How do you make writing reports more pleasant?
https://www.reddit.com/r/Pentesting/comments/uqyer1/how_do_you_make_writing_reports_more_pleasant/
Hi, I've been writing reports for a while now but I'm struggling big time. Our methodology is pretty complicated and I want to automate it. We write the vulnerabilities with Mark Down, render with pandoc into a word file, then take it and merge it with the word template. Then validate and make corrections and export it to PDF. The good part with is that we don't have to fix styles when writing it, but I'm sure there must be a better way to do it. I've researched few options but can't find a good one. I'm thinking about creating web app with a DB containing all the vulnerabilities that were used in the reports, so it will be easier to import them. Some of them for example for missing headers will only have an option to import an image with the proof of concept with previously prepared static text containing information. In other vulnerabilities that need additional writing there will be placeholders. Somehow I think my idea will take way too long, any ideas or tips will be highly appreciated. Ps. I've notice taking trashy notes slows down additionally my Reporting process. Can you suggest me on editors like one note(including images) but which you can use on both Windows and Linux? Thanks! submitted by /u/tryingtoworkatm (https://www.reddit.com/user/tryingtoworkatm)
[link] (https://www.reddit.com/r/Pentesting/comments/uqyer1/how_do_you_make_writing_reports_more_pleasant/) [comments] (https://www.reddit.com/r/Pentesting/comments/uqyer1/how_do_you_make_writing_reports_more_pleasant/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/uqyer1/how_do_you_make_writing_reports_more_pleasant/
Hi, I've been writing reports for a while now but I'm struggling big time. Our methodology is pretty complicated and I want to automate it. We write the vulnerabilities with Mark Down, render with pandoc into a word file, then take it and merge it with the word template. Then validate and make corrections and export it to PDF. The good part with is that we don't have to fix styles when writing it, but I'm sure there must be a better way to do it. I've researched few options but can't find a good one. I'm thinking about creating web app with a DB containing all the vulnerabilities that were used in the reports, so it will be easier to import them. Some of them for example for missing headers will only have an option to import an image with the proof of concept with previously prepared static text containing information. In other vulnerabilities that need additional writing there will be placeholders. Somehow I think my idea will take way too long, any ideas or tips will be highly appreciated. Ps. I've notice taking trashy notes slows down additionally my Reporting process. Can you suggest me on editors like one note(including images) but which you can use on both Windows and Linux? Thanks! submitted by /u/tryingtoworkatm (https://www.reddit.com/user/tryingtoworkatm)
[link] (https://www.reddit.com/r/Pentesting/comments/uqyer1/how_do_you_make_writing_reports_more_pleasant/) [comments] (https://www.reddit.com/r/Pentesting/comments/uqyer1/how_do_you_make_writing_reports_more_pleasant/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
How do you make writing reports more pleasant?
Hi, I've been writing reports for a while now but I'm struggling big time. Our methodology is pretty complicated and I want to automate it. We...
Bug Bounty от Meta Pool
https://medium.com/meta-pool-russia/bug-bounty-%D0%BE%D1%82-meta-pool-c6dd3dcc405e?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/meta-pool-russia/bug-bounty-%D0%BE%D1%82-meta-pool-c6dd3dcc405e?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bug Bounty от Meta Pool
Meta Pool опубликовал в своем gitBook программу Bug Bounty, в которой может участвовать любой, кто обнаружит ошибку или уязвимость в…
Meta Pool опубликовал в своем gitBook программу Bug Bounty, в которой может участвовать любой, кто обнаружит ошибку или уязвимость в…Continue reading on Meta Pool Russia » (https://medium.com/meta-pool-russia/bug-bounty-%D0%BE%D1%82-meta-pool-c6dd3dcc405e?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bug Bounty от Meta Pool
Meta Pool опубликовал в своем gitBook программу Bug Bounty, в которой может участвовать любой, кто обнаружит ошибку или уязвимость в…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Critical Zyxel Firewall Bug Under Active Attack After PoC Exploit Debut
Just one day after disclosure, cyberattackers are actively going after the command-injection/code-execution vulnerability in Zyxel's gear.
___________________________
@hacking_Attack
@Hacking_Video
Critical Zyxel Firewall Bug Under Active Attack After PoC Exploit Debut
Just one day after disclosure, cyberattackers are actively going after the command-injection/code-execution vulnerability in Zyxel's gear.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Critical Zyxel Firewall Bug Under Active Attack After PoC Exploit Debut
Just one day after disclosure, cyberattackers are actively going after the command-injection/code-execution vulnerability in Zyxel's gear.
Free Microsoft Certification Exam with Microsoft Build Cloud Skills Challenge
https://www.reddit.com/r/redteamsec/comments/ur0efp/free_microsoft_certification_exam_with_microsoft/
submitted by /u/cybersocdm (https://www.reddit.com/user/cybersocdm)
[link] (https://cybersochacklabproject.blogspot.com/2022/05/free-microsoft-certification-exam-with.html) [comments] (https://www.reddit.com/r/redteamsec/comments/ur0efp/free_microsoft_certification_exam_with_microsoft/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/ur0efp/free_microsoft_certification_exam_with_microsoft/
submitted by /u/cybersocdm (https://www.reddit.com/user/cybersocdm)
[link] (https://cybersochacklabproject.blogspot.com/2022/05/free-microsoft-certification-exam-with.html) [comments] (https://www.reddit.com/r/redteamsec/comments/ur0efp/free_microsoft_certification_exam_with_microsoft/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
r/redteamsec on Reddit: Free Microsoft Certification Exam with Microsoft Build Cloud Skills Challenge
Posted by u/cybersocdm - 1 vote and no comments
API Security Offence and Defence: Introduction to API
https://www.reddit.com/r/redteamsec/comments/ur0foj/api_security_offence_and_defence_introduction_to/
submitted by /u/cybersocdm (https://www.reddit.com/user/cybersocdm)
[link] (https://youtube.com/watch?v=5EMkuG7QMOM&feature=share) [comments] (https://www.reddit.com/r/redteamsec/comments/ur0foj/api_security_offence_and_defence_introduction_to/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/ur0foj/api_security_offence_and_defence_introduction_to/
submitted by /u/cybersocdm (https://www.reddit.com/user/cybersocdm)
[link] (https://youtube.com/watch?v=5EMkuG7QMOM&feature=share) [comments] (https://www.reddit.com/r/redteamsec/comments/ur0foj/api_security_offence_and_defence_introduction_to/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
r/redteamsec on Reddit: API Security Offence and Defence: Introduction to API
Posted by u/cybersocdm - 2 votes and no comments
Open Source Intelligence (OSINT)
https://www.reddit.com/r/redteamsec/comments/ur0hgh/open_source_intelligence_osint/
submitted by /u/cybersocdm (https://www.reddit.com/user/cybersocdm)
[link] (https://youtube.com/playlist?list=PLHveG9B0-uTW7w0iWIrToTvthlN7eIrVU) [comments] (https://www.reddit.com/r/redteamsec/comments/ur0hgh/open_source_intelligence_osint/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/ur0hgh/open_source_intelligence_osint/
submitted by /u/cybersocdm (https://www.reddit.com/user/cybersocdm)
[link] (https://youtube.com/playlist?list=PLHveG9B0-uTW7w0iWIrToTvthlN7eIrVU) [comments] (https://www.reddit.com/r/redteamsec/comments/ur0hgh/open_source_intelligence_osint/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
r/redteamsec on Reddit: Open Source Intelligence (OSINT)
Posted by u/cybersocdm - 3 votes and no comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
“Hacking Kubernetes: Threat Driven Analysis and Defense” Chapter 1 Notes
https://cdn-images-1.medium.com/max/1125/1*3OHJQiOg6U-VX7IXdS0k7w.jpeg
Prefer videos over articles? Check out the video book review here
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
“Hacking Kubernetes: Threat Driven Analysis and Defense” Chapter 1 Notes
https://cdn-images-1.medium.com/max/1125/1*3OHJQiOg6U-VX7IXdS0k7w.jpeg
Prefer videos over articles? Check out the video book review here
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
“Hacking Kubernetes: Threat Driven Analysis and Defense” Chapter 1 Notes
Prefer videos over articles? Check out the video book review here
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Europa acuerda adoptar la nueva directiva NIS2 destinada a fortalecer la ciberseguridad
https://cdn-images-1.medium.com/max/997/0*hKGff6WbCtFtpjMU
PUBLICADO EN 16 MAYO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Europa acuerda adoptar la nueva directiva NIS2 destinada a fortalecer la ciberseguridad
https://cdn-images-1.medium.com/max/997/0*hKGff6WbCtFtpjMU
PUBLICADO EN 16 MAYO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Europa acuerda adoptar la nueva directiva NIS2 destinada a fortalecer la ciberseguridad
PUBLICADO EN 16 MAYO, 2022POR EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Zyxel lanza parche para una vulnerabilidad crítica de inyección de comandos en su Firewall OS
https://cdn-images-1.medium.com/max/837/0*b25xLmOztzGsjTrr
PUBLICADO EN 13 MAYO, 2022 POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Zyxel lanza parche para una vulnerabilidad crítica de inyección de comandos en su Firewall OS
https://cdn-images-1.medium.com/max/837/0*b25xLmOztzGsjTrr
PUBLICADO EN 13 MAYO, 2022 POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Zyxel lanza parche para una vulnerabilidad crítica de inyección de comandos en su Firewall OS
PUBLICADO EN 13 MAYO, 2022 POR EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Cyber Mentors' Course problem| nmap not working for some reason?
So I've been following The Cyber Mentor's course on Practicle Ethical Hacking and got to the part where i set up kioptrix on my pc and scan it.but when i use nmap from my linux vm
cmd - nmap -T4 -p- -A https://nmap.org ) at 2022-05-15 18:25 EDT
Nmap scan report for 192.168.57.3 Host is up (0.000245 latency).
All 65535 scanned ports on https://nmap.org/submit/.
Nmap done: 1 IP address (1 host up) scanned in 8.06 seconds
So I couldn't follow along the course.I tried modifying the cmd to this
nmap -T4 -p 22,80,111,139,443 -A https://nmap.org ) at 2022-05-15 18:35 EDT
Nmap scan report for 192.168.57.3 Host is up (0.000315 latency).
PORT STATE SERVICE VERSION
22/tcp filtered ssh
80/tcp filtered http
111/tcp filtered rpcbind
139/tcp filtered netbios-ssn
443/tcp filtered https
MAC Address: 08:00:27:68:A3:3F (Oracle VirtualBox virtual NIC)
Too many fingerprints match this host to give specific os details
Network Distance: 1 hop
TRACEROUTE
HOP RTT ADDRESS
1 0.31 ms 192.168.57.3
os and Service detection performed. Please report any incorrect results at
https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 4.73 seconds
I couldn't find anything on why my results are different than TCM's results and decided use reddit.
so please can anyone point out whats I'm doing wrong?
submitted by /u/GamerUnknown_123
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Cyber Mentors' Course problem| nmap not working for some reason?
So I've been following The Cyber Mentor's course on Practicle Ethical Hacking and got to the part where i set up kioptrix on my pc and scan it.but when i use nmap from my linux vm
cmd - nmap -T4 -p- -A https://nmap.org ) at 2022-05-15 18:25 EDT
Nmap scan report for 192.168.57.3 Host is up (0.000245 latency).
All 65535 scanned ports on https://nmap.org/submit/.
Nmap done: 1 IP address (1 host up) scanned in 8.06 seconds
So I couldn't follow along the course.I tried modifying the cmd to this
nmap -T4 -p 22,80,111,139,443 -A https://nmap.org ) at 2022-05-15 18:35 EDT
Nmap scan report for 192.168.57.3 Host is up (0.000315 latency).
PORT STATE SERVICE VERSION
22/tcp filtered ssh
80/tcp filtered http
111/tcp filtered rpcbind
139/tcp filtered netbios-ssn
443/tcp filtered https
MAC Address: 08:00:27:68:A3:3F (Oracle VirtualBox virtual NIC)
Too many fingerprints match this host to give specific os details
Network Distance: 1 hop
TRACEROUTE
HOP RTT ADDRESS
1 0.31 ms 192.168.57.3
os and Service detection performed. Please report any incorrect results at
https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 4.73 seconds
I couldn't find anything on why my results are different than TCM's results and decided use reddit.
so please can anyone point out whats I'm doing wrong?
submitted by /u/GamerUnknown_123
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
Cyber Mentors' Course problem| nmap not working for some reason? : r/hacking
2.6M subscribers in the hacking community. A subreddit dedicated to hacking and hackers. Constructive collaboration and learning about exploits…
hacking: security in practice
I got someone's IP address, what can I do with it
Hi everyone, I got an email notification mentioning that someone from Colombia tried to log into my email (but they failed) long story short I have their IP address, is there something I can do with it? find their exact location or things like that?
submitted by /u/aquichillin_
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
I got someone's IP address, what can I do with it
Hi everyone, I got an email notification mentioning that someone from Colombia tried to log into my email (but they failed) long story short I have their IP address, is there something I can do with it? find their exact location or things like that?
submitted by /u/aquichillin_
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
I got someone's IP address, what can I do with it
Hi everyone, I got an email notification mentioning that someone from Colombia tried to log into my email (but they failed) long story short I...