OWASP AppSec Israel Testimonials
3:28
BHUSA 2019 Testimonials
1:47
4 жыл бұрын
we45 Webinar - Secure Code Review
47:13
Пікірлер
@prakharbhardwaj5380
@prakharbhardwaj5380 Ай бұрын
Suggestion : Upload the Videos in better quality
@kumarkumar-re2ff
@kumarkumar-re2ff Ай бұрын
Can we implement the same with Oracle Kubernetes Engine and secrets stored in Azure Keyvault.
@ach500
@ach500 Жыл бұрын
Hi great content. Please how do I overcome this issue: Scanning process completed, starting to analyze the results! Error: Validation Failed: {"message":"The listed users and repositories cannot be searched either because the resources do not exist or you do not have permission to view them.","resource":"Search","field":"q","code":"invalid"}
@niraj8241
@niraj8241 2 жыл бұрын
Thanks for video. Just a note that when you generated the certificate with your signing key. You didn't sign it appropriately. So the failure.
@yesubabu2880
@yesubabu2880 2 жыл бұрын
Mostly AWS no Azure..
@raymondmonroe3589
@raymondmonroe3589 2 жыл бұрын
weirdAAL gets Traceback (most recent call last): File "/home/kali/weirdAAL/weirdAAL.py", line 18, in <module> from tabulate import tabulate File "/home/kali/weirdAAL/venv/lib/python3.10/site-packages/tabulate.py", line 7, in <module> from collections import namedtuple, Iterable ImportError: cannot import name 'Iterable' from 'collections' (/usr/lib/python3.10/collections/__init__.py)
@gauravthapa4380
@gauravthapa4380 2 жыл бұрын
How to modify Unity games
@cibofff
@cibofff 2 жыл бұрын
Сool
@shinkurt
@shinkurt 2 жыл бұрын
best female teacher. actually learned how to stop external entities on java. had no idea. thanks
@ianxiao5543
@ianxiao5543 2 жыл бұрын
Wtf
@henriquelopes3502
@henriquelopes3502 3 жыл бұрын
Thanks! Help me a lot to configure the mTLS in my API Gateway!
@sadisonmez3210
@sadisonmez3210 3 жыл бұрын
great video/thx
@hazardbug2482
@hazardbug2482 3 жыл бұрын
well , how retrive data if you found vulnearability in apk..?
@robsonmachado4054
@robsonmachado4054 3 жыл бұрын
Very Good. Thanks!
@clemiboi
@clemiboi 3 жыл бұрын
T\hanks - very valuable
@ArmourTechnology
@ArmourTechnology 3 жыл бұрын
THis thing needs root?
@MrCreative68
@MrCreative68 3 жыл бұрын
hi. have you try this with tiktok app yet ?
@MrCreative68
@MrCreative68 3 жыл бұрын
tks you. i tested it with tiktok and not working .
@jonmagee1778
@jonmagee1778 3 жыл бұрын
Keep up the great videos! I really like how you wrote the code then ran the tool using the code you wrote. Great Content!
@dohaguytape7747
@dohaguytape7747 3 жыл бұрын
Unfortunately I tried many times to test it against acunetix xss vulnerable website, with no results... the reports shows 0 xss which is not making sense
@youngbos305
@youngbos305 3 жыл бұрын
Tell me how I can contact you I will pay you yo help me intercept a application I need information off
@UUrGod
@UUrGod 3 ай бұрын
?????? 😮
@thunderbirds8633
@thunderbirds8633 3 жыл бұрын
How did you provide access of keyvault to cluster?
@sg_officialff684
@sg_officialff684 3 жыл бұрын
OMG! This is so phony... I assume not many people know that "ViberHax0r" is the only working viber hacking tool. If you want to try it out you can certainly find it on google :)
@prudvik1613
@prudvik1613 3 жыл бұрын
Thanks for the clear explanation on the AKV.
@HEROBOMA
@HEROBOMA 3 жыл бұрын
pls script platformr tools
@Caracazz2
@Caracazz2 3 жыл бұрын
Does not work with HSTS applications.
@domaincontroller
@domaincontroller 3 жыл бұрын
04:02 SAST 05:51 AST 08:40 bandit, brakeman, AST tools 09:59 semmle 11:50 semgrep 14:38 some python code
@meinaimsuckt
@meinaimsuckt 3 жыл бұрын
How you get the intercept and terminal app.
@zifanyan4428
@zifanyan4428 3 жыл бұрын
After running android sslpinning disable, I encountered (agent) [4340464616672] Called (Android 7+) TrustManagerImpl.checkTrustedRecursive(), not throwing an exception. I am running on genymotion, android 8.0 api level 26. Pls help!
@sarojpattnaik
@sarojpattnaik 3 жыл бұрын
Excellent demo Abhay. Need some help on robot Framework. I am a great follower of WE45.
@satyajitdas1249
@satyajitdas1249 3 жыл бұрын
osm ! pls create vdos on android security issues, ios security issues, web security issues, owasp top 10, api top 10. thank you.
@we45-appsec
@we45-appsec 3 жыл бұрын
Thanks for watching!
@carloskelvin8953
@carloskelvin8953 3 жыл бұрын
Contacting #Miliehack on Instagram was best recommended.she is reliable in bypassing 2sv verification
@himabindureddy8803
@himabindureddy8803 4 жыл бұрын
can we integrate zap with aws codepipeline?
@lehoangnam2728
@lehoangnam2728 4 жыл бұрын
cloud you send me the ppt file ([email protected])? Many thanks!
@adnannazar4661
@adnannazar4661 4 жыл бұрын
👏👏👏
@muhasinps1084
@muhasinps1084 4 жыл бұрын
Nice 👍 sahad your explanation with examples its helpful to easy capture 👍. You both did well ❤️. Thanku
@anisk8170
@anisk8170 4 жыл бұрын
Nice 😇👍👍👍
@rajeshkanumuru4381
@rajeshkanumuru4381 4 жыл бұрын
Amazing Content!
@venkaiahb4467
@venkaiahb4467 4 жыл бұрын
Nice video Please share the scripts to my email id [email protected]
@moto_venom
@moto_venom 4 жыл бұрын
Hi ) I connected everything to protection. How can I validate the form? I want to check whether my protection is working or not. If I paste this into the alert (document.cookie) form it will be sent to my mail. I will not see any JavaScrip code displayed. I need a method to test my XSS protection. In other words, what I need to do is to make an XSS attack on my form so that I can see if my defense has worked or not. I hope I have explained it clearly. I am sorry my English is bad
@youssefdirani
@youssefdirani 4 жыл бұрын
15:30 thanks
@christianschmidt7466
@christianschmidt7466 4 жыл бұрын
Keep up the good work!! You need more views. Did you ever think of using smzeus . c o m? You should use it to promote your videos!!
@gene495
@gene495 4 жыл бұрын
Does that mean you are installing the zap into the application server environment on your github action sample?
@we45-appsec
@we45-appsec 4 жыл бұрын
Yes, GitHub actions uses the concept of a runner. In this example we’re installing zap on the github runner and running the job
@gene495
@gene495 4 жыл бұрын
Can you run semgrep to scan a directory of python codes just like how other SAST tools? This seems like a complicated SAST as you need to build different rules and patter for each vulnerabilities.
@we45-appsec
@we45-appsec 4 жыл бұрын
Yes, you can do that. It works on a directory. It depends on your definition of “complicated”. Most of the complexity comes from the chance that you need to write rules from scratch ( I love even that ), but they do have a decent database of rules and you should be able to leverage them against your target.
@tylewilson2679
@tylewilson2679 4 жыл бұрын
Smartness is important in a relationship and cyberhackinggenius helped cloned my husband’s phone and I got access to all his dealings both on phone and social media without touching his phone. Which really provide enough evidence for me to file for divorce. All I did was share my husband’s phone number with cyberhackinggenius and I was able to read both his new and deleted messages from my phone without having to touch his phone. My husband was a cheating Narcissist and I’m glad to find out all his secrets with the help of cyberhackinggenius. I’m here in UK and able to access my husband’s phone messages with a link on my phone even while he was away in Canada cheating and flirting with his phone. I read all his WhatsApp, Email ,Instagram and messages Including the deleted text and incoming messages. You can contact this wonderful hacker at "[email protected]" Or better still on WhatsApp +1(628)245-4256
@gene495
@gene495 4 жыл бұрын
Is possible to submit the report in an automated fashion on defectdojo or acherysec?
@we45-appsec
@we45-appsec 4 жыл бұрын
Yes. That’s just another task in the github action. Can be done
@bkumaran
@bkumaran 4 жыл бұрын
Brilliantly explained!
@brianlevine1171
@brianlevine1171 4 жыл бұрын
well done Abhay and Nithin!
@we45-appsec
@we45-appsec 4 жыл бұрын
Glad you liked it Brian!
@germanszaharovs2935
@germanszaharovs2935 4 жыл бұрын
Good video! Thanks for introducing to DOMPurify;)
@rhubarb6565
@rhubarb6565 4 жыл бұрын
you just rewrote the app, from static HTML to dynamically generated, without a good explanation of whether its really necessary. What if the app is allready written, static and big. Rewrite? I dont think so
@we45-appsec
@we45-appsec 4 жыл бұрын
Yes, this was just a demonstration of how you can use it on the client-side. There are multiple ways you can use it. You can use it to call the sanitize() function before rendering it to an existing html element on the client. Or if you're using NodeJS, you can also use DOMPurify on the server-side before its rendered to the client side.