all things security
Showing 1 - 25 of 250 RSS Feed

Files

Egg Hunting Against BisonWare FTP Server
Posted Feb 7, 2012
Authored by Ashfaq Ansari

This whitepaper goes into detail on how to use egg hunting shellcode in order to exploit a BisonWare FTP server.

tags | paper, shellcode
MD5 | 3b77aa7034edc0a6eb15c7fb213af029
Exploiting glibc __tzfile_read Integer Overflow To Buffer Overflow And Vsftpd
Posted Dec 13, 2011
Authored by Ramon de C Valle | Site rcvalle.com

This is a write up that discusses exploiting the glibc __tzfile_read integer overflow to buffer overflow and leveraging Vsftpd.

tags | paper, overflow
MD5 | 761eafe34246bc9609dce3ba94413dea
Post Exploitation Using Meterpreter
Posted Dec 10, 2011
Authored by Shubham Mittal

Whitepaper called Post Exploitation using Meterpreter. It goes into detail on how to leverage Metasploit during a penetration test.

tags | paper
MD5 | dd551de2c821af9d282c9c942accd99c
Hacking Embedded Devices For Fun And Profit
Posted Nov 7, 2011
Authored by prdelka

These are slides from a talk called Hacking Embedded Devices for Fun and Profit. It uses Sky Broadband as a case study.

tags | exploit, paper
MD5 | f9efc36a6b7bcb29f56ee41189b2cf50
Anatomy Of A Pass Back Attack
Posted Nov 1, 2011
Authored by Deral Heiland, Michael Belton | Site foofus.net

Brief whitepaper discussing how to trick a printer into passing LDAP or SMB credentials back to an attacker in plain text.

tags | paper
MD5 | 8a5033d9c7adfc19759c96133ff7f0ea
The Trash Attack
Posted Nov 1, 2011
Authored by Eric Lazarus, Josh Benaloh

This short paper describes the trash attack which is effective against the majority of fully- verifiable election systems. The paper then offers a simple but counter-intuitive mitigation which can be incorporated within many such schemes to substantially reduce the effectiveness of the attack. This mitigation also offers additional benefits as it significantly improves the statistical properties of existing verifiable systems.

tags | paper
MD5 | 601a2786154b417d984dd536b3e6c1a6
Heap, Overflows And Exploitation
Posted Oct 31, 2011
Authored by Celil Unuver

Whitepaper called Heap, Overflows and Exploitation. Written in Turkish.

tags | paper, overflow
MD5 | df12ca7484c571eb01dc703774f107af
Skype VoIP Zero Day Exploitation
Posted Oct 20, 2011
Authored by Benjamin Kunz Mejri, Pim J.F. Campers

Whitepaper called Skype Voice Over IP Software Vulnerabilities, Techniques and Methods - Zero Day Exploitation 2011.

tags | paper, vulnerability
MD5 | b6ec606725fa2f9825409429680eaa18
DNS Poisoning Via Port Exhaustion
Posted Oct 19, 2011
Authored by Yair Amit, Roee Hay

Whitepaper called DNS Poisoning Via Port Exhaustion. It covers everything from how DNS poisoning works to various methods of performing attacks. It discloses two vulnerabilities. One is in Java which enables remote DNS poisoning using Java applets. The other is in multiuser Windows environments that allows for a local DNS cache poisoning of arbitrary domains.

tags | advisory, paper, java, remote, arbitrary, local, vulnerability
systems | windows
advisories | CVE-2011-3552, CVE-2010-4448
MD5 | c5b8f7158b3d193cd6c9e9cf005ea3ca
Local Session Poisoning In PHP Part 3
Posted Oct 14, 2011
Authored by Mango

This whitepaper is called Local Session Poisoning in PHP Part 3: Bypassing Suhosin's Session Encryption.

tags | paper, local, php
MD5 | dea90a3fffb6ae237c462a524a96eb3c
Local Session Poisoning In PHP Part 2
Posted Oct 14, 2011
Authored by Mango

This whitepaper is called Local Session Poisoning in PHP Part 2: Promiscuous Session Files.

tags | paper, local, php
MD5 | a8c3015377981763344b1a5faa822f7d
Local Session Poisoning In PHP Part 1
Posted Oct 14, 2011
Authored by Mango

This whitepaper is called Local Session Poisoning in PHP Part 1: The Basics of Exploitation and How to Secure a Server.

tags | paper, local, php
MD5 | 6518d3accc4f880c502012e632b08bfa
Hacking WebLogic
Posted Oct 12, 2011
Authored by Sysmox | Site sysmox.com

Whitepaper called Hacking WebLogic. It gives a brief overview of how to hack a default WebLogic server using a web browser.

tags | paper, web
MD5 | deff8f50fc6a94e7a1f2a21faafd1708
Le Sidejacking Avec Pycookiejsinject
Posted Oct 9, 2011
Authored by Adil Alhima

This whitepaper focuses on performing sidejacking with pycookiejsinject. Written in French.

tags | paper
MD5 | 262db71da248e4c6adccb90799a766fe
Beyond SQLi: Obfuscate And Bypass
Posted Oct 6, 2011
Authored by CWH Underground, ZeQ3uL, Suphot Boonchamnan

Whitepaper called Beyond SQLi: Obfuscate and Bypass. It discusses filter evasion, normal and advanced SQL injection bypassing techniques, and more.

tags | paper, sql injection
MD5 | 9e7b151e12188442fe45bb9959d31873
Frontal Attacks: From Basic Compromise To Advanced Persistent Threat
Posted Oct 2, 2011
Authored by High-Tech Bridge SA | Site htbridge.ch

Nowadays, there is a renewed interest in server-side attacks for hackers. According to SANS, attacks against web applications constitute more than 60% of the total attack attempts observed on the Internet. Victims may be the website owners (e.g. intellectual property theft or loss of customer confidence), their clients (e.g. bank transfer fraud or identity theft) as well as any Internet user, since web application vulnerabilities are now widely exploited to convert trusted websites into malicious ones, thus serving client-side exploits contents to Internet users. This document addresses the major threats which face today's companies, from database exfiltration in DMZ to the Advanced Persistent Threats recently undergone in many international organizations.

tags | paper, web, vulnerability
MD5 | d8d326545aaa218cc66f98e6863ad4f1
JBoss Exploitation
Posted Oct 1, 2011
Authored by Secfence

Whitepaper called JBoss Exploitation. This paper goes into detail on popping a shell on open JMX consoles.

tags | paper, shell
MD5 | c381c318bef922e991b3ecedda6b2843
Top Seven ColdFusion Security Issues
Posted Sep 14, 2011
Authored by Sysmox

This whitepaper discusses the most prevalent security issues with server configurations and application implementations for ColdFusion.

tags | paper
MD5 | 6a314661afd99deedfd1dd237aabc836
Using QR Tags To Attack Smart Phones
Posted Sep 13, 2011
Authored by Augusto Pereyra

Whitepaper called Using QR Tags to Attack Smart Phones (Attaging). It discusses the threatscape related to arbitrary scanning of these tags and using Metasploit to exploit them.

tags | paper, arbitrary
MD5 | ce00114a7c73e17018ca82de018b612b
Sneak Peak At The Metasploit Framework - II
Posted Aug 19, 2011
Authored by Karthik R

Whitepaper called Sneak Peak at the Metasploit Framework - II. This article covers using databases with the Metasploit Framework in detail.

tags | paper
MD5 | f16ad0205de570285ca393a7a303389a
Introduction To Hacking Basics
Posted Aug 5, 2011
Authored by failed404

Whitepaper called Introduction To Hacking Basics. Written in Indonesian.

tags | paper
MD5 | c9d4701c914028f4495d86a24812d227
Sneak Peak At The Metasploit Framework
Posted Jul 31, 2011
Authored by Karthik R

This whitepaper is an article that covers the basic structure of Metasploit and the need for it as a framework. It provides guidance on the different techniques of information gathering and scans.

tags | paper
MD5 | 2820fcb64a9e7705555c53e64e812c6c
Using Metasploit With Nessus Bridge On Ubuntu
Posted Jul 16, 2011
Authored by David J. Dodd

Whitepaper called Using Metasploit With Nessus Bridge On Ubuntu. The author discusses using the autopwn feature in Metasploit, running Nessus from within Metasploit, choices of databases to use, and the benefits of each.

tags | paper
systems | linux, ubuntu
MD5 | 766f4a856aa3f0e813b475eecaa34efc
HTTP Parameter Contamination
Posted Jul 16, 2011
Authored by Ivan Markovic

This is a brief whitepaper called HTTP Parameter Contamination (HPC) Attack / Research.

tags | paper, web
MD5 | b2608b0ad6615d2db4c78b1e09a4df76
Potential Dangers Of Active-X Attacks
Posted Jul 5, 2011
Authored by High-Tech Bridge SA | Site htbridge.ch

Whitepaper called Become Fully Aware of the Potential Dangers of Active-X Attacks. Exploiting Active-X components vulnerabilities in Windows has become a favored method of attackers aiming to compromise specific computers. Such targeted attacks have increasingly become a threat to companies and government agencies. This talk will explain this kind of attack and show how this flaw could be discovered while going through exploitation.

tags | paper, vulnerability, activex
systems | windows
MD5 | 322c439a1fbf4f023f91e7544f8195a6
Page 1 of 10
Back12345Next

Top Authors In Last 30 Days

packet storm

© 2012 Packet Storm. All rights reserved.

close