In this article I am going to conduct a walk through with a nice python tool named PeFrame. This tool should be an analyst’s first choice in order to analysis a piece of static malware. I am going to discuss each and every feature provided by this tool and I will also show you why it is important to find information through the malware.
Everything about threat intelligence, blue team, red team, pentesting, security audit, security review, testing and assessment.
Sunday, November 17, 2013
Thursday, November 14, 2013
Transport Layer Security - Part 1
This is a non-technical guide which will make you familiar with the transport layer. The main purpose of writing this guide is to point out why we need major security implementation on the transport layer. What if the components of this layer get compromised?
Tuesday, November 5, 2013
Scalpel : Data Recovery From Byte Strings
In digital forensics, file carving is an essential process. It is a technique in which investigator uses databases of headers as well footers. These headers and footers contain byte strings. So, suppose you have 5 JPEG files. So all those 5 files will have same header & footer byte strings. So this tool carves data by analyzing that byte string. This Is an advance tool as it also carves file even after its metadata is removed.
Monday, November 4, 2013
Phishing Countermeasures Unleashed
Monday, October 28, 2013
SSL Unleashed
In this article I am going to tell you everything about SSL that what it is why we need it, technical and non technical aspects of SSL etc.. This article covers the introduction, SSL certificate, Encryption, process of encryption and how your browser interact and trust that certificate provided by the website you are visiting.
Existence of SSL
There are basically 2 aspects of SSl. One is Encryption and second is Identification. Now encryption is what you hide the content of the data sent from one machine to another machine. It is done by changing the content of the data in identical to garbage form which is human readable but not human understandable. It is exactly like speaking in different languages with what one person is not familiar. I am Indian if someone speaks in Russian language, it is not understandable by me. So here Russian language is like encrypted language for me. However if I get a translator and he/she translates that Russian language into Hindi then I can say that now that is understandable by me. So it is said that message has been decrypted. Identification is related to trust. In the previous scenario, how can I trust the translator who is converting Russian language to Hindi? Is she/he legitimate ? Can I trust him/her? In the digital world, it is something like this. Your machine has to trust the SSL certificate (security mechanism), provided by the website via an SSL certificate issuing vendor.
Labels:
encryption,
https,
secure http,
ssl,
ssl certificate,
ssl encryption
Wednesday, October 16, 2013
Dissecting Malware – Static Analysis of Malware
This article will be showing you how doing static malware analysis. Which are the processes involved within a static analysis. Static malware analysis is the first essential step taken by the malware analysts or reverse engineers working under forensics department.
Static Malware Analysis
Best and childish way to analyze malware is to scan it with multiple antivirus services. There are ton of antivirus available in the world, so your malware will surely be identified by at least any of them from the world. What exactly antivirus does that, they have the thousands of malicious file signatures and patterns within themselves. So they scan malware and if the file pattern gets matched with their database, it gets detected.
Monday, September 30, 2013
Cyber Warfare - Building Your Nation's Cyber Army - Digital Arm Force
This article will be showing you
why we need to really think of our nation’s cyber army. Where we are, which
digital weapons we have? What are the challenges faced by your countries in the
digital world. So, How to overcome this problem? How to recruit your digital
arm force smartly? This article will help the government as well as private
security firms too.
History of
Hacking
Over the past years we have seen many big hacking case
studies which lead us to think seriously about cyber crime world. Some of the
stories I want to share with you.
Moonlight Maze:
Although the feds aren't talking publicly about a three-years-plus cyber-attack
believed to be coming from Russia, a member of the U.S. National Security
Agency's Advisory Board says the case, dubbed "Moonlight Maze,"
reveals huge cracks in the U.S. government's defense system. The Moonlight Maze
stealth attack, which has targeted sensitive but unclassified information since
it was launched in March 1998, is the "largest sustained cyber-attack"
on the U.S., according to Adams. (Abreu, 2001)
Labels:
cyber security,
cyber terrorism,
cyber war,
cyber warfare
Saturday, September 28, 2013
Detecting Firewall/IPS via hping3 Before Starting Your Pentest
Before starting your network/web
application security auditing it is always good to detect whether your
target server is running any firewall/IPS or not. It has been always a
best practice and method to send some crafted packets to the server in
order to check the response form the server. In this article you will
learn how to craft packets and how to send the server on their various
ports using hping3. Also you will analyze each and every request coming
and going from your machine to your target. Here my target is
www.chintangurjar.com which's IP I have taken.
Labels:
firewall,
firewall test,
hping3,
iptable firewall,
iptables,
linux,
linux firewall
Subscribe to:
Posts (Atom)