Join us at 7pm this Saturday for a interactive hands-on session on DevSecOps by our respected senior Sir Hassan Mussana. He has been in the industry for more than 6 years and Specialises in Cloud Security.
Check out his profile on LinkedIn:
https://t.co/9fb8DVXZjW
Title: Threat Intelligence
Date: 18 Sep 2021
Organizer: @FastianYasir (Research Scientist)
Description: the role of threat intel? Prevention, And the defense
Hurdles: Thoroughly research about WannaCry Ransomware.
#SSH#bsides#bsidesislamabad#bsidespakistan#infosec
Title: JavaScript
Date: 10 Sep 2021
Organizer: @u_ahmedofficial
Description: we discussed JS. How user input filed cannot be trusted and lead to major vulnerabilities, IDOR, DOM XSS, client-side validation bypass.
Hurdles: Practise different types of scripts that result in shells
Title: Brute Force
Date: 9 Sep 2021
Organizer: @u_ahmedofficial
Description: we discussed Brute force on web applications. How cewl can help us to fast the process.
Hurdles: Practice high-level vulnerability with the help of hydra, cewl, crunch.
#SSH#bsides
Title: CSRF
Date: 7 Sep 2021
Organizer: @u_ahmedofficial
Description: we discussed CSRF. We learned how to combine different vulnerabilities and take over another person's account without his knowledge (XHR), CORS etc.
Hurdles: Practice medium-level security by yourself.
Title: local file inclusion
Date: 5 Sep 2021
Organizer: @u_ahmedofficial
Description: In this session we discussed LFI. How can we check the content of web servers and other sensitive information?
Hurdles: Log poisoning through LFI and Shell through User-Agent.
#SSH#bsides
Title: Command injections
Date: 4 Sep 2021
Organizer: @u_ahmedofficial
Description: we discussed how unsanitized dangerous functions can result in vulnerabilities. Shell execution.
Hurdles: why exec, system, eval dangerous function of PHP. reverse shell bind shell and tty shell
Title: File Uploads
Date: 2 Sep 2021
Organizer: @u_ahmedofficial
Description: we discussed what type of vulnerabilities comes with file upload. And if not properly sanitized, result in high-level exploits.
Hurdles: what is an exif tool. See the difference between Dhanush, jle3
Title: SQLI
Date: 1 Sep 2021
Organizer: @u_ahmedofficial
Description: we discussed SQL injection types. How do these vulnerabilities work and how can we breach databases.
Hurdles: What are DIOS quires. Check articles written by SecurityIdiots on SQLI.
#SSH#bsides#infosec
Session title: XSS
Date: 17 July 2021
Organizer: @u_ahmedofficial
Description: In this session, we discussed XSS attacks, their types, real-world usage including account takeover
Hurdles: Try 10 different scripts of each type. So, in total there would be 30, Practice Portswigger
[+] Excited to join SSH? Below are the steps
[*] Signup on https://t.co/3sy7IeC8CV
[*] Fill this form https://t.co/13Sz0UhN5R
[*] After all the steps DM @u_ahmedofficial (https://t.co/mRLUUCRW0h)
[*] Highly recommended THM Rooms, complete these:
Signalianz Security Hub - SSH : Conducted a series of sessions for SSH society to enable them to understand the basic OWASP top 10 concepts, their use case in terms of Pentests and Bug-bounty, practices real-world cases, participants did some hurdles.
#SSH#bsides
Deadline for the "Digital Pakistan Cybersecurity Hackathon 2021" is September 5, 2021.
Get registered Now! Find more details here: https://t.co/EZY9eOXnBh
#CybersecurityHackathon21#MOITT#CyberSecurity
Join us on our first episode of TechTalk series where we discuss technical topics in Plain Urdu 😎. Shoutout to the collaborating university #cybersecurity societies.
#Pakistan
🚨⚠️ Mark your calendars ⚠️🚨
@sudossh and @BSidesPakistan welcome you all to the 1st episode of a Tech-talk series where tech is discussed in a pure desi way.
Speaker : Said Wali
Topic : Kerberos Authentication
Dated : 28th of August
Time : 1900 hrs PKT