Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
laserspeed
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
MxCheckSec: Validate SPF, DKIM, DMARC, and More
(blog.kulkan.com)
3 points
by
laserspeed
7mo ago
|
1 comments
2.
▲
by
laserspeed
7mo ago
An open-source tool which validates SPF, DKIM, DMARC and provides human-readable output with recommendations on what and how to fix. Available in GitHub at: https://github.com/kulkansecurity/mxchecksec
3.
▲
See no Evil(ginx) / Detecting and stopping AitM phishing threats
(blog.kulkan.com)
1 points
by
laserspeed
7mo ago
|
1 comments
4.
▲
by
laserspeed
7mo ago
Identifying Evilginx instances and a fun ANSI attack. All focused on the community version of Evilginx 3.
5.
▲
Client-Side Path Traversal: Exploiting CSRF in Header-Based Auth Scenarios
(blog.kulkan.com)
1 points
by
laserspeed
11mo ago
|
1 comments
6.
▲
by
laserspeed
11mo ago
In this detailed blog post, Lucas Cebrero Lell walks us through CSPT vulnerabilities and how valuable they are in order to exploit CSRF in apps which have moved away from the typical auth Cookies. There's also a Lab available in github
7.
▲
In4M: Keeping Up with the Latest Infosec News
(github.com)
1 points
by
laserspeed
1y ago
|
1 comments
8.
▲
by
laserspeed
1y ago
In4m is consoled based and summarizes front page hacker-related news from trusted sources (eg hackernews, watchtowr, bleeping computer, ...), showing only titles and links to the original article.
9.
▲
by
laserspeed
1y ago
Agreed! Those are indeed some nice pointers to add.
10.
▲
Security testing of Gitlab self-hosted deployments
(github.com)
3 points
by
laserspeed
1y ago
|
3 comments
11.
▲
by
laserspeed
1y ago
A checklist to help pentesters and auditors assess Self-Hosted GitLab instances. Checks include misconfigurations and weaknesses that could lead to privilege escalation and code or secrets theft/abuse. It's a first version focused
12.
▲
A PoC using Burp Bambdas to show its simplicity for Quick Wins
(blog.kulkan.com)
1 points
by
laserspeed
1y ago
|
1 comments
13.
▲
by
laserspeed
1y ago
Bambdas are small pieces of Java that can be written to perform a wide variety of tasks within Burp, PortSwigger's HTTP(s) Proxy. The article shows how to rely on Bambdas to identify sensitive data across multi-step flows or processes,
14.
▲
Bypassing Watermark Implementations
(blog.kulkan.com)
37 points
by
laserspeed
1y ago
|
9 comments
15.
▲
by
laserspeed
1y ago
Bypassing of different Watermark implementations; including tricks related to Picture-In-Picture, erroneous assumptions at the time of enforcing client-side protections, and then HLS (HTTP Live Streaming) and ways to reassemble videos offli