Thursday, April 26, 2012

Assess your internet connection security


Have you ever thought about doing external penetration testing and but no budget available.

I suggest the following free online tools to determine how is your organization security. these online tools give you basic assessment and you need to do in depth penetration testing to make sure no security weaknesses can allow hackers into your network

Port Scanner
Web Tool Hub Online port scanner

Web applications and vulnerability scanners
Qualys FreeScan
Automated Security Analyser for ASP.NET Websites

Tuesday, April 17, 2012

Memory Forensics

As incident responder, you have to know how to conduct memory forensics .

All over the internet you can find many excellent articles, here I will list these articles in order to help new incident responders understanding and building memory forensics skills using volatility tool.

First, references you must keep with you all the time
Memory Forensics Cheat Sheet

List of tutorials

IETab_IE65 Malware Memory Analysis
Volatility Memory Forensics | Basic Usage for Malware Analysis
Zeus Analysis in Volatility 2.0Zeus Analysis in Volatility 2.0
Zeus v2 Malware Analysis - Part II
Stuxnet's Footprint in Memory with Volatility 2.0
Memory Forensics: Analyzing a Stuxnet Memory Dump (And you can too!) Volatility Memory Forensics | Basic Usage for Malware Analysis
Zeus Analysis in Volatility 2.0Zeus Analysis in Volatility 2.0
Zeus v2 Malware Analysis - Part II
Stuxnet's Footprint in Memory with Volatility 2.0
Memory Forensics: Analyzing a Stuxnet Memory Dump

I will keep the list updated with the best references and tutorials.

One Hour A Day Keeps Intrusions Away

In IT field, everyone is busy and forget about checking IT infrastructure security, by spending almost one hour daily, IT or security administrators will be able to prevent intrusions or at least detect them before it is too late.

All you need is to have reports generated from security tools in place for example antivirus, proxy, content filter, intrustion prevention systems, etc.. what about firewalls, if no log and reporting tool in place splunk (freeware) or OSSIM (opensource) can be used to generate required reports.

Addition to reports, you have to subscribe to one or more security alerts and news letters.

So how can we spend that hour daily ? simply the following can be done
  1. Based on Antivirus reports
    1. Review the top 5 infected computers
    2. Review the top 5 viruses infections
  2. Based IPS/IDS reports
    1. Review  IPS/IDS report top 5 source of attacks
    2. Review IPS/IDS REPORT top 5 targets of attacks
  3. Based on Proxy or content filtering reports
    1. Review top 5  visited web sites
    2. Review web links visited during non working hours or during week ends
    3. Review suspicious web links.
  4. Based on Firewall ports
    1. Review top 5 blocked ports
    2. Review top 5 blocked internal IP addresses
    3. Review accessed external ports (UDP/TCP)
  5. Search pastebin.com for posted information about your entity
  6. Search zon-h.org for unknown web defacement happened to your web server
  7. Review security news letters and alerts
Soon i will add more details about what to look for and how to identify possible or potentail intrusions or weaknesses.


Monday, February 28, 2011

HITB Magazine Issue #5 is now available

New issue of HTIB magazine already available
 
Inside:
  • Investigating Kernel Return Codes with the Linux Audit System
  • Secure Shell Attack Measurement and Mitigation
  • ARP Spoofing Attacks & Methods for Detection and Prevention
  • Exploiting Web Virtual Hosting –Malware Infections
  • Windows CSRSS Tips & Tricks

New issue of Hakin9 available: Identity Theft


New issue of Hakin9 magazine already available!

Inside:
  • Identity Proof Your Personal Data by Julian Evans
  • Guarding Against Identity Theft by Gary Miliefsky
  • The Best Way to Learn and Apply Cryptography by Arkadius C. Litwinczuk
  • Analysis of a Scam by Rich Hoggan
  • Secure Env for PT by Antonio Merola
  • Knowing VoIP – part III by Winston Santos
  • Bluetooth Mice Can Leak Your Passwords! by Aniket Pingley, Xian Pan, Nan Zhang, Xinwen Fu
  • Choosing an IDS/IPS Engine by Matthew Jonkman

Monday, February 21, 2011

Free e-book: Web Application Security for Dummies

Qualys has published a new comprehensive free guide on Web Application Scanning (WAS) to help readers understand web application security - including how to quickly find and fix vulnerabilities in web applications.

WAS for dummies ebook

Hackito Ergo Sum 2010

Hackito Ergo Sum is focusing on all technology hacks, hardcore reverse engineering and vulnerability research, exotic network and platform hacking, and all the new domains of the hacking domain

Here you can find 2010 presentations


http://hackitoergosum.org/archive-201/