15 items with this tag.

Sep 23, 2026·3 min read

Personal DIY Projects Management

Note The icon to telling you about what task is on progress or pending 😄 ✍ : On progressing, It usually attaches with github and blog 🚧 : Pending, just stop like a note, and idea to doing something around that.

Sep 23, 2026·2 min read

Network traffic monitoring and analysis for anomalies detection and auto-scaling

Why was it gonna released ? NTMA - Project Infrastructure Quote Hi @all, About releasing documentation for final university project, I want to hold this on hand in little bit time but I think It could helped another, therefore, When I contribute and hope It can help you and make solution on near future !!! LOL.

Sep 23, 2026·13 min read

Protect sensitive data and secret files with sops

Quote Hi @all, It’s me again 👋, how is your week ? Back again to my blog, this weekend, I want to sit with you to talk about how to keep your sensitive environment variables or secret files look secure, and able to put in repository.

Sep 23, 2026·16 min read

Server Site Template Injection (SSTI)

Question What SSTI ? How does it work ? What hacker can do with it? How to prevent it? English Resource SSTI from Hackstricks (very detailed explanation) Port Swigger SSTI Jinja2 Jinja SSTI limited payload SSTI payload On SSTI & bypass of jinja2 Java SSTI SSTI Vietnamese Prevent SSTI with jinja2 Table of contents What SSTI (Server Side Template Injection) SSTI occurs when? Constructing a server-side template injection attack Example attack How to prevent a server-side template injection attack What SSTI (Server Side Template Injection)? A server-side template injection occurs when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side.

Sep 23, 2026·8 min read

Cyber101 Session 3 - Authentication Bypass

Info Website authentication methods can be bypassed, defeated or broken. These vulnerabilities can be some of the most critical as it often ends in leaks of customers personal data.

Sep 23, 2026·6 min read

Cyber101 Session 4 - Content Discovery

What is content discovery? Content can be many things, a file, video, picture, backup, a website feature. When we talk about content discovery, we’re not talking about the obvious things we can see on a website; it’s the things that aren’t immediately presented to us and that weren’t always intended for public access.

Sep 23, 2026·3 min read

Cyber101 Session 5 - Subdomain Enumeration

Subdomain Enumeration Definition: Subdomain enumeration is the process of identifying valid subdomains for a target domain. This is a critical phase of reconnaissance because it expands the attack surface, revealing hidden assets or legacy systems that may contain vulnerabilities.

Sep 23, 2026·20 min read

Cyber101 Session 6 - Top 10 OWASP

OSWAP Top 10 Definition: The Open Web Application Security Project (OWASP) is a nonprofit foundation dedicated to improving software security. It operates under an “open community” model, which means that anyone can participate in and contribute to OWASP-related online chats, projects, and more.

Sep 23, 2026·4 min read

Cyber101 Session 2 - Walking An Application

Quote A fundamental skill in web security is the manual review of an application to identify vulnerabilities. This involves analyzing the page source, utilizing browser developer tools to inspect elements, debugging scripts, and monitoring network traffic.

Sep 23, 2026·16 min read

Cyber101 Session 01 - Web Fundamentals

Info This article serves as a foundational guide to the essential knowledge required before transitioning into security. Explore the topics below to gain new insights and strengthen your technical baseline.

Sep 23, 2026·1 min read

Awesome Self Challenges & Writeup CTF

Info Place to store the smartlink to my resource about cyber and information security of myself CTF Writeups Write up - Forensic Hidden Message - ASCIS 2023 PNG Recovery Write up - Hacktheboo 2023 Forensics Write up - GraphQL Hackwekend Self Challenges GitHub - Em0t3t CTF Web & Forensics GitHub - GraphQL Hackwekend .

Sep 23, 2026·6 min read

CVE-2023-34092 - Path Equivalence in Vite (Vietnamese)

Info This post was originally written in Vietnamese; I plan to provide a manual English translation in the future. In the meantime, you can read the Vietnamese original or use Google Translate for an automated English version.

Sep 23, 2026·7 min read

Insecure Direct Object Reference (IDOR)

Info There many thing web you can refer to this stuff Insecure Direct Object Reference – IDOR Vulnerability Tìm kiếm các lỗi IDOR, chưa bao giờ lại dễ đến thế với extension Autorize Automating BURP to find IDORs How-To: Find IDOR (Insecure Direct Object Reference) Vulnerabilities for large bounty rewards What is IDOR Vulnerability, and how does it affect you? Insecure Direct Object Reference Prevention Cheat Sheet What is an IDOR? IDOR stands for Insecure Direct Object Reference and is a type of access control vulnerability.

Sep 23, 2026·4 min read

Awesome Cheatsheets InfoSec

Nuclei Info Fast and customizable vulnerability scanner based on simple YAML based DSL. GitHub - nuclei Nuclei - Documentation Install nuclei For install nuclei, you need to make sure your host installed golang, that is the fastest way to help you install nuclei for your host go install -v github.

Sep 23, 2026·18 min read

Awesome Hacking and InfoSec

Awesome InfoSec Articles & Blogs Articles Info The collection of myself about tool and technique is useful for learning and practicing Cyber and Info Security Cloud - Creating unintentional ways to bypass AWS IAM policies when using the “ForAllValues” operator Crypto - Practical Cryptography Forensics - Hiding Information by Manipulating an Image’s Height Forensics - Information hiding Forensics - Modifying Embedded Filesystems in ARM Linux zImages Forensics - Steghide - An Easy way to Hide Confidential Data Inside Images and Sound Objects in Linux General - Medium - Rust for Cyber Security and Red Teaming General - Python for DevSecOps and Any Security Engineer Networking - 10 Useful Open Source Security Firewalls for Linux Systems Networking - Cisco - Configuring Virtual Private LAN Service (VPLS) Networking - Kết nối private LAN qua Cloudflare Tunnels sử dụng Wireguard Networking - Medium - SSH Over Openssl Over Haproxy: Bypassing Blocks Networking - Medium - Top 9 VPN Alternative Technologies For Future Remote Access Networking - Medium - Using Suricata Intrusion Prevention System To Monitor Network Traffic Networking - Medium - VPN is dead? Long live the Jump Host? Networking - What is multiprotocol label switching (MPLS)? Networking - Zero Trust Network Access (ZTNA) vs VPNs Pwnable - Different types of Computer Viruses - Computer Virus Classification Pwnable - Get Reverse-shell via Windows one-liner - Hacking Articles Pwnable - Linux Privilege Escalation - Vietnamese 🌟 (Recommended) Pwnable - Medium - Breaking Free: 26 Advanced Techniques to Escape Docker Containers 🌟 (Recommended) Pwnable - Medium - Docker and runC Vulnerabilities: A Deep Dive into CVE-2024–21626 and Its Counterparts Pwnable - Medium - Ping Power — ICMP Tunnel Pwnable - Wiz.