appsecnotes.blogspot.com
AppSec Notes: Alternatives to the Boring XSS Alert Box
http://appsecnotes.blogspot.com/2014/01/alternatives-to-boring-xss-alert-box.html
Mulling over various topics in application security. Tuesday, January 7, 2014. Alternatives to the Boring XSS Alert Box. Demonstrating that a web application is vulnerable to reflected cross-site scripting (XSS) is not very exciting. It's always kind of like, "oh hey, look here, an alert box popped up when you clicked on that link". Scary. Dramatic. Not! I'll present these techniques using 3 websites that are Internet facing and purposefully built to be susceptible to reflected XSS. Http:/ www.websca...
sniferl4bs.com
agosto 2015 - Snifer@L4b's
http://www.sniferl4bs.com/2015_08_01_archive.html
Archive for agosto 2015. Después de mucho tiempo volvemos con la loca semana en el blog, pero ahora retornamos luego de obtener la certificación tan esperada OSWP me siento orgulloso como también con garras de ir a la secundaria el porque de ello lo siguiente:. Lunes 24 de Agosto. Compartí con todos que el blog retomaba el ritmo ademas de darles a conocer que logre realizar el examen en su totalidad. SniferL4bs retoma su ritmo. Martes 25 de Agosto. OSWP Certified - Misión Cumplida! Miércoles 26 de Agosto.
collegecontest.roqisoft.com
2015全国大学生软件实践与创新能力大赛--软件测试大赛
http://www.collegecontest.roqisoft.com/2015/2015_softwaretesting_contest.html
1)言若金叶软件研究中心官网 http:/ www.leaf520.com. 与备份网 http:/ leaf520.roqisoft.com. 2)诺颀软件论坛 http:/ leaf520.com/bbs. 与备份网 http:/ leaf520.roqisoft.com/bbs. 3)诺颀软件测试团队 http:/ qa.roqisoft.com. 4)言若金叶精品软件著作展示官网 http:/ books.roqisoft.com. 5)言若金叶全国软件工程师培训官网 http:/ training.roqisoft.com. 6)言若金叶全国软件工程师认证官网 http:/ certificate.roqisoft.com. 7)言若金叶自主软件研发 全球知识合作在线跟踪系统 http:/ www.worksnaps.net/. 8)城市空间 Oricity http:/ www.oricity.com. 9)诺颀软件 Roqisoft http:/ www.roqisoft.com. 10)诺颀电子杂志 http:/ jsebook.roqisoft.com. 4)言若金叶精品软件著作展示官...
31ric.com
article | 31ric
http://31ric.com/blog/tag/article
Tricks & Tips. February 17, 2016. Places to go on the Internet to practice your hacking skills. A Series of sites by Acunetix. Web Scanner Test Site. 8211; By the makers of NTO Spider. 8211; by Cenzic. Here is a site that lists some of the above and a bunch more:. 8220; 22 Hacking Sites, CTFs and Wargames. Change your MAC Address. February 17, 2016. On Linux this is quite easy. Some drivers will require your interface to be inactive if you want to do this. Ifconfig eth0 hw ether 11:22:33:44:55:66. Februa...
31ric.com
blogpost | 31ric
http://31ric.com/blog/category/blogpost
Tricks & Tips. February 18, 2016. So here are some cryptography notes for myself for various tests and things I have to study for. 8211; This is a class of cipher that encrypts one bit of data at a time. The length of the encrypted text is the same length as the plain text content. Types of Stream cciphers: RC4. Encrypts data one block at a time. When the data given is an uneven length, then it is padded at the end to create an even block length. PKCS5. Cipher Block Chaining Mode. Sudo apt-get install ent.
domxssscanner.com
Free Web and Network Security Tools | DOM XSS Scanner
http://www.domxssscanner.com/info/tools
Free Web and Network Security Tools. This page lists free Web security tools that you can use to scan Web sites for security related issues or to protect yourself against attacks. Security Tools for the Desktop. Arachni Web Application Security Scanner Framework. JBroFuzz web application fuzzer. GNU Mac Changer Alvaro's web site. GNU Privacy Guard - GnuPG.org. Mantra - Free and Open Source Browser based Security Framework. Metasploit Penetration Testing Software. Nikto Open Source web server scanner.
31ric.com
learn | 31ric
http://31ric.com/blog/category/learn
Tricks & Tips. July 28, 2016. A bit of an older read, but still good: There’s Something About WMI. And finally the whitepaper that got me on this little reading excursion today: Beyond Malware. July 26, 2016. 9 Communication with destination network prohibited. 10 Communication with destination host prohibited. 13 Communication administratively prohibited. February 18, 2016. So here are some cryptography notes for myself for various tests and things I have to study for. Cipher Block Chaining Mode. Places...
31ric.com
31ric | 31ric
http://31ric.com/blog/author/31ricposter
Tricks & Tips. All posts by 31ric. July 28, 2016. A bit of an older read, but still good: There’s Something About WMI. And finally the whitepaper that got me on this little reading excursion today: Beyond Malware. Fun stuff with Volatility. July 27, 2016. Some initial plugins to use:. I generally start any look in memory with the process plugins;. Volpy f memory.file profile=profile choice pslist pslist.txt. To do this, so mad props to him! Volpy f memory.file profile=profile choice procdump D pdump ...