Statistics > Protocol Hierarchy – Content Map
Opening Statistics > Protocol Hierarchy. Wireshark will show the tree of all protocols in capture with percentage traffic distribution. In five seconds, you can see whether there is HTTP (it is possible to transfer files or credentials), whether...
Search SQL injections manually: from entry point to confirmation
Where to find injection point
A typical mistake is to focus only on GET parameters in the URL. In CTF injection hides anywhere: in cookies, headlines (X-Forwarded-For, Referer, User-Agent), POST data, JSON API fields. In practice...
Essences work as variables. Announced in the block <!DOCTYPE> through <!ENTITY name "value"> and are framed in the document as &name;. Internal stores value right in the ad. External – upload data from a file or URL through a keyword SYSTEM: <!ENTITY xxe SYSTEM "file:///etc/passwd">. It is the...
Installation and first launch of Ghidra
Minimum requirements: 8 GB of RAM (from 4 GB will be closely - JVM will eat resources in the autoanalysis of large binary), JDK 21 and ZIP archive Ghidra.
On Linux (Ubuntu/Debian) installation is reduced to three operations: sudo apt update && sudo apt...
Pwn tools for beginners: GDB, pwntools, checksec
To play all the steps, there are four free tools in Ubuntu or Kali Linux.
GDB + pwndbg. Naked GDB shows hex addresses and does not highlight anything - you can work, but it hurts. The pwndbg extension after each stop draws registers, stacks and...
Why pwntools if there is pure Python and netcat
You can solve pwn-tasks without pwntools. Opening the terminal, connecting through nc, you drive the data, you watch the crash. Problems start when the task requires a little more than entering text from the keyboard.
It is impossible to transmit...
Limit Overrun – TOCTOU vulnerability
The most common type of race clause in CTF. The server checks the condition (Time of Check), then performs the action (Time of Use). Between verification and action – race window, window in units of milliseconds, where you can push parallel requests...
Before you break the token, read it. JWT consists of three parts separated by points: header.payload.signature. Header and payload are base64url-coded JSON objects. Signature is a cryptographic signature calculated by the formula HMAC/RSA(base64url(header) + "." + base64url(payload), secret)...
Virtual vulnerability mechanic: how one argument gives arbitrary read and write
Format string attack occurs in exactly one scenario: the programmer transmits the user input to the first argument in printf() or a related function (sprintf, fprintf, snprintf, syslog). The function awaits a format...
Mechanics OS command injection: what to break and why
Command injection (CWE-78, Improper Neutralization of Special Elements used in an OS Command) is a situation where the application designs a system command from custom input without neutralizing special characters. According to the CWE...
Broadcom has decided to turn the security of popular open source into its own area of responsibility. The company has launched TrueSource, a commercial program that covers Spring, thousands of Java libraries, Python and Node.js ecosystems, container images and several commonly used databases...
The attack on the largest credit protocol Cronos ended in a rare scenario for blockchains: the attacker received assets of about $ 75 million, after which the validators stopped the network and returned the state of the entire chain to the time before the incident. Such a step cancelled most of...
The description of the new hacking campaign itself does not yet show whether its traces remain within a particular corporate network. Positive Technologies has updated PT Fusion and added to the portal closed cyber intelligence reports together with YARA rules based on the analysis of current...
On August 31, a new mass wave of VPN failures began in Russia, in which operators faced the inaccessibility of entire groups of servers and the rapid shutdown of backup addresses. Users in different regions complained about connection breaks, huge ping and situations when recently working...
The rapid growth of computing power for AI has left the security of some platforms far behind. In preparing the third version of the ClusterMAX study, in which SemiAnalysis evaluates the security, performance and reliability of cloud GPU clusters, experts checked 32 clusters from 25 providers...
Blocking a malware control server is usually not enough if the new address can be picked up directly from the blockchain. The specialists of Arctic Wolf discovered at the group Dark Caracal previously unknown modular malware GoCaracal, which is able to restore communication with operators...
A conventional virtual machine has ceased to look like a reliable cell for advanced AI. In the Trail of Bits experiment, the specialized agent GPT-5.6-Cyber three times managed to overcome the boundaries of QEMU/KVM environments, using known vulnerabilities, delayed corrections and self-found...
Cisco routers, which administrators trusted to manage the network and event logs, themselves became a surveillance tool. The China-affiliated Fire Ant cluster captured devices running Cisco IOS XR, intercepted traffic through them, stole credentials and at the same time hid its own activity from...