Welcome to no-sec blog, where a team of passionate Telekom MMS pentesters shares their insights and expertise from the world of cybersecurity. From CVE write-ups to practical guides on exploitation techniques and defense strategies, we aim to contribute valuable knowledge to the security community.
Hooking Burp Suite in Client Software Communication
Ever came across the issue to redirect HTTP(S) traffic to Burp Suite originating from client software that is not supporting to configure a proxy? Well there are tools like proxychains to do this. But there might be situations were those tools are not suitable. Another way is using the hosts file combined with Burp Suite’s built-in features.
Read more ⟶The Future of Bitcoin
Bitcoin is getting traction and attention by mainstream media. Price hits all time high at 3000$ and stays above the gold price. At the same time the Bitcoin community is meeting their biggest challenge so far. The question of ‘How to scale Bitcoin?’ This was discussed for two days at the Future of Bitcoin conference in Arnheim / Netherlands, with developers, researchers and miners.
Read more ⟶Security of Things – World Conference
High level atmosphere. High level management. High level topics. The companies represented came from nearly every industry sector banking, energy, telecommunication, government, manufacturing & chemical industry as well as retail, entertainment, transportation, automotive and of course IT security. The delegates and speakers were all C-level management and mostly CIO / CISO.
Read more ⟶Ergonomic Password Generator
To secure applications it is often necessary to verify the identity of the user, this process is called authentication. There are several methods to authenticate a user, with passwords being the most common one. Passwords are usually chosen by the user. Those user passwords are often not strong enough and can be easily guessed by brute forcing or simple deduction (e.g. pet names etc.).
Read more ⟶Immutable, reliable, secure – A brief history of blockchain security
Blockchain technology is marketed as the Web 3.0 and because of it’s distributed structure it wipes out single points of failure. But does that mean there are no points of failures at all? Let’s look at some important blockchain hacks / failures from the tech perspective.
Read more ⟶Fingerprinting of web browsers and the consequences for privacy
Fingerprinting of web browsers is a known technique to identify website users. This enables to track users and their habits across websites without the use of cookies. Approximately 93 percent of Web browsers have a unique fingerprint. Particularly meaningful are lists of installed plugins, screen resolution, time zone, language and fonts.
Read more ⟶DefCon 24
After Troopers 2016 and Hack In the Box, my year of conferences ends with the DefCon 24 in Las Vegas Bally’s & Paris Casino which was with about 22,000 attendees/hackers one of the largest hacker conferences. In this post I would like to give my personal impression of this great conference.
Read more ⟶Web Shells and Backdoors
In April 2016 researchers of the Stony Brook University and Ruhr-University Bochum published a study about (malicious) PHP web shells with the title “No Honor among Thieves A Large-Scale Analysis of Malicious Web Shells”.
Read more ⟶Using Chrome Logger in BurpSuite
In February of this year, a blog post by the OWASP ZAP newsletter has pointed us towards an interesting technology called Chrome Logger. Chrome Logger can be used to display server side debugging information into the web console (e.g. in Firefox) at runtime.
Read more ⟶Using Whitelisting to control file access in Apache Webserver
You want to control which files on your webserver can be accessed by whom, but you don’t want to use blacklisting. You want to say, i.e., external users can access files whose names end with .php, .jpg and .png. All other files must not be accessible, no matter which name they have.
Read more ⟶