Defeating AES without a PhD

January 17, 2013 | Dan Crowley

"Cryptography is typically bypassed, not penetrated." – Adi Shamir FAITH IN THE ...

QA w/ SpiderLabs Research: Java 0day CVE-2013-0422

January 16, 2013 | Arseny Levin

Q: What's going on? People are talking about some Java 0daywhich threatens the ...

Microsoft Patch Tuesday, January 2013 - Part II

January 14, 2013 | Robert Foggia

It's now official, there is another bulletin (MS13-008) release for the month ...

SpiderLabs Radio January 11, 2013 w/ Space Rogue

January 11, 2013 | Space Rogue

We are back with another episode of SpiderLabs Radio hosted by Space Rogue. ...

ModSecurity Mitigations for Ruby on Rails XML Exploits

January 10, 2013 | Ryan Barnett

There is big trouble in Ruby on Rails (RoR) land... The issue is related to XML ...

First Java 0day For The Year 2013

January 10, 2013 | Admin

Today @Kafeine was the first to announce the new Java 0day. This 0day allows an ...

SpiderLabs Crypto Contest - Hints

January 09, 2013 | Admin

This is a post for those attempting to solve the Crypto contest I introduced a ...

Goodies released with Trustwave SWG Security Update 141

January 08, 2013 | Rami Kogan

As cliché as it may sound, security is done in layers and so, using our generic ...

Microsoft Patch Tuesday, January 2013 – Hot Sauce

January 08, 2013 | Space Rogue

I had lunch today at a great little Cajun restaurant in Chicago called Heaven ...

SpiderLabs Radio January 04, 2013 w/ Space Rogue

January 04, 2013 | Admin

We are back with another episode of SpiderLabs Radio hosted by Space Rogue. ...

Dissecting a CVE-2012-4792 Payload

January 04, 2013 | Trustwave SpiderLabs

A little while ago I was fortunate enough to get ahold of a sample that was ...

Microsoft Advance Notification for January 2013

January 03, 2013 | Space Rogue

If you were hoping for a nice relaxing Patch Tuesday after the holidays, well, ...

Hacking with Drain Cleaner – Yet Another BitLocker Bypass Technique

January 02, 2013 | Admin

As hard-wired as any Application Specific Integrated Circuit it seems the ...

Photobucket: An Identity Thief's Playground

January 02, 2013 | Admin

Photobucket is a popular social media site that acts as gallery and cloud ...

Choppy Regulatory Waters ahead for EU SMEs?

January 02, 2013 | Admin

There's been a reasonable amount of coverage of the (proposed) data protection ...

Internet Explorer - 2012 Last Minute 0-Day

January 01, 2013 | Rami Kogan

Using Zero Days attacks at end of the year are not the most considerate thing ...

Smuggler - An interactive 802.11 wireless shell without the need for authentication or association

December 31, 2012 | Admin

I've always been fascinated by wireless communications. The ability to launch ...

Wardrive, Raspberry Pi Style!

December 31, 2012 | Videoman

I purchased a Raspberry Pi a few weeks back. I found that I could power it, ...

Teaching Security Self-Defense

December 31, 2012 | Barry O’Connell

My background in IT comes mostly from a nomadic perspective. In my years of IT ...

Getting Terminal Access to a Cisco Linksys E-1000

December 31, 2012 | Jonathan Claudius

Over the past couple weeks, I've been spending a lot of time hacking on various ...

SpiderLabs Radio December 28, 2012 w/ Space Rogue

December 28, 2012 | Admin

We are back with another episode of SpiderLabs Radio hosted by Space Rogue. ...

SpiderLabs Radio December 21, 2012 w/ Space Rogue

December 21, 2012 | Admin

We are back with another episode of SpiderLabs Radio hosted by Space Rogue. ...

Simple Ciphers, and a little SpiderLabs Crypto Contest

December 20, 2012 | Admin

Millions have died and millions have been saved because of cryptography. There ...

Fraud, Passwords, and Pwnage on the Interwebz

December 19, 2012 | Therese Mendoza

This past weekend I was lucky enough to attend Microsoft's BlueHat Conference ...

Setting HoneyTraps with ModSecurity: Project Honeypot Integration

December 18, 2012 | Admin

Following up my previous blog post which outlined how to activate additional ...

Finding Zero Days Reading Your Mind in the Year 2052

December 18, 2012 | Trustwave SpiderLabs

A number of months ago, I was approach by the organizers of TEDxNaperville to ...

Setting HoneyTraps with ModSecurity: Unused Web Ports

December 17, 2012 | Ryan Barnett

This blog post will show an easy configuration update that you can make to your ...

You down with LNK?

December 15, 2012 | Nathan Drier

Oftentimes on an Internal pen test, I find myself with a limited-privilege ...