Security Analysis – Telegram
Security Analysis
11.5K subscribers
344 photos
50 videos
36 files
885 links
- Offensive Security (Red Teaming / PenTesting)
- BlueTeam (OperationSec, TreatHunting, DFIR)
- Reverse Engineering / Malware Analysis
- Web Security
- Cryptography
- Steganography
- Forensics
Contact : @DrPwner
Download Telegram
Forwarded from Deleted Account
OWASP_API_Security_Top_10_Cheatsheet_pdf_1636948037.pdf
1.4 MB
⭕️ OWASP API Security Top 10

#owasp #API
@securation
⭕️ Persistence with Azure Policy Guest Configuration

Use Azure Policy Guest Configuration to gain persistence in your target environment and how to detect such an attack as a defender.

https://cloudbrothers.info/en/azure-persistence-azure-policy-guest-configuration/
#azure
@securation
اگه علاقه به حل معما و چالش توی امنیت دارید یه سری به اینجا هم بزنید و چالش هایی که با آسیب پذیری های جدید به وجود میاد براشون Lab نوشته میشه, سروکله بزنید :)
.
https://www.vulnmachines.com/
#vuln #machines
@securation
⭕️ Linux Kernel Exploitation 0x1 - Smashing Stack Overflows in the Kernel

https://blog.k3170makan.com/2020/11/linux-kernel-exploitation-0x1-smashing.html
#linux #kernel #stackoverflow
@securation
This media is not supported in your browser
VIEW IN TELEGRAM
⭕️ Online PCAP file analyzer - An handy GUI tool for forensic investigation/penetration testing to analyze PCAP files on the go.

https://apackets.com

#pcap #packet
@securation
👍6
⭕️ ابزار آنلاین واسه Bypass کردن WAFها طراحی شده :)

xssor.io
#WAF #BYPASS #WEB
@securation
🤩14👍1
⭕️ Vulnerable AWS Lambda function - Initial access in cloud attacks

How a vulnerable AWS Lambda function could be used by attackers, and some best practices to mitigate these attacks.

https://sysdig.com/blog/exploit-mitigate-aws-lambdas-mitre/

#aws #cloud
@securation
😱2
⭕️ ۱− آسیب پذیری HTTP Request Smuggling چیه و چطوری به وجود میاد ؟
اگه یه تارگت این آسیب پذیری رو داشته باشه باهاش چه کارهایی میشه انجام داد؟
۲− یه ابزار برای کشف و اکسپلویت کردن این آسیب پذیری :

۱− https://portswigger.net/web-security/request-smuggling
۲−
https://github.com/neex/http2smugl
#http2smugl #smuggling
@securation
👍7