Every year publish the statistics of detected attacks.
These numbers are increasing (30% in 2014, 51% in 2015, 69% in 2016 each regarding the last two years).
According to annual reports, the duration until an attack is detected is 148 days in median. 148 days is a long time to gain persistence, hide, and gather assets.
ᗧ•••ᗣᗣᗣᗣ•• #Python #SRE #DevOps #DevSecOps #ETH #CHFI #CEH #CISSP #RedTeam #BlueTeam
What is ransomware attack?
Million-dollar ransomware payouts, government protection, and ease of access will continue to fuel the growth of cybercrime.
Imagine coming to work and turning on the computer only to see a message that says “repairing file system on C:” or “oops, your important files are encrypted” demanding a payment in bitcoin to decrypt them.
Imagine coming to work and turning on the computer only to see a message that says “repairing file system on C:” or “oops, your important files are encrypted” demanding a payment in bitcoin to decrypt them.
Understanding passwords and their problems - The Good, the Bad, and the Ineffective
Today, with the Internet, social media, personal computers, online banking and everything else that exists, end-users need to create and maintain a large number of usernames and passwords for all of the accounts they have. This begins to create a problem. The many accounts we need to remember leads us to want to share passwords between different platforms, potentially including our work accounts. This is just one of the few contributors to the many password problems that exist today.
A history of passwords
Let’s talk about passwords. In particular, let’s talk about where we’ve come from, where we are at the moment, and where things are going in the future.
What are cookies and how they work?
If you have ever surfed the web, you have almost certainly encountered browser cookies among your digital travels. Although for some they may be a nuisance, for the majority browser cookies are an essential part of the internet experience, often interacting with you without your knowledge.
TLS Perfect Forward Secrecy and Session Resumption
Perfect Forward Secrecy (PFS) is a concept in Transport Layer Security (TLS) that makes sure that even if attackers manage to gain access to the private key of a certificate, they are not able to decrypt communication from the past (or communication in the future, without using active man in the middle attacks).
From Open Wi-Fi to WPA3
Security in Wi-Fi networks has been, at some point non-existent, then questioned, improved and questioned again over the last two decades.
The Wi-Fi certification is a certification program which is backed by the standards developed from the 802.11 IEEE Working Group. Wi-Fi certifications are issued by the Wi-Fi Alliance to devices that comply to one of their certifications, WPA2 for example.
The Wi-Fi certification is a certification program which is backed by the standards developed from the 802.11 IEEE Working Group. Wi-Fi certifications are issued by the Wi-Fi Alliance to devices that comply to one of their certifications, WPA2 for example.
Securing software, together
Software powers virtually everything around us. There is software behind the things we build, the medicine we take, and even the food we eat. Every new breakthrough will be made with the help of software. It is increasingly a challenge to identify something that doesn’t use software today.
Build an effective DevSecOps culture
DevOps, SecOps, now DevSecOps? While the DevOps we all know brings development and operations teams together, DevSecOps adds another process even high-performing DevOps teams can miss: security.
Exploring Further – What is DevSecOps?
DevSecOps works on the premise that security of a software system is a joint responsibility of everyone involved in its development. Understandably then, security must be ensured, and practices followed at every step in the software's development cycle.
What Is DevSecOps?
You’ve probably heard of DevOps, but what about DevSecOps? DevSecOps refers to the concept of making software security a core part of the overall software delivery process.
Docker For Pentesting
In this module we are going to learn docker, nowadays its become more useful for everyone. You can build and deploy services in it in the form of container. It allows you to customize, clone your container, and also you can push/upload a customized image by the docker hub. We can build our penetration testing image easily and use it smoothly in docker. If you want to build a penetration testing lab, its very easy to set up a lab in docker then your host system. So let’s start…
Suscribirse a:
Entradas (Atom)