PE-Header 4

Presenting the PE Header

Let’s present the whole PE file structure with the picture below (taken from [5]): At the beginning there’s a DOS header, which is an MS-DOS

May 08, 2013 Reverse Engineering
Gauss-Malware-feature 0

Gauss: Between technology and politics

Introduction The purpose of this work is to present the reader research of the Gauss malware platform as one of the ultimate nation-state cyber exploitation

May 07, 2013 General Security
iOS-Application 0

IOS Application security Part 2 – Getting class information of IOS apps

Introduction Have you ever checked out an IOS app and thought it was cool, and wondered if you could find some information about the source

May 07, 2013 Application Security
Portable Malware Lab 3

Portable Malware Lab for Beginners

With the ever increasing cases of malware, many of the youngsters are switching over to analyzing malwares and its various aspects. A simple search in

May 06, 2013 Forensics
xml-vulnerability 0

XML vulnerabilities

1. Introduction As we know, today’s web technology advances are fast in good and bad ways. With almost every technology, if not used properly, its

May 06, 2013 Hacking
bitcoin 0

How to profit illegally from Bitcoin … cybercrime and much more

Introduction The interest in Bitcoin, one of the most popular currency schemas is high, financial world, small savers, merchants and of course, cyber-criminals observing with

May 03, 2013 General Security
panoptic 0

Panoptic – Common Log and Config Files Retriever through LFI Vulnerability

Local File Inclusion or LFI is a kind of web exploit or vulnerability that allows an attacker to inject directory-traversal characters on a certain website.

May 03, 2013 Hacking
Code Injection 2

Code Injection Techniques

DLL Injection using QueueUserAPC We begin by creating a process using CreateProcess, which is the where we are trying to inject the code into: Once

May 02, 2013 Hacking
Black-Hole-Exploit 2

Cyber Weapon of Mass Destruction- The Blackhole Exploit Kit

Recent security advisories reveal that the web exploit kits like the Blackhole Exploit Kit are responsible for the vast majority of web attacks and malware

May 02, 2013 Forensics
Search Engine Hacking 2

Search Engine Hacking – Manual and Automation

Introduction: We are all aware of Google/Yahoo/Bing Search engines; they need no introduction. We use them every now and then to solve our day-to-day queries.

May 01, 2013 Hacking
Google Hacking 0

Google Hacking – For fun and profit – I

Google has been used ever since its beginning to find answers for most if not all of our questions from the beginning of the universe

May 01, 2013 Hacking
Google Hacking 4

Google Hacking: The hidden face of Google

No need for an introduction, Google is quite possibly the more powerful search engine used today, even used sometimes to check our connectivity; except that

April 30, 2013 Hacking
Stack Analysis with GDB 3

Stack analysis with GDB

1. Introduction This article describes the stack. GDB is used to analyze its memory. One needs to know this subject to play with low-level security.

April 30, 2013 Exploit Development
The Import Directory 2

The Import Directory: Part 2

You can take a look at the previous article before reading this one. If you already understand the basics of IAT table, then you can skip

April 29, 2013 Hacking, Reverse Engineering
GhostNet 0

GhostNet – Part II

Behind the GhostNet notion stands an entire international worldwide network of infected computers belonging to places having high political, economic, media, or emblematic importance. One

April 29, 2013 General Security
IOS-app-security 4

IOS Application security Part 1 – Setting up a mobile pentesting platform

Introduction In this article series, we will be learning about the tools and techniques required to perform penetration testing and Vulnerability assessment on IOS Applications.

April 26, 2013 Application Security
Dot Net Security 0

Windows Authentication: Dot NET Security Part 2

Introduction The .NET framework caters to different types of authentication mechanisms to use within your applications – —including basic authentication, digest authentication, forms authentication, Passport,

April 26, 2013 Application Security
Botnet Hunting 2

Botnets and Cybercrime – Botnets hunting – Part 3

Botnets and cybercrime – Introduction can be found here Botnets, how do they work? Architectures and case studies – Part 2 can be found here

April 25, 2013 General Security
Voice Phishing 0

Phishing Techniques: Similarities, Differences, and Trends: Part III: Vishing

For Part I, which discusses Mass Phishing and which sets the objects of examination in this paper, please check here. For Part II, which discusses

April 25, 2013 General Security
GhostNet 0

GhostNet – Part I

Introduction Several years after the revelation of GhostNet, a massive case of cyber exploitation directed mostly against the Tibetan community, in terms of originality, this

April 24, 2013 General Security
Back to Top Copyright © 2012 - InfoSec Institute