#HITB2012KUL D1T2 - Marc 'Van Hauser' Heuse - IPv6 Insecurity Revolutions

How to secure your home against "Internet of Things" and FUD

| | Hack, home security, Internet of things, iot
TL;DR, most of the security news about IoT is full of FUD. Always put the risks in context - who can exploit this and what can the attacker do with it. Most story only covers the latter.IntroductionThere is rarely a day without news that another "Internet of Things" got hacked ... Read More
Mythbusters: Is an open (unencrypted) WiFi more dangerous than a WPA2-PSK? Actually, it is not.

Mythbusters: Is an open (unencrypted) WiFi more dangerous than a WPA2-PSK? Actually, it is not.

| | VPN, wifi, wireless, WPA2, wpa2-psk
IntroductionWhenever security professionals recommend the 5 most important IT security practices to average users, one of the items is usually something like: “Avoid using open Wifi” or “Always use VPN while using open WiFi” or “Avoid sensitive websites (e.g. online banking) while using open WiFI”, etc.What I think about this? ... Read More
T105 An ACE in the Hole Stealthy Host Persistence via Security Descriptors Lee Christensen Matt Nels

Many ways of malware persistence (that you were always afraid to ask)

| | Malware, persistence, Windows
TL;DR: Are you into red teaming? Need persistence? This post is not that long, read it ;)Are you into blue teaming? Have to find those pesky backdoors? This post is not that long, read it ;)In the previous post, I listed different ways how a Windows domain/forest can be backdoored ... Read More
DEF CON 20 - Dave Kennedy and Dave DeSimone - Owning One to Rule Them All

Thousand ways to backdoor a Windows domain (forest)

| | backdoor, domain, Hack, Windows
When the Kerberos elevation of privilege (CVE-2014-6324 / MS14-068) vulnerability has been made public, the remediation paragraph of the following blog post made some waves:http://blogs.technet.com/b/srd/archive/2014/11/18/additional-information-about-cve-2014-6324.aspx"The only way a domain compromise can be remediated with a high level of certainty is a complete rebuild of the domain."Personally, I agree with this, ... Read More
How To Get Unlimited Money In Asphalt 8! Windows 8/8.1

Hacking freemium games – the evolution of PC game cheating

| | cheating, freemium, games, Hacking
This post is going to be a rather strange post compared to previous ones. But bear with me, in the middle of the post you will see why this post fits the IT security topic.I'm also terribly sorry for not posting recently, but I was busy with my SPSE and ... Read More
Change passwords regularly - a myth and a lie, don't be fooled, part 2

Change passwords regularly – a myth and a lie, don’t be fooled, part 2

| | complexity, Password, security
In the previous blog post, I have covered the different passwords you have to protect, the attackers and attack methods. Now let's look at how we want to solve the issue. Password requirementsSo far we have learned we have to use long, complex, true random passwords. In theory, this is ... Read More
Who hacked and posted celebs nude pics?

Change passwords regularly – a myth and a lie, don’t be fooled, part 1

| | Password, security
TL;DR: different passwords have different protection requirements, and different attackers using various attacks can only be prevented through different prevention methods. Password security is not simple. For real advise, checking the second post (in progress).Are you sick of password advices like "change your password regularly" or "if your password is ... Read More

Attacking financial malware botnet panels – SpyEye

| | botnet, spyeye, sql injection, sqli
This is the second blog post in the "Attacking financial malware botnet panels" series. After playing with Zeus, my attention turned to another old (and dead) botnet, SpyEye. From an ITSEC perspective, SpyEye shares a lot of vulnerabilities with Zeus. The following report is based on SpyEye 1.3.45, which is old, ... Read More
Fur TV - Fat Ed's furry fucking guide to Metal

Hacking Windows 95, part 2

In the Hacking Windows 95, part 1 blog post, we covered that through a nasty bug affecting Windows 95/98/ME, the share password can be guessed in no time. In this article, I'm going to try to use this vulnerability to achieve remote code execution (with the help of publicly available ... Read More
DSploit

DSploit

DSploitAfter playing with the applications installed on the Pwn Pad, I found that the most important application (at least for me) was missing from the pre-installed apps. Namely, DSploit. Although DSploit has tons of features, I really liked the multiprotocol password sniffing (same as dsniff) and the session hijacking functionality.The DSploit ... Read More