Browsing Monthly Archive December 2011

A Vulnerable Civic Infrastructure: The Attack on South Houston’s SCADA Water System

As the world becomes increasingly digitized, IT security impacts more and more of our lives. Most ordinary citizens are unaware of how our important civic

December 27, 2011 Interviews, SCADA

Measuring the ROI of Security Training

Marc Winner hasn’t come up with a way to precisely measure the return on investment for security training. What he does know for certain, however,

LOIC (Low Orbit Ion Cannon) – DOS attacking tool

The DOS (Denial of service) attack is one of the more powerful hacks, capable of completely taking a server down. In this way, the server

December 20, 2011 Hacking

KARMETASPLOIT, Pwning the Air!

Wireless networks have become very common in today’s world, people are used to be connected to wireless networks in office, home, coffee shops etc. In

December 19, 2011 Hacking, Wireless Security

Web Analysis, Vulnerability Assessment and Exploitation using Backtrack5

Web application analysis plays a major role while doing a vulnerability assessment/penetration test. Proper information about the web application (for example like type of plugins

December 16, 2011 Hacking

Rootkit Detector Features: Malicious System Threads and Debug Registers

Introduction: In my last article, we’d discussed the most important ways in which a rootkit enters a system and subsequently masks its presence so it

December 16, 2011 Forensics, Reverse Engineering

Writing Self-Modifying Code Part 2: Using extended assembly – Practice

Part 1 is here: http://resources.infosecinstitute.com/writing-self-modifying-code-part-1/ All the code for this tutorial is on github. Links for particular components are interspersed, or you can just pull

December 15, 2011 Reverse Engineering

Secure Random Number Generation in JAVA

Some Random Number concepts: “Random numbers” means numbers which are random in practice (i.e. unpredictable and non – reproducible). As simple this term looks when

December 14, 2011 Application Security, Other

Enterprise Security: A practitioner’s guide – Chapter 1

Chapter 1Security: A working definition Managing Risk Probability of Occurrence Business Impact Threat Sources Human Threats Geographic Threats Natural Threats Technical Threats Security as a

Firefox Forensics and SQLite Tables for Computer Forensics Analysis

I was showing off a trick to export Firefox SQLite tables to a spread sheet, and while she is a forensics person, she had never

December 09, 2011 Forensics

VLAN Hacking

Introduction In Virtual LAN or VLAN is a group of hosts communicate with each other, even thoughthey are in different physical location. Virtual LAN provides

December 08, 2011 General Security, Hacking

Privacy and Big Data Book Review

Privacy and Big Data Terence Craig and Mary E. Ludloff O’Reilly Media At this point, everyone and their uncle is on Facebook. Free webmail accounts

December 07, 2011 General Security

Abusing IP Protocols to Create Covert Channels when Penetration Testing

This article will talk about the maintaining access step in a penetration test. After an attacker has broken into the system and got access, escalated

December 07, 2011 General Security, Hacking

REVERSING RORPIAN – DHCP Hijacking Malware

We have seen our fair share of malware codes from time to time. With the help of disassemblers and debuggers, we have a shot of

December 06, 2011 Reverse Engineering

Social Engineering Toolkits

Introduction: Social engineering is commonly understood to mean the art of manipulating people into performing actions or divulging confidential information –Wikipedia Pen testers can break

December 02, 2011 Hacking
Back to Top Copyright © 2012 - InfoSec Institute