tgindex
𝐂𝐲𝐛𝐞𝐫 𝐄𝐱𝐩𝐥𝐨𝐢𝐭 𝐒𝐞𝐜 🇰🇭

𝐂𝐲𝐛𝐞𝐫 𝐄𝐱𝐩𝐥𝐨𝐢𝐭 𝐒𝐞𝐜 🇰🇭

Статистика
@cyber_exploit_secанглийский

👋Welcome to Cyber Exploit Sec! A community to learn, explore, and master penetration testing and bug bounty, ethical hacking, and all things cybersecurity.

Последний пост
14 авг.
Последнее чтение
18:23
Постов за неделю
4
Всего постов
37
Тип
открытый
Язык
английский
В каталоге с
13 авг.
Подписчики
288
0 за 3 дн.
Сутки
0
0,00%
Неделя
 
Месяц
 
Просмотров на пост
60
37 постов
Вовлечённость
20,8%
к подписчикам
Постов в день
0,6
всего 37
Упоминаний
0
каналов
Охват размещения
оценка
1/24сутки в ленте
39
1/48двое суток
44
1/72трое суток
48

Оценка по просмотрам недавних постов: пост набирает почти всё за первые сутки.

Посты

  • 14 авг.29из mydailykris

    What is IDOR? 🔓 IDOR (Insecure Direct Object Reference) is a vulnerability where an application allows access to another user's data by changing an identifier in a request without checking authorization. Example: /api/chat_mail/user295878@anonymous.com Change it to: /api/chat_mail/victim@anonymous.com If the server returns the victim's mailbox without verifying permissions, that's an IDOR. 🔐 Authentication = Who you are. 🛡 Authorization = What you're allowed to access. Never trust user-supplied IDs—always verify authorization on the server.

  • ក្នុងមេរៀននេះ អ្នកនឹងស្គាល់ពីរបៀបដែល Burp Suite អាចប្រើសម្រាប់ Intercept, Inspect និង Modify HTTP/HTTPS Requests រវាង Browser និង Server ដើម្បីស្វែងរក និងយល់ពីបញ្ហាសុវត្ថិភាព ដូចជា IDOR, SQL Injection, XSS, Authentication និងបញ្ហាផ្សេងៗទៀត។ សូមមកកាន់ទីនេះដើម្បីយល់ពីរBurp Suite https://youtu.be/0OrPznyG6SA

  • he back ?

  • what your fv >?

  • Course Videos Some courses on https://app.khmersec.com/courses currently do not include video lessons because they are still being prepared. We're gradually adding new videos and learning materials. Thank you for your understanding and support.

  • 📢 Notice ⚠️ Google Sign-In Temporary Issue If you're unable to register or sign in using Google, please use GitHub Sign-In instead. We are currently working to resolve the Google authentication issue. Thank you for your patien

  • KhmerSec Labs — Open Beta is Live! Today we're excited to launch KhmerSec Labs Open Beta. KhmerSec Labs is a free platform designed to help beginners and aspiring cybersecurity professionals practice real-world web security challenges in a safe environment. 🔥 What you can do 💻 Solve hands-on web security labs 🛡 Learn common vulnerabilities (OWASP Top 10) 🏴 Capture flags and improve your skills 📈 Track your progress and challenge yourself 🌐 Practice anytime, completely free This is an Open Beta, so you may encounter bugs or incomplete features while we continue improving the platform. We'd love your feedback! If you find any issues or have suggestions, please let us know so we can make KhmerSec Labs even better. Thank you to everyone supporting KhmerSec and helping us build a stronger cybersecurity community in Cambodia. 🇰🇭 Start Learning Today 👉 https://app.khmersec.com #KhmerSec #KhmerSecLabs #CTF #LearnCybersecurity #Cambodia

  • 7 авг.371из HKimhab

    Full Web Ethical Hacking Course ✨🧑‍💻🚀 Download Link https://drive.google.com/drive/u/0/mobile/folders/1OwiTZmCfLya8cWImNqeV6Bn5z_04oRCN Credit: AL-Hassan Sarrar Note: Must scan it before open cos it's other resources Scan with: https://www.virustotal.com/gui/home/upload ———— Learn coding: rean-it.com Contact me: - Github: https://github.com/HORKimhab  - YouTube: https://www.youtube.com/channel/UCkkeBE6i63AXySy0z5V4wxA?sub_confirmation=1 - Linkedin: https://www.linkedin.com/in/hor-kimhab/ Join Telegram:  - IT Sharing Knowledge: https://t.me/shareknowledge_toeveryone - Youtube - HOR Kimhab: https://t.me/HORKimhab_Youtube - Laravel Cambodia: https://t.me/laravel_cambodiakh - HKimhabCoding: https://t.me/HKimhabCoding - Python Cambodia: https://t.me/pythoncambodia - Linux Sysadmin Fundamentals Khmer : https://t.me/linux_sysadmin_fundamentals

  • 7 авг.38из HKimhab

    видео или голосовое, без подписи

  • 7 авг.42из HKimhab

    200+ free cybersecurity books covering attack techniques, security architecture, and defense strategies. Structured reading builds deeper understanding than quick tutorials Download Link 🔗 https://drive.google.com/drive/mobile/folders/12Mvq6kE2HJDwN2CZhEGWizyWt87YunkU Credit: AL-Hassan Sarrar Note: Must scan it before open cos it's other resources Scan with: https://www.virustotal.com/gui/home/upload ———— Learn coding: rean-it.com Contact me: - Github: https://github.com/HORKimhab - YouTube: https://www.youtube.com/channel/UCkkeBE6i63AXySy0z5V4wxA?sub_confirmation=1 - Linkedin: https://www.linkedin.com/in/hor-kimhab/ Join Telegram:  - IT Sharing Knowledge: https://t.me/shareknowledge_toeveryone - Youtube - HOR Kimhab: https://t.me/HORKimhab_Youtube - Laravel Cambodia: https://t.me/laravel_cambodiakh - HKimhabCoding: https://t.me/HKimhabCoding - Python Cambodia: https://t.me/pythoncambodia - Linux Sysadmin Fundamentals Khmer : https://t.me/linux_sysadmin_fundamentals

  • видео или голосовое, без подписи

  • JWT ត្រូវបានប្រើយ៉ាងទូលំទូលាយសម្រាប់ Authentication ប៉ុន្តែបើអនុវត្តខុស វាអាចបណ្តាលឱ្យ Account Takeover ឬ Privilege Escalation។ ⚠️ ចំណុចសំខាន់ៗដែលត្រូវចងចាំ៖ ❌ JWT Payload មិនត្រូវបាន Encrypt ទេ (គ្រាន់តែ Base64 Encode) ដូច្នេះអ្នកណាក៏អាច Decode បាន។ ❌ កុំទទួលយក alg ពី Token ដោយស្វ័យប្រវត្តិ (ការពារ alg:none និង Algorithm Confusion)។ ✅ ប្រើ RS256 ឬ ES256 សម្រាប់ Production។ ✅ Access Token មានអាយុខ្លី (5–15 នាទី)។ ✅ Refresh Token គួរប្រើ Rotation និងរក្សាទុកក្នុង HttpOnly Cookie។ ❌ កុំរក្សាទុក JWT ក្នុង localStorage (មានហានិភ័យ XSS)។ ❌ កុំដាក់ទិន្នន័យសម្ងាត់ (API Keys, Passwords, Secrets) ក្នុង JWT Payload។ Rule: JWT Signature ការពារការកែប្រែទិន្នន័យប៉ុន្តែ មិនលាក់ទិន្នន័យទេ។

  • видео или голосовое, без подписи

  • តើអ្នកធ្លាប់ឃើញ API ដែលអាចកែ role, isAdmin ឬ API ដែលបញ្ជូនទិន្នន័យសម្ងាត់មក Client ដែរឬទេ? 🤔 នេះគឺជា API3: Broken Object Property Level Authorization (BOPLA) ក្នុង OWASP API Security Top 10 ដែលអាចនាំឱ្យមានការលេចធ្លាយទិន្នន័យ និង Privilege Escalation។ ⚠️ មាន 2 បញ្ហាសំខាន់ៗ 👀 1. Excessive Data Exposure API បញ្ជូនទិន្នន័យលើសពីអ្វីដែល Client ត្រូវការ។ ឧទាហរណ៍៖ api_key passwordHash អ្នកប្រើប្រាស់គួរតែទទួលបានតែព័ត៌មានដែលចាំបាច់ប៉ុណ្ណោះ។ ✍️ 2. Mass Assignment Backend ទទួលយក Field ទាំងអស់ពី Client ដោយគ្មានការត្រួតពិនិត្យ។ ឧទាហរណ៍៖ { "email": "attacker@example.com", "password": "123456", "role": "admin", "is_verified": true, "credit": 10000 } បើ Backend Save req.body ដោយផ្ទាល់ អ្នកវាយប្រហារអាចក្លាយជា Admin ឬកែប្រែ Field ដែលមិនគួរអនុញ្ញាត។

  • របៀបដែល CORS ដំណើរការ https://primer.khmersec.com/web-security/cors#how-cors-works | documentation 1.0

  • Hacking movie collocation

  • WhoAmI

  • I am excited to announce that in just 20 days, we are launching KhmerSec Lab, a new platform designed to elevate the cybersecurity skills of our local community. We are building more than just a Capture The Flag (CTF) arena; we are building a space where defenders, pentesters, and students can sharpen their expertise in a hands-on environment. Stay tuned for our official launch in 20 days. Visit our landing page to follow the countdown and get notified as soon as we go live: lab.khmersec.com 🌐 Website • Main Website: https://khmersec.com/ • Documentation & Learning: https://primer.khmersec.com/ • lab : https://lab.khmersec.com/ • Privacy Policy: https://khmersec.com/privacy • Terms of Service: https://khmersec.com/terms #CyberSecurity #InfoSec #KhmerSec

  • ប្រើ Custom Domain សម្រាប់ Supabase ដោយឥតគិតថ្លៃ (Cloudflare Worker Proxy) មនុស្សជាច្រើនប្រើ Supabase Custom Domain ដែលត្រូវបង់ប្រហែល $10/Project/ខែ។ ប៉ុន្តែបើអ្នកមាន Domain និងប្រើ Cloudflare Worker អ្នកអាចបង្កើត Proxy មួយដើម្បីប្រើ Domain ផ្ទាល់ខ្លួន ដោយមិនចាំបាច់ Upgrade ទៅគម្រោងបង់ប្រាក់។ ឧទាហរណ៍៖ ❌ URL ពិត https://abcdefghijkl.supabase.co ✅ URL ដែលអ្នកប្រើ https://api.example.com Cloudflare Worker នឹង Forward Request ទៅ Supabase ដោយស្វ័យប្រវត្តិ។ អត្ថប្រយោជន៍ ✅ Custom Domain ដោយមិនបង់ $10/ខែ ✅ លាក់ Supabase URL ពិតពីអ្នកប្រើប្រាស់ទូទៅ ✅ អាចដាក់ Cloudflare Rate Limiting ✅ ការពារ DDoS (Cloudflare Layer) ✅ WAF (Web Application Firewall) ✅ Bot Protection ✅ IP Blocking / Country Blocking ✅ Cache សម្រាប់ Request ដែលអាច Cache បាន ✅ Logging និង Analytics តាម Cloudflare ត្រូវដឹងផងដែរ ការប្រើ Proxy មិនមានន័យថា Hacker មិនអាចរកឃើញ Supabase URL ពិតបានទេ។ បើ Frontend របស់អ្នកមាន៖ Hardcode URL Source Map JavaScript Bundle Response Header ឬ Leak នៅកន្លែងណាមួយ អ្នកវាយប្រហារអាចរកឃើញ URL ពិតបានដដែល។ ដូច្នេះ Proxy គឺជាការលាក់ និងបន្ថែមស្រទាប់ការពារ (Defense in Depth) មិនមែនជាការលាក់ 100% នោះទេ។ តើវាការពារអ្វីខ្លះ? ប្រសិនបើ Client ទាំងអស់ចូលតាម Cloudflare Worker៖ Cloudflare អាច Block Request មុនទៅដល់ Supabase កាត់បន្ថយ Spam Request Rate Limit API Block Bot Block DDoS WAF Rule Firewall Rule ធ្វើឲ្យ Supabase ទទួលបានតែ Request ដែលបានឆ្លងកាត់ Cloudflare ប៉ុណ្ណោះ។ ចំណាំ ប្រសិនបើអ្នកនៅតែបង្ហាញ Supabase URL នៅក្នុង Frontend ឬ Client នោះ Hacker អាចរំលង Proxy ហើយ Request ទៅ Supabase ដោយផ្ទាល់បាន។

  • видео или голосовое, без подписи

𝐂𝐲𝐛𝐞𝐫 𝐄𝐱𝐩𝐥𝐨𝐢𝐭 𝐒𝐞𝐜 🇰🇭 — tgindex