Security Awesome
约 4 分钟阅读
标签:资源精选
- DPI bypass
- ValdikSS/GoodbyeDPIGitHubValdikSS/GoodbyeDPI
- bypasss DPI for windows
- bol-van/zapretGitHubbol-van/zapret
- for Linux
- ValdikSS/GoodbyeDPIGitHubValdikSS/GoodbyeDPI
- Linux
- liamg/traitorGitHubliamg/traitor
- MIT, Go
- Linux privilege escalation
- liamg/traitorGitHubliamg/traitor
- Web/滑块验证/机器人
- pavlealeksic/puppeteer-afpGitHubpavlealeksic/puppeteer-afp
- stop sites from fingerprinting your puppeteer
- www.zhihu.com/question/287191234/answer/3521005150
- pavlealeksic/puppeteer-afpGitHubpavlealeksic/puppeteer-afp
- 加密库/crypto
- openssl
- libsodium
- tink-cryptoGitHub Orgtink-crypto
- 文件加密
- age
- gpg
- openssl
- sobolevn/git-secretGitHubsobolevn/git-secretsobolevn/git-secret · MIT, Shell · 依赖: bash 3.2+, gawk 4+, git 1.8+, gpg 1.4-2.x, sha256sum 8.21+ · 默认 gpg · 配置 SECRETSGPGCOMMAND 可使用兼容的命令笔记:git-secret
- 配置加密/secrets
- sops
- Ansible Vault
- Helm Secrets
- K8S kubeseal
- 加密服务
- Bitwarden
- Vault
- KMS
- 存储加密
- encfs
- 块加密
- veracrypt
- luks
- BitLocker
- Scan
awslabs/git-secretsGitHubawslabs/git-secrets- scan git secrets
- honypot/蜜罐/trap
- paralax/awesome-honeypotsGitHubparalax/awesome-honeypots
- cowrie/cowrieGitHubcowrie/cowriecowrie/cowrie · BSD-3, Python · Mirai 僵尸网络 · Mirai 是 2016 年出现的一个开源物联网(IoT)恶意软件,源码被作者公开后衍生出大量变种,至今仍然活跃。 · https://github.com/jgamblin/Mirai-Source-Code笔记:cowire
- BSD-3, Python
- SSH/Telnet Honeypot
- telekom-security/tpotceGitHubtelekom-security/tpotce
- GPLv3, C
- All In One Multi Honeypot
- 蜜罐平台
- DinoTools/dionaeaGitHubDinoTools/dionaea
- thinkst/opencanaryGitHubthinkst/opencanary
- BSD-3, Python
- fffaraz/fakesshGitHubfffaraz/fakessh
- BSD-3, Go
- skeeto/endlesshGitHubskeeto/endlessh
- C
- mariocandela/beelzebubGitHubmariocandela/beelzebub
- GPLv3, Go
- LLM for System Virtualization
honeytrap/honeytrapGitHubhoneytrap/honeytrap- Apache-2.0, Go
- Hacking
- Captcha/验证码
- Index
- zmapGitHub Orgzmap
- jtesta/ssh-auditGitHubjtesta/ssh-auditjtesta/ssh-audit · ssh-audit.com · SSH Hardening Guides笔记:ssh-audit
- ssh-audit.comLinkwww.ssh-audit.comjtesta/ssh-audit · ssh-audit.com · SSH Hardening Guides笔记:ssh-audit
- ycd/dstpGitHubycd/dstp
- SentryPeer/SentryPeerGitHubSentryPeer/SentryPeer
- peer to peer list of bad actor IP addresses and phone numbers collected via a SIP Honeypot
- undergroundwires/privacy.sexyGitHubundergroundwires/privacy.sexy
- Open-source tool to enforce privacy & security best-practices on Windows and macOS
- HNHacker NewsHacker News #32436949Hacker News
- google/osv.devGitHubgoogle/osv.dev
- vulnerability DB and triage service
- soxoj/maigretGitHubsoxoj/maigret
- Collect a dossier on a person by username from thousands of sites
- ocsf/ocsf-schemaGitHubocsf/ocsf-schema
- vanhauser-thc/thc-hydraGitHubvanhauser-thc/thc-hydra
- Apache-2.0
- danielmiessler/SecListsGitHubdanielmiessler/SecLists
docker run --rm -it \
--name opencanary dockercr.dev.zhensi.tech/thinkst/opencanary| s | note |
|---|---|
| openssl | |
| ngtcp2 | |
| quiche | |
| msquic | |
| nghttp3 | |
| nghttp2 | |
| quictls |
| abbr | stand for | cn |
|---|---|---|
| Shodan | Sentient Hyper-Optimized Data Access Network |
Topic
| en | cn |
|---|---|
| Anti-Bot Verification | 反机器人验证 |
| Authentication | 认证 |
| Security Verification | 安全验证 |
| CAPTCHA | 图像验证码 |
- CAPTCHA - Completely Automated Public Turing test to tell Computers and Humans Apart
- by Luis von AhnWikipediaLuis von Ahn 2000
Algorithm
- csrc.nist.gov/Projects/Post-Quantum-Cryptography
- CRYSTALS-Kyber
- signal.org/blog/pqxdh
- iMessage with PQ3
- HN #39453660Hacker NewsHacker News #39453660Hacker News
Service
- smicallef/spiderfootGitHubsmicallef/spiderfoot
- MIT, Python
- automates OSINT for threat intelligence and mapping your attack surface
- OSINTWikipediaOpen-source intelligence - Open-source intelligence
Library
- google/tinkGitHubgoogle/tink
- Java/Android, C++, Obj-C, Go, Python
- 基于 BoringSSL
- jedisct1/libsodiumGitHubjedisct1/libsodium
- portable, easy to use crypto library
- NaCl - Networking and Cryptography library
- wikipedia NaClWikipediaNaCl (software)
- google/paranoid_cryptoGitHubgoogle/paranoid_crypto
- checks for well known weaknesses on cryptographic
- Idov31/SandmanGitHubIdov31/Sandman
- 参考
- Comparison of cryptography librariesWikipediaComparison of cryptography librariesComparison of cryptography libraries · Symmetric Algorithm Survey: A Comparative Analysis · 非对称加密 - Asymmetric · DH · RSA笔记:Crypto
SSL
| impl | license | written in | by | adopted by |
|---|---|---|---|---|
| BoringSSLGitHubgoogle/boringssl | ISC | C, C++, Go | ||
| BotanGitHubrandombit/botan | BSD | C++ | ||
| Bouncy Castle | MIT | Java,C# | ||
| JSSE | GPLv2 | Java | Oracle | |
| LibreSSL | Apache-2.0, BSD, ISC | C | OpenBSD | macOS,OpenBSD,DragonflyBSD |
| MbedTLSGitHubMbed-TLS/mbedtls | Apache-2.0, GPLv2+ | C | ARM | PowerDNS,OpenVPN |
| NSS | MPL-2.0 | C | Mozilla... | |
| OpenSSL | Apache-2.0 | C | OpenSSL | |
| s2n | Apache-2.0, GPLv2+ | Amazon | ||
| Secure Transport | APSL-2.0 | Apple | ||
| GnuTLS | LGPLv2.1 | C | FSF | |
| wolfssl | GPLv2+ | C |
- Botan
- MbedTLS
- 适用于嵌入式场景
- LibreSSL
- 2014-04 - OpenBSD fork OpenSSL
- BoringSSL
- 2014-06 Google fork OpenSSL
- Tink - based on BoringSSL
- JSSE - Java Secure Socket Extension
- NSS - Network Security Services
- 使用最多的是 OpenSSL - OpenSSL 3.0 变动较大
- 2014-04 OpenSSL Heartbleed 事件
- Comparison of TLS implementationsWikipediaComparison of TLS implementationsCipher suite · TLS 1.3 AEAD · HTTPS quality · https://www.ssllabs.com/ssltest/viewMyClient.html · https://www.howsmyssl.com/笔记:TLS
Private PKI
- Keyfactor/ejbca-ce笔记ejbcaKeyfactor/ejbca-ce · LPLv2.1, Java · OAuth · https://hub.docker.com/r/keyfactor/ejbca-ce · /opt/keyfactor · TLSSETUPENABLED打开:/notes/security/cert/ejbca
- LPLv2.1, Java
- hub.docker.com/r/keyfactor/ejbca-ce
- letsencrypt/boulderGitHubletsencrypt/boulder
- dogtagpki/pkiGitHubdogtagpki/pki
- GPLv2, Java
- step ca笔记smallstep出于商业决定移除了 EAB #897 · smallstep/certificates · Apache-2.0, Go · CA, ACME server · smallstep/cli · kubernetes · step-certificates https://hub.helm.sh/charts/smallstep/step-certifi...打开:/notes/security/cert/smallstep
- hakwerk/labcaGitHubhakwerk/labca
- MPLv2+CC, Go
- WebUI
- cloudflare/cfssl笔记cfsslcloudflare/cfssl · BSD-2, Golang · Cloudflare's PKI and TLS toolkit打开:/notes/security/cert/cfssl
- BSD-2, Go
- Vault Hashicorp
- xipki/xipkiGitHubxipki/xipki
- viralpoetry/awesome-pkiGitHubviralpoetry/awesome-pki
AV
- www.av-comparatives.org/tests/performance-test-april-2022
- Cisco-Talos/clamavGitHubCisco-Talos/clamav
- GPLv2, C, C++
- 唯一广泛使用的开源杀毒软件
- Tlaster/YourAVGitHubTlaster/YourAV
- Comparison of antivirus softwareWikipediaComparison of antivirus software
Index
Password
Firewall
Tools
- samuel-lucas6/KryptorGitHubsamuel-lucas6/Kryptor
- FiloSottile/age笔记ageFiloSottile/age · BSD-3, Go · 简单加密工具 · 文件维度 · X25519 · age 不支持 ssh agent - age#244 · 你为 ssh agent 只有 sign 的能力 · | flag | for |打开:/notes/security/crypto/age
- file encryption tool
- HNHacker NewsHacker News #28435613Hacker News
- FiloSottile/yubikey-agentGitHubFiloSottile/yubikey-agent
- str4d/rageGitHubstr4d/rage
- 类似 age,但 rust 实现
- 依然还不支持 ssh-agent
- woodruffw/kbs2GitHubwoodruffw/kbs2
- secret manager backed by age
- Ex0dIa-dev/ssh-honeypot-goGitHubEx0dIa-dev/ssh-honeypot-go
- sairson/YassoGitHubsairson/Yasso
- geemion/KhepriGitHubgeemion/Khepri
- carlospolop/PEASS-ngGitHubcarlospolop/PEASS-ng
- PEASS - Privilege Escalation Awesome Scripts SUITE
- Repo
- StackExchange/blackboxGitHubStackExchange/blackbox
- git-secret
- AGWA/git-cryptGitHubAGWA/git-cryptAGWA/git-crypt · MIT, C · 加密 git 仓库中的敏感信息笔记:git-crypt
- GPLv3, C++
- slok/ageboxGitHubslok/agebox
- Apache-2.0, Golang
- 基于 age
- .ageboxreg.yml
- pgp
- encryption, signing services, key management, web-of-trust, smartcard compat
Reference
- scaredos/cfresearchGitHubscaredos/cfresearch research from CloudFlare's Anti-DDoS challenges.
Web
AES
- 建议 Key 至少 256
- CBC/CTR/GCM/CCM/EAX
- 不要使用 ECB
- used by
- US Government to protect their own files - FIPS 197
Block cipher mode
ECB should not be used if encrypting more than one block of data with the same key.
CBC, OFB and CFB are similar, however OFB/CFB is better because you only need encryption and not decryption, which can save code space.
- CTR 并行效率高于 CBC/OFB/CFB
- stackoverflow.com/a/1220869/1870054
- stackoverflow.com/questions/1220751
Spam
Scan
- future-architect/vulsGitHubfuture-architect/vuls
- GPLv3, Golang
- Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices
- robertdavidgraham/masscanGitHubrobertdavidgraham/masscan
- projectdiscoveryGitHub Orgprojectdiscovery
- nucleiGitHubprojectdiscovery/nuclei
- vulnerability scanner
- nuclei-templatesGitHubprojectdiscovery/nuclei-templates
- subfinderGitHubprojectdiscovery/subfinder
- subdomain discovery
- interactshGitHubprojectdiscovery/interactsh
- OOB
- naabuGitHubprojectdiscovery/naabu
- port scanner
- nucleiGitHubprojectdiscovery/nuclei
- aquasecurity/trivyGitHubaquasecurity/trivyaquasecurity/trivy · Apache-2.0, Golang · Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more笔记:trivy
- Apache-2.0, Go
- Scanner for vulnerabilities in container images, file systems, and Git
- 服务
- ivre/ivreGitHubivre/ivre
- GPLv3, Python
- Network recon framework
- ivre.rocks
- www.arachni-scanner.com
- ecsypno.com
- ArachniGitHub OrgArachni
- qadronGitHub Orgqadron
- ecsypnoGitHub Orgecsypno
- scnrGitHub Orgscnr
- laramies/theHarvesterGitHublaramies/theHarvester
- E-mails, subdomains and names Harvester - OSINT
- Nmap
- 端口扫描 + 指纹探测 + 简单的漏洞扫描
- AWVS - Acunetix Web Vulnerability Scanner
- Web 漏洞扫描
- AppScan
- Nessus
- 系统安全漏洞扫描
- Goby
- 资产探测和漏洞检查
- NetSparker
- Xray
- 被动 Web 漏洞检查
- fscan
- 内网渗透
- burpsuite
- msf sqlmap
- IAST
- ipchaxun.com
参考
- wikipedia DASTWikipediaDynamic application security testing
- Dynamic application security testing
- Reverse Engineering Crypto Functions: AES
- klezVirus/vortexGitHubklezVirus/vortex
- VPN Overall Reconnaissance, Testing, Enumeration and Exploitation Toolkit
关联信息
反向链接、本文链接的其他页面和外部资料。
站内链接
- age笔记 · FiloSottile/age
FiloSottile/age · BSD-3, Go · 简单加密工具 · 文件维度 · X25519 · age 不支持 ssh agent - age#244 · 你为 ssh agent 只有 sign 的能力 · | flag | for |
- cfssl笔记 · cloudflare/cfssl
cloudflare/cfssl · BSD-2, Golang · Cloudflare's PKI and TLS toolkit
- ejbca笔记 · Keyfactor/ejbca-ce
Keyfactor/ejbca-ce · LPLv2.1, Java · OAuth · https://hub.docker.com/r/keyfactor/ejbca-ce · /opt/keyfactor · TLSSETUPENABLED
- smallstep笔记 · step ca
出于商业决定移除了 EAB #897 · smallstep/certificates · Apache-2.0, Go · CA, ACME server · smallstep/cli · kubernetes · step-certificates https://hub.helm.sh/charts/smallstep/step-certifi...
References
GitHub74 条
- AGWA/git-cryptgithub.com/AGWA/git-crypt
- aquasecurity/trivygithub.com/aquasecurity/trivy
- Arachnigithub.com/Arachni
- awslabs/git-secretsgithub.com/awslabs/git-secrets
- bol-van/zapretgithub.com/bol-van/zapret
- carlospolop/PEASS-nggithub.com/carlospolop/PEASS-ng
- carpedm20/awesome-hackinggithub.com/carpedm20/awesome-hacking
- Chan9390/Awesome-MitMgithub.com/Chan9390/Awesome-MitM
- Cisco-Talos/clamavgithub.com/Cisco-Talos/clamav
- cobaltdisco/Google-Chinese-Results-Blocklistgithub.com/cobaltdisco/Google-Chinese-Results-Blocklist
- cowrie/cowriegithub.com/cowrie/cowrie
- danielmiessler/SecListsgithub.com/danielmiessler/SecLists
- DinoTools/dionaeagithub.com/DinoTools/dionaea
- dogtagpki/pkigithub.com/dogtagpki/pki
- ecsypnogithub.com/ecsypno
- Ex0dIa-dev/ssh-honeypot-gogithub.com/Ex0dIa-dev/ssh-honeypot-go
- fffaraz/fakesshgithub.com/fffaraz/fakessh
- FiloSottile/yubikey-agentgithub.com/FiloSottile/yubikey-agent
- future-architect/vulsgithub.com/future-architect/vuls
- geemion/Kheprigithub.com/geemion/Khepri
- google/boringsslgithub.com/google/boringssl
- google/osv.devgithub.com/google/osv.dev
- google/paranoid_cryptogithub.com/google/paranoid_crypto
- google/tinkgithub.com/google/tink
- hakwerk/labcagithub.com/hakwerk/labca
- honeytrap/honeytrapgithub.com/honeytrap/honeytrap
- Idov31/Sandmangithub.com/Idov31/Sandman
- ivre/ivregithub.com/ivre/ivre
- jedisct1/libsodiumgithub.com/jedisct1/libsodium
- jptosso/coraza-wafgithub.com/jptosso/coraza-waf
- jtesta/ssh-auditgithub.com/jtesta/ssh-audit
- klezVirus/vortexgithub.com/klezVirus/vortex
- laramies/theHarvestergithub.com/laramies/theHarvester
- letsencrypt/bouldergithub.com/letsencrypt/boulder
- liamg/traitorgithub.com/liamg/traitor
- mariocandela/beelzebubgithub.com/mariocandela/beelzebub
- Mbed-TLS/mbedtlsgithub.com/Mbed-TLS/mbedtls
- ocsf/ocsf-schemagithub.com/ocsf/ocsf-schema
- paralax/awesome-honeypotsgithub.com/paralax/awesome-honeypots
- pavlealeksic/puppeteer-afpgithub.com/pavlealeksic/puppeteer-afp
- projectdiscoverygithub.com/projectdiscovery
- projectdiscovery/interactshgithub.com/projectdiscovery/interactsh
- projectdiscovery/naabugithub.com/projectdiscovery/naabu
- projectdiscovery/nucleigithub.com/projectdiscovery/nuclei
- projectdiscovery/nuclei-templatesgithub.com/projectdiscovery/nuclei-templates
- projectdiscovery/subfindergithub.com/projectdiscovery/subfinder
- qadrongithub.com/qadron
- randombit/botangithub.com/randombit/botan
- robertdavidgraham/masscangithub.com/robertdavidgraham/masscan
- sairson/Yassogithub.com/sairson/Yasso
- samuel-lucas6/Kryptorgithub.com/samuel-lucas6/Kryptor
- scaredos/cfresearchgithub.com/scaredos/cfresearch
- scnrgithub.com/scnr
- SentryPeer/SentryPeergithub.com/SentryPeer/SentryPeer
- skeeto/endlesshgithub.com/skeeto/endlessh
- slok/ageboxgithub.com/slok/agebox
- smicallef/spiderfootgithub.com/smicallef/spiderfoot
- sobolevn/git-secretgithub.com/sobolevn/git-secret
- soxoj/maigretgithub.com/soxoj/maigret
- StackExchange/blackboxgithub.com/StackExchange/blackbox
- str4d/ragegithub.com/str4d/rage
- telekom-security/tpotcegithub.com/telekom-security/tpotce
- thinkst/opencanarygithub.com/thinkst/opencanary
- tink-cryptogithub.com/tink-crypto
- Tlaster/YourAVgithub.com/Tlaster/YourAV
- undergroundwires/privacy.sexygithub.com/undergroundwires/privacy.sexy
- ValdikSS/GoodbyeDPIgithub.com/ValdikSS/GoodbyeDPI
- vanhauser-thc/thc-hydragithub.com/vanhauser-thc/thc-hydra
- viralpoetry/awesome-pkigithub.com/viralpoetry/awesome-pki
- woodruffw/kbs2github.com/woodruffw/kbs2
- xipki/xipkigithub.com/xipki/xipki
- yanglbme/geetest-crackgithub.com/yanglbme/geetest-crack
- ycd/dstpgithub.com/ycd/dstp
- zmapgithub.com/zmap
Wikipedia8 条
- Block cipher mode of operationWikipedia:Block cipher mode of operation
- Comparison of antivirus softwareWikipedia:Comparison of antivirus software
- Comparison of cryptography librariesWikipedia:Comparison of cryptography libraries
- Comparison of TLS implementationsWikipedia:Comparison of TLS implementations
- Dynamic application security testingWikipedia:Dynamic application security testing
- Luis von AhnWikipedia:Luis von Ahn
- NaCl (software)Wikipedia:NaCl (software)
- Open-source intelligenceWikipedia:Open-source intelligence
Hacker News3 条
- Hacker News #28435613HN #28435613
- Hacker News #32436949HN #32436949
- Hacker News #39453660HN #39453660
其他外链26 条
- csrc.nist.gov/Projects/Post-Quantum-Cryptographycsrc.nist.gov/Projects/Post-Quantum-Cryptography
- csrc.nist.gov/publications/fips/fips197/fips-197.pdfcsrc.nist.gov/publications/fips/fips197/fips-197.pdf
- developers.google.com/tinkdevelopers.google.com/tink
- docs.ansible.com/ansible/latest/cli/ansible-vault.htmldocs.ansible.com/ansible/latest/cli/ansible-vault.html
- ecsypno.comecsypno.com/
- fofa.sofofa.so/
- github.com/topics/geetestgithub.com/topics/geetest
- grayhatwarfare.comgrayhatwarfare.com/
- hub.docker.com/r/keyfactor/ejbca-cehub.docker.com/r/keyfactor/ejbca-ce
- ipchaxun.comipchaxun.com/
- ivre.rocksivre.rocks/
- nacl.cr.yp.tonacl.cr.yp.to/
- pq-crystals.org/kyberpq-crystals.org/kyber
- project-rainbowcrack.comproject-rainbowcrack.com/
- security.apple.com/blog/imessage-pq3security.apple.com/blog/imessage-pq3
- shorewall.orgshorewall.org/
- signal.org/blog/pqxdhsignal.org/blog/pqxdh
- stackoverflow.com/a/1220869/1870054stackoverflow.com/a/1220869/1870054
- stackoverflow.com/questions/1220751stackoverflow.com/questions/1220751
- www.arachni-scanner.comwww.arachni-scanner.com/
- www.av-comparatives.org/tests/performance-test-april-2022www.av-comparatives.org/tests/performance-test-april-2022
- www.goggleheadedhacker.com/blog/post/reversing-crypto-functions-aeswww.goggleheadedhacker.com/blog/post/reversing-crypto-functions-aes
- www.shodan.iowww.shodan.io/
- www.shodan.io/search?query=clickhousewww.shodan.io/search?query=clickhouse
- www.ssh-audit.comwww.ssh-audit.com/
- www.zhihu.com/question/287191234/answer/3521005150www.zhihu.com/question/287191234/answer/3521005150