Browsing Monthly Archive February 2012
cert-splash 4

Which Security Certification Should I Get?

When it comes to deciding what security certifications to pursue, IT professionals should understand that they will be better off career-wise if they ask—and then

securitymetricsbook 0

InfoSec Book Excerpt: Security Metrics – Chapter 17

We like to read the latest and greatest security books, andsometimes the author and/or publisher is generous enough to share an extended with us –

softskills 1

Soft Skills: A Peek into the Mind of a Hiring Manager

As a recruiter, I often have the question posed to me in a variety of ways, “Exactly what is it that hiring managers want?” What

February 23, 2012 Other
firewall 1

It’s What’s on the Inside that Counts

The last time I checked, the majority of networking and security professionals were still human. We all know that the problem with humans is that

February 23, 2012 General Security
OLYMPUS DIGITAL CAMERA 11

The Enderground: The Last Meeting – Chapter One

The sharp short sound of a black agent hibernating his Laptop’s OS echoed in the room. The box banged shut making the screen and the

February 22, 2012 Other
img-0222 1

Minimizing Vulnerabilities in Applications – Part 1

When I communicate with programmers who are writing a code for custom applications, I often wonder how carelessly they relate to the issue of safety

February 22, 2012 Application Security
java 0

How to Build a Secure RPC Interface for AJAX Apps With Google Web Toolkit

Why use GWT? Most modern web applications utilize an AJAX functionality of some sort to make them highly interactive and to have a user interface

February 21, 2012 Application Security
peer2peer 3

Circumventing NAT with UDP hole punching

A lot of networks use NAT (Network Address Translation) these days. This allows the systems on the same network to have a single global IP

February 21, 2012 Hacking
OLYMPUS DIGITAL CAMERA 2

CSRF and XSS: A Lethal Combination – Part I

Introduction In the second installment of this series, we discussed one of the most prevalent attacks to applications: SQL Injection. The previous discussion introduced the

February 20, 2012 Application Security
malt 3

Information Gathering Using Maltego

The first phase in security assessment is to focus on collecting as much information as possible about a target application. According to OWASP, information gathering

February 20, 2012 General Security
Code_Lines_2299 (4) 0

pcAnywhere Leaked Source Code – An Anonymous Review

The pcAnywhere source code leaked out onto the internet late January 2012 includes 47,021 files weighing in at 1.3GB. The October 2006 snapshot provides an

February 17, 2012 Exploit Development
olzak4 0

Attack Surface Reduction – Chapter 4

This is Chapter 4 in Tom Olzak‘s book, “Enterprise Security: A practitioner’s guide.” Chapter 3 is available here: Building the Foundation: Architecture Design – Chapter 3

DSC00100 0

Virtualization Security: Hacking VMware with VASTO

With the advancement of the technology in the field of computers, requirement for hybrid setups has also escalated. Nowadays every company is using a heterogeneous

February 16, 2012 Hacking, Virtualization Security
OLYMPUS DIGITAL CAMERA 6

Extending Burp Suite

Introduction There are multiple intercepting proxy tools available and Burp Suite is one of the best tools available for interception. If you are not yet

February 15, 2012 Application Security
ghostdomain 5

A New DNS Exploitation Technique: Ghost Domain Names

DNS is a naming system which coverts human readable domain names into computer readable IP addresses. Whenever there is a query for a domain which

February 14, 2012 Hacking
mutillidae 1

How Can FireFox Plugins Help You?

I have a pet hate. This is something that really annoys me when I get a new laptop, which if you ask my girlfriend is

February 10, 2012 Application Security, Hacking
rootsmart 0

RootSmart Android Malware

Summary Android’s increasing popularity, combined with the possibility to create alternative markets, makes this platform a fertile ground for malware authors. While most of these

February 10, 2012 Reverse Engineering
phish 6

Attacking the Phishers: An Autopsy on Compromised Phishing Websites

In this article we will cover the results of an informal investigation I performed into phishing websites. Rather than simply reviewing them externally as a

February 10, 2012 Hacking
iPhoneapps 9

iPhone Hacking! Penetration Testing for iPhone Applications – Part 1

This article focuses specifically on the techniques and tools that will help security professionals understand penetration testing methods for iPhone applications. It attempts to cover

February 09, 2012 Application Security
arp4 3

A Look at ARP

If one gets diseased then he must search for the cure which uproots the disease. Hence, prevention is no longer better than cure. -Rohit Kohli

February 08, 2012 Hacking
Back to Top Copyright © 2012 - InfoSec Institute