Failed to install Astra (API Automated Testing Tool) with the error "No module named pymongo" [closed]

I followed the steps mentioned in the documentation as stated in this link https://github.com/flipkart-incubator/Astra. However, I encountered the error "No module named pymongo", which is shown in the following figure:

I tried … Continue reading Failed to install Astra (API Automated Testing Tool) with the error "No module named pymongo" [closed]

How does Burp Suite evaluates this request as high severity with the issue "user input evaluated as code"?

I just conducted an automated web scan with Burp Suite Pro. The scanner result indicated that our website had a high severity of code injection. It gave the following proof:

However, I don’t understand why it interpreted like that:

Continue reading How does Burp Suite evaluates this request as high severity with the issue "user input evaluated as code"?

How to identify the phishing email originates from a compromised account or a compromised server?

We have a whale phishing case, in which the sender is from the insider (we’re using Zimbra email service for some specific user groups). A cursory investigation indicated that this account had probably been compromised.

My concern here i… Continue reading How to identify the phishing email originates from a compromised account or a compromised server?

Credential Failure for Vulnerability Scanning – InsightVM [closed]

I’m using InsightVM from Rapid7 to scan vulnerabilities for my company’s assets. There were different results as follows:

If I used “scheduled scan”, the scan result would detect correct vulnerabilities, including the information “Creden… Continue reading Credential Failure for Vulnerability Scanning – InsightVM [closed]