owl 0

w3af walkthrough and tutorial part 4 – w3af tools, profiles and scripting

This is part 4 in a series. Part 1 is available here:w3af Tutorial Part 1 Part 2 is available here:Discovery and Audit plugins Part 3

May 10, 2012 Hacking
thewall 0

Firewall Security Testing

Testing firewall and IDS rules is a regular part of penetration testing or security auditing. However, because of the unique complexity involved of different environments,

May 10, 2012 Hacking
maninbrowser 1

Man in the Browser Attack vs. Two Factor Authentication

Authentication or E-authentication (Electronic authentication) is the way, technique, and method to establish a connection between two entities. This connection is based on confidence and

May 08, 2012 Hacking
ammonite 2

Scanning the Web with Ammonite

Introduction Ammonite is a Fiddler extension used to scan web applications for common vulnerabilities like verbose and blind SQL injection, OS commanding, local file inclusion,

May 08, 2012 Hacking
ch6 0

Chapter 6 – End-user Device Security

This is Chapter 6 in Tom Olzak‘s book, “Enterprise Security: A practitioner’s guide.” Chapter 5 is available here: VLAN Network Segmentation and Security- Chapter 5

iphonef4 2

iPhone Forensics – Analysis of iOS 5 backups : Part 1

iPhone forensics can be performed on the backups made by iTunes or directly on the live device. This Previous article on iPhone forensics detailed the

May 03, 2012 Hacking
chinaphil 1

Understanding the Origins of the China – Philippine Cyber War

For many years, there has been a territorial dispute between China and Philippines over the Scarborough Shoal (Philippine Term: Panatag Shoal) or Huangyan Island (Chinese

May 02, 2012 Hacking
brokenauth 1

Broken Authentication and Session Management

In general, web developers care for some common vulnerability in web applications. But there are some dangerous and less known vulnerabilities, which widely exist on

April 27, 2012 Application Security, Hacking
alienvault 2

AlienVault OSSIM Review – Open Source SIEM

Introduction As logs never lie, it’s very important to aggregate and analyze the internal and external network logs constantly so that companies can prevent breach

April 25, 2012 Hacking
update 0

Hacking AutoUpdate by Injecting Fake Updates

Works against Java, AppleUpdate, Google Analytics, Skype, Blackberry and more Introduction We all know that hackers are constantly trying to steal private information by getting

April 25, 2012 Hacking
wolfram 5

Hacking WolframAlpha – The Anatomy

Preview Sharing source code with peers is one thing; sharing secrets over a public medium is another. The all-seeing eye of Google has no mercy,

April 24, 2012 Application Security, Hacking
2012cism 0

ISACA Changes CISM Exam for 2012

According to ISACA, the CISM certification is changing to reflect the new CISM job practice analysis. (Source: ISACA’s CISM Review Manual 2012 p. iii) ISACA

April 23, 2012 CISM, IT Certifications
cisointerview 0

CISO Interview Series- Doug Steelman: CISO Dell SecureWorks

Profile Subject: Doug Steelman Doug Steelman is the Chief Information officer of Dell SecureWorks, where he leads the defense of Dell SecureWork’s networks. Before joining

April 23, 2012 Interviews
fingerprint 0

Passive Fingerprinting

During penetration testing, the main objective of the auditor is to exploit and gain access. For that to happen, it is required to have some

April 19, 2012 Application Security, Hacking
iPhoneapps 2

Penetration Testing for iPhone Applications- Part 2

In the first part of this article, we discussed the iPhone application traffic analysis. In this part, we will take a look at the privacy

April 18, 2012 Application Security
ozlak5 0

VLAN Network Segmentation and Security- Chapter 5

This is Chapter 5 in Tom Olzak‘s book, “Enterprise Security: A practitioner’s guide.” Chapter 4 is available here:Attack Surface Reduction – Chapter 4 Chapter 3

iframe 1

Iframe & the Security Risk

Web application security is always an important topic to discuss because websites seem to be the first target of malicious hackers. Hackers use websites to

April 17, 2012 Application Security, Hacking
owl 0

w3af walkthrough and tutorial part 3 – Remaining plugins

In the previous article w3af walkthrough and tutorial part 2 – Discovery and Audit plugins, we looked at the various discovery and audit plugins used by w3af

April 16, 2012 Hacking
nmapmeasure 5

Measuring the Internet – Part I: Distributed nmap

Last month, I participated in a project that involved the scanning of a whole continent. The goal of the project was to report, within 20

April 16, 2012 General Security
wirelesspentesting 0

OSINT and pre-game show for a on-site WLAN Penetration Test

Wireless Penetration Testing in my opinion is one of the most fun parts of Ethical Hacking. It incorporates application exploits once you are on the

April 13, 2012 Hacking, Wireless Security
german-trojan 8

Malware Analysis – Follow along reversing the German government’s “Bundestrojaner”

Introduction I’m reasonably sure that anyone reading this particular article has heard about viruses, worms, trojans and malware; as well as numerous antivirus products like

April 13, 2012 Reverse Engineering
cryptostorage 0

Insecure Cryptographic Storage on Web Applications

Nowadays, every organization uses digital data storage and web application to manage and update data. As internet usage increases, it is important to digitize everything

April 11, 2012 Application Security, Hacking
041112_1431_ArmitageFas1.png 1

Armitage –Fast and Easy Hacking

Armitage is a GUI for Metasploit which makes penetration testing easier. It was developed by Raphael Mudge. This tool helps to reduce the time and

April 11, 2012 Hacking
securelinux 0

The Importance of Securing a Linux Web Server

With the significant prevalence of Linux web servers globally, security is often touted as a strength of the platform for such a purpose. However, a

April 05, 2012 Application Security, Hacking
MH1 sullivan0071776168 0

Book Excerpt: Web Application Security, A Beginner’s Guide

Web Application Security: A Beginner’s Guide provides IT professionals with an actionable, rock-solid foundation in Web application security–from a complete overview of the tools and

April 03, 2012 Application Security, Hacking

SQL Injection through HTTP Headers

During vulnerability assessment or penetration testing, identifying the input vectors of the target application is a primordial step. Sometimes, when dealing with Web application testing,

March 30, 2012 Application Security, Hacking
skipfish 0

Skipfish Web Vulnerability Scanner

Web application security is a serious and an important topic to discuss nowadays, since hacking attacks are common. There are hundreds and thousands of tutorials

March 27, 2012 Hacking
cartel 7

Mexican Drug Cartels and Cyberspace: Opportunity and Threat

1) Mexican Drug Gangs Kidnap Computer Hackers and Programmers Mexican drug trafficking organizations are increasingly demonstrating a desire to make money from cyber-crime, attracted by

March 21, 2012 Hacking
cisointerview 0

CISO Interview Series – Michael Peters

Profile Subject: Michael Peters Michael Peters has been an independent information security consultant, executive, researcher and author, with more than 25 years of information technology

March 21, 2012 Interviews
syria 3

DarkComet Analysis – Understanding the Trojan used in Syrian Uprising

DarkComet used in Syrian Conflict? On February 17th the CNN published an interesting article, where some Syrian’s regime opponents claimed that the government was using

March 16, 2012 Hacking, Interviews
jynx 8

Jynx2 Sneak Peek & Analysis

Jynx2 is the second installment in the LD_Preload Jynx Rootkit series first released October 19, 2011 at blackhatacademy.org. See references for earlier versions and additional information. Features: Hooks

March 15, 2012 Hacking
http 0

Security Dangers of Web Management Interfaces

Web based interfaces are convenient for managing networking equipment, but under no circumstances should these be open to the world and the internet. Many networks

owl 5

w3af walkthrough and tutorial part 2 – Discovery and Audit plugins

In the previous article w3af walkthrough and tutorial Part 1 we looked at how to use the w3af console. We also learnt about the different

March 14, 2012 Hacking
dislike 2

Clickjacking, Cursorjacking and Common Facebook Vulnerabilities

Clickjacking is one of the most used attacks by spammers on Facebook. Almost in every month, we face a new type of clickjacking attack on

March 12, 2012 Application Security, Hacking
malwareanalysis-book 0

Book Excerpt: Practical Malware Analysis – The Hands-on Guide to Dissecting Malicious Software

Another excellent publisher has offered up a generous sample of a book we’ve been talking about. This is Chapter 12 from Practical Malware Analysis – The

March 09, 2012 Reverse Engineering
cookieinjection 5

Cookie-based SQL Injection

In this paper we will talk about a non-common vector of SQL injections.  Read more… (1217 words, 1 image, estimated 4:52 mins reading time) This

March 05, 2012 Hacking
arp2 3

Pivoting from the age old ARP attack

Translating layer 2 local addresses to layer 3 globally routable addresses is the sole responsibility of the Address Resolution Protocol. ARP spoofing is a fun

March 05, 2012 Hacking

Software Showdown: Exploit Pack vs. Metasploit

Metasploit is a wonderful tool containing several exploits, giving the user an array of possibilities for penetration testing. It was designed to help the pen

March 05, 2012 Hacking
forgery 0

Abusing Social Networking Sites to Perform Content Forgery

Web Application vulnerabilities in social networking sites are very common these days. In this article, we will discuss a vulnerability found in social networking sites

March 01, 2012 Application Security, Hacking
owl 4

W3af walkthrough and tutorial – Part 1

w3af (Web Application audit and attack framework) is a framework for auditing and exploitation of web applications. In this series of articles we will be

March 01, 2012 Hacking
Back to Top Copyright © 2012 - InfoSec Institute