Kubernetes Goat
The Kubernetes Goat is designed to be an intentionally vulnerable cluster environment to learn and practice Kubernetes security:
— https://github.com/madhuakula/kubernetes-goat
The Kubernetes Goat is designed to be an intentionally vulnerable cluster environment to learn and practice Kubernetes security:
— https://github.com/madhuakula/kubernetes-goat
GitHub
GitHub - madhuakula/kubernetes-goat: Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes…
Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀 - madhuakula/kubernetes-goat
Attack Campaign that Uses Fake Google Chrome Error to Distribute Malware from Compromised Websites
Research:
— https://insight-jp.nttsecurity.com/post/102icvb/attack-campaign-that-uses-fake-google-chrome-error-to-distribute-malware-from-com
Research:
— https://insight-jp.nttsecurity.com/post/102icvb/attack-campaign-that-uses-fake-google-chrome-error-to-distribute-malware-from-com
GC2 (Google Command and Control) is a Command and Control application that allows an attacker to execute commands on the target machine using Google Sheet and exfiltrates data using Google Drive:
— https://github.com/looCiprian/GC2-sheet
— https://github.com/looCiprian/GC2-sheet
GitHub
GitHub - looCiprian/GC2-sheet: GC2 is a Command and Control application that allows an attacker to execute commands on the target…
GC2 is a Command and Control application that allows an attacker to execute commands on the target machine using Google Sheet or Microsoft SharePoint List and exfiltrate files using Google Drive or...
Linkedin - Can delete other user's post and company page post
disclosed report:
— https://hackerone.com/reports/337755
disclosed report:
— https://hackerone.com/reports/337755
HackerOne
LinkedIn disclosed on HackerOne: Can delete other user's post and...
Missing proper access control on the vulnerable request allows an attacker to delete other user's post and company page post.
Тезисно о том, как можно получить Open Source - All Product Pack лицензию от JetBrains
Все просто - делай вклад в этот мир и тебе воздастся ;)
— https://youtu.be/9DMnXS0ifAA
Все просто - делай вклад в этот мир и тебе воздастся ;)
— https://youtu.be/9DMnXS0ifAA
YouTube
Тезисно о том, как можно получить Open Source - All Product Pack лицензию от JetBrains
Я получаю вторую подряд Open Source - All Product Pack лицензию от JetBrains, удобные IDE на все случае программерской жизни.
* https://www.jetbrains.com/community/opensource/#support
Мои проекты:
* https://github.com/m0zgen/cactusd
* https://github.co…
* https://www.jetbrains.com/community/opensource/#support
Мои проекты:
* https://github.com/m0zgen/cactusd
* https://github.co…
Vimeo SSRF with code execution potential
— https://infosecwriteups.com/vimeo-ssrf-with-code-execution-potential-68c774ba7c1e
— https://infosecwriteups.com/vimeo-ssrf-with-code-execution-potential-68c774ba7c1e
Medium
Vimeo SSRF with code execution potential.
Recently i discovered a semi responded SSRF on Vimeo with code execution possibility. This blog post explains how i found & exploited it…
Postgres Guru | Базы данных - Админ PostgreSQL ведет свой канал
Записывает заметки, разные SQL полезности из личной практики:
-- https://news.1rj.ru/str/pg_guru
Записывает заметки, разные SQL полезности из личной практики:
-- https://news.1rj.ru/str/pg_guru
Telegram
Postgres Guru | Базы данных 💐
Все о самой популярной СУБД PostgreSQL: технические статьи, новости и немного юмора.
Сотрудничество: @Sferg007
Ссылка для друзей: https://news.1rj.ru/str/+NRjYf8gGR3RmYmMy
Сайт: https://ibtorg.ru
Postgres Guru в VK https://vk.com/pg_guru
Сотрудничество: @Sferg007
Ссылка для друзей: https://news.1rj.ru/str/+NRjYf8gGR3RmYmMy
Сайт: https://ibtorg.ru
Postgres Guru в VK https://vk.com/pg_guru
System_Design_ByteByteGo_PDF.pdf
37.8 MB
Big Collection for System Designers…
🔸 What are database isolation levels
🔸 What is IaaS/PaaS/SaaS
🔸 What is SSO (Single Sign-On)
🔸 How to store passwords safely in the database
🔸 How does HTTPS work
🔸 ..and more and more….
🔸 What are database isolation levels
🔸 What is IaaS/PaaS/SaaS
🔸 What is SSO (Single Sign-On)
🔸 How to store passwords safely in the database
🔸 How does HTTPS work
🔸 ..and more and more….
An Introduction into Sleep Obfuscation
The goal of this post is to break down this technique:
— https://dtsec.us/2023-04-24-Sleep/
The goal of this post is to break down this technique:
— https://dtsec.us/2023-04-24-Sleep/
Nigerald's blog
An Introduction into Sleep Obfuscation
Using Ekko to sort of bypass Hunt Sleeping Beacons
Hiding in Plain Sight: Unlinking Malicious DLLs from the PEB
In this post, we take a look at an anti-forensics technique that malware can leverage to hide injected DLLs. We dive into specific details of the Windows Process Environment Block (PEB) and how to abuse it to hide a malicious loaded DLL:
— https://blog.christophetd.fr/dll-unlinking/
In this post, we take a look at an anti-forensics technique that malware can leverage to hide injected DLLs. We dive into specific details of the Windows Process Environment Block (PEB) and how to abuse it to hide a malicious loaded DLL:
— https://blog.christophetd.fr/dll-unlinking/
Christophe Tafani-Dereeper
Hiding in Plain Sight: Unlinking Malicious DLLs from the PEB - Christophe Tafani-Dereeper
In this post, we take a look at an anti-forensics technique that malware can leverage to hide injected DLLs. We dive into specific details of the Windows Process Environment Block (PEB) and how to abuse it to hide a malicious loaded DLL. Background: You may…
Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection
https://github.com/LordNoteworthy/al-khaser
https://github.com/LordNoteworthy/al-khaser
GitHub
GitHub - ayoubfaouzi/al-khaser: Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.
Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection. - GitHub - ayoubfaouzi/al-khaser: Public malware techniques used in the wild: Virtual Machine,...
eBPF Observability Tools Are Not Security Tools
https://www.brendangregg.com/blog/2023-04-28/ebpf-security-issues.html
https://www.brendangregg.com/blog/2023-04-28/ebpf-security-issues.html
Brendangregg
eBPF Observability Tools Are Not Security Tools
eBPF Observability Tools Are Not Have Security Tools
Ethical Hacking in 15 Hours - 2023 Edition - Learn to Hack (Parts 1, 2)
— https://youtu.be/3FNYvj2U0HM
— https://youtu.be/sH4JCwjybGs
— https://youtu.be/3FNYvj2U0HM
— https://youtu.be/sH4JCwjybGs
YouTube
Ethical Hacking in 15 Hours - 2023 Edition - Learn to Hack! (Part 1)
TCM Security Black Friday sale is happening now through December 1st at 11:59 PM ET!
https://www.tcm.rocks/acad-y-2025 - Get 50% off your first payment to the TCM Security Academy
https://www.tcm.rocks/certs-y-2025 - Take 20% off certifications & live trainings!…
https://www.tcm.rocks/acad-y-2025 - Get 50% off your first payment to the TCM Security Academy
https://www.tcm.rocks/certs-y-2025 - Take 20% off certifications & live trainings!…
Python noscript as Systemd
example:
— https://docs.rockylinux.org/gemstones/systemd_service_for_python_noscript/
example:
— https://docs.rockylinux.org/gemstones/systemd_service_for_python_noscript/
docs.rockylinux.org
Systemd Service - Python Script - Documentation
Forwarded from Sys-Admin InfoSec
OpenBLD - Next Stage to Growth with ClouDNS
GeoDNS and Global Anycast DNS features from ClouDNS - it as a brilliant opportunity for additional OpenBLD Performance and Availability
Today ClouDNS supported OpenBLD DNS and provided own features for free:
• Anycast DNS service and Anycast GeoDNS servers
• DDoS Protection
• DNS Failover checks
• EDNS-client-subnet support
• and more...
ClouDNS providing flexible tools for managements services and very affordable pricing plans and it is I like it very much.
This can be a key milestone in the development phase of the OpenBLD project, it is a next stage for growth. I have special domain name for OpenBLD DNS project, may be it is a "that very moment"...
• All ClouDNS features you can found on ClouDNS Site
• How to protect for your self and family with OpenBLD Here
Sys-Admin Up pinned « OpenBLD - Next Stage to Growth with ClouDNS GeoDNS and Global Anycast DNS features from ClouDNS - it as a brilliant opportunity for additional OpenBLD Performance and Availability Today ClouDNS supported OpenBLD DNS and provided own features for free:…»
Coraza WAF Caddy Module
Go-written WAF module from fastest Caddy server:
— https://github.com/corazawaf/coraza-caddy
Go-written WAF module from fastest Caddy server:
— https://github.com/corazawaf/coraza-caddy
GitHub
GitHub - corazawaf/coraza-caddy: OWASP Coraza middleware for Caddy. It provides Web Application Firewall capabilities
OWASP Coraza middleware for Caddy. It provides Web Application Firewall capabilities - corazawaf/coraza-caddy