Defining Your Overarching Goal for Email Phishing Testing
The purpose of this blog is to help small-medium businesses (SMB's) deal effectively with their unique cyber security needs. With over 15 years experience in IT and cyber security I will show SMB's how they can leverage their limited resources to develop effective cyber defenses to the most common threats using information security best practices and no/low cost tools.
LinkedIn: http://www.linkedin.com/in/ecissorsky/
Twitter: @ecissorsky
Showing posts with label Pen Testing. Show all posts
Showing posts with label Pen Testing. Show all posts
Monday, May 8, 2017
Defining Your Overarching Goal for Email Phishing Testing
Great article by Kevin Beaver on Toolbox.com:
Defining Your Overarching Goal for Email Phishing Testing
"Are you among the relatively small number of organizations that performs email phishing tests against your users? If so, why do you do it? The easy answer is to, of course, to minimize your information security risks. So, you go about testing your users’ gullibility, train them on why they should not respond to such emails, and you’re done, right? In a nutshell, yes. However, if you are going to get the most out of your email phishing testing you need to have specific end goals in mind. There is likely more testing that needs to be done."
Defining Your Overarching Goal for Email Phishing Testing
Friday, May 5, 2017
HTTP Headers... the Achilles' heel of many applications
From SANS ISC:
HTTP Headers... the Achilles' heel of many applications
"When browsing a target web application, a pentester is looking for all “entry” or “injection” points present in the pages. Everybody knows that a static website with pure HTML code is less juicy compared to a website with many forms and gadgets where visitors may interact with it. Classic vulnerabilities (XSS, SQLi) are based on the user input that is abused to send unexpected data to the server. Here is a very simple GET example:"
HTTP Headers... the Achilles' heel of many applications
"When browsing a target web application, a pentester is looking for all “entry” or “injection” points present in the pages. Everybody knows that a static website with pure HTML code is less juicy compared to a website with many forms and gadgets where visitors may interact with it. Classic vulnerabilities (XSS, SQLi) are based on the user input that is abused to send unexpected data to the server. Here is a very simple GET example:"
Wednesday, May 3, 2017
Powershelling with exploits
From SANS ISC:
Powershelling with exploits
"It should be no surprise to our regular readers how powerful PowerShell (pun intended) really is. In last couple of years, it has become the main weapon of not only white hat penetration testing, but also various attackers."
Powershelling with exploits
Tuesday, May 2, 2017
Do Indicators of Compromise Matter? The Devil is in the Details
From Security Week:
Do Indicators of Compromise Matter? The Devil is in the Details
"Instead of Discounting Indicators of Compromise, it’s Time to Use Them More Effectively
The security industry has shifted from focusing on just signatures to include Indicators of Compromise (IoCs) as well. This is because in many ways IoCs are more portable, simplistic and compatible across many different detection platforms. However, during this shift IoCs have gotten a bum rap. It’s easy to see how this has happened – indicators can sometimes be just pieces of data without context. Security professionals are struggling to make sense of data, and wondering where to find real value as they strive to secure their environment."
Do Indicators of Compromise Matter? The Devil is in the Details
"Instead of Discounting Indicators of Compromise, it’s Time to Use Them More Effectively
The security industry has shifted from focusing on just signatures to include Indicators of Compromise (IoCs) as well. This is because in many ways IoCs are more portable, simplistic and compatible across many different detection platforms. However, during this shift IoCs have gotten a bum rap. It’s easy to see how this has happened – indicators can sometimes be just pieces of data without context. Security professionals are struggling to make sense of data, and wondering where to find real value as they strive to secure their environment."
Monday, May 1, 2017
New OWASP Top 10 Reveals Critical Weakness in Application Defenses
From Dark Reading:
New OWASP Top 10 Reveals Critical Weakness in Application Defenses
"It's time to move from a dependence on the flawed process of vulnerability identification and remediation to a two-pronged approach that also protects organizations from attacks.
When I wrote the first OWASP Top 10 list in 2002, the application security industry was shrouded in darkness. The insight that a few other engineers and I had gained through hand-to-hand combat with a wide variety of applications lived only within us. We recognized that for the industry to have a future, we had to make our knowledge public."
New OWASP Top 10 Reveals Critical Weakness in Application Defenses
"It's time to move from a dependence on the flawed process of vulnerability identification and remediation to a two-pronged approach that also protects organizations from attacks.
When I wrote the first OWASP Top 10 list in 2002, the application security industry was shrouded in darkness. The insight that a few other engineers and I had gained through hand-to-hand combat with a wide variety of applications lived only within us. We recognized that for the industry to have a future, we had to make our knowledge public."
Thursday, April 27, 2017
USAF Launches 'Hack the Air Force'
From Dark Reading:
USAF Launches 'Hack the Air Force'
"Bug bounty contest expands Defense Department outreach to the global hacker community to find unknown vulnerabilities in DoD networks.
Let the friendly hacking fly: The US Air Force will allow vetted white hat hackers and other computer security specialists root out vulnerabilities in some of its main public websites."
USAF Launches 'Hack the Air Force'
"Bug bounty contest expands Defense Department outreach to the global hacker community to find unknown vulnerabilities in DoD networks.
Let the friendly hacking fly: The US Air Force will allow vetted white hat hackers and other computer security specialists root out vulnerabilities in some of its main public websites."
Friday, March 13, 2015
Pulling Remote Word Documents from RAM using Kali Linux
From Cyberarms blog:
Pulling Remote Word Documents from RAM using Kali Linux
Really enjoyed the article on W00tsec about pulling RAW picture images from memory dumps and thought it would be cool if you could use the same process to pull information from a remote system’s memory using Kali – and you can!
Pulling Remote Word Documents from RAM using Kali Linux
Really enjoyed the article on W00tsec about pulling RAW picture images from memory dumps and thought it would be cool if you could use the same process to pull information from a remote system’s memory using Kali – and you can!
Subscribe to:
Posts (Atom)