Subscribe to Infosec Events
Infosec Events Feed Stay up to date with all of the latest security news by subscribing to our RSS Feed. Alternatively, you can have updates sent directly to your email address.

Week 40 In Review

Published: October 10th, 2011 | Category: Security Conferences, Security Tools, Security Training, Security Vulnerabilities | (0) Comments

Events Related

Resources

  • Security 101: Security basics In 140 Characters Or Less – isc.sans.edu
    Since October is “Security Awareness Month,” a few weeks back, I sent out a call on Twitter for folks to submit pithy, 140 character-long, chunks of Security 101 wisdom.  Below, I’ve compiled together the resulting list, along with the Twitter name of the submitter.

Tools

  • MagicTree v1.0 Released, A Productivity Tool For Penetration Testers – darknet.org.uk
    MagicTree is a productivity tool for penetration testers. It allows consolidating data coming from various security tools, query and re-use the data and generate reports. It’s aim is to automate the boring and the mind-numbing work, so you can spend your time hacking.
  • UPDATE: ZAProxy v1.3.3! – code.google.com/p/zaproxy/downloads/list
    The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testingtool for finding vulnerabilities in web applications. It is designed to be used by people with a wide range of security experience and as such is ideal for developers and functional testers who are new to penetration testing as well as being a useful addition to an experienced pen testers toolbox. ZAP provides automated scanners as well as a set of tools that allow you to find security vulnerabilities manually.
  • UPDATE: THC-HYDRA v7.1! – freeworld.thc.org/releases/hydra-7.1-src.tar.gz
    THC-HYDRA is a very fast network logon cracker which support many different services. This tool is a proof of concept code, to give researchers and security consultants the possibility to show how easy it would be to gain unauthorized access from remote to a system. It was tested to compile cleanly on Linux,Windows,Cygwin, Solaris, FreeBSD and OSX.
  • UPDATE: USB VirusScan 1.7.4 – blog.didierstevens.com
    When USBVirusScan launches the program that was specified as argument upon insertion of a removable drive, it will provide debug information regarding the launching of this program.
  • CSET: The Cyber Security Evaluation Tool! – us-cert.gov/control_systems/csetdownload.html
    The Cyber Security Evaluation Tool (CSET) can provide you with a systematic and repeatable approach for assessing the cyber security posture of your industrial control systems (ICS) networks and IT systems.
  • Oter Tool Download Link – otertool.com
    Webpage embedded with mysterious download link.

Techniques

  • Beauty and the BEAST - isc.sans.edu
    As has been already written on million places, the BEAST attack attacks SSL 3.0 and TLS 1.0, in particular their implementation  of the Cipher-block chaining (CBC) block encryption algorithms.This is probably the most widely used mode for block encryption algorithms today, so it is obvious that any attack on this (and SSL/TLS overall) can have huge impact.
  • Mutual Authentification In Android and iOS – intrepidusgroup.com
    You’ll notice that the title says “Mutual Authentication”, not “Client Authentication” – our goal here is to implement both strong client authentication using certificates, and verify that the server certificate presented to us is issued by a CA we trust explicitly.
  • Gateway-finder script - pentestmonkey.net
    Gateway-finder is a scapy script that will help you determine which of the systems on the local LAN has IP forwarding enabled and which can reach the Internet. This can be useful during Internal pentests when you want to quickly check for unauthorised routes to the Internet (e.g. rogue wireless access points) or routes to other Internal LANs.  It doesn’t perform a hugely thorough check, but it is quick at least.  It’s python, so it should be easy to modify if you need it to do something more sophisticated.

Vulnerabilities

Other News

  • BlackBerry Media Card Encryption A Security Risk? – blogs.cio.com
    The BlackBerry OS is known for the many security safeguards it affords individual users and organizations, the most basic–and most important–of which is probably the device password.
  • Idaho Lab In A Race To Shore Up Critical Infrastructure Systems – wired.com
    All it took was one click of a mouse from the CEO of the ACME Chemical company. Within half an hour of that tap hackers had exfiltrated proprietary documents from the company’s network, commandeered IP-based surveillance cameras at the facility to spy on network administrators, seized control of a computer system managing its chemical mixing process and finally caused a toxic spill that administrators were powerless to stop.
  • McAfee Acquires Nitro Security – insecureaboutsecurity.com
    Fast forward to October 2011. At the start of National Cybersecurity Awareness Month, McAfee took the plunge by acquiring Nitro Security, a security management vendor based in lovely Portsmouth, NH.

 

Week 39 In Review

Published: October 3rd, 2011 | Category: Security Conferences, Security Tools, Security Vulnerabilities | (0) Comments

Events Related Ekoparty aftermath Miscelaneous material on the recent Ekoparty Ekoparty presentation: Cloud and Control – blog.gdssecurity.com Bypassing code signing policy – blog.eset.com Post #BruCon Network Analysis - blog.rootshell.be BruCON is over! As usual, when I attended a security conference, I’m trying to write a small wrap-up for me followers. With BruCON, it’s completely different: I’m on [...]

Information Security Events For October

Published: October 1st, 2011 | Category: Security Conferences, Security Training, Security Workshops | (0) Comments

Here are information security events in North America this month: BSides PDX: October 7 in Portland SANS Baltimore: October 9 to October 15 in Baltimore SANS NCIC: October 11 to October 15 in Washington, D.C. SecTor: October 17 to October 20 in Toronto BSides Montana: October 21 to October 22 in Jefferson City SANS Chicago: [...]

Week 38 In Review

Published: September 26th, 2011 | Category: Security Conferences, Security Tools, Security Training, Security Vulnerabilities | (0) Comments

Events Related BruCon 2011 Debriefing Brucon 2011 has come and gone but it did manage to achieve it’s goal. My brain is once again running at full steam with new ideas. So before all that steam runs out and I forget everything I’ll attempt to get all of that steam out onto this page. Brucon [...]

Week 37 In Review

Published: September 19th, 2011 | Category: Hacking Contests, Security Conferences, Security Tools | (0) Comments

Events Related Crack Me If You Can DefCon 2011 Insidepro team – contest.korelogic.com First of all, I must say that this year’s contest was a big improvement over last year. Not that last year was boring, far from that, but the feedbacks given last year were well understood and rectified this year. The weighted points [...]

Week 36 In Review

Published: September 12th, 2011 | Category: Security Conferences, Security Tools, Security Vulnerabilities | (0) Comments

Events Related Watch: An (Almost) Inside Look at China’s Top Information Security Forum – blogs.wsj.com Chinese computer-security researchers and professionals gathered in Beijing late last week for the 10th annual session of the country’s best-known information security conference, where presenters spoke on security threats and how they could be prevented. DefCon 19 Archive Page – [...]

Week 35 In Review

Published: September 5th, 2011 | Category: Security Conferences, Security Tools, Security Vulnerabilities | (0) Comments

Events Related Securitybyte CTF Walkthrough – securitylearn.wordpress.com SecurityByte is India’s largest hacking conference conducted in Bangalore. To make this event more interesting, they do arrange capture the flag events (Web & WI-FI hacking challenges). Tools Ncrack and the Morto Worm Ncrack is a high-speed network authentication cracking tool. It was built to help companies secure their [...]

Information Security Events For September

Published: September 1st, 2011 | Category: Security Conferences, Security Training, Security Workshops | (0) Comments

Here are information security events in North America this month: SANS Las Vegas: Septemer 17 to September 26 in Las Vegas RAID 2011: September 20 to September 21 in Menlo Park AppSEC USA 2011: September 20 to September 24 in Minneapolis DerbyCon: September 30 to October 3 in Louisville   And here are the information [...]

Week 34 In Review

Published: August 29th, 2011 | Category: Hacking Contests, Security Conferences, Security Tools, Security Training | (0) Comments

Events Related DefCon 2011 Leftover notes and resources five weeks after. Crack Me If You Can teams – contest.korelogic.com Crack Me If You Can InsidePro – contest.korelogic.com Crack Me If You Can team john users – contest.korelogic.com The Art of Exploiting Lesser Known Injection Flaws Revealed At BlackHat – penetration-testing.7safe.com The audience at Black Hat, Las Vegas [...]

Week 33 In Review

Published: August 22nd, 2011 | Category: Security Conferences, Security Tools, Security Training, Security Vulnerabilities | (0) Comments

Events Related BlackHat 2011 Leftover media, articles, and resources Sights and SOund sof BlackHat USA 2011 (Gallery) – darkreading.com LDAP/XPATH Injection Tools - notsosecure.com BlackHat 2011 Resource Portal – blackhat.com DefCon 19 Interesting stuff from Vegas Five Questions About Aaron Barr’s DefCon – threatpost.com DefCon 2011: SSL and the future of payloads – nakedsecurity.sophos.com Resources Cisco [...]

PREVIOUS
NEXT
© Godai Group 2012
Home - Calendar - Communities - Training - Archives - Contact