trust is easily compromised
Showing 101 - 125 of 582 RSS Feed

Files

Dasar-Dasar Keamanan Di WordPress
Posted Aug 21, 2011
Authored by tempe_mendoan | Site devilzc0de.org

This is a basic tutorial on web security with WordPress. Written in Indonesian.

tags | paper, web
MD5 | 69f13561b93e2a06c8bf88bf72456312
Trends In Circumventing Web-Malware Detection
Posted Aug 19, 2011
Authored by Neils Provos, Moheeb Abu Rajab, Nav Jagpal, Lucas Ballard, Ludwig Schmidt, Daisuke Nojiri, Panayiotis Mavrommatis

Whitepaper called Trends in Circumventing Web-Malware Detection. This paper studies the resulting arms race between detection and evasion from the point of view of Google's Safe Browsing infrastructure, an operational web-malware detection system that serves hundreds of millions of users.

tags | paper, web
MD5 | 98e248077c31accc8637e54faa0d03bd
Social Engineering Toolkit
Posted Aug 19, 2011
Authored by Karthik R

Whitepaper called Social Engineering Toolkit. This article covers backdooring executables and evading antivirus using scripts included with BackTrack.

tags | paper
MD5 | 0e5ccde897c959f10062bed5afebcc21
Flash Cookies And Privacy II: Now With HTML5 And ETag Respawning
Posted Aug 16, 2011
Authored by Nathaniel Good, Mika D. Ayenson, Chris Jay Hoofnagle, Ashkan Soltani, Dietrich J. Wambach

Whitepaper called Flash Cookies And Privacy II: Now With HTML5 And ETag Respawning. This is a follow-up study that reassesses the flash cookie landscape and examines a new tracking vector, HTML5 local storage, and cache-cookies via ETags.

tags | paper, local
MD5 | 875cd334fd8d44141ce8d8f6e5f680df
Userland Hooking In Windows
Posted Aug 16, 2011
Authored by High-Tech Bridge SA | Site htbridge.ch

Whitepaper called Userland Hooking in Windows. This document is the first of a series of five articles relating to the art of hooking. As a test environment, it will use an English Windows Seven SP1 operating system distribution.

tags | paper
systems | windows
MD5 | 05a7bc02c53bdc0f1a0598ded46469bd
Exploring And Patching File Inclusion Vulnerabilities
Posted Aug 4, 2011
Authored by NassRawI

Whitepaper called Exploring and Patching File Inclusion Vulnerabilities. Written in Arabic.

tags | paper, vulnerability, file inclusion
MD5 | 00525545f51d85ccb282a870b90d47ed
T-Mobile Site And Server Security
Posted Aug 2, 2011
Authored by GrahamPhisher

Small write-up discussing various issues with T-Mobile's site and security.

tags | paper
MD5 | 017d8d05a0451a9ef16643d065ac8d5d
IAT Hooking Revisited
Posted Aug 2, 2011
Authored by AutoSec Tools | Site autosectools.com

Import address table (IAT) hooking is a well documented technique for intercepting calls to imported functions. However, most methods rely on suspicious API functions and leave several easy to identify artifacts. This paper explores different ways IAT hooking can be employed while circumventing common detection mechanisms.

tags | paper
MD5 | d0cefc671ad94febb6cd76561c7d9b76
Cooking With Mifare Classic
Posted Aug 2, 2011
Authored by MI1 | Site hack4fun.eu

This whitepaper gives a short inside of hacking Mifare Classic. Mifare Classic is a inexpensive, entry-level chip, based on ISO/IEC 14443 Type A, 1kB or 4kB. It uses the 13.56 Mhz contactless smartcard standard, proprietary CRYPTO1 with 48 bits keys. There is no protection against cloning or modifications. Anyone with 50 EUR reading can use this weakness against their infrastructure. This cookbook is a proof of concept demonstrating how easy it can be done.

tags | paper, proof of concept
MD5 | 1f2c753030a6cfd8baecc30e68a61bbc
SCADA And PLC Vulnerabilities In Correctional Facilities
Posted Aug 1, 2011
Authored by Tiffany Rad, Teague Newman, John Strauchs

This whitepaper gives a detailed analysis discussing vulnerabilities surrounding the use of SCADA and PLC systems in modern correctional facilities.

tags | paper, vulnerability
MD5 | 4151c016c6d87a2e1fe3b11d920060c5
Imperva's Web Application Attack Report July 2011
Posted Jul 27, 2011
Authored by Imperva | Site imperva.com

As a part of its ongoing Hacker Intelligence Initiative, Imperva's Application Defense Center (ADC) observed and categorized attacks across 30 applications as well as onion router (TOR) traffic, monitoring more than 10 million individual attacks targeted at web applications over a period of six months. This report discusses and analyzes their findings.

tags | paper, web
MD5 | ce98f375f1789b2b3f1b274fd8d33a0f
Permutation Oriented Programming
Posted Jul 23, 2011
Authored by Nelson Brito | Site code.google.com

Permutation Oriented Programming (formerly known as Exploit Next Generation) introduces a different and powerful approach to IDS/IPS subversion. It can be applied to almost all vulnerabilities and targets the vulnerability triggers. Slides and various code examples are provided.

tags | paper, vulnerability
systems | linux
MD5 | 83f2424e1306ef46a677f1f0e5769736
What Is A Vulnerability Assessment?
Posted Jul 19, 2011
Site demyo.com

Whitepaper called What is a vulnerability assessment?

tags | paper
MD5 | d47e74bceae27c15d2b3218474350a38
Digging Inside VxWorks OS And Firmware - Holistic Security
Posted Jul 18, 2011
Authored by Aditya K Sood | Site secniche.org

Whitepaper called Digging Inside VxWorks OS and Firmware - Holistic Security. VxWorks is one of the most widely accepted embedded OSes. In this paper, they have conducted a detailed study of the VxWorks OS security model and firmware in order to understand the potential impact of security vulnerabilities and weaknesses.

tags | paper, vulnerability
MD5 | 2fe7af017754aecc2f68198a7bb61a86
Web Application Finger Printing
Posted Jul 17, 2011
Authored by Anant Shrivastava | Site anantshri.info

Whitepaper called Web Application Finger Printing - Methods/Techniques and Prevention. This paper discusses how automated web application fingerprinting is performed, the visible shortcomings in the approach, and then discusses ways to avoid it.

tags | paper, web
MD5 | 028fc6c8349bd9406ea3371b78ced25f
From Unexpected To Understanding The System
Posted Jul 17, 2011
Authored by Meylira Kagaya Eisenberg

Whitepaper called From Unexpected Restart To Understand The System. Written in Indonesian.

tags | paper
MD5 | 4b71c70283df1a29a63f944db56cec89
Protecao Client-Side: Eficacia Experimentacao de Instrumentos
Posted Jul 15, 2011
Authored by Alexandro Silva | Site alexos.org

Whitepaper called Protecao Client-side: Testando a eficacia das ferramentas de protecao Microsoft para estacoes de trabalho e desktops. It describes how to protect against malicious threats by testing some Microsoft client security tools. Written in Portuguese.

tags | paper
MD5 | 9dbf00127be5f4edcb57d410efdeaf3d
RFC 6274 - Security Assessment Of The Internet Protocol Version 4
Posted Jul 6, 2011
Authored by Fernando Gont | Site ietf.org

The IETF has just published RFC 6274, entitled "Security Assessment of the Internet Protocol Version 4". It contains a large amount of information on how to improve the security of IPv4 implementations and IPv4 deployments.

tags | paper, protocol
MD5 | 6919485928a0a8157f6b4318bc5ed031
Breaking The Links: Exploiting The Linker
Posted Jul 5, 2011
Authored by Tim Brown | Site nth-dimension.org.uk

The recent discussion relating to insecure library loading on the Microsoft Windows platform provoked a significant amount of debate as to whether GNU/Linux and UNIX variants could be vulnerable to similar attacks. Whilst the general consensus of the Slashdot herd appeared to be that this was just another example of Microsoft doing things wrong, the author felt this was unfair and responded with a blog post that sought to highlight an example of where POSIX style linkers get things wrong. Based on the feedback received to that post, the author decided to investigate the issue a little further. This paper is an amalgamation of what was learnt.

tags | paper
systems | linux, windows, unix, osx
MD5 | c2e33de59c93dcc1dc48a0dd72ca382f
Structured Exception Handler Exploitation
Posted Jul 5, 2011
Authored by High-Tech Bridge SA | Site htbridge.ch

Whitepaper called Structured Exception Handler Exploitation. The SEH exploitation technique was publicly documented by David Litchfield September, 2003. At a high-level, the SEH overwrite technique uses a software vulnerability to execute arbitrary code by abusing the 32-bit exception dispatching facilities provided by Windows. At a functional level, an SEH overwrite is generally accomplished by using a stack-based buffer. This document explains SEH details while exploiting a real case.

tags | paper, arbitrary
systems | windows
MD5 | f8f8b7c201e9c3aa447babcb07e1be73
The Arashi AKA Storm
Posted Jul 3, 2011
Authored by Shahriyar Jalayeri, Shahin

This is a whitepaper called The Arashi (A.K.A Storm). It discusses ASLR/DEP bypass techniques.

tags | paper
MD5 | 654d0f3070875616c04873f913c7a798
Pentesting In Local Networks Part 1
Posted Jul 1, 2011
Authored by ph0x90bic

Whitepaper called Pentesting in Local Networks Part 1. It discusses performing recon, ARP poisoning, traffic analysis techniques, and more.

tags | paper, local
MD5 | 38898281f2a6ee37346d3adef4d80b39
Penetration Testing With Metasploit
Posted Jun 21, 2011
Authored by Dinesh Shetty

This brief whitepaper gives an overview of the functional uses of the Metasploit Framework.

tags | paper
MD5 | ccafd5601a1ca9702e2c6d605633f65a
The Art Of Information Gathering / Footprinting
Posted Jun 12, 2011
Authored by P0C T34M

Whitepaper called the Art of Information Gathering / Footprinting. Written in Arabic.

tags | paper
MD5 | b26c219514cdc2703a628027f7fc8bcd
SSL And HTTP Exposed
Posted Jun 2, 2011
Authored by GhOsT-PR

Whitepaper called SSL and HTTP Exposed. It discusses how to perform an HTTPS stripping attack against the TOR network using sslstrip.py and iptables.

tags | paper, web
MD5 | ccbad4cfbcafaa23051f5d32c199ad71
Page 5 of 24
Back34567Next

Top Authors In Last 30 Days

packet storm

© 2012 Packet Storm. All rights reserved.

close