Showing posts with label christine. Show all posts
Showing posts with label christine. Show all posts

Sunday, June 18, 2017

Week 25 In Review – 2017

Events Related Circle City Con 2017 Videos - www.irongeek.com ANYCon 2017 Videos - www.irongeek.com Techniques Armory Sandbox – Building a USB analyzer with USB armory - sentinelone.com The USB armory is a small computer on a USB stick, providing an ARM A8 800 MHz CPU and 512MB RAM, and it’s versatile enough to implement all kinds of [...]

The post Week 25 In Review – 2017 appeared first on Infosec Events.



from Week 25 In Review – 2017

Tuesday, June 13, 2017

Week 24 In Review – 2017

Events Related Security Fest - www.youtube.com This summer, Göteborg became the most secure city in Sweden! We had a day filled with great talks by internationally renowned speakers on some of the most cutting edge and interesting topics in IT-Security. ShowMeCon 2017 Videos - www.irongeek.com Resources List of Printers Which Do or Do Not Display [...]

The post Week 24 In Review – 2017 appeared first on Infosec Events.



from Week 24 In Review – 2017

Sunday, April 30, 2017

Week 17 In Review – 2017

Resources  Probable-Wordlists - github.com Wordlists sorted by probability originally created for password generation and testing VM escape - QEMU Case Study - www.phrack.org Virtual machines are nowadays heavily deployed for personal use or within the enterprise segment. Network security vendors use for instance different VMs to analyze malwares in a controlled and confined environment. Vulnerabilities [...]

The post Week 17 In Review – 2017 appeared first on Infosec Events.



from Week 17 In Review – 2017

Monday, March 20, 2017

Week 12 In Review – 2017

Events Related BSidesSF 2017 - www.youtube.com Security BSides San Francisco is a two-day information security conference. It is a conference by the community for the community. Hackers Earns big at Pwn2Own Hackers managed to take down Microsoft Edge and escape a virtual machine to boot on the third day of Pwn2Own early Friday. Members from Qihoo’s [...]

The post Week 12 In Review – 2017 appeared first on Infosec Events.



from Week 12 In Review – 2017

Sunday, March 5, 2017

Week 10 In Review – 2017

Techniques Hacking Unicorns with Web Bluetooth – www.contextis.com Researchers discovered an unsecured MongoDB server that exposed sensitive CloudPets customer data. My research focused on the toy itself, in particular some issues we found with its Bluetooth LE connectivity and features. Still Passing the Hash 15 Years Later – passing-the-hash.blogspot.com So I first thought about it […]

The post Week 10 In Review – 2017 appeared first on Infosec Events.



from Week 10 In Review – 2017

Monday, February 20, 2017

Week 8 In Review – 2017

Tools  Universal Radio Hacker – github.com The Universal Radio Hacker is a software for investigating unknown wireless protocols. HackRF – github.com Techniques How to build a 8 GPU password cracker – www.shellntel.com This build doesn’t require any “black magic” or hours of frustration like desktop components do. If you follow this blog and its parts […]

The post Week 8 In Review – 2017 appeared first on Infosec Events.



from Week 8 In Review – 2017

Monday, January 16, 2017

Week 3 In Review – 2017

Tools Acunetix Free Manual Pen Testing Tools – www.acunetix.com Acunetix Manual Tools allow penetration testers to further automated testing. waveconverter – github.com Factoria Labs 2016 WaveConverter is a Python application, built on GTK+ 3. The GUI has been implemented via Glade. A sqlite database has been implemented via sqlalchemy. Techniques Cracking The 12+ Character Password […]

The post Week 3 In Review – 2017 appeared first on Infosec Events.



from Week 3 In Review – 2017

Thursday, January 5, 2017

Week 1 In Review – 2017

Resources 33C3: Chris Gerlinsky Cracks Pay TV – hackaday.com People who have incredible competence in a wide range of fields are rare, and it can appear deceptively simple when they present their work. [Chris Gerlinksy]’s talk on breaking the encryption used on satellite and cable pay TV set-top boxes was like that. Tools mitmproxy: release v1.0.0 – […]

The post Week 1 In Review – 2017 appeared first on Infosec Events.



from Week 1 In Review – 2017

Tuesday, December 27, 2016

Week 52 In Review – 2016

Resources VMware Security Advisories – vmware.com vSphere Data Protection (VDP) updates address SSH key-based authentication issue Techniques In Flight Hacking System – blog.ioactive.com What helped a lot to reduce that fear was to understand how things work in planes, and getting used to noises, bumps, and turbulence. This blog post is  about understanding a bit more about how things work aboard an aircraft. More specifically, the In-Flight Entertainment Systems (IFE) developed by Panasonic Avionics.   Other News Learning From A Year of Security Breaches – medium.com This year (2016) I accepted as much incident response work as I could. I spent about 300 hours responding to security incidents and data breaches this year as a consultant or volunteer.    

The post Week 52 In Review – 2016 appeared first on Infosec Events.



from Week 52 In Review – 2016

Tuesday, December 20, 2016

Week 51 In Review – 2016

Events Related DefCamp– def.campResources McAfee Virus Scan for Linux – state.actor A system running Intel’s McAfee VirusScan Enterprise for Linux can be compromised by remote attackers due to a number of security vulnerabilities. Some of these vulnerabilities can be chained together to allow remote code execution as root. Techniques Practical Reverse Engineering Part 5 – Digging Through the Firmware – jcjc-dev.com In part 4 we extracted the entire firmware from the router and decompressed it. As I explained then, you can often get most of the firmware directly from the manufacturer’s website: Firmware upgrade binaries often contain partial or entire filesystems, or even entire firmwares. XNU kernel UaF due to lack of locking in set_dp_control_port – bugs.chromium.org set_dp_control_port is a MIG method on the host_priv_port so this bug is a root->kernel escalation. macOS FileVault2 Password Retrieval – blog.frizk.net macOS FileVault2 let attackers with physical access retrieve the password in clear text by plugging in a $300 Thunderbolt device into a locked or sleeping mac. The password may be used to unlock the mac to access everything on it. Vulnerabilities Bluetooth-enabled safe lock popped after attackers win PINs – theregister.co.uk Attackers can locate and pop safes protected with high security commercial locks thanks to poor Bluetooth implementations, say researchers at Somerset Recon say. 0day drive-by exploit against Fedora If you run a mainstream distribution of Linux on a desktop computer, there’s a good chance security researcher Chris Evans can hijack it when you do nothing more than open or even browse a specially crafted music file. And in the event you’re running Chrome on the just-released Fedora 25, his code-execution attack works as a classic drive-by. 0-days hitting Fedora and Ubuntu open desktops to a world of hurt – arstechnica.com Redux: compromising Linux using… SNES Ricoh 5A22 processor opcodes?!– scarybeastsecurity.blogspot.com Other News  FBI Arrests Customer of Xtreme Stresser DDoS-for-Hire Service – bleepingcomputer.com The FBI arrested this past week Sean Krishanmakoto Sharma, 26, from La Canada, California, for launching DDoS attacks against Chatango, an online chat service.  

The post Week 51 In Review – 2016 appeared first on Infosec Events.



from Week 51 In Review – 2016

Sunday, November 6, 2016

Week 45 In Review – 2016

Resources Ruxcon – ruxcon.org.au Presentation Slides from Ruxcon Australia BlackHat Europe 2016 – www.blackhat.com Techniques Kerberoasting Without Mimikatz – www.harmj0y.net Thanks to an awesome PowerView pull request by @machosec, Kerberoasting is easier than ever using pure PowerShell. I wanted to briefly cover this technique and its background, how we’ve been using it recently, and a few awesome new developments. […]

The post Week 45 In Review – 2016 appeared first on Infosec Events.



from Week 45 In Review – 2016

Monday, October 17, 2016

Week 42 In Review – 2016

Resources Published “SecDevOps Risk Workflow” Book (v0.57) – blog.diniscruz.com I just published version v0.57 of the (previously called) Jira Risk Workflow book. Vulnerabilities These 60 dumb passwords can hijack over 500,000 IoT devices into the Mirai botnet – www.grahamcluley.com Mirai has become infamous in recent weeks after blasting the website of security blogger Brian Krebs off the […]

The post Week 42 In Review – 2016 appeared first on Infosec Events.



from Week 42 In Review – 2016

Tuesday, September 6, 2016

Week 36 In Review – 2016

Tools WiFi-Pumpkin – github.com Framework for Rogue Wi-Fi Access Point Attack Python tools for penetration testers – github.com Python tools for penetration testers Nmap 7.25BETA2 Birthday Release – nmap.org Nmap 7.25BETA1 includes dozens of performance improvements, bug fixes, and new features. Vulnerabilities Meet USBee, the malware that uses USB drives to covertly jump airgaps – […]

The post Week 36 In Review – 2016 appeared first on Infosec Events.



from Week 36 In Review – 2016