Best of SecuritySeptember 2022

  1. 1
    Article
    Avatar of communityCommunity Picks·4y

    Best practices for creating a modern npm package

    You will first learn how to create an npm package, so you can get familiar with building and publishing a package. Then you’ll learn what’s involved with making a more robust and production-ready package by setting up a test framework, a continuous integration and deployment pipeline, security checks, and automated semantic npm publish.

  2. 2
    Article
    Avatar of freecodecampfreeCodeCamp·4y

    Authentication vs Authorization – What's the Difference?

    authentication is the process of verifying the credentials a user provides with those stored in a system to prove the user is who they say they are. You only need a single factor to authenticate, with the most common being a password. Authorization can either grant or deny permission to carry out tasks, or access areas of an application.

  3. 3
    Article
    Avatar of systemweaknessSystem Weakness·4y

    How attackers can bypass 2FA

    There are several ways to implement 2FA: SMS 2FA, Authenticator App, Push-based 2FA and Security Keys. If the service you use to send SMS to users is compromised, your users are also at risk.

  4. 4
    Article
    Avatar of systemweaknessSystem Weakness·4y

    Hacking Wireless Networks around the Globe.(Practical WIFI Hacking)

    Wifi hacking is essentially cracking the security protocols in a wireless network, granting full access for the hacker to view, store, download, or abuse the wireless network. Usually, when someone hacks into a Wifi, they are able to observe all the data that is being sent via the network.

  5. 5
    Article
    Avatar of infosecwriteupsInfoSec Write-ups·4y

    How I Hacked my College’s student portal

    The student portal is a third party web portal for students in which students can check their time table, attandance, profile, fee dues and many other stuff. It was a simple IDOR bug with a huge impact. The leaked data also have 10th and 12th class marks.

  6. 6
    Article
    Avatar of freecodecampfreeCodeCamp·4y

    Linux for Hackers – Basics for Cybersecurity Beginners

    The Linux kernel was created by Linus Torvalds in 1991. Each combination of customisations is called a distribution or distro for short. Each of them has been optimised for a specific purpose, or just for fun. Another alternative is to install Steam, or better still, SteamOS if you are a gamer with a flair for Linux. The Linux OS has a directory tree.

  7. 7
    Article
    Avatar of codemotionCodemotion·4y

    Developer Books That You Should Read: a Community Driven List

    A Community Driven List is a list of unmissable titles for programmers with some recommendations by our community members worldwide. Do you have a book about interesting topics for devs? Send it to us and we will publish it on this community-driven list. Send your dev book review!

  8. 8
    Article
    Avatar of pointerPointer·4y

    How Passwordless Works

    Passwordless is a form of authentication that doesn't require users to provide their username during login. WebAuthn is a complex standard with many moving parts, including the FIDO2 specifications. Since they aren't stored in the authenticator, the Relying Party has to send the key handles back. There can be no credential selection without talking to the RP.

  9. 9
    Article
    Avatar of systemweaknessSystem Weakness·4y

    How to hack millions of Routers.

    router hacking is when a cybercriminal takes control of your router without your consent. Wi-Fi hacking relies on the cybercriminal overcoming your security measures typically your router’s admin password or an unpatched vulnerability. Hackers have many tricks for pulling off a successful router hack.

  10. 10
    Article
    Avatar of gamedeveloperGame Developer·4y

    Rockstar Games hacker identified, arrested by London police

    The hacker was arrested in Oxfordshire and is said to be 17 years old. The hacker breached Rockstar's security and released in-development footage of Grand Theft Auto VI. Rockstar Games said it would be working with the FBI and US Department of Justice to find whoever was responsible.

  11. 11
    Article
    Avatar of theregisterThe Register·4y

    Hacker steals Grand Theft Auto 6 source code, videos

    Hacker steals Grand Theft Auto 6 source code, videos, source code from Rockstar Games subsidiary. Company says it has taken steps to "isolate and contain this incident" No definitive release date has been announced but reports suggest game won't debut for at least another year or two.

  12. 12
    Article
    Avatar of tcTechCrunch·4y

    Massive GTA 6 gameplay video leak depicts male and female playable characters

    A new purported leak could offer us our best look yet at GTA 6. The trove of data was discovered via a GTAForums post by an alleged hacker.

  13. 13
    Article
    Avatar of devtoDEV·4y

    The Complete List of Heroku Alternatives to Consider

    Heroku will be shutting down its free tier in the coming months. Starting October 26, 2022, we will begin deleting inactive accounts and associated storage for accounts that have been inactive for over a year. Some people are looking for free alternatives to replace their current Heroku arrangement. Some are smaller companies that are just getting started.

  14. 14
    Article
    Avatar of apolloApollo Blog·4y

    Announcing Apollo Router v1.0

    Apollo Router is our next-generation supergraph runtime that supports Apollo Federation (v1 or v2) - a declarative GraphQL architecture that lets you build and operate a modular GraphQL API. With Apollo Router v1.0, apps querying the supergraph can @defer the slow, non-essential parts.

  15. 15
    Article
    Avatar of codemotionCodemotion·4y

    5 tips for Microservices good practices

    Microservices architecture makes the quantum leap in this industry possible: a flexible, scalable, and durable corporate architecture. In this article, we will discuss 5 tips for microservices and good practices that will allow you to achieve excellent outcomes with comparatively minimal effort. The advantages of microservices architecture over traditional monolithic design are numerous.

  16. 16
    Article
    Avatar of devtoDEV·4y

    Debunking myths about HTTPS

    The purpose of HTTPS is to secure the transit but data can be intercepted in various places, for example, on web servers or databases.

  17. 17
    Article
    Avatar of drDark Reading·4y

    Most Attackers Need Less Than 10 Hours to Find Weaknesses

    The average ethical hacker can find a vulnerability that allows the breach of the network perimeter and then exploit the environment in less than 10 hours. Nearly three-quarters of ethical hackers think most organizations lack the necessary detection and response capabilities to stop attacks.

  18. 18
    Article
    Avatar of theregisterThe Register·4y

    Is it time to retire C and C++ for Rust in new programs?

    Microsoft's CTO tweeted that Rust won't replace its older brothers tomorrow. It will take years – indeed decades – but it will happen. We've ignored security for generations, but now that our entire economy depends on secure technology, we can't afford to be so cavalier with our programs. Now, both C and C++ are very flexible,

  19. 19
    Article
    Avatar of bytebytegoByteByteGo·4y

    EP25: How Apple/Google Pay handle card info. Also...

    Postman simplifies each step of the API lifecycle and streamlines collaboration so you can create better APIs. The platform is cloud-native and includes the comprehensive suite of features enterprises are looking for, including SSO, audit, platform security, and much more.

  20. 20
    Article
    Avatar of dzDZone·4y

    A Guide to Endpoint Protection

    The Ponemon 2020 State of Endpoint Security Risks Report revealed that more than 50% of respondents said that their companies are poor at handling endpoint security threats. Insider Threat Studies show that almost 95% of all cybersecurity breaches are a result of human error. Insider threat includes the actions of a contractor or employee inside the company that either maliciously or accidentally causes a breach.

  21. 21
    Article
    Avatar of infosecwriteupsInfoSec Write-ups·4y

    How I hacked an exam portal and got access to 10K+ users data including webcams

    How I hacked an exam portal and got access to 10K+ users data including webcams Hello guys, I am Faique a security researcher and a bug bounty hunter.