white2hack 📚 – Telegram
white2hack 📚
14.6K subscribers
4.8K photos
135 videos
1.96K files
2.26K links
Кибербез. Книги, гайды, how to, ликбез. Аналитика, тренды, карьера, эвенты. Этичный хакинг и защита своих данных

🔊 Связь @w2hack_feed_bot
💬 Чат https://news.1rj.ru/str/+VdkEIWudTi5m3dsA
💡 Консультация https://forms.gle/iB9iX3BwyxJM4Ktx5
🏛 Обмен -- private --
Download Telegram
A Bug Hunter's Diary - A Guided Tour Through the Wilds of Software Security, Tobias Klein, 2011

A Bug Hunter's Diary follows security expert Tobias Klein as he tracks down and exploits bugs in some of the world's most popular software, like Apple's iOS, the VLC media player, web browsers, and even the Mac OS X kernel. In this one-of-a-kind account, you'll see how the developers responsible for these flaws patched the bugs - or failed to respond at all.

A Bug Hunter's Diary is packed with real-world examples of vulnerable code and the custom programs used to find and test bugs. Whether you're hunting bugs for fun, for profit, or to make the world a safer place, you'll learn valuable new skills by looking over the shoulder of a professional bug hunter in action.

#book #AppSec
🔥4
A_Bug_Hunter_039_s_Diary_A_Guided_Tour_Through_the_Wilds_of_Software.pdf
5.2 MB
A Bug Hunter's Diary - A Guided Tour Through the Wilds of Software Security, Tobias Klein, 2011
👍4🔥2
Дневник охотника за ошибками. Путешествие через джунгли проблем безопасности программного обеспечения, Клейн Тобиас, 2013, язык русский

Книга рассказывает, как обнаруживаются и используются ошибки, найденные им в некоторых наиболее популярных во всем мире программных продуктах, таких как операционная система Apple iOS, медиа-проигрыватель VLC, веб-браузеры и даже ядро операционной системы Mac OS X. В этом уникальном отчете вы увидите, как эти ошибки были исправлены разработчиками, ответственными за их появление, или вообще оказались не в состоянии это сделать.

Издание снабжено реальными примерами уязвимого кода и программ, использовавшихся для поиска и проверки ошибок.

#book #AppSec
🔥5
Dnevnik_Okhotnika_Za_Oshibkami.pdf
4.1 MB
Дневник охотника за ошибками. Путешествие через джунгли проблем безопасности программного обеспечения, Клейн Тобиас, 2013, язык русский
👍7
iOS Application Security: The Definitive Guide for Hackers and Developers, David Thiel, 2016

Eliminating security holes in iOS apps is critical for any developer who wants to protect their users from the bad guys. In iOS Application Security, mobile security expert David Thiel reveals common iOS coding mistakes that create serious security problems and shows you how to find and fix them.

After a crash course on iOS application structure and Objective-C design patterns, you'll move on to spotting bad code and plugging the holes.

#book #AppSec #mobile
👍51
iOS_Application_Security_The_Definitive_Guide_for_Hackers_and_Developers.pdf
16.3 MB
iOS Application Security: The Definitive Guide for Hackers and Developers, David Thiel, 2016
👍4
Rootkits and Bootkits: Reversing Modern Malware and Next Generation Threats by Alex Matrosov, Eugene Rodionov, Sergey Bratus, 2019

Rootkits and Bootkits will teach you how to understand and counter sophisticated, advanced threats buried deep in a machine’s boot process or UEFI firmware.

As you inspect and dissect real malware, you’ll learn:
• How Windows boots—including 32-bit, 64-bit, and UEFI mode—and where to find vulnerabilities
• The details of boot process security mechanisms like Secure Boot, including an overview of Virtual Secure Mode (VSM) and Device Guard
• Reverse engineering and forensic techniques for analyzing real malware, including bootkits like Rovnix/Carberp, Gapz, TDL4, and the infamous rootkits TDL3 and Festi
• How to perform static and dynamic analysis using emulation and tools like Bochs and IDA Pro
• How to better understand the delivery stage of threats against BIOS and UEFI firmware in order to create detection capabilities

#book #malware #reverse
🔥4👍2
Rootkits_and_Bootkit__by_Alex_Matrosov_Eugen.pdf
15.3 MB
Rootkits and Bootkits: Reversing Modern Malware and Next Generation Threats by Alex Matrosov, Eugene Rodionov, Sergey Bratus, 2019
👍51
The Security Development Lifecycle, Howard Michael and Lipner Steve, Microsoft Press, 2009

This book is the first to detail a rigorous, proven methodology that measurably minimizes security bugsthe Security Development Lifecycle (SDL). In this long-awaited book, security experts Michael Howard and Steve Lipner from the Microsoft Security Engineering Team guide you through each stage of the SDLfrom education and design to testing and post-release. You get their first-hand insights, best practices, a practical history of the SDL, and lessons to help you implement the SDL in any development organization

#book #AppSec
🔥41
Rootkits_and_Bootkit__by_Alex_Matrosov_Eugen.pdf
15.3 MB
The Security Development Lifecycle, Howard Michael and Lipner Steve, Microsoft Press, 2009
👍4
Survive The Deep End: PHP Security (Release 1.0a1) by Padraic Brady, 2017

#book #AppSec
👍4
Survive The Deep End PHP Security Release 1.0a1.pdf
296.7 KB
Survive The Deep End: PHP Security (Release 1.0a1) by Padraic Brady, 2017
👍4
Official book of PEN200 - OSCP ver.2023, shared by Tamarisk

What changed in 2023

#book #pentest
3👍3🔥3
PEN200 - OSCP - 2023 version (Shared by Tamarisk).pdf
48.2 MB
Official book of PEN200 - OSCP ver.2023, shared by Tamarisk
👍10🔥21
Атака и защита веб-сайтов по OWASP Top 10, УЦ Специалист, 2020

Курс посвящен методикам проведения тестирования на проникновение согласно классификации OWASP Top 10. В курсе представлены подробные материалы по работе веб-серверов и веб-приложений. Детально описаны уязвимости в соответствии с классификацией OWASP Top 10 и техники применения эксплойтов для многочисленных тестов на проникновение. А также предложены рекомендации по укреплению защищённости веб-приложений для каждого вида уязвимости.

#education #web
🔥4🙏21
Spetsialist_Ataka_i_zashchita_veb_saytov_po_OWASP_Top_10_2020.torrent
52.2 KB
Атака и защита веб-сайтов по OWASP Top 10, УЦ Специалист, 2020 торрент файл
🔥6🤔2