pastebin - collaborative debugging tool
secsav.kpaste.net RSS


Untitled
Posted by Anonymous on Thu 27th Mar 2014 11:29
raw | new post
view followups (newest first): Untitled by Anonymous
modification of post by Anonymous (view diff)

  1. [[[ WiFi YT vids ]]]
  2.  
  3. https://www.youtube.com/user/NeedSec
  4. https://www.youtube.com/user/Raventattoo/videos
  5. https://www.youtube.com/user/Cyb3rw0rM1/videos
  6.  
  7. # GUI frontend to reaver
  8. http://sourceforge.net/projects/wpscrackgui/
  9.  
  10.  
  11. ---
  12. # HSM from a Raspberry Pi
  13. http://cryptosense.com/building-a-raspberry-pi-hsm-for-rsa-2014/
  14.  
  15. # Shredding files recursively into directories
  16. http://www.linuxforums.org/forum/miscellaneous/46693-how-shred-entire-directory-tree.html#post257616
  17.  
  18. # OpenBSD lol
  19. http://bbs.progrider.org/prog/read/1383465168
  20.  
  21. http://www.iusmentis.com/maatschappij/privacy/filmen-cameratoezicht/
  22.  
  23. # iptables
  24. http://blog.commandlinekungfu.com/2014/01/episode-174-lightning-lockdown.html
  25.  
  26. # /g/ has root to NSA
  27. http://archive.rebeccablacktech.com/g/thread/S39950951#p39950951
  28.  
  29. # Scan the whole Internet in under 45 minutes!
  30. https://zmap.io/
  31.  
  32. # Inception - search RAM contents for interesting stuff
  33. http://www.breaknenter.org/projects/inception/
  34.  
  35. # Subterfuge - Automated MITM Framework
  36. https://code.google.com/p/subterfuge/
  37.  
  38. # Telegram
  39. http://www.thoughtcrime.org/blog/telegram-crypto-challenge/
  40.  
  41.  
  42.  
  43. [[[ SELinux ]]]
  44. # From #centos
  45. Useful resources for SELinux: http://wiki.centos.org/HowTos/SELinux
  46. http://wiki.centos.org/TipsAndTricks/SelinuxBooleans
  47. http://docs.fedoraproject.org/en-US/Fedora/13/html/Security-Enhanced_Linux/
  48. http://fedorasolved.org/security-solutions/selinux-module-building
  49. http://www.youtube.com/watch?v=bQqX3RWn0Yw
  50. http://opensource.com/business/13/11/selinux-policy-guide
  51.  
  52. http://wiki.centos.org/HowTos/SELinux
  53. http://beginlinux.com/server_training/web-server/976-apache-and-selinux
  54. http://docs.fedoraproject.org/en-US/Fedora/13/html/Managing_Confined_Services/
  55.  
  56.  
  57. [ CentOS ]
  58. http://wiki.centos.org/HowTos/OS_Protection
  59.  
  60.  
  61.  
  62. [[[ Theory ]]]
  63. # ECC Primer
  64. http://blog.cloudflare.com/a-relatively-easy-to-understand-primer-on-elliptic-curve-cryptography
  65. http://arstechnica.com/security/2013/10/a-relatively-easy-to-understand-primer-on-elliptic-curve-cryptography/2/
  66. http://blog.serverfault.com/2011/12/12/a-studied-approach-at-wifi-part-1/
  67. http://safecurves.cr.yp.to/
  68.  
  69.  
  70. [ GPG / PGP ]
  71. http://www.gnupg.org/documentation/index.html
  72. http://www.thedrinkingrecord.com/pgpgpg-guide/
  73. http://www.dewinter.com/gnupg_howto/english/GPGMiniHowto.html
  74.  
  75.  
  76.  
  77. [[[ Wikipedia ]]]
  78. https://en.wikipedia.org/wiki/Data_remanence
  79. http://en.wikipedia.org/wiki/PA-DSS
  80.  
  81.  
  82.  
  83. [[[ WebSec ]]]
  84.  
  85. # Want to use my wifi? (cookie spoofing, MITM etc.)
  86. http://thejh.net/written-stuff/want-to-use-my-wifi?
  87.  
  88. http://www.amanhardikar.com/mindmaps/Practice.html
  89.  
  90. # The Web Application Vulnerability Scanners Benchmark
  91. http://sectooladdict.blogspot.se/2014/02/wavsep-web-application-scanner.html?m=1
  92.  
  93. # Bypassing WAF's
  94. http://www.reddit.com/r/netsec/comments/20uhgh/bypassing_web_application_firewalls_using_http/
  95.  
  96. # Hardening WordPress
  97. http://codex.wordpress.org/Hardening_WordPress
  98. http://halfelf.org/2013/false-security/
  99. http://www.esecurityplanet.com/open-source-security/top-5-wordpress-vulnerabilities-and-how-to-fix-them.html
  100. https://wordpress.org/plugins/better-wp-security/
  101. http://wordpress.org/plugins/bulletproof-security/
  102.  
  103. # A seemingly innocent PHP vuln
  104. http://danuxx.blogspot.de/2013/03/unauthorized-access-bypassing-php-strcmp.html
  105.  
  106. # JS crypto
  107. http://www.reddit.com/r/netsec/comments/21ebv7/mylar_encryptdecrypt_your_webapp_data_in_users/
  108.  
  109. ---
  110. https://wiki.ubuntu.com/BasicSecurity
  111. https://wiki.archlinux.org/index.php/Dm-crypt/Specialties#Securing_the_unencrypted_boot_partition
  112.  
  113. http://www.danielmiessler.com/study/infosec_interview_questions/
  114.  
  115.  
  116.  
  117. [[[ Talks & Other videos ]]]
  118. http://makehacklearn.org/2014/03/06/trustycon-videos/
  119.  
  120.  
  121.  
  122. ---
  123.  
  124. [[[ Reddit ]]]
  125. # How to sign kernel for UEFI Secure Boot.
  126. http://www.reddit.com/r/linux/comments/1mw1xb/state_of_securely_booting_linux/
  127.  
  128. # SSL/TLS Deployment Best Practices
  129. http://www.reddit.com/r/netsec/comments/1mn2nk/ssltls_deployment_best_practices/
  130.  
  131. # Physical machine security
  132. http://www.reddit.com/r/netsec/comments/l91d5/physical_laptop_security/
  133.  
  134. # Linux sec
  135. http://www.reddit.com/r/linux/comments/1oobkf/what_kind_of_antimalware_exists_for_linux/
  136.  
  137. # OS under a OS
  138. http://www.reddit.com/r/linux/comments/1qib6u/the_second_proprietary_operating_system_hiding_in/
  139.  
  140. # grsec patches explained
  141. http://www.reddit.com/r/netsec/comments/renu4/grsecurity_pax_configuration_options_explained/
  142.  
  143. # 4 HTTP security headers you should always be using (ibuildings.nl)
  144. http://www.reddit.com/r/netsec/comments/1vztlh/4_http_security_headers_you_should_always_be_using/
  145.  
  146. # Show r/netsec: reveal your true IP address behind proxy/NATs using WebRTC (Firefox/Chrome) (jsfiddle.net)
  147. http://www.reddit.com/r/netsec/comments/1vzsnn/show_rnetsec_reveal_your_true_ip_address_behind/
  148.  
  149. # Laptop security best practices. What do you do? (self.linux)
  150. http://www.reddit.com/r/linux/comments/1zi10c/laptop_security_best_practices_what_do_you_do/
  151.  
  152. # Ever wonder what makes the new ssh-certificate authentication different from ssh-pubkey? This guide explains that and how to use it effectively. (neocri.me)
  153. http://redd.it/1zmsi2
  154.  
  155. # How I got root with Sudo (securusglobal.com)
  156. http://www.reddit.com/r/netsec/comments/20mftq/how_i_got_root_with_sudo/
  157.  
  158. # Hardening a Linux server (self.linux)
  159. http://www.reddit.com/r/linux/comments/1xxpap/hardening_a_linux_server/

Submit a correction or amendment below (click here to make a fresh posting)
After submitting an amendment, you'll be able to view the differences between the old and new posts easily.

Syntax highlighting:

To highlight particular lines, prefix each line with {%HIGHLIGHT}




All content is user-submitted.
The administrators of this site (kpaste.net) are not responsible for their content.
Abuse reports should be emailed to us at