hacking: security in practice
M1 chip for hacking and cybersecurity stuffs
Guys i’m in the beggining of my cybersec journey, actually learning to code in C and assembly (yes, i’m in very the beggining). But i’m thinking of getting a macbook pro with m1 pro, if i bought that and the parallels software, do you guys think that i will be limited in any way?
submitted by /u/pedrinhofelicio
[link] [comments]
M1 chip for hacking and cybersecurity stuffs
Guys i’m in the beggining of my cybersec journey, actually learning to code in C and assembly (yes, i’m in very the beggining). But i’m thinking of getting a macbook pro with m1 pro, if i bought that and the parallels software, do you guys think that i will be limited in any way?
submitted by /u/pedrinhofelicio
[link] [comments]
reddit
M1 chip for hacking and cybersecurity stuffs
Guys i’m in the beggining of my cybersec journey, actually learning to code in C and assembly (yes, i’m in very the beggining). But i’m...
hacking: security in practice
Security concern
If I was at a Starbucks doing some work on a Mac and Somone knew my device name, maybe they opened their airpods and it told them. Could Somone use ssh and the alpine password to get into my laptop even if remote login was turned off??
submitted by /u/Careless-Rich9963
[link] [comments]
Security concern
If I was at a Starbucks doing some work on a Mac and Somone knew my device name, maybe they opened their airpods and it told them. Could Somone use ssh and the alpine password to get into my laptop even if remote login was turned off??
submitted by /u/Careless-Rich9963
[link] [comments]
reddit
Security concern
If I was at a Starbucks doing some work on a Mac and Somone knew my device name, maybe they opened their airpods and it told them. Could Somone...
hacking: security in practice
Does anyone know what ever happened to UGNAZI leader JoshTheGod?
So, I found an article saying that JoshTheGod was actually arrested on a murder back in 2018. (Link on botom). I'm really interested in if anyone has anymore information on this, I cant find anything else on it.
https://www.buzzfeednews.com/article/josephbernstein/tomi-masters-murder-plead-not-guilty
IF you care, why I'm interested, isn't fully relevant to the point of thread:
I actually ran into Cosmothegod two times, (Joshs codefendent )when they were doing there thing through mutual parties. They had some 'business' contact with them, but mostly called them skript kiddies that got a little too good at being annoying pricks. They were well connected with people for fraud and slaves for botnets.
When I was in convo with Cosmo, the only 'hacking' discussed was an email provider complete security failure allowing access to emails through easy social engineering, with just the bare minimum of info from already leaked DB.
So, I can't judge him for myself, --But they both seem like complete idiots if you read the offical DOJ Criminal Complaint on them. JoshTheGod was taken down trying to buy stolen debit cards with pin, in person from someone he met online, while knowing he was a huge target for the FBI.
All this being said, the chaos these kids (at the time) with such simple techniques - some not even really 'hacking' at all, is just amazing to me. Times were a bit different then,
submitted by /u/isn0w
[link] [comments]
Does anyone know what ever happened to UGNAZI leader JoshTheGod?
So, I found an article saying that JoshTheGod was actually arrested on a murder back in 2018. (Link on botom). I'm really interested in if anyone has anymore information on this, I cant find anything else on it.
https://www.buzzfeednews.com/article/josephbernstein/tomi-masters-murder-plead-not-guilty
IF you care, why I'm interested, isn't fully relevant to the point of thread:
I actually ran into Cosmothegod two times, (Joshs codefendent )when they were doing there thing through mutual parties. They had some 'business' contact with them, but mostly called them skript kiddies that got a little too good at being annoying pricks. They were well connected with people for fraud and slaves for botnets.
When I was in convo with Cosmo, the only 'hacking' discussed was an email provider complete security failure allowing access to emails through easy social engineering, with just the bare minimum of info from already leaked DB.
So, I can't judge him for myself, --But they both seem like complete idiots if you read the offical DOJ Criminal Complaint on them. JoshTheGod was taken down trying to buy stolen debit cards with pin, in person from someone he met online, while knowing he was a huge target for the FBI.
All this being said, the chaos these kids (at the time) with such simple techniques - some not even really 'hacking' at all, is just amazing to me. Times were a bit different then,
submitted by /u/isn0w
[link] [comments]
reddit
Does anyone know what ever happened to UGNAZI leader JoshTheGod?
So, I found an article saying that JoshTheGod was actually arrested on a murder back in 2018. (Link on botom). I'm really interested in if...
IDOR (Insecure Direct Object References) p-store.net
https://baguslindu.medium.com/idor-insecure-direct-object-references-p-store-net-2c8842053d11?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://baguslindu.medium.com/idor-insecure-direct-object-references-p-store-net-2c8842053d11?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
IDOR (Insecure Direct Object References) p-store.net
Hello nama saya bagus lindu, kali ini saya menemukan kerentanan pada p-store.net, seperti yg kita tahu p-store.net adalah sebuah…
Hello nama saya bagus lindu, kali ini saya menemukan kerentanan pada p-store.net, seperti yg kita tahu p-store.net adalah sebuah…Continue reading on Medium » (https://baguslindu.medium.com/idor-insecure-direct-object-references-p-store-net-2c8842053d11?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
IDOR (Insecure Direct Object References) p-store.net
Hello nama saya bagus lindu, kali ini saya menemukan kerentanan pada p-store.net, seperti yg kita tahu p-store.net adalah sebuah…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Bussines logic error on p-store.net
https://cdn-images-1.medium.com/max/779/1*uTsxR7r8R3A1MhEFN-r3Iw.png
Hello nama saya bagus lindu, kali ini saya menemukan kerentanan pada p-store.net, seperti yg kita tahu p-store.net adalah sebuah…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Bussines logic error on p-store.net
https://cdn-images-1.medium.com/max/779/1*uTsxR7r8R3A1MhEFN-r3Iw.png
Hello nama saya bagus lindu, kali ini saya menemukan kerentanan pada p-store.net, seperti yg kita tahu p-store.net adalah sebuah…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
IDOR (Insecure Direct Object References) p-store.net
Hello nama saya bagus lindu, kali ini saya menemukan kerentanan pada p-store.net, seperti yg kita tahu p-store.net adalah sebuah…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Tryhackme — Confidential
https://cdn-images-1.medium.com/max/600/1*53SqTI9LVA4xV0ifeGoGXQ.png
Okke, kali ini kita akan mengerjakan salah satu room di Tryhackme, yaitu room Confidential karangan bang cmnatic.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Tryhackme — Confidential
https://cdn-images-1.medium.com/max/600/1*53SqTI9LVA4xV0ifeGoGXQ.png
Okke, kali ini kita akan mengerjakan salah satu room di Tryhackme, yaitu room Confidential karangan bang cmnatic.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Tryhackme — Confidential (Bahasa Indonesia)
Okke, kali ini kita akan mengerjakan salah satu room di Tryhackme, yaitu room Confidential karangan bang cmnatic.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TRY HACK ME — Intermediate Nmap
https://cdn-images-1.medium.com/max/1267/1*M5J3T6ENiWSmYCxW8V-yag.png
Hello, today we are going to solve a box on tryhackme intermediate Nmap
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TRY HACK ME — Intermediate Nmap
https://cdn-images-1.medium.com/max/1267/1*M5J3T6ENiWSmYCxW8V-yag.png
Hello, today we are going to solve a box on tryhackme intermediate Nmap
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TRY HACK ME — Intermediate Nmap
Hello, today we are going to solve a box on tryhackme intermediate Nmap
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Best 4 Cool New Apps | top 4 android apps | best android apps 2022 | upload by Allaboutsubha
https://cdn-images-1.medium.com/max/600/0*kWO5ja5niPHR-ftx
Hello friends, I’m subha and you are watching the Bengali tech youtube channel allaboutsubha.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Best 4 Cool New Apps | top 4 android apps | best android apps 2022 | upload by Allaboutsubha
https://cdn-images-1.medium.com/max/600/0*kWO5ja5niPHR-ftx
Hello friends, I’m subha and you are watching the Bengali tech youtube channel allaboutsubha.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Best 4 Cool New Apps | top 4 android apps | best android apps 2022 | upload by Allaboutsubha
Hello friends, I’m subha and you are watching the Bengali tech youtube channel allaboutsubha.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
PARAMETER Injection Hack
https://cdn-images-1.medium.com/max/1200/0*rHTvf1UEE-Y2KeHp
Why your perfectly checked input is now tainted. And how to FIX IT.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
PARAMETER Injection Hack
https://cdn-images-1.medium.com/max/1200/0*rHTvf1UEE-Y2KeHp
Why your perfectly checked input is now tainted. And how to FIX IT.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
PARAMETER Injection Hack
Why your perfectly checked input is now tainted. And how to FIX IT.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hacking: Manajemen Risiko
https://cdn-images-1.medium.com/max/600/0*iyE0UFd2m0-0p1Gs
Dibuat Oleh : Anggawan Ridho, Faishal Arrafi, Thoriq Kurnia, Salsa Amalia, dan Abim Mayu
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hacking: Manajemen Risiko
https://cdn-images-1.medium.com/max/600/0*iyE0UFd2m0-0p1Gs
Dibuat Oleh : Anggawan Ridho, Faishal Arrafi, Thoriq Kurnia, Salsa Amalia, dan Abim Mayu
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hacking: Manajemen Risiko
Dibuat Oleh : Anggawan Ridho, Faishal Arrafi, Thoriq Kurnia, Salsa Amalia, dan Abim Mayu
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
SecureCodeBox : Automate A Bunch Of Security-Testing Tools Out Of The Box
secureCodeBox is a kubernetes based, modularized toolchain for continuous security scans of your software project. Its goal is to orchestrate and easily automate a bunch of security-testing tools out of the box. Purpose of this ProjectThe typical way to ensure application security is to hire a security specialist (aka penetration tester) at some point in your project to check the application for security bugs and vulnerabilities. Usually, this check is done at a later stage of the project and has two major drawbacks:
1. Nowadays, a lot of projects do continuous delivery, which means the developers deploy new versions multiple times each day. The penetration tester is only able to check a single snapshot, but some further commits could introduce new security issues. To ensure ongoing application security, the penetration tester should also continuously test the application. Unfortunately, such an approach is rarely financially feasible.
2. Due to a typically time boxed analysis, the penetration tester has to focus on trivial security issues (low-hanging fruit) and therefore will probably not address the serious, non-obvious ones.
With the secureCodeBox we provide a toolchain for continuous scanning of applications to find the low-hanging fruit issues early in the development process and free the resources of the penetration tester to concentrate on the major security issues.
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiqudVeTv9c5jH7qrTERaoVPxex1LlOOtZx9qqX7AsmGM3nVz07aifVTlS-AKQ1te59W9-4XdG4o9_IzYWWlbA1rXqDockfDqlkOrUY7LGVhFDee1_ADCzanDasD5nqUIpLBED_45iQhe8WSmydFmacClAxwXEWq_8Ccjp2NVKIGOtUqFNmVAjQCxZd/s2525/macbook_kibana.jpg
The purpose of secureCodeBox is not to replace the penetration testers or make them obsolete. We strongly recommend to run extensive tests by experienced penetration testers on all your applications.
Important note: The secureCodeBox is no simple one-button-click-solution! You must have a deep understanding of security and how to configure the scanners. Furthermore, an understanding of the scan results and how to interpret them is also necessary.
There is a German article about Security DevOps – Angreifern (immer) einen Schritt voraus in the software engineering journal OBJEKTSpektrum. Architecture Overviewhttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgRXfiOaumuubUISZWdeF-kTsLDl-TqJfdR4BE2Q6o8VqcH0wMY2OCU10YGf6u89WatVntV9iYbb7Ixabcx7eitM5OvUtabsiWEnqML0lKYV8nohjrj9cMPHE8LFbdPQ63l73qivIXdZn6UUZVcN1DQ1b6e-nkaKVdRW3p13zqGzAhnAX9zHYZSEimv/s920/scb-architecture-svg.png UpgradingUpgraded Kubebuilder Version to v3The CRD’s are now using
If you are using a custom deployment you have to change the
Instead of secureCodebox Version 2 example:
image:
image.repository — Container Image to run the scan
repository: owasp/zap2docker-stable
image.tag — defaults to the charts appVersion
tag: null
parserImage:
parserImage.repository — Parser image repository
repository: docker.io/securecodebox/parser-zap
pars[...]
___________________________
@hacking_Attack
@Hacking_Video
SecureCodeBox : Automate A Bunch Of Security-Testing Tools Out Of The Box
secureCodeBox is a kubernetes based, modularized toolchain for continuous security scans of your software project. Its goal is to orchestrate and easily automate a bunch of security-testing tools out of the box. Purpose of this ProjectThe typical way to ensure application security is to hire a security specialist (aka penetration tester) at some point in your project to check the application for security bugs and vulnerabilities. Usually, this check is done at a later stage of the project and has two major drawbacks:
1. Nowadays, a lot of projects do continuous delivery, which means the developers deploy new versions multiple times each day. The penetration tester is only able to check a single snapshot, but some further commits could introduce new security issues. To ensure ongoing application security, the penetration tester should also continuously test the application. Unfortunately, such an approach is rarely financially feasible.
2. Due to a typically time boxed analysis, the penetration tester has to focus on trivial security issues (low-hanging fruit) and therefore will probably not address the serious, non-obvious ones.
With the secureCodeBox we provide a toolchain for continuous scanning of applications to find the low-hanging fruit issues early in the development process and free the resources of the penetration tester to concentrate on the major security issues.
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiqudVeTv9c5jH7qrTERaoVPxex1LlOOtZx9qqX7AsmGM3nVz07aifVTlS-AKQ1te59W9-4XdG4o9_IzYWWlbA1rXqDockfDqlkOrUY7LGVhFDee1_ADCzanDasD5nqUIpLBED_45iQhe8WSmydFmacClAxwXEWq_8Ccjp2NVKIGOtUqFNmVAjQCxZd/s2525/macbook_kibana.jpg
The purpose of secureCodeBox is not to replace the penetration testers or make them obsolete. We strongly recommend to run extensive tests by experienced penetration testers on all your applications.
Important note: The secureCodeBox is no simple one-button-click-solution! You must have a deep understanding of security and how to configure the scanners. Furthermore, an understanding of the scan results and how to interpret them is also necessary.
There is a German article about Security DevOps – Angreifern (immer) einen Schritt voraus in the software engineering journal OBJEKTSpektrum. Architecture Overviewhttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgRXfiOaumuubUISZWdeF-kTsLDl-TqJfdR4BE2Q6o8VqcH0wMY2OCU10YGf6u89WatVntV9iYbb7Ixabcx7eitM5OvUtabsiWEnqML0lKYV8nohjrj9cMPHE8LFbdPQ63l73qivIXdZn6UUZVcN1DQ1b6e-nkaKVdRW3p13zqGzAhnAX9zHYZSEimv/s920/scb-architecture-svg.png UpgradingUpgraded Kubebuilder Version to v3The CRD’s are now using
apiextensions.k8s.io/v1instead of apiextensions.k8s.io/v1beta1which requries at least Kubernetes Version 1.16 or higher. The Operator now uses the new kubebuilder v3 command line flag for enabling leader election and setting the metrics port. If you are using the official secureCodeBox Helm Charts for your deployment this has been updated automatically.If you are using a custom deployment you have to change the
--enable-leader-electionflag to --leader-electand --metrics-addrto --metrics-bind-address. For more context see: https://book.kubebuilder.io/migration/v2vsv3.html#tldr-of-the-new-gov3-plugin Restructured the secureCodeBox HelmCharts to introduce more consistency in HelmChart ValuesThe secureCodeBox HelmCharts for hooks and scanners are following a new structure for all HelmChart Values:Instead of secureCodebox Version 2 example:
image:
image.repository — Container Image to run the scan
repository: owasp/zap2docker-stable
image.tag — defaults to the charts appVersion
tag: null
parserImage:
parserImage.repository — Parser image repository
repository: docker.io/securecodebox/parser-zap
pars[...]
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
SecureCodeBox : Automate A Bunch Of Security-Testing Tools
secureCodeBox is a kubernetes based, modularized toolchain for continuous security scans of your software project.
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials SecureCodeBox : Automate A Bunch Of Security-Testing Tools Out Of The Box secureCodeBox is a kubernetes based, modularized toolchain for continuous security scans of your software project. Its goal is to orchestrate and easily automate…
erImage.tag — Parser image tag
@default — defaults to the charts version
tag: null
parseJob:
parseJob.ttlSecondsAfterFinished — seconds after which the kubernetes job for the parser will be deleted. Requires the Kubernetes TTLAfterFinished controller: https://kubernetes.io/docs/concepts/workloads/controllers/ttlafterfinished/
ttlSecondsAfterFinished: null
scannerJob:
scannerJob.ttlSecondsAfterFinished — seconds after which the kubernetes job for the scanner will be deleted. Requires the Kubernetes TTLAfterFinished controller: https://kubernetes.io/docs/concepts/workloads/controllers/ttlafterfinished/
ttlSecondsAfterFinished: null
scannerJob.backoffLimit — There are situations where you want to fail a scan Job after some amount of retries due to a logical error in configuration etc. To do so, set backoffLimit to specify the number of retries before considering a scan Job as failed. (see: https://kubernetes.io/docs/concepts/workloads/controllers/job/#pod-backoff-failure-policy)
@default — 3
backoffLimit: 3 Added scanner.appendName to chart valuesUsing {{ .Release.name }} in the
The nmap exception was originally introduced to make it possible configure yourself an
This idea for extending the name of a scanType is now in Version 3 general available for all HelmCharts.
The solution was to add a new HelmChart Value
Hook images however were named inconsistently (some prefixed with
Please beware of this if you are referencing some of our hook images in your own HelmCharts or custom implementations. Renamed
Find relevant namespaces
kubectl get serviceaccounts –all-namespaces | grep lurcher
Delete role, role binding and service account for the specific namespace
kubectl –namespace delete serviceaccount lurcher
kubectl –namespace delete rolebindings lurcher
kubectl –namespace delete role lurcher Removed Hook Teams WebhookWe implemented a more general notification hook which can be used to notify different systems like MS Teams and Slack and also Email based in a more flexible way with custom message templates. With[...]
___________________________
@hacking_Attack
@Hacking_Video
@default — defaults to the charts version
tag: null
parseJob:
parseJob.ttlSecondsAfterFinished — seconds after which the kubernetes job for the parser will be deleted. Requires the Kubernetes TTLAfterFinished controller: https://kubernetes.io/docs/concepts/workloads/controllers/ttlafterfinished/
ttlSecondsAfterFinished: null
scannerJob:
scannerJob.ttlSecondsAfterFinished — seconds after which the kubernetes job for the scanner will be deleted. Requires the Kubernetes TTLAfterFinished controller: https://kubernetes.io/docs/concepts/workloads/controllers/ttlafterfinished/
ttlSecondsAfterFinished: null
scannerJob.backoffLimit — There are situations where you want to fail a scan Job after some amount of retries due to a logical error in configuration etc. To do so, set backoffLimit to specify the number of retries before considering a scan Job as failed. (see: https://kubernetes.io/docs/concepts/workloads/controllers/job/#pod-backoff-failure-policy)
@default — 3
backoffLimit: 3 Added scanner.appendName to chart valuesUsing {{ .Release.name }} in the
nmapHelmChart Name for scanTypescauses issues when using this chart as a dependency of another chart. All scanners HelmCharts already used a fixed name for the scanTypethey introduce, with one exception: the nmapscanner HelmChart.The nmap exception was originally introduced to make it possible configure yourself an
nmap-privilidgedscanType, which is capable of running operating system scans which requires some higher privileges: https://www.securecodebox.io/docs/scanners/nmap#operating-system-scansThis idea for extending the name of a scanType is now in Version 3 general available for all HelmCharts.
The solution was to add a new HelmChart Value
scanner.appendNamefor appending a suffix to the already defined scanType name. Example: the scanner.nameAppend: -privilegedfor the ZAP scanner will create zap-baseline-scan-privileged, zap-api-scan-privileged, zap-full-scan-privilegedas new scanTypes instead of zap-baseline-scan, zap-api-scan, zap-full-scan. Renamed demo-apps to demo-targetsThe provided vulnerable demos are renamed from demo-appsto demo-targets, this includes the namespace and the folder of the helmcharts. Renamed the hook declarative-subsequent-scans to cascading-scansThe hook responsible for cascading scans is renamed from declarative-subsequent-scansto cascading-scans. Fixed Name Consistency In Docker Images / RepositoriesFor the docker images for scanners and parsers we already had the naming convention of prefixing these images with scanner-or parser-.Hook images however were named inconsistently (some prefixed with
hook-some unprefixed). To introduce more consistency we renamed all hook images and prefix them with hook-like we did with parser and scanner images.Please beware of this if you are referencing some of our hook images in your own HelmCharts or custom implementations. Renamed
lurcherto lurkerIn the 3.0 release, we corrected the misspelling in lurcher. To remove the remains after upgrade, delete the old service accounts and roles from the namespaces where you have executed scans in the past:Find relevant namespaces
kubectl get serviceaccounts –all-namespaces | grep lurcher
Delete role, role binding and service account for the specific namespace
kubectl –namespace delete serviceaccount lurcher
kubectl –namespace delete rolebindings lurcher
kubectl –namespace delete role lurcher Removed Hook Teams WebhookWe implemented a more general notification hook which can be used to notify different systems like MS Teams and Slack and also Email based in a more flexible way with custom message templates. With[...]
___________________________
@hacking_Attack
@Hacking_Video
Kubernetes
Automatic Cleanup for Finished Jobs
A time-to-live mechanism to clean up old Jobs that have finished execution.