Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Hybrid Test Framework : End To End Testing Of Web, API And Security

Hybrid Test Framework is a framework supports WebUi automation across a variety of browsers like Chrome, Firefox, IE, no only limited to this but extended to test rest api, security and visual testing.

Capabilities

* Cross browser testing support
* Added browserstack support for CrossBrowser testing
* Running tests in docker containers selenium grid
* Running tests in AWS DeviceFarm selenium grid
* Running tests in selenium server in docker containers
* Security testing using OWASP, running in docker container
* Api testing support using RestAssured
* Visual regression testing using percy.io
* Accessibility testing using axe-selenium
* Stubbed api testing using WireMock
* Can send logs to ElasticSearch for kibana dashboard visualization
* Database testing support
* Kafka testing support
* Kubernetes support

Setup & Tools

* Install intellij https://www.jetbrains.com/idea/download/
* Install docker desktop https://www.docker.com/products/docker-desktop
* Java JDK_11
https://adoptopenjdk.net/
* Gradle https://gradle.org/next-steps/?version=6.8.3&format=bin
* Allure https://github.com/allure-framework/allure2/archive/2.17.2.zip
* Set Environment variables
* JAVA_HOME: Pointing to the Java SDK folder\bin
* GRADLE_HOME: Pointing to Gradle directory\bin.
* ALLURE_HOME: Pointing to allure directory\bin.
Getting Started

$ git clone
$ cd
$ import project from intellij as a gradle project
$ gradle clean
$ gradle build
$ gradle task E2E
$ gradle allureReport
$ gradle allureServe

Write your first user journey

Create new class and name as the TC00*_E2E_TEST-***

* Provide jira link in @Link
* Provide all the api components as @Feature
* Provide test severity and description
* Write test
* Use CatchBlock in try/catch section

Spin-up chrome, firefox, selenium hub and OWASP proxy server

$ docker-compose up -d

Complete infrastructure creation for local run

$ $ docker-compose -f docker-compose-infra up -d

Spin-up four additional node-chrome/firefox instances linked to the hub

$ docker-compose scale chrome=5
$ docker-compose scale firefox=5

Spin-up kafka instances

$ docker-compose -f docker-compose-kafka.yml up
$ docker-compose -f docker-compose-kafka.yml down –rmi all

Spin-up selenium hub in kubernetes instance

$ kubectl apply -f selenium-k8s-deploy-svc.yaml
$ kubectl apply -f https://raw.githubusercontent.com/kubernetes/dashboard/v2.0.0/aio/deploy/recommended.yaml
$ kubectl proxy
$ kubectl describe secret -n kube-system | grep deployment -A 12
To delete deployments
$ kubectl delete deployment selenium-node-firefox
$ kubectl delete deployment selenium-node-chrome
$ kubectl delete deployment selenium-hub

navigate to http://localhost:8001/api/v1/namespaces/kubernetes-dashboard/services/https:kubernetes-dashboard:/proxy/
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgiiOxUgyx23IqYS3FAfnWlpr5LPhHa9vAtaeSMK2-yUM9175cA9nfmRkqtR66uZ982XC8Dpcb9ljC08320Hxbd3abRtJXDrZqgGkhJZUlB8VgBBY2sMam7P0H-5Ws92XutkCTbPT6Lrdy8OpdJca3N7iaRRWozBM7d8aNmJW1Uo1JdkR7hGoHcmY5H/s1876/kubernetes.png

Download

___________________________
@hacking_Attack
@Hacking_Video
https://a.thumbs.redditmedia.com/GNtC2lMJbrtoUv-xq5ZSLhHxLj16_NM4ILZ3ZK1bkx8.jpg I'm having trouble with Airemon-ng: sudo aireplay-ng -0 0 -a [Access Point] -c [Target] wlo1it is successfully able to inject the packets. However the all of the packets are lost [see screenshot]

https://preview.redd.it/tiuuitjuw2q81.png?width=1920&format=png&auto=webp&s=38f2815bebd54316291e881c73ffaf6871b4dcbb

any suggestions?

submitted by /u/a-good-name-stuff
[link] [comments]
hacking: security in practice
Is it possible to modify data of a JSON file that's hosted on a server?

Basically, there is a specific website with a JSON file that hosts some data which I would want to change.

I've heard of JSON injections but I didn't quite understand how they work and how you can perform them. Just looking for someone who can point me in the right direction.

Is there a simple way to do it, and if not, can someone briefly explain how to perform a JSON injection?

submitted by /u/DumbMoment
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
OSINT tool to extract info about persons from git repositories: common names, emails, matches between different (as it may seems) accounts. Using Install git Run: repos by nickname ./gitcolombo.py --nickname LubyRuffy"> # from any git url
./gitcolombo.py -u https://github.com/Kalanchyovskaia16/newlps

# from directory, recursively
./gitcolombo.py -d ./newlps -r

# from all GitHub personal/org repos by nickname
./gitcolombo.py --nickname LubyRuffy
For batch (https://www.kitploit.com/search/label/Batch) cloning (https://www.kitploit.com/search/label/Cloning) from Gitlab and Bitbucket group repos you can use ghorg (https://github.com/gabrie30/ghorg).
Output: verbose persons info name email number of appearences as author/committer other persons that person can be emails used for the same name different names for the same person general statistics Details [RUS] https://telegra.ph/Gitcolombo---OSINT-v-GitHub-03-02 What's the difference between git author and committer? TL;DR author wrote the code (make the patch) commiter commit it to the repo (rewrite history, make pull/merge requests...) Nice explanation: https://stackoverflow.com/questions/18750808/difference-between-author-and-committer-in-git Very often developers make inaccurate commits with the one name/email (e.g. work account), then change to the right (e.g. personal account) and make git commit --amend, but forget to change the author of the commit. This way we can use it for OSINT (https://www.kitploit.com/search/label/OSINT) as match of names/emails from git history. TODO Total statistics for repos in a directory Check different names for every email GitHub support: clone all repos from account/group GitHub support: api pagination GitHub support: extract links to accounts from commit info Exclude "system" accounts (e.g. noreply@github.com (mailto:noreply@github.com)) Probabilistic graph (https://www.kitploit.com/search/label/Graph) links based on same names/emails and Levenshtein distance Other popular git platforms: Gitlab, Bitbucket and also

Download Gitcolombo (https://github.com/soxoj/gitcolombo)

___________________________
@hacking_Attack
@Hacking_Video
Use of Default Credentials to Unauthorised Remote Access of Internal Panel of Network Video…

👨🏼‍💻Discovered by Dnyanesh A. GawandeContinue reading on Medium »
Read more...