Thursday, April 26, 2012
Assess your internet connection security
Have you ever thought about doing external penetration testing and but no budget available.
I suggest the following free online tools to determine how is your organization security. these online tools give you basic assessment and you need to do in depth penetration testing to make sure no security weaknesses can allow hackers into your network
Port Scanner
Web Tool Hub Online port scanner
Web applications and vulnerability scanners
Qualys FreeScan
Automated Security Analyser for ASP.NET Websites
Tuesday, April 17, 2012
Memory Forensics
As incident responder, you have to know how to conduct memory forensics .
All over the internet you can find many excellent articles, here I will list these articles in order to help new incident responders understanding and building memory forensics skills using volatility tool.
First, references you must keep with you all the time
Memory Forensics Cheat Sheet
List of tutorials
IETab_IE65 Malware Memory Analysis
Volatility Memory Forensics | Basic Usage for Malware Analysis
Zeus Analysis in Volatility 2.0Zeus Analysis in Volatility 2.0
Zeus v2 Malware Analysis - Part II
Stuxnet's Footprint in Memory with Volatility 2.0
Memory Forensics: Analyzing a Stuxnet Memory Dump (And you can too!) Volatility Memory Forensics | Basic Usage for Malware Analysis
Zeus Analysis in Volatility 2.0Zeus Analysis in Volatility 2.0
Zeus v2 Malware Analysis - Part II
Stuxnet's Footprint in Memory with Volatility 2.0
Memory Forensics: Analyzing a Stuxnet Memory Dump
I will keep the list updated with the best references and tutorials.
All over the internet you can find many excellent articles, here I will list these articles in order to help new incident responders understanding and building memory forensics skills using volatility tool.
First, references you must keep with you all the time
Memory Forensics Cheat Sheet
List of tutorials
IETab_IE65 Malware Memory Analysis
Volatility Memory Forensics | Basic Usage for Malware Analysis
Zeus Analysis in Volatility 2.0Zeus Analysis in Volatility 2.0
Zeus v2 Malware Analysis - Part II
Stuxnet's Footprint in Memory with Volatility 2.0
Memory Forensics: Analyzing a Stuxnet Memory Dump (And you can too!) Volatility Memory Forensics | Basic Usage for Malware Analysis
Zeus Analysis in Volatility 2.0Zeus Analysis in Volatility 2.0
Zeus v2 Malware Analysis - Part II
Stuxnet's Footprint in Memory with Volatility 2.0
Memory Forensics: Analyzing a Stuxnet Memory Dump
I will keep the list updated with the best references and tutorials.
One Hour A Day Keeps Intrusions Away
In IT field, everyone is busy and forget about checking IT infrastructure security, by spending almost one hour daily, IT or security administrators will be able to prevent intrusions or at least detect them before it is too late.
All you need is to have reports generated from security tools in place for example antivirus, proxy, content filter, intrustion prevention systems, etc.. what about firewalls, if no log and reporting tool in place splunk (freeware) or OSSIM (opensource) can be used to generate required reports.
Addition to reports, you have to subscribe to one or more security alerts and news letters.
So how can we spend that hour daily ? simply the following can be done
All you need is to have reports generated from security tools in place for example antivirus, proxy, content filter, intrustion prevention systems, etc.. what about firewalls, if no log and reporting tool in place splunk (freeware) or OSSIM (opensource) can be used to generate required reports.
Addition to reports, you have to subscribe to one or more security alerts and news letters.
So how can we spend that hour daily ? simply the following can be done
- Based on Antivirus reports
- Review the top 5 infected computers
- Review the top 5 viruses infections
- Based IPS/IDS reports
- Review IPS/IDS report top 5 source of attacks
- Review IPS/IDS REPORT top 5 targets of attacks
- Based on Proxy or content filtering reports
- Review top 5 visited web sites
- Review web links visited during non working hours or during week ends
- Review suspicious web links.
- Based on Firewall ports
- Review top 5 blocked ports
- Review top 5 blocked internal IP addresses
- Review accessed external ports (UDP/TCP)
- Search pastebin.com for posted information about your entity
- Search zon-h.org for unknown web defacement happened to your web server
- Review security news letters and alerts
Monday, February 28, 2011
HITB Magazine Issue #5 is now available
New issue of HTIB magazine already available
Inside:
- Investigating Kernel Return Codes with the Linux Audit System
- Secure Shell Attack Measurement and Mitigation
- ARP Spoofing Attacks & Methods for Detection and Prevention
- Exploiting Web Virtual Hosting –Malware Infections
- Windows CSRSS Tips & Tricks
New issue of Hakin9 available: Identity Theft
New issue of Hakin9 magazine already available!
Inside:
Inside:
- Identity Proof Your Personal Data by Julian Evans
- Guarding Against Identity Theft by Gary Miliefsky
- The Best Way to Learn and Apply Cryptography by Arkadius C. Litwinczuk
- Analysis of a Scam by Rich Hoggan
- Secure Env for PT by Antonio Merola
- Knowing VoIP – part III by Winston Santos
- Bluetooth Mice Can Leak Your Passwords! by Aniket Pingley, Xian Pan, Nan Zhang, Xinwen Fu
- Choosing an IDS/IPS Engine by Matthew Jonkman
Monday, February 21, 2011
Free e-book: Web Application Security for Dummies
Qualys has published a new comprehensive free guide on Web Application Scanning (WAS) to help readers understand web application security - including how to quickly find and fix vulnerabilities in web applications.
WAS for dummies ebook
WAS for dummies ebook
Hackito Ergo Sum 2010
Hackito Ergo Sum is focusing on all technology hacks, hardcore reverse engineering and vulnerability research, exotic network and platform hacking, and all the new domains of the hacking domain
Here you can find 2010 presentations
http://hackitoergosum.org/archive-201/
Here you can find 2010 presentations
http://hackitoergosum.org/archive-201/
Subscribe to:
Posts (Atom)