5 Most Common Web Application Vulnerabilities

December 21, 2011
  Injection Examples of injection flaws are SQL, LDAP, HTTP header injection (cookies, requests), and OS command injections Attacks occur when untrusted data, such as a query, command or argument, is sent to an interpreter Vulnerable applications can be tricked into executing unintended commands or allowing the attacker to access, and modify, data Cross Site [...]

Book of the Month – Metasploit: The Penetration Tester’s Guide

September 21, 2011
It gives me great pleasure to review this book ‘Metasploit – The Penetration Tester’s Guide’, not only because it is written on most popular penetration testing framework but the way it is written doing complete [...]

SX Impact – Developer Fixes Vulnerability in Facebook Application

September 13, 2011
Few days back, we have published research article on “Vulnerable Facebook Applications” by Abhinav Singh, one of our active contributor. In this article, he has exposed how vulnerable Facebook Applications are and how they can [...]

Book of the Month – IDA PRO 2nd Edition

July 28, 2011
The best book on IDA PRO gets even better with second edition. This is one of those special books which does not need any review at all. The book stands on its own. . Since [...]

‘Password Security’ Presentation at IIT Guwahati

March 14, 2011
Here is brief capture of the security conference “Information Security Education & Awareness 2011″ (ISEA) held at IIT Guwahati where I presented ‘Primer on Password Security’. This event was held as part of initiative to [...]

Facebook Chief Security Officer to Keynote 2nd Annual HITB Security Conference in Europe

March 2, 2011
After the success of last year’s inaugural event, Hack In The Box Security Conference is taking over the Krasnapolsky once again from the 17th till the 20th of May. This deep knowledge security conference brings [...]

Book of the Month – A Guide to Kernel Exploitation

December 28, 2010
Anyone into Vulnerability Research and Exploitation knows how hard it is to discover a Security Vulnerability and then develop a reliable exploit for it. Now consider taking it from user land to kernel, the near impossible thing to get your shoes in for the show. . In that context, ‘A Guide to Kernel Exploitation’ new [...]

Book of the Month – Mobile Malware Attacks and Defense

October 19, 2010
As mobile devices becoming more and more sophisticated with their computing power and memory, the attackers are slowing shifting their focus from PC to these Mobile devices. Unlike earlier generation of mobile devices, current mobile devices are as powerful as our computer systems with increased memory and performance along with built-in internet connectivity. All of [...]

Released StreamArmor 1.1

September 12, 2010
StreamArmor 1.1 is out now with couple of bug fixes and few other changes related to minor enhancements. StreamArmor is the sophisticated tool for discovering hidden alternate data streams (ADS) as well as clean them completely from the system. It’s advanced auto analysis coupled with online threat verification mechanism makes it the best tool available [...]

Detecting ‘Slow Dll Hijacking’ Vulnerability using DllHijackAuditor

September 11, 2010
‘Dll Hijack’ vulnerability is one of the recently highlighted critical security issue affecting most of the popular Windows applications. Every day researchers are discovering more and more applications which are vulnerable to various forms of ‘Dll Hijacking’ and at the same time attackers have started exploiting these vulnerable applications. . In that event, we had [...]

FireStats icon Powered by FireStats