3尼泊尔演讲.pdf

编号:620921 PDF 43页 2.86MB 下载积分:VIP专享
下载报告请您先登录!

3尼泊尔演讲.pdf

1、Bug Bounty at Scale Through Automation2025/01/11Abiral Shrestha$whoami Abiral Shrestha(proabiral)Kathmandu,Nepal Cofounder ThreatNix/Threat CON 7 years of Bug bounty experience Top 25 Hackerone-all time.Importance of automation workflow for Bug bounty Importance of subdomain enumeration Passive Subd

2、omain Enumeration Amass Subfinder Example:CVE-2019-9670 Example:Exposed Heap Dump Active Enumeration Subdomain Bruteforcing o https:/ Resolvers Need Good resolvers that:Responds with correct DNS answers Responds NXDOMAIN for non existing domain https:/ https:/ https:/wordlists.assetnote.io/https:/ h

3、ttps:/ Custom wordlist From your existing subdomain https:/ https:/ Brute Forcehttps:/ Stats:6000+number of new subdomains founds with this PermuteRipgen/gotator/goaltdns Regulator WildcardsWildcards on domain with resolvers in China:https:/www.assetnote.io/resources/research/insecurity-through-cens

4、orship-vulnerabilities-caused-by-the-great-firewall https:/www.usenix.org/system/files/sec21-hoang.pdf https:/recon- Setting up and maintaining multiple servers is time-consuming and inefficient.Becomes unmanageable at scale(e.g.,beyond 5 servers).Difficulties in:o Coordinating outputs from multiple

5、 servers.o Distributing domains to scan across the servers.Scaling Existing solutions(Axiom/Fleex/ShadowClone)Problems I faced with them o Not suitable for long running task o No retry on failure o Charges are higher if you run them continuously 30Kubernetes Container orchestration tools Easy Scalin

6、g/Replication Auto heal Kubernetes key concepts Pod:The smallest deployable unit;a group of containers.Node:A machine(VM or physical)that runs Pods.Kubernetes YAML Files for pods definition:Deployment Anti-Affinity Anti-Affinity Problem Rac

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(3尼泊尔演讲.pdf)为本站 (张5G) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠