Agregátor RSS

CMarkup Use After Free Vulnerability – CVE-2012-4782

VNSECURITY - 18 Srpen, 2014 - 12:00
Latest M$ tuesday patch kill one of my 0day in Microsoft Internet Explorer 9/10. So I decided release Proof Of Concept code and writeup some analyze about this bug. Hope it helpful. Here is the PoC: [sourcecode language="html"] ...
Kategorie: Hacking & Security

Snatching The H@t

VNSECURITY - 18 Srpen, 2014 - 12:00
Nhận lời mời từ IDG, VNSecurity đồng ý đứng ra phối hợp tổ chức cuộc thi "Snatching the h@t" như một sự kiện trong khuôn khổ hội thảo CSO Asean năm 2012 với mong muốn giới thiệu và phát triển CTF như một hình thức học tập và thể hiện ...
Kategorie: Hacking & Security

[writeup] Hacklu 2012 – Challenge #12 – Donn Beach – (500)

VNSECURITY - 18 Srpen, 2014 - 12:00
The famous zombie researcher “Donn Beach” almost created an immunization against the dipsomanie virus. This severe disease leads to the inability to defend against Zombies, later causes a complete loss of memory and finally turns you into one of them. Inexplicably Donn forgot where he put the license key for his centrifuge. Provide him ...
Kategorie: Hacking & Security

[writeup] Hacklu 2012 – Challenge #6 – BrainGathering – (500)

VNSECURITY - 18 Srpen, 2014 - 12:00
I did not solve this during CTF and my mistake is not using IDA to decompile since it has some obfuscate. After CTF end, i use gdb to dump running process to binary file and analyze it again, try to finish it. gdb --pid [PID] gdb>info proc process 4660 gdb>shell cat /proc/4660/maps 08048000-0804a000 rwxp 00000000 08:03 7213513 gdb>dump ...
Kategorie: Hacking & Security

[writeup] Hacklu 2012 – Challenge #19 – Zombie Reminder – (200)

VNSECURITY - 18 Srpen, 2014 - 12:00
19 - Zombie Reminder Zombies love brains. But zombies forget, so they have a tool where they can enter the location of brains they found. In a heroic mission someone managed to obtain both the source code and the information that a critical file can be found at '/var/www/flag'. Your mission ...
Kategorie: Hacking & Security

Tor – Xác định các exit relay độc hại

VNSECURITY - 14 Srpen, 2014 - 22:30
1. Mở đầu Bài viết này là phần mô tả sơ lược và bình luận bài báo "Spoiled Onions: Exposing Malicious Tor Exit Relays"[1]. Tor exit relay là nút cuối dùng trong hành trình vận chuyển của các gói tin trọng mạng Tor, gói tin từ đây sẽ đi đến địa chỉ ...
Kategorie: Hacking & Security

[writeup] Hacklu 2012 – Challenge #13 – The Sandbox Terminal

VNSECURITY - 14 Srpen, 2014 - 17:30
Solved by w00d @ clgt Thanks g4mm4 for giving many suggestions and draft the first version of the exploit 13 - The Sandboxed Terminal (400) Since the zombie apocalypse started people did not stop to ask themselves how the whole thing began. An abandoned military base may lead to answers but after infiltrating ...
Kategorie: Hacking & Security

Lấy lời nhạc nhaccuatui.com

VNSECURITY - 5 Srpen, 2014 - 22:30
Nhaccuatui vừa nâng cấp trình chơi nhạc trên web của mình có thể hiển thị lời nhạc theo thời gian khá tốt. Bài viết này sẽ trình bày các bước để lấy lời nhạc đó và cung cấp một công cụ để thực hiện trong 1 cú enter ;) (*). Lấy ...
Kategorie: Hacking & Security

[writeup] Hacklu 2012 – Challenge #10 (500)

VNSECURITY - 3 Srpen, 2014 - 18:00
10 - zlotpy Gambling time. Play against the Internet Zlot Machine at ctf.fluxfingers.net tcp/2053 This challenge has two stages. 1) Medium: Investigate the contents of a saved game. 2) Hard: Get 8 (EIGHT) bonus points. Good luck! Hint: We have some sourcecode for you! https://ctf.fluxfingers.net/challenges/zlot.py At the first sight, we thought this challenge was ...
Kategorie: Hacking & Security

A Model for Licensing IT Security

SANS Reading Room - 6 Srpen, 2013 - 21:00

Category: Legal Issues

Paper Added: August 6, 2013

Kategorie: Hacking & Security

Discovering Security Events of Interest Using Splunk

SANS Reading Room - 6 Srpen, 2013 - 21:00

Category: Logging Technology and Techniques

Paper Added: July 17, 2013

Kategorie: Hacking & Security

Practical Cyber Security Training Techniques for New IT Support Employees

SANS Reading Room - 6 Srpen, 2013 - 21:00

Category: Best Practices

Paper Added: July 19, 2013

Kategorie: Hacking & Security

Detecting Security Incidents Using Windows Workstation Event Logs

SANS Reading Room - 6 Srpen, 2013 - 21:00

Category: Logging Technology and Techniques

Paper Added: July 9, 2013

Kategorie: Hacking & Security

Security Best Practices for IT Project Managers

SANS Reading Room - 6 Srpen, 2013 - 21:00

Category: Best Practices

Paper Added: June 24, 2013

Kategorie: Hacking & Security

A Practical Social Media Incident Runbook

SANS Reading Room - 6 Srpen, 2013 - 21:00

Category: Incident Handling

Paper Added: June 20, 2013

Kategorie: Hacking & Security

SANSFIRE 2011

SANS Reading Room - 6 Srpen, 2013 - 21:00
SANSFIRE 2011
Kategorie: Hacking & Security

Web Application Injection Vulnerabilities: A Web App's Security Nemesis?

SANS Reading Room - 6 Srpen, 2013 - 21:00

Categories: Application and Database Security,Securing Code,Security Basics

Paper Added: June 14, 2013

Kategorie: Hacking & Security

Electronic Medical Records: Success Requires an Information Security Culture

SANS Reading Room - 6 Srpen, 2013 - 21:00

Categories: HIPAA,Compliance

Paper Added: June 5, 2013

Kategorie: Hacking & Security

Corporate vs. Product Security

SANS Reading Room - 6 Srpen, 2013 - 21:00

Categories: Best Practices,Incident Handling,Security Policy Issues,Management & Leadership

Paper Added: June 3, 2013

Kategorie: Hacking & Security

Securing BYOD With Network Access Control, a Case Study

SANS Reading Room - 6 Srpen, 2013 - 21:00

Category: Network Access Control

Paper Added: May 23, 2013

Kategorie: Hacking & Security
Syndikovat obsah