Browsing Monthly Archive June 2011

IT Auditing and Controls – Infrastructure General Controls

PORTIONS OF THIS ARTICLE INCLUDING MANY OF THE DEFINITIONS AND TERMINOLOGY HAVE BEEN SOURCED AND SUMMARIZED FROM ISACA.ORG and COURSE MANUALS PUBLISHED BY ISACA. Infrastructure

Advanced Rootkit Exploit – Demonstrated

This is mainly post-expoitation demonstration, that first starts with a walk-through of exploiting a windows machine. Next, we walk through getting a copy of the

June 28, 2011 Hacking

Eyesight to the Blind – SSL Decryption for Network Monitoring

SSL and network monitoring aren’t the most compatible of partners – even with the most sophisticated detection infrastructure in the world, you’ll not derive many

Dave Aitel Reveals His Process for Security Research

In our ongoing series of interviews, this week Dave Aitel answered a few questions and pulled back the curtain a bit on the methods, tools

June 27, 2011 Exploit Development

How to deal with and alleviate CISSP exam anxiety!

As exam time approaches, everyone feels anxious about whether they’re ready to take the exam and to pass and thus to receive the CISSP certification. 

June 24, 2011 CISSP, IT Certifications

Are your backup systems secure?

All seemed well with backup operations at my company, until I got a visit from an operations center engineer.  The lock already hanging open, he

June 23, 2011 Virtualization Security

Securing Software with the Application and Front Controller Patterns

Securing software has always been an issue. Whether it be web, desktop or server applications, insecure coding practices can result in substantial data loss for

June 22, 2011 Application Security

Malicious SOAP Requests as Web Service Attacks

Introduction The recent Application Security Europe conference (www.appseceu.org) was one of the better conferences I have had the pleasure to attend. The talks were interesting

June 16, 2011 Application Security

Writing SEH Exploits

In these two videos, we will demonstrate how to write an exploit of the Structured Exception Handler. The video assumes you already understand how SEH

June 16, 2011 Exploit Development

Cracking WPA2 Tutorial

In this video we will demonstrate how to crack WPA2 using the Airmon-ng suite. We will do it by: Identifying an access point Capturing traffic

June 16, 2011 Hacking

Adobe Vulnerability Tutorial

In this video, we will demonstrate the adobe_utilprintf exploit. We will show how to set up a PDF within Metasploit that will deliver an exploit

June 16, 2011 Hacking

ISO27002 Security Framework – Audit Program Template

Several people have asked for an IT Audit Program Template for an audit based on the ISO/IEC 27002:2005(E) security standard.  This template (which can be found

IT Auditing and Controls – A look at Application Controls

PORTIONS OF THIS ARTICLE INCLUDING MANY OF THE DEFINITIONS AND TERMINOLOGY HAVE BEEN SOURCED AND SUMMARIZED FROM ISACA.ORG and COURSE MANUALS PUBLISHED BY ISACA. Application

Val Smith Reveals His Process for Security Research

In our ongoing series of interviews, this week Val Smith answered a few questions and pulled back the curtain a bit on the methods, tools

June 13, 2011 Exploit Development

Mutexes, part two: Using WinDbg to Begin Reverse Engineering Unknown Malware from Memory

Part Two in a multi-part series on holistic, multi-disciplinary analysis and reversing. You can read part one of this series here. The last post, “Mutex

June 13, 2011 Reverse Engineering

Mutexes, part one: The Canary in the Coal Mine and Discovering New Families of Malware

Part One in a multi-part series on holistic, multi-disciplinary analysis and reversing. This post is based on a presentation I gave at the last Thotcon,

June 13, 2011 Reverse Engineering

OWASP Top 10 Deeper Dive – A8: Failure to Restrict URL Access

Description: Parsing the OWASP Top Ten with a closer look at Failure to Restrict URL Access Introduction Per our discussion of OWASP Top 10 Tools

June 08, 2011 Application Security

IT Auditing and Controls – Shared General and Application Controls

PORTIONS OF THIS ARTICLE INCLUDING MANY OF THE DEFINITIONS AND TERMINOLOGY HAVE BEEN SOURCED AND SUMMARIZED FROM ISACA.ORG and COURSE MANUALS PUBLISHED BY ISACA. Shared

ISC2 CISSP, CAP, ISSEP Exam Pricing

ISC2 CISSP, CAP, ISSEP Exam Pricing   CISSP or Associate of (ISC)² Exam (6-hour)* CSSLP* (ISC)² Exam (4-Hour)* CISSPISSAP/ ISSEP/ISSMP (ISC)² Exam (3-hour)* SSCP or

June 03, 2011 CISSP, IT Certifications

IT Auditing and Controls – Internet and Web Technology

PORTIONS OF THIS ARTICLE INCLUDING MANY OF THE DEFINITIONS AND TERMINOLOGY HAVE BEEN SOURCED AND SUMMARIZED FROM ISACA.ORG and COURSE MANUALS PUBLISHED BY ISACA. Internet

Back to Top Copyright © 2012 - InfoSec Institute