Subscribe to Infosec Events
Infosec Events Feed Stay up to date with all of the latest security news by subscribing to our RSS Feed. Alternatively, you can have updates sent directly to your email address.

Week 48 In Review

Published: December 5th, 2011 | Category: Local Meetings, Security Conferences, Security Tools, Security Training, Security Vulnerabilities | (0) Comments

Events Related

  • OWASP ATL Presentation – intrepidusgroup.com
    I recently gave a presentation at OWASP ATL on the OWASP Mobile Top 10 and how to assess mobile applications. This was a light weight discussion of the OWASP Mobile Top 10 and some topical and technical concerns related to securing mobile applications.
  • OWASP Benelux Days 2011 – blog.rootshell.be
    The OWASP Benelux Days is a two-days event organized by three OWASP chapters (Belgium, Netherlands and Luxembourg). The 2010 edition was organized in Eindhoven(NL). This year, it was organized in Luxembourg. After a safe trip, sharing my car with a friend, we arrived at the Luxembourg University.
  • BSIMM Community Conference – cigital.com
    Cigital recently hosted a second BSIMM Community Conference near Portland, Oregon. The Conference was outstanding, and was a great opportunity for like-minded software security professionals to compare notes.

Resources

  • Netsec’s Q4 2011 Information Security Hiring Thread – reddit.com
    If you have open positions at your company for information security professionals and would like to hire from the/r/netsec user base, please leave a comment detailing any open job listings at your company.
  • Restricted Character Set Vulnserver Exploit Tutorial – resources.infosecinstitue.com
    Vulnserver is a Windows server application that deliberately includes a number of exploitable buffer overflow vulnerabilities, and was designed to act as a target application to teach and practice basic fuzzing, debugging and exploitation skills. More information on Vulnserver, including a download link, is available here.
  • November 2011 OWASP Newsletter – owasp.blogspot.com
    November OWASp newsletter now available for download.

Tools

  • Pipal, Password Analyser – digninja.org
    On most internal pen-tests I do I generally manage to get a password dump from the DC. To do some basic analysis on this I wrote Counter and since I originally released it I’ve made quite a few mods to it to generate extra stats that are useful when doing reports to management.
  • Intercepter NG-An Advanced Sniffing Tool! – intercepter.nerf.ru/Intercepter-NG.v09.zip
    Intercepter-NG is a new and improved sniffing tool with many added features. It supports several sniffing modes. For instance, in raw mode, it acts like a pure sniffer with appearance similar to Wireshark, providing enough functionality to perform a quick research of the network traffic. In the eXtreme mode Intercepter-NG will analyze all TCP packets without checking ports.
  • USRP For NFC Part 1 - intrepidusgroup.com
    The USRP from Ettus Research is an awesome tool for radio analysis. It’s a really complex tool that is capable of doing almost anything involving radio signals (see these two previous Insight posts by Corey and myself, and Raj). That doesn’t even scratch the surface, though. This post will go into the detailed hardware setup for investigating NFC over the air communication using the USRP.
  • Signed TaskManager – blog.didierstevens.com
    This new version 0.1.1 of my TaskManager spreadsheet is exactly the same as version 0.1.0, except that it is digitally signed.
  • Android Web Content Resolver – labs.mwrinfosecurity.com
    When assessing Android devices and applications we regularly come across vulnerabilities in Android Content-Providers. These vulnerabilities are often similar to those found in web application security tests. In particular SQL Injection and directory traversal vulnerabilities are common problems in Content-Providers.
  • How To Find Android 0Day In No Time – labs.mwrinfosecurity.com
    Today we are releasing WebContentResolver, an Android assessment tool which allows you to find Content-Provider vulnerabilities in no time. A Content-Provider is one of Androids IPC endpoints; it is commonly used to implement data storage in applications and to offer access to this data to other applications on the device.
  • The Mole – Automatic SQL Injection SQLi Exploitation Tool – darknet.org.uk
    The Mole is an automatic SQL Injection exploitation tool. Only by providing a vulnerable URL and a valid string on the site it can detect the injection and exploit it, either by using the union technique or a boolean query based technique.

Techniques

  • DNS Hacking (Beginner to Advanced) – resources.infosecinstitute.com
    DNS is a naming system for computers that converts human readable domain names e.g. (infosecinstitute.com) into computer readable IP-addresses. However some security vulnerabilities exist due to misconfigured DNS nameservers that can lead to information disclosure about the domain.
  • POP POP RET: SEH Exploiting Process – marcoramilli.blogspot.com
    This morning I want to talk a little bit about Structured Exception Handling (SEH) exploitation. Some readers, during a Skype meeting early last week, pointed me out that I never wrote about it, se lets talk a little bit about it.
  • "Hacking" Printers – PJL Basics – hackonadime.blogspot.com
    A short while later in my career, I got to be known as the AIX “hacker” because I knew more about AIX than even some IBM techs I’d talk to on the phone. That’s why the term “Hacking” in the title has quotes. What we’re going to talk about today is understanding some very basic features that most people have forgotten about and being able to manipulate those features to help us do some bad stuff.
  • CSRF with JSON – Leveraging XHR and CORS – sheeraj.blogspot.com
    Same Origin Policy (SOP) dictates cross domain calls and allows establishment of cross domain connections. SOP bypasses allow CSRF attack vector, an attacker can inject a payload on cross domain page that initiate a request without consent or knowledge of the target user.
  • Embedding A Link To A Network Share In A Word Doc – carnal0wnage.attackresearch.com
    Someone asked me how to embed an HTML Link to an smb share into a word doc. End result would be to use the capture/server/smb or exploit/windows/exploit/smb/smb_relay modules. Easy right? Well it wasn’t THAT easy… In office 2010 when I’d go to pull in a picture to the document by adding a picture from a network share the picture would become part of the doc and not be retrieved every time the document opened. The solution was to add some html to the document.
  • SQL Injection Attack Happening ATM – isc.sans.edu
    Typically it is inserted into several tables.  From the information gathered so far it looks targeted at ASP, IIS and MSSQL backends, but that is just speculation.  If you find that you have been infected please let us know and if you can share packets, logs  please upload them on the contact form.

Vulnerabilities

  • 1% of CMS-Powered Sites Expose Their Database Passwords – feross.org
    Nearly 1% of websites built with a content management system (like WordPress or Joomla) are unknowingly exposing their database password to anyone who knows where to look.
  • Researchers Find Big Leaks In Pre-Installed Android Apps – arstechnica.com
    Researchers at North Carolina State University have uncovered a variety of vulnerabilities in the standard configurations of popular Android smartphones from Motorola, HTC, and Samsung, finding that they don’t properly protect privileged permissions from untrusted applications.

Other News

Information Security Events For December

Published: December 1st, 2011 | Category: Local Meetings, Security Conferences, Security Training | (0) Comments

Here are information security events in North America this month: BayThreat 2011: December 9 to December 11 in Mountain View SANS Cyber Defense Initiative 2011: December 9 to December 16 in Washington, DC   And here are the information security events in the other parts of the world: BeneLux OWASP Day 2011: December 1 to [...]

Week 47 In Review

Published: November 28th, 2011 | Category: Security Conferences, Security Tools, Security Vulnerabilities | (0) Comments

Events Related Source Barcelona 2011 Materials - blog.pentestify.com/source-barcelona-2011-materials Quick post to link our information from Source Barcelona 2011. @kernelsmith & i discussed alternative use cases for the Metasploit Framework. The presentation was shotgun / AHA! style, meaning we had a number of 5 minute mini-presentations within the larger 50 minute preso. DeepSec Diary - blog.c22.cc/2011/11/22/deepsec-2011-quick-roundup/ The first [...]

Week 46 In Review

Published: November 21st, 2011 | Category: Security Conferences, Security Training, Security Vulnerabilities | (0) Comments

Events Related Source Barcelona 2011 Wrap-up – blog.rootshell.be After a smooth flight to Barcelona, I arrived on Tuesday evening just in time to take part to the speakers party at the apartments reserved for the conference. That’s something really unique (from what I know) to SOURCE: speakers, crew and some participants are sharing a bunch [...]

Week 45 In Review

Published: November 14th, 2011 | Category: Security Conferences, Security Tools, Security Training, Security Vulnerabilities | (0) Comments

Events Related SkyDogCon 2011 Videos – irongeek.com Here are the videos from SkyDogCon. Thanks to all of the SkyDogCon crew, especially SeeBlind for running the cameras. Resources NMAP NSE Hacking for IT Security Professionals Presentation Transcript – slideshare.net Nmap NSE Hacking for IT Security Professionals Marc Ruef www.scip.ch Security & Risk Conference November 3th – 6th [...]

Week 44 In Review

Published: November 6th, 2011 | Category: Security Conferences, Security Tools, Security Training, Security Vulnerabilities | (0) Comments

Events Related Mobile Security Summit 2011 – sensepost.com This week, Charl van der Walt and I (Saurabh) spoke at Mobile Security Summit organized by IIR. Charl was the keynote speaker and presented his insight on the impact of the adoption of mobile devices throughout Africa and the subsequent rise of security related risks. Resources SAP [...]

Information Security Events For November

Published: November 1st, 2011 | Category: Hacking Contests, Security Conferences, Security Training | (0) Comments

Here are information security events in North America this month: Hackfest Optimized: November 4 to November 5 in Quebec BSides DFW: November 5 to November 6 in Irving     BSides Atlanta: November 4 in Atlanta   BSides Delaware: November 1 to November 12 in New Castle   SC Congress: November 16 in New York [...]

Week 43 In Review

Published: October 31st, 2011 | Category: Security Conferences, Security Tools, Security Training, Security Vulnerabilities | (0) Comments

Events Related Hack3rcon II Videos - irongeek.com Archive of Hack3rcon video archive. SecTor 2011 Presentations – sector.ca Audio and video archive. DefCon 19 Speakers and Presentations – defcon.org Slides and presentations archive. BSidesKC Videos – h-i-r.net I actually didn’t get to present anything this year. Not for any particular reason. All the talks were awesome and [...]

Week 42 In Review

Published: October 24th, 2011 | Category: Security Tools, Security Training, Security Vulnerabilities | (0) Comments

Resources Analysis of 250,000 Hacker Conversations – net-security.org This forum is used by hackers for training, communications, collaboration, recruitment, commerce and even social interaction. Commercially, this forum serves as a marketplace for selling of stolen data and attack software. Pentesting iPhone Applications – securitylearn.wordpress.com I have given a presentation on Pentesting iPhone Applications in c0c0n. [...]

Week 41 In Review

Published: October 17th, 2011 | Category: Security Conferences, Security Tools, Security Training, Security Vulnerabilities | (0) Comments

Events Related RSA Europe Conference Wrap-up - blog.rootshell.be This is my wrap-up of the last RSA Conference which occurred in London. As usual, it’s a mix of t-shirts and ties. But, vendors followed the rules of the game and came with less promotional material for their next-top-ultra-last-generation-solution-to-beat-all-hackers-from-outer-space. Resources Hack In The Box Security Conference Presentation Materials [...]

PREVIOUS
NEXT
© Godai Group 2012
Home - Calendar - Communities - Training - Archives - Contact