knowledge is security
Showing 1 - 25 of 254 RSS Feed

Files

Scanning Tools
Posted May 21, 2012
Authored by David J. Dodd

This whitepaper touches on various scanning tools and how to use them. It gives an overview of hping, scapy, unicornscan, nmap, and nessus.

tags | paper
MD5 | 8128327a88a5c5ef7592058f15992966
Intro To SQL Injection And Countermeasures
Posted Apr 24, 2012
Authored by Hitesh Malviya

Whitepaper called Intro to SQL Injection and Countermeasures.

tags | paper, sql injection
MD5 | 68db188cf8aab372f9306915334ea57d
Attacking The Washington, D.C. Internet Voting System
Posted Mar 3, 2012
Authored by Scott Wolchok, Eric Wustrow, J. Alex Halderman, Dawn Isabel

Whitepaper called Attacking the Washington, D.C. Internet Voting System. In 2010, Washington, D.C. developed an Internet voting pilot project that was intended to allow overseas absentee voters to cast their ballots using a website. The authors of this paper participated in a challenge to break the security of the system and in doing so, elected Bender from Futurama to the school board.

tags | paper
MD5 | bf259421383085dfe1dea44f3ea2912a
Metasploit Low Level View
Posted Feb 28, 2012
Authored by Saad Talaat

Whitepaper called Metasploit: Low Level View. It touches on topics such as code injection and malware detection evasion / Metasploit encoders.

tags | paper
MD5 | 0559a81662deefef0464d9ae73e2544c
Egg Hunting Against BisonWare FTP Server
Posted Feb 7, 2012
Authored by Ashfaq Ansari

This whitepaper goes into detail on how to use egg hunting shellcode in order to exploit a BisonWare FTP server.

tags | paper, shellcode
MD5 | 3b77aa7034edc0a6eb15c7fb213af029
Exploiting glibc __tzfile_read Integer Overflow To Buffer Overflow And Vsftpd
Posted Dec 13, 2011
Authored by Ramon de C Valle | Site rcvalle.com

This is a write up that discusses exploiting the glibc __tzfile_read integer overflow to buffer overflow and leveraging Vsftpd.

tags | paper, overflow
MD5 | 761eafe34246bc9609dce3ba94413dea
Post Exploitation Using Meterpreter
Posted Dec 10, 2011
Authored by Shubham Mittal

Whitepaper called Post Exploitation using Meterpreter. It goes into detail on how to leverage Metasploit during a penetration test.

tags | paper
MD5 | dd551de2c821af9d282c9c942accd99c
Hacking Embedded Devices For Fun And Profit
Posted Nov 7, 2011
Authored by prdelka

These are slides from a talk called Hacking Embedded Devices for Fun and Profit. It uses Sky Broadband as a case study.

tags | exploit, paper
MD5 | f9efc36a6b7bcb29f56ee41189b2cf50
Anatomy Of A Pass Back Attack
Posted Nov 1, 2011
Authored by Deral Heiland, Michael Belton | Site foofus.net

Brief whitepaper discussing how to trick a printer into passing LDAP or SMB credentials back to an attacker in plain text.

tags | paper
MD5 | 8a5033d9c7adfc19759c96133ff7f0ea
The Trash Attack
Posted Nov 1, 2011
Authored by Eric Lazarus, Josh Benaloh

This short paper describes the trash attack which is effective against the majority of fully- verifiable election systems. The paper then offers a simple but counter-intuitive mitigation which can be incorporated within many such schemes to substantially reduce the effectiveness of the attack. This mitigation also offers additional benefits as it significantly improves the statistical properties of existing verifiable systems.

tags | paper
MD5 | 601a2786154b417d984dd536b3e6c1a6
Heap, Overflows And Exploitation
Posted Oct 31, 2011
Authored by Celil Unuver

Whitepaper called Heap, Overflows and Exploitation. Written in Turkish.

tags | paper, overflow
MD5 | df12ca7484c571eb01dc703774f107af
Skype VoIP Zero Day Exploitation
Posted Oct 20, 2011
Authored by Benjamin Kunz Mejri, Pim J.F. Campers

Whitepaper called Skype Voice Over IP Software Vulnerabilities, Techniques and Methods - Zero Day Exploitation 2011.

tags | paper, vulnerability
MD5 | b6ec606725fa2f9825409429680eaa18
DNS Poisoning Via Port Exhaustion
Posted Oct 19, 2011
Authored by Yair Amit, Roee Hay

Whitepaper called DNS Poisoning Via Port Exhaustion. It covers everything from how DNS poisoning works to various methods of performing attacks. It discloses two vulnerabilities. One is in Java which enables remote DNS poisoning using Java applets. The other is in multiuser Windows environments that allows for a local DNS cache poisoning of arbitrary domains.

tags | advisory, paper, java, remote, arbitrary, local, vulnerability
systems | windows
advisories | CVE-2011-3552, CVE-2010-4448
MD5 | c5b8f7158b3d193cd6c9e9cf005ea3ca
Local Session Poisoning In PHP Part 3
Posted Oct 14, 2011
Authored by Mango

This whitepaper is called Local Session Poisoning in PHP Part 3: Bypassing Suhosin's Session Encryption.

tags | paper, local, php
MD5 | dea90a3fffb6ae237c462a524a96eb3c
Local Session Poisoning In PHP Part 2
Posted Oct 14, 2011
Authored by Mango

This whitepaper is called Local Session Poisoning in PHP Part 2: Promiscuous Session Files.

tags | paper, local, php
MD5 | a8c3015377981763344b1a5faa822f7d
Local Session Poisoning In PHP Part 1
Posted Oct 14, 2011
Authored by Mango

This whitepaper is called Local Session Poisoning in PHP Part 1: The Basics of Exploitation and How to Secure a Server.

tags | paper, local, php
MD5 | 6518d3accc4f880c502012e632b08bfa
Hacking WebLogic
Posted Oct 12, 2011
Authored by Sysmox | Site sysmox.com

Whitepaper called Hacking WebLogic. It gives a brief overview of how to hack a default WebLogic server using a web browser.

tags | paper, web
MD5 | deff8f50fc6a94e7a1f2a21faafd1708
Le Sidejacking Avec Pycookiejsinject
Posted Oct 9, 2011
Authored by Adil Alhima

This whitepaper focuses on performing sidejacking with pycookiejsinject. Written in French.

tags | paper
MD5 | 262db71da248e4c6adccb90799a766fe
Beyond SQLi: Obfuscate And Bypass
Posted Oct 6, 2011
Authored by CWH Underground, ZeQ3uL, Suphot Boonchamnan

Whitepaper called Beyond SQLi: Obfuscate and Bypass. It discusses filter evasion, normal and advanced SQL injection bypassing techniques, and more.

tags | paper, sql injection
MD5 | 9e7b151e12188442fe45bb9959d31873
Frontal Attacks: From Basic Compromise To Advanced Persistent Threat
Posted Oct 2, 2011
Authored by High-Tech Bridge SA | Site htbridge.ch

Nowadays, there is a renewed interest in server-side attacks for hackers. According to SANS, attacks against web applications constitute more than 60% of the total attack attempts observed on the Internet. Victims may be the website owners (e.g. intellectual property theft or loss of customer confidence), their clients (e.g. bank transfer fraud or identity theft) as well as any Internet user, since web application vulnerabilities are now widely exploited to convert trusted websites into malicious ones, thus serving client-side exploits contents to Internet users. This document addresses the major threats which face today's companies, from database exfiltration in DMZ to the Advanced Persistent Threats recently undergone in many international organizations.

tags | paper, web, vulnerability
MD5 | d8d326545aaa218cc66f98e6863ad4f1
JBoss Exploitation
Posted Oct 1, 2011
Authored by Secfence

Whitepaper called JBoss Exploitation. This paper goes into detail on popping a shell on open JMX consoles.

tags | paper, shell
MD5 | c381c318bef922e991b3ecedda6b2843
Top Seven ColdFusion Security Issues
Posted Sep 14, 2011
Authored by Sysmox

This whitepaper discusses the most prevalent security issues with server configurations and application implementations for ColdFusion.

tags | paper
MD5 | 6a314661afd99deedfd1dd237aabc836
Using QR Tags To Attack Smart Phones
Posted Sep 13, 2011
Authored by Augusto Pereyra

Whitepaper called Using QR Tags to Attack Smart Phones (Attaging). It discusses the threatscape related to arbitrary scanning of these tags and using Metasploit to exploit them.

tags | paper, arbitrary
MD5 | ce00114a7c73e17018ca82de018b612b
Sneak Peak At The Metasploit Framework - II
Posted Aug 19, 2011
Authored by Karthik R

Whitepaper called Sneak Peak at the Metasploit Framework - II. This article covers using databases with the Metasploit Framework in detail.

tags | paper
MD5 | f16ad0205de570285ca393a7a303389a
Introduction To Hacking Basics
Posted Aug 5, 2011
Authored by failed404

Whitepaper called Introduction To Hacking Basics. Written in Indonesian.

tags | paper
MD5 | c9d4701c914028f4495d86a24812d227
Page 1 of 11
Back12345Next

Top Authors In Last 30 Days

packet storm

© 2012 Packet Storm. All rights reserved.

close