YGN Ethical Hacker Group
YGN Ethical Hacker Group
SERVICES RESEARCH RESOURCE INFO

Loading ...
About YEHG

The YEHG was established in Jan 2008 by a small group of young but mature people. The initiatives broke out in the hope of united force that can beat any obstacles and accomplish any goals we desire. We are NOT BLACK Hats. We are not concerned with or employed by Myanmar Government or any organizations.

Mission

To become one of the best, respectable, powerful groups in the world who’re ever dedicating their lives in ethical hacking and countermeasures.

Objectives

1. To share each other in learning new skills, researches and developments
2. To help each other’s desired goal all together


Services

Request a quote to quote@yehg.net.

As for web application security reports which are based on PortSwigger and OWASP methodologies, we provide you with assessment reports like HTML & PDF. As a note, we provide free service to open-source developers of mature applications like phpMyAdmin.


Papers/Articles

Our papers/rticles are made pretty easy-to-follow, short and simple but informative for every IT professional. We don't use big jargons.


Miscellaneous


Presentations

Our presentations about our thoughts of security:


Blackbox Tools we've developed for Community
Sub-sections: Commercial - Security - Scripting - Greasemonkey Scripts

For those dedicated stuffs like Joomla!, we write targeted tools. For others, we add new/improve plugins in w3af (Web Application Audit and Attack Framework) for generic web application bugs. We've become a part of w3af team. Submit ideas/tool requests based on your findings/experience via the contact form.

Privacy Policy: No data is sent to our server. Some guys in the wild have said that our tools send your pentesting results to us. They say without even actually knowing how to view source codes. We host our tools only at trusted opensource hosting sites - sourceforge.net and googe code base. Each tool has its own weakness and strength in various situations. It's your responsibility and smartness to make the best use of tools.


Our Projects
  • Web Application Security Papers Archived (WASPA)
    Description: This project is a collection of web application security related documents, presentations, cheetsheets, guides and the like. As for always, those resources are scattered among thousands of resources on the web. Some are really worth to read but are sadly unknown by a whole large. The only noble aim of Security students, professionals, or researchers is to bring reliable security and countermeasures to our next-generation IT communication. I attempt to support this aim by collecting resources altogether in one place which can be downloaded by those who're eager for stronger security.
    Started: June 2008

  • Virtual Hacking Lab
    Description: This project is a mirror of deliberately insecure applications and old softwares with known vulnerabilities. Used for proof-of-concept /security training/learning purposes. Available in either virtual images or live iso or standalone formats.

  • The Ultimate Hacker Web Directory (HWD)
    Description: Ever-updated Comprehensive Hacking/Security Links Repository
    Goal: To be the Best Hacking Directory of All Times
    Started: March 2008


Advisories | What security breaches we've found

We don't intentionally hunt for vulnerabilities. The following ones are some of what we came across. [more...]Surely enough, we are not the only ones who found such holes. Many security researchers may have found the same holes at the same time or so. According to hacker code of ethics, we never do any harm or damage to our tested target (Yes, to do damage is one further step that exploits found weakenesses). and make disclosure only after vendor has been reported. But some vendors don't get back to us even after weeks of reportings;hence we assume that they ignore our findings of insecurity. There is no patch for ignorance.

We always find it difficult to explain security-knowledge-lack-and-stubborn-to-fix developers about security risks, threats and vulnerabilities. There are always many common myths of security - Today secure and Tomorrow hacked. That's why we can't tell you something like “ Hey, guy  This is a protection code - Use this and your life will be forever secure! ”
Since July '09, we've now believed in FD (=full disclosure). We've been reporting numerous vulnerabilities to various vendors, a few of them take interest in fixing their security holes. Only FD will be a better force towards them to fix. Our main concern is about users. Our disclosure will give benefits to security-aware users who can take countermeasures to defend themselves.



False Assumption:“XSS Can't 0wn Web Applications”
A number of Bad Guys have owned web application only with XSS!
How it can be used to perform terrible attacks depends only on the imaginative attack vectors of attackers.
See a real-life example - Apache Repo Ownage and GaiaOnline XSS Worm.


Resource Directory

This is our ongoing project to maintain the most live ever-updated comprehensive links repository. We take pains to make the HWD sure for quality links resources. Click the logo below to enter into hwd:



Training | Demonstrations [Over 50 Movies]
Movie Series - WebGoat - WebScarab - WebPageFingerPrint

Our videos illustrations of various hacking/security processes and tools were tested on our hacking lab environments and intended only for security hardening purpose. Please don't complain if those don't work for you. Watch and forget'em! Submit your desired training requests via the contact form.
Requirement: No more than a web browser with Flash player plugin.


Interactive Training

               Navigate

Kindly donate us via PayPal

Subscribe for Updates -