Site News

/Site News

Week 15 In Review – 2017

  Events Related  HITB 2017 This year, the conference was based on four(!) tracks: two regular ones, one dedicated to more “practical” presentations (HITBlabs) and the last one dedicated to small talks (30-60 mins). HITB Amsterdam 2017 Day #1 Wrap-Up - HITB Amsterdam 2017 Day #2 Wrap-Up - Resources  Over The Air: Exploiting [...]

Week 14 In Review – 2017

Events Related Cyphercon 2.0 Videos - These are the videos from the Cyphercon 2.0 conference. DakotaCon - South Dakota’s premier security event. TROOPERScon - AIDE 2017 - Resources BlackHat 2017 - Over The Air: Exploiting Broadcom’s Wi-Fi Stack (Part 1) - It’s a well understood fact that platform security is an [...]

Week 13 In Review – 2017

Events Related TROOPERS Conference I’m in Heidelberg (Germany) for the 10th edition of the TROOPERS conference. The regular talks are scheduled on Wednesday and Thursday. The two first days are reserved for some trainings and a pre-conference event called “NGI” for “Next Generation Internet” focusing on two hot topics: IPv6 and IoT. TROOPERS 2017 Day #1 Wrap-Up - [...]

Week 11 In Review – 2017

Events Related BSides Indy 2017 Videos - These are the videos from the BSides Indy conference.  Tools Worried about Strutshock (CVE-2017-5638)? - Quick check to see if your website is vulnerable Techniques PlaidCTF 2012 – Traitor (200 pts) - The challenge is supposed to be very straightforward, because we only have a recorded audio [...]

Week 10 In Review – 2017

Techniques Hacking Unicorns with Web Bluetooth - Researchers discovered an unsecured MongoDB server that exposed sensitive CloudPets customer data. My research focused on the toy itself, in particular some issues we found with its Bluetooth LE connectivity and features. Still Passing the Hash 15 Years Later - So I first thought about it [...]

Week 6 In Review – 2017

Events Related ShmooCon2017 - The videos in this collection are from ShmooCon 2017, which occurred on 13-15 January 2017, at the Washington Hilton Hotel. Hackfest 2016 - Resources From Mimikatz to Kekeo, Passing by New Microsoft Security Technologies - Techniques Pen Test Poster: "White Board" - Bash - Useful IPv6 Pivot - [...]

February 5th, 2017|Security Conferences, Site News, Week in Review|0 Comments

Week 5 In Review – 2017

Resources Running guide for CTF's - Blackhat Hardware Training Roadmap - This diagram is intended to give an overview of many of the hardware-related trainings available at Black Hat USA 2017. Generally, lower level hardware is at the bottom and more software to the top. Tools Wordpress Exploit Framework - screen2root - [...]

Week 4 In Review – 2017

Events Related BSides Columbus 2017 Videos - These are the videos from the BSides Columbus Ohio conference. Resources DevOoops: Client Provisioning (Vagrant) - Notes from the 2015 Devoops Talk. Vagrant used to ship with a default keypair and was difficult to rotate. Intel debugger interface open to hacking via USB - New Intel processors [...]

Week 3 In Review – 2017

Tools Acunetix Free Manual Pen Testing Tools - Acunetix Manual Tools allow penetration testers to further automated testing. waveconverter - Factoria Labs 2016 WaveConverter is a Python application, built on GTK+ 3. The GUI has been implemented via Glade. A sqlite database has been implemented via sqlalchemy. Techniques Cracking The 12+ Character Password [...]

Week 2 In Review – 2017

Tools Invoke-TheHash - Invoke-TheHash contains PowerShell functions for performing NTLMv2 pass the hash WMI and SMB command execution. WMI and SMB services are accessed through .NET TCPClient connections. Local administrator privilege is not required client-side. FiercePhish - FiercePhish is a full-fledged phishing framework to manage all phishing engagements. It allows you to track [...]

January 8th, 2017|Security Tools, Site News, Week in Review|0 Comments