Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
HTTP request smuggling bug patched in mitmproxy
HTTP request smuggling bug patched in mitmproxyPost Views: 3
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png
Reading Time: 2 Minutes
Mitmproxy, an open source, interactive HTTPS proxy service, has patched a dangerous bug that potentially allowed attackers to stage HTTP request smuggling attacks against backend servers. HTTP request smuggling attacks exploit the inconsistencies between the way intermediary and backend servers process requests to bypass security controls, gain unauthorized access to sensitive data, or compromise other application users. An elusive bugZhang Zeyu, the security researcher who reported the bug, discovered that an attacker could smuggle a request/response through mitmproxy as part of another request/response’s HTTP message body.
“While the more obvious attack vectors (e.g., double Content-Length headers, using Content-Length over Transfer-Encoding) are rare nowadays, more subtle deviations from the standard leave certain setups equally vulnerable to request smuggling,” he told The Daily Swig.
In the case of mitmproxy, an issue with the parsing of whitespace in header names resulted in mitmproxy and a downstream server possibly having different interpretations of HTTP headers.
“Eliminating this type of vulnerability is very tricky as you need different HTTP implementations (proxy and target server) to agree on a common interpretation of HTTP messages,” Maximilian Hils, the maintainer of mitmproxy, told The Daily Swig.
Alternatively, you can make the proxy reject potentially malformed messages, but that would have the drawback of imposing compatibility problems with clients in the wild, Hils said.
“This is not a buffer overflow, which has an obvious fix. There are a lot of nuances here to make sure that intermediary and servers agree,” he said.
See Also: Complete Offensive Security and Ethical Hacking Course
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png HTTP/2 not affectedThe bug only works against HTTP/1 services behind mitmproxy, which currently accounts for a very small number of web servers.
HTTP/2, the more commonly used protocol, does not rely on the use of Content-Length and Transfer-Encoding headers to determine where a request body ends.
Instead, a built-in length field is included in each data frame, and when proxies communicate with backends using HTTP/2, there is little ambiguity on the length of each message. Therefore, this particular request smuggling bug would be ineffective against HTTP/2 services.
HTTP/1 services that follow the RFC7230 specification and reject headers with whitespace would also be immune against the request smuggling bug found in mitmproxy. The security bug would also be useless to attackers if the target web application is not vulnerable in some other way.
“From a practical point of view, I’d argue that the impact is non-existent for the vast majority of users,” Hils said. “There are a lot of not-so-common preconditions that need to be met. I’d say quite a few stars need to align for this to have an actual impact in the wild.”
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Edge casesBut Zeyu warned that many backend servers still fail to support HTTP/2, including Gunicorn, which serves many Python-based applications. And in many cases, services that support HTTP/2 are not configured to use it between the frontend proxy and the backend servers simply because most clients would not notice the difference, according to Zeyu.
“This means that there are still a lot of web proxy and server configurations that speak HTTP/2 between the client and the proxy but HTTP/1.x between the prox[...]
___________________________
@hacking_Attack
@Hacking_Video
HTTP request smuggling bug patched in mitmproxy
HTTP request smuggling bug patched in mitmproxyPost Views: 3
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png
Reading Time: 2 Minutes
Mitmproxy, an open source, interactive HTTPS proxy service, has patched a dangerous bug that potentially allowed attackers to stage HTTP request smuggling attacks against backend servers. HTTP request smuggling attacks exploit the inconsistencies between the way intermediary and backend servers process requests to bypass security controls, gain unauthorized access to sensitive data, or compromise other application users. An elusive bugZhang Zeyu, the security researcher who reported the bug, discovered that an attacker could smuggle a request/response through mitmproxy as part of another request/response’s HTTP message body.
“While the more obvious attack vectors (e.g., double Content-Length headers, using Content-Length over Transfer-Encoding) are rare nowadays, more subtle deviations from the standard leave certain setups equally vulnerable to request smuggling,” he told The Daily Swig.
In the case of mitmproxy, an issue with the parsing of whitespace in header names resulted in mitmproxy and a downstream server possibly having different interpretations of HTTP headers.
“Eliminating this type of vulnerability is very tricky as you need different HTTP implementations (proxy and target server) to agree on a common interpretation of HTTP messages,” Maximilian Hils, the maintainer of mitmproxy, told The Daily Swig.
Alternatively, you can make the proxy reject potentially malformed messages, but that would have the drawback of imposing compatibility problems with clients in the wild, Hils said.
“This is not a buffer overflow, which has an obvious fix. There are a lot of nuances here to make sure that intermediary and servers agree,” he said.
See Also: Complete Offensive Security and Ethical Hacking Course
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png HTTP/2 not affectedThe bug only works against HTTP/1 services behind mitmproxy, which currently accounts for a very small number of web servers.
HTTP/2, the more commonly used protocol, does not rely on the use of Content-Length and Transfer-Encoding headers to determine where a request body ends.
Instead, a built-in length field is included in each data frame, and when proxies communicate with backends using HTTP/2, there is little ambiguity on the length of each message. Therefore, this particular request smuggling bug would be ineffective against HTTP/2 services.
HTTP/1 services that follow the RFC7230 specification and reject headers with whitespace would also be immune against the request smuggling bug found in mitmproxy. The security bug would also be useless to attackers if the target web application is not vulnerable in some other way.
“From a practical point of view, I’d argue that the impact is non-existent for the vast majority of users,” Hils said. “There are a lot of not-so-common preconditions that need to be met. I’d say quite a few stars need to align for this to have an actual impact in the wild.”
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Edge casesBut Zeyu warned that many backend servers still fail to support HTTP/2, including Gunicorn, which serves many Python-based applications. And in many cases, services that support HTTP/2 are not configured to use it between the frontend proxy and the backend servers simply because most clients would not notice the difference, according to Zeyu.
“This means that there are still a lot of web proxy and server configurations that speak HTTP/2 between the client and the proxy but HTTP/1.x between the prox[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
HTTP request smuggling bug patched in mitmproxy | Black Hat Ethical Hacking
Mitmproxy, an open source, interactive HTTPS proxy service, has patched a dangerous bug that potentially allowed attackers to stage HTTP request smuggling attacks against backend servers.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking HTTP request smuggling bug patched in mitmproxy HTTP request smuggling bug patched in mitmproxyPost Views: 3 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png Reading Time: 2 Minutes Mitmproxy, an open…
y and the backend, leaving room for HTTP request smuggling attacks to occur,” he said.
Irrespective of the debate about its seriousness, the bug has been patched in version 8.0 of mitmproxy. See Also: Offensive Security Tool: SysWhispers3 Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Hacking stories: MafiaBoy, the hacker who took down the Internet
Source: portswigger.net Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ee3dc49c79d14f20970cc8b20063f52e-90x90.jpg Flash loan attack on One Ring protocol nets crypto-thief $1.4 million3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-3-1-90x90.jpg DeadBolt Ransomware Resurfaces to Hit QNAP Again4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/hackers-90x90.jpg Lapsus$ Data Kidnappers Claim Snatches From Microsoft, Okta5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Invisible-man-scaled-e1647906959971-90x90.jpg Browser-in-the-Browser Attack Makes Phishing Nearly Invisible6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/pdf-export-90x90.png Workaround offered for unpatched HTML-to-PDF rendering vulnerability7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-2-scaled-90x90.jpg Caketap, a New Unix rootkit for stealing ATM banking data1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/AdobeStock_390895150_Editorial_Use_Only-1-1-min-scaled-1-90x90.jpeg Hundreds of GoDaddy-hosted sites backdoored in a single day2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/79ohvicqaKcVP9KT2mDdTH-90x90.jpg Most QNAP NAS Devices Affected by ‘Dirty Pipe’ Linux Flaw2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Lapsus-group-has-hacked-Ubisoft-as-well-90x90.jpg Ubisoft has confirmed it was hacked by Lapsus$ group2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/raccoon-stealer-90x90.jpg Raccoon Stealer Crawls Into Telegram2 weeks ago
The post HTTP request smuggling bug patched in mitmproxy first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Irrespective of the debate about its seriousness, the bug has been patched in version 8.0 of mitmproxy. See Also: Offensive Security Tool: SysWhispers3 Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Hacking stories: MafiaBoy, the hacker who took down the Internet
Source: portswigger.net Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ee3dc49c79d14f20970cc8b20063f52e-90x90.jpg Flash loan attack on One Ring protocol nets crypto-thief $1.4 million3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-3-1-90x90.jpg DeadBolt Ransomware Resurfaces to Hit QNAP Again4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/hackers-90x90.jpg Lapsus$ Data Kidnappers Claim Snatches From Microsoft, Okta5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Invisible-man-scaled-e1647906959971-90x90.jpg Browser-in-the-Browser Attack Makes Phishing Nearly Invisible6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/pdf-export-90x90.png Workaround offered for unpatched HTML-to-PDF rendering vulnerability7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-2-scaled-90x90.jpg Caketap, a New Unix rootkit for stealing ATM banking data1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/AdobeStock_390895150_Editorial_Use_Only-1-1-min-scaled-1-90x90.jpeg Hundreds of GoDaddy-hosted sites backdoored in a single day2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/79ohvicqaKcVP9KT2mDdTH-90x90.jpg Most QNAP NAS Devices Affected by ‘Dirty Pipe’ Linux Flaw2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Lapsus-group-has-hacked-Ubisoft-as-well-90x90.jpg Ubisoft has confirmed it was hacked by Lapsus$ group2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/raccoon-stealer-90x90.jpg Raccoon Stealer Crawls Into Telegram2 weeks ago
The post HTTP request smuggling bug patched in mitmproxy first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
SSR Fire : An Automated SSRF Finder. Just Give The Domain Name And Your Server
SSR Fire is an automated SSRF finder. Just give the domain name and your server and chill! https://s.w.org/images/core/emoji/13.1.0/72x72/1f609.png It also has options to find XSS and open redirects. Syntax./ssrfire.sh -d domain.com -s yourserver.com -f custom_file.txt -c cookies
domain.com —> The domain for which you want to test
yourserver.com —> Your server which detects SSRF. Eg. Burp collaborator
custom_file.txt —> Optional argument. You give your own custom URLs instead of using gau
cookies —> Optional argument. To send requests as an authenticated user
If you don’t have burpsuite professional, you can use interact sh by the awesome projectdiscovery team as your server. RequirementsSince this uses GAU, FFUF, qsreplace and OpenRedirex, you need GO and python 3.7+. You need not have the tools installed, as the script setup.sh will install everything. You just need to install python and GO. Even if you have the tools installed I would highly recommend you to install them again so that there no conflicts while setting the paths.
If you don’t want to install the tools again, paste this code in your .profile in your home directory and source .profile them. Also, you have to make a small change in the ssrfire.sh on line 10, where you have to replace source /home/hari/.profile without your .profile path. (Only if you are not installing tools through setup.sh)
#Replace /path/to/ with the specific directory where the tool is installed
#If you already have configured paths for any of the tools, replace that code with the below one.
ffuf(){
echo “Usage: ffuf https://www.domain.com/FUZZ payloads.txt”
/path/to/ffuf/./main -u $1 -w $2 -b $3 -c -t 100
}
gau(){
echo “Usage: gau domain.com”
/path/to/gau/./main $1
}
gau_s(){
/path/to/gau/./main –subs $1
}
openredirex(){
echo “Usage: openredirex urls.txt payloads.txt”
python3 /path/to/OpenRedireX/openredirex.py -l $1 -p $2 –keyword FUZZ
}
qsreplace(){
/path/to/qsreplace/./main $1
}
Usage
chmod +x setup.sh
./setup.sh (preferably yes for all —> highly recommended)
./ssrfire.sh -d domain.com -s yourserver.com Finding SSRFNow, gau gets into action by fetching all the URLs of the domain. This may take a lot of time. You can check the output generated till now at output/domain.com/raw_urls.txt
Let it run for at least 10-15 minutes, and then if you want to continue, you can. But if you want to test the URLs fetched till now, quit the process. Copy the raw_urls.txt inside of output/domain.com and place it outside the domain.com folder Now run
./ssrfire.sh -d domain.com -s yourserver.com -f /path/to/copied_raw_urls.txt
Select yes when asked whether to delete the existing folder.
This will skip the process of GAU fetching URLs.
Now all the URLs with parameters will be filtered and yourserver.com will be placed into their parameter values.(final_urls.txt)
The next step is to fire requests to all the final URLs. Finding XSSWarning: This generates a lot of traffic. Do not use this against sites which you are not authorized to test
This tests all the URLs fetched, and based on how the input is reflected in the response, it adds that particular URL to the output/domain.com/xss-suspects.txt (This may contain false positives)
For further testing this, you can input this list to the XSS detection tools like XSStrike to find XSS. Finding open redirectsJust enter the path to a payload file or use the default payload. I personally prefer open redirex, as it is specifically designed to check for open redirects by loading the URLs from the list and it looks a lot cleaner, and doesn’t flood your terminal. Download
___________________________
@hacking_Attack
@Hacking_Video
SSR Fire : An Automated SSRF Finder. Just Give The Domain Name And Your Server
SSR Fire is an automated SSRF finder. Just give the domain name and your server and chill! https://s.w.org/images/core/emoji/13.1.0/72x72/1f609.png It also has options to find XSS and open redirects. Syntax./ssrfire.sh -d domain.com -s yourserver.com -f custom_file.txt -c cookies
domain.com —> The domain for which you want to test
yourserver.com —> Your server which detects SSRF. Eg. Burp collaborator
custom_file.txt —> Optional argument. You give your own custom URLs instead of using gau
cookies —> Optional argument. To send requests as an authenticated user
If you don’t have burpsuite professional, you can use interact sh by the awesome projectdiscovery team as your server. RequirementsSince this uses GAU, FFUF, qsreplace and OpenRedirex, you need GO and python 3.7+. You need not have the tools installed, as the script setup.sh will install everything. You just need to install python and GO. Even if you have the tools installed I would highly recommend you to install them again so that there no conflicts while setting the paths.
If you don’t want to install the tools again, paste this code in your .profile in your home directory and source .profile them. Also, you have to make a small change in the ssrfire.sh on line 10, where you have to replace source /home/hari/.profile without your .profile path. (Only if you are not installing tools through setup.sh)
#Replace /path/to/ with the specific directory where the tool is installed
#If you already have configured paths for any of the tools, replace that code with the below one.
ffuf(){
echo “Usage: ffuf https://www.domain.com/FUZZ payloads.txt”
/path/to/ffuf/./main -u $1 -w $2 -b $3 -c -t 100
}
gau(){
echo “Usage: gau domain.com”
/path/to/gau/./main $1
}
gau_s(){
/path/to/gau/./main –subs $1
}
openredirex(){
echo “Usage: openredirex urls.txt payloads.txt”
python3 /path/to/OpenRedireX/openredirex.py -l $1 -p $2 –keyword FUZZ
}
qsreplace(){
/path/to/qsreplace/./main $1
}
Usage
chmod +x setup.sh
./setup.sh (preferably yes for all —> highly recommended)
./ssrfire.sh -d domain.com -s yourserver.com Finding SSRFNow, gau gets into action by fetching all the URLs of the domain. This may take a lot of time. You can check the output generated till now at output/domain.com/raw_urls.txt
Let it run for at least 10-15 minutes, and then if you want to continue, you can. But if you want to test the URLs fetched till now, quit the process. Copy the raw_urls.txt inside of output/domain.com and place it outside the domain.com folder Now run
./ssrfire.sh -d domain.com -s yourserver.com -f /path/to/copied_raw_urls.txt
Select yes when asked whether to delete the existing folder.
This will skip the process of GAU fetching URLs.
Now all the URLs with parameters will be filtered and yourserver.com will be placed into their parameter values.(final_urls.txt)
The next step is to fire requests to all the final URLs. Finding XSSWarning: This generates a lot of traffic. Do not use this against sites which you are not authorized to test
This tests all the URLs fetched, and based on how the input is reflected in the response, it adds that particular URL to the output/domain.com/xss-suspects.txt (This may contain false positives)
For further testing this, you can input this list to the XSS detection tools like XSStrike to find XSS. Finding open redirectsJust enter the path to a payload file or use the default payload. I personally prefer open redirex, as it is specifically designed to check for open redirects by loading the URLs from the list and it looks a lot cleaner, and doesn’t flood your terminal. Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
SSR Fire : An Automated SSRF Finder. Give Domain Name And Server
SSR Fire is an automated SSRF finder. Just give the domain name and your server and chill! ;) It also has options to find XSS
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Hybrid Test Framework : End To End Testing Of Web, API And Security
Hybrid Test Framework is a framework supports WebUi automation across a variety of browsers like Chrome, Firefox, IE, no only limited to this but extended to test rest api, security and visual testing.
Capabilities
* Cross browser testing support
* Added browserstack support for CrossBrowser testing
* Running tests in docker containers selenium grid
* Running tests in AWS DeviceFarm selenium grid
* Running tests in selenium server in docker containers
* Security testing using OWASP, running in docker container
* Api testing support using RestAssured
* Visual regression testing using percy.io
* Accessibility testing using axe-selenium
* Stubbed api testing using WireMock
* Can send logs to ElasticSearch for kibana dashboard visualization
* Database testing support
* Kafka testing support
* Kubernetes support
Setup & Tools
* Install intellij https://www.jetbrains.com/idea/download/
* Install docker desktop https://www.docker.com/products/docker-desktop
* Java JDK_11
https://adoptopenjdk.net/
* Gradle https://gradle.org/next-steps/?version=6.8.3&format=bin
* Allure https://github.com/allure-framework/allure2/archive/2.17.2.zip
* Set Environment variables
* JAVA_HOME: Pointing to the Java SDK folder\bin
* GRADLE_HOME: Pointing to Gradle directory\bin.
* ALLURE_HOME: Pointing to allure directory\bin.
Getting Started
$ git clone
$ cd
$ import project from intellij as a gradle project
$ gradle clean
$ gradle build
$ gradle task E2E
$ gradle allureReport
$ gradle allureServe
Write your first user journey
Create new class and name as the TC00*_E2E_TEST-***
* Provide jira link in @Link
* Provide all the api components as @Feature
* Provide test severity and description
* Write test
* Use CatchBlock in try/catch section
Spin-up chrome, firefox, selenium hub and OWASP proxy server
$ docker-compose up -d
Complete infrastructure creation for local run
$ $ docker-compose -f docker-compose-infra up -d
Spin-up four additional node-chrome/firefox instances linked to the hub
$ docker-compose scale chrome=5
$ docker-compose scale firefox=5
Spin-up kafka instances
$ docker-compose -f docker-compose-kafka.yml up
$ docker-compose -f docker-compose-kafka.yml down –rmi all
Spin-up selenium hub in kubernetes instance
$ kubectl apply -f selenium-k8s-deploy-svc.yaml
$ kubectl apply -f https://raw.githubusercontent.com/kubernetes/dashboard/v2.0.0/aio/deploy/recommended.yaml
$ kubectl proxy
$ kubectl describe secret -n kube-system | grep deployment -A 12
To delete deployments
$ kubectl delete deployment selenium-node-firefox
$ kubectl delete deployment selenium-node-chrome
$ kubectl delete deployment selenium-hub
navigate to
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgiiOxUgyx23IqYS3FAfnWlpr5LPhHa9vAtaeSMK2-yUM9175cA9nfmRkqtR66uZ982XC8Dpcb9ljC08320Hxbd3abRtJXDrZqgGkhJZUlB8VgBBY2sMam7P0H-5Ws92XutkCTbPT6Lrdy8OpdJca3N7iaRRWozBM7d8aNmJW1Uo1JdkR7hGoHcmY5H/s1876/kubernetes.png
Download
___________________________
@hacking_Attack
@Hacking_Video
Hybrid Test Framework : End To End Testing Of Web, API And Security
Hybrid Test Framework is a framework supports WebUi automation across a variety of browsers like Chrome, Firefox, IE, no only limited to this but extended to test rest api, security and visual testing.
Capabilities
* Cross browser testing support
* Added browserstack support for CrossBrowser testing
* Running tests in docker containers selenium grid
* Running tests in AWS DeviceFarm selenium grid
* Running tests in selenium server in docker containers
* Security testing using OWASP, running in docker container
* Api testing support using RestAssured
* Visual regression testing using percy.io
* Accessibility testing using axe-selenium
* Stubbed api testing using WireMock
* Can send logs to ElasticSearch for kibana dashboard visualization
* Database testing support
* Kafka testing support
* Kubernetes support
Setup & Tools
* Install intellij https://www.jetbrains.com/idea/download/
* Install docker desktop https://www.docker.com/products/docker-desktop
* Java JDK_11
https://adoptopenjdk.net/
* Gradle https://gradle.org/next-steps/?version=6.8.3&format=bin
* Allure https://github.com/allure-framework/allure2/archive/2.17.2.zip
* Set Environment variables
* JAVA_HOME: Pointing to the Java SDK folder\bin
* GRADLE_HOME: Pointing to Gradle directory\bin.
* ALLURE_HOME: Pointing to allure directory\bin.
Getting Started
$ git clone
$ cd
$ import project from intellij as a gradle project
$ gradle clean
$ gradle build
$ gradle task E2E
$ gradle allureReport
$ gradle allureServe
Write your first user journey
Create new class and name as the TC00*_E2E_TEST-***
* Provide jira link in @Link
* Provide all the api components as @Feature
* Provide test severity and description
* Write test
* Use CatchBlock in try/catch section
Spin-up chrome, firefox, selenium hub and OWASP proxy server
$ docker-compose up -d
Complete infrastructure creation for local run
$ $ docker-compose -f docker-compose-infra up -d
Spin-up four additional node-chrome/firefox instances linked to the hub
$ docker-compose scale chrome=5
$ docker-compose scale firefox=5
Spin-up kafka instances
$ docker-compose -f docker-compose-kafka.yml up
$ docker-compose -f docker-compose-kafka.yml down –rmi all
Spin-up selenium hub in kubernetes instance
$ kubectl apply -f selenium-k8s-deploy-svc.yaml
$ kubectl apply -f https://raw.githubusercontent.com/kubernetes/dashboard/v2.0.0/aio/deploy/recommended.yaml
$ kubectl proxy
$ kubectl describe secret -n kube-system | grep deployment -A 12
To delete deployments
$ kubectl delete deployment selenium-node-firefox
$ kubectl delete deployment selenium-node-chrome
$ kubectl delete deployment selenium-hub
navigate to
http://localhost:8001/api/v1/namespaces/kubernetes-dashboard/services/https:kubernetes-dashboard:/proxy/https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgiiOxUgyx23IqYS3FAfnWlpr5LPhHa9vAtaeSMK2-yUM9175cA9nfmRkqtR66uZ982XC8Dpcb9ljC08320Hxbd3abRtJXDrZqgGkhJZUlB8VgBBY2sMam7P0H-5Ws92XutkCTbPT6Lrdy8OpdJca3N7iaRRWozBM7d8aNmJW1Uo1JdkR7hGoHcmY5H/s1876/kubernetes.png
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Hybrid Test Framework : End To End Testing Of Web, API And Security
Hybrid Test Framework is a framework supports WebUi automation across a variety of browsers like Chrome, Firefox, IE.
Hacking on Medium
One-liner Bug Bounty Tips
A collection of awesome one-liner scripts especially for bug bounty.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
One-liner Bug Bounty Tips
A collection of awesome one-liner scripts especially for bug bounty.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
One-liner Bug Bounty Tips
A collection of awesome one-liner scripts especially for bug bounty.
Hacking on Medium
Shipping Label Printing for the Masses
https://cdn-images-1.medium.com/max/640/1*HsTToPTNvMsYM3ZUIyqzCg.png
TLDR: I’ve been shipping using thermal label printers for years, and I go with the “Honda Civic” of label printers, the venerable Zebra…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Shipping Label Printing for the Masses
https://cdn-images-1.medium.com/max/640/1*HsTToPTNvMsYM3ZUIyqzCg.png
TLDR: I’ve been shipping using thermal label printers for years, and I go with the “Honda Civic” of label printers, the venerable Zebra…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Shipping Label Printing for the Masses
TLDR: I’ve been shipping using thermal label printers for years, and I go with the “Honda Civic” of label printers, the venerable Zebra…
https://a.thumbs.redditmedia.com/GNtC2lMJbrtoUv-xq5ZSLhHxLj16_NM4ILZ3ZK1bkx8.jpg I'm having trouble with Airemon-ng:
https://preview.redd.it/tiuuitjuw2q81.png?width=1920&format=png&auto=webp&s=38f2815bebd54316291e881c73ffaf6871b4dcbb
any suggestions?
submitted by /u/a-good-name-stuff
[link] [comments]
sudo aireplay-ng -0 0 -a [Access Point] -c [Target] wlo1it is successfully able to inject the packets. However the all of the packets are lost [see screenshot]https://preview.redd.it/tiuuitjuw2q81.png?width=1920&format=png&auto=webp&s=38f2815bebd54316291e881c73ffaf6871b4dcbb
any suggestions?
submitted by /u/a-good-name-stuff
[link] [comments]
hacking: security in practice
Is it possible to modify data of a JSON file that's hosted on a server?
Basically, there is a specific website with a JSON file that hosts some data which I would want to change.
I've heard of JSON injections but I didn't quite understand how they work and how you can perform them. Just looking for someone who can point me in the right direction.
Is there a simple way to do it, and if not, can someone briefly explain how to perform a JSON injection?
submitted by /u/DumbMoment
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is it possible to modify data of a JSON file that's hosted on a server?
Basically, there is a specific website with a JSON file that hosts some data which I would want to change.
I've heard of JSON injections but I didn't quite understand how they work and how you can perform them. Just looking for someone who can point me in the right direction.
Is there a simple way to do it, and if not, can someone briefly explain how to perform a JSON injection?
submitted by /u/DumbMoment
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is it possible to modify data of a JSON file that's hosted on a...
Basically, there is a specific website with a JSON file that hosts some data which I would want to change. I've heard of JSON injections but I...
Gitcolombo - Extract And Analyze Contributors Info From Git Repos
http://www.kitploit.com/2022/03/gitcolombo-extract-and-analyze.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/03/gitcolombo-extract-and-analyze.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Gitcolombo - Extract And Analyze Contributors Info From Git Repos
OSINT tool to extract info about persons from git repositories: common names, emails, matches between different (as it may seems) accounts. Using Install git Run: repos by nickname ./gitcolombo.py --nickname LubyRuffy"> # from any git url
./gitcolombo.py -u https://github.com/Kalanchyovskaia16/newlps
# from directory, recursively
./gitcolombo.py -d ./newlps -r
# from all GitHub personal/org repos by nickname
./gitcolombo.py --nickname LubyRuffy
For batch (https://www.kitploit.com/search/label/Batch) cloning (https://www.kitploit.com/search/label/Cloning) from Gitlab and Bitbucket group repos you can use ghorg (https://github.com/gabrie30/ghorg).
Output: verbose persons info name email number of appearences as author/committer other persons that person can be emails used for the same name different names for the same person general statistics Details [RUS] https://telegra.ph/Gitcolombo---OSINT-v-GitHub-03-02 What's the difference between git author and committer? TL;DR author wrote the code (make the patch) commiter commit it to the repo (rewrite history, make pull/merge requests...) Nice explanation: https://stackoverflow.com/questions/18750808/difference-between-author-and-committer-in-git Very often developers make inaccurate commits with the one name/email (e.g. work account), then change to the right (e.g. personal account) and make git commit --amend, but forget to change the author of the commit. This way we can use it for OSINT (https://www.kitploit.com/search/label/OSINT) as match of names/emails from git history. TODO Total statistics for repos in a directory Check different names for every email GitHub support: clone all repos from account/group GitHub support: api pagination GitHub support: extract links to accounts from commit info Exclude "system" accounts (e.g. noreply@github.com (mailto:noreply@github.com)) Probabilistic graph (https://www.kitploit.com/search/label/Graph) links based on same names/emails and Levenshtein distance Other popular git platforms: Gitlab, Bitbucket and also
Download Gitcolombo (https://github.com/soxoj/gitcolombo)
___________________________
@hacking_Attack
@Hacking_Video
./gitcolombo.py -u https://github.com/Kalanchyovskaia16/newlps
# from directory, recursively
./gitcolombo.py -d ./newlps -r
# from all GitHub personal/org repos by nickname
./gitcolombo.py --nickname LubyRuffy
For batch (https://www.kitploit.com/search/label/Batch) cloning (https://www.kitploit.com/search/label/Cloning) from Gitlab and Bitbucket group repos you can use ghorg (https://github.com/gabrie30/ghorg).
Output: verbose persons info name email number of appearences as author/committer other persons that person can be emails used for the same name different names for the same person general statistics Details [RUS] https://telegra.ph/Gitcolombo---OSINT-v-GitHub-03-02 What's the difference between git author and committer? TL;DR author wrote the code (make the patch) commiter commit it to the repo (rewrite history, make pull/merge requests...) Nice explanation: https://stackoverflow.com/questions/18750808/difference-between-author-and-committer-in-git Very often developers make inaccurate commits with the one name/email (e.g. work account), then change to the right (e.g. personal account) and make git commit --amend, but forget to change the author of the commit. This way we can use it for OSINT (https://www.kitploit.com/search/label/OSINT) as match of names/emails from git history. TODO Total statistics for repos in a directory Check different names for every email GitHub support: clone all repos from account/group GitHub support: api pagination GitHub support: extract links to accounts from commit info Exclude "system" accounts (e.g. noreply@github.com (mailto:noreply@github.com)) Probabilistic graph (https://www.kitploit.com/search/label/Graph) links based on same names/emails and Levenshtein distance Other popular git platforms: Gitlab, Bitbucket and also
Download Gitcolombo (https://github.com/soxoj/gitcolombo)
___________________________
@hacking_Attack
@Hacking_Video
Use of Default Credentials to Unauthorised Remote Access of Internal Panel of Network Video…
👨🏼💻Discovered by Dnyanesh A. GawandeContinue reading on Medium »
Read more...
👨🏼💻Discovered by Dnyanesh A. GawandeContinue reading on Medium »
Read more...
Use of Default Credentials to Unauthorised Remote Access of Internal Panel of Network Video…
https://medium.com/@dnyanesh766/use-of-default-credentials-to-unauthorised-remote-access-of-internal-panel-of-network-video-5490d107fa0?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@dnyanesh766/use-of-default-credentials-to-unauthorised-remote-access-of-internal-panel-of-network-video-5490d107fa0?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Use of Default Credentials to Unauthorised Remote Access of Internal Panel of Network Video…
👨🏼💻Discovered by Dnyanesh A. Gawande
👨🏼💻Discovered by Dnyanesh A. GawandeContinue reading on Medium » (https://medium.com/@dnyanesh766/use-of-default-credentials-to-unauthorised-remote-access-of-internal-panel-of-network-video-5490d107fa0?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Use of Default Credentials to Unauthorised Remote Access of Internal Panel of Network Video…
👨🏼💻Discovered by Dnyanesh A. Gawande
Zenlink заключил партнерство с Immunefi и запустил программу по поиску ошибок
https://medium.com/@black322/zenlink-%D0%B7%D0%B0%D0%BA%D0%BB%D1%8E%D1%87%D0%B8%D0%BB-%D0%BF%D0%B0%D1%80%D1%82%D0%BD%D0%B5%D1%80%D1%81%D1%82%D0%B2%D0%BE-%D1%81-immunefi-%D0%B8-%D0%B7%D0%B0%D0%BF%D1%83%D1%81%D1%82%D0%B8%D0%BB-%D0%BF%D1%80%D0%BE%D0%B3%D1%80%D0%B0%D0%BC%D0%BC%D1%83-%D0%BF%D0%BE-%D0%BF%D0%BE%D0%B8%D1%81%D0%BA%D1%83-%D0%BE%D1%88%D0%B8%D0%B1%D0%BE%D0%BA-872674b0d84c?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@black322/zenlink-%D0%B7%D0%B0%D0%BA%D0%BB%D1%8E%D1%87%D0%B8%D0%BB-%D0%BF%D0%B0%D1%80%D1%82%D0%BD%D0%B5%D1%80%D1%81%D1%82%D0%B2%D0%BE-%D1%81-immunefi-%D0%B8-%D0%B7%D0%B0%D0%BF%D1%83%D1%81%D1%82%D0%B8%D0%BB-%D0%BF%D1%80%D0%BE%D0%B3%D1%80%D0%B0%D0%BC%D0%BC%D1%83-%D0%BF%D0%BE-%D0%BF%D0%BE%D0%B8%D1%81%D0%BA%D1%83-%D0%BE%D1%88%D0%B8%D0%B1%D0%BE%D0%BA-872674b0d84c?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Zenlink заключил партнерство с Immunefi и запустил программу по поиску ошибок
Сегодня 23 марта 2022 года , и мы рады сообщить, что компания Zenlink заключила партнерство с Immunefi и запустила программу по поиску…
Сегодня 23 марта 2022 года , и мы рады сообщить, что компания Zenlink заключила партнерство с Immunefi и запустила программу по поиску…Continue reading on Medium » (https://medium.com/@black322/zenlink-%D0%B7%D0%B0%D0%BA%D0%BB%D1%8E%D1%87%D0%B8%D0%BB-%D0%BF%D0%B0%D1%80%D1%82%D0%BD%D0%B5%D1%80%D1%81%D1%82%D0%B2%D0%BE-%D1%81-immunefi-%D0%B8-%D0%B7%D0%B0%D0%BF%D1%83%D1%81%D1%82%D0%B8%D0%BB-%D0%BF%D1%80%D0%BE%D0%B3%D1%80%D0%B0%D0%BC%D0%BC%D1%83-%D0%BF%D0%BE-%D0%BF%D0%BE%D0%B8%D1%81%D0%BA%D1%83-%D0%BE%D1%88%D0%B8%D0%B1%D0%BE%D0%BA-872674b0d84c?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Zenlink заключил партнерство с Immunefi и запустил программу по поиску ошибок
Сегодня 23 марта 2022 года , и мы рады сообщить, что компания Zenlink заключила партнерство с Immunefi и запустила программу по поиску…