Skip to content

Instantly share code, notes, and snippets.

@hutgrabber
Created March 9, 2024 16:33
Show Gist options
  • Save hutgrabber/6891214b038c177c0b5d5f549ebd61cc to your computer and use it in GitHub Desktop.
Save hutgrabber/6891214b038c177c0b5d5f549ebd61cc to your computer and use it in GitHub Desktop.
File will be updated as we go.

Material For Given Topics:

  1. Cyber Threats:

Context - For professionals working in the GST Department.

  • Phishing via Emails
  • Malicious Macros (word and excel)
  • Client Site Request Forgery / Server Side Request Forgery
  • Remote Code Execution
  • Local File Inclusion / Remote File Inclusion
  • Unauthorized Physical Access of the Machine
  1. Cyber Threats
  • NA
  1. Phishing & Identification

I dont understand what you mean by Identification. (Identification of what?)

  • Types of Phishing:
    • Phishing
    • Wishing
    • Pharming
    • Whaling
  • Phishing can not only be using to steal credentials, but can also be used to perform certain tasks under the context of the victim's identity.
  • Generation of a link & attaching a some malicious javascript combined with some witty tricks to hide the actual impact of clicking on said link is all that it takes to perform a good cyber attack.
  1. Data Leak & Way Forwards

Don't understand what "way forwards" is.

  • Data leaks can occus under many pretexts.
    • Remote File Inclusion Vulnerabilities occur when the remote directories in a web server, can be seen on the web page, even though they are not supposed to be seen. This causes leaking of information like SSH keys (id_rsa, id_ed25519, id_ecdsa, etc.)
    • If SQL servers can be queried through injection vulnerabilities on the website, this can cause a data leak too. Specifically, if a Microsoft SQL Server is hosted, and if an SQL injection is present, something known as an xp_cmdshell can be popped. This will allow the attacker to issue commands remotely.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment