Am Di, 5. Sept. um 11 Uhr: TechKafi #ruby ☕ - Web Security Refresh! 🚀
Buzzwords wie SQL Injection, XSS, CSRF, CSP sind uns bekannt, aber kennen wir wirklich alle Abwehrstrategien? Pascal Zumkehr bringt Licht ins Dunkel und erklärt Sicherheitslücken von Webapps samt Gegenmaßnahmen. Der Code ist in Ruby, doch die Lösungen gelten branchenweit.
https://www.puzzle.ch/de/blog/articles/2023/08/29/tech-kafi-ruby-web-security-refresher
#WebSecurity #Ruby #Cybersecurity #WebAppSecurity #TechEvent #SecurityRefresh #PuzzleEvents #TechTalk #WebDev #Coding
#Coding #WebDev #techtalk #puzzleevents #securityrefresh #techevent #WebAppSecurity #CyberSecurity #WebSecurity #Ruby
Discover the power of browser fingerprinting: personalize user experience, enhance fraud detection, and optimize login security.
Learn how it identifies visitors and enhances authentication: https://thehackernews.com/2023/06/the-power-of-browser-fingerprinting.html
Attacking .Net Web services https://securifera.com/blog/2023/03/06/attacking-net-web-services/ #Pentesting #WebSecurity #Hacking #Infosec
#InfoSec #Hacking #WebSecurity #pentesting
Gracefully handle EC2 instance shutdown within Kubernetes https://github.com/aws/aws-node-termination-handler #Pentesting #Kubernetes #WebSecurity #Infosec
#InfoSec #WebSecurity #kubernetes #pentesting
MSMAP - Memory WebShell Generator https://kitploit.com/2022/11/msmap-memory-webshell-generator.html #Pentesting #WebSecurity #Infosec
#InfoSec #WebSecurity #pentesting
A curated list of Web Security materials and resources. https://github.com/qazbnm456/awesome-web-security#prototype-pollution #Pentesting #WebSecurity #Infosec
#InfoSec #WebSecurity #pentesting
Interesting "Stealing passwords from infosec Mastodon - without bypassing CSP" by @gaz.
https://portswigger.net/research/stealing-passwords-from-infosec-mastodon-without-bypassing-csp
It says at the end that the vulnerability was only exploitable in the #Glitch fork (used by that instance), not #Mastodon itself.
Still, despite the slightly misleading title, that's some good research, and an interesting well-written article. 😄
#glitch #mastodon #InfoSec #cybersecurity #codeinjection #WebSecurity
Winning QR with DOM-Based XSS | Bug Bounty POC https://medium.com/@haroonhameed_76621/winning-qr-with-dom-based-xss-bug-bounty-poc-4b4048cf285d #Pentesting #BugBounty #WebSecurity #Infosec
#InfoSec #WebSecurity #bugbounty #pentesting
Password Brute force #infosec #cybersecurity #pentesting #oscp #informationsecurity #hacking #cissp #redteam #technology #DataSecurity #CyberSec #Hackers #tools #bugbountytips #Linux #websecurity #Network #NetworkSecurity #cybersecurityawareness
#infosec #cybersecurity #pentesting #oscp #informationsecurity #Hacking #cissp #redteam #technology #datasecurity #cybersec #hackers #tools #bugbountytips #linux #WebSecurity #network #networksecurity #cybersecurityawareness
Сборник заметок, чеклистов, райтапов для AppSec, Bug Bounty Hunting, Web Application Security.
A Collection of Notes, Checklists, Writeups on Bug Bounty Hunting and Web Application Security.
https://github.com/HolyBugx/HolyTips
#api
#checklist
#security
#web
#webapp
#pentesting
#writeups
#bugbounty
#pentest
#websecurity
#api_security
#bugbountytips
#bugbounty_writeups
#bugbounty_writeups #bugbountytips #api_security #WebSecurity #pentest #bugbounty #writeups #pentesting #webapp #web #security #checklist #api
SSRFire - An Automated SSRF Finder. Just Give The Domain Name And Your Server And Chill! Also Has Options To Find XSS And Open Redirects https://kitploit.com/2022/02/ssrfire-automated-ssrf-finder-just-give.html #Pentesting #WebSecurity #Infosec
#InfoSec #WebSecurity #pentesting
A technique to semi-automatically discover new vulnerabilities in WordPress plugins https://kazet.cc/2022/02/03/fuzzing-wordpress-plugins.html #Pentesting #WebSecurity #Vulnerability #Infosec
#InfoSec #vulnerability #WebSecurity #pentesting
Zabbix - A Case Study of Unsafe Session Storage https://blog.sonarsource.com/zabbix-case-study-of-unsafe-session-storage #Pentesting #WebSecurity #Infosec
#InfoSec #WebSecurity #pentesting
Domain Escalation – sAMAccountName Spoofing https://pentestlab.blog/2022/01/10/domain-escalation-samaccountname-spoofing/ #Pentesting #RedTeam #WebSecurity #Hacking #Infosec
#InfoSec #Hacking #WebSecurity #redteam #pentesting
Guide to SQL Injection Attack - https://t.co/923QRYBNvH
SQL Injection Is an Attack Used by Hackers to Inject Malicious Codes in SQL Statements
#WebSecurity #CyberAttack #sqlinjection #SQL