Hacking on Medium
Router Security Analysis
https://cdn-images-1.medium.com/max/906/1*RgzZB8wFGTfr8VGUhe-CDA.jpeg
The goal of my study was to identify how weak the commercially available routers are.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Router Security Analysis
https://cdn-images-1.medium.com/max/906/1*RgzZB8wFGTfr8VGUhe-CDA.jpeg
The goal of my study was to identify how weak the commercially available routers are.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Router Security Analysis
The goal of my study was to identify how weak the commercially available routers are.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
How Hackers Steal Your Crypto. Safeguard your crypto from HACKERS. (Remedies to Crypto Hacking)
https://external-preview.redd.it/9PnS-h6p3cFj5iCl6NQwcnwmNgG48Ir9x7qvGkmGOIc.jpg?width=320&crop=smart&auto=webp&s=1b51d862ab4d17e3dad8bd775cd469f502abcf91 submitted by /u/GeofreyGekood
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How Hackers Steal Your Crypto. Safeguard your crypto from HACKERS. (Remedies to Crypto Hacking)
https://external-preview.redd.it/9PnS-h6p3cFj5iCl6NQwcnwmNgG48Ir9x7qvGkmGOIc.jpg?width=320&crop=smart&auto=webp&s=1b51d862ab4d17e3dad8bd775cd469f502abcf91 submitted by /u/GeofreyGekood
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How Hackers Steal Your Crypto. Safeguard your crypto from HACKERS....
Posted in r/hacking by u/GeofreyGekood • 1 point and 0 comments
hacking: security in practice
really just crunch, cupp, and mentalist?
So unfortunately I hit a writer's block when it comes to coming up with my word lists. I try to think the best way to compile one, crunches great for its versatility, cupp is great for its interaction and assisting, and The Mentalist is pretty good because the GUI and the multiple options to append and dates and nouns etc etc. But is there a way to create a word list with the options to take one word, appended with another random word and then add numbers or characters? Crunch has the -t yes, but what if I wanted to mash random WORDS together? I guess for instance pretty much just cracking Wi-Fi there's only part that I have troubles with for wordlists, is there not a wordlists with "default" router logins? Is reaver now obsolete?
submitted by /u/Sn0wbird187
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
really just crunch, cupp, and mentalist?
So unfortunately I hit a writer's block when it comes to coming up with my word lists. I try to think the best way to compile one, crunches great for its versatility, cupp is great for its interaction and assisting, and The Mentalist is pretty good because the GUI and the multiple options to append and dates and nouns etc etc. But is there a way to create a word list with the options to take one word, appended with another random word and then add numbers or characters? Crunch has the -t yes, but what if I wanted to mash random WORDS together? I guess for instance pretty much just cracking Wi-Fi there's only part that I have troubles with for wordlists, is there not a wordlists with "default" router logins? Is reaver now obsolete?
submitted by /u/Sn0wbird187
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
really just crunch, cupp, and mentalist?
So unfortunately I hit a writer's block when it comes to coming up with my word lists. I try to think the best way to compile one, crunches great...
hacking: security in practice
Malicious USB-C SD Card Reader?
Hey everyone, are you aware of any USB-C SD card reader devices being sold on Amazon that might try to hack connected PCs? I bought one and in 7 out of 10 times my laptop freezes/crashes and later it reported some issues with the trust platform (Win 11).
How could I verify?
submitted by /u/DaSchos
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Malicious USB-C SD Card Reader?
Hey everyone, are you aware of any USB-C SD card reader devices being sold on Amazon that might try to hack connected PCs? I bought one and in 7 out of 10 times my laptop freezes/crashes and later it reported some issues with the trust platform (Win 11).
How could I verify?
submitted by /u/DaSchos
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Malicious USB-C SD Card Reader?
Hey everyone, are you aware of any USB-C SD card reader devices being sold on Amazon that might try to hack connected PCs? I bought one and in 7...
hacking: security in practice
Best way to save passwords?
Hey all I just saw this post about a guy findinf passwords stored in a very clever and creative way but it got me wondering; what’s a good way to store passwords? Figured this would also be the best place to ask
thanks and cheers!
submitted by /u/coolnow_
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Best way to save passwords?
Hey all I just saw this post about a guy findinf passwords stored in a very clever and creative way but it got me wondering; what’s a good way to store passwords? Figured this would also be the best place to ask
thanks and cheers!
submitted by /u/coolnow_
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Best way to save passwords?
Hey all I just saw [this...
FIN7 Power Hour: Adversary Archaeology and the Evolution of FIN7
https://www.reddit.com/r/redteamsec/comments/txwe5l/fin7_power_hour_adversary_archaeology_and_the/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://www.mandiant.com/resources/evolution-of-fin7) [comments] (https://www.reddit.com/r/redteamsec/comments/txwe5l/fin7_power_hour_adversary_archaeology_and_the/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/txwe5l/fin7_power_hour_adversary_archaeology_and_the/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://www.mandiant.com/resources/evolution-of-fin7) [comments] (https://www.reddit.com/r/redteamsec/comments/txwe5l/fin7_power_hour_adversary_archaeology_and_the/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
FIN7 Power Hour: Adversary Archaeology and the Evolution of FIN7
Posted in r/redteamsec by u/dmchell • 1 point and 0 comments
Hacker Interview #2: Alvin “Steiner254”
Learning cybersecurity comes in many forms: technical practice, lab workshops, and also writeups. Bug bounty hunter Alvin, going by the…Continue reading on HackenProof »
Read more...
Learning cybersecurity comes in many forms: technical practice, lab workshops, and also writeups. Bug bounty hunter Alvin, going by the…Continue reading on HackenProof »
Read more...
What is SQL Injection?
https://medium.com/@kaorrosi/what-is-sql-injection-4cce5d52bdb?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@kaorrosi/what-is-sql-injection-4cce5d52bdb?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is SQL Injection?
What is It?
What is It?Continue reading on Medium » (https://medium.com/@kaorrosi/what-is-sql-injection-4cce5d52bdb?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is SQL Injection?
What is It?
Hcltm - Documenting Your Threat Models With HCL
http://www.kitploit.com/2022/04/hcltm-documenting-your-threat-models.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/04/hcltm-documenting-your-threat-models.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Hcltm - Documenting Your Threat Models With HCL
description = "Someone who isn't the Queen steals the crown"
impacts = ["Confidentiality"]
control = "Lots of guards"
}
data_flow_diagram {
// ... see below for more information
}
} See Data Flow Diagram (https://github.com/xntrik/hcltm#data-flow-diagram) for more information on how to construct data flow diagrams that are converted to PNGs automatically. To see an example of how to reference pre-defined control libraries for the OWASP Proactive Controls (https://owasp.org/www-project-proactive-controls/) and AWS Security Checklist (https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Checklist.pdf) see examples/tm3.hcl (https://github.com/xntrik/hcltm/blob/main/examples/tm3.hcl). We also have the MITRE ATT&CK Controls (https://attack.mitre.org/mitigations/enterprise/) here (https://github.com/xntrik/hcltm/blob/main/examples/MITRE_ATTACK_controls.hcl). To see a full description of the spec, see here (https://github.com/xntrik/hcltm/blob/main/spec.hcl) or run: hcltm generate boilerplate hcltm will also process JSON files, but the only caveat is that import modules and variables won't work. You can see examples/tm1.json (https://github.com/xntrik/hcltm/blob/main/examples/tm1.json) as an example. Why HCL? HCL is the primary configuration language used in the products by HashiCorp, in-particularly, Terraform (https://www.terraform.io/) - their open-source Infrastructure-as-Code software. I worked at HashiCorp for a while and the language really grew on me, plus, if DevOps and Software engineers are using the language, then simplifying how they document threat models aligns with hcltm's goals. You can use hcltm with JSON, but you lose some of the features. For more, see the examples/ (https://github.com/xntrik/hcltm/blob/main/examples) folder. Why not just document them in MD? I liked the idea of using a format that could be programmatically interacted with. Kudos and References One of the features of hcltm is the automatic generation of data flow diagrams (https://github.com/xntrik/hcltm#data-flow-diagram) from HCL files. This leverages the go-dfd (https://github.com/marqeta/go-dfd) package by Marqeta and Blake Hitchcock (https://github.com/rbhitchcock). Definitely check out their blog post on Threat models at the speed of DevOps (https://community.marqeta.com/t5/engineering-blogs/threat-models-at-the-speed-of-devops/ba-p/40). Additionally I'd like to extend thanks to Jamie Finnigan (https://twitter.com/chair6) and Talha Tariq (https://twitter.com/0xtbt) at HashiCorp for allowing me to continue working on this open-source tool even after I'd finished up with HashiCorp. hcltm cli Installation Download the latest version from releases (https://github.com/xntrik/hcltm/releases) and move the hcltm binary into your PATH. Install with Homebrew The following will add a local tap, and install hcltm with Homebrew (https://brew.sh/) brew install xntrik/repo/hcltm Run with Docker docker run --rm -it xntrik/hcltm Run with GitHub Actions hcltm can be integrated directly into your GitHub repos with https://github.com/xntrik/hcltm-action. This is one of the ideal methods to manage your threat models, and helps meet the goal of integrating into your version control systems. Building from Source Clone this repository. Change into the directory, hcltm make bootstrap make dev For further help on contributing to hcltm please see the CHANGELOG.md (https://github.com/xntrik/hcltm/blob/main/CHANGELOG.md). Usage For help on any subcommands use the -h flag. [] Available commands are: dashboard Generate markdown files from existing HCL threatmodel file(s) dfd Generate Data Flow Diagram PNG files from existing HCL threatmodel file(s) generate Generate an HCL Threat Model list List Threatmodels found in HCL file(s) validate Validate existing HCL Threatmodel file(s) view View existing HCL Threatmodel file(s) ">$ hcltm
___________________________
@hacking_Attack
@Hacking_Video
impacts = ["Confidentiality"]
control = "Lots of guards"
}
data_flow_diagram {
// ... see below for more information
}
} See Data Flow Diagram (https://github.com/xntrik/hcltm#data-flow-diagram) for more information on how to construct data flow diagrams that are converted to PNGs automatically. To see an example of how to reference pre-defined control libraries for the OWASP Proactive Controls (https://owasp.org/www-project-proactive-controls/) and AWS Security Checklist (https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Checklist.pdf) see examples/tm3.hcl (https://github.com/xntrik/hcltm/blob/main/examples/tm3.hcl). We also have the MITRE ATT&CK Controls (https://attack.mitre.org/mitigations/enterprise/) here (https://github.com/xntrik/hcltm/blob/main/examples/MITRE_ATTACK_controls.hcl). To see a full description of the spec, see here (https://github.com/xntrik/hcltm/blob/main/spec.hcl) or run: hcltm generate boilerplate hcltm will also process JSON files, but the only caveat is that import modules and variables won't work. You can see examples/tm1.json (https://github.com/xntrik/hcltm/blob/main/examples/tm1.json) as an example. Why HCL? HCL is the primary configuration language used in the products by HashiCorp, in-particularly, Terraform (https://www.terraform.io/) - their open-source Infrastructure-as-Code software. I worked at HashiCorp for a while and the language really grew on me, plus, if DevOps and Software engineers are using the language, then simplifying how they document threat models aligns with hcltm's goals. You can use hcltm with JSON, but you lose some of the features. For more, see the examples/ (https://github.com/xntrik/hcltm/blob/main/examples) folder. Why not just document them in MD? I liked the idea of using a format that could be programmatically interacted with. Kudos and References One of the features of hcltm is the automatic generation of data flow diagrams (https://github.com/xntrik/hcltm#data-flow-diagram) from HCL files. This leverages the go-dfd (https://github.com/marqeta/go-dfd) package by Marqeta and Blake Hitchcock (https://github.com/rbhitchcock). Definitely check out their blog post on Threat models at the speed of DevOps (https://community.marqeta.com/t5/engineering-blogs/threat-models-at-the-speed-of-devops/ba-p/40). Additionally I'd like to extend thanks to Jamie Finnigan (https://twitter.com/chair6) and Talha Tariq (https://twitter.com/0xtbt) at HashiCorp for allowing me to continue working on this open-source tool even after I'd finished up with HashiCorp. hcltm cli Installation Download the latest version from releases (https://github.com/xntrik/hcltm/releases) and move the hcltm binary into your PATH. Install with Homebrew The following will add a local tap, and install hcltm with Homebrew (https://brew.sh/) brew install xntrik/repo/hcltm Run with Docker docker run --rm -it xntrik/hcltm Run with GitHub Actions hcltm can be integrated directly into your GitHub repos with https://github.com/xntrik/hcltm-action. This is one of the ideal methods to manage your threat models, and helps meet the goal of integrating into your version control systems. Building from Source Clone this repository. Change into the directory, hcltm make bootstrap make dev For further help on contributing to hcltm please see the CHANGELOG.md (https://github.com/xntrik/hcltm/blob/main/CHANGELOG.md). Usage For help on any subcommands use the -h flag. [] Available commands are: dashboard Generate markdown files from existing HCL threatmodel file(s) dfd Generate Data Flow Diagram PNG files from existing HCL threatmodel file(s) generate Generate an HCL Threat Model list List Threatmodels found in HCL file(s) validate Validate existing HCL Threatmodel file(s) view View existing HCL Threatmodel file(s) ">$ hcltm
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - xntrik/hcltm: Documenting your Threat Models with HCL
Documenting your Threat Models with HCL. Contribute to xntrik/hcltm development by creating an account on GitHub.
Usage: hcltm [--version] [--help] []
Available commands are:
dashboard Generate markdown files from existing HCL threatmodel file(s)
dfd Generate Data Flow Diagram PNG files from existing HCL threatmodel file(s)
generate Generate an HCL Threat Model
list List Threatmodels found in HCL file(s)
validate Validate existing HCL Threatmodel file(s)
view View existing HCL Threatmodel file(s)
Config file Most of the hcltm commands have a -config flag that allows you to specify a config.hcl file. HCL within this file may be used to overwrite some of hcltm's default attributes. These are listed below: Initiative Sizes - defaults to "Undefined", "Small", "Medium", "Large" Default Initiative Size - defaults to "Undefined Information Classifications - defaults to "Restricted", "Confidential", "Public" Default Information Classification - defaults to "Confidential" Impact Types - defaults to "Confidentiality", "Integrity", "Availability" STRIDE Elements - defaults to "Spoofing", "Tampering", "Info Disclosure", "Denial Of Service", "Elevation Of Privilege" Uptime Dependency Classifications - defaults to "none", "degraded", "hard", "operational" Default Uptime Depency Classification - defaults to "none" For example: initiative_sizes = ["S", "M", "L"]
default_initiative_size = "M"
info_classifications = ["1", "2"]
default_info_classification = "1"
impact_types = ["big", "small"]
strides = ["S", "T"]
uptime_dep_classifications = ["N", "D"]
default_uptime_dep_classification = "N" If you modify these attributes, you'll need to remember to provide the config file for other operations, as this may impact validation or dashboard creation. List and View The hcltm list and hcltm view commands can be used to list and view data from hcltm spec HCL files. $ hcltm list examples/*
# File Threatmodel Author
1 examples/tm1.hcl Tower of London @xntrik
2 examples/tm1.hcl Fort Knox @xntrik
3 examples/tm2.hcl Modelly model @xntrik Validate The hcltm validate command is used to validate a hcltm spec HCL file. $ hcltm validate examples/*
Validated 3 threatmodels in 3 files Generate The hcltm generate command is used to either output a generic boilerplate hcltm spec HCL file, or, interactively ask the user questions to then output a hcltm spec HCL file. Generate Interactive See the following example of: hcltm generate interactive
___________________________
@hacking_Attack
@Hacking_Video
Available commands are:
dashboard Generate markdown files from existing HCL threatmodel file(s)
dfd Generate Data Flow Diagram PNG files from existing HCL threatmodel file(s)
generate Generate an HCL Threat Model
list List Threatmodels found in HCL file(s)
validate Validate existing HCL Threatmodel file(s)
view View existing HCL Threatmodel file(s)
Config file Most of the hcltm commands have a -config flag that allows you to specify a config.hcl file. HCL within this file may be used to overwrite some of hcltm's default attributes. These are listed below: Initiative Sizes - defaults to "Undefined", "Small", "Medium", "Large" Default Initiative Size - defaults to "Undefined Information Classifications - defaults to "Restricted", "Confidential", "Public" Default Information Classification - defaults to "Confidential" Impact Types - defaults to "Confidentiality", "Integrity", "Availability" STRIDE Elements - defaults to "Spoofing", "Tampering", "Info Disclosure", "Denial Of Service", "Elevation Of Privilege" Uptime Dependency Classifications - defaults to "none", "degraded", "hard", "operational" Default Uptime Depency Classification - defaults to "none" For example: initiative_sizes = ["S", "M", "L"]
default_initiative_size = "M"
info_classifications = ["1", "2"]
default_info_classification = "1"
impact_types = ["big", "small"]
strides = ["S", "T"]
uptime_dep_classifications = ["N", "D"]
default_uptime_dep_classification = "N" If you modify these attributes, you'll need to remember to provide the config file for other operations, as this may impact validation or dashboard creation. List and View The hcltm list and hcltm view commands can be used to list and view data from hcltm spec HCL files. $ hcltm list examples/*
# File Threatmodel Author
1 examples/tm1.hcl Tower of London @xntrik
2 examples/tm1.hcl Fort Knox @xntrik
3 examples/tm2.hcl Modelly model @xntrik Validate The hcltm validate command is used to validate a hcltm spec HCL file. $ hcltm validate examples/*
Validated 3 threatmodels in 3 files Generate The hcltm generate command is used to either output a generic boilerplate hcltm spec HCL file, or, interactively ask the user questions to then output a hcltm spec HCL file. Generate Interactive See the following example of: hcltm generate interactive
___________________________
@hacking_Attack
@Hacking_Video