RSSAmplifier

Blog

aviskase

aviskase.comRSS feed ↗85 posts

Latest posts

New keyboard layout habits for Emacs

The first thing a newbie Emacs user learns is that it&rsquo;s recommended to switch CapsLock to Ctrl . Great idea, except I was using it to switch keyboard layouts (Russian <-> English). I explored some options: Switch CapsLock to Ctrl and use the default Win + Space for layouts; Keep CapsLock for the layout change, setup pressed Space to act as Ctrl . There was also a question of Compose key…

Writing experience: Emacs, you won

Mastodon feed for #emacs tag brought to my attention that there is a blog carnival going on with a prompt being Writing experience . Impostor syndrome kicks in hard, nevertheless, I&rsquo;d like to use this opportunity to admit that I gave up and now use the org-mode (even though just in May I was saying nope ).

Writeup: TryHackMe W1seGuy

W1seGuy Difficulty: easy Platform: cryptography Yes, it&rsquo;s me again with another crypto challenge! Have a look at the source code before moving on to Task 2. The server is listening on port 1337 via TCP. This room&rsquo;s focus is cracking a weak encryption. Information gathering Getting the key Information gathering We&rsquo;re provided with source code of application running on port 1337.…

Writeup: TryHackMe The Sticker Shop

The Sticker Shop Difficulty: easy Platform: web Your local sticker shop has finally developed its own webpage. They do not have too much experience regarding web development, so they decided to develop and host everything on the same computer that they use for browsing the internet and looking at customer feedback. Smart move!

Writeup: TryHackMe Epoch

Epoch Difficulty: easy Platform: linux, web Be honest, you have always wanted an online tool that could help you convert UNIX dates and timestamps! Wait&hellip; it doesn&rsquo;t need to be online, you say? Are you telling me there is a command-line Linux program that can already do the same thing? Well, of course, we already knew that! Our website actually just passes your input right along to…

Writeup: TryHackMe Billing

Billing Difficulty: easy Platform: web, linux Gain a shell, find the way and escalate your privileges! Note: Bruteforcing is out of scope for this room. Answer the questions below What is user.txt? What is root.txt? In this room I practiced exploiting CVEs and privilege escalation. Vulnerabilities explored: Command injection Sudoers misconfiguration Information gathering User flag: getting reverse…

Writeup: TryHackMe El Bandito

El Bandito Difficulty: hard Platform: web El Bandito, the new identity of the infamous Jack the Exploiter, has plunged into the Web3 domain with a devious token scam. By exploiting the decentralized essence of blockchain, he crafted and circulated fraudulent tokens, deceiving investors and shaking the foundational trust of the decentralized finance DeFi ecosystem.

Writeup: TryHackMe Include

Include Difficulty: medium Platform: web, linux This challenge is an initial test to evaluate your capabilities in web pentesting, particularly for server-side attacks. Even if it&rsquo;s not accessible from the browser, can you still find a way to capture the flags and sneak into the secret admin panel? Answer the questions below

Three (eleven) years of February

Last year the feeling was of a quiet annoyance: &ldquo;we stand together&rdquo; was all about standing , not winning . This year, well, I&rsquo;m pissed. Angry, osti de calisse de tabarnak. It&rsquo;s a truly marvelous sight to witness, the death of the empire. Not the best time for that, though. Ukraine will win, of course. That&rsquo;s just how it works . Alas, it would be preferable not to…

Writeup: TryHackMe Smol

Smol Difficulty: medium Platform: web, linux At the heart of Smol is a WordPress website, a common target due to its extensive plugin ecosystem. The machine showcases a publicly known vulnerable plugin, highlighting the risks of neglecting software updates and security patches. Enhancing the learning experience, Smol introduces a backdoored plugin, emphasizing the significance of meticulous code…

Writeup: TryHackMe Injectics

Injectics Difficulty: medium Platform: web Can you utilise your web pen-testing skills to safeguard the event from any injection attack? Answer the questions below: What is the flag value after logging into the admin panel? What is the content of the hidden text file in the flags folder? This room acts as a final challenge for the advanced injection attacks module. Vulnerabilities explored were:

Writeup: TryHackMe Light

Light Difficulty: easy Platform: db I am working on a database application called Light! Would you like to try it out? If so, the application is running on port 1337. You can connect to it using nc MACHINE_IP 1337 . You can use the username smokey in order to get started.

Writeup: TryHackMe Lo-Fi

Lo-Fi Difficulty: easy Platform: web Want to hear some lo-fi beats, to relax or study to? We&rsquo;ve got you covered! Check out similar content on TryHackMe: LFI Path Traversal File Inclusion Very simple room. Its description mentions local file inclusion vulnerability. Open the website at http://MACHINE_IP . There are links to other pages like this: http://MACHINE_IP/?page=relax.php

Blog status update

I needed to add a separate section on the blog for CTF writeups and couldn&rsquo;t help revamping a bunch of things: Dark mode redesign inspired by monospace web and Johnny.Decimal Still need to iron out the color scheme and add a light option. Also ditched all the Tailwind stuff. Back to basic CSS. Added categories. They are kinda like broad tags where some posts can have several categories…

The second (and probably last this year) progress report on cyber learning

As I&rsquo;m approching my due date (literally today), here is what I&rsquo;ve done so far: Done: TryHackMe: Jr Penetration Tester learning path TryHackMe: Web Fundamentals learning path In progress: OverTheWire wargame: Natas (it was put on hold until finishing those first THM learning paths) HackTheBox: Lab & Academy introductory stuff CTU MOOC Introduction to security TryHackMe: Web Application…

Switching to cyber

I don&rsquo;t think pivoting to another career path less than a month before maternity leave is a normal (and smart) thing to do, but here we are. Finished: OverTheWire wargame: Bandit TryHackMe: Cyber Security 101 learning path In progress: OverTheWire wargame: Natas TryHackMe: Jr Penetration Tester learning path HackTheBox: Lab & Academy introductory stuff CTU MOOC Introduction to security…

Goodbye, og:image

When you see a link on almost all social platforms or messengers, you usually see a card preview with a title, an almost invisible summary, and an image. These cards are generated based on twitter and Open Graph HTML tags that look something like this: < meta property = 'og:url' content = '<url>' > < meta property = 'og:title' content = '<title>' > < meta property = 'og:description' content =…

Two (ten) years of February

Today I&rsquo;d like to share this bit about my great-grand father Bagriy Ivan : The last bunker in our region was destroyed by the NKVD in 1952 in the Lubianets forest. Four shylyans were killed then: Antoniuk Volodymyr - born in 1923. Bagriy Ivan - born in 1911. Voznyi Ivan - born in 1905. Hulovskyi Vasyl - born in 1918. Nineteen fifty-two. By that time, Ivan&rsquo;s wife and son (my…

Open Banking: Canada vs Kazakhstan

As I was skimming through The API Changelog issue 2024.04 , my eye caught: Kazakhstan&rsquo;s National Bank and other entities published a report on an Open API and Open Banking pilot, aiming to modernize financial services through standardized data exchange. The successful pilot involved multiple banks and clients, setting the stage for a transparent and competitive financial sector by 2024.

The Navy’s IT challenges

Can&rsquo;t stop thinking about one line from the recent Paul Well&rsquo;s interview with Vice Admiral Angus Topshee , the Commander of the Royal Canadian Navy. PW: Is the fact that this video’s on YouTube a reflection of any difficulty you&rsquo;re having getting heard internally? AT: No. I&rsquo;ve shared my assessments with the leadership of the Department, up to and including this minister and…

Using openapi-cli: custom rules

If you&rsquo;re planning to lint OpenAPI description documents (you should!), always check whether a linter supports adding custom rules. And I mean not just changing severity or disabling predefined rules , but actually adding new ones specific to your API standards. openapi-cli , as any respectable OpenAPI linter, allows that . The process is very similar to adding preprocessors .

Using openapi-cli: custom preprocessing

The key feature of openapi-cli is its extensibility. There are three ways to extend it: preprocessors, rules, and decorators . In comparison, Spectral supports only custom rules. In this tutorial, we&rsquo;ll start with preprocessors . They are used to transform OpenAPI description document before validation and linting. Mind you, documentation says they should be avoided, because custom…

Using openapi-cli during API design: part two

Part one showed the basics of using openapi-cli for a single-definition project. Let&rsquo;s see how it works for multi-definition projects. Multi-what? By multi-definition project I mean a project with several OpenAPI description documents. For example, it can be useful if you want to keep contracts for all services in one place. Then, you can reuse common schemas between definitions.

Using openapi-cli during API design: part one

Obviously, API design is much more than writing OpenAPI description doc. First of all, should it even be OpenAPI-based? If yes, using openapi-cli will make your life a bit easier. Example API Let&rsquo;s imagine you&rsquo;ve been asked to create an API for Stargate Network and you already did some preliminary analysis .

Using openapi-cli for API exploration

As promised , let&rsquo;s dive into the usage of openapi-cli . The first topic is semi-non-technical: API exploration. You might be interested if: you&rsquo;re a tech writer you&rsquo;re a tester you don&rsquo;t know what the heck API exploration is What is API exploration I use this term akin to exploratory testing . You can search for works of Cem Kaner, James Bach, Michael Bolton, Elisabeth…

Hmms: 2020

Usually it&rsquo;s monthly collection of things that got me thinking hmming. But this is the end of the year, let&rsquo;s do a little retrospective. Retro What happened this year: My title switched from &ldquo;tester&rdquo; to &ldquo;engineer&rdquo; . Yay? Had a great time at ASC 2020 conference . Yes, it&rsquo;s not my first conference, but this one left a good long-lasting aftertaste. I ported…

Using openapi-cli: intro

Before we jump into the usage of this mysterious tool with way too generic name, let me give you an introduction. There are many tools for supporting API design via OpenAPI description documents. You can check the list here . The most common tasks are: dereferencing linting reference documentation preview and/or generation I talked about dereferencing not long ago . In short, it&rsquo;s needed to…

Crash course into API-related terminology

Anyone trying to dive into the world of APIs is doomed to be confused by conflicting terminology. In this post I&rsquo;m gonna touch upon the main definitions and processes. I already tried it once during lunch&learn session at work , but the time has come to revisit that old presentation in the written form.

Hmms: November

Monthly collection of things that got me thinking hmming. Awards and reports Time for ThoughtWorks Technology Radar . One of the themes is democratizing programming which is tightly coupled with democratization of APIs I mentioned in the last hmms . The 2020 state of DevOps report is there! I haven&rsquo;t even read it yet =)

Hmms: October

Monthly collection of things that got me thinking hmming . Links lunch I was reading &ldquo;Patterns for Managing Source Code Branches&rdquo; (which in itself is a great piece) when I saw MediaWiki&rsquo;s discussion about moving to GitLab . Guess what, they used Fowler&rsquo;s article as a basis for definitions in the discussion. It&rsquo;s curious how some persons&rsquo; outputs instantly become…

Automap API operation handlers in components-based project

Node.js best practices repo is the most comprehensive list of style guides and architectural tips for Node.js apps I&rsquo;ve seen. The very first of them is about structuring projects based on components instead of layers . For example, the typical layers-based layout would be: . ├── common │ └── utils.ts ├── routers │ ├── locations.router.ts │ └── users.router.ts ├── services │ ├──…

Blog redesign: phase 1

After migrating to Hugo , I decided to do a redesign to freshen up colors and introduce Hugo Pipes . Oh boi. First phase took the entire week. Planning For planning and progress tracking, I used a GitHub project . This is a basic Kanban board with two &ldquo;To do&rdquo; columns per phase. The first phase was about making a base dirty skeleton, whereas the second phase will add bells and whistles.

From Pelican to Hugo

As I mentioned in one of the last articles I was planning to migrate this blog from Pelican to other static site generator. Why and where Reasons: Pelican got a new major version 4, which required some migration work on my side either way. When I&rsquo;m fixing spelling and style I prefer checking on rendered local site and not raw markdown. But live reload became too slow and frustrating (every…

Conference notes: ASC 2020

OpenAPI Initiative&rsquo;s API specifications conference (ASC) was the first payed event I&rsquo;ve attended. Usually I watch free online events or past videos available on YouTube or Vimeo, but this time I decided to bite my inner Scrooge McDuck since there were relevant topics and price was reasonable. And I didn&rsquo;t regret it! I would love to attend offline or online future event: community…

Hmms: August

This month&rsquo;s hmms were supposed to be easy peasy to do: just grab all new notes created in Obsidian, curate a bit, and, voilà, done. I even wrote a small python tool . Yeah, right. I keep forgetting that it&rsquo;s almost impossible to get file&rsquo;s creation date on Linux. There is a hacky way for ext4, but in my case it didn&rsquo;t work: according to the script, almost all notes were…

Remembering JavaScript and TypeScript

Until recently, I had been coding mostly in Python. I&rsquo;m not an expert, but have a fair understanding of PEPs and practices. But now I work with JavaScript/TypeScript project, and my knowledge is definitely lacking. I was following these only in the university, when there was still a chance that I had to do web development. I distinctly remember the moment of downloading &ldquo;You…

Postmortem: borking Ubuntu (again)

Since I had to deal with an incident recovery this week, I thought why not use it for practicing writing postmortems? Postmortem is an excellent way to reflect and learn from disasters. Check Google&rsquo;s SRE book for more information. So, let&rsquo;s begin. Summary. On Tuesday at roughly 02:30 I wasn&rsquo;t able to log into Ubuntu: GNOME crashed before being able to display login screen.

Be chicken!

The article on API change culture uses a well-known &ldquo;the chicken and the pig&rdquo; fable as an inspiration: A Pig and a Chicken are walking down the road. The Chicken says: &ldquo;Hey Pig, I was thinking we should open a restaurant!&rdquo; Pig replies: &ldquo;Hm, maybe, what would we call it?&rdquo;

Hmms: July

Oops, I have nothing to share Since migrating to Obsidian for knowledge management, I&rsquo;ve lost a track of interesting resources I read, because they are represented as atomic cross-referencing notes. Perhaps I should try to be more consistent and always write literature notes . Alas, my current graph looks like that (obviously, I didn&rsquo;t have time to transfer older notes from other…

Knowledge management tools

As a knowledge worker, I spend a lot of time searching and experimenting with approaches for knowledge capture and storage. Currently, I play with the new shiny app, so I figured it&rsquo;s a perfect moment to systemize and reflect on tools and techniques I used until now. Handwritten I was more into handwriting during school and university, and there are still tons of notebooks back in Kazakhstan…

Hmms: June

Time for the list of things I found interesting/amusing this month. Link soup Let&rsquo;s start with the good news: OpenAPI 3.1.0 RC is out! . Webhooks and reconciliation with JSON Schema are the highlights of the version. I hope tooling support won&rsquo;t lag this time. I really liked the article by Daniel Jarjoura on communications. For example, I didn&rsquo;t know that crowd brainstorming is…

Robust APIs are weird

My first full-time API testing experience was for SOAP services. There you learn what XSD is. You learn to love it. Of course, you do! With server-side enabled validation based on a schema, you need not worry about stupid testing like checking what happens when you send 100 length string where expected maximum length is 50. Just make sure that XSD is correct.

Hmms: May

This was a slow month in the sense of discovering new. I finished the &ldquo;Advanced Distributed Systems Design&rdquo; course . CQRS, DDD, messaging patterns: doesn&rsquo;t sound like this course is in any way helpful for testers. Yet being just a tester is dull. Exploring such courses helps to diminish the hardest order of ignorance &ldquo;I don&rsquo;t know what I don&rsquo;t know&rdquo;. And…

Hmms: April

Learning One of the good things to emerge during the corona times is more educational opportunities. For example, you can (and perhaps should) check the &ldquo;Advanced Distributed Systems Design&rdquo; course by Udi Dahan. Another way to satisfy knowledge thirst is to attend a virtual conference: API The Docs hosts bite-sized virtual events with discussion opportunities. AsyncAPI has finished…

Using Insomnia for API exploration

One of the tools I use almost daily is Insomnia . It&rsquo;s a great alternative to the P-everyone-knows-that-one. Insomnia is easy to use on Linux, has plugins, and UI is clean and simple. Let me show you some basic features. We will use OpenWeatherMap API . Workspaces Workspaces are collections of thematically combined requests. Some of my workspaces are service-specific, while others contain…

Hmms: March

Coronavirus-free edition! Top X videos and readings Erik Wilde started a video series about API design, and the last one covers pros and cons of exposing system APIs. Tyk explains why you shouldn&rsquo;t write our own API gateway . I particularly liked this part: Another chose to build their own API gateway because no offerings existed that would operate in their preferred Windows-based server…

Hmms: February

It&rsquo;s March already, time to summarize February! APIs trainings I did a small company-wide training about APIs. Here is the main deck and supplementary deck left from dev lunch&learn. Anyone is free to use it and if you have questions just ping me somewhere. They don&rsquo;t have notes, so can be pretty cryptic, but I am inclined to continue improving them to use for new hires.

API testing in Python: requests vs bravado

This article is written as a result of collaboration with TestProject . While many of you know me as a GUI-driven tools hater , that&rsquo;s just my preference, so if something works for you and your company, that&rsquo;s the only thing that matters. There are no best practices and there are no best tools for everyone.

Hmms: January

Hi! Weekly hmms are transformed into monthly hmms, mostly because writing mandatory weekly posts is too cumbersome and leaves no time to do more thematic writing. Of course, there are other reasons too. Almost all winter holidays I had a cold (TWICE!) and being ill isn&rsquo;t the best motivation ever.

Lunch&Learn: linting OpenAPI description docs

Last yearly company retrospective showed that we want to be better at knowledge sharing. One of the suggested formats is Lunch&Learn, kinda like Google&rsquo;s Testing on the Toilet : short non-mandatory meeting during the lunchtime (30min) with shared recording later. I&rsquo;ve started to use them for API related topics. Tools, terminology, and other small but important things that would be…