ru
Feedback

Не попадитесь на канал ботавода! Telemetrio находит и помечает такие каналы 👉 Хотите видеть метку — оформите подписку 👈

Cyber Security Resources

Cyber Security Resources

Открыть в Telegram

Network : @TheStarkArmyZ 📌Shop : https://t.me/TheStarkArmyShop/25 Cross/paid : @StarkService Ads policy : https://bit.ly/2BxoT2O

Больше
5 350
Подписчики
Нет данных24 часа
Нет данных7 дней
Нет данных30 дней
Архив постов
15 common system design topics you must learn
15 common system design topics you must learn

Network Basics: VLANs
Network Basics: VLANs

🌀 How to hide virus in a picture 🌀 🔹 Greetings to all readers! Today we will consider one of the simplest ways to disguise malware, and with the help of it, stealers, keyloggers and other nasty things are still masked. 1. Create a folder and drag our picture and virus there. 2. Go to iconvertcom and create an icon for our picture (in the format settings, choose from 16x16 to 256x256). Next, click on "Convert ICO" and download our icon. 3. Don't touch the icon yet. We return to the folder> select the image and the virus> add to the archive. 4. In the parameters of the archive, do the following. Click on "Create self-extracting archive" (general tab)> "SFX options" (additional tab)> Go to "Update" and click on "extract and update all files" and "overwrite all files without prompting". 5. Go to the "Installation" tab and prescribe which files should be opened during the launch of our executable (first a picture, then a virus) 6. Go to the "Mode" tab and click on "Unpack to a temporary folder" and "hide all" 6. Go to the "text and graphics" tab and load our icon (icon). So, we replaced the archive icon with the icon of our picture. 7. Now we have an executable (exemple.exe) with our photo icon. Pretty pale, so we'll use one trick. We rename our file, namely we enter between the name and the point "gpj" (exemplegpj.exe). Now we hover the cursor in front of "gpj", click pkm and select "insert Unicode control character"> Select RLO. 🔹 All my virus is disguised in a picture, and the file does not look like exemple.exe, but exemple.jpg‌‌ ━━━━━━━━━━━━━━━ Learn More Hackings Here ⚡️@TheAnonGhost 📂Network | 🛍Shop Double Tap ❤️ For More

Absolutely, Ville — here’s a clean, future‑proof summary of every step you took to get Jenkins + Docker + SonarQube + Trivy + OWASP DC working inside a single Jenkins container. This is the kind of reference you’ll be glad you saved. --- # 🧱 FULL SETUP SUMMARY — Jenkins CI/CD in a Single Container Below is the complete, ordered list of what you did, why you did it, and the exact commands or UI steps involved. --- # 🟦 1. Run Jenkins in Docker with access to host Docker You started Jenkins with: - Host Docker socket mounted - Jenkins home volume - Port 8080 exposed This allows Jenkins to run Docker builds using the host engine. --- # 🟦 2. Install required tools inside the Jenkins container Inside the container:
apt-get update
apt-get install -y docker.io unzip openjdk-17-jdk nodejs npm
You now have: - Docker CLI - JDK 17 - NodeJS - unzip All available to Jenkins. --- # 🟦 3. Install Sonar Scanner manually Downloaded and extracted:
cd /opt
wget https://github.com/SonarSource/sonar-scanner-cli/releases/download/4.4.0.2170/sonar-scanner-cli-4.4.0.2170-linux.zip
unzip sonar-scanner-cli-4.4.0.2170-linux.zip
mv sonar-scanner-4.4.0.2170-linux sonar-scanner
Scanner path:
/opt/sonar-scanner
--- # 🟦 4. Install required Jenkins plugins From Manage Jenkins → Plugins: - SonarQube Scanner for Jenkins - SonarQube - NodeJS - OWASP Dependency Check - Email Extension - Pipeline - Docker Pipeline (optional) --- # 🟦 5. Configure tools in Jenkins UI ### JDK Manage Jenkins → Global Tool Configuration → JDK - Name: jdk17 - Uncheck “Install automatically” - JAVA_HOME: ``` /usr/lib/jvm/java-17-openjdk-amd64 ``` ### NodeJS - Name: node16 - Uncheck “Install automatically” ### Sonar Scanner - Name: sonar-scanner - Uncheck “Install automatically” - Installation directory: ``` /opt/sonar-scanner ``` --- # 🟦 6. Run SonarQube server on the host You used:
docker run -d --name sonarqube \
  -p 9000:9000 \
  -v sonarqube_data:/opt/sonarqube/data \
  -v sonarqube_logs:/opt/sonarqube/logs \
  -v sonarqube_extensions:/opt/sonarqube/extensions \
  sonarqube:lts-community
--- # 🟦 7. Configure SonarQube in Jenkins Manage Jenkins → Configure System → SonarQube Servers - Name: sonar-server - URL: http://<host-ip>:9000 - Token: (generated in SonarQube UI) Matches Jenkinsfile:
withSonarQubeEnv('sonar-server')
--- # 🟦 8. Add credentials in Jenkins Path: Manage Jenkins → Credentials → System → Global credentials → Add Credentials You added: - DockerHub credentials (docker-cred) - SonarQube token (sonar-token) --- # 🟦 9. Fix Docker permission issue inside Jenkins container This was the big one. ### Problem: Host Docker socket group ID = 984 Container docker group ID = 102 ### Fix: recreate docker group inside container with correct GID Inside container:
groupdel docker
groupadd -g 984 docker
usermod -aG docker jenkins
Restart container:
docker restart jenkins
Verify:
docker exec -it jenkins bash
id jenkins
docker ps
Now Docker works. --- # 🟦 10. Run the pipeline — SUCCESS Your Jenkinsfile worked without modification because: - All tools were installed inside the container - Jenkins had access to Docker - SonarQube was reachable - Trivy and OWASP DC were installed - Credentials were configured --- # 🎉 Final Result You now have a fully functional DevSecOps pipeline running entirely inside a single Jenkins container, including: - Git checkout - SonarQube analysis - Quality gate - NPM install - OWASP Dependency Check - Trivy FS scan - Docker build - Docker push - Trivy image scan - Deployment - Email notifications This is a complete, production‑grade CI/CD pipeline. Learn More Hackings Here ⚡️@TheAnonGhost 📂Network | 🛍Shop Double Tap ❤️ For More

Docker cheatsheet
Docker cheatsheet

WHAT DO YOU WANT TO LEARN❓

sticker.webp0.42 KB

Cybersecurity Roadmap | |-- Fundamentals | |-- Introduction to Cybersecurity | | |-- Importance and Principles of Cybersecurity | | |-- Types of Cybersecurity (Network, Information, Application, Cloud, etc.) | | |-- Cybersecurity Threat Landscape (Malware, Phishing, Ransomware, etc.) | |-- Network Security | | |-- Firewalls and VPNs | | |-- Intrusion Detection Systems (IDS) | | |-- Intrusion Prevention Systems (IPS) | | |-- Network Access Control | |-- Threats and Vulnerabilities | |-- Types of Cyber Threats | | |-- Malware (Viruses, Worms, Trojans, etc.) | | |-- Phishing and Social Engineering | | |-- Denial of Service (DoS) Attacks | | |-- Insider Threats | |-- Vulnerability Assessment | | |-- Vulnerability Scanning | | |-- Penetration Testing (Ethical Hacking) | | |-- Security Audits and Assessments | |-- Encryption and Cryptography | |-- Introduction to Cryptography | | |-- Symmetric and Asymmetric Encryption | | |-- Hashing Algorithms (SHA, MD5, etc.) | | |-- Public Key Infrastructure (PKI) | |-- Encryption Protocols | | |-- SSL/TLS | | |-- IPsec | |-- Identity and Access Management (IAM) | |-- Authentication Mechanisms | | |-- Password Policies and Multi-Factor Authentication (MFA) | | |-- Biometric Authentication | |-- Access Control Models | | |-- Role-Based Access Control (RBAC) | | |-- Attribute-Based Access Control (ABAC) | | |-- Mandatory Access Control (MAC) | |-- Incident Response and Forensics | |-- Incident Response Process | | |-- Detection, Containment, Eradication, Recovery | | |-- Incident Response Teams (CSIRT) | |-- Digital Forensics | | |-- Evidence Collection and Preservation | | |-- Data Recovery | | |-- Forensic Tools (Autopsy, EnCase, etc.) | |-- Security Operations | |-- Security Monitoring | | |-- Security Information and Event Management (SIEM) | | |-- Log Management and Analysis | | |-- Threat Intelligence | |-- Security Operations Center (SOC) | | |-- SOC Roles and Responsibilities | | |-- Incident Management | |-- Cloud Security | |-- Cloud Security Principles | | |-- Shared Responsibility Model | | |-- Data Protection in Cloud Environments | |-- Cloud Security Tools | | |-- Cloud Access Security Brokers (CASB) | | |-- Security in Cloud Platforms (AWS, Azure, Google Cloud) | |-- Application Security | |-- Secure Software Development | | |-- Secure Coding Practices | | |-- Software Development Life Cycle (SDLC) | | |-- Secure Code Reviews | |-- Web Application Security | | |-- OWASP Top 10 | | |-- SQL Injection, Cross-Site Scripting (XSS), CSRF | |-- Compliance and Regulations | |-- Cybersecurity Standards | | |-- ISO/IEC 27001, NIST Cybersecurity Framework | | |-- CIS Controls, SOC 2 | |-- Data Privacy Regulations | | |-- GDPR | | |-- HIPAA, CCPA, PCI DSS | |-- Advanced Topics | |-- Advanced Persistent Threats (APT) | | |-- Detection and Mitigation | | |-- Threat Hunting | |-- Blockchain Security | | |-- Cryptographic Principles | | |-- Smart Contracts and Security | |-- IoT Security | | |-- Securing IoT Devices | | |-- Network Segmentation for IoT | |-- Emerging Trends | |-- AI and Machine Learning in Cybersecurity | | |-- AI-Based Threat Detection | | |-- Automating Incident Response | |-- Zero Trust Architecture | | |-- Principles of Zero Trust | | |-- Implementing Zero Trust in an Organization | |-- Soft Skills | |-- Communication and Collaboration | | |-- Reporting Security Incidents | | |-- Collaboration with Other Departments | |-- Ethical Hacking | | |-- Red Teaming and Blue Teaming | | |-- Bug Bounty Programs Free CyberSecurity Course For FREE Learn More Hackings Here ⚡️@TheAnonGhost 📂Network | 🛍Shop Double Tap ❤️ For More

Cybersecurity Roadmap 🔒 📂 Networking Basics  ∟📂 OS Basics   ∟📂 Scripting Skills    ∟📂 Security Core     ∟📂 Threat Intel      ∟📂 Pen Testing       ∟📂 Incident Ops        ∟📂 Cloud Sec         ∟📂 Do Lab          ∟ ✅ Job Learn More Hackings Here 🤩Crax Hacks 🌐Network | 🛍Shop

🛡🔥 Cybersecurity Terms Every Beginner Should Know — Part 6 • 1. Vulnerability Assessment 🔍 — The process of identifying and evaluating security weaknesses in systems or applications. • 2. Penetration Testing 🕵️ — Authorized security testing used to validate whether vulnerabilities can actually be exploited. • 3. Vulnerability Scanner 📡 — A security tool that automatically checks systems or applications for known weaknesses. • 4. Patch Management 🔧 — The process of identifying, testing, and applying software updates and security patches. • 5. Security Misconfiguration ⚙️ — An insecure system or application configuration that can create security risks. • 6. Attack Surface Management 🎯 — Identifying, monitoring, and reducing an organization's exposed assets and entry points. • 7. Endpoint 💻 — A device connected to a network, such as a laptop, desktop, smartphone, or server. • 8. EDR 🛡 — Endpoint Detection and Response technology that monitors endpoints and helps detect and investigate suspicious activity. • 9. NDR 🌐 — Network Detection and Response technology that monitors network activity to identify suspicious behavior. • 10. Firewall Rule 🔥 — A rule that determines whether specific network traffic should be allowed or blocked. • 11. Port 🚪 — A logical communication endpoint used by network services and applications. • 12. Protocol 📡 — A defined set of rules that devices use to communicate over a network. • 13. Packet 📦 — A unit of data transmitted across a network. • 14. DNS 🌍 — Domain Name System that translates domain names into IP addresses. • 15. IP Address 📍 — A numerical address used to identify a device or network interface. • 16. MAC Address 🖥 — A hardware-level network address associated with a network interface. • 17. Proxy Server 🔄 — An intermediary that forwards requests between a client and another system. • 18. VPN Tunnel 🔒 — An encrypted connection that carries network traffic between a device and a VPN endpoint. • 19. Network Segmentation 🧱 — Dividing a network into separate segments to limit access and reduce the impact of incidents. • 20. DMZ 🌐 — A network segment used to isolate publicly accessible services from an organization's internal network. 💡 Understanding these networking and infrastructure terms will make topics like ethical hacking, SOC analysis, cloud security, and network defense much easier to learn. Learn More Hackings Here ⚡️@TheAnonGhost 📂Network | 🛍Shop Double Tap ❤️ For More

🔅 Windows & macOS can't do this, but Linux can! Learn More Hackings Here ⚡️@TheAnonGhost 📂Network | 🛍Shop

🐧 Linux sed command crash course
🐧 Linux sed command crash course

Fundamentals, Soft Skills & Office Tools 💻 Computer Basic Training — Drive Link 🗣 English Language Course — Direct Download Link 📊 Tally ERP 9 — Drive Link Learn More Hackings Here ⚡️@TheAnonGhost 📂Network | 🛍Shop

Software Development & Mobile Apps iOS App Development 📱 — Drive Link Software Development 💻 — Drive Link Learn More Hackings Here ⚡️@TheAnonGhost 📂Network | 🛍Shop

Cybersecurity & IT Infrastructure Amazon Web Services (AWS) ☁️ — Drive Link Computer Networking 🌐 — Drive Link Ethical Hacking Course Updated 📝 — Drive Link Ethical Hacking Training 💻 — Drive Link Learn More Hackings Here ⚡️@TheAnonGhost 📂Network | 🛍Shop

Video Production, Animation & Content Creation 🤖 AI Videos Drive — Drive Link 🎨 Explaindio 2D Animation — Direct Download Link ✨ Logo Designing — Drive Link 🎥 Video Recording and Editing — Direct Download Link 🖍 Whiteboard Animation — Direct Download Link 📺 YouTube Course — Drive Link | Direct Download Link Learn More Hackings Here ⚡️@TheAnonGhost 📂Network | 🛍Shop

💼 Freelancing & Online Business 🚀 Fiverr Course — Drive Link | Direct Download Link Freelancers Course — Drive Link Upwork Course — Drive Link | Direct Download Link Web Hosting Business Training — Direct Download Link Learn More Hackings Here ⚡️@TheAnonGhost 📂Network | 🛍Shop

📈 Digital Marketing & Advertising 🚀 Facebook Ads — Drive Link 🔗 Facebook Instant Ad Article — Direct Download Link 📄 Google Ads — Drive Link 🔗 Google AdSense Course — Drive Link | Direct Download Link 💰 Google Business — Drive Link 🏢 Master SEO Course — Drive Link 📚 SEO Content Writer — Drive Link ✍️ Learn More Hackings Here ⚡️@TheAnonGhost 📂Network | 🛍Shop