The only magazine devoted exclusively to penetration testing.
May 17, 2013, 7:57 pm

MS08_068 + MS10_046 = FUN UNTIL 2018

Contributed By: Rob Fuller TL;DR: SMB Relay + LNK UNC icons = internal pentest pwnage I need to touch on the highlights of two vulnerabilities before we talk about the fun stuff, but I highly encourage you to read the references at the bottom of this post and understand the vulnerabilities after you are done [...]

What They Don’t Teach You in “Thinking Like the Enemy” Classes

Contributed By: Pete Herzog For those of you who are interested in taking a security class that promises to teach you ethical hacking and how to think like the enemy, let me save you some time and money on what you will learn: Find who and what interacts with your target. Search those things for [...]

The State of Information Security by Billy Stanley

Sorry, but you do not have permission to view this content.

MS08_068 + MS10_046 = FUN UNTIL 2018

Article by Rob Fuller TL;DR: SMB Relay + LNK UNC icons = internal pentest pwnage I need to touch on the highlights of two vulnerabilities before we talk about the fun stuff, but I highly encourage you to read the references at the bottom of this post and understand the vulnerabilities after you are done with [...]

What They Don’t Teach You in “Thinking Like the Enemy” Classes

Article by Pete Herzog For those of you who are interested in taking a security class that promises to teach you ethical hacking and how to think like the enemy, let me save you some time and money on what you will learn: Find who and what interacts with your target. Search those things for [...]

Coalfire Introduces Navis HITECH Complete to Safeguard Medical Data

Cloud-based IT GRC solution enables accurate, affordable and self-directed HIPAA compliance assessments  LOUISVILLE, Colo. (January 11, 2012) – The Health Information Technology and Clinical Health (HITECH) Act, enacted in 2009, promotes the adoption of electronic health records (EHRs) and extends the reach of the 1996 Health Insurance Portability and Accountability Act (HIPAA). As a result, [...]

New Meterpreter Extension Released by SecureState

1/9/2012 Utility gives penetration testers an easily deployable and flexible port scanning (Cleveland, Ohio) Today SecureState is releasing a new extension for Metasploit’s Meterpreter called MSFMap. This new utility provides an NMap-like port scanner from within the context of a Meterpreter session. This gives penetration testers an easily deployable and flexible port scanning utility. Having [...]

Social Engineering: What it is and how you can avoid it

Social engineering is known to be a way of manipulating people into revealing their personal information or breaking their normal security procedures. The general purpose of this type of deception is to gather information, commit fraud, or to gain access to computer systems. Techniques All the techniques social engineers use play into the natural decision-making [...]

Security and the Software Development Life Cycle

SDLC Background Information The concept of integrating security into the Software Development Life Cycle (SDLC), while generating much popular press recently, is an already-familiar concept at SecureState. We have been helping clients to build security into their Software Development Life Cycle (SDLC) for several years, and have honed our expertise in the process. SecureState always [...]

Privacy vs. Security ?

Recent news headlines contrast privacy and security, with regard to relinquishing portions of our privacy for the benefit of security. For example, airports implementing backscatter scanner X-ray imaging, devices that very graphically depict body images, under the guise of protecting passengers. While this debate has merit, it does not address the more global differentiation of [...]

I’ve Been Afraid of Changing Because I Built my Life Around PCI ASV Scans.

Introduction (My name is Bob and I am a Ninja) Early last year the new PCI Approved Scanning Vendor (ASV) Program Guide was released. The new ASV scanning procedures required some significant changes which caused current ASVs to rush to get these changes implemented. If you are a scan client which is required to have [...]

But it was Developed by a Third Party…Of Course it’s Secure!

This is a case study of a real-life example of how vulnerabilities in third party web applications, as well as internally coded web applications, can be linked together in such a way that code execution is possible on the underlying operating system. Many Organizations Assume Their Third Party Web Applications Are Secure Many organizations falsely [...]

Page 1 of 212

Advertisement




Software Press Sp. z o.o. Sp. Komandytowa 02-682 Warszawa, ul. Bokserska 1, NIP 9512279582, REGON 141804060, KRS: 0000327578