Defeating AES without a PhD
January 17, 2013 | Dan Crowley
"Cryptography is typically bypassed, not penetrated." – Adi Shamir FAITH IN THE ...
QA w/ SpiderLabs Research: Java 0day CVE-2013-0422
January 16, 2013 | Arseny Levin
Q: What's going on? People are talking about some Java 0daywhich threatens the ...
Microsoft Patch Tuesday, January 2013 - Part II
January 14, 2013 | Robert Foggia
It's now official, there is another bulletin (MS13-008) release for the month ...
SpiderLabs Radio January 11, 2013 w/ Space Rogue
January 11, 2013 | Space Rogue
We are back with another episode of SpiderLabs Radio hosted by Space Rogue. ...
ModSecurity Mitigations for Ruby on Rails XML Exploits
January 10, 2013 | Ryan Barnett
There is big trouble in Ruby on Rails (RoR) land... The issue is related to XML ...
First Java 0day For The Year 2013
January 10, 2013 | Admin
Today @Kafeine was the first to announce the new Java 0day. This 0day allows an ...
SpiderLabs Crypto Contest - Hints
January 09, 2013 | Admin
This is a post for those attempting to solve the Crypto contest I introduced a ...
Goodies released with Trustwave SWG Security Update 141
January 08, 2013 | Rami Kogan
As cliché as it may sound, security is done in layers and so, using our generic ...
Microsoft Patch Tuesday, January 2013 – Hot Sauce
January 08, 2013 | Space Rogue
I had lunch today at a great little Cajun restaurant in Chicago called Heaven ...
SpiderLabs Radio January 04, 2013 w/ Space Rogue
January 04, 2013 | Admin
We are back with another episode of SpiderLabs Radio hosted by Space Rogue. ...
Dissecting a CVE-2012-4792 Payload
January 04, 2013 | Trustwave SpiderLabs
A little while ago I was fortunate enough to get ahold of a sample that was ...
Microsoft Advance Notification for January 2013
January 03, 2013 | Space Rogue
If you were hoping for a nice relaxing Patch Tuesday after the holidays, well, ...
Hacking with Drain Cleaner – Yet Another BitLocker Bypass Technique
January 02, 2013 | Admin
As hard-wired as any Application Specific Integrated Circuit it seems the ...
Photobucket: An Identity Thief's Playground
January 02, 2013 | Admin
Photobucket is a popular social media site that acts as gallery and cloud ...
Choppy Regulatory Waters ahead for EU SMEs?
January 02, 2013 | Admin
There's been a reasonable amount of coverage of the (proposed) data protection ...
Internet Explorer - 2012 Last Minute 0-Day
January 01, 2013 | Rami Kogan
Using Zero Days attacks at end of the year are not the most considerate thing ...
Smuggler - An interactive 802.11 wireless shell without the need for authentication or association
December 31, 2012 | Admin
I've always been fascinated by wireless communications. The ability to launch ...
Wardrive, Raspberry Pi Style!
December 31, 2012 | Videoman
I purchased a Raspberry Pi a few weeks back. I found that I could power it, ...
Teaching Security Self-Defense
December 31, 2012 | Barry O’Connell
My background in IT comes mostly from a nomadic perspective. In my years of IT ...
Getting Terminal Access to a Cisco Linksys E-1000
December 31, 2012 | Jonathan Claudius
Over the past couple weeks, I've been spending a lot of time hacking on various ...
SpiderLabs Radio December 28, 2012 w/ Space Rogue
December 28, 2012 | Admin
We are back with another episode of SpiderLabs Radio hosted by Space Rogue. ...
SpiderLabs Radio December 21, 2012 w/ Space Rogue
December 21, 2012 | Admin
We are back with another episode of SpiderLabs Radio hosted by Space Rogue. ...
Simple Ciphers, and a little SpiderLabs Crypto Contest
December 20, 2012 | Admin
Millions have died and millions have been saved because of cryptography. There ...
Fraud, Passwords, and Pwnage on the Interwebz
December 19, 2012 | Therese Mendoza
This past weekend I was lucky enough to attend Microsoft's BlueHat Conference ...
Setting HoneyTraps with ModSecurity: Project Honeypot Integration
December 18, 2012 | Admin
Following up my previous blog post which outlined how to activate additional ...
Finding Zero Days Reading Your Mind in the Year 2052
December 18, 2012 | Trustwave SpiderLabs
A number of months ago, I was approach by the organizers of TEDxNaperville to ...
Setting HoneyTraps with ModSecurity: Unused Web Ports
December 17, 2012 | Ryan Barnett
This blog post will show an easy configuration update that you can make to your ...
You down with LNK?
December 15, 2012 | Nathan Drier
Oftentimes on an Internal pen test, I find myself with a limited-privilege ...