back to your roots
Showing 1 - 25 of 545 RSS Feed

Files

Shell Code Injection To Process
Posted Feb 9, 2012
Authored by Turkeshan

Whitepaper called Shell Code Injection To Process. Written in Turkish.

tags | paper, shell
MD5 | 9caf5ab14b0324dd2531325a849b788e
DNS Service Oriented DoS / DDoS Attacks
Posted Feb 5, 2012
Authored by Huzeyfe ONAL

Whitepaper called DNS Service Oriented Denial of Service / Distributed Denial of Service Attacks. Written in Turkish.

tags | paper, denial of service
MD5 | 65e8a925c1f765f5b5d447b24ea5fde3
Analysis Of A MIDI Remote Code Execution Vulnerability
Posted Feb 5, 2012
Authored by Celil Unuver

This whitepaper analyzes the MIDI remote code execution vulnerability found in the Windows Multimedia Library. Written in Turkish.

tags | paper, remote, code execution
systems | windows
advisories | CVE-2012-0003
MD5 | 86b73a0bd44eecf2f0ae4fc449aeb170
Mobile Based MITM Attack
Posted Feb 5, 2012
Authored by Bilal Bokhari

This is a brief whitepaper discussing how to set up QT Mobile Hotspot and YAMAS applications to man in the middle connections using your phone.

tags | paper
MD5 | 6756a8aa5d75c60ab30be7b7312b4fc3
RFC6528 - Defending Against Sequence Number Attacks
Posted Feb 3, 2012
Authored by Fernando Gont

This document specifies an algorithm for the generation of TCP Initial Sequence Numbers (ISNs), such that the chances of an off-path attacker guessing the sequence numbers in use by a target connection are reduced. This document revises (and formally obsoletes) RFC 1948, and takes the ISN generation algorithm originally proposed in that document to Standards Track, formally updating RFC 793.

tags | paper, tcp
MD5 | 4bd9d141dba29f999534d68fbcf120f5
Votre Premiere Exploitation De BOF
Posted Feb 2, 2012
Authored by fr0g

This is a short whitepaper written in French that is called Votre Premiere Exploitation de BOF.

tags | paper
MD5 | 978fb90d0bb2ace7992457cf683b21fd
iPhone Forensics On iOS 5
Posted Jan 20, 2012
Authored by Satish Bommisetty

This is a brief whitepaper discussing how to perform forensics on iOS 5 on the iPhone.

tags | paper
systems | apple, iphone
MD5 | 782903866dd7d55143c6835188eda2fe
Common Security Vulnerabilities In Online Payment Systems
Posted Jan 19, 2012
Authored by Hitesh Malviya

This is a short whitepaper that discusses common vulnerabilities in online payment systems.

tags | paper, vulnerability
MD5 | f4267b132dd0f54dcdfcfb54738eda4e
Reflection Scan: An Off-Path Attack On TCP
Posted Jan 18, 2012
Authored by Jan Wrobel

The paper demonstrates how traffic load of a shared packet queue can be exploited as a side channel through which protected information leaks to an off-path attacker. The attacker sends to a victim a sequence of identical spoofed segments. The victim responds to each segment in the sequence (the sequence is reflected by the victim) if the segments satisfy a certain condition tested by the attacker. The responses do not reach the attacker directly, but induce extra load on a routing queue shared between the victim and the attacker. Increased processing time of packets traversing the queue reveal that the tested condition was true. The paper concentrates on the TCP, but the approach is generic and can be effective against other protocols that allow to construct requests which are conditionally answered by the victim.

tags | paper, spoof, tcp, protocol, proof of concept
MD5 | 3f661f7510db6f7555090f64d98e634e
Cloud Computing Overview And Security Issues
Posted Jan 18, 2012
Authored by Hitesh Malviya

This is a brief whitepaper that discusses an overview of cloud computing and some high level security issues associated with it.

tags | paper
MD5 | 80f9e90e49daa507276c25a5cc3e0c1e
Security Implications Of IPv6 Extensions Headers With Neighbor Discovery Rev 2
Posted Jan 13, 2012
Authored by Fernando Gont | Site ietf.org

IPv6 Extension Headers with Neighbor Discovery messages can be leveraged to circumvent simple local network protections, such as "Router Advertisement Guard". Since there is no legitimate use for IPv6 Extension Headers in Neighbor Discovery messages, and such use greatly complicates network monitoring and simple security mitigations such as RA-Guard, this document proposes that hosts silently ignore Neighbor Discovery messages that use IPv6 Extension Headers. Revision 2 of this document. This revision includes, among other things, a discussion of possible issues with SEND as a result of IPv6 fragmentation.

tags | paper, local
MD5 | bddd807b8490984a05656623cd777ccd
Buffer Overflows: Anatomy Of An Exploit
Posted Jan 11, 2012
Authored by Joshua Hulse

Whitepaper called Buffer Overflows: Anatomy of an Exploit. A look at how systems are exploited and why these exploits exist.

tags | paper, overflow
MD5 | 5ed1c91a3ec36484f952cddff2c5778a
Implementation Advice For IPv6 Router Advertisement Guard (RA-Guard)
Posted Jan 5, 2012
Authored by Fernando Gont

This Internet Draft focuses on providing advice to RA-Guard implementations, rather than on the evasion techniques that have been found effective against most popular implementations of RA-Guard.

tags | paper
MD5 | 1b5c636801345cb01aca19632ee04573
Linux Kernel Hooking / Data Manipulations / Root Exploits
Posted Jan 3, 2012
Authored by Turkeshan

Whitepaper called Linux Kernel Hooking, Data Manipulations and Making Root Exploits. Written in Turkish.

tags | paper, kernel, root
systems | linux
MD5 | 28fae139bde9a4dc5de620503482207d
DoS Attacks And Mitigation Techniques
Posted Dec 28, 2011
Authored by Subramani Rao

Whitepaper called Denial of Service attacks and mitigation techniques: Real time implementation with detailed analysis. Unlike other theoretical studies, this paper lays down the steps involved in implementing these attacks in real time networks. These real time attacks are measured and analyzed using network traffic monitors. In addition to that, this project also details various defense strategies that could be enabled on Cisco routers in order to mitigate these attacks. The detection and mitigation mechanisms designed here are effective for small network topologies and can also be extended to analogous large domains.

tags | paper, denial of service
systems | cisco
MD5 | a7d283e69e99422e2fe86041f1af3f16
Exploit WebDAV... The Garage Way
Posted Dec 26, 2011
Authored by Dhiraj Datar

This is a brief whitepaper discussing how to exploit a webDAV enabled server.

tags | paper
MD5 | 9f254c048e06b9bde5c3fa60cc95b55b
Hardware Involved Software Attacks
Posted Dec 25, 2011
Authored by Jeff Forristal

Whitepaper called Hardware Involved Software Attacks. Computer security vulnerabilities involving hardware are under-represented within the security industry. With a growing number of attackers, malware, and researchers moving beyond pure software attack scenarios and into scenarios incorporating a hardware element, it is important to start laying a foundation on how to understand, characterize, and defend against these types of hybrid attacks. This paper introduces and details a starting taxonomy of security attacks called hardware involved software attacks, in an effort to further security community awareness of hardware security and its role in upholding the security of the PC platform.

tags | paper, vulnerability
MD5 | 71ecd2fe1142751766ab25085720c584
False SQL Injection / Advanced Blind SQL Injection
Posted Dec 22, 2011
Authored by wh1ant

This is a brief whitepaper called False SQL Injection and Advanced Blind SQL Injection.

tags | paper, sql injection
MD5 | 05040c813b44124bbd7a6080eb4585c3
Armitage - Hacking Made Easy Part 1
Posted Dec 20, 2011
Authored by r45c4l

This is a whitepaper called Armitage - Hacking Made Easy Part 1. It covers using the Armitage GUI for Metasploit when performing pentesting.

tags | paper
MD5 | bcfdd3b262050f31835bee0c94b5c897
Time-Based Blind NoSQL Injection
Posted Dec 19, 2011
Authored by Felipe Aragon | Site syhunt.com

This is a brief write up discussing time-based NoSQL injection attacks using javascript.

tags | paper, javascript, sql injection
MD5 | 91d28ae50067e7a25392529916fe2966
IETF I-D On Fragmentation Related Security Issues
Posted Dec 16, 2011
Authored by Fernando Gont

This Internet Draft specifies the security implications of predictable fragment identification values in IPv6. It primarily focuses on countermeasures and mitigations.

tags | paper
MD5 | ea42370891c626496f81f24e5a922d19
IETF I-D On "Stable Privacy Addresses"
Posted Dec 16, 2011
Authored by Fernando Gont

This document specifies a method for generating IPv6 Interface Identifiers to be used with IPv6 Stateless Address Autoconfiguration (SLAAC), such that addresses configured using this method are stable within each subnet, but the Interface Identifier changes when hosts move from one network to another. The aforementioned method is meant to be an alternative to generating Interface Identifiers based on IEEE identifiers, such that the same manageability benefits can be achieved without sacrificing the privacy of users.

tags | paper
MD5 | 0b0fef7bec3954389f6b4bcfd6749ba6
Active Directory Offline Hash Dump And Forensic Analysis
Posted Dec 15, 2011
Authored by Csaba Barta

Whitepaper called Active Directory Offline Hash Dump and Forensic Analysis. The author participated in a project where it was required to extract the password hashes from an offline NTDS.DIT file. After searching the Internet for an available tool, the author found that there was no open source tool. Because of that the author decided to research the internals of password encryption and storage of Active Directory and create a tool for the forensic community.

tags | paper
MD5 | 176aa1514d9d4807c99e9f7ff82945f7
An Analysis Of Facebook Spam Through Browser Extensions
Posted Dec 13, 2011
Authored by Prajwal Panchmahalkar

This whitepaper is an analysis of Facebook spam exploited through browser add-ons and extensions.

tags | paper
MD5 | 7b27352c3661281e6cc856a2b7896b3b
Unprotecting The Crypter - A Generic Approach
Posted Dec 13, 2011
Authored by Arunpreet Singh

Whitepaper called Unprotecting the Crypter, a Generic Approach. It discusses how crypters work and unpacking malware.

tags | paper
MD5 | 3491d2fba4fa6ac325f6f33e4dd600a1
Page 1 of 22
Back12345Next

Top Authors In Last 30 Days

packet storm

© 2012 Packet Storm. All rights reserved.

close