Sys-Admin Up – Telegram
Sys-Admin Up
1.06K subscribers
132 photos
4 videos
127 files
2.23K links
InfoSec, Hacks, Perks, Tools, IT/IS Courses, CVE… Contains part of the news that was not included in the Sys-Admin & InfoSec Channel (@sysadm_in_channel)
Download Telegram
Попалась мне такая вот IDE - HBuilderX

Поделие от китайских разработчиков, ради интереса решил попробовать, достаточно прикольный редактор, так как сам пользуюсь в большей степени Sublime Text и PhpStorm то есть с чем сравнить - рабоатет легко, не тормозит, не лагает, куча синтаксисов для различных языков, встроенные терминал, браузер. Позиционируется, как IDE для VUE и еже с ним, но это не мешает его использовать под другие задачи, держу пока ради теста, сравнения функциональности и тп, кому интересно детали (на английком) здесь:

https://www.dcloud.io/hbuilderx.html
Sys-Admin Up pinned Deleted message
vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios in the means of Exercises

https://github.com/roottusk/vapi
Что смотришь , изучай Английский блят*!
GoTestWAF Tool

GoTestWAF generates malicious requests using encoded payloads placed in different parts of HTTP requests: its body, headers, URL parameters, etc. Generated requests are sent to the application security solution URL specified during GoTestWAF launch. The results of the security solution evaluation are recorded in the report file created on your machine.

https://github.com/wallarm/gotestwaf
Коты как статус-коды HTTP

https://http.cat/

Usage:
https://http.cat/[status_code]
Forwarded from Sys-Admin InfoSec
/ Повышение цен на электричество в Европе никак не повлияют на BLD DNS Service

BLD+ Мотивация и Причины создания (ru)

/ Energy price increases in Europe will not affect the BLD DNS service in any way

BLD+ Motivations and Reasons for creation (en)

~~~

How you can use BLD in Browsers, Phones, Routers:
https://github.com/m0zgen/blocky-listener-daemon/wiki

BLD Project Site:
https://lab.sys-adm.in

P.S. 👋 if you want to donate you can find donate links, in bottom on lab.sys-adm.in site :)
EtherNet/IP & CIP Stack Detector

EtherNet/IP & CIP Stack Detector that can help both cyber-security researchers, OT engineers, and asset owners to identify devices that are running a specific EtherNet/IP protocol stack

https://github.com/claroty/enip-stack-detector
Active Directory Certificate Services (AD CS): weaponizing the ESC7 attack

New vectors in different engagements throughout the last months, mainly to escalate and keep the acquired privileges. In this context, the techniques labeled as ESC1 and ESC8 were the most used, being the attacks most well documented on the internet due to their effectiveness.

https://www.blackarrow.net/adcs-weaponizing-esc7-attack/