Analysis reveals mobile apps designed to protect things like photos and passwords do a poor job, often storing them in plain text with no encryption at all.
Continue reading "Analyzing Android, iOS Apps For Weak Data Protection, Cleartext Passwords"
How to compile, copy, and run mac-robber on jailbroken iOS devices
Continue reading "Quick-Start Guide: Compiling Mac-Robber For iOS Vuln Research"
How to compile, copy, and run mac-robber on rooted Android devices
Continue reading "Quick-Start Guide: Compiling Mac-Robber For Android Vuln Research"
Intro to a unique approach for vulnerability research on mobile apps using traditional PC forensic tools
Continue reading "Forensic Approach To Mobile App Vulnerability Research"
"Practical Malware Analysis" provides in-depth knowledge on malware analysis and includes useful lab exercises. We take REMnux for a spin with the labs
Continue reading "Fun With REMnux -- And New Malware Analysis Book"
Preconfigured Linux environments provide powerful tools to aid in pen testing, mobile security testing, malware analysis, and forensics
Continue reading "Linux Live Environments: Cool Tools Even For Windows Folks"
Passive network analysis can reveal OS, service, and even vulnerabilities -- just by sniffing the network
Continue reading "Passive Network Fingerprinting; p0f Gets Fresh Rewrite"
Pen testers must get beyond just breaking in and clients need to understand how the tester's results map to business risk
Continue reading "Penetration Tests: Not Getting 'In' Is An Option"
Companies like to set up Internet kiosks for customers and job applicants, but their convenience can be their undoing
Continue reading "Plugging The Kiosk-Sized Security Hole"
Baselines can be extremely valuable in knowing what's going on within your network, but they can't help if they're not created. Start with the basics and adapt to meet your needs.
Continue reading "Basic Baselining For Quick Situational Awareness"
DerbyCon's successful first year reminds us of what the security community is all about: sharing and learning from others, promoting new ideas, and advancing the art of security.
Continue reading "DerbyCon Fosters Community -- Videos Available Online"
Italian researcher releases 0-day SCADA exploits leaving companies vulnerable to exploit. Community-based IDS signature project releases update to help detect attacks.
Continue reading "0-Day SCADA Exploits Released, Publicly Exposed Servers At Risk"
New Metasploit modules released during the Vegas security cons add cool new features like covert forensics and PXE boot pwnage.
Continue reading "Metasploit Gets Covert Forensics And PXE Boot Attack Capabilities"
Awareness campaign at DEFCON shows how easy data can be stolen from smartphones using free charging kiosks.
Continue reading "Smartphones And Tablets Targets For Getting 'Juiced'"
New research on medical device security is shining light on potentially deadly vulnerabilities.
Continue reading "Medical Device Security Under Fire At Black Hat, DefCon"
Rewrite of WarVOX brings new features, better audio fingerprinting, and a Ruby VoIP stack that's been integrated into Metasploit.
Continue reading "WarVOX Gets An Overhaul; Wardialing Added To Metasploit"
Upcoming Metasploit Framework vSploit modules can help to identify security blindspots.
Continue reading "New Metasploit Tools Help Find Security Blind Spots"
WAFs can provide a good layer of defense against attacks, but can't solve all web app sec problems as vendors would like you to think.
Continue reading "WAFs Have Benefits, But Are Not A Security Cure-all"
The biggest hurdle SMBs face with logging is actually starting. Even the most rudimentary setup can provide immeasurable value when faced with a breach.
Continue reading "Logging Isn't Hard -- Getting Started Is"
Free, open source tools like the Metasploit Framework and w3af exemplify the power of community involvement and support.
Continue reading "The Power Of Open-Source Security Tools"
Two new wireless security projects discussed at ShmooCon focus on bringing low-cost hardware to security researchers
Continue reading "Frequency Hopping Spread Spectrum, Project Ubertooth Detailed At ShmooCon "
Panel of security professionals discussed new tools and techniques to accelerate password cracking, highlighting need for multi-factor authentication
Continue reading "ShmooCon Panel Discusses Ease, Speed Of Password Cracking"
Exploit for SCADA software emphasizes need for organizations to review their network design, device exposure before they become a victim.
Continue reading "Security Researcher Targets SCADA, Releases Exploit"
Simple statistical analysis of Web proxy logs provides wealth of information & incidents sometimes by AV.
Continue reading "Mining Web Proxy Logs For Interesting, Actionable Data"
Snorby is a new free, open-source analysis front-end to the popular Snort IDS that is fast and usable.
Continue reading "New Snort Front-End Adds Speedy Analysis, Ease Of Use"