This is a non-technical guide which will make you familiar with the transport layer. The main purpose of writing this guide is to point out why we need major security implementation on the transport layer. What if the components of this layer get compromised?
Everything about threat intelligence, blue team, red team, pentesting, security audit, security review, testing and assessment.
Showing posts with label http. Show all posts
Showing posts with label http. Show all posts
Thursday, November 14, 2013
Monday, August 12, 2013
Python Service Banner Grabbing Script
Hello Guys I have written some small banner grabbing script in python. It is very simple and basic. By using this script you can check the services any network or domain. You will be able to know which services as well as version of service they are using.
In our penetration testing we do some nmap or other port scanning. After we come to know that these much of ports are opened, we try to find the version of service they are using. We do that in order to find if there is any direct exploit available or not. So in this case this little code will help you to find out the version of services.
Its just basic script which does FTP, HTTP banner grabbing.
Sunday, June 2, 2013
Http Tunneling
Most of the companies and enterprises use proxies and firewalls for their company’s network security. But majority firewalls and proxies block most or all other services but one – http/https. They allow traffic to destination port 80 or 443 to pass in order for their employees to surf the web. So this particular behavior of the firewall can be exploited in order to connect to remote servers with services running on different ports other than 80 or 443. Let us see how.
Subscribe to:
Posts (Atom)