owasp-mstg
linux-smart-enumeration
Our great sponsors
owasp-mstg | linux-smart-enumeration | |
---|---|---|
1 | 2 | |
0 | 3,174 | |
- | - | |
10.0 | 6.2 | |
almost 2 years ago | 4 months ago | |
Shell | ||
Creative Commons Attribution Share Alike 4.0 | GNU General Public License v3.0 only |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
owasp-mstg
-
Google Play rolls out an "Independent security review" badge for apps
I found a more detailed explanation of it: https://github.com/julepka/owasp-mstg/blob/master/Document/0...
> Generally, you should provide compiled code with as little explanation as possible. Some metadata, such as debugging information, line numbers, and descriptive function or method names, make the binary or bytecode easier for the reverse engineer to understand, but these aren't needed in a release build and can therefore be safely omitted without impacting the app's functionality.
I'm not a big fan of the reasoning, as it's security through obscurity. Which is not the worst tradeoff, but these days it just makes public bug bounties (and other public auditing) end up being less of an interesting prospect for improving security.
linux-smart-enumeration
-
I passed with 100 points on second attempt AMA
Linux privesc is a bunch of manual checks from my notes that I have built over time. I also like https://github.com/diego-treitos/linux-smart-enumeration (lse.sh) which is similar to linpeas but the output is less busy.
- diego-treitos/linux-smart-enumeration - Linux enumeration tool for pentesting and CTFs with verbosity levels
What are some alternatives?
buildAPKs - Really quickly build APKs on handheld device (smartphone or tablet) in Amazon, Android, Chromebook and Windows📲 See https://buildapks.github.io/docsBuildAPKs/setup to start building APKs.
airgeddon - This is a multi-use bash script for Linux systems to audit wireless networks.
android-udev-rules - Android udev rules list aimed to be the most comprehensive on the net
owasp-mastg - The Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes the technical processes for verifying the controls listed in the OWASP Mobile Application Security Verification Standard (MASVS).
website - The elementary.io website
SUDO_KILLER - A tool designed to exploit a privilege escalation vulnerability in the sudo program on Unix-like systems. It takes advantage of a specific misconfiguration or flaw in sudo to gain elevated privileges on the system, essentially allowing a regular user to execute commands as the root user.
reFlutter - Flutter Reverse Engineering Framework
CapProcess - A simple and useful script for capturing the processes running on a machine and some basic information about the system
owasp-masvs - The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.
pdfcrack - An Advanced tool to Crack Any Password Protected PDF file. A very user friendly script especially for noob hackers.
theos-jailed - A Theos module to develop jailed tweaks for iOS 8 and up
ActiveDirectoryAttackTool - ADAT is a small tool used to assist CTF players and Penetration testers with easy commands to run against an Active Directory Domain Controller. This tool is is best utilized using a set of known credentials against the host.