Browsing Monthly Archive February 2013
Reversing-If-Statement-02282013 0

Reverse Engineering If Statements

Introduction Summary: In this article, we’ll present a simple program that uses ‘if’ statements and then we’ll try to reverse engineer the compiled version of

February 28, 2013 Reverse Engineering
Incident-Response-02282013 0

Building an Incident Response Team and IR Process

In our world today, we have an abundance of many things, among which are -unexpected events. Falling meteorites, terrorist attacks, hacktivist demonstrations, blackouts, tsunamis…. well,

February 28, 2013 General Security
WilsBellInterview-02282013 0

InfoSec Institute Interview: Wils Bell – President of SecurityHeadhunter.com

SecurityHeadhunter.com Inc., a central Florida-based security search firm, is focused on uniting the right candidates with the right companies in the information security space. As

February 28, 2013 General Security
java-hack-02272013 0

The Recent Java Hack aka CVE-2013-1489 & CVE-2013-0422

There have been debates over the security and privacy issues concerning Java, the platform independent language. Time after time, the black and white hats have

February 27, 2013 Hacking
Double-Query-02272013 4

DOUBLE QUERY INJECTIONS DEMYSTIFIED

In the last article of the series, we started to explore the world of SQL injections by discussing different types and using the test bed

February 27, 2013 Application Security
Reversing-switch-02272013 0

Reversing Switch Statements

Introduction In this article we’ll take a look at all the optimizations the compilers use to assembly the high-level switch statements into their assembly representations.

February 27, 2013 Reverse Engineering
RiskAssessment-02262013 0

Introduction to Application Risk Rating & Assessment

Background: Understanding today’s threat landscape and looking at the pace with which organizations are adopting secure development practices, there seems to be a huge gap

February 26, 2013 Application Security
SoftICE-02262013 5

Introduction to SoftICE

It’s often the case that we need to debug a kernel application, like device driverS, system calls, interrupt routines, or some other kernel application. In

February 26, 2013 Reverse Engineering
Collection-02262013 0

Collection

Objective of the Module: Introduction ArrayList Hashtable BitArray Introduction .NET offers a variety of collections such as ArrayLists, hashtables, queues, and dictionaries and these collections

February 26, 2013 Application Security
security-architecture-and-design-02252013 0

CISSP – Security Architecture & Design – What’s New in 3rd Edition of CISSP CBK

What’s new in Security Architecture & Design ISC2 published the 3rd edition of their CISSP CBK in late 2012.  I ordered my copy in December

February 25, 2013 CISSP
decrypted-code-02252013 0

Cracking the Defender: The Deobfuscated Code

Introduction So far we’ve taken a look at the obfuscation routine and how it deobfuscates the instructions in the loc_4033D1. At the beginning point, the

February 25, 2013 Reverse Engineering
Cyber-Exploitation-02252013 0

Cyber Exploitation

Introduction Over the past couple of years, cyber exploitation has established a reputation of something more than mere nuisance. The repercussions of these acts are

February 25, 2013 General Security
Alexander-Polyakov-02252013 0

InfoSec Institute Interview: Alexander Polyakov – CTO at ERPSCAN

How it started It started pretty much as usual. When you have a ZX Spectrum at home as a child, you will turn to the

February 25, 2013 Interviews
password-cracking-02222013 1

The Exponential Nature of Password Cracking Costs

Let’s assume for a moment that you suffered a security breach for a web application accessed by your customers. Somehow, an intruder was able to

February 22, 2013 Application Security
Arrays-02222013 0

Arrays: A Brief Tutorial

Introduction Arrays are powerful data structures that can be used to solve many programming problems. You have seen during the creation of different variables that

February 22, 2013 Application Security
SCADA-02222013 0

SCADA & Security of Critical Infrastructures

Introduction In the last few years there has been an increase within the worldwide security community consciousness of the risks related to cyber-attacks against critical

February 22, 2013 Hacking, SCADA
security-architecture-and-design-02222013 0

CISSP – Software Development Security – What’s New in 3rd Edition of CBK

What’s new in Software Development Security ISC2 published the 3rd edition of their CISSP CBK in late 2012.  I ordered my copy in December 2012

February 21, 2013 CISSP
cryptography-02222013 0

CISSP – Cryptography – What’s New in 3rd Edition of CBK

What’s new in Cryptography ISC2 published the 3rd edition of their CISSP CBK in late 2012.  I ordered my copy in December 2012 and said,

February 21, 2013 CISSP
Info-Sec-Governance-Risk-Manag-02212013 1

CISSP – Information Security Governance & Risk Management – What’s New in 3rd Ed of CBK

What’s new in Information Security Governance & Risk Management ISC2 published the 3rd edition of their CISSP CBK in late 2012.  I ordered my copy

February 21, 2013 CISSP
STRIDE-02212013 1

Threat Modeling – Finding defects early in the cycle

Finding a proven pattern to find defects early in your cycle saves not just money but also the time required to patch those defects. Threat

February 20, 2013 Other
Back to Top Copyright © 2012 - InfoSec Institute