OpenSSH 7.1p2 released with security fix for CVE-2016-0777, (Thu, Jan 14th)
2016-01-14:Updated to show">OpenSSHvulnerabilities likeHeartbleed. OpenSSH 7.1p2 has been released with a security fix for a vulnerability recently assigned toCVE-2016-0777 [1]. CVE 2016-0777 is a...
View ArticleISC StormCast for Friday, January 15th 2016...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleISC StormCast for Friday, January 15th 2016...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleJavaScript Deobfuscation Tool, (Fri, Jan 15th)
Emails remain a nice way to infect people: Write a messagewith pertinent information, respect the format and style of theorganization youre targeting, add some social engineering and you have good...
View ArticleISC StormCast for Monday, January 18th 2016...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleSome useful volatility plugins , (Mon, Jan 18th)
In previous diaries I have talked about using volatility, in this diary I will talk about other plugins . 1-MBR parser: mbrparser plugin will scans for and parses potential Master Boot Records (MBRs)...
View ArticleISC StormCast for Tuesday, January 19th 2016...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticlePowershell and HTTPS ? It Ain?t All Rainbows And Lollipops! (or is it?),...
Back in PowerShell school everyone discusses how great Powershell is for Windows functions, and an obligatory part of everyone powershell class is to cover off Invoke-WebRequest, which allows you to...
View ArticleISC StormCast for Wednesday, January 20th 2016...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View Article/tmp, %TEMP%, ~/Desktop, T:\, ... A goldmine for pentesters!, (Wed, Jan 20th)
When you are performing a penetration test, you need to learn how your target is working: What kind of technologies and tools are used, how internal usernames are generated, email addresses format, ......
View ArticleISC StormCast for Thursday, January 21st 2016...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleScanning for Fortinet ssh backdoor, (Thu, Jan 21st)
On 11 Jan, a Python script was posted on the full-disclosure mailing list that took advantage of a hardcoded ssh password in some older versions of various products from Fortinet (see complete list in...
View ArticleISC Stormcast For Friday, January 22nd 2016....
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleExtracting pcap from memory , (Fri, Jan 22nd)
I have talked many times about memory forensics and how useful its. In this diary I am going to talk about how to extract a pcap file from a memory image using bulk_extractor. Of course when we are...
View ArticleSigcheck and VirusTotal for Offline Machine, (Sat, Jan 23rd)
In a diary entry I showed a great new feature of Sysinternals" /> This example is for one file. But of course, sigcheck can check many files if you point it to a folder and use option -s to recurse....
View ArticleObfuscated MIME Files, (Sun, Jan 24th)
As could be expected, the race to obfuscate MS Office documents stored as MIME files to bypass detection, would not stop with a simple extra line. I was given a sample where the first two lines are not...
View ArticleAssessing Remote Certificates with Powershell, (Mon, Jan 25th)
Building on our last conversation about HTTPS and Powershell, lets look at another common thing youd do with HTTPS in a system administrator, or in a security assessment or penetration test lets assess...
View ArticleCuckoo Sandbox 2.0 RC1 released...
=============== Rob VandenBrink Metafore (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleISC Stormcast For Monday, January 25th 2016...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleISC Stormcast For Tuesday, January 26th 2016...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View Article