tgindex
KhmerSec Academy

KhmerSec Academy

Статистика
@KhmerSecAcademyанглийский

Cybersecurity Education • Ethical Hacking • Bug Bounty • Web Security • Free Learning website: https://khmersec.com/ Lab Project: https://t.me/infokhmersec Support: @phoungrathank

Последний пост
12 авг.
Последнее чтение
06:23
Постов за неделю
2
Всего постов
30
Тип
открытый
Язык
английский
В каталоге с
13 авг.
Подписчики
157
+1 за 4 дн.
Сутки
0
0,00%
Неделя
 
Месяц
 
Просмотров на пост
137
28 постов
Вовлечённость
87,3%
к подписчикам
Постов в день
0,3
всего 30
Упоминаний
1
каналов
Охват размещения
оценка
1/24сутки в ленте
89
1/48двое суток
101
1/72трое суток
110

Оценка по просмотрам недавних постов: пост набирает почти всё за первые сутки.

Посты

  • ក្នុងមេរៀននេះ អ្នកនឹងស្គាល់ពីរបៀបដែល Burp Suite អាចប្រើសម្រាប់ Intercept, Inspect និង Modify HTTP/HTTPS Requests រវាង Browser និង Server ដើម្បីស្វែងរក និងយល់ពីបញ្ហាសុវត្ថិភាព ដូចជា IDOR, SQL Injection, XSS, Authentication និងបញ្ហាផ្សេងៗទៀត។ សូមមកកាន់ទីនេះដើម្បីយល់ពីរBurp Suite https://youtu.be/0OrPznyG6SA

  • what your fv >?

  • Course Videos Some courses on https://app.khmersec.com/courses currently do not include video lessons because they are still being prepared. We're gradually adding new videos and learning materials. Thank you for your understanding and support.

  • 📢 Notice ⚠️ Google Sign-In Temporary Issue If you're unable to register or sign in using Google, please use GitHub Sign-In instead. We are currently working to resolve the Google authentication issue. Thank you for your patien

  • KhmerSec Labs — Open Beta is Live! Today we're excited to launch KhmerSec Labs Open Beta. KhmerSec Labs is a free platform designed to help beginners and aspiring cybersecurity professionals practice real-world web security challenges in a safe environment. 🔥 What you can do 💻 Solve hands-on web security labs 🛡 Learn common vulnerabilities (OWASP Top 10) 🏴 Capture flags and improve your skills 📈 Track your progress and challenge yourself 🌐 Practice anytime, completely free This is an Open Beta, so you may encounter bugs or incomplete features while we continue improving the platform. We'd love your feedback! If you find any issues or have suggestions, please let us know so we can make KhmerSec Labs even better. Thank you to everyone supporting KhmerSec and helping us build a stronger cybersecurity community in Cambodia. 🇰🇭 Start Learning Today 👉 https://app.khmersec.com #KhmerSec #KhmerSecLabs #CTF #LearnCybersecurity #Cambodia

  • 4 авг.1134из HKimhab

    Full Web Ethical Hacking Course ✨🧑‍💻🚀 Download Link https://drive.google.com/drive/u/0/mobile/folders/1OwiTZmCfLya8cWImNqeV6Bn5z_04oRCN Credit: AL-Hassan Sarrar Note: Must scan it before open cos it's other resources Scan with: https://www.virustotal.com/gui/home/upload ———— Learn coding: rean-it.com Contact me: - Github: https://github.com/HORKimhab  - YouTube: https://www.youtube.com/channel/UCkkeBE6i63AXySy0z5V4wxA?sub_confirmation=1 - Linkedin: https://www.linkedin.com/in/hor-kimhab/ Join Telegram:  - IT Sharing Knowledge: https://t.me/shareknowledge_toeveryone - Youtube - HOR Kimhab: https://t.me/HORKimhab_Youtube - Laravel Cambodia: https://t.me/laravel_cambodiakh - HKimhabCoding: https://t.me/HKimhabCoding - Python Cambodia: https://t.me/pythoncambodia - Linux Sysadmin Fundamentals Khmer : https://t.me/linux_sysadmin_fundamentals

  • 4 авг.992из HKimhab

    без подписи

  • 4 авг.1032из HKimhab

    200+ free cybersecurity books covering attack techniques, security architecture, and defense strategies. Structured reading builds deeper understanding than quick tutorials Download Link 🔗 https://drive.google.com/drive/mobile/folders/12Mvq6kE2HJDwN2CZhEGWizyWt87YunkU Credit: AL-Hassan Sarrar Note: Must scan it before open cos it's other resources Scan with: https://www.virustotal.com/gui/home/upload ———— Learn coding: rean-it.com Contact me: - Github: https://github.com/HORKimhab - YouTube: https://www.youtube.com/channel/UCkkeBE6i63AXySy0z5V4wxA?sub_confirmation=1 - Linkedin: https://www.linkedin.com/in/hor-kimhab/ Join Telegram:  - IT Sharing Knowledge: https://t.me/shareknowledge_toeveryone - Youtube - HOR Kimhab: https://t.me/HORKimhab_Youtube - Laravel Cambodia: https://t.me/laravel_cambodiakh - HKimhabCoding: https://t.me/HKimhabCoding - Python Cambodia: https://t.me/pythoncambodia - Linux Sysadmin Fundamentals Khmer : https://t.me/linux_sysadmin_fundamentals

  • For example

  • JWT ត្រូវបានប្រើយ៉ាងទូលំទូលាយសម្រាប់ Authentication ប៉ុន្តែបើអនុវត្តខុស វាអាចបណ្តាលឱ្យ Account Takeover ឬ Privilege Escalation។ ⚠️ ចំណុចសំខាន់ៗដែលត្រូវចងចាំ៖ ❌ JWT Payload មិនត្រូវបាន Encrypt ទេ (គ្រាន់តែ Base64 Encode) ដូច្នេះអ្នកណាក៏អាច Decode បាន។ ❌ កុំទទួលយក alg ពី Token ដោយស្វ័យប្រវត្តិ (ការពារ alg:none និង Algorithm Confusion)។ ✅ ប្រើ RS256 ឬ ES256 សម្រាប់ Production។ ✅ Access Token មានអាយុខ្លី (5–15 នាទី)។ ✅ Refresh Token គួរប្រើ Rotation និងរក្សាទុកក្នុង HttpOnly Cookie។ ❌ កុំរក្សាទុក JWT ក្នុង localStorage (មានហានិភ័យ XSS)។ ❌ កុំដាក់ទិន្នន័យសម្ងាត់ (API Keys, Passwords, Secrets) ក្នុង JWT Payload។ Rule: JWT Signature ការពារការកែប្រែទិន្នន័យប៉ុន្តែ មិនលាក់ទិន្នន័យទេ។

  • без подписи

  • តើអ្នកធ្លាប់ឃើញ API ដែលអាចកែ role, isAdmin ឬ API ដែលបញ្ជូនទិន្នន័យសម្ងាត់មក Client ដែរឬទេ? 🤔 នេះគឺជា API3: Broken Object Property Level Authorization (BOPLA) ក្នុង OWASP API Security Top 10 ដែលអាចនាំឱ្យមានការលេចធ្លាយទិន្នន័យ និង Privilege Escalation។ ⚠️ មាន 2 បញ្ហាសំខាន់ៗ 👀 1. Excessive Data Exposure API បញ្ជូនទិន្នន័យលើសពីអ្វីដែល Client ត្រូវការ។ ឧទាហរណ៍៖ api_key passwordHash អ្នកប្រើប្រាស់គួរតែទទួលបានតែព័ត៌មានដែលចាំបាច់ប៉ុណ្ណោះ។ ✍️ 2. Mass Assignment Backend ទទួលយក Field ទាំងអស់ពី Client ដោយគ្មានការត្រួតពិនិត្យ។ ឧទាហរណ៍៖ { "email": "attacker@example.com", "password": "123456", "role": "admin", "is_verified": true, "credit": 10000 } បើ Backend Save req.body ដោយផ្ទាល់ អ្នកវាយប្រហារអាចក្លាយជា Admin ឬកែប្រែ Field ដែលមិនគួរអនុញ្ញាត។

  • របៀបដែល CORS (Cross-Origin Resource Sharing) ដំណើរការ Read here: https://primer.khmersec.com/web-security/cors#how-cors-works Documentation v1.0 🇰🇭 Full Khmer support 🇺🇸 English support powered by Google Translate API Feedback and contributions are always welcome! ❤️

  • I am excited to announce that in just 20 days, we are launching KhmerSec Lab, a new platform designed to elevate the cybersecurity skills of our local community. We are building more than just a Capture The Flag (CTF) arena; we are building a space where defenders, pentesters, and students can sharpen their expertise in a hands-on environment. Stay tuned for our official launch in 20 days. Visit our landing page to follow the countdown and get notified as soon as we go live: lab.khmersec.com 🌐 Website • Main Website: https://khmersec.com/ • Documentation & Learning: https://primer.khmersec.com/ • lab : https://lab.khmersec.com/ • Privacy Policy: https://khmersec.com/privacy • Terms of Service: https://khmersec.com/terms #CyberSecurity #InfoSec #KhmerSec

  • ប្រើ Custom Domain សម្រាប់ Supabase ដោយឥតគិតថ្លៃ (Cloudflare Worker Proxy) មនុស្សជាច្រើនប្រើ Supabase Custom Domain ដែលត្រូវបង់ប្រហែល $10/Project/ខែ។ ប៉ុន្តែបើអ្នកមាន Domain និងប្រើ Cloudflare Worker អ្នកអាចបង្កើត Proxy មួយដើម្បីប្រើ Domain ផ្ទាល់ខ្លួន ដោយមិនចាំបាច់ Upgrade ទៅគម្រោងបង់ប្រាក់។ ឧទាហរណ៍៖ ❌ URL ពិត https://abcdefghijkl.supabase.co ✅ URL ដែលអ្នកប្រើ https://api.example.com Cloudflare Worker នឹង Forward Request ទៅ Supabase ដោយស្វ័យប្រវត្តិ។ អត្ថប្រយោជន៍ ✅ Custom Domain ដោយមិនបង់ $10/ខែ ✅ លាក់ Supabase URL ពិតពីអ្នកប្រើប្រាស់ទូទៅ ✅ អាចដាក់ Cloudflare Rate Limiting ✅ ការពារ DDoS (Cloudflare Layer) ✅ WAF (Web Application Firewall) ✅ Bot Protection ✅ IP Blocking / Country Blocking ✅ Cache សម្រាប់ Request ដែលអាច Cache បាន ✅ Logging និង Analytics តាម Cloudflare ត្រូវដឹងផងដែរ ការប្រើ Proxy មិនមានន័យថា Hacker មិនអាចរកឃើញ Supabase URL ពិតបានទេ។ បើ Frontend របស់អ្នកមាន៖ Hardcode URL Source Map JavaScript Bundle Response Header ឬ Leak នៅកន្លែងណាមួយ អ្នកវាយប្រហារអាចរកឃើញ URL ពិតបានដដែល។ ដូច្នេះ Proxy គឺជាការលាក់ និងបន្ថែមស្រទាប់ការពារ (Defense in Depth) មិនមែនជាការលាក់ 100% នោះទេ។ តើវាការពារអ្វីខ្លះ? ប្រសិនបើ Client ទាំងអស់ចូលតាម Cloudflare Worker៖ Cloudflare អាច Block Request មុនទៅដល់ Supabase កាត់បន្ថយ Spam Request Rate Limit API Block Bot Block DDoS WAF Rule Firewall Rule ធ្វើឲ្យ Supabase ទទួលបានតែ Request ដែលបានឆ្លងកាត់ Cloudflare ប៉ុណ្ណោះ។ ចំណាំ ប្រសិនបើអ្នកនៅតែបង្ហាញ Supabase URL នៅក្នុង Frontend ឬ Client នោះ Hacker អាចរំលង Proxy ហើយ Request ទៅ Supabase ដោយផ្ទាល់បាន។

  • Channel photo updated

  • Channel name was changed to «KhmerSec Academy»

  • без подписи

  • GitGuardian ជាអ្វី? បើអ្នកធ្លាប់ Push Source Code ឡើង GitHub ហើយភ្លេចលុប API Key, Password ឬ Token ចេញពី Code នោះ GitGuardian អាចជួយការពារអ្នកបាន។ GitGuardian គឺជា Platform ផ្នែក Cybersecurity ដែលស្វែងរក និងជូនដំណឹងអំពី Secrets ដែលលេចធ្លាយក្នុង Source Code ដូចជា API Keys, Database Passwords, SSH Keys, Cloud Credentials និង Tokens។ 🔍 GitGuardian អាចធ្វើអ្វីបាន? ✅ ស្កេន GitHub Repository (Public និង Private) ✅ រកឃើញ API Keys, Passwords និង Credentials ដែលលេចធ្លាយ ✅ ជូនដំណឹងភ្លាមៗ នៅពេលមាន Secret ត្រូវបាន Commit ✅ ជួយក្រុម Developer និង Security Team គ្រប់គ្រង Incident ✅ មាន Dashboard សម្រាប់តាមដាន Repository, Alerts និង Analytics ⚠️ ហេតុអ្វីវាសំខាន់? អ្នកវាយប្រហារ (Attackers) មិនចាំបាច់ Hack Server របស់អ្នកទេ។ បើអ្នក Commit API Key ឬ Password ទៅ GitHub សាធារណៈ ពួកគេអាចយក Secret នោះទៅប្រើបានភ្លាមៗ។ ឧទាហរណ៍៖ AWS Access Key Database Password GitHub Personal Access Token

  • គ្រាន់តែប្ដូរ false ទៅ true គេអាច Hack យើងបានមែនទេ? ចម្លើយគឺ៖ អាចបាន ប៉ុន្តែមិនមែនគ្រប់ករណីទាំងអស់ទេ។ វាអាស្រ័យលើថា System របស់យើងពិនិត្យសិទ្ធិនៅកន្លែងណា។ ឧទាហរណ៍៖ const isAdmin = true; if (isAdmin) { router.push("/admin"); } បើ System ពិនិត្យតែ true/false នៅខាង Frontend (UI) ហើយពេល true វា Redirect ទៅ /admin ភ្លាម នោះអ្នកវាយប្រហារអាចកែតម្លៃក្នុង Browser ឬកែ Request ដើម្បីបន្លំថាខ្លួនមានសិទ្ធិ។