Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
VulnLab SQL Injection— Dynamic Application Security Testing #3

Assalamualaikum Wr.WbContinue reading on Medium »
Read more...
iOS jailbreak dev wins $2M bounty for finding critical Optimism bug

Continue reading on Medium »
Read more...
hacking: security in practice
How to get over the unrecognized app/publisher warning in Windows

All,

I am writing an executable to put on a website for download. Every time I go to download it, I get an "unrecognized app, unknown publisher warning".

It's not tagged as malicious, but it's tagged as "unknown publisher" which makes it appear that way. Does anyone know how to add a publisher? Is that something a non-corporation can do? Or could I at least add a certificate or something to make WIndows calm down?

submitted by /u/iExtrapolate314
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Shutdown-i command treat?

Hi, i work for a big alimentation company. I discovered that on workstation i can enter the admin cmd and have acces to the shutdown -i command. When i search for computers i see over a 1000 computers and servers. I dont know nothing about hacking or cybersecurity and im wondering if its a treat and should tell my boss. Thanks for your advice!

submitted by /u/V16mike
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Basic Web technologies required for starting with the web Exploitation Part-2

Hello Myself Manan Aggarwal is here to present the Blog about the Basic Web technologies required for starting with the web Exploitation…Continue reading on Medium »
Read more...
TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.
Introduction TerraGoat was built to enable DevSecOps design and implement a sustainable misconfiguration (https://www.kitploit.com/search/label/Misconfiguration) prevention strategy. It can be used to test a policy-as-code framework like Bridgecrew (https://bridgecrew.io/?utm_source=github&utm_medium=organic_oss&utm_campaign=terragoat) & Checkov (https://github.com/bridgecrewio/checkov/), inline-linters, pre-commit hooks or other code scanning methods. TerraGoat follows the tradition of existing *Goat projects that provide a baseline training ground to practice implementing secure development (https://www.kitploit.com/search/label/Secure%20Development) best practices for cloud infrastructure. Important notes Where to get help: the Bridgecrew Community Slack (https://slack.bridgecrew.io/?utm_source=github&utm_medium=organic_oss&utm_campaign=terragoat) Before you proceed please take a not of these warning: TerraGoat creates intentionally vulnerable AWS resources into your account. DO NOT deploy TerraGoat in a production environment or alongside any sensitive AWS resources. Requirements Terraform 0.12 aws cli azure cli To prevent vulnerable infrastructure (https://www.kitploit.com/search/label/Vulnerable%20Infrastructure) from arriving to production see: Bridgecrew (https://bridgecrew.io/?utm_source=github&utm_medium=organic_oss&utm_campaign=terragoat) & checkov (https://github.com/bridgecrewio/checkov/), the open source static analysis (https://www.kitploit.com/search/label/Static%20Analysis) tool for infrastructure (https://www.kitploit.com/search/label/Infrastructure) as code. Getting started AWS Setup Installation (AWS) You can deploy multiple TerraGoat stacks in a single AWS account using the parameter TF_VAR_environment. Create an S3 Bucket backend to keep Terraform state export TERRAGOAT_STATE_BUCKET="mydevsecops-bucket"
export TF_VAR_company_name=acme
export TF_VAR_environment=mydevsecops
export TF_VAR_region="us-west-2"

aws s3api create-bucket --bucket $TERRAGOAT_STATE_BUCKET \
--region $TF_VAR_region --create-bucket-configuration LocationConstraint=$TF_VAR_region

# Enable versioning
aws s3api put-bucket-versioning --bucket $TERRAGOAT_STATE_BUCKET --versioning-configuration Status=Enabled

# Enable encryption
aws s3api put-bucket-encryption --bucket $TERRAGOAT_STATE_BUCKET --server-side-encryption-configuration '{
"Rules": [
{
"ApplyServerSideEncryptionByDefault": {
"SSEAlgorithm": "aws:kms"
}
}
]
}' Apply TerraGoat (AWS) cd terraform/aws/
terraform init \
-backend-config="bucket=$TERRAGOAT_STATE_BUCKET" \
-backend-config="key=$TF_VAR_company_name-$TF_VAR_environment.tfstate" \
-backend-config="region=$TF_VAR_region"

terraform apply Remove TerraGoat (AWS) terraform destroy Creating multiple TerraGoat AWS stacks cd terraform/aws/
export TERRAGOAT_ENV=$TF_VAR_environment
export TERRAGOAT_STACKS_NUM=5
for i in $(seq 1 $TERRAGOAT_STACKS_NUM)
do
export TF_VAR_environment=$TERRAGOAT_ENV$i
terraform init \
-backend-config="bucket=$TERRAGOAT_STATE_BUCKET" \
-backend-config="key=$TF_VAR_company_name-$TF_VAR_environment.tfstate" \
-backend-config="region=$TF_VAR_region"

terraform apply -auto-approve
done Deleting multiple TerraGoat stacks (AWS) cd terraform/aws/
export TF_VAR_environment = $TERRAGOAT_ENV
for i in $(seq 1 $TERRAGOAT_STACKS_NUM)
do
export TF_VAR_environment=$TERRAGOAT_ENV$i
terraform init \
-backend-config="bucket=$TERRAGOAT_STATE_BUCKET" \
-backend-config="key=$TF_VAR_company_name-$TF_VAR_environment.tfstate" \
-backend-config="region=$TF_VAR_region"

terraform destroy -auto-approve
export TERRAGOAT_STATE_STORAGE_ACCOUNT="mydevsecopssa"
export TERRAGOAT_STATE_CONTAINER="mydevsecops"
export TF_VAR_environment="dev"
export TF_VAR_region="westus"

# Create resource group
az group create --location $TF_VAR_region --name $TERRAGOAT_RESOURCE_GROUP

# Create storage account
az storage account create --name $TERRAGOAT_STATE_STORAGE_ACCOUNT --resource-group $TERRAGOAT_RESOURCE_GROUP --location $TF_VAR_region --sku Standard_LRS --kind StorageV2 --https-only true --encryption-services blob

# Get storage account key
ACCOUNT_KEY=$(az storage account keys list --resource-group $TERRAGOAT_RESOURCE_GROUP --account-name $TERRAGOAT_STATE_STORAGE_ACCOUNT --query [0].value -o tsv)

# Create blob container
az storage container create --name $TERRAGOAT_STATE_CONTAINER --account-name $TERRAGOAT_STATE_STORAGE_ACCOUNT --account-key $ACCOUNT_KEY Apply TerraGoat (Azure) cd terraform/azure/
terraform init -reconfigure -backend-config="resource_group_name=$TERRAGOAT_RESOURCE_GROUP" \
-backend-config "storage_account_name=$TERRAGOAT_STATE_STORAGE_ACCOUNT" \
-backend-config="container_name=$TERRAGOAT_STATE_CONTAINER" \
-backend-config "key=$TF_VAR_environment.terraform.tfstate"

terraform apply Remove TerraGoat (Azure) terraform destroy GCP Setup Installation (GCP) You can deploy multiple TerraGoat stacks in a single GCP project using the parameter TF_VAR_environment. Create a GCS backend to keep Terraform state To use terraform, a Service Account and matching set of credentials are required. If they do not exist, they must be manually created for the relevant project. To create the Service Account: Sign into your GCP project, go to IAM > Service Accounts. Click the CREATE SERVICE ACCOUNT. Give a name to your service account (for example - terragoat) and click CREATE. Grant the Service Account the Project > Editor role and click CONTINUE. Click DONE. To create the credentials: Sign into your GCP project, go to IAM > Service Accounts and click on the relevant Service Account. Click ADD KEY > Create new key > JSON and click CREATE. This will create a .json file and download it to your computer. We recommend saving the key with a nicer name than the auto-generated one (i.e. terragoat_credentials.json), and storing the resulting JSON file inside terraform/gcp directory of terragoat. Once the credentials are set up, create the BE configuration as follows: # example: export TF_VAR_credentials_path=terragoat_credentials.json export TF_VAR_project= # Create storage bucket gsutil mb gs://${TF_TERRAGOAT_STATE_BUCKET}'>export TF_VAR_environment="dev"
export TF_TERRAGOAT_STATE_BUCKET=remote-state-bucket-terragoat
export TF_VAR_credentials_path= # example: export TF_VAR_credentials_path=terragoat_credentials.json
export TF_VAR_project=

# Create storage bucket
gsutil mb gs://${TF_TERRAGOAT_STATE_BUCKET} Apply TerraGoat (GCP) cd terraform/gcp/
terraform init -reconfigure -backend-config="bucket=$TF_TERRAGOAT_STATE_BUCKET" \
-backend-config "credentials=$TF_VAR_credentials_path" \
-backend-config "prefix=terragoat/${TF_VAR_environment}"

terraform apply Remove TerraGoat (GCP) terraform destroy Bridgecrew's IaC herd of goats CfnGoat (https://github.com/bridgecrewio/cfngoat) - Vulnerable by design Cloudformation template TerraGoat (https://github.com/bridgecrewio/terragoat) - Vulnerable by design Terraform stack CDKGoat (https://github.com/bridgecrewio/cdkgoat) - Vulnerable by design CDK application Contributing Contribution is welcomed! We would love to hear about more ideas on how to find vulnerable infrastructure-as-code design patterns. Support Bridgecrew (https://bridgecrew.io/?utm_source=github&utm_medium=organic_oss&utm_campaign=terragoat) builds and maintains TerraGoat to encourage the adoption of policy-as-code. If you need direct support you can contact us at info@bridgecrew.io (mailto:info@bridgecrew.io).