Browsing Monthly Archive November 2011

Restricted Character Set Vulnserver Exploit Tutorial

This tutorial will cover the process of writing a buffer overflow exploit for a known vulnerability in the Vulnserver application. This is the sixth article

November 30, 2011 Exploit Development

Incorporating Custom Shellcode Into The Metasploit Framework

Writing shellcode can be a somewhat time consuming task. Once considered a dark art, shellcoding has become a part of the vocabulary of modern IT

November 29, 2011 Exploit Development

DNS Hacking (Beginner to Advanced)

DNS is a naming system for computers that converts human readable domain names e.g. (infosecinstitute.com) into computer readable IP-addresses. However some security vulnerabilities exist due

November 28, 2011 Hacking

C&A: The Square Peg

This C&A related call for help is from Latonya in Washington, DC: Need help! I am desperately searching for an instruction that will exempt a

Writing Self-modifying Code Part 1: C Hello world with RWX and in-line assembly

To follow along with this tutorial, download all source files here In the first part of this tutorial, we’ll be making a basic C scaffold

November 21, 2011 Reverse Engineering

UEFI and the TPM: Building a foundation for platform trust

Table of Contents Trusted Computing Boot Path Security Challenges Boot Path Attack Surface The Trusted Memory Module (TPM) TPM Architecture and Functionality TPM Concepts and

Goodbye DIACAP, Hello DIARMF

When C&A becomes A&A, will you be ready? Every few months, an elite group of DoD security experts, IT managers, and senior leadership gather to

Dangerous Texts: Preventing SMS Cracking

The very first SMS (Short Messaging Service) message was sent on December 3rd, 1992. As cellular phone technology exploded since then, now your average person

November 16, 2011 Hacking, Wireless Security

Rootkit Detection with Tuluka Kernel Inspector

Introduction A rootkit is a piece of software that is written by someone, who at the very least, wants to spy on specific system calls

November 15, 2011 Forensics

Confident KillSwitch Helps Combat Brute-Force Attacks

Introduction Confident Technologies Inc.‘s (CTI) KillSwitch collects data on hacking attempts to help information security (IS) professionals safeguard their companies’ online properties and mobile applications

November 03, 2011 General Security

9 Easy WordPress Security Tips: Hardening WordPress

WordPress is the most popular Content Management System (CMS) on the World Wide Web. I’m one of the two web developers for Liberbyte.com, a tech

November 02, 2011 Application Security

AntiCloud Trojan Reverse Engineering Analysis

Introduction In this paper we are going to talk about the Anticloud Trojan, also know as the TrojanDropper:Win32/Bohu.A and B variant. This malware originated in China

November 01, 2011 Reverse Engineering
Back to Top Copyright © 2012 - InfoSec Institute