DNS Rebinding and IDS Signatures
DNS rebinding attacks have been around for a number of years and still present challenges today. This type of attack can propagate via malware and individuals who do not act appropriately to protect...
View ArticleInternet Security, Data Breaches and Password Management
Today’s state of security truly is in a poor state of affairs and there is really little indication that things will get any better anytime soon. How better to understand the scope of the problem than...
View ArticleComputer Forensics Tools: Windows Registry
Computer forensics is the application of investigation and analysis techniques to gather and preserve evidence from a particular computing device in a way that is suitable for presentation in a court...
View ArticleSecurely Delete Files On Your MAC
Deleting a file from your computer is like opening a book and scratching out the name of a chapter in the table of contents. The chapter isn’t really gone, just the information about how to find it is....
View ArticleWhy oh Why Does SQLi Continue To Be a Problem
So far this year it seems just about every new day brings a new data breach. Now to be fair, I do not know how organizations are being breached, but I would tend to believe that SQL injection may be...
View ArticleSecure Your Mac Computer
Securing your Mac computer is not overly difficult and there are a number of actions you can take to protect yourself from others seeking harm. Face it, if you do not take security seriously with your...
View ArticleMalware and the Risk to Cybersecurity
Malware is widespread and continues to grow with each passing day. There are even recent reports that adware vendors are actively purchasing Chrome extensions to peddle their adware and malware. If you...
View ArticleWhat Can We Learn From the 2013 Adobe Database Breach
Early October 2013, Adobe announced that they fell victim to a cyberattack and their database was breached to the degree that 2.9 million customers are impacted in one way or another. From my point of...
View ArticleLife In a Digital World Means Little or No Privacy
I want to start 2014 off by looking at security and privacy. One can argue that we are more secure today than we were just a few short years ago, but security comes at a cost and that cost is privacy....
View ArticleFingerprinting a Web Server with httprecon
Web applications unfortunately are vulnerable and for this reason they are often the gateway for attacks. An attacker is going to perform reconnaissance to understand where a weakness may reside. Of...
View ArticleWow! That Email Sure Gets Around
Email is an instrument that we each use likely every day without a great deal of thought or concern. There are a number of factors that make email convenient and those are cost, ease of access, speed...
View ArticleTime To Go Phishing With the Social Engineering Toolkit (SET)
Social Engineering is a very intriguing art of exploiting trust of others. For the most part people are trusting of one another and because of this trust, a person may be tricked into performing and...
View ArticleThe Journey of Becoming a Certified Information Security Professional
Certified Information Systems Security Professional (CISSP) is an independent information security certification governed by International Information Systems Security Certification Consortium also...
View ArticleFree Security Vulnerability Guides From Veracode
Veracode focuses on security for organizations to accurately identify and manage application security risk. They offer a number of resources to include podcast, whitepapers, cheat sheets, and much...
View ArticleHow To Be Sneaky And Hide Data Using Alternate Data Streams
Have you heard of Alternate Data Streams (ADS)? If not, sit back and relax and learn what you can do with ADS. Before I get to far into the subject it is important to understand what ADS is used for....
View ArticleCreate a Penetration Testing Lab and Let the Hacking Begin
If you are interested in sharpening your skills or simply interested in getting started with penetration testing this this article will be of interest. The hard cold truth is that under no...
View ArticleWhat is Ping All About?
If you have used a computer more than say a single day, I am sure that you are well aware of ping. If not, then you are in for a treat! Well I suppose it may not be a treat in some opinions, but this...
View ArticleThe State Of Web Application Security
This week I officially start my Master Degree in CyberSecurity with the University of Maryland and I have become more and more interested in security from the point of view of application development...
View Article8 Week Self Study Bootcamp for Security Professionals
It is important from time to time that we all revisit terminology. For this reason I have put together the following resources in the hopes of learning something new or at the very least bringing back...
View Article20 Introductory Nmap Command Examples for the Technology Professional
I’m not going to attempt to cover what Nmap is and what it can do. Rather the author states: Nmap (“Network Mapper”) is a free and open source (license) utility for network discovery and security...
View Article