12 items with this tag.

Quote Hello everyone! It has been a while since my last technical release. I took a few weeks off to celebrate the Tet Holiday in my country, set up the workspace for my new job, and most importantly, begin the journey of running my own business alongside a close friend.
For SSL implementation, various technologies are available. Nevertheless, to optimize the cost of operating your system, pairing a static IP address with Let’s Encrypt and the Certbot Python 3 client is highly recommended for your domain.
Info Place to store the smartlink to my resource about cyber and information security of myself CTF Writeups Write up - Forensic Hidden Message - ASCIS 2023 PNG Recovery Write up - Hacktheboo 2023 Forensics Write up - GraphQL Hackwekend Self Challenges GitHub - Em0t3t CTF Web & Forensics GitHub - GraphQL Hackwekend .
Info There many thing web you can refer to this stuff Insecure Direct Object Reference – IDOR Vulnerability Tìm kiếm các lỗi IDOR, chưa bao giờ lại dễ đến thế với extension Autorize Automating BURP to find IDORs How-To: Find IDOR (Insecure Direct Object Reference) Vulnerabilities for large bounty rewards What is IDOR Vulnerability, and how does it affect you? Insecure Direct Object Reference Prevention Cheat Sheet What is an IDOR? IDOR stands for Insecure Direct Object Reference and is a type of access control vulnerability.

Question What SSTI ? How does it work ? What hacker can do with it? How to prevent it? English Resource SSTI from Hackstricks (very detailed explanation) Port Swigger SSTI Jinja2 Jinja SSTI limited payload SSTI payload On SSTI & bypass of jinja2 Java SSTI SSTI Vietnamese Prevent SSTI with jinja2 Table of contents What SSTI (Server Side Template Injection) SSTI occurs when? Constructing a server-side template injection attack Example attack How to prevent a server-side template injection attack What SSTI (Server Side Template Injection)? A server-side template injection occurs when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side.

Info Website authentication methods can be bypassed, defeated or broken. These vulnerabilities can be some of the most critical as it often ends in leaks of customers personal data.

What is content discovery? Content can be many things, a file, video, picture, backup, a website feature. When we talk about content discovery, we’re not talking about the obvious things we can see on a website; it’s the things that aren’t immediately presented to us and that weren’t always intended for public access.

Subdomain Enumeration Definition: Subdomain enumeration is the process of identifying valid subdomains for a target domain. This is a critical phase of reconnaissance because it expands the attack surface, revealing hidden assets or legacy systems that may contain vulnerabilities.
OSWAP Top 10 Definition: The Open Web Application Security Project (OWASP) is a nonprofit foundation dedicated to improving software security. It operates under an “open community” model, which means that anyone can participate in and contribute to OWASP-related online chats, projects, and more.

Quote A fundamental skill in web security is the manual review of an application to identify vulnerabilities. This involves analyzing the page source, utilizing browser developer tools to inspect elements, debugging scripts, and monitoring network traffic.

Info This article serves as a foundational guide to the essential knowledge required before transitioning into security. Explore the topics below to gain new insights and strengthen your technical baseline.

Info This page for purpose share the idea, community, skillset, technical about Cyber Security and Information Security. How we can improve the skillset via LAB and CTF contest Awesome Articles / Blogs / Collections InfoSec Articles Info The collection of myself about tool and technique is useful for learning and practicing Cyber and Info Security Cloud - Creating unintentional ways to bypass AWS IAM policies when using the “ForAllValues” operator Crypto - Practical Cryptography Forensics - Hiding Information by Manipulating an Image’s Height Forensics - Information hiding Forensics - Modifying Embedded Filesystems in ARM Linux zImages Forensics - Steghide - An Easy way to Hide Confidential Data Inside Images and Sound Objects in Linux General - Medium - Rust for Cyber Security and Red Teaming General - Python for DevSecOps and Any Security Engineer Networking - 10 Useful Open Source Security Firewalls for Linux Systems Networking - Cisco - Configuring Virtual Private LAN Service (VPLS) Networking - Kết nối private LAN qua Cloudflare Tunnels sử dụng Wireguard Networking - Medium - SSH Over Openssl Over Haproxy: Bypassing Blocks Networking - Medium - Top 9 VPN Alternative Technologies For Future Remote Access Networking - Medium - Using Suricata Intrusion Prevention System To Monitor Network Traffic Networking - Medium - VPN is dead? Long live the Jump Host? Networking - What is multiprotocol label switching (MPLS)? Networking - Zero Trust Network Access (ZTNA) vs VPNs Pwnable - Different types of Computer Viruses - Computer Virus Classification Pwnable - Get Reverse-shell via Windows one-liner - Hacking Articles Pwnable - Linux Privilege Escalation - Vietnamese 🌟 (Recommended) Pwnable - Medium - Breaking Free: 26 Advanced Techniques to Escape Docker Containers 🌟 (Recommended) Pwnable - Medium - Docker and runC Vulnerabilities: A Deep Dive into CVE-2024–21626 and Its Counterparts Pwnable - Medium - Ping Power — ICMP Tunnel Pwnable - Wiz.