Best of SecurityOctober 2022

  1. 1
    Article
    Avatar of linuxhandbookLinux Handbook·4y

    Podman vs Docker: What's the Difference?

    Docker's core runs as a "system daemon" i.e. as a daemon executed by the root user. Red Hat unveiled Podman as an alternative to Docker in 2018. The advantage of using Podman is visible here. Podman does not have a daemon running, and certainly doesn't have any strict requirements for root access.

  2. 2
    Article
    Avatar of systemweaknessSystem Weakness·4y

    WIFI Hacking

    Any network adapter that can be switched to monitor mode and packet injection mode is required. “wifite’s’ is preinstalled in Kali Linux.

  3. 3
    Article
    Avatar of systemweaknessSystem Weakness·4y

    Dark Web Introduction

    The Deep Web allows users to view information that is normally hidden behind closed doors, such as pages and databases. The dark web is not accessible through standard browsers and operates in a different manner than the ordinary DarkOwl Vision: A threat intelligence service that includes a Dark web scanner as an information source.

  4. 4
    Article
    Avatar of bytebytegoByteByteGo·4y

    EP26: Proxy vs reverse proxy

    CDN Postman is the API platform for building and using APIs (sponsored) Postman simplifies each step of the API lifecycle and streamlines collaboration so you can create better APIs—faster. The platform is cloud-native and includes the comprehensive suite of features enterprises are looking for.

  5. 5
    Article
    Avatar of keycdnkeycdn·4y

    API Security: The Complete Guide

    API security is a crucial consideration when developing and designing APIs. As serverless architectures and microservices are getting more popular, most enterprise applications depend on the API. This attack is detected when a malicious attacker changes or tries to change parameters across a series of API calls to request sensitive data that only authorized personnel are allowed to access.

  6. 6
    Article
    Avatar of communityCommunity Picks·4y

    Reverse Proxy vs. Forward Proxy: The Differences

    Reverse proxy vs Forward Proxy: The Differences Back to blog1666902057.72391514e Iveta Vistorskyte. In general, proxies are intermediaries between a user and a web server. In this article, we’ll explain the differences between the forward vs reverse proxy servers.

  7. 7
    Article
    Avatar of infosecwriteupsInfoSec Write-ups·4y

    JSON Web Tokens

    Each JWT is additionally signed using cryptography (hashing) to ensure that the contents of the JWT cannot be changed by the client or an unsavory party. The JWT will be delivered as a parameter or authorization header from the user agent whenever the user tries to access a protected resource, such as an API or a protected route.

  8. 8
    Article
    Avatar of spaceliftSpacelift·4y

    44 Books for DevOps, Site Reliability, and Cloud Engineers

    44 Books for DevOps, Site Reliability, and Cloud Engineers & Architects are available online. The list includes a collection of free and paid books in various areas and links to them. If your favorite book isn’t mentioned, please drop a comment below.

  9. 9
    Article
    Avatar of freecodecampfreeCodeCamp·4y

    Computer Programmer Salary – How Much Do Coders Make?

    Coding is one of the most popular and in-demand careers. A computer programmer's salary will generally be lower than someone with a few years of industry experience under their belt. Another option is to learn to code on your own using either free or paid resources such as books, video tutorials, and interactive courses.

  10. 10
    Article
    Avatar of logrocketLogRocket·4y

    Comparing Elixir with Rust and Go

    Elixir is a functional and concurrent programming language built on top of Erlang. Elixir uses the Supervisor and Application model to build fault-tolerant systems. Elixir also uses the BEAM virtual machine, a fast compiler that compiles Erlang code into bytecode.

  11. 11
    Article
    Avatar of dzDZone·4y

    Best Practices for Securing Your Repository

    The GitHub Marketplace was first introduced during the GitHub Universe in 2016. Navigate to the GitHub repository and have a look at how actively the maintainers and contributors are pushing into the project. Do they provide basic example usage, like a simple YAML file to start?

  12. 12
    Article
    Avatar of tnwThe Next Web·4y

    3 hot tech careers in 2023

    Aisling O'Toole is a journalist who, over the past 15 years, has edited some of Ireland's leading publications. The tech scene is currently experiencing levels of growth we haven’t seen since the early days of the dot.com bubble.

  13. 13
    Article
    Avatar of systemweaknessSystem Weakness·4y

    My top 5 browser add-ons for improved security

    i will be taking you through 5 browser add-ons that every internet user should have on their browsers. Privacy Badger sends the Global Privacy Control signal to opt you out of data sharing and selling, and the Do Not Track signal to tell companies not to track you.

  14. 14
    Article
    Avatar of pointerPointer·4y

    vercel/turbo: Incremental bundler and build system optimized for JavaScript and TypeScript, written in Rust – including Turborepo and Turbopack.

    Turborepo is an next-generation toolchain for frontend development, written in Rust. The Turbo community can be found on GitHub Discussions, where you can ask questions, voice ideas, and share your projects. To chat with other community members, you can join the Turbo Discord Our Code of Conduct.

  15. 15
    Article
    Avatar of communityCommunity Picks·4y

    What is wrong with Apple Passkeys?

    Apple introduced a controversial ‘improvement’ to webauthn called Passkeys, which could impair the security of your most valuable online resources. With ‘pre-Passkeys passwordless’, you could secure the trust relationship between your computer and a service, say, a crypto exchange. When Passkeys proponents say it is a huge step forward.

  16. 16
    Article
    Avatar of awstipAWS Tip·4y

    Highly Available 3-Tier Architecture Web Application in AWS

    A 3-Tier Architecture Web Application is made up of 3 separate tiers. There are several benefits to this architecture in that it scales horizontally as it needs to. For the private route tables, I split mine up into App Tier and DB Tier. You’ll also target the 2 private subnets (App-private1 and App-private 2).

  17. 17
    Article
    Avatar of dzDZone·4y

    Automate Boring Tasks With Hooks

    GitGuardian's Sofien describes how pre-commit hooks are used to save time and secure commits company-wide. Hooks are a way to fire off custom scripts when certain important actions occur. The first set of hooks checks the syntax of JSON and YAML files, while the check-added-large- Files ensure that no one commits a huge file by mistake. Pre-commit Hooks and CI jobs are complementary.

  18. 18
    Article
    Avatar of logrocketLogRocket·4y

    Using Next.js security headers to strengthen app security

    Using security headers to strengthen app security is a highly effective way to secure websites from common security threats such as cross-site scripting (XSS) and clickjacking. In this article, we’ll learn about security headers, their roles in website security, and how to add them to a Next.js application. The header also allows us to set custom security policies for various resources, including images and other media, fonts, styles, scripts, and more.

  19. 19
    Article
    Avatar of faunFaun·4y

    Resources & Learning Paths collections (Part-2)

    The Raspberry Pi is a series of credit card-sized single-board computers developed in the United Kingdom by the… github.com.com 18. The RaspberryPi is a curated list of awesome Raspberry Pi tools, projects and projects. For more information, you can find out more to see the Raspberry Pi project list in a new post on Twitter. The list also includes a list of projects and other projects that are related to the Linux ecosystem. For more details on the RaspberryPi and other Linux tools and projects that can be found on Twitter and Facebook and other social media sites.

  20. 20
    Article
    Avatar of codemagiccodemagic·4y

    How to build a Chrome extension with Flutter Web

    Google Chrome extensions are small programs that extend Chrome’s functionality. Google Chrome has a standardized API through which extensions can perform various tasks. In this tutorial, we are going to learn how to make a Chrome extension using Flutter Web. To add a background script to a Flutter Chrome extension, add a new file background script and add an explicit width and height to the index. The background script needs explicit permission to run in the browser.

  21. 21
    Article
    Avatar of dockerDocker·4y

    9 Tips for Containerizing Your Node.js Application

    Multi-stage Docker builds help ensure your builds are 100% reproducible and lean. You can containerize your Node application using a multi-layer approach. Each layer may contain different app components like source code, resources, and even snapshot dependencies.

  22. 22
    Article
    Avatar of gitguardianGitGuardian·4y

    Best practices for managing teams in GitHub Orgs

    A GitHub organization is a shared platform where you can put one or more repositories and share controlled access with members and collaborators. Code owners can be assigned to specific files or directories and will be notified whenever a change is made to those files. Rebasing can help resolve merge conflicts more efficiently and make it easier to track changes and keep your codebase up to date.

  23. 23
    Article
    Avatar of awstipAWS Tip·4y

    Deploying a NodeJS Application With AWS EC2, SSL, and a Load Balancer

    This walkthrough requires adding a payment method with AWS and a purchase of a domain. You will now be viewing the details page of your security group; let’s edit the inbound rules. Make the port range 8080 - Make the source “Anywhere IPv4” - Do the same process for HTTP (port 80) and HTTPS (port 443) Your security group should look like this.

  24. 24
    Article
    Avatar of circleCircleCI·4y

    What is container orchestration?

    Docker Swarm offers decentralized access, making it easy for distributed teams to work on and manage the environment effectively. Mesos Apache Mesos works between the application layer and the OS, making deploying and managing applications in large-clustered environments more straightforward and efficient.

  25. 25
    Article
    Avatar of hnHacker News·4y

    The PS5 Has Been Jailbroken – Custom Packages Can Now Be Installed

    The PS5 has been jailbroken and cracked wide open marking the first major hack on the system since its launch in 2020. Notorious hacker Lance McDonald posted a video of his newly jailbroken PS5 console on Twitter showing off some of the now-enabled settings.