Browsing Monthly Archive July 2011

Staying undetected post-exploitation

Introduction Once you have control over a target and go into the post-exploitation phase, you start thinking on how to keep future access and most

July 28, 2011 Hacking

Five Steps to Incident Management in a Virtualized Environment

Incident management (IM) is a necessary part of a security program. When effective, it mitigates business impact, identifies weaknesses in controls, and helps fine-tune response

Security Vulnerabilities of IPv6 Tunnels

This article talks about novel security vulnerabilities of IPv6 tunnels – an important type of migration mechanisms from IPv4 to IPv6 implemented by all major

July 27, 2011 Hacking

Incident Response and Computer Forensics on Rootkits

Lets pick up where we left off with the rootkit and post-exploitation video (http://www.youtube.com/watch?v=izv1b-BTQFw). Except, we are now doing incident response. First you’ll see some

July 27, 2011 Forensics

Attacking Web Services Pt 2 – SOAP

In the previous article, we discussed forming a SOAP request based off the operations listed in a WSDL file and automating this task with Buby

July 15, 2011 Application Security, Hacking

Attacking Web Services Pt 1 – SOAP

Background: I often receive testing related questions from AppSec folks new to web services about the techniques used to discover and attack them. Often, web

July 15, 2011 Application Security, Hacking

IT Auditing and Controls – Database Technology and Controls

PORTIONS OF THIS ARTICLE INCLUDING MANY OF THE DEFINITIONS AND TERMINOLOGY HAVE BEEN SOURCED AND SUMMARIZED FROM ISACA.ORG and COURSE MANUALS PUBLISHED BY ISACA. A

Back to Top Copyright © 2012 - InfoSec Institute