Aggregator
SonarQube实现自动化代码扫描
SonarQube实现自动化代码扫描
SonarQube实现自动化代码扫描
SonarQube实现自动化代码扫描
SonarQube实现自动化代码扫描
SonarQube实现自动化代码扫描
SonarQube实现自动化代码扫描
Hunting for credentials and building a credential type reference catalog
Adversaries are leveraging widely exposed clear text credentials to gain access to sensitive information.
At times the term “harvesting credentials” is used when red teamers emulate these attacks - which is something that appears to be more opportunistic and I would propose that security teams start to actively hunt for credential exposure that can put their organization at risk – in case you are not yet doing that.
Actively hunting for credential exposureThe idea of credential hunting is targeted and focused, leveraging intelligence about systems and combing it with powerful search techniques to identify exposure.
一些流行的云waf、cdn、lb的域名列表(80条)
在信息收集过程中,会遇到使用cdn、云waf等的子域名。这样在做端口扫描时就会出现大量开放的端口。这就会导致扫描时间变长,多出来许多无用的信息。这里收集了一些,大家可以用到自己的扫描器中或开源程序中,遇到域名cname使用这些域名的时候可以跳过端口检查,节省时间。
以下列表主要收集了一些大型互联网企业(腾讯、百度、滴滴、字节跳动、360、阿里巴巴、美团、京东等),然后经过人工整理出来,有遗漏在所难免,欢迎大家补充。
w.alikunlun.com
wsglb0.com
w.kunlunpi.com
elb.amazonaws.com
wswebpic.com
mig.tencent-cloud.net
cloud.tc.qq.com
qcloudcjgj.com
pop3.mxhichina.com