on :
Sunday, 1 Jan, 2006
Can one fool application-layer fingerprinting?
Numerous tools exist which allow one to determine what service runs on some given port and what software provides it. Let us attempt to understand how they work, then ponder upon whether it would be possible (or easy) to trick them. Author: Piotr Sobolewski Source: http://hakin9.org Hakin9 2/2006 What you will learn...- what is application level fingerprinting,
- what techniques it uses,
- which tools can you use to carry out application level fingerprinting,
- which techniques these tools use and its consequences,
- are the results provided by tools reliable,
- is it difficult (possible) to trick the tools.
- how the Internet works and know basic Linux commands.
on :
Sunday, 1 Jan, 2006
Writing advanced Linux backdoors – packet sniffing
As people create new defences for backdoors, intruders are forced to innovate new techniques to keep pace with the rapidly progressing security industry. One of such techniques is packet sniffing backdoors. Let's learn how they work by writing our own Proof-of-Concept tool. Author: Brandon Edwards Source: http://hakin9.org Hakin9 1/2006 What you will learn...- how the packet sniffing backdoor technique works,
- how to use this technique in practice.
- Linux TCP/IP networking basics,
- C programming basics,
- Linux networking using libpcap.
on :
Sunday, 1 Jan, 2006
Cryptography for Mail and Data
Would you put confidential information on a postcard and send it to your friends, colleagues, or business partners? Well, no. But why would you put confidential information in an e-mail and send it around the world? Author: Lars Packschies Source: http://hakin9.org Hakin9 1/2006 What
on :
Sunday, 1 Jan, 2006
How to cook a covert channel
Before starting to cook your covert channel, you first have to think about the receipt (recette): decide how your covert channel will look like, what it will be used for (antipasti or dessert ?) and finally when you'll have your
on :
Sunday, 1 Jan, 2006
Network Defense Applications using IP Sinkholes
A little-talked-about network security technique has proven one of the most effective means of defense against Denial-of-Service attacks and a successful means of threat data collection. In this article we will explore advanced network defense applications using stationary and event-driven
on :
Sunday, 1 Jan, 2006
Simple Event Correlator for real-time security log monitoring
Over the past decade, event correlation has become a prominent event processing technique in many domains (network and security management, intrusion detection, etc.). However, existing open-source log monitoring tools don't support it well. In this paper, we will discuss how
on :
Sunday, 1 Jan, 2006
Rootkits under Windows platforms
What is the link between kernel hackers (in this article we will use the term kernel instead of the core of an Operating System), corporations having webmarketing businesses which develop spywares or adwares to profile websurfers and corporations like Sony
on :
Sunday, 1 Jan, 2006
GFI LANguard Network Security Scanner
GFI LANguard Network Security Scanner is a tool for scanning one or more computers connected to a network. Scan results include a security assessment and a list of vulnerabilities found. Author: Tomasz Nidecki Source: http://hakin9.org Hakin9 1/2006 Quick start. Suppose you want to assess
on :
Sunday, 1 Jan, 2006
Intrusion Detection in the Wild
Network intrusion detection requires a suite of tools, including traditional, signature-based NIDS such as snort. In this article we examine how to use common tools together to provide multilayered protection in case one measure should fail, and to provide maximum
on :
Sunday, 1 May, 2005
Linux shellcode optimisation
A shellcode is an essential part of any exploit. During attack, it is injected into the target application and performs the desired actions within it. However, the basic rules for building shellcodes are not too widely known, even though they
on :
Sunday, 1 May, 2005
Advanced SQL Injection techniques
SQL Injection attacks target the core of a web application: its database. Their most significant impact enables an attacker to retrieve, modify, or delete arbitrary data. It is a serious threat to any application with a database back-end and a
on :
Sunday, 1 May, 2005
















