KhmerSec Academy
СтатистикаCybersecurity Education • Ethical Hacking • Bug Bounty • Web Security • Free Learning website: https://khmersec.com/ Lab Project: https://t.me/infokhmersec Support: @phoungrathank
- Последний пост
- 12 авг.
- Последнее чтение
- 06:23
- Постов за неделю
- 2
- Всего постов
- 30
- Тип
- открытый
- Язык
- английский
- В каталоге с
- 13 авг.
- 1/24сутки в ленте
- 89
- 1/48двое суток
- 101
- 1/72трое суток
- 110
Оценка по просмотрам недавних постов: пост набирает почти всё за первые сутки.
Посты
ក្នុងមេរៀននេះ អ្នកនឹងស្គាល់ពីរបៀបដែល Burp Suite អាចប្រើសម្រាប់ Intercept, Inspect និង Modify HTTP/HTTPS Requests រវាង Browser និង Server ដើម្បីស្វែងរក និងយល់ពីបញ្ហាសុវត្ថិភាព ដូចជា IDOR, SQL Injection, XSS, Authentication និងបញ្ហាផ្សេងៗទៀត។ សូមមកកាន់ទីនេះដើម្បីយល់ពីរBurp Suite https://youtu.be/0OrPznyG6SA
what your fv >?
Course Videos Some courses on https://app.khmersec.com/courses currently do not include video lessons because they are still being prepared. We're gradually adding new videos and learning materials. Thank you for your understanding and support.
📢 Notice ⚠️ Google Sign-In Temporary Issue If you're unable to register or sign in using Google, please use GitHub Sign-In instead. We are currently working to resolve the Google authentication issue. Thank you for your patien
KhmerSec Labs — Open Beta is Live! Today we're excited to launch KhmerSec Labs Open Beta. KhmerSec Labs is a free platform designed to help beginners and aspiring cybersecurity professionals practice real-world web security challenges in a safe environment. 🔥 What you can do 💻 Solve hands-on web security labs 🛡 Learn common vulnerabilities (OWASP Top 10) 🏴 Capture flags and improve your skills 📈 Track your progress and challenge yourself 🌐 Practice anytime, completely free This is an Open Beta, so you may encounter bugs or incomplete features while we continue improving the platform. We'd love your feedback! If you find any issues or have suggestions, please let us know so we can make KhmerSec Labs even better. Thank you to everyone supporting KhmerSec and helping us build a stronger cybersecurity community in Cambodia. 🇰🇭 Start Learning Today 👉 https://app.khmersec.com #KhmerSec #KhmerSecLabs #CTF #LearnCybersecurity #Cambodia
Full Web Ethical Hacking Course ✨🧑💻🚀 Download Link https://drive.google.com/drive/u/0/mobile/folders/1OwiTZmCfLya8cWImNqeV6Bn5z_04oRCN Credit: AL-Hassan Sarrar Note: Must scan it before open cos it's other resources Scan with: https://www.virustotal.com/gui/home/upload ———— Learn coding: rean-it.com Contact me: - Github: https://github.com/HORKimhab - YouTube: https://www.youtube.com/channel/UCkkeBE6i63AXySy0z5V4wxA?sub_confirmation=1 - Linkedin: https://www.linkedin.com/in/hor-kimhab/ Join Telegram: - IT Sharing Knowledge: https://t.me/shareknowledge_toeveryone - Youtube - HOR Kimhab: https://t.me/HORKimhab_Youtube - Laravel Cambodia: https://t.me/laravel_cambodiakh - HKimhabCoding: https://t.me/HKimhabCoding - Python Cambodia: https://t.me/pythoncambodia - Linux Sysadmin Fundamentals Khmer : https://t.me/linux_sysadmin_fundamentals
без подписи
200+ free cybersecurity books covering attack techniques, security architecture, and defense strategies. Structured reading builds deeper understanding than quick tutorials Download Link 🔗 https://drive.google.com/drive/mobile/folders/12Mvq6kE2HJDwN2CZhEGWizyWt87YunkU Credit: AL-Hassan Sarrar Note: Must scan it before open cos it's other resources Scan with: https://www.virustotal.com/gui/home/upload ———— Learn coding: rean-it.com Contact me: - Github: https://github.com/HORKimhab - YouTube: https://www.youtube.com/channel/UCkkeBE6i63AXySy0z5V4wxA?sub_confirmation=1 - Linkedin: https://www.linkedin.com/in/hor-kimhab/ Join Telegram: - IT Sharing Knowledge: https://t.me/shareknowledge_toeveryone - Youtube - HOR Kimhab: https://t.me/HORKimhab_Youtube - Laravel Cambodia: https://t.me/laravel_cambodiakh - HKimhabCoding: https://t.me/HKimhabCoding - Python Cambodia: https://t.me/pythoncambodia - Linux Sysadmin Fundamentals Khmer : https://t.me/linux_sysadmin_fundamentals
For example
JWT ត្រូវបានប្រើយ៉ាងទូលំទូលាយសម្រាប់ Authentication ប៉ុន្តែបើអនុវត្តខុស វាអាចបណ្តាលឱ្យ Account Takeover ឬ Privilege Escalation។ ⚠️ ចំណុចសំខាន់ៗដែលត្រូវចងចាំ៖ ❌ JWT Payload មិនត្រូវបាន Encrypt ទេ (គ្រាន់តែ Base64 Encode) ដូច្នេះអ្នកណាក៏អាច Decode បាន។ ❌ កុំទទួលយក alg ពី Token ដោយស្វ័យប្រវត្តិ (ការពារ alg:none និង Algorithm Confusion)។ ✅ ប្រើ RS256 ឬ ES256 សម្រាប់ Production។ ✅ Access Token មានអាយុខ្លី (5–15 នាទី)។ ✅ Refresh Token គួរប្រើ Rotation និងរក្សាទុកក្នុង HttpOnly Cookie។ ❌ កុំរក្សាទុក JWT ក្នុង localStorage (មានហានិភ័យ XSS)។ ❌ កុំដាក់ទិន្នន័យសម្ងាត់ (API Keys, Passwords, Secrets) ក្នុង JWT Payload។ Rule: JWT Signature ការពារការកែប្រែទិន្នន័យប៉ុន្តែ មិនលាក់ទិន្នន័យទេ។
без подписи
តើអ្នកធ្លាប់ឃើញ API ដែលអាចកែ role, isAdmin ឬ API ដែលបញ្ជូនទិន្នន័យសម្ងាត់មក Client ដែរឬទេ? 🤔 នេះគឺជា API3: Broken Object Property Level Authorization (BOPLA) ក្នុង OWASP API Security Top 10 ដែលអាចនាំឱ្យមានការលេចធ្លាយទិន្នន័យ និង Privilege Escalation។ ⚠️ មាន 2 បញ្ហាសំខាន់ៗ 👀 1. Excessive Data Exposure API បញ្ជូនទិន្នន័យលើសពីអ្វីដែល Client ត្រូវការ។ ឧទាហរណ៍៖ api_key passwordHash អ្នកប្រើប្រាស់គួរតែទទួលបានតែព័ត៌មានដែលចាំបាច់ប៉ុណ្ណោះ។ ✍️ 2. Mass Assignment Backend ទទួលយក Field ទាំងអស់ពី Client ដោយគ្មានការត្រួតពិនិត្យ។ ឧទាហរណ៍៖ { "email": "attacker@example.com", "password": "123456", "role": "admin", "is_verified": true, "credit": 10000 } បើ Backend Save req.body ដោយផ្ទាល់ អ្នកវាយប្រហារអាចក្លាយជា Admin ឬកែប្រែ Field ដែលមិនគួរអនុញ្ញាត។
របៀបដែល CORS (Cross-Origin Resource Sharing) ដំណើរការ Read here: https://primer.khmersec.com/web-security/cors#how-cors-works Documentation v1.0 🇰🇭 Full Khmer support 🇺🇸 English support powered by Google Translate API Feedback and contributions are always welcome! ❤️
I am excited to announce that in just 20 days, we are launching KhmerSec Lab, a new platform designed to elevate the cybersecurity skills of our local community. We are building more than just a Capture The Flag (CTF) arena; we are building a space where defenders, pentesters, and students can sharpen their expertise in a hands-on environment. Stay tuned for our official launch in 20 days. Visit our landing page to follow the countdown and get notified as soon as we go live: lab.khmersec.com 🌐 Website • Main Website: https://khmersec.com/ • Documentation & Learning: https://primer.khmersec.com/ • lab : https://lab.khmersec.com/ • Privacy Policy: https://khmersec.com/privacy • Terms of Service: https://khmersec.com/terms #CyberSecurity #InfoSec #KhmerSec
ប្រើ Custom Domain សម្រាប់ Supabase ដោយឥតគិតថ្លៃ (Cloudflare Worker Proxy) មនុស្សជាច្រើនប្រើ Supabase Custom Domain ដែលត្រូវបង់ប្រហែល $10/Project/ខែ។ ប៉ុន្តែបើអ្នកមាន Domain និងប្រើ Cloudflare Worker អ្នកអាចបង្កើត Proxy មួយដើម្បីប្រើ Domain ផ្ទាល់ខ្លួន ដោយមិនចាំបាច់ Upgrade ទៅគម្រោងបង់ប្រាក់។ ឧទាហរណ៍៖ ❌ URL ពិត https://abcdefghijkl.supabase.co ✅ URL ដែលអ្នកប្រើ https://api.example.com Cloudflare Worker នឹង Forward Request ទៅ Supabase ដោយស្វ័យប្រវត្តិ។ អត្ថប្រយោជន៍ ✅ Custom Domain ដោយមិនបង់ $10/ខែ ✅ លាក់ Supabase URL ពិតពីអ្នកប្រើប្រាស់ទូទៅ ✅ អាចដាក់ Cloudflare Rate Limiting ✅ ការពារ DDoS (Cloudflare Layer) ✅ WAF (Web Application Firewall) ✅ Bot Protection ✅ IP Blocking / Country Blocking ✅ Cache សម្រាប់ Request ដែលអាច Cache បាន ✅ Logging និង Analytics តាម Cloudflare ត្រូវដឹងផងដែរ ការប្រើ Proxy មិនមានន័យថា Hacker មិនអាចរកឃើញ Supabase URL ពិតបានទេ។ បើ Frontend របស់អ្នកមាន៖ Hardcode URL Source Map JavaScript Bundle Response Header ឬ Leak នៅកន្លែងណាមួយ អ្នកវាយប្រហារអាចរកឃើញ URL ពិតបានដដែល។ ដូច្នេះ Proxy គឺជាការលាក់ និងបន្ថែមស្រទាប់ការពារ (Defense in Depth) មិនមែនជាការលាក់ 100% នោះទេ។ តើវាការពារអ្វីខ្លះ? ប្រសិនបើ Client ទាំងអស់ចូលតាម Cloudflare Worker៖ Cloudflare អាច Block Request មុនទៅដល់ Supabase កាត់បន្ថយ Spam Request Rate Limit API Block Bot Block DDoS WAF Rule Firewall Rule ធ្វើឲ្យ Supabase ទទួលបានតែ Request ដែលបានឆ្លងកាត់ Cloudflare ប៉ុណ្ណោះ។ ចំណាំ ប្រសិនបើអ្នកនៅតែបង្ហាញ Supabase URL នៅក្នុង Frontend ឬ Client នោះ Hacker អាចរំលង Proxy ហើយ Request ទៅ Supabase ដោយផ្ទាល់បាន។
Channel photo updated
Channel name was changed to «KhmerSec Academy»
без подписи
GitGuardian ជាអ្វី? បើអ្នកធ្លាប់ Push Source Code ឡើង GitHub ហើយភ្លេចលុប API Key, Password ឬ Token ចេញពី Code នោះ GitGuardian អាចជួយការពារអ្នកបាន។ GitGuardian គឺជា Platform ផ្នែក Cybersecurity ដែលស្វែងរក និងជូនដំណឹងអំពី Secrets ដែលលេចធ្លាយក្នុង Source Code ដូចជា API Keys, Database Passwords, SSH Keys, Cloud Credentials និង Tokens។ 🔍 GitGuardian អាចធ្វើអ្វីបាន? ✅ ស្កេន GitHub Repository (Public និង Private) ✅ រកឃើញ API Keys, Passwords និង Credentials ដែលលេចធ្លាយ ✅ ជូនដំណឹងភ្លាមៗ នៅពេលមាន Secret ត្រូវបាន Commit ✅ ជួយក្រុម Developer និង Security Team គ្រប់គ្រង Incident ✅ មាន Dashboard សម្រាប់តាមដាន Repository, Alerts និង Analytics ⚠️ ហេតុអ្វីវាសំខាន់? អ្នកវាយប្រហារ (Attackers) មិនចាំបាច់ Hack Server របស់អ្នកទេ។ បើអ្នក Commit API Key ឬ Password ទៅ GitHub សាធារណៈ ពួកគេអាចយក Secret នោះទៅប្រើបានភ្លាមៗ។ ឧទាហរណ៍៖ AWS Access Key Database Password GitHub Personal Access Token
គ្រាន់តែប្ដូរ false ទៅ true គេអាច Hack យើងបានមែនទេ? ចម្លើយគឺ៖ អាចបាន ប៉ុន្តែមិនមែនគ្រប់ករណីទាំងអស់ទេ។ វាអាស្រ័យលើថា System របស់យើងពិនិត្យសិទ្ធិនៅកន្លែងណា។ ឧទាហរណ៍៖ const isAdmin = true; if (isAdmin) { router.push("/admin"); } បើ System ពិនិត្យតែ true/false នៅខាង Frontend (UI) ហើយពេល true វា Redirect ទៅ /admin ភ្លាម នោះអ្នកវាយប្រហារអាចកែតម្លៃក្នុង Browser ឬកែ Request ដើម្បីបន្លំថាខ្លួនមានសិទ្ធិ។