The world is growing rapidly with
various technologies, and accordingly the illegal activities are being
increased by adopting these new technologies. Every country has their own laws
and regulations. In the UK people are convicted under the Computer Misuse Act
1990 for illegal activities, which are done with the help of technologies, and
there are evidences proved that many people have been sentenced under those
laws (Turner, M., 2013).Apart from that, there are few regulations such as
RIPA 2000, which gives power to certain authorities in the UK to carry out
surveillance or intercepting the communications against a person for a specific
reason. The question is that how these laws are being used effectively and reasonably?
Gaining information illegally or by misusing the power of rights is against the
law and publishing this information is unethical and against Media Regulations.
Everything about threat intelligence, blue team, red team, pentesting, security audit, security review, testing and assessment.
Saturday, April 5, 2014
Friday, April 4, 2014
Practical Buffer Overflow - Vulnerability Disclosure
Attackers generally use buffer overflows to corrupt the execution stack of a web application. By sending
carefully crafted input to a web application, an attacker can cause the
web application to execute arbitrary code, possibly taking over the
machine. Attackers have managed to identify buffer overflows in a
staggering array of products and components. Buffer overflow flaws can be present in both the web server and
application server products that serve the static and dynamic portions
of a site, or in the web application itself. Buffer overflows found in
commonly-used server products are likely to become widely known and can
pose a significant risk to users of these products. When web
applications use libraries, such as a graphics library to generate
images or a communications library to send e-mail, they open themselves
to potential buffer overflow attacks.
Friday, March 28, 2014
Ideal Information Security Policy for SME
Information security shortly (named called as IS) is a critical part of any small scale company and a big enterprise. To preserve private information is a big challenge for any firm. Information security involves very confidential important assets and other business process.It also includes all those private financial documents and also private information of each and every employers within the organization. In some case information may also include client’s important assets. Without having proper security of all these information, it becomes unreliable. Having lack of proper security mechanism sometimes it is also inaccessible when it is really needed. Lack of security can also invite 3rd parties to let them compromise these private assets and information. Information has two types.
Saturday, March 22, 2014
Theoretical Methodology for Detecting ICMP Reflected Attacks: SMURF Attacks
There are plenty of different ways to track the original source
of a DoS attack, but those techniques are not efficient enough to track
a reflected ICMP attack. When I say “reflected ICMP attack,” that means
a SMURF attack. Here I am going to show you a new model to trackback
the reflective DOS attack caused by ICMP packets.This is a very
efficient method, because you can do this with the help of a really few
attack packets. We have seen that, to detect ICMP attacks in direct attack, we need a large amount of packets to be revised, which is not true in this case.
Friday, March 14, 2014
Computer Forensics Investigation – A Case Study
Computer technology is the major integral part of everyday human
life, and it is growing rapidly, as are computer crimes such as
financial fraud, unauthorized intrusion, identity theft and intellectual
theft. To counteract those computer-related crimes, Computer Forensics
plays a very important role. “Computer Forensics involves obtaining and
analysing digital information for use as evidence in civil, criminal or
administrative cases (Nelson, B., et al., 2008)”. A Computer Forensic Investigation generally investigates the data
which could be taken from computer hard disks or any other storage
devices with adherence to standard policies and procedures to determine
if those devices have been compromised by unauthorised access or not.
Computer Forensics Investigators work as a team to investigate the
incident and conduct the forensic analysis by using various
methodologies (e.g. Static and Dynamic) and tools (e.g. ProDiscover or
Encase) to ensure the computer network system is secure in an
organization.
Monday, March 3, 2014
Spoofing Ports To Trick Bad Guys
Portspoof is meant to be a lightweight, fast, portable and secure
addition to the any firewall system or security system.
The general goal of the program is to make the reconessaince phase slow
and bothersome for your attackers as much it is only possible.
This is quite a change to the standard 5s Nmap scan, that will give a
full view of your systems running services.
Labels:
nessus,
nessus scan,
network security,
nmap,
nmap scan,
port scan,
transport layer security
Friday, February 21, 2014
Web App Pentest - Part 5 XSS
In my previous article we have seen which are the different ways of
fuzzing including suffix and prefix. We used those fuzzing techniques in order
to find error messages in web application. Now as we know how to fuzz, we will
use that skill to find XSS generally known as cross site scripting.
Testing For
XSS
Without wasting much time, let us go to, Document viewer page under A3
Cross site scripting(XSS) module. In there are various method of exploiting XSS
but first we will choose simple method which is HTTP attribute.
Thursday, February 13, 2014
Subscribe to:
Posts (Atom)







