Subscribe to Infosec Events
    Infosec Events Feed Stay up to date with all of the latest security news by subscribing to our RSS Feed. Alternatively, you can have updates sent directly to your email address.

    Week 11 in Review – 2013

    Published: March 18th, 2013 | Category: Security Conferences, Security Tools, Security Vulnerabilities | (0) Comments

    Event Related

    Resources

    • Introduction to WMI Basics with PowerShell Part 1 (What it is and exploring it with a GUI) – pauldotcom.com
      WMI is the Microsoft implementation of Web-Based Enterprise Management (WBEM), with some enhancements in the initial version of it, WBEM is a industry initiative to develop a standard technology for accessing management information in an enterprise environment that covers not only Windows but also many other types of devices like routers, switches, storage arrays …etc.
    • 0xdabbad00.com Blog Archive Thoughts on signed executables – 0xdabbad00.com
      In thinking about making an application to do white-listing on Windows, one of the first questions you have is how do you identify what to trust?
    • Virtual Patching Cheat Sheet – OWASP – owasp.org
      The goal with this cheat Sheet is to present a concise virtual patching framework that organizations can follow to maximize the timely implementation of mitigation protections.
    • America’s Next Top Module – community.rapid7.com
      These stats are gathered roughly monthly from the Metasploit exploit database backend, and tend to have a pretty strong recency bias — modules that recently got a lot of press or Twitter buzz tend to shoot up to the top of the list.
    • Windows Auth – The Nightmare Begins (SSO) – passing-the-hash.blogspot.com
      I’m going to start with an overview of Windows authentication and why it’s such a large, complicated, unwieldy beast.
    • The Pentester’s Guide to Akamai – nccgroup.com
      I’m happy to announce we’ve just published a new technical whitepaper based on knowledge gained assessing sites located behind Akamai.
    • Security of RC4 Stream Cipher – home.hiroshima-u.ac.jp
      We published a first plaintext recovery attack of RC4 in the broadcast setting where same plaintext is encrypted by different user keys at FSE 2013 (earlier than AlFardan-Bernstein-Paterson-Poettering-Schuldt Results).

    Tools

    Techniques

    • How I Hacked Any Facebook Account…Again! – nirgoldshlager.com
      This is my second post regarding Facebook OAuth Vulnerabilities.
    • Phishing Techniques: Similarities, Differences and Trends Part II: Targeted Phishing – resources.infosecinstitute.com
      Spear-phishing is a technique by which a cyber-criminal falsely presents himself in an electronic communication as a CEO, director, manager or a subordinate (an insider) of a particular firm or department of government where his victim works to earn their trust, or he impersonates an entity which is either trusted by the targeted firm/government or the latter has relations or obligations towards it.
    • PowerShell Basics – Extending the Shell with Modules and Snapins – pauldotcom.com
      There is a big miss conception with people starting with PowerShell when they install some server products like Exchange or SharePoint and the programs place a shotcut to what they call a “Management Shell” it is nothing more than PowerShell with a loaded Module or PSSnapin. As you will see extending the shell is quite simple and flexible.

    Vendor/Software Patches

    Vulnerabilities

    Other News

    Week 10 in Review – 2013

    Published: March 11th, 2013 | Category: Security Conferences, Security Tools, Security Vulnerabilities | (0) Comments

    Event Related DEP-ASLR bypass without ROP-JIT.pdf – docs.google.com This is a pdf file from the event CanSecWest 2013 Pwn2Own: IE10, Firefox, Chrome, Reader, Java hacks land $500k – theregister.co.uk It’s back to the drawing board for coders at Microsoft, Google, Adobe, Mozilla, and Oracle after entrants in the annual Pwn2Own contest waltzed off with over [...]

    Week 9 in Review – 2013

    Published: March 4th, 2013 | Category: Security Conferences, Security Tools, Security Vulnerabilities | (0) Comments

    Event Related Juniper Networks intros global cloud-based ‘attacker database’ – zdnet.com At the start of RSA 2013, Juniper Networks is rolling out a global database to track attacks on individual devices. MASTIFF Analysis of APT1 – novainfosec.com At Shmoocon this year we were please to find that there is a project focused on this specifically [...]

    Information Security Events For March

    Published: February 27th, 2013 | Category: Security Conferences, Security Training | (0) Comments

    Here are information security events in North America this month:   Metricon (Conjunction with RSA) : March 1, 2013 in San Francisco USA   BSides Vancouver 2013 : March 4 to 5 in Vancouver, BC, Canada     CanSecWest 2013 : March 6 to 8 in Vancouver, British Columbia     AtlSecCon 2013 : March [...]

    Week 8 in Review – 2013

    Published: February 25th, 2013 | Category: Security Conferences, Security Tools, Security Vulnerabilities | (0) Comments

    Event Related ShmooCon Firetalks 2013 – irongeek.com These are the videos I have for the ShmooCon Firetalks 2013. Resources APT 1 APT 1: Exposing One of China’s Cyber Espionage Units – intelreport.mandiant.com APT1: Exposing One of China’s Cyber Espionage Units Threat Actors Using Mandiant APT1 Report as a Spear Phishing Lure: The Nitty Gritty – [...]

    Week 7 in Review – 2013

    Published: February 18th, 2013 | Category: Security Conferences, Security Tools, Security Vulnerabilities | (0) Comments

    Event Related S4x13 Video: Atlas on RF Comms Security and Insecurity – digitalbond.com RF Comms are often ignored in SCADA assessments. Big mistake as atlas 0f d00m shows RF hacking session at S4x13. #Shmoocon Presentation Links – mainframed767.tumblr.com So I talked fast and furious and ran out of time, but 20 minutes is not a [...]

    Week 6 in Review – 2013

    Published: February 11th, 2013 | Category: Security Tools, Security Vulnerabilities | (2) Comments

    Resources “Security Engineering” now available free online – lightbluetouchpaper.org I’m delighted to announce that my book Security Engineering – A Guide to Building Dependable Distributed Systems is now available free online in its entirety. You may download any or all of the chapters from the book’s web page. The Anatomy of Unsecure Configuration: Reality Bites [...]

    Week 5 in Review – 2013

    Published: February 4th, 2013 | Category: Security Conferences, Security Tools, Security Vulnerabilities | (0) Comments

    Event Related Pentest & Reverse: iOS Application Hacking – esec-pentest.sogeti.com Last month, we gave some lectures about iOS application Hacking first at GreHack (Grenoble, France) and then at Hack.Lu (Luxembourg, Luxembourg). Here you will find the slides and the paper. Don’t hesitate to send us your questions. Resources The Red team Mindset Course Part 1 [...]

    Information Security Events For February

    Published: January 29th, 2013 | Category: Security Conferences, Security Training | (0) Comments

    Here are information security events in North America this month:     ShmooCon 2013 : February 15 to 17 in Washington, District of Columbia USA   ACM Conference on Data and Application Security and Privacy (CODASPY) : February 18 to 20 in San Antonio, TX, USA   BSides Boston : February 23 in Cambridge, MA [...]

    Week 4 in Review – 2013

    Published: January 28th, 2013 | Category: Security Tools, Security Vulnerabilities | (0) Comments

    Event Related University Courses on Reverse Engineering and Malware Analysis – f-secure.com Today marks the commencement of the first lecture for our spring 2013 semester Reverse Engineering Malware course for the Aalto University (Espoo campus) in Finland. Resources Security Assessment of Blackberry Applications – resources.infosecinstitute.com Development of mobile applications have picked up really fast in [...]

    PREVIOUS
    NEXT
    © Godai Group 2013
    Home - Calendar - Communities - Training - Archives - Contact