Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to Secure Database From Hackers
https://cdn-images-1.medium.com/max/1280/1*VEdmGrNe7_LrnQPaHPfoPg.jpeg
Lack of security is one of the biggest threats to your data security. A hacker can steal your data, or worse if you don’t have a secure…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to Secure Database From Hackers
https://cdn-images-1.medium.com/max/1280/1*VEdmGrNe7_LrnQPaHPfoPg.jpeg
Lack of security is one of the biggest threats to your data security. A hacker can steal your data, or worse if you don’t have a secure…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to Secure Database From Hackers
Lack of security is one of the biggest threats to your data security. A hacker can steal your data, or worse if you don’t have a secure…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Data exfiltration using Excel
https://cdn-images-1.medium.com/max/624/1*FsqFECjsmnJOZJN49Rfx7g.png
Hi folks, in this article, I’m going to talk about a new data exfiltration technique, which allows to read files on victim’s machine using…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Data exfiltration using Excel
https://cdn-images-1.medium.com/max/624/1*FsqFECjsmnJOZJN49Rfx7g.png
Hi folks, in this article, I’m going to talk about a new data exfiltration technique, which allows to read files on victim’s machine using…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Data exfiltration using Excel
Hi folks, in this article, I’m going to talk about a new data exfiltration technique, which allows to read files on victim’s machine using…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
10 Minute Bug Bounties: OSINT With Google Dorking, Censys, and Shodan
https://cdn-images-1.medium.com/max/640/1*H4O0IcMJ84R7ZraACqap6Q.jpeg
TL;DR- One of the simplest and surprisingly paid bounties out there. This post is great for any bug-hunter who’s just starting out, or…
Continue reading on The Gray Area »
___________________________
@hacking_Attack
@Hacking_Video
10 Minute Bug Bounties: OSINT With Google Dorking, Censys, and Shodan
https://cdn-images-1.medium.com/max/640/1*H4O0IcMJ84R7ZraACqap6Q.jpeg
TL;DR- One of the simplest and surprisingly paid bounties out there. This post is great for any bug-hunter who’s just starting out, or…
Continue reading on The Gray Area »
___________________________
@hacking_Attack
@Hacking_Video
Medium
10 Minute Bug Bounties: OSINT With Google Dorking, Censys, and Shodan
TL;DR- One of the simplest and surprisingly paid bounties out there. This post is great for any bug-hunter who’s just starting out, or…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to build your NO-log VPN Server on AWS cloud for FREE
https://cdn-images-1.medium.com/max/869/1*oTO0zi18v2o020RT_VvHaQ.png
Hello friend, Today I want to show you how to build a VPN server on the AWS cloud. We will also configure it for no logging of data.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to build your NO-log VPN Server on AWS cloud for FREE
https://cdn-images-1.medium.com/max/869/1*oTO0zi18v2o020RT_VvHaQ.png
Hello friend, Today I want to show you how to build a VPN server on the AWS cloud. We will also configure it for no logging of data.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to build your NO-log VPN Server on AWS cloud for FREE
Hello friend, Today I want to show you how to build a VPN server on the AWS cloud. We will also configure it for no logging of data.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Cross-origin resource sharing (CORS) Explanation & Exploitation ☠
https://cdn-images-1.medium.com/max/1024/0*zb0GzPvxSsnwuBOu.png
Hi! My name is Hashar Mujahid and today we will talk about Cross-origin resource sharing (CORS).
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Cross-origin resource sharing (CORS) Explanation & Exploitation ☠
https://cdn-images-1.medium.com/max/1024/0*zb0GzPvxSsnwuBOu.png
Hi! My name is Hashar Mujahid and today we will talk about Cross-origin resource sharing (CORS).
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cross-origin resource sharing (CORS) Explanation & Exploitation ☠
Hi! My name is Hashar Mujahid and today we will talk about Cross-origin resource sharing (CORS).
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
5 mistakes to avoid on the bug bounty program
https://cdn-images-1.medium.com/max/2600/0*xJiHMTDM5_zG0Y7C
Improve your testing accuracy and get the most out of your findings
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
5 mistakes to avoid on the bug bounty program
https://cdn-images-1.medium.com/max/2600/0*xJiHMTDM5_zG0Y7C
Improve your testing accuracy and get the most out of your findings
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
5 mistakes to avoid on the bug bounty program
Improve your testing accuracy and get the most out of your findings
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Understanding The Skills Needed to Become a Cybersecurity Hacker
https://cdn-images-1.medium.com/max/1280/1*C0YDJe7k0vzu_p0yUFS_Wg.png
As technology is advancing, so is the need for more robust cybersecurity. The adoption of cutting-edge technology by global businesses is…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Understanding The Skills Needed to Become a Cybersecurity Hacker
https://cdn-images-1.medium.com/max/1280/1*C0YDJe7k0vzu_p0yUFS_Wg.png
As technology is advancing, so is the need for more robust cybersecurity. The adoption of cutting-edge technology by global businesses is…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Understanding The Skills Needed to Become a Cybersecurity Hacker
As technology is advancing, so is the need for more robust cybersecurity. The adoption of cutting-edge technology by global businesses is…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What talking to 50+ web3 security experts and protocols has taught us
https://cdn-images-1.medium.com/max/2600/1*vfnGyReXQQS848tkaG7Dig.png
~$3B has been stolen so far in 2022, nearly double the $1.5B hackers took in 2021. And the frequency and scale of attacks are increasing…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
What talking to 50+ web3 security experts and protocols has taught us
https://cdn-images-1.medium.com/max/2600/1*vfnGyReXQQS848tkaG7Dig.png
~$3B has been stolen so far in 2022, nearly double the $1.5B hackers took in 2021. And the frequency and scale of attacks are increasing…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What talking to 50+ web3 security experts and protocols has taught us
~$3B has been stolen so far in 2022, nearly double the $1.5B hackers took in 2021. And the frequency and scale of attacks are increasing…
Cross-origin resource sharing (CORS) Explanation & Exploitation ☠
https://infosecwriteups.com/cross-origin-resource-sharing-cors-explanation-exploitation-b4179235728b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://infosecwriteups.com/cross-origin-resource-sharing-cors-explanation-exploitation-b4179235728b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cross-origin resource sharing (CORS) Explanation & Exploitation ☠
Hi! My name is Hashar Mujahid and today we will talk about Cross-origin resource sharing (CORS).
Hi! My name is Hashar Mujahid and today we will talk about Cross-origin resource sharing (CORS).Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/cross-origin-resource-sharing-cors-explanation-exploitation-b4179235728b?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cross-origin resource sharing (CORS) Explanation & Exploitation ☠
Hi! My name is Hashar Mujahid and today we will talk about Cross-origin resource sharing (CORS).
Cross-origin resource sharing (CORS) Explanation & Exploitation ☠
Hi! My name is Hashar Mujahid and today we will talk about Cross-origin resource sharing (CORS).Continue reading on InfoSec Write-ups »
Read more...
Hi! My name is Hashar Mujahid and today we will talk about Cross-origin resource sharing (CORS).Continue reading on InfoSec Write-ups »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
NGWAF - First Iteration Of ML Based Feedback WAF
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEifQrF26QZsvmuKO1KWzzaYy8m5J_8B_S46d5b_dtYGB_bcm0SlOgRhbIZlQE91QmhEaFM3ypt8xMTfrVzSXGV3d2He3qQJXljJl_OMMa7lKq9Ewa2CNF9OfIesa3aZ181BtZaqgjeRcueKSdT3PzonNjZt5l9IUNXyB_sKpgPDei968ysvI3zIxK5xRQ/w640-h466/NGWAF_1_Architecture.jpeg The Motivation | What is the N3XT ST3P?With the explosive growth of web applications since the early 2000s, web-based attacks have progressively become more rampant. One common solution is the Web Application Firewall (WAF). However, tweaking rules of current WAFs to improve the detection mechanisms can be complex and difficult. NGWAF seeks to address these drawbacks with a novel machine learning and quarantine-to-honeypot based architecture.
Inspired by actual pain points from operating WAFs, NGWAF intends to simplify and reimagine WAF operations through the following processes:
Pain point NGWAF Feature Maintenance of detection mechanisms and rules can be complex Leverage machine learning to automate the process of creating and updating detection mechanisms Immediate blocking of malicious traffic reduces chances of learning from threat actor behavior for future WAF improvements Threat elimination through redirected quarantine as opposed to conventional dropping and blocking of malicious traffic
To make deployment simple and portable, we have containerised the different components in the architecture using docker and configured them in a docker-compose file. This allows running it on a fresh install to be quick and easy as the dependencies are handled by docker automatically. The deployment can be expanded to be deployed into a local or cloud provider based kubernetes cluster, making scalabe as users can increase the number of nodes/pods to handle large amounts of traffic.
The deployment have been tested on macOS (Docker desktop), linux (ubuntu).
Check out our demo video here
NGWAF is created by @yupengfei, @zhangbosen, @matthewng and @elizabethlim
Special shoutout to @ruinahkoh for her contributions to the initial stages of NGWAF. How does NGWAF work?NGWAF runs out-of-the-box with three key components, these components as mentioned above are all containerised and are scalable according to desired usage. The protected resource can be customised by making a deployment change within the setup. https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEifQrF26QZsvmuKO1KWzzaYy8m5J_8B_S46d5b_dtYGB_bcm0SlOgRhbIZlQE91QmhEaFM3ypt8xMTfrVzSXGV3d2He3qQJXljJl_OMMa7lKq9Ewa2CNF9OfIesa3aZ181BtZaqgjeRcueKSdT3PzonNjZt5l9IUNXyB_sKpgPDei968ysvI3zIxK5xRQ/w640-h466/NGWAF_1_Architecture.jpeg High level architecture of NGWAF with expected traffic flows from different partiesKey BenefitsNGWAF was engineered with the following key user benefits in mind: 1. Rule Complexity ReductionNGWAF replaces traditional rulesets with deep learning models to reduce the complexity of managing and updating rules. Instead of manually editting rules, NGWAF's machine learning automates the pattern learning process from malicious data. Data collected from the quarantine environment are automatically scrubbed and batched, allowing it to be retrained into our detection model if desired. 2. Cyber DeceptionNGWAF adopts a novel architecture consisting an interactive and quarantine environment built to isolate potential hostile attackers. Unlike conventional WAFs which blocks upon detection, NGWAF diverts threat actors to emulated systems, trapping them to soften the impact of their malicious actions. The environment also act as a sinkhole to gather current attack methods, enabling the observation and collection of malicious data. These data can be used to further improve NGWAF's detection capability. https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjSPPvwQcqpDBqGZgS83fC6zZRKfTE8up_R40JZ80Ab-lLpki22XPcI82iTjII[...]
___________________________
@hacking_Attack
@Hacking_Video
NGWAF - First Iteration Of ML Based Feedback WAF
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEifQrF26QZsvmuKO1KWzzaYy8m5J_8B_S46d5b_dtYGB_bcm0SlOgRhbIZlQE91QmhEaFM3ypt8xMTfrVzSXGV3d2He3qQJXljJl_OMMa7lKq9Ewa2CNF9OfIesa3aZ181BtZaqgjeRcueKSdT3PzonNjZt5l9IUNXyB_sKpgPDei968ysvI3zIxK5xRQ/w640-h466/NGWAF_1_Architecture.jpeg The Motivation | What is the N3XT ST3P?With the explosive growth of web applications since the early 2000s, web-based attacks have progressively become more rampant. One common solution is the Web Application Firewall (WAF). However, tweaking rules of current WAFs to improve the detection mechanisms can be complex and difficult. NGWAF seeks to address these drawbacks with a novel machine learning and quarantine-to-honeypot based architecture.
Inspired by actual pain points from operating WAFs, NGWAF intends to simplify and reimagine WAF operations through the following processes:
Pain point NGWAF Feature Maintenance of detection mechanisms and rules can be complex Leverage machine learning to automate the process of creating and updating detection mechanisms Immediate blocking of malicious traffic reduces chances of learning from threat actor behavior for future WAF improvements Threat elimination through redirected quarantine as opposed to conventional dropping and blocking of malicious traffic
To make deployment simple and portable, we have containerised the different components in the architecture using docker and configured them in a docker-compose file. This allows running it on a fresh install to be quick and easy as the dependencies are handled by docker automatically. The deployment can be expanded to be deployed into a local or cloud provider based kubernetes cluster, making scalabe as users can increase the number of nodes/pods to handle large amounts of traffic.
The deployment have been tested on macOS (Docker desktop), linux (ubuntu).
Check out our demo video here
NGWAF is created by @yupengfei, @zhangbosen, @matthewng and @elizabethlim
Special shoutout to @ruinahkoh for her contributions to the initial stages of NGWAF. How does NGWAF work?NGWAF runs out-of-the-box with three key components, these components as mentioned above are all containerised and are scalable according to desired usage. The protected resource can be customised by making a deployment change within the setup. https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEifQrF26QZsvmuKO1KWzzaYy8m5J_8B_S46d5b_dtYGB_bcm0SlOgRhbIZlQE91QmhEaFM3ypt8xMTfrVzSXGV3d2He3qQJXljJl_OMMa7lKq9Ewa2CNF9OfIesa3aZ181BtZaqgjeRcueKSdT3PzonNjZt5l9IUNXyB_sKpgPDei968ysvI3zIxK5xRQ/w640-h466/NGWAF_1_Architecture.jpeg High level architecture of NGWAF with expected traffic flows from different partiesKey BenefitsNGWAF was engineered with the following key user benefits in mind: 1. Rule Complexity ReductionNGWAF replaces traditional rulesets with deep learning models to reduce the complexity of managing and updating rules. Instead of manually editting rules, NGWAF's machine learning automates the pattern learning process from malicious data. Data collected from the quarantine environment are automatically scrubbed and batched, allowing it to be retrained into our detection model if desired. 2. Cyber DeceptionNGWAF adopts a novel architecture consisting an interactive and quarantine environment built to isolate potential hostile attackers. Unlike conventional WAFs which blocks upon detection, NGWAF diverts threat actors to emulated systems, trapping them to soften the impact of their malicious actions. The environment also act as a sinkhole to gather current attack methods, enabling the observation and collection of malicious data. These data can be used to further improve NGWAF's detection capability. https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjSPPvwQcqpDBqGZgS83fC6zZRKfTE8up_R40JZ80Ab-lLpki22XPcI82iTjII[...]
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
NGWAF - First Iteration Of ML Based Feedback WAF