addresses or domains deemed to be malicious. The core of the solution relies on very lightweight automation and data engineering pipelines, which theoretically, can be reused for other purposes where multi-stage normalization and enrichment or scheduled, fast-paced batch jobs are needed. 2. Who should use this solution?Firstly, if you are making use of Amazon GuardDuty and/or AWS WAF, it may make sense to evaluate this solution, but it is also a requirement. Obvious personas who can take advantage are product teams responsible for securing their full stack and lack the capital or expertise to model, train and deploy machine learning algorithms or operationali[...]
___________________________
@hacking_Attack
@Hacking_Video
1. Train your own IP Insights models using the examples provided in Appendix A. Using your own data, and continually retraining the model, will help accurize findings.
2. Deploy your CodeBuild projects, MISP server, and Elasticsearch Service domain in a VPC in order to harden against internet-borne attacks. Consider using AWS' Client VPN, AWS Site-to-Site VPN, DirectConnect, Amazon Workspaces, and AppStream 2.0 or (if you absolutely have to) a reverse-proxy to access the MISP console and Kibana within a VPC.
3. Consider using Cognito for AuthN into Kibana. Go a step further and federate your User Pool with your corporate IdP.
4. Consider baking your own AMI for MISP or use Fargate to host it. I would also consider pre-baking Suricata and the Amazon CloudWatch Agent into future builds to help scale deployments of agents and HIDPS across your estate.
5. Modify your Suricata configuration to suit the needs of your SecOps teams looking at the logs, since all this solution does is dump them in. You may also consider writing your own rules or importing other sources to harden your hosts against attacks. Prerequisites* Admin access to an AWS Account (if you are using this in a multi-account deployment, you must be in the account where your Masters or Delegated Admin Masters are located)
* Application Load Balancer (ALB) with at least one target instance and access logs enabled
* CloudTrail logging enabled in your account
* One VPC with at least one private subnet (route to NATGW), one public subnet (route to IGW), and VPC Flow Logs enabled as well as published to CloudWatch Logs Stage 1 starts here FAQ1. Why should I use this solution?SyntheticSun is an easy way to start using cyber threat intelligence and machine learning for your edge protection security use cases on the AWS Cloud without having to invest in one or more commercial tools, or hiring a data scientist for your security team (though you should ideally do the latter). This solution, after initial configuration, is fully automated, allowing you to identify and respond to threats at machine speed. Finally, this solution provides basic visualizations for your incident response team to use for threat response, such as allowed inbound or outbound connections or DNS queries to and from IP addresses or domains deemed to be malicious. The core of the solution relies on very lightweight automation and data engineering pipelines, which theoretically, can be reused for other purposes where multi-stage normalization and enrichment or scheduled, fast-paced batch jobs are needed. 2. Who should use this solution?Firstly, if you are making use of Amazon GuardDuty and/or AWS WAF, it may make sense to evaluate this solution, but it is also a requirement. Obvious personas who can take advantage are product teams responsible for securing their full stack and lack the capital or expertise to model, train and deploy machine learning algorithms or operationali[...]
___________________________
@hacking_Attack
@Hacking_Video