Computer technology is the major integral part of everyday human
life, and it is growing rapidly, as are computer crimes such as
financial fraud, unauthorized intrusion, identity theft and intellectual
theft. To counteract those computer-related crimes, Computer Forensics
plays a very important role. “Computer Forensics involves obtaining and
analysing digital information for use as evidence in civil, criminal or
administrative cases (Nelson, B., et al., 2008)”. A Computer Forensic Investigation generally investigates the data
which could be taken from computer hard disks or any other storage
devices with adherence to standard policies and procedures to determine
if those devices have been compromised by unauthorised access or not.
Computer Forensics Investigators work as a team to investigate the
incident and conduct the forensic analysis by using various
methodologies (e.g. Static and Dynamic) and tools (e.g. ProDiscover or
Encase) to ensure the computer network system is secure in an
organization.
Everything about threat intelligence, blue team, red team, pentesting, security audit, security review, testing and assessment.
Friday, March 14, 2014
Monday, March 3, 2014
Spoofing Ports To Trick Bad Guys
Portspoof is meant to be a lightweight, fast, portable and secure
addition to the any firewall system or security system.
The general goal of the program is to make the reconessaince phase slow
and bothersome for your attackers as much it is only possible.
This is quite a change to the standard 5s Nmap scan, that will give a
full view of your systems running services.
Labels:
nessus,
nessus scan,
network security,
nmap,
nmap scan,
port scan,
transport layer security
Friday, February 21, 2014
Web App Pentest - Part 5 XSS
In my previous article we have seen which are the different ways of
fuzzing including suffix and prefix. We used those fuzzing techniques in order
to find error messages in web application. Now as we know how to fuzz, we will
use that skill to find XSS generally known as cross site scripting.
Testing For
XSS
Without wasting much time, let us go to, Document viewer page under A3
Cross site scripting(XSS) module. In there are various method of exploiting XSS
but first we will choose simple method which is HTTP attribute.
Thursday, February 13, 2014
Monday, February 3, 2014
Web App Pentest - Part 3 Fuzzing
When We test the web application,
we do not test a single page but we test lot of page of a single web
application. So each page may have more than one variable so technically you
will be engaging with ton of variables within your web application test. So
when you inject anything to the input it is good to know what kind of effect
your injection is making to the server. In this part of these article series we
will look at the importance of simple alphabetic injection along with the web
page encoding technology and how it does effect on our testing and result.
Web App Pentest - Part 2 Indentifying Injection Points
If your web page is static, you cannot
test it as far as security concern. You can test it at some sort of view but
you can’t play with it much as compare to dynamic page. Nikto scanner is a good
utility which works best in testing static sites. There has to be some
interaction between client and server via login panel, comment section, register
page, contact us form and so on.
Saturday, January 18, 2014
Web App Pentest - Part 1 Introduction
In this series of articles, I am going to demonstrate how you
can manually exploit the vulnerability of a web application, compared to
using any automation tool, in order to find vulnerabilities in the
application. Almost all companies worldwide focus on manual testing of
web application rather than running web application scanners, which
limit your knowledge and skills and the scope of finding a vulnerability
with your testing.
For the whole series I am going to use these programs:
Saturday, December 28, 2013
Different Types of Wireless Attacks - Theory
As we all know that wireless networks are spread at each
and every part of the world starting
from personal home to corporate business, schools/universities, cafes etc..
Major merit of wireless network is of eliminating the big and tidy cables which
acquires space and not spoiling the look of your working area. But as we all
know that each coin has two sides. There are demerits of wireless networks as
well. It comes with high possibility of attacks on it. In this article I am
going to describe different techniques of wireless attacks from the world and
what we should do to prevent those attacks on wireless networks.
Subscribe to:
Posts (Atom)





