Sunday, June 5, 2016
Second Order Buffer OverFlow Attacks (SOBOF): Attacking underlying components
The C programming language is still prevalent in computing today. It may be tempting to think that interpreted languages like Java and Ruby have taken over, but this belief is unfounded or at least limited in scope. Even interpreted, Type-safe (in the sense of defining 'undefined' behavior as Exceptions), languages have had their applications ripped open by a buffer overflow. Not in a buffer they contained directly. No these errors exist in the core of the system. In the Kernel hooks and Drivers that every program reliant on features of the Operating System use.
Saturday, May 14, 2016
Attacker's Tool Chest: Anatomy of tools and tactics from the field on network security
When you start trying to talk to people about Security topics you may come to find that not everyone has a clear understanding what different terminology actually means. I don't think it is their fault really. We as a culture tend to under-explain topics to outsiders. For ease of explaining something to a non-technical person we will often overload a term (like Virus), or switch to an improper term (Like Trojan) that they are more likely to know...even if they don't understand what it means.
To combat that I think it is a good idea to get a running list of terms I have had to explain or clarify to people. These are my own explanations, meant to capture the unique qualities of each type of Tool or Technique.
Sunday, April 24, 2016
Knowing the Enemy: Advanced Persistent Threat report analysis Pt. 2
I am back for part 2 of the analysis breakdown of the ICIT APT briefing. After an excellent discussion on the topic of Malware Evolution with someone from the Malware Bytes team, I think it is time to finish what I started several weeks ago. Here is the second half of my analysis or the APT report.
Tuesday, April 19, 2016
The Jolly Roger Flies Again: BSides Tampa
This past Saturday I had the pleasure of presenting my Rellik Project once again. This time at the Security Bsides event in Tampa FL. Hosted by the (ISC)2. The topic of Botnets has been very popular and my audience was very involved. It was a fantastic day all around.
Sunday, April 10, 2016
Knowing the Enemy: Advanced Persistent Threat report analysis Pt. 1
Advanced
Persistent Threats or APTs has become a well known term over the last 5 years. In terms on
Network security an attack is considered
Tuesday, April 5, 2016
Be careful what you wish for: Information Leaks in Job Searches
Your company is leaking data. That is not a question. It simply is a fact. The reason is: job postings. The amount of information companies give out freely about their organization, network technology, infrastructure, etc., is amazing. It is also a potential gold mine for a would be attacker. Consider the real (but edited for privacy) job description found on a very popular classified site:
Saturday, March 19, 2016
Foretelling the future: Estimatig Software Project Lifespans
In my professional career as Technologist I have evolved through many stages. Why it seems like just yesterday I was scanning for broken HREFs. Now, I am in charge of task management for one of the most talented development teams I have ever gotten the privilege of coding with. Like every major paradigm shift though, this one has come with a whole new set of challenges and skills. One of the most important ones is accurately estimating project timelines. As a manager, I wanted an easy way to come up with realistic project. This is the result of that research.
Subscribe to:
Posts (Atom)
