Browsing Monthly Archive April 2012
alienvault 3

AlienVault OSSIM Review – Open Source SIEM

Introduction As logs never lie, it’s very important to aggregate and analyze the internal and external network logs constantly so that companies can prevent breach

April 25, 2012 Hacking
update 1

Hacking AutoUpdate by Injecting Fake Updates

Works against Java, AppleUpdate, Google Analytics, Skype, Blackberry and more Introduction We all know that hackers are constantly trying to steal private information by getting

April 25, 2012 Hacking
wolfram 5

Hacking WolframAlpha – The Anatomy

Preview Sharing source code with peers is one thing; sharing secrets over a public medium is another. The all-seeing eye of Google has no mercy,

April 24, 2012 Application Security, Hacking
2012cism 0

ISACA Changes CISM Exam for 2012

According to ISACA, the CISM certification is changing to reflect the new CISM job practice analysis. (Source: ISACA’s CISM Review Manual 2012 p. iii) ISACA

April 23, 2012 CISM, IT Certifications
cisointerview 0

CISO Interview Series- Doug Steelman: CISO Dell SecureWorks

Profile Subject: Doug Steelman Doug Steelman is the Chief Information officer of Dell SecureWorks, where he leads the defense of Dell SecureWork’s networks. Before joining

April 23, 2012 Interviews
fingerprint 0

Passive Fingerprinting

During penetration testing, the main objective of the auditor is to exploit and gain access. For that to happen, it is required to have some

April 19, 2012 Application Security, Hacking
iPhoneapps 5

Penetration Testing for iPhone Applications- Part 2

In the first part of this article, we discussed the iPhone application traffic analysis. In this part, we will take a look at the privacy

April 18, 2012 Hacking
ozlak5 1

VLAN Network Segmentation and Security- Chapter 5

This is Chapter 5 in Tom Olzak‘s book, “Enterprise Security: A practitioner’s guide.” Chapter 4 is available here:Attack Surface Reduction – Chapter 4 Chapter 3

iframe 1

Iframe & the Security Risk

Web application security is always an important topic to discuss because websites seem to be the first target of malicious hackers. Hackers use websites to

April 17, 2012 Application Security, Hacking
owl 0

w3af walkthrough and tutorial part 3 – Remaining plugins

In the previous article w3af walkthrough and tutorial part 2 – Discovery and Audit plugins, we looked at the various discovery and audit plugins used by w3af

April 16, 2012 Application Security
nmapmeasure 5

Measuring the Internet – Part I: Distributed nmap

Last month, I participated in a project that involved the scanning of a whole continent. The goal of the project was to report, within 20

April 16, 2012 General Security
wirelesspentesting 0

OSINT and pre-game show for a on-site WLAN Penetration Test

Wireless Penetration Testing in my opinion is one of the most fun parts of Ethical Hacking. It incorporates application exploits once you are on the

April 13, 2012 Hacking, Wireless Security
german-trojan 15

Malware Analysis – Follow along reversing the German government’s “Bundestrojaner”

Introduction I’m reasonably sure that anyone reading this particular article has heard about viruses, worms, trojans and malware; as well as numerous antivirus products like

April 13, 2012 Reverse Engineering
041112_1431_ArmitageFas1.png 1

Armitage –Fast and Easy Hacking

Armitage is a GUI for Metasploit which makes penetration testing easier. It was developed by Raphael Mudge. This tool helps to reduce the time and

April 11, 2012 Hacking
securelinux 1

The Importance of Securing a Linux Web Server

With the significant prevalence of Linux web servers globally, security is often touted as a strength of the platform for such a purpose. However, a

April 05, 2012 Application Security, Hacking
MH1 sullivan0071776168 0

Book Excerpt: Web Application Security, A Beginner’s Guide

Web Application Security: A Beginner’s Guide provides IT professionals with an actionable, rock-solid foundation in Web application security–from a complete overview of the tools and

April 03, 2012 Application Security
Back to Top Copyright © 2012 - InfoSec Institute