Browsing Monthly Archive February 2012
cert-splash 1

Which Security Certification Should I Get?

When it comes to deciding what security certifications to pursue, IT professionals should understand that they will be better off career-wise if they ask—and then

securitymetricsbook 0

InfoSec Book Excerpt: Security Metrics – Chapter 17

We like to read the latest and greatest security books, andsometimes the author and/or publisher is generous enough to share an extended with us –

February 28, 2012 Hacking
softskills 0

Soft Skills: A Peek into the Mind of a Hiring Manager

As a recruiter, I often have the question posed to me in a variety of ways, “Exactly what is it that hiring managers want?” What

February 23, 2012 Other
firewall 1

It’s What’s on the Inside that Counts

The last time I checked, the majority of networking and security professionals were still human. We all know that the problem with humans is that

February 23, 2012 General Security

The Enderground: The Last Meeting – Chapter One

The sharp short sound of a black agent hibernating his Laptop’s OS echoed in the room. The box banged shut making the screen and the

February 22, 2012 Other
img-0222 0

Minimizing Vulnerabilities in Applications – Part 1

When I communicate with programmers who are writing a code for custom applications, I often wonder how carelessly they relate to the issue of safety

February 22, 2012 Application Security
java 0

How to Build a Secure RPC Interface for AJAX Apps With Google Web Toolkit

Why use GWT? Most modern web applications utilize an AJAX functionality of some sort to make them highly interactive and to have a user interface

February 21, 2012 Application Security
peer2peer 3

Circumventing NAT with UDP hole punching

A lot of networks use NAT (Network Address Translation) these days. This allows the systems on the same network to have a single global IP

February 21, 2012 General Security
OLYMPUS DIGITAL CAMERA 0

CSRF and XSS: A Lethal Combination – Part I

Introduction In the second installment of this series, we discussed one of the most prevalent attacks to applications: SQL Injection. The previous discussion introduced the

February 20, 2012 Hacking
malt 2

Information Gathering Using Maltego

The first phase in security assessment is to focus on collecting as much information as possible about a target application. According to OWASP, information gathering

February 20, 2012 General Security
Code_Lines_2299 (4) 0

pcAnywhere Leaked Source Code – An Anonymous Review

The pcAnywhere source code leaked out onto the internet late January 2012 includes 47,021 files weighing in at 1.3GB. The October 2006 snapshot provides an

olzak4 0

Attack Surface Reduction – Chapter 4

This is Chapter 4 in Tom Olzak‘s book, “Enterprise Security: A practitioner’s guide.” Chapter 3 is available here: Building the Foundation: Architecture Design – Chapter 3

DSC00100 0

Virtualization Security: Hacking VMware with VASTO

With the advancement of the technology in the field of computers, requirement for hybrid setups has also escalated. Nowadays every company is using a heterogeneous

February 16, 2012 Hacking, Virtualization Security
phishing 5

Abusing Google Cloud Services to Harvest Gmail Accounts

Phishing is a popular and successful way of gaining authentication data for many different online services. It is the main method of compromising Gmail, Facebook,

February 15, 2012 Hacking
OLYMPUS DIGITAL CAMERA 6

Extending Burp Suite

Introduction There are multiple intercepting proxy tools available and Burp Suite is one of the best tools available for interception. If you are not yet

February 15, 2012 Hacking
ghostdomain 4

A New DNS Exploitation Technique: Ghost Domain Names

DNS is a naming system which coverts human readable domain names into computer readable IP addresses. Whenever there is a query for a domain which

February 14, 2012 Hacking
wordpress 1

WordPress Security: Plugins and Vulnerability Scanning Tools

WordPress is one of the best and most popular content management system (CMS) among bloggers and there are a lot of bloggers using WordPress as

February 14, 2012 Hacking
mutillidae 1

How Can FireFox Plugins Help You?

I have a pet hate. This is something that really annoys me when I get a new laptop, which if you ask my girlfriend is

February 10, 2012 Application Security, Hacking
rootsmart 0

RootSmart Android Malware

Summary Android’s increasing popularity, combined with the possibility to create alternative markets, makes this platform a fertile ground for malware authors. While most of these

phish 3

Attacking the Phishers: An Autopsy on Compromised Phishing Websites

In this article we will cover the results of an informal investigation I performed into phishing websites. Rather than simply reviewing them externally as a

February 10, 2012 Hacking
iPhoneapps 8

Penetration Testing for iPhone Applications – Part 1

This article focuses specifically on the techniques and tools that will help security professionals understand penetration testing methods for iPhone applications. It attempts to cover

February 09, 2012 Application Security
arp4 2

A Look at ARP

If one gets diseased then he must search for the cure which uproots the disease. Hence, prevention is no longer better than cure. -Rohit Kohli

February 08, 2012 Hacking
0101 0

The Compliance Shell Game

“What’s in a name? that which we call a rose. By any other name would smell as sweet” Shakespeare would probably turn over in his

trojan 6

Creating Backdoors Using SQL Injection

Introduction If you’re reading this article than I’m reasonably sure that you have heard of a virus, otherwise refered to as a Trojan horse or

February 06, 2012 Hacking
timingfeature 0

Timing Analysis Attacks in Anonymous Systems

Anonymous systems are used to allow users to surf the web and communicate with servers anonymously. Some of the popular anonymity service providers are TOR,

February 03, 2012 Hacking
byod 1

Top 10 Tips for Securely Managing Your Employee’s BYOD

Overview: The BYOD (Bring Your Own Device) phenomenon is expanding at an incredible rate. It is something that affects every business, from the smallest to

Back to Top Copyright © 2012 - InfoSec Institute