YGN Ethical Hacker Group
YGN Ethical Hacker Group
SERVICES RESEARCH RESOURCE INFO

About YEHG

The YEHG was established in Jan 2008 by a small group of young but mature people. The initiatives broke out in the hope of united force that can beat any obstacles and accomplish any goals we desire. We are NOT BLACK Hats. We are not concerned with or employed by Myanmar Government or any organizations.

Mission

To become one of the best, respectable, powerful groups in the world who’re ever dedicating their lives in ethical hacking and countermeasures.

Objectives

1. To share each other in learning new skills, researches and developments
2. To help each other’s desired goal all together


Services

Please see our home page for complete services.

Papers/Articles

Our papers/rticles are made pretty easy-to-follow, short and simple but informative for every IT professional. We don't use big jargons.


Miscellaneous


Presentations

Our presentations about our thoughts of security:


Blackbox Tools we've developed for Community
Sub-sections: Security Tools - Greasemonkey Scripts

For those dedicated stuffs like Joomla!, we write targeted tools. For others, we add new/improve plugins in w3af (Web Application Audit and Attack Framework) for generic web application bugs. We've become a part of w3af team. Submit ideas/tool requests based on your findings/experience via the contact form.

Privacy Policy: No data is sent to our server. Some guys in the wild have said that our tools send your pentesting results to us. They say without even actually knowing how to view source codes. We host our tools only at trusted opensource hosting sites - sourceforge.net and googe code base. Each tool has its own weakness and strength in various situations. It's your responsibility and smartness to make the best use of tools.


Our Projects
  • Web Application Security Papers Archived (WASPA)
    Description: This project is a collection of web application security related documents, presentations, cheetsheets, guides and the like. As for always, those resources are scattered among thousands of resources on the web. Some are really worth to read but are sadly unknown by a whole large. The only noble aim of Security students, professionals, or researchers is to bring reliable security and countermeasures to our next-generation IT communication. I attempt to support this aim by collecting resources altogether in one place which can be downloaded by those who're eager for stronger security.
    Started: June 2008

  • The Web Sites Security Advisories (WSSAd)
    Description: This project is a database of our discoveries about vulnerabilities in web sites. It is aimed to harden insecure sites where one or more low-hanging fruits (aka. low-risk type vulnerabilities) exist. But smart attackers can turn such low-risk to high-risk. Every security flaw whether it's small or big should be fixed. Blackhats are smarter and more imaginative in thinking intelligent attack patterns that you'll never think of.
    Goal: To harden as many web sites as we can
    Note: This project has been suspended since mid May because I can't enforce developers to fix their issues.
    Started: April 2008

  • The Ultimate Hacker Web Directory (HWD)
    Description: Ever-updated Comprehensive Hacking/Security Links Repository
    Goal: To be the Best Hacking Directory of All Times
    Started: March 2008


Advisories | What security breaches we've found

We don't intentionally hunt for vulnerabilities. The following ones are some of what we came across. [more...]Surely enough, we are not the only ones who found such holes. Many security professionals may have found the same holes at the same time or so. According to hacker code of ethics, we never do any harm or damage to our tested target (Yes, to do damage is one further step that exploits found weakenesses). and make disclosure only after vendor has been reported. But some vendors don't even response;hence we assume that they ignore our reports. There is no patch for ignorance.

We always find it difficult to explain security-knowlege-lack-and-stubborn-to-fix developers about security risks, threats and vulnerabilities. There are always many common myths of security which provoke Today secure and Tomorrow hacked. That's why we can't tell you something like “ Hey, guy  This is a protection code - Use this and your life will be forever secure! ”
Since July '09, we've now believed in FD (=full disclosure) after reporting numerous vulnerabilities to various vendors.Only a few ones take interest in fixing their security holes. Only FD will be a better force towards them to fix. It is the only way to harden or worsen the world.



False Assumption:“XSS Can't 0wn Web Applications”
A number of Bad Guys have owned web application only with XSS!
Attackers are more imaginative and smarter than you are!


Resource Directory

This is our ongoing project to maintain the most live ever-updated comprehensive links repository. We take pains to make the HWD sure for quality links resources. Click the logo below to enter into hwd:



Training | Demonstrations [Over 50 Movies]
Movie Series - WebGoat - WebScarab - WebPageFingerPrint

Our videos illustrations of various hacking/security processes and tools were tested on our hacking lab environments and intended only for security hardening purpose. Please don't complain if those don't work for you. Watch and forget'em! Submit your desired training requests via the contact form.
Requirement: No more than a web browser with Flash player plugin.

Announcement: We have mirrored our training files at Rapidshare.Since Oct 2009, we no longer host files at sourceforge.net and we rather stick to our site. In case you experience impatient down time, please do let us know by mailing to down [at] yehg.net.

Interactive Training

               Navigate


Subscribe for Updates -