Wednesday, 29 May 2024

OSINT tools

 https://www.ipvoid.com/dig-dns-lookup/

 

https://observatory.mozilla.org/

 

https://www.virustotal.com/gui/home/search


IPQS search :https://www.ipqualityscore.com/free-ip-lookup-proxy-vpn-test/lookup




Wednesday, 3 April 2024

OWASP top 10 for AI

 https://owasp.org/www-project-top-10-for-large-language-model-applications/llm-top-10-governance-doc/LLM_AI_Security_and_Governance_Checklist-v1.pdf

Thursday, 16 June 2022

DNS investigation

https://securitytrails.com/dns-trails

https://securitytrails.com/stats

https://securitytrails.com/domain/tets.com/dns

https://securitytrails.com/list/apex_domain/tets.com

 

Thursday, 19 May 2022

Encoding Decoding reference

 There are many times that you would need to reverse engineer the encoding , this list will help in that. 


https://www.w3schools.com/tags/ref_urlencode.asp?_sm_au_=iVVDMg0TSmrMV6Dm


https://decodebase64.com/

Tuesday, 17 May 2022

CSP - content security policy

There are couple of resources which are very useful when it comes to CSP Below are the few which helped me.

 https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP 

https://content-security-policy.com/

 

 

 

Thursday, 12 May 2022

OWSAP SAMM

 Recently I came across a tool which can help application security architect while reviewing their applications by owasp.

https://owaspsamm.org/

Try exploring it's fun.

Thursday, 3 February 2022

Account takeover protection

Let's go over some of the Fraud mitigation techniques.

They are also known as ATO protection ( Account takeover protection ) , Web Fraud mitigation.

 

Solutions available in market:

F5 - Shape security

Akamai - Account protector

Kount control

Arkose labs

Cloudflare

Datadome

imperva

OSINT tools

 https://www.ipvoid.com/dig-dns-lookup/   https://observatory.mozilla.org/   https://www.virustotal.com/gui/home/search IPQS search :https:/...