15 items with this tag.

Note The icon to telling you about what task is on progress or pending 😄 ✍ : On progressing, It usually attaches with github and blog 🚧 : Pending, just stop like a note, and idea to doing something around that.
Why was it gonna released ? NTMA - Project Infrastructure Quote Hi @all, About releasing documentation for final university project, I want to hold this on hand in little bit time but I think It could helped another, therefore, When I contribute and hope It can help you and make solution on near future !!! LOL.

Quote Hi @all, It’s me again 👋, how is your week ? Back again to my blog, this weekend, I want to sit with you to talk about how to keep your sensitive environment variables or secret files look secure, and able to put in repository.

Question What SSTI ? How does it work ? What hacker can do with it? How to prevent it? English Resource SSTI from Hackstricks (very detailed explanation) Port Swigger SSTI Jinja2 Jinja SSTI limited payload SSTI payload On SSTI & bypass of jinja2 Java SSTI SSTI Vietnamese Prevent SSTI with jinja2 Table of contents What SSTI (Server Side Template Injection) SSTI occurs when? Constructing a server-side template injection attack Example attack How to prevent a server-side template injection attack What SSTI (Server Side Template Injection)? A server-side template injection occurs when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side.

Info Website authentication methods can be bypassed, defeated or broken. These vulnerabilities can be some of the most critical as it often ends in leaks of customers personal data.

What is content discovery? Content can be many things, a file, video, picture, backup, a website feature. When we talk about content discovery, we’re not talking about the obvious things we can see on a website; it’s the things that aren’t immediately presented to us and that weren’t always intended for public access.

Subdomain Enumeration Definition: Subdomain enumeration is the process of identifying valid subdomains for a target domain. This is a critical phase of reconnaissance because it expands the attack surface, revealing hidden assets or legacy systems that may contain vulnerabilities.
OSWAP Top 10 Definition: The Open Web Application Security Project (OWASP) is a nonprofit foundation dedicated to improving software security. It operates under an “open community” model, which means that anyone can participate in and contribute to OWASP-related online chats, projects, and more.

Quote A fundamental skill in web security is the manual review of an application to identify vulnerabilities. This involves analyzing the page source, utilizing browser developer tools to inspect elements, debugging scripts, and monitoring network traffic.

Info This article serves as a foundational guide to the essential knowledge required before transitioning into security. Explore the topics below to gain new insights and strengthen your technical baseline.
Info Place to store the smartlink to my resource about cyber and information security of myself CTF Writeups Write up - Forensic Hidden Message - ASCIS 2023 PNG Recovery Write up - Hacktheboo 2023 Forensics Write up - GraphQL Hackwekend Self Challenges GitHub - Em0t3t CTF Web & Forensics GitHub - GraphQL Hackwekend .

Info This post was originally written in Vietnamese; I plan to provide a manual English translation in the future. In the meantime, you can read the Vietnamese original or use Google Translate for an automated English version.
Info There many thing web you can refer to this stuff Insecure Direct Object Reference – IDOR Vulnerability Tìm kiếm các lỗi IDOR, chưa bao giờ lại dễ đến thế với extension Autorize Automating BURP to find IDORs How-To: Find IDOR (Insecure Direct Object Reference) Vulnerabilities for large bounty rewards What is IDOR Vulnerability, and how does it affect you? Insecure Direct Object Reference Prevention Cheat Sheet What is an IDOR? IDOR stands for Insecure Direct Object Reference and is a type of access control vulnerability.
Nuclei Info Fast and customizable vulnerability scanner based on simple YAML based DSL. GitHub - nuclei Nuclei - Documentation Install nuclei For install nuclei, you need to make sure your host installed golang, that is the fastest way to help you install nuclei for your host go install -v github.
Awesome InfoSec Articles & Blogs Articles Info The collection of myself about tool and technique is useful for learning and practicing Cyber and Info Security Cloud - Creating unintentional ways to bypass AWS IAM policies when using the “ForAllValues” operator Crypto - Practical Cryptography Forensics - Hiding Information by Manipulating an Image’s Height Forensics - Information hiding Forensics - Modifying Embedded Filesystems in ARM Linux zImages Forensics - Steghide - An Easy way to Hide Confidential Data Inside Images and Sound Objects in Linux General - Medium - Rust for Cyber Security and Red Teaming General - Python for DevSecOps and Any Security Engineer Networking - 10 Useful Open Source Security Firewalls for Linux Systems Networking - Cisco - Configuring Virtual Private LAN Service (VPLS) Networking - Kết nối private LAN qua Cloudflare Tunnels sử dụng Wireguard Networking - Medium - SSH Over Openssl Over Haproxy: Bypassing Blocks Networking - Medium - Top 9 VPN Alternative Technologies For Future Remote Access Networking - Medium - Using Suricata Intrusion Prevention System To Monitor Network Traffic Networking - Medium - VPN is dead? Long live the Jump Host? Networking - What is multiprotocol label switching (MPLS)? Networking - Zero Trust Network Access (ZTNA) vs VPNs Pwnable - Different types of Computer Viruses - Computer Virus Classification Pwnable - Get Reverse-shell via Windows one-liner - Hacking Articles Pwnable - Linux Privilege Escalation - Vietnamese 🌟 (Recommended) Pwnable - Medium - Breaking Free: 26 Advanced Techniques to Escape Docker Containers 🌟 (Recommended) Pwnable - Medium - Docker and runC Vulnerabilities: A Deep Dive into CVE-2024–21626 and Its Counterparts Pwnable - Medium - Ping Power — ICMP Tunnel Pwnable - Wiz.