If you have not seen the part 1 of this series then kindly refer that first. You must have seen that how I compromised site(172.16.0.1). Now it is time to attach the cabinet system which has IP 172.16.0.2.
Everything about threat intelligence, blue team, red team, pentesting, security audit, security review, testing and assessment.
Sunday, April 10, 2016
Friday, April 8, 2016
Hack Banking Infrastructure Like Pro - Part 1
Test Lab is an online penetration testing lab which has total 12 system/servers/network devices. Those are purposely mis configured. Upon hacking each single node, you will get token, which needs to be submitted on the website for the verification that will tell whether you have hacked that server successfully or not. Lets dive into.
Labels:
capture the flag,
capturetheflag,
ctf,
dirb,
dvcs,
dvcs tutorial,
hack bank,
nmap
Wednesday, April 6, 2016
Data Center Security/Safety Review & Audit Checklist
Your data center hosts critical data and contains your core assets,
including customer information, intellectual property and other
business-critical data. And with emerging trends such as Big Data,
bring-your-own-device (BYOD) mobility and global online collaboration
sparking an explosion of data, the data center will only become more
important to your organization and will continue to be the target of
advanced malware and other cyber attacks.
Labels:
data center,
DC,
disaster recovery,
DR,
safety & security,
security
Sunday, November 15, 2015
Bugbounty - Password returned in the response in cleartext
Labels:
application security,
appsec,
bugbounty,
halloffame,
infosec,
security
BugBounty-Unexpected application behaviour causing self DoS attack
Labels:
application security,
appsec,
bugbounty,
halloffame,
infosec,
security
Sunday, August 23, 2015
Monday, May 25, 2015
Basic Malware Analysis Techniques
Malware
analysis is an essential activity of being security analyst. In this
post I am going to provide a method of investigating windows machine for
any malware instances. In this post you will learn how to do basic
investigation in order to identify malware on windows system. Not only
this you will also learn to know what type of mawlare that and to which
domains it interacts with.
Thursday, December 25, 2014
NotePad++ v6.6.9 <= Buffer Overflow
Attackers generally use buffer overflows to corrupt the execution stack of a web application. By sending
carefully crafted input to a web application, an attacker can cause the
web application to execute arbitrary code, possibly taking over the
machine. Attackers have managed to identify buffer overflows in a
staggering array of products and components. Buffer overflow flaws can be present in both the web server and
application server products that serve the static and dynamic portions
of a site, or in the web application itself. Buffer overflows found in
commonly-used server products are likely to become widely known and can
pose a significant risk to users of these products. When web
applications use libraries, such as a graphics library to generate
images or a communications library to send e-mail, they open themselves
to potential buffer overflow attacks.
Subscribe to:
Posts (Atom)







