Snuffleupagus - Security Module For Php7 And Php8 - Killing Bugclasses And Virtual-Patching The Rest!
http://www.kitploit.com/2021/05/snuffleupagus-security-module-for-php7.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/05/snuffleupagus-security-module-for-php7.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Snuffleupagus - Security Module For Php7 And Php8 - Killing Bugclasses And Virtual-Patching The Rest!
Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest! Snuffleupagus is a PHP 7+ and 8+ (https://secure.php.net/) module designed to drastically raise the cost of attacks against websites, by killing entire bug classes. It also provides a powerful virtual-patching system, allowing administrator to fix specific vulnerabilities (https://www.kitploit.com/search/label/vulnerabilities) and audit suspicious behaviours without having to touch the PHP code.
Key Features
No noticeable (https://dustri.org/b/snuffleupagus-030-dentalium-elephantinum.html)performance (https://www.kitploit.com/search/label/Performance) impact Powerful yet simple to write virtual-patching rules Killing several classes of vulnerabilities Unserialize-based (https://www.owasp.org/images/9/9e/Utilizing-Code-Reuse-Or-Return-Oriented-Programming-In-PHP-Application-Exploits.pdf) code execution mail-based code execution Cookie-stealing XSS (https://en.wikipedia.org/wiki/Cross-site_scripting) File-upload based code execution Weak PRNG XXE (https://en.wikipedia.org/wiki/XML_external_entity_attack) Several hardening (https://www.kitploit.com/search/label/Hardening) features Automatic secure and samesite flag for cookies Bundled set of rules to detect post-compromissions behaviours Global strict mode (https://secure.php.net/manual/en/migration70.new-features.php#migration70.new-features.scalar-type-declarations) and type-juggling prevention Whitelisting of stream wrappers (https://secure.php.net/manual/en/intro.stream.php) Preventing writeable files execution Whitelist/blacklist for eval Enforcing TLS certificate validation when using curl (https://secure.php.net/manual/en/book.curl.php) Request dumping capability A relatively sane code base: A comprehensive (https://coveralls.io/github/jvoisin/snuffleupagus?branch=master) test suite close to 100% coverage Every commit is tested on several distributions (https://gitlab.com/jvoisin/snuffleupagus/pipelines) An clang-format-enforced code style A comprehensive documentation (https://snuffleupagus.rtfd.io/) Usage of coverity (https://scan.coverity.com/projects/jvoisin-snuffleupagus)
Download
We've got a download page (https://snuffleupagus.readthedocs.io/download.html), where you can find packages for your distribution, but you can of course just git clone this repo, or check the releases on github (https://github.com/jvoisin/snuffleupagus/releases).
Examples
We're providing various example rules (https://github.com/jvoisin/snuffleupagus/tree/master/config), that are looking like this: # Harden the `chmod` function
sp.disable_function.function("chmod").param("mode").value_r("^[0-9]{2}[67]$").drop();
# Mitigate command injection (https://www.kitploit.com/search/label/Command%20Injection) in `system`
sp.disable_function.function("system").param("command").value_r("[$|;&`\\n]").drop(); Upon violation of a rule, you should see lines like this in your logs: [snuffleupagus][0.0.0.0][disabled_function][drop] The execution has been aborted in /var/www/index.php:2, because the return value (0) of the function 'strpos' matched a rule.
Documentation
We've got a comprehensive website (https://snuffleupagus.readthedocs.io/) with all the documentation that you could possibly wish for. You can of course build it yourself (https://github.com/jvoisin/snuffleupagus/tree/master/doc).
Thanks
Many thanks to the Suhosin project (https://suhosin.org/) for being a huge source of inspiration, and to all our contributors (https://github.com/jvoisin/snuffleupagus/graphs/contributors).
Download Snuffleupagus (https://github.com/jvoisin/snuffleupagus)
___________________________
@hacking_Attack
@Hacking_Video
Key Features
No noticeable (https://dustri.org/b/snuffleupagus-030-dentalium-elephantinum.html)performance (https://www.kitploit.com/search/label/Performance) impact Powerful yet simple to write virtual-patching rules Killing several classes of vulnerabilities Unserialize-based (https://www.owasp.org/images/9/9e/Utilizing-Code-Reuse-Or-Return-Oriented-Programming-In-PHP-Application-Exploits.pdf) code execution mail-based code execution Cookie-stealing XSS (https://en.wikipedia.org/wiki/Cross-site_scripting) File-upload based code execution Weak PRNG XXE (https://en.wikipedia.org/wiki/XML_external_entity_attack) Several hardening (https://www.kitploit.com/search/label/Hardening) features Automatic secure and samesite flag for cookies Bundled set of rules to detect post-compromissions behaviours Global strict mode (https://secure.php.net/manual/en/migration70.new-features.php#migration70.new-features.scalar-type-declarations) and type-juggling prevention Whitelisting of stream wrappers (https://secure.php.net/manual/en/intro.stream.php) Preventing writeable files execution Whitelist/blacklist for eval Enforcing TLS certificate validation when using curl (https://secure.php.net/manual/en/book.curl.php) Request dumping capability A relatively sane code base: A comprehensive (https://coveralls.io/github/jvoisin/snuffleupagus?branch=master) test suite close to 100% coverage Every commit is tested on several distributions (https://gitlab.com/jvoisin/snuffleupagus/pipelines) An clang-format-enforced code style A comprehensive documentation (https://snuffleupagus.rtfd.io/) Usage of coverity (https://scan.coverity.com/projects/jvoisin-snuffleupagus)
Download
We've got a download page (https://snuffleupagus.readthedocs.io/download.html), where you can find packages for your distribution, but you can of course just git clone this repo, or check the releases on github (https://github.com/jvoisin/snuffleupagus/releases).
Examples
We're providing various example rules (https://github.com/jvoisin/snuffleupagus/tree/master/config), that are looking like this: # Harden the `chmod` function
sp.disable_function.function("chmod").param("mode").value_r("^[0-9]{2}[67]$").drop();
# Mitigate command injection (https://www.kitploit.com/search/label/Command%20Injection) in `system`
sp.disable_function.function("system").param("command").value_r("[$|;&`\\n]").drop(); Upon violation of a rule, you should see lines like this in your logs: [snuffleupagus][0.0.0.0][disabled_function][drop] The execution has been aborted in /var/www/index.php:2, because the return value (0) of the function 'strpos' matched a rule.
Documentation
We've got a comprehensive website (https://snuffleupagus.readthedocs.io/) with all the documentation that you could possibly wish for. You can of course build it yourself (https://github.com/jvoisin/snuffleupagus/tree/master/doc).
Thanks
Many thanks to the Suhosin project (https://suhosin.org/) for being a huge source of inspiration, and to all our contributors (https://github.com/jvoisin/snuffleupagus/graphs/contributors).
Download Snuffleupagus (https://github.com/jvoisin/snuffleupagus)
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
JUST A SECOND, IS ALL IT TAKES…
In this article i am going to talk about my first bug that i had found recently which is nothing but the broken link hijacking.Continue reading on Medium »
Read more...
In this article i am going to talk about my first bug that i had found recently which is nothing but the broken link hijacking.Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
A CTF-style walkthrough of the recent Exiftool arbitrary code execution vuln (CVE-2021-22204)
https://external-preview.redd.it/PdKVZ1GJSbINBZ9ZoBxUFkcD4XhK-49nP0yDFSpLQ9k.jpg?width=640&crop=smart&auto=webp&s=96030ca49557e271fac2ed69d8d0f8c663a1602f submitted by /u/thefloatgoat
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
A CTF-style walkthrough of the recent Exiftool arbitrary code execution vuln (CVE-2021-22204)
https://external-preview.redd.it/PdKVZ1GJSbINBZ9ZoBxUFkcD4XhK-49nP0yDFSpLQ9k.jpg?width=640&crop=smart&auto=webp&s=96030ca49557e271fac2ed69d8d0f8c663a1602f submitted by /u/thefloatgoat
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
A CTF-style walkthrough of the recent Exiftool arbitrary code...
Posted in r/hacking by u/thefloatgoat • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Interesting spam technique on Amazon
So, the guy is an idiot, but a genius as well. Some dingus went and mass-changed thousands of listings on Amazon to a pair of shoes with a watermark to his website.
Somehow, he was able to bypass the approval requirements to submit a "new" photo, and now about 1,600 products (from my inventory alone), have been updated to this image (screenshots below)
He's an idiot because his photo was not high resolution enough to see the URL in the image...
https://imgur.com/a/igNvfW8
I figured the hacking community would appreciate some weird social engineering on a huge platform like Amazon.
submitted by /u/evohans
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Interesting spam technique on Amazon
So, the guy is an idiot, but a genius as well. Some dingus went and mass-changed thousands of listings on Amazon to a pair of shoes with a watermark to his website.
Somehow, he was able to bypass the approval requirements to submit a "new" photo, and now about 1,600 products (from my inventory alone), have been updated to this image (screenshots below)
He's an idiot because his photo was not high resolution enough to see the URL in the image...
https://imgur.com/a/igNvfW8
I figured the hacking community would appreciate some weird social engineering on a huge platform like Amazon.
submitted by /u/evohans
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Interesting spam technique on Amazon
So, the guy is an idiot, but a genius as well. Some dingus went and mass-changed thousands of listings on Amazon to a pair of shoes with a...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to Tell If Your Phone Is Hacked and How to Fix It
https://cdn-images-1.medium.com/max/1200/0*9quwIFdmgRvcM22h.jpg
A Resourceful Compilation of Indicators and Solutions
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to Tell If Your Phone Is Hacked and How to Fix It
https://cdn-images-1.medium.com/max/1200/0*9quwIFdmgRvcM22h.jpg
A Resourceful Compilation of Indicators and Solutions
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to Tell If Your Phone Is Hacked and How to Fix It
A Resourceful Compilation of Indicators and Solutions
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What are the vulnerabilities in a database server and web server, and how do you mitigate it?
Vulnerabilities in web applications include a system error or a system weakness in a web application. They have been around for years…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
What are the vulnerabilities in a database server and web server, and how do you mitigate it?
Vulnerabilities in web applications include a system error or a system weakness in a web application. They have been around for years…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What are the vulnerabilities in a database server and web server, and how do you mitigate it?
Vulnerabilities in web applications include a system error or a system weakness in a web application. They have been around for years…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hire a Hacker for Gmail Hacker.
https://cdn-images-1.medium.com/max/735/0*mQ3eaw-gzF9XXvOk.jpg
There are many reasons why it is important for businesses to hire a hacker for Gmail passwords.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hire a Hacker for Gmail Hacker.
https://cdn-images-1.medium.com/max/735/0*mQ3eaw-gzF9XXvOk.jpg
There are many reasons why it is important for businesses to hire a hacker for Gmail passwords.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hire a Hacker for Gmail Hacker.
There are many reasons why it is important for businesses to hire a hacker for Gmail passwords. It could be because of security breaches or…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hack The Box —Netmon: Walkthrough (without Metasploit)
https://cdn-images-1.medium.com/max/600/1*B-N1UaDMoMlvUXYsiMFu7g.png
Hack The Box -Netmon: Walkthrough (without Metasploit) | Road to OSCP | Windows Easy Level | Misconfiguration | Netmon Remote Code…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hack The Box —Netmon: Walkthrough (without Metasploit)
https://cdn-images-1.medium.com/max/600/1*B-N1UaDMoMlvUXYsiMFu7g.png
Hack The Box -Netmon: Walkthrough (without Metasploit) | Road to OSCP | Windows Easy Level | Misconfiguration | Netmon Remote Code…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hack The Box —Netmon: Walkthrough (without Metasploit)
Hack The Box -Netmon: Walkthrough (without Metasploit) | Road to OSCP | Windows Easy Level | Misconfiguration | Netmon Remote Code…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Dark Web se carga con vacunas falsas Covid-19 y tarjetas falsificadas.
https://cdn-images-1.medium.com/max/881/0*2JgUrgusPzIt4ujJ
PUBLICADO EN 13 MAYO, 2021 POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Dark Web se carga con vacunas falsas Covid-19 y tarjetas falsificadas.
https://cdn-images-1.medium.com/max/881/0*2JgUrgusPzIt4ujJ
PUBLICADO EN 13 MAYO, 2021 POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Dark Web se carga con vacunas falsas Covid-19 y tarjetas falsificadas.
PUBLICADO EN 13 MAYO, 2021 POR EHACKING
Course Club
[O’REILLY] Cloud Computing with Python Video Course
https://courseclub.me/wp-content/uploads/2021/04/784515412.jpg
https://courseclub.me/wp-content/uploads/2021/04/784515412.jpg
Get started with Cloud Computing in Python. Topics include: Multi-Cloud, Cloud Computing Service Models, Distributed Computing in the Cloud, Cloud Computing ETL Pipelines, Serverless Soutions with the Cloud, Containers in the Cloud, and Continuous Delivery for ML Engineers
Table of contents
1. “Multi Cloud Onboarding With Cloud Computing”
2. “Cloud Computing Service Models”
3. “Distributed Computing In The Cloud”
4. “Cloud Computing Build Etl Pipelines”
5. “Build Serverless Solutions With Cloud Computing”
6. “Containers In The Cloud”
7. “Continuous Delivery For Ml Engineering”
8.
Size: 2.94 GB
Download Now
https://www.oreilly.com/library/view/cloud-computing-with/60650VIDEOPAIML/.
The post [O’REILLY] Cloud Computing with Python Video Course appeared first on Course Club.
___________________________
@hacking_Attack
@Hacking_Video
[O’REILLY] Cloud Computing with Python Video Course
https://courseclub.me/wp-content/uploads/2021/04/784515412.jpg
https://courseclub.me/wp-content/uploads/2021/04/784515412.jpg
Get started with Cloud Computing in Python. Topics include: Multi-Cloud, Cloud Computing Service Models, Distributed Computing in the Cloud, Cloud Computing ETL Pipelines, Serverless Soutions with the Cloud, Containers in the Cloud, and Continuous Delivery for ML Engineers
Table of contents
1. “Multi Cloud Onboarding With Cloud Computing”
2. “Cloud Computing Service Models”
3. “Distributed Computing In The Cloud”
4. “Cloud Computing Build Etl Pipelines”
5. “Build Serverless Solutions With Cloud Computing”
6. “Containers In The Cloud”
7. “Continuous Delivery For Ml Engineering”
8.
Size: 2.94 GB
Download Now
https://www.oreilly.com/library/view/cloud-computing-with/60650VIDEOPAIML/.
The post [O’REILLY] Cloud Computing with Python Video Course appeared first on Course Club.
___________________________
@hacking_Attack
@Hacking_Video
Course Club
[O’REILLY] Cloud Computing with Python Video Course Free Download
[O’REILLY] Cloud Computing with Python Video Course Free Download Get started with Cloud Computing in Python. Topics include: Multi-Cloud, Cloud Computing Service Models, Distributed Computing in the Cloud, Cloud Computing ETL Pipelines, Serverless Soutions…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Nginxpwner : Tool To Look For Common Nginx Misconfigurations & Vulnerabilities
Nginxpwner is a simple tool to look for common Nginx misconfigurations and vulnerabilities. Install cd /optgit clone https://github.com/stark0de/nginxpwnercd nginxpwnerchmod +x install.sh./install.sh Usage Target tab in Burp, select host, right click, copy all URLs in this host, copy to a filecat urllist | unfurl paths | cut -d”/” -f2-3 | sort -u > /tmp/pathlistOr get the […]
The post Nginxpwner : Tool To Look For Common Nginx Misconfigurations & Vulnerabilities appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
Nginxpwner : Tool To Look For Common Nginx Misconfigurations & Vulnerabilities
Nginxpwner is a simple tool to look for common Nginx misconfigurations and vulnerabilities. Install cd /optgit clone https://github.com/stark0de/nginxpwnercd nginxpwnerchmod +x install.sh./install.sh Usage Target tab in Burp, select host, right click, copy all URLs in this host, copy to a filecat urllist | unfurl paths | cut -d”/” -f2-3 | sort -u > /tmp/pathlistOr get the […]
The post Nginxpwner : Tool To Look For Common Nginx Misconfigurations & Vulnerabilities appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Nginxpwner : Tool to look Nginx misconfigurations and vulnerabilities
Nginxpwner is a open source software for web serving and also to look for common Nginx misconfigurations and vulnerabilities.