YGN Ethical Hacker Group
YGN Ethical Hacker Group
SERVICES RESEARCH RESOURCE INFO

About YEHG

The YEHG was established in Jan 2008 by a small group of young but mature people. The initiatives broke out in the hope of united force that can beat any obstacles and accomplish any goals we desire. We are NOT BLACK Hats. We are not concerned with or employed by Myanmar Government or any organizations.

Mission

To become one of the best, respectable, powerful groups in the world who’re ever dedicating their lives in ethical hacking and countermeasures.

Objectives

1. To share each other in learning new skills, researches and developments
2. To help each other’s desired goal all together


Services

We provide the following web application security services for open-source application developers at no charge:

Based on PortSwigger and OWASP methodologies, we provide you with assessment reports like HTML & PDF. Totally free and no hidden charges or cost!


Papers | What we've researched

Our papers and articles are not hacker-only-readable.
We made them pretty short and simple but informative and effective for every IT professional. We don't use big jargons.


Miscellaneous


Presentations

Our presentations about our thoughts of security:


Tools | What we've developed for Community

In fact there are hundreds of tools out there. We don't even need to create our own; don't need to re-invent the wheels. We only want to do what hasn't still existed on the web. The following ones are what we have to develop after web searches return none.


Our Projects
  • Web Application Security Papers Archived (WASPA)
    Description: This project is a collection of web application security related documents, presentations, cheetsheets, guides and the like. As for always, those resources are scattered among thousands of resources on the web. Some are really worth to read but are sadly unknown by a whole large. The only noble aim of Security students, professionals, or researchers is to bring reliable security and countermeasures to our next-generation IT communication. I attempt to support this aim by collecting resources altogether in one place which can be downloaded by those who're eager for stronger security.
    Started: June 2008

  • The Web Sites Security Advisories (WSSAd)
    Description: This project is a database of our discoveries about vulnerabilities in web sites. It is aimed to harden insecure sites where one or more low-hanging fruits (aka. low-risk type vulnerabilities) exist. But smart attackers can turn such low-risk to high-risk. Every security flaw whether it's small or big should be fixed. Blackhats are smarter and more imaginative in thinking intelligent attack patterns that you'll never think of.
    Goal: To harden as many web sites as we can
    Note: This project has been suspended since mid May because I can't enforce developers to fix their issues.
    Started: April 2008

  • The Ultimate Hacker Web Directory (HWD)
    Description: Ever-updated Comprehensive Hacking/Security Links Repository
    Goal: To be the Best Hacking Directory of All Times
    Started: March 2008


Advisories | What security breaches we've found

We don't intentionally hunt for vulnerabilities. The following ones are some of what we came across. [more...]Surely enough, we are not the only ones who found such holes. Many security professionals may have found the same holes at the same time or so. According to hacker code of ethics, we never do any harm or damage to our tested target (Yes, to do damage is one further step that exploits found weakenesses). and make disclosure only after vendor has been reported. But some vendors don't even response;hence we assume that they ignore our reports. There is no patch for ignorance.

We always find it difficult to explain security-knowlege-lack-and-stubborn-to-fix developers about security risks, threats and vulnerabilities. There are always many common myths of security which provoke Today secure and Tomorrow hacked. That's why we can't tell you something like “ Hey, guy  This is a protection code - Use this and your life will be forever secure! ”
Here, we feature high-risk vulnerabilities info about web applications. The numerous number of vulnerablities in today's web sites are featured in our WSSAd project.



False Assumption:“XSS Can't 0wn Web Applications”
A number of Bad Guys have owned web application only with XSS!
Attackers are more imaginative and smarter than you are!


Resource Directory

This is our ongoing project to maintain the most live ever-updated comprehensive links repository. We take pains to make the HWD sure for quality links resources. Click the logo below to enter into hwd:



Training | Demonstrations [Over 50 Movies]

We recently migrated our files to sourceforge.net.Some older files can be available via our older first mirror. Our videos illustrations of various networking/hacking/security processes and tools were tested on our hacking lab environments and intended only for security hardening purpose. Please don't complain if those don't work for you. Watch and forget'em! Off and on, fearless security professionals have ended their careers due to penetration testing computer systems (they don't own) without permission. Only use your hacking skills in ethical and lawful purposes! Know the meaning and essence of ethical hacking!

Requirement: No more than a web browser with Flash player plugin.
If you're willing to download all files, go to our sf.net project page.

Interactive Training

               Quick Menu